[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Re: strange Shorewall entry



apologies, forwarding to list

Note: forwarded message attached.


jwlockhart

Registered Linux User #458799
Registered Kubuntu User #19678
this user is penguin powered


      ____________________________________________________________________________________
Never miss a thing.  Make Yahoo your home page. 
http://www.yahoo.com/r/hs
--- Begin Message ---
--- "Douglas A. Tutty" <dtutty@porchlight.ca> wrote:

> Hello all,
> 
> I found this in my log today:
> 
> Jan  3 21:58:05 titan kernel:
> Shorewall:fw2net:REJECT:
> 	IN= OUT=ppp0 SRC=209.29.44.23 DST=16.100.185.144 
> 	LEN=60 TOS=0x00 PREC=0x00 TTL=64 ID=27582 DF 
> 	PROTO=TCP SPT=38111 DPT=8030 WINDOW=5840 RES=0x00
> SYN URGP=0 
> Jan  3 21:58:05 titan kernel:
> Shorewall:fw2net:REJECT:
> 	IN= OUT=ppp0 SRC=209.29.44.23 DST=16.100.184.142 
> 	LEN=60 TOS=0x00 PREC=0x00 TTL=64 ID=27569 DF 
> 	PROTO=TCP SPT=47263 DPT=8030 WINDOW=5840 RES=0x00
> SYN URGP=0 
> 
> I have shorewall reject anything going out via a
> port I haven't opened.
> Neither source nor destination ports are in
> /etc/services and I haven't
> seen these before.
> 
> My concern is that they come from my box (fw) and
> attempt to go out to
> the net.  This implies that something on my box is
> corrupted.  Any
> ideas?  At the time of this entry, my box was
> running Konqueror (via ssh
> from the other box) and was downloading information
> on HP DDS tapes from
> the HP website.  It also had open tabs to wikipedia
> and perhaps a google
> search results page.
> 
> The box is an AMD Athlon64 running Etch amd64
> up-to-date as of
> yesterday.
> 
> Just in case, I have my backup from December 22 on
> another box.  I'm
> running a new backup on the affected box (my main
> box) now.
> 
> Any ideas?  Thanks, 
> 
> Doug.
> 
> 
[snip syslog]

make sure destinaton port 8030 is allowed, seems to be
a know problem (though i don't run shorewall) see
http://www.mail-archive.com/shorewall-users@lists.sourceforge.net/msg02749.html
for a similar error message. this is all i could find
on the mighty google but it may be a place to start


jwlockhart

Registered Linux User #458799
Registered Kubuntu User #19678
this user is penguin powered


      ____________________________________________________________________________________
Looking for last minute shopping deals?  
Find them fast with Yahoo! Search.  http://tools.search.yahoo.com/newsearch/category.php?category=shopping

--- End Message ---

Reply to: