[KLUG Members] Security and Firewalls

Adam Williams members@kalamazoolinux.org
Wed, 11 Feb 2004 09:05:12 -0500 (EST)


>Feb 11 07:20:11 localhost kernel: IN-interface1:IN=ppp0 OUT= MAC=
>SRC=212.202.14.30 DST=68.72.X.X LEN=60 TOS=0x00 PREC=0x00 TTL=42

Know who -
[admin-c]
Type:         PERSON
Name:         Christian Ebert
Address:      QSC AG
Address:      Mathias-Brueggen-Str. 55
City:         Koeln
Pcode:        50829
Country:      DE
Changed:      20020228 093428
Source:       DENIC
- is?

>ID=42346 DF PROTO=TCP SPT=3464 DPT=4662 WINDOW=5808 RES=0x00 SYN URGP=0

Niether 3464 or 4662 are commonly known service ports.  You have an IRC 
client or something running when this happens?