Great Circle Associates Firewalls
(August 1997)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Strange IP filter logs...
From: Michael Finken <finken @ nentec . de>
Organization: Maniac Coffee Drinkers
Date: Mon, 18 Aug 1997 20:52:11 +0200 (MET DST)
To: firewalls @ GreatCircle . COM

Hi,

We have several Windows NT machines (3.51 SP5 and 4.0SP3) in our network. Most
of them have mounted filesystems exported from Unix machines using Samba.

I find lots of strange entries in the filter logs of our internet router:

153.92.5.253: UDP packet from 153.92.64.34 to 81.226.0.0 port 138 filtered!
153.92.5.253: UDP packet from 153.92.64.34 to 95.10.0.0 port 138 filtered!
153.92.5.253: UDP packet from 153.92.64.34 to 77.229.0.0 port 138 filtered!
153.92.5.253: UDP packet from 153.92.64.34 to 67.114.0.0 port 138 filtered!
153.92.5.253: UDP packet from 153.92.64.34 to 70.5.0.0 port 138 filtered!


It seems the packet destinations are more or less random.  Has anybody else
seen this strange phenomenon?  

Michael

--
Michael Finken                                NENTEC Netzwerktechnologie GmbH
Tel.:  +49 721 9495-0                         76227 Karlsruhe/Germany
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Very funny, Scotty.  Now beam down my clothes.


Follow-Ups:
Indexed By Date Previous: Re: Firewalls-Digest V6 #395
From: Jerald Josephs <Jerald . Josephs @ Ebay . Sun . COM>
Next: somewhat off topic: encryption
From: "k. frisco" <kfrisco @ shrike . depaul . edu>
Indexed By Thread Previous: RE: Firewalls-Digest V6 #395
From: "Paquette, Trevor" <TrevorPaquette @ mcc . net>
Next: Re: Strange IP filter logs...
From: Cuauhtemoc Zamudio Avila <cuauhtemoc @ usa . net>

Google
 
Search Internet Search www.greatcircle.com