Re: Port 18593 attacks

Michael Osten <lists-CQFAP1yJWv5Wk0Htik3J/[email protected]> Sat, 7 Aug 2004 23:32:09 -0500
Newsgroups gmane.org.user-groups.aclug.linux-help
Message-ID <[email protected]>
On Aug 7, 2004, at 8:46 PM, bbales wrote:

>> My advice..
>>
>> Make sure you machine is up to date with patches and don't worry about
>> port scans, you'll lose too much sleep.
>>
> Probably pretty good advice.  But it screws up the Frazierwall report=20
> as the
> firewall can't seem to keep up with it.  The log gets up to around=20
> 150KB and
> drops the earliest hits.
>
> I shut the modem and firewall down for over 24 hours and switched the=20
> eth0
> board.  Now I am no longer getting hits on TCP port 18395.  They are=20
> UDP on
> port 2849.  196 in the first 90 minutes.  Quite obviously, something=20
> is going
> on that I don't understand.
> bruce
>

Well, is there any way to turn off reporting?  So what happens if you=20
telnet to port 18395? or nmap the box?  No one is coming in if there is=20
no door.  I guess what I'm saying is that you are probably getting=20
false or overzealous  reports from your firewall, and that they are=20
really nothing to lose sleep about.


-- Attached file included as plaintext by Ecartis --
-- File: PGP.sig
-- Desc: This is a digitally signed message part

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.4 (Darwin)

iD8DBQFBFazJ+siimnI2HPURAm3kAJ4xpiC5ss0kdPrKwH7obrMsmmLePACfQm81
abNgAirU3vSF02RY/RnDwsQ=3D
=3DhIgo
-----END PGP SIGNATURE-----


-- This is the [email protected] list.  To unsubscribe,
visit http://www.complete.org/cgi-bin/listargate-aclug.cgi