Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email firstname.lastname@example.org
Re: strange connection attempts
From: dawnshade (h-kmail.ru)
Date: Mon Apr 14 2003 - 06:42:26 CDT
G> I have turned on sysctls variables:
G> net.inet.tcp.log_in_vain: 1
G> net.inet.udp.log_in_vain: 1
G> And i have plenty of strange connection attempts on udp protocol
G> Connection attempt to UDP xx.xx.x.xxx:55414 from 220.127.116.11:53
G> Apr 13 23:56:53 pals /kernel: Connection attempt to UDP xx.xx.x.xxx:55414 from 18.104.22.168:53
G> Connection attempt to UDP xx.xx.x.xxx:12545 from 22.214.171.124:53
G> Apr 13 23:56:54 pals /kernel: Connection attempt to UDP xx.xx..xxx:12545 from 126.96.36.199:53
G> Connection attempt to UDP xx.xx.x.xxx:44308 from 188.8.131.52:53
G> i know that those connections are from dns but why kernel logs such thing.
G> I have statufull firewall and all trafic to any port on UDP protocol are deny and
G> only those UDP datagrams from my resolver are passed back through dynamics rules.
G> These connections are caused by returned queruies from dns servers.
G> Is it normal to have such type connection attempts ?
G> Can anybody help me solve my problem.
I think yes. Got a same messages. The suspicion on squid - when
connect to some server not completed or refused.
rootsome_hostname.ru$ echo "reboot" > /etc/rc&&reboot
freebsd-securityfreebsd.org mailing list
To unsubscribe, send any mail to "freebsd-security-unsubscribefreebsd.org"