Chris Joyce wrote:
can anyone tell me what the following means ?

validated probe(132.246.80.45:25534, 203.35.218.70:111, -1551270949)
validated probe(132.246.80.45:25534, 203.35.218.70:111, -1551270949)
validated probe(132.246.80.45:6320, 203.35.218.70:111, 711727143)

This means you have compiled TCP Syn Cookies into your kernel, and that your system belived at the time that it was being synflooded - Ie: It was receiving a lot of connection requests in a reletively short amount of time and begin trying to validate them by returning a cookie to the connector in step 2 of the 3-way handshake. This doesn't necessarilly mean you were attacked; sometimes connectivity just sucks and it takes a few attempts (ie, a few syn packets) for the initiator to get thru, and syncookies support will send out probes in an effort to protect you from what could be a possible attack. I have this problem with Big Brother because it has code that will preempt the connection and retry if it doesn't complete in 3 seconds. Of course, another thing to point out is that this is trafic going to your port-mapper from what appears to be someone not on your local network. Are you trying to share a disk via nfs?
 
-- 
Mike Ireton
Network Systems Manager
Broadlink Communications
 

Reply via email to