Security Incidents mailing list archives

Re: strange entrys in /var/log/messages


From: lwcashd () BIW COM (Larry W. Cashdollar)
Date: Wed, 12 Jan 2000 15:19:42 -0500


Are you running dhcp or bootp on the machine in question?  This would be the
cause.


Dec 10 09:44:41 myhostname kernel: IP fw-in deny eth0 UDP 0.0.0.0:68
255.255.255.255:67 L=328 S=0x00 I=3075 F=0x0000 T=128
Dec 10 09:44:47 myhostname kernel: IP fw-in deny eth0 UDP 0.0.0.0:68
255.255.255.255:67 L=328 S=0x00 I=3331 F=0x0000 T=128
Dec 10 09:44:53 myhostname kernel: IP fw-in deny eth0 UDP 0.0.0.0:68
255.255.255.255:67 L=328 S=0x00 I=3587 F=0x0000 T=128
Dec 10 09:44:59 myhostname kernel: IP fw-in deny eth0 UDP 0.0.0.0:68
255.255.255.255:67 L=328 S=0x00 I=3843 F=0x0000 T=128
Dec 10 09:50:05 myhostname kernel: IP fw-in deny eth0 UDP 0.0.0.0:68
255.255.255.255:67 L=328 S=0x00 I=4099 F=0x0000 T=128
Dec 10 09:50:11 myhostname kernel: IP fw-in deny eth0 UDP 0.0.0.0:68
255.255.255.255:67 L=328 S=0x00 I=4355 F=0x0000 T=128
Dec 10 09:50:17 myhostname kernel: IP fw-in deny eth0 UDP 0.0.0.0:68
255.255.255.255:67 L=328 S=0x00 I=4611 F=0x0000 T=128
Dec 10 09:50:23 myhostname kernel: IP fw-in deny eth0 UDP 0.0.0.0:68
255.255.255.255:67 L=328 S=0x00 I=4867 F=0x0000 T=128
Dec 10 09:55:29 myhostname kernel: IP fw-in deny eth0 UDP 0.0.0.0:68
255.255.255.255:67 L=328 S=0x00 I=5123 F=0x0000 T=128
Dec 10 09:55:35 myhostname kernel: IP fw-in deny eth0 UDP 0.0.0.0:68
255.255.255.255:67 L=328 S=0x00 I=5379 F=0x0000 T=128
Dec 10 09:55:41 myhostname kernel: IP fw-in deny eth0 UDP 0.0.0.0:68
255.255.255.255:67 L=328 S=0x00 I=5635 F=0x0000 T=128
Dec 10 09:55:47 myhostname kernel: IP fw-in deny eth0 UDP 0.0.0.0:68
255.255.255.255:67 L=328 S=0x00 I=5891 F=0x0000 T=128


Current thread: