FIRE-WARS : Attack of the Cloaks

Discussion in 'QnA (read only)' started by klinux, Oct 29, 2004.

Thread Status:
Not open for further replies.
  1. klinux

    klinux New Member

    Joined:
    Sep 25, 2004
    Messages:
    625
    Likes Received:
    0
    Trophy Points:
    0
    got pccillin 2002 av with firewall . just noticed today in firewall log a couple of wierd entries . if someone can explain it it will help . i got hundreds of entries as the 2 given below per day . the list reads out like Star Wars opening scroll

    - Firewall,21:21:51,IN,TCP," filled with ip addresses and i think port number ",NetBIOS Browsing,
    - Cloaking,21:20:11,IN,UDP," filled with ip addresses and i think port number ",Cloaking,

    more weird part is i started getting these entries after i joined the digit forum . Any Clues as to what they are and what i should do to stop'em .
     
  2. technovice

    technovice New Member

    Joined:
    Sep 12, 2004
    Messages:
    98
    Likes Received:
    0
    Trophy Points:
    0
    Location:
    Utopia
    LOL!!
    Nice topic for the post

    SOS the Jedi Knights maybe!!!
    Maybe theyve got a engineering wing!!
    :lol:
     
  3. OP
    OP
    klinux

    klinux New Member

    Joined:
    Sep 25, 2004
    Messages:
    625
    Likes Received:
    0
    Trophy Points:
    0
    another day another attack !!

    Firewall,00:57:22,IN,UDP,ip address,port,ip address,port,Traceroute,

    can anyone decypher them ??
     
  4. GameAddict

    GameAddict New Member

    Joined:
    Apr 28, 2004
    Messages:
    265
    Likes Received:
    0
    Trophy Points:
    0
    Location:
    Hyderabad
    My guess...

    Hi klinux,

    Here is one of the entries:

    Firewall,00:57:22,IN,UDP,ip address,port,ip address,port,Traceroute,

    The second part- 00:57:22 -- seems to be the timestamp.
    IN-Connection Type (inbound)
    UDP-Protocol
    ip address-Your/ or the attacker's
    port-Your/or the attacker's

    The above fields depend upon the settings of the log file. I too wonder what's the realtion between joining the forums and getting the above entries ???

    Stumped about the last part-Traceroute???

    Bye!

    GA
     
Thread Status:
Not open for further replies.

Share This Page