Re: Question...

[ Available lists | Index of freebsd-security | Month of Jul 1998 | Week of 13 Jul 1998 | Raw email | View thread | Wrap long lines | Reply | Tag ]
From
Robert Watson <robert@cyrus.watson.org>
Date
13 Jul 1998 16:58:43
Subject
Re: Question...
Message-ID
Pine.BSF.3.96.980713195634.8340D-100000@fledge.watson.org

In reply to

[ Hide this part ]
On Mon, 13 Jul 1998, Ludwig Pummer wrote:

> My guess is someone either a) has an incorrectly set firewall/proxy gateway
> system or b) is trying to hack/break your machine
> My guess is that it's b), since people who try to hack/break your machine
> try to hide who they are by spoofing their IP.

I have a number of machines attached to a private network with a reserved
address range in use -- I have ipfw set up to reject packets from that
address range coming from the exposed interfaces on the big bad internet.
I often see ipfw accounting entries from rejected packets that are
addressed to or from the reserved address range on the outside interfaces.
I've never caught any in a sniffer, but then, I have never tried.

I suggest everyone verify their ipfw/border router filters to make sure
they are rejecting appropriate ranges of addresses!

Robert N Watson

Carnegie Mellon University http://www.cmu.edu/
TIS Labs at Network Associates, Inc. http://www.tis.com/
SafePort Network Services http://www.safeport.com/
robert@fledge.watson.org http://www.watson.org/~robert/


To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe security" in the body of the message


Elapsed time: 0.079 seconds