Is the 10.82.43.130 address from your internal network, and the 
202... on the external side?

> From:          "qiu cheng" <[EMAIL PROTECTED]>
> To:            [EMAIL PROTECTED]
> Subject:       [Masq]  security alarm
> Date:          Wed, 19 May 1999 04:46:36 PDT

> 
> The following is some lines in my messages file logged by ipchains:
> 
> May 17 18:47:43 firewall kernel: Packet log: input REJECT eth1 PROTO=6 
> 10.82.43.130:80 202.106.75.97:62290 L=678 S=0x00 I=5553 F=0x4000 T=118
> May 17 18:47:43 firewall kernel: Packet log: output ACCEPT eth0 PROTO=1 
> 202.106.75.97:3 10.82.43.130:3 L=576 S=0xC0 I=8673 F=0x0000 T=255
> May 17 18:47:43 firewall kernel: Packet log: input REJECT eth1 PROTO=6 
> 10.82.43.130:80 202.106.75.97:62311 L=40 S=0x00 I=5809 F=0x4000 T=118
> May 17 18:47:43 firewall kernel: Packet log: output ACCEPT eth0 PROTO=1 
> 202.106.75.97:3 10.82.43.130:3 L=88 S=0xC0 I=8674 F=0x0000 T=255
> May 17 18:47:43 firewall kernel: Packet log: input REJECT eth1 PROTO=6 
> 10.82.43.130:80 202.106.75.97:62311 L=44 S=0x00 I=6065 F=0x4000 T=118
> May 17 18:47:43 firewall kernel: Packet log: output ACCEPT eth0 PROTO=1 
> 202.106.75.97:3 10.82.43.130:3 L=92 S=0xC0 I=8675 F=0x0000 T=255
> 
> eth0 is my internal interface, and eth1 is my external interface, I use ip 
> masq to let internal machines get out.
> 
> I don't know why my external interface capture an 10.82.43.130?
> I'm not sure it is an attact. And the output chain let 202.106.75.97:3 -> 
> 10.82.43.130:3 pass, is this a security hole?
> 
> I'm very worry about that! Please give a hand.
> 
> qiucheng
> 
> 
> 
> 
> _______________________________________________
> Masq maillist  -  [EMAIL PROTECTED]
> http://tiffany.indyramp.com/mailman/listinfo/masq
> Admin requests can be handled by web (above) or [EMAIL PROTECTED]
> 
 


_______________________________________________
Masq maillist  -  [EMAIL PROTECTED]
http://tiffany.indyramp.com/mailman/listinfo/masq
Admin requests can be handled by web (above) or [EMAIL PROTECTED]

Reply via email to