> So the following would indicate a tracert being performed on my
> system? 2000/01/15 22:43:26 GMT +1100: Blocking incoming ICMP:
> src=203.30.236.118, type 3.
Nyet, the dest unreaches would be outbound from your dialup if that were
the case. If you're concerned and/or it's a regular occurence, amp up the
logging with ipchains so you can see what's going on (aka log everything
in/out through ppp+).
> As I didn't send out any connection to this system, I find it odd that
> I would be getting these packets incoming.
In this case the host is a router (well, it appears to be a tnt), you
probably had something going on (or were attempting to) with a host behind
it.
> > ICMP 3.x was also a favourite of people long ago in an attempt to
> > cause your conection to somewhere (particularly IRC) to be closed.
> > They would send a destination unreachable to either you or the
You'd know if this were happening. Unless the attacker can snoop either
end of the connection or you're some sort of vanilla-slackware-install
Johnny running netstat out of inetd, you'll see ~65k (or 65k^2 in some
cases) unreaches when someone tries that.
-- adm
--
SLUG - Sydney Linux Users Group Mailing List - http://www.slug.org.au
To unsubscribe send email to [EMAIL PROTECTED] with
unsubscribe in the text