"Source Route Failed", "LOGIN FAIL..", "Malformed response", and "Lame server" messages in /var/log

"Source Route Failed", "LOGIN FAIL..", "Malformed response", and "Lame server" messages in /var/log

Post by Terry Jon » Tue, 03 Sep 1996 04:00:00



I have been getting occasional messages in /var/log/messages that look
like this:

/var/log # grep 'Source Route Failed' messages
Sep  1 00:55:14 anis kernel: ICMP: 205.226.64.153: Source Route Failed.
Sep  1 23:52:20 anis kernel: ICMP: 200.246.129.101: Source Route Failed.
Sep  2 11:51:46 anis kernel: ICMP: 204.95.110.85: Source Route Failed.

The second last IP number above also turned up in this context:

Sep  1 23:47:37 anis login: 1 LOGIN FAILURE FROM 200.246.129.101, news^H
Sep  1 23:47:47 anis login: 2 LOGIN FAILURES FROM 200.246.129.101, guest

Should I be concerned?

Also, I installed BIND-4.9.4-P1 and have been getting messages like this:

Sep  1 01:03:05 anis named[7455]: Malformed response from [199.2.252.10].53 (dn_expand failed in query)
Sep  1 01:03:13 anis named[7455]: Malformed response from [204.97.212.10].53 (dn_expand failed in query)

Is this a problem of mine, or theirs? What do these mean?

Finally, the new version of BIND has been occasionally saying things like this:

Sep  1 01:25:52 anis named[7455]: Lame server on 'www-city.europeonline.com' (in 'EUROPEONLINE.com'?): [199.2.252.10].53 'NS2.SPRINTLINK.NET': learnt (A=204.117.214.10,NS=192.33.4.12)

Which I guess means something went wrong and it's learning its way
around the problem?

Thanks for any help,

 
 
 

"Source Route Failed", "LOGIN FAIL..", "Malformed response", and "Lame server" messages in /var/log

Post by B.A.McCau.. » Tue, 03 Sep 1996 04:00:00



>I have been getting occasional messages in /var/log/messages that look
>like this:

>/var/log # grep 'Source Route Failed' messages
>Sep  1 00:55:14 anis kernel: ICMP: 205.226.64.153: Source Route Failed.
>Sep  1 23:52:20 anis kernel: ICMP: 200.246.129.101: Source Route Failed.
>Sep  2 11:51:46 anis kernel: ICMP: 204.95.110.85: Source Route Failed.

>The second last IP number above also turned up in this context:

>Sep  1 23:47:37 anis login: 1 LOGIN FAILURE FROM 200.246.129.101, news^H
>Sep  1 23:47:47 anis login: 2 LOGIN FAILURES FROM 200.246.129.101, guest

>Should I be concerned?

Yes, it would appear someone is attempting to break into your system.

--

 .  _\\__[oo       from       | Phones: +44 121 471 3789 (home)

.  l___\\    /~~) /~~[  /   [ | PGP-fp: D7 03 2A 4B D8 3A 05 37...
 # ll  l\\  ~~~~ ~   ~ ~    ~ | http://wcl-l.bham.ac.uk/~bam/


 
 
 

"Source Route Failed", "LOGIN FAIL..", "Malformed response", and "Lame server" messages in /var/log

Post by Marcus Fau » Thu, 05 Sep 1996 04:00:00


: I have been getting occasional messages in /var/log/messages that look
: like this:
: /var/log # grep 'Source Route Failed' messages
: Sep  1 00:55:14 anis kernel: ICMP: 205.226.64.153: Source Route Failed.
: Sep  1 23:52:20 anis kernel: ICMP: 200.246.129.101: Source Route Failed.
: Sep  2 11:51:46 anis kernel: ICMP: 204.95.110.85: Source Route Failed.

: The second last IP number above also turned up in this context:
: Sep  1 23:47:37 anis login: 1 LOGIN FAILURE FROM 200.246.129.101, news^H
: Sep  1 23:47:47 anis login: 2 LOGIN FAILURES FROM 200.246.129.101, guest
: Should I be concerned?
This could mean somebody tried to break into Your system. You should be
concerned.

: Also, I installed BIND-4.9.4-P1 and have been getting messages like this:
: Sep  1 01:03:05 anis named[7455]: Malformed response from [199.2.252.10].53 (dn_expand failed in query)
: Sep  1 01:03:13 anis named[7455]: Malformed response from [204.97.212.10].53 (dn_expand failed in query)
: Is this a problem of mine, or theirs? What do these mean?
Probably not Your problem. You should not worry about that

: Finally, the new version of BIND has been occasionally saying things like this:
: Sep  1 01:25:52 anis named[7455]: Lame server on 'www-city.europeonline.com' (in 'EUROPEONLINE.com'?): [199.2.252.10].53 'NS2.SPRINTLINK.NET': learnt (A=204.117.214.10,NS=192.33.4.12)
You shouldn't see these any longer since europeonline died 2 weeks ago.

: Thanks for any help,

Doc Holiday

------------------------------------------------------------
| MS-DOS: Malformed System - (D)elete (O)verwrite (S)cream |
------------------------------------------------------------