Good day! My proxy wrote about 200 of the below messages into /var/log/messages during the last days: Nov 15 09:34:08 proxy kernel: NET: 166 messages suppressed. Nov 15 09:34:08 proxy kernel: neighbour table overflow The number of suppressed messages is changing with every line. I am completely stuck with this. Does this mean, someone is trying to do a buffer overflow? P.S.: I am using SuSE 6.3 on this machine. Thank you very much in advance for your help! Rgds Dustin
Am Fri, 17 Nov 2000 15:50:21 schrieb Dustin Huptas: [...]
Nov 15 09:34:08 proxy kernel: NET: 166 messages suppressed. Nov 15 09:34:08 proxy kernel: neighbour table overflow [...]
Hi Dustin... I once had this one, too... It was caused by a wrong initialization of the loopback interface. What does "ifconfig lo" say? Does the loopback interface exist? Is it correctly bound to 127.0.0.1? It should look similar to this: # /sbin/ifconfig lo lo Linkverkapselung:Locale Schleife inet addr:127.0.0.1 Maske:255.0.0.0 UP LOOPBACK RUNNING MTU:3924 Metric:1 Maybe, this can help you... Best regard, Heiko -- Heiko Rother -- CM Systemhaus GmbH, Hannover, Abt. Online-Medien
Hi Heiko, the command line you send gives me the same information plus some extra info, so it seems to be a different problem. I am still stuck on this one! Greetings Dustin -----Ursprüngliche Nachricht----- Von: Heiko Rother [mailto:rother@cmsnet.de] Gesendet: Freitag, 17. November 2000 16:39 An: Dustin Huptas Cc: suse-security@suse.com Betreff: Re: [suse-security] NET Am Fri, 17 Nov 2000 15:50:21 schrieb Dustin Huptas: [...]
Nov 15 09:34:08 proxy kernel: NET: 166 messages suppressed. Nov 15 09:34:08 proxy kernel: neighbour table overflow [...]
Hi Dustin... I once had this one, too... It was caused by a wrong initialization of the loopback interface. What does "ifconfig lo" say? Does the loopback interface exist? Is it correctly bound to 127.0.0.1? It should look similar to this: # /sbin/ifconfig lo lo Linkverkapselung:Locale Schleife inet addr:127.0.0.1 Maske:255.0.0.0 UP LOOPBACK RUNNING MTU:3924 Metric:1 Maybe, this can help you... Best regard, Heiko -- Heiko Rother -- CM Systemhaus GmbH, Hannover, Abt. Online-Medien --------------------------------------------------------------------- To unsubscribe, e-mail: suse-security-unsubscribe@suse.com For additional commands, e-mail: suse-security-help@suse.com
Syslog made these entries. I cannot remember what the "neighbor table overflow" is, but its not a buffer overflow attempt. When something creates a large number of syslog entries syslog puts the entry "whatever: howmanytimes messages suppressed" so that your logs don't fill up with the same message over and over. By default Linux does not "Buffer Overflow" detection, and even the products like "libsafe" cannot be 100% guaranteed to log every attempt. -miah On Fri, Nov 17, 2000 at 03:50:21PM +0100, Dustin Huptas wrote:
Good day!
My proxy wrote about 200 of the below messages into /var/log/messages during the last days:
Nov 15 09:34:08 proxy kernel: NET: 166 messages suppressed. Nov 15 09:34:08 proxy kernel: neighbour table overflow
The number of suppressed messages is changing with every line. I am completely stuck with this. Does this mean, someone is trying to do a buffer overflow?
P.S.: I am using SuSE 6.3 on this machine.
Thank you very much in advance for your help!
Rgds Dustin
--------------------------------------------------------------------- To unsubscribe, e-mail: suse-security-unsubscribe@suse.com For additional commands, e-mail: suse-security-help@suse.com
participants (3)
-
Dustin Huptas
-
Heiko Rother
-
jjohnson@penguincomputing.com