how should i interpret this??


Results 1 to 7 of 7

Thread: how should i interpret this??

  1. #1
    Join Date
    Nov 2003
    Posts
    16

    how should i interpret this??

    i got these lines on my /var/log/messages

    Jun 10 14:41:53 zoo kernel: Connection attempt (PRIV): IN=eth0 OUT= MAC=ff:ff:ff:ff:ff:ff:00:10:b5:10:12:98:08:00 SRC=192.168.2.34 DST=192.168.2.255 LEN=78 TOS=0x00 PREC=0x00 TTL=128 ID=28132 PROTO=UDP SPT=137 DPT=137 LEN=58

    Jun 10 14:13:49 zoo kernel: Connection attempt (PRIV): IN=eth0 OUT= MAC=00:04:5a:4d:ff:0f:00:30:bd:09:b1:ac:08:00 SRC=24.81.240.124 DST=192.168.2.14 LEN=48 TOS=0x10 PREC=0x00 TTL=110 ID=62013 DF PROTO=TCP SPT=2028 DPT=21 WINDOW=16384 RES=0x00 SYN URGP=0
    Jun 10 14:13:52 zoo kernel: Connection attempt (PRIV): IN=eth0 OUT= MAC=00:04:5a:4d:ff:0f:00:30:bd:09:b1:ac:08:00 SRC=24.81.240.124 DST=192.168.2.14 LEN=48 TOS=0x10 PREC=0x00 TTL=110 ID=62521 DF PROTO=TCP SPT=2028 DPT=21 WINDOW=16384 RES=0x00 SYN URGP=0

    well the 196.168.2.34 is my sister's computer internal ip within the a router, does this mean my sister computer is pinging mine??

    and the other ip.. was that just an attempts.. or did he/she successfully got into my computer

    im using arno iptatbles script...

    monk

  2. #2
    Join Date
    Jul 2002
    Location
    Vladivostok, Russia
    Posts
    9,053
    IP 24.81.240.124 is "shawcable.net"....sound familiar?
    "I was pulled over for speeding today. The officer said, "Don't you know
    the speed limit is 55 miles an hour?" And I said, "Yes, but I wasn't going
    to be out that long."

    How To Ask Questions The Smart Way
    COME VISIT ME IN RUSSIA NOW!!

  3. #3
    Join Date
    Nov 2003
    Posts
    16
    i dont get it... im using comcast

    as another person pointed out to me.. it was trying to connect through ftp... i dont have any ftp services running.

    monk

  4. #4
    Join Date
    May 2004
    Posts
    128
    baldmonk,

    The first line means that your sister's computer (192.168.2.34) sent a broadcast message to your internal subnet on UDP port 137 (windows file sharing). That's no big deal.

    The next lines mean that a computer with the IP address of 24.81.240.124 attempted to connect to your computer on TCP port 21 (ftp). This most likely is someone scanning your computer. I get this stuff all the time on my computer also. I don't use the same script as you use, but from what I gather, those messages mean that your firewall is functioning properly. If you'd care to post the script you're using in this forum, I can get you more detailed info of exactly what "Connection attempt (PRIV)" actually means (it is kind of vague).

    Anyways, just know that people scanning you is normal. Sometimes I'll scan them back, and if they're running an SMTP server I'll kindly email them telling them to knock it off.

    Hope that helps.
    "Never ask the barber if you need a haircut."

    Things could be worse...

    YnJldHRfYnVydG9uXzgyQHlhaG9vLmNvbQ== (hidemyemail.net)

    Use the MUTT Mailreader!

  5. #5
    Join Date
    Nov 2003
    Posts
    16
    well i decided to stop using that script and installed shorewall.. now when i check my log, it's actually telling me what it is dropping.

    and to my surprise, i had port fowarding for port 21 on my router the whole time.

  6. #6
    Join Date
    Jan 2001
    Location
    Worcester, MA
    Posts
    722
    You can could install LogWatch http://www2.logwatch.org:81/
    and it will send you emails, after it analizes your logs. I find it pretty helpful.

    -goon12

  7. #7
    Join Date
    Nov 2003
    Posts
    16
    cool.. i'll take a look into that

    thanks,

    monk

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •