/* HINT: Search archives @ http://www.indyramp.com/masq/ before posting! 
/* ALSO: Don't quote this header. It makes you look lame :-) */


Jake Colman wrote:

> I have a pretty robust ipchains firewall set up via TrinityOS.  I am seeing
> many rejection messages on my external interface for strange ports.  For
> example,
> 
> Dec 20 00:12:10 firewall kernel: Packet log: input REJECT eth1 PROTO=6
> 24.190.9.93:1169 24.191.246.159:27374 L=48 S=0x00 I=62197 F=0x4000 T=123 SYN
> (#77) 
> 
> What is port 1169 and why is it probing my port 27374?  Should I be concerned
> about this kind of crap?  Should I stop logging it?

port 1169 is just the src port. it has no significance here.
port 27374 is part of the subseven trojan.

you can stop logging it if you want just don't stop blocking it :)

raf

_______________________________________________
Masq maillist  -  [EMAIL PROTECTED]
Admin requests can be handled at http://www.indyramp.com/masq-list/ -- 
THIS INCLUDES UNSUBSCRIBING!
or email to [EMAIL PROTECTED]

PLEASE read the HOWTO and search the archives before posting.
You can start your search at http://www.indyramp.com/masq/
Please keep general linux/unix/pc/internet questions off the list.

Reply via email to