LinuxQuestions.org
Visit Jeremy's Blog.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 04-12-2001, 01:18 AM   #1
MrGreg
Member
 
Registered: Apr 2001
Location: Hamilton
Distribution: RedHat 7.2, 9.0
Posts: 52

Rep: Reputation: 15

I was wondering if this kind of firewall activity could be
considered Hostile/Suspicious?

59, 2001-04-12 04:05:30, 2000301, TCP port scan, 66.20.83.34, adsl-20-83-34.lft.bellsouth.net, 216.209.113.158,<=me, port=1243|6711-6713|6776|27300|27310|27374|275736711-6713&name=Sub_7_2|Sub_7, 78, A

59, 2001-04-12 06:14:05, 2003104, Proxy port probe, 24.200.199.28, modemcable028.199-200-24.que.mc.videotron.ca, 206.172.136.186,<=me, port=3128&reason=Firewalled, 6, A

If so, should this be reported to the network administrator?

farmer greg
 
Old 04-18-2001, 04:59 AM   #2
raz
Member
 
Registered: Apr 2001
Location: London
Posts: 408

Rep: Reputation: 31
What kind of logs are they ?
They look messy, anyway looks like two different people are doing a scan for backdoors that others may leave once hacked into a system.

I would just add a rule to Reject them, not Deny.
Then the go away quicker and don't take up as much bandwidth.

/Raz

I get about 5 - 10 attempt to attack my firewall a day, some I chase some I don't.
Most are just scripts looking for port 53 and the Bind bug.
 
Old 04-18-2001, 09:06 AM   #3
MrGreg
Member
 
Registered: Apr 2001
Location: Hamilton
Distribution: RedHat 7.2, 9.0
Posts: 52

Original Poster
Rep: Reputation: 15
MESSY LOG

It may be messy but it is complete => Completely Windows!

I should have the Linmodem up soon, Thanx.

farmer greg
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
ms-sql-m hits dareino Fedora 1 08-10-2005 04:57 AM
Why So Many Hits on port 25 Tonight ?!? opioid General 1 08-14-2004 02:18 AM
Stop Spyware before it hits... InEeDhElPlInUx Linux - General 5 06-08-2004 06:49 PM
Firestarter not logging hits? MrH0TT Linux - Security 3 11-04-2003 02:33 PM
Dual booting and performance hits mastahnke Linux - General 2 11-03-2002 05:19 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 07:03 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration