[CLUE-Tech] Netfilter Log Message

Kevin Fenzi kevin at scrye.com
Thu Aug 9 11:05:51 MDT 2001


>>>>> "Jeremiah" == Jeremiah Stanley <miah at miah.org> writes:

Jeremiah> Can anyone decrypt this for me? :) Aug 9 10:31:36 larry
Jeremiah> kernel: Netfilter: IN=eth1 OUT=
Jeremiah> MAC=00:a0:cc:d0:d1:ef:00:30:80:23:6d:8c:08:00
Jeremiah> SRC=24.178.31.64 DST=24.178.96.233 LEN=48 TOS=0x00 PREC=0x00
Jeremiah> TTL=119 ID=42185 DF PROTO=TCP SPT=4135 DPT=80 WINDOW=16384
Jeremiah> RES=0x00 SYN URGP=0

Jeremiah> This is a log message that I'm getting about once every
Jeremiah> thirty or so seconds from what seems random @Home
Jeremiah> machines...

more than likely it's everyone's favorate worm... code red 2 ;) 

@home is supposedly hit pretty hard by it...lots of infected machines,
and they tend to want to probe things in their local net more often
than not. 

kevin
-- 
Kevin Fenzi
MTS, tummy.com, ltd.
http://www.tummy.com/  KRUD - Kevin's Red Hat Uber Distribution



More information about the clue-tech mailing list