> Date:          Sun, 16 Jan 2000 14:10:42 +1100 (EST)
> Subject:       Re: [SLUG] ICMP Type 3

> 
> > So the following would indicate a tracert being performed on my
> > system?
> > 2000/01/15 22:43:26 GMT +1100: Blocking incoming ICMP:
> > src=203.30.236.118, type 3.
> 
> Nyet, the dest unreaches would be outbound from your dialup if that
> were the case. If you're concerned and/or it's a regular occurence,
> amp up the logging with ipchains so you can see what's going on (aka
> log everything in/out through ppp+).

Already got full logging of all packets and connections through the
firewall.

> > As I didn't send out any connection to this system, I find it odd
> > that I would be getting these packets incoming.
> 
> In this case the host is a router (well, it appears to be a tnt),
> you probably had something going on (or were attempting to) with a
> host behind it.

 Let me put this in absolutely plain English. I had NOTHING running
that would have made such a connection. My ICQ doesn't have anyone
even close to that location, much less running through the network.
No outgoing packets were recorded for this connection (ALL incoming
and outgoing connections are logged) and these incoming ICMP packets
suddenly started arriving. Maybe I should point out that roughly 2
minutes before, another 8 packets arrived (ICMP Type 3) from an IP
in USA, and another 6 from an IP in Australia. About 5 minutes
afterward, 10 more packets were received, this time from Indonesia.
 At no time during this time was I running any service except for a
single NTP request sent to the 'local' university. No ICQ messages
arrived during this time, and no FTP or WEB accesses were made,
either in or out. No other programs were running that use the net.
 Does this give anyone some indication of what has been happening?
I'm getting rather annoyed at having unknown IP addresses send me
(in some cases) dozens of ICMP packets.

> > > ICMP 3.x was also a favourite of people long ago in an attempt to 
> > > cause your conection to somewhere (particularly IRC) to be closed. 
> > > They would send a destination unreachable to either you or the
> 
> You'd know if this were happening. Unless the attacker can snoop either
> end of the connection or you're some sort of vanilla-slackware-install
> Johnny running netstat out of inetd, you'll see ~65k (or 65k^2 in some
> cases) unreaches when someone tries that.

Haven't seen that at any stage, so that's not the cause then.

Aussie

Have you visited my homepage recently?
You may be missing out on all the latest FREE
Software, Themes, Screensavers and more!

Visit now at http://come.fast.to/aussie
--
SLUG - Sydney Linux Users Group Mailing List - http://www.slug.org.au
To unsubscribe send email to [EMAIL PROTECTED] with
unsubscribe in the text

Reply via email to