Weird networktraffic

2001-04-21 Thread pf
Hi there, I get some weird log messages from my denying catchall ipchains rule: Apr xx hh:mm:ss kernel: Packet log: input - eth0 PROTO=17 x.x.x.x:27300 x.x.x.x:58078 L=158 S=0x00 I=36151 F=0x T=55 (#82) That is UDP connections from port 27300 to port 58078. The source port sometimes i

Weird networktraffic

2001-04-21 Thread pf
Hi there, I get some weird log messages from my denying catchall ipchains rule: Apr xx hh:mm:ss kernel: Packet log: input - eth0 PROTO=17 x.x.x.x:27300 x.x.x.x:58078 L=158 S=0x00 I=36151 F=0x T=55 (#82) That is UDP connections from port 27300 to port 58078. The source port sometimes

Server reboots

2001-03-13 Thread pf
Hey there. I've just had the pleasure of a server which rebootet itself, and found it's ext2fs partition to be unclean. Now, I wonder if that could be a security problem in the direction of some nasty person having fun with me? Or is it just deffective hardware/software setup? (The kernel shouldn't

Server reboots

2001-03-13 Thread pf
Hey there. I've just had the pleasure of a server which rebootet itself, and found it's ext2fs partition to be unclean. Now, I wonder if that could be a security problem in the direction of some nasty person having fun with me? Or is it just deffective hardware/software setup? (The kernel shouldn'

Re: Network security

2001-03-08 Thread pf
On Thu, Mar 08, 2001 at 04:13:15PM +0100, Tollef Fog Heen wrote: > Have you chosen to use 'Explicit Congestion Notification' when you > compiled the kernel? If so, many firewalls and routers drop packages > with this set. It bit me, and I couldn't find out what it was - look > at whether /proc/sy

Network security

2001-03-08 Thread pf
Hi, I have been playing around with kernel 2.4.2 lately, and suddenly my TCP packets get rejected by some firewalls with the error: TCP packet dropped (195.249.21.201->firewall.ao-vvs.dk[129.142.86.2]: Protocol=TCP[SYN 0xc0] Port 58355->25): Bad TCP flags combination (received on interface 129.14

Re: Network security

2001-03-08 Thread pf
On Thu, Mar 08, 2001 at 04:13:15PM +0100, Tollef Fog Heen wrote: > Have you chosen to use 'Explicit Congestion Notification' when you > compiled the kernel? If so, many firewalls and routers drop packages > with this set. It bit me, and I couldn't find out what it was - look > at whether /proc/s

Network security

2001-03-08 Thread pf
Hi, I have been playing around with kernel 2.4.2 lately, and suddenly my TCP packets get rejected by some firewalls with the error: TCP packet dropped (195.249.21.201->firewall.ao-vvs.dk[129.142.86.2]: Protocol=TCP[SYN 0xc0] Port 58355->25): Bad TCP flags combination (received on interface 129.1