Security Incidents mailing list archives

strange entrys in /var/log/messages


From: benr () FRESHFOOD NET AU (Ben Russell)
Date: Wed, 12 Jan 2000 13:37:35 +1100


Hi,
I was reading my messages log today and came across these entrys...
the packet activity started on the 8th of december at 17:43... this first
round of packets lasted
about an hour... the packets seem to come in groups of four about every 5
minutes... sometimes 1 minute intervals..

I read /etc/services and it says that these are bootp client and server
ports but I have no bootp servers anywhere.

A second round of packets started at Dec 9, 13:40 and lasted until Dec 10,
09:55 ... the same pattern, groups of
4 at 5 minute intervals...

any feedback would be appreciated,

thanx,
br.

Dec 10 09:44:41 myhostname kernel: IP fw-in deny eth0 UDP 0.0.0.0:68
255.255.255.255:67 L=328 S=0x00 I=3075 F=0x0000 T=128
Dec 10 09:44:47 myhostname kernel: IP fw-in deny eth0 UDP 0.0.0.0:68
255.255.255.255:67 L=328 S=0x00 I=3331 F=0x0000 T=128
Dec 10 09:44:53 myhostname kernel: IP fw-in deny eth0 UDP 0.0.0.0:68
255.255.255.255:67 L=328 S=0x00 I=3587 F=0x0000 T=128
Dec 10 09:44:59 myhostname kernel: IP fw-in deny eth0 UDP 0.0.0.0:68
255.255.255.255:67 L=328 S=0x00 I=3843 F=0x0000 T=128
Dec 10 09:50:05 myhostname kernel: IP fw-in deny eth0 UDP 0.0.0.0:68
255.255.255.255:67 L=328 S=0x00 I=4099 F=0x0000 T=128
Dec 10 09:50:11 myhostname kernel: IP fw-in deny eth0 UDP 0.0.0.0:68
255.255.255.255:67 L=328 S=0x00 I=4355 F=0x0000 T=128
Dec 10 09:50:17 myhostname kernel: IP fw-in deny eth0 UDP 0.0.0.0:68
255.255.255.255:67 L=328 S=0x00 I=4611 F=0x0000 T=128
Dec 10 09:50:23 myhostname kernel: IP fw-in deny eth0 UDP 0.0.0.0:68
255.255.255.255:67 L=328 S=0x00 I=4867 F=0x0000 T=128
Dec 10 09:55:29 myhostname kernel: IP fw-in deny eth0 UDP 0.0.0.0:68
255.255.255.255:67 L=328 S=0x00 I=5123 F=0x0000 T=128
Dec 10 09:55:35 myhostname kernel: IP fw-in deny eth0 UDP 0.0.0.0:68
255.255.255.255:67 L=328 S=0x00 I=5379 F=0x0000 T=128
Dec 10 09:55:41 myhostname kernel: IP fw-in deny eth0 UDP 0.0.0.0:68
255.255.255.255:67 L=328 S=0x00 I=5635 F=0x0000 T=128
Dec 10 09:55:47 myhostname kernel: IP fw-in deny eth0 UDP 0.0.0.0:68
255.255.255.255:67 L=328 S=0x00 I=5891 F=0x0000 T=128


Current thread: