Skip site navigation (1)Skip section navigation (2)
Date:      Mon, 7 Jan 2002 14:36:11 -0200 (BRST)
From:      Paulo Fragoso <paulo@nlink.com.br>
To:        <freebsd-security@freebsd.org>
Subject:   LAST_ACK traffic?
Message-ID:  <20020107141924.C55391-100000@mirage.nlink.com.br>

next in thread | raw e-mail | index | archive | help
Hi,

In our network there are some workstation under a firewall, today we ware
looking our internal traffic, there was one workstation sending packets
to one webserver at 200kbps:

roto Recv-Q Send-Q  Local Address          Foreign Address        (state)
tcp4       0      0  our.work.station.1412    200.226.137.10.80     LAST_ACK

The user that workstation was using Opera 6.0 for linux (on FreeBSD
4.4-RELEASE). The strange traffic had started after the he closed the
opera.

Are there any secure problem with this? Why our workstation was send
packets of LAST_ACK whithout any processes bound at 1412 (checked with
lsof)?

Many Thanks,
Paulo Fragoso.

-- 
   __O
 _-\<,_     Why drive when you can bike?
(_)/ (_)



To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-security" in the body of the message




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?20020107141924.C55391-100000>