Great Circle Associates Firewalls
(February 1997)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: weird snoop log ?
From: Kim <cgkim @ rara . kotel . co . kr>
Date: Thu, 20 Feb 1997 12:35:50 +0900 (JST)
To: firewalls @ greatcircle . com

I have some strange output like this.
root> snoop from mysystem icmp
Using device /dev/le (promiscuous mode)
      mysystem -> NS.SESQUI.NET ICMP Destination unreachable (Bad port)
      mysystem -> ns.geocities.com ICMP Destination unreachable (Bad port)
      mysystem -> 198.6.1.1    ICMP Destination unreachable (Bad port)
      mysystem -> shell2.ba.best.com ICMP Destination unreachable (Bad port)
      mysystem -> 206.79.240.10 ICMP Destination unreachable (Bad port)
      mysystem -> 198.70.64.210 ICMP Destination unreachable (Bad port)
      mysystem -> inquiry1.card.com ICMP Destination unreachable (Bad port)
      mysystem -> 205.217.237.6 ICMP Destination unreachable (Bad port)
      mysystem -> 193.124.5.37 ICMP Destination unreachable (Bad port)

At first I thought someone was scanning but I couldn'find anything.
My system's running web server so does this related to web surging ?
-Kim.

Indexed By Date Previous: Re: Spoof 127.0.0.1 AND get a response. Possible?
From: Ron DuFresne <dufresne @ parka . winternet . com>
Next: Re: ACE/SecurID and the Big Agenda
From: Vin McLellan <vin @ shore . net>
Indexed By Thread Previous: weird snoop log ?
From: Kim <cgkim @ rara . kotel . co . kr>
Next: Firewall desactivation
From: David Amigo <damigo @ interaccess . cl>

Google
 
Search Internet Search www.greatcircle.com