Samba "Leak"

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



I cannot figure this out. Our server - running IPTables - has very few
ports open to input and the default is Drop. While a substantial number
of 139 and 445 packets show up in the log as rejected, I am seeing a few
attempts to connect to Samba in the log. These are identified by WAN IPs
so they are not spoofing localhost or a LAN IP.

I also have INVALID and fragmented packets rejected so that path is
closed.

So far, nobody has actually gained access, yet it is disconcerting. Any
ideas how these are getting past the firewall?

-- 
                            David Cary Hart
Hart's PGP key: http://pgp.mit.edu:11371/pks/lookup?op=get&search=0x58A60BB1



[Index of Archives]     [Linux Netfilter Development]     [Linux Kernel Networking Development]     [Netem]     [Berkeley Packet Filter]     [Linux Kernel Development]     [Advanced Routing & Traffice Control]     [Bugtraq]

  Powered by Linux