[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: firewall log messages



On Thu, Apr 19, 2001 at 03:21:14PM -0500, John Patton wrote:
> Whoops... what was I thinking??? udp port 513 is the who
> service, which could conceivably be used for malicious
> purposes. None-the-less, silently denying messages not
> intended for you will still solve that part of the problem.

Well, except for the fact that the message *originated* from him.  I
suspect he installed rwhod without realizing (or is it rstatd?  I don't
remember, having purged them long ago).  I almost made the same mistake
that you did, not realizing at first that the packets originated on his
machine.  Had that not been the case then ignoring the packets
completely would make the most sense.

noah

-- 
 _______________________________________________________
| Web: http://web.morgul.net/~frodo/
| PGP Public Key: http://web.morgul.net/~frodo/mail.html 

Attachment: pgpM8e9PW8a6c.pgp
Description: PGP signature


Reply to: