Michael C. Toren on 1 Aug 2004 21:29:02 -0000 |
On Sun, Aug 01, 2004 at 05:00:43PM -0400, eric@lucii.org wrote: > Aug 1 16:07:17 polaris kernel: denylog:IN=eth1 > OUT= MAC=NN:NN:NN:NN:NN:NN:00:01:5c:22:00:02:08:00 > SRC=68.111.197.211 DST=68.34.XXX.YYY LEN=48 TOS=0x00 > PREC=0x00 TTL=110 ID=10932 DF PROTO=TCP SPT=3811 > DPT=5554 WINDOW=64240 RES=0x00 SYN URGP=0 > > Where NN:NN:NN:NN:NN:NN is my external ethernet card's MAC address > and 68.34.XXX.YYY is the external ethernet card's IP address. Not to single you out, but generally speaking it would be very much appreciate when pasting log and configuration file snippets if they were pasted verbatim. In this particular case, half of the data you munged -- your IP address -- is easily obtainable simply by looking at the Received: lines of your post: Received: from lucii.dnsalias.org ([68.34.167.232]) by comcast.net (sccrmhc13) with SMTP -mct -- perl -e'$u="\4\5\6";sub H{8*($_[1]%79)+($_[0]%8)}sub G{vec$u,H(@_),1}sub S{vec ($n,H(@_),1)=$_[2]}$_=q^{P`clear`;for$iX){PG($iY)?"O":" "forX8);P"\n"}for$iX){ forX8){$c=scalar grep{G@$_}[$i-1Y-1Z-1YZ-1Y+1ZY-1ZY+1Z+1Y-1Z+1YZ+1Y+1];S$iY,G( $iY)?$c=~/[23]/?1:0:$c==3?1:0}}$u=$n;select$M,$C,$T,.2;redo}^;s/Z/],[\$i/g;s/Y /,\$_/xg;s/X/(0..7/g;s/P/print+/g;eval' # Michael C. Toren <mct@toren.net> ___________________________________________________________________________ Philadelphia Linux Users Group -- http://www.phillylinux.org Announcements - http://lists.phillylinux.org/mailman/listinfo/plug-announce General Discussion -- http://lists.phillylinux.org/mailman/listinfo/plug
|
|