Skip site navigation (1)Skip section navigation (2)
Date:      Mon, 13 Jul 1998 10:48:16 -0700
From:      Ludwig Pummer <ludwigp@bigfoot.com>
To:        Alexander Kandelaki <stealth@sanet.ge>, freebsd-security@FreeBSD.ORG
Subject:   Re: Question...
Message-ID:  <3.0.3.32.19980713104816.03203d78@mail.plstn1.sfba.home.com>
In-Reply-To: <Pine.BSF.3.96.980713161709.6806A-100000@access.sanet.ge>

next in thread | previous in thread | raw e-mail | index | archive | help
At 04:24 PM 7/13/98 +0500, Alexander Kandelaki wrote:
>
>Hi all!
>
>Once I run netstat and received : 
>
>tcp        0      0  access.pop3   ppp170-tc3.1658 TIME_WAIT
>tcp        0     87  access.smtp   egeo.unipg.it.4930 ESTABLISHED
>tcp        0    169  access.smtp   ARMINCO.COM.51685  ESTABLISHED
>tcp        0      0  access.3314   192.168.1.2.smtp   SYN_SENT
>                                   ^^^^^^^^^^^^^^^^ 
>tcp        0      0  access.smtp   interfuture.com.3509 TIME_WAIT
>
>I haven't any proxy server installed on my system or something look like
>it. Strange why in my system i see this IP ? What is it ?

My guess is someone either a) has an incorrectly set firewall/proxy gateway
system or b) is trying to hack/break your machine
My guess is that it's b), since people who try to hack/break your machine
try to hide who they are by spoofing their IP.

--Ludwig Pummer
ludwigp@bigfoot.com
ICQ UIN: 692441   http://chipweb.home.ml.org

To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe security" in the body of the message



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?3.0.3.32.19980713104816.03203d78>