> So the following would indicate a tracert being performed on my
> system? 2000/01/15 22:43:26 GMT +1100: Blocking incoming ICMP:
> src=203.30.236.118, type 3.

Nyet, the dest unreaches would be outbound from your dialup if that were
the case. If you're concerned and/or it's a regular occurence, amp up the
logging with ipchains so you can see what's going on (aka log everything
in/out through ppp+).

> As I didn't send out any connection to this system, I find it odd that
> I would be getting these packets incoming.

In this case the host is a router (well, it appears to be a tnt), you
probably had something going on (or were attempting to) with a host behind
it.

> > ICMP 3.x was also a favourite of people long ago in an attempt to 
> > cause your conection to somewhere (particularly IRC) to be closed. 
> > They would send a destination unreachable to either you or the

You'd know if this were happening. Unless the attacker can snoop either
end of the connection or you're some sort of vanilla-slackware-install
Johnny running netstat out of inetd, you'll see ~65k (or 65k^2 in some
cases) unreaches when someone tries that.

-- adm

--
SLUG - Sydney Linux Users Group Mailing List - http://www.slug.org.au
To unsubscribe send email to [EMAIL PROTECTED] with
unsubscribe in the text

Reply via email to