Skip site navigation (1)Skip section navigation (2)
Date:      Fri, 19 Mar 1999 07:52:20 +0100
From:      "laurens van alphen" <alphen@craxx.com>
To:        "Steven Alexander" <steve@cell2000.net>
Cc:        <freebsd-security@freebsd.org>
Subject:   RE: unknown connection attempts from localhost
Message-ID:  <000501be71d5$08e30120$0a0010ac@ren.craxx.com>
In-Reply-To: <000801be7193$b5bf58e0$1502110a@matrice>

next in thread | previous in thread | raw e-mail | index | archive | help
mornin'

> It isn't sending UDP packets to random ports.  Your logs are showing that
a
> host was looked up from UDP port 1645/1739 and that yoru DNS replied to
> them.

my bad, of course there was a lookup from localhost from sourceport 1645 and
1739 first. but since there was clearly no one interested in the return
packets
(due to timeouts, whatever) i refered to them as 'random'. i will watch my
words 7from now on.

> The 'connection attempt' is used for a lack of a better term.  As UDP
> is connectionless, the replies from the DNS server show up as connection
> attempts.  This is standard behavior when using net.inet.*.log_in_vain=1

did i hear an echo ? ;-)

--
laurens van alphen, craxx
alphen@craxx.com, http://craxx.com



To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-security" in the body of the message




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?000501be71d5$08e30120$0a0010ac>