Mailinglist Archive: opensuse-security (757 mails)

< Previous Next >
Re: [suse-security] SuSEFirewall logs port 8 remote to port 0 local?
  • From: "Kurt Seifried" <listuser@xxxxxxxxxxxx>
  • Date: Mon, 14 Jan 2002 00:05:47 -0700
  • Message-id: <000b01c19cc9$e45c5360$6400030a@xxxxxxxxxxxx>
protocols list: /etc/protocols
proto 1 is icmp.
icmp codes list: http://www.seifried.org/security/ports/icmp.txt
0=echo-reply, 8=echo-request.


Kurt Seifried, kurt@xxxxxxxxxxxx
A15B BEE5 B391 B9AD B0EF
AEB0 AD63 0B4E AD56 E574
http://www.seifried.org/security/


----- Original Message -----
From: "Nick Webb" <nickw@xxxxxxxxxx>
To: <suse-security@xxxxxxxx>
Sent: Monday, January 14, 2002 12:00 AM
Subject: [suse-security] SuSEFirewall logs port 8 remote to port 0 local?


> Hi,
>
> Just a stupid, quick question. I checked my firewall logs from the past
few days, and all accepted traffic was familiar to me, accept for two IPs.
The log says it came from port 8 on the remote machine to port 0 on mine,
what kind of traffic is this? Anything to worry about?
>
> ====
> Jan 12 00:50:44 gizmo kernel: Packet log: input ACCEPT eth0 PROTO=1
xx.xx.xx.xx:8 xx.xx.xx.xx:0 L=64 S=0x00 I=39662 F=0x0000 T=111 (#8)
> Jan 12 00:50:44 gizmo kernel: Packet log: input ACCEPT eth0 PROTO=1
xx.xx.xx.xx:8 xx.xx.xx.xx:0 L=64 S=0x00 I=39663 F=0x0000 T=111 (#9)
>
> Jan 13 22:05:34 gizmo kernel: Packet log: input ACCEPT eth0 PROTO=1
xx.xx.xx.xx:8 xx.xx.xx.xx:0 L=64 S=0x00 I=30563 F=0x0000 T=113 (#8)
> Jan 13 22:05:34 gizmo kernel: Packet log: input ACCEPT eth0 PROTO=1
xx.xx.xx.xx:8 xx.xx.xx.xx:0 L=64 S=0x00 I=30819 F=0x0000 T=114 (#9)i
> ====
>
> Thanks for your help.
>
> --
> Nick Webb
> http://www.uidaho.edu/~nickw/
>
> --
> To unsubscribe, e-mail: suse-security-unsubscribe@xxxxxxxx
> For additional commands, e-mail: suse-security-help@xxxxxxxx
>


< Previous Next >
This Thread
References