Re: Port 18593 attacks
Michael Osten <lists-CQFAP1yJWv5Wk0Htik3J/[email protected]> Sat, 7 Aug 2004 23:32:09 -0500
| Newsgroups | gmane.org.user-groups.aclug.linux-help |
|---|---|
| Message-ID | <[email protected]> |
On Aug 7, 2004, at 8:46 PM, bbales wrote: >> My advice.. >> >> Make sure you machine is up to date with patches and don't worry about >> port scans, you'll lose too much sleep. >> > Probably pretty good advice. But it screws up the Frazierwall report=20 > as the > firewall can't seem to keep up with it. The log gets up to around=20 > 150KB and > drops the earliest hits. > > I shut the modem and firewall down for over 24 hours and switched the=20 > eth0 > board. Now I am no longer getting hits on TCP port 18395. They are=20 > UDP on > port 2849. 196 in the first 90 minutes. Quite obviously, something=20 > is going > on that I don't understand. > bruce > Well, is there any way to turn off reporting? So what happens if you=20 telnet to port 18395? or nmap the box? No one is coming in if there is=20 no door. I guess what I'm saying is that you are probably getting=20 false or overzealous reports from your firewall, and that they are=20 really nothing to lose sleep about. -- Attached file included as plaintext by Ecartis -- -- File: PGP.sig -- Desc: This is a digitally signed message part -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.2.4 (Darwin) iD8DBQFBFazJ+siimnI2HPURAm3kAJ4xpiC5ss0kdPrKwH7obrMsmmLePACfQm81 abNgAirU3vSF02RY/RnDwsQ=3D =3DhIgo -----END PGP SIGNATURE----- -- This is the [email protected] list. To unsubscribe, visit http://www.complete.org/cgi-bin/listargate-aclug.cgi