Re: icmp messages to spoofed address acceptedby -m conntrack --ctstate ESTABLISHED,RELATED

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



On Friday 19 March 2004 8:41 pm, Jim Laurino wrote:

> On 2004.03.18 17:35, Jim Laurino  - nfcan.x.jimlaur@xxxxxxxx wrote:

> > I added a rule with this matching pattern to
> > the iptables firewall on my machine.
> >
> > -m conntrack --ctstate ESTABLISHED,RELATED
> >
> > It is matching icmp packets about an
> > unreachable destination that are sent here
> > because someone is spoofing my IP address.

On Thursday 18 March 2004 10:53 pm, Antony Stone wrote:

> I agree with this latter explanation.
>
> http://isc.incidents.org/port_details.html?port=1026
> http://www.mynetwatchman.com/kb/security/articles/popupspam
> http://www.lurhq.com/popup_spam.html

Regards,

Antony.

-- 
In Heaven, the police are British, the chefs are Italian, the beer is Belgian, 
the mechanics are German, the lovers are French, the entertainment is 
American, and everything is organised by the Swiss.

In Hell, the police are German, the chefs are British, the beer is American, 
the mechanics are French, the lovers are Swiss, the entertainment is Belgian, 
and everything is organised by the Italians.

                                                     Please reply to the list;
                                                           please don't CC me.



[Index of Archives]     [Linux Netfilter Development]     [Linux Kernel Networking Development]     [Netem]     [Berkeley Packet Filter]     [Linux Kernel Development]     [Advanced Routing & Traffice Control]     [Bugtraq]

  Powered by Linux