This is bad.... Very bad....

This is bad.... Very bad....

Post by SUDD » Thu, 13 Jan 2000 04:00:00



I just checked my logs and found this:

Jan 11 19:31:43 C287853-A kernel: Packet log: output DENY eth0 PROTO=17
24.1.27.58:61607 24.112.64.15:69 L=43 S=0x00 I=45927 F=0x0000 T=127 (#53)
Jan 11 19:33:00 C287853-A kernel: Packet log: output DENY eth0 PROTO=17
24.1.27.58:61607 24.112.64.15:69 L=43 S=0x00 I=33640 F=0x0000 T=127 (#53)

The bad part is that the source IP address is mine!!!  At the time of these
log entries I was playing Quake 3.

Please tell me that there is a legitimate reason that my server was trying

 
 
 

This is bad.... Very bad....

Post by Jo » Thu, 13 Jan 2000 04:00:00




> I just checked my logs and found this:

> Jan 11 19:31:43 C287853-A kernel: Packet log: output DENY eth0 PROTO=17
> 24.1.27.58:61607 24.112.64.15:69 L=43 S=0x00 I=45927 F=0x0000 T=127 (#53)
> Jan 11 19:33:00 C287853-A kernel: Packet log: output DENY eth0 PROTO=17
> 24.1.27.58:61607 24.112.64.15:69 L=43 S=0x00 I=33640 F=0x0000 T=127 (#53)

> The bad part is that the source IP address is mine!!!  At the time of these
> log entries I was playing Quake 3.

> Please tell me that there is a legitimate reason that my server was trying


Have you browsed to that address?  It's a Q3 ranking site.  I
would say your Q3 is trying to log into that machine to upload
your player stats or something along those lines.  If so, this is
either built-in by ID Software or your copy was modified for the
purpose... worth asking ID about.

Jon

 
 
 

This is bad.... Very bad....

Post by Tim Hayne » Fri, 14 Jan 2000 04:00:00





> > I just checked my logs and found this:

> > Jan 11 19:31:43 C287853-A kernel: Packet log: output DENY eth0 PROTO=17
> > 24.1.27.58:61607 24.112.64.15:69 L=43 S=0x00 I=45927 F=0x0000 T=127 (#53)
> > Jan 11 19:33:00 C287853-A kernel: Packet log: output DENY eth0 PROTO=17
> > 24.1.27.58:61607 24.112.64.15:69 L=43 S=0x00 I=33640 F=0x0000 T=127 (#53)

> > The bad part is that the source IP address is mine!!!  At the time of these
> > log entries I was playing Quake 3.

> > Please tell me that there is a legitimate reason that my server was trying

> Have you browsed to that address?  It's a Q3 ranking site.  I
> would say your Q3 is trying to log into that machine to upload
> your player stats or something along those lines.  If so, this is
> either built-in by ID Software or your copy was modified for the
> purpose... worth asking ID about.

FWIW there was an article some time ago on http://slashdot.org/ about Q3
stuff "sending info back to iD" or whatever, which provoked a suitable
outcry from some quarters. Shouldn't be too hard to find...

of Usenet if they don't sort themselves out, aren't they? Be grateful it
was denied, then :)

~Tim
--
| Geek Code: GCS dpu s-:+ a-- C++++ UBLUAVHSC++++ P+++ L++ E--- W+++(--) N++
| w--- O- M-- V-- PS PGP++ t--- X+(-) b D+ G e++(*) h++(*) r--- y-
| The sun is melting over the hills,         | http://www.glutinous.custard.org

 
 
 

This is bad.... Very bad....

Post by Michael Mars » Fri, 14 Jan 2000 04:00:00



: of Usenet if they don't sort themselves out, aren't they? Be grateful it
: was denied, then :)

namespace Rant {




My question is:  Who the heck is peering with these idiots, and why?
Couldn't we get rid of this little slice of problem in one fell swoop?

Quote:}

--

"Time is an illusion.  Lunch time, doubly so." -- Ford Prefect
 
 
 

This is bad.... Very bad....

Post by Dave VanHor » Fri, 14 Jan 2000 04:00:00


Me too!

Quote:> My question is:  Who the heck is peering with these idiots, and why?
> Couldn't we get rid of this little slice of problem in one fell swoop?

I suggested that they implement a port scanner that customers could use to
check themselves. (rahter than having them do it) I know when I change
something, and that's when I need a re-scan. Also, it would be pretty
trivial to make it so that it only scans at the requesting address, and only

I think they may use this as an excuse to crack down on home networks, and

What's a home sysadmin to do? :)

 
 
 

This is bad.... Very bad....

Post by Stev » Fri, 14 Jan 2000 04:00:00



never found an explanation of who or what they are.





> Me too!

> > My question is:  Who the heck is peering with these idiots, and why?
> > Couldn't we get rid of this little slice of problem in one fell swoop?

> I suggested that they implement a port scanner that customers could use to
> check themselves. (rahter than having them do it) I know when I change
> something, and that's when I need a re-scan. Also, it would be pretty
> trivial to make it so that it only scans at the requesting address, and only

> I think they may use this as an excuse to crack down on home networks, and


> What's a home sysadmin to do? :)

 
 
 

This is bad.... Very bad....

Post by Dave VanHor » Fri, 14 Jan 2000 04:00:00



> never found an explanation of who or what they are.


were bought by adelphia, but it's all the same thing.
 
 
 

This is bad.... Very bad....

Post by Tim Hayne » Sat, 15 Jan 2000 04:00:00



> > My question is: Who the heck is peering with these idiots, and why?
> > Couldn't we get rid of this little slice of problem in one fell swoop?

> I suggested that they implement a port scanner that customers could use
> to check themselves. (rahter than having them do it) I know when I change
> something, and that's when I need a re-scan. Also, it would be pretty
> trivial to make it so that it only scans at the requesting address, and


Anyone for <http://www.hackerwhacker.com/>? :]

Quote:> What's a home sysadmin to do? :)

man ipchains ;)
Don't give out enough ports that nmap -O -sS will identify you as Linux of
any sort ;)

~Tim
--
| Geek Code: GCS dpu s-:+ a-- C++++ UBLUAVHSC++++ P+++ L++ E--- W+++(--) N++
| w--- O- M-- V-- PS PGP++ t--- X+(-) b D+ G e++(*) h++(*) r--- y-
| The sun is melting over the hills,         | http://www.glutinous.custard.org

 
 
 

This is bad.... Very bad....

Post by Dave VanHor » Sat, 15 Jan 2000 04:00:00


Quote:> > What's a home sysadmin to do? :)

> man ipchains ;)
> Don't give out enough ports that nmap -O -sS will identify you as Linux of
> any sort ;)

Won't help me at this point, I'm connecting through a W98SE box running
connection sharing.