Firewall Wizards mailing list archives

RE: fragmented packet from res6.geocities.com?


From: Karl Greenwood <Karl () pt-services co uk>
Date: Tue, 25 Apr 2000 09:33:03 +0100

Does the following connection attempt sound familiar to anyone:

Apr 20 14:47:57 fw /kernel: ipfw: 9100 Deny TCP 209.1.224.16 
12.38.161.54 in  
via fxp0 Fragment = 147
Apr 20 14:48:21 fw last message repeated 9 times
Apr 20 14:50:26 fw last message repeated 33 times
Apr 20 14:55:40 fw last message repeated 11 times


yep, get the same thing once in a while, i have been wondering what this
was???

4/20/00, 18:40:00, 209.1.224.16,Tcp, 165, 38320, FIN SYN RST , Frag, 
4/20/00, 18:40:02,Tcp, 165, 38320, FIN SYN RST , Frag, 
4/20/00, 18:40:05,Tcp, 50978, 28056, FIN SYN PSH ACK URG , Frag, 
4/20/00, 18:40:07,Tcp, 50978, 28056, FIN SYN PSH ACK URG , Frag, 
4/20/00, 18:40:08,Tcp, 165, 38320, FIN SYN RST , Frag, 
4/20/00, 18:40:11,Tcp, 50978, 28056, FIN SYN PSH ACK URG , Frag, 
4/20/00, 18:40:17,Tcp, 165, 38320, FIN SYN RST , Frag, 
4/20/00, 18:40:18,Tcp, 50978, 28056, FIN SYN PSH ACK URG , Frag, 
4/20/00, 18:40:34,Tcp, 50978, 28056, FIN SYN PSH ACK URG , Frag, 
4/20/00, 18:40:39,Tcp, 165, 38320, FIN SYN RST , Frag, 
4/20/00, 18:41:06,Tcp, 50978, 28056, FIN SYN PSH ACK URG , Frag, 
4/20/00, 18:41:22,Tcp, 165, 38320, FIN SYN RST , Frag, 
4/20/00, 18:42:28,Tcp, 41460, 34586, FIN SYN RST PSH ACK URG , Frag, 
4/20/00, 18:42:29,Tcp, 41460, 34586, FIN SYN RST PSH ACK URG , Frag, 
4/20/00, 18:42:33,Tcp, 41460, 34586, FIN SYN RST PSH ACK URG , Frag, 
4/20/00, 18:42:38,Tcp, 41460, 34586, FIN SYN RST PSH ACK URG , Frag, 
4/20/00, 18:42:50,Tcp, 41460, 34586, FIN SYN RST PSH ACK URG , Frag, 
4/20/00, 18:43:13,Tcp, 41460, 34586, FIN SYN RST PSH ACK URG , Frag, 
4/20/00, 18:43:59,Tcp, 41460, 34586, FIN SYN RST PSH ACK URG , Frag, 



Current thread: