Re: IPTABLES question in general
Patrick Benson <benson <at> chello.se>
2004-10-21 12:53:22 GMT
Shorewall Admin User wrote:
>
> Hello All,
>
> I have a question in regards to iptables in general, I have been getting these
> log messages for a while now, and I am trying to figure out why these are
> coming in, I know that I am dropping all packets from the net 2 dmz named
> service. My question is why would I get these all the time, they are from
> multiple different sites. Are they trying to do something to my host or is
> this a common occurance?
>
> -------- cut ----------
> Oct 20 23:16:17 iprouter kernel: Shorewall:net2dmz:DROP:IN=eth0 OUT=eth2 SRC=213.136.52.31
DST=xx.xx.xx.xx LEN=56 TOS=0x00 PREC=0x00 TTL=39 ID=37389 DF PROTO=UDP SPT=9166 DPT=53 LEN=36
> Oct 20 23:16:17 iprouter kernel: Shorewall:net2dmz:DROP:IN=eth0 OUT=eth2 SRC=213.136.52.31
DST=xx.xx.xx.xx LEN=56 TOS=0x00 PREC=0x00 TTL=39 ID=37403 DF PROTO=UDP SPT=55524 DPT=53 LEN=36
> Oct 20 23:16:18 iprouter kernel: Shorewall:net2dmz:DROP:IN=eth0 OUT=eth2 SRC=64.12.66.11
DST=xx.xx.xx.xx LEN=56 TOS=0x00 PREC=0x00 TTL=45 ID=0 DF PROTO=UDP SPT=9253 DPT=53 LEN=36
It's still quite a nuisance. They started to show up at about the
beginning of 2001, actually. Several people started to notice this on
the LEAF-LRP lists and then appeared promptly on the Incidents list at
Securityfocus.com and Usenet. When a pop-up ad appeared, showing a cam,
in a web browser, it triggered a load of DROP, DENY messages in the
logs, non-SYN packets destined to port 53 on users' machines, like your
own. You can see a brief detailed explanation below, with the
coyotepoint.com link. It's a way of getting the end user to see the ad
at its closest location rather than circumventing the globe to reach a
very remote host, hosting the same ad, wasting bandwidth resources.
Unfortunately, www.geocrawler.com seems to be down for the moment, where
(Continue reading)