hosted by liquidweb


Go Back   Web Hosting Talk : Web Hosting Main Forums : Hosting Security and Technology : Wht are these iptables logs have to do with hang up?
Reply

Hosting Security and Technology Configuring and optimizing web hosting servers and operating systems, developing administration scripts, building servers, protecting against hackers, and general security (SSL certificates, etc.)
Forum Jump

Wht are these iptables logs have to do with hang up?

Reply Post New Thread In Hosting Security and Technology Subscription
 
Send news tip View All Posts Thread Tools Search this Thread Display Modes
  #1  
Old 07-26-2005, 03:55 AM
atul atul is offline
Web Hosting Guru
 
Join Date: Apr 2004
Location: India
Posts: 292

Wht are these iptables logs have to do with hang up?


Hi Geeks,
My machine was hanged up in the morning...and lots of iptables logs were started pouring on screen...I was even unable to login..

The messages were something like that:
10.0.1.255 LEN=78 TOS=0x00 PREC=0x00 TTL=128 ID=22244 PROTO=UDP SPT=137 DPT=137 LEN=58
Jul 26 12:17:51 mail1 kernel: IPTABLES UDP-IN: IN=eth0 OUT= MAC=ff:ff:ff:ff:ff:ff:00:0d:61:2f:06:19:08:00 SRC=10.0.1.49 DST=10.0.1.255 LEN=78 TOS=0x00 PREC=0x00 TTL=128 ID=16750 PROTO=UDP SPT=137 DPT=137 LEN=58
Jul 26 12:17:51 mail1 kernel: IPTABLES UDP-IN: IN=eth0 OUT= MAC=ff:ff:ff:ff:ff:ff:00:0d:61:2b:b5:0b:08:00 SRC=10.0.1.111 DST=10.0.1.255 LEN=78 TOS=0x00 PREC=0x00 TTL=128 ID=19591 PROTO=UDP SPT=137 DPT=137 LEN=58
Jul 26 12:17:51 mail1 kernel: IPTABLES UDP-IN: IN=eth0 OUT= MAC=ff:ff:ff:ff:ff:ff:00:0d:61:2f:06:19:08:00 SRC=10.0.1.49 DST=10.0.1.255 LEN=78 TOS=0x00 PREC=0x00 TTL=128 ID=16757 PROTO=UDP SPT=137 DPT=137 LEN=58
Jul 26 12:17:51 mail1 kernel: IPTABLES UDP-IN: IN=eth0 OUT= MAC=ff:ff:ff:ff:ff:ff:00:11:11:2f:9b:44:08:00 SRC=10.0.1.71 DST=10.0.1.255 LEN=78 TOS=0x00 PREC=0x00 TTL=128 ID=49919 PROTO=UDP SPT=137 DPT=137 LEN=58

Can anyone tell me is it h/w issue or kernel..?
And if h/w is it with n/w card...?

Thanks..

__________________
thelinophile
Thinking Different !!

Reply With Quote


Sponsored Links
  #2  
Old 07-26-2005, 03:59 AM
atul atul is offline
Web Hosting Guru
 
Join Date: Apr 2004
Location: India
Posts: 292
Oh..
I forgot to give details:
It is Intel Xeon 4Processor...6GB RAM 350GB HD FC3 machine..
n/w card is of
Ethernet controller: Intel Corp. 82544GC Gigabit Ethernet Controller (LOM) (rev 02)

__________________
thelinophile
Thinking Different !!

Reply With Quote
  #3  
Old 07-26-2005, 04:09 AM
bijo bijo is offline
WHT Addict
 
Join Date: Jun 2005
Location: India
Posts: 123
Re: Wht are these iptables logs have to do with hang up?

Hello,

It seems that you have enabled apf on your box. I think, it is the normal apf log.
Let me know the status

With regards,
Bijo

Reply With Quote
Sponsored Links
  #4  
Old 07-26-2005, 05:01 AM
atul atul is offline
Web Hosting Guru
 
Join Date: Apr 2004
Location: India
Posts: 292
Hi,
No I don't use apf...
it is iptables only...

See the issue is that they start pouring on screen...and it hangs up..
I am not damm sure...about them ..they are haarmless...as it seems..
But whatis that SPT=137 and DST=137...

Why is it on 137...and why they start coming on screen..
Thanks...

__________________
thelinophile
Thinking Different !!

Reply With Quote
  #5  
Old 07-26-2005, 08:23 AM
bijo bijo is offline
WHT Addict
 
Join Date: Jun 2005
Location: India
Posts: 123
Re: Wht are these iptables logs have to do with hang up?

Quote:
Originally posted by atul
Hi Geeks,
My machine was hanged up in the morning...and lots of iptables logs were started pouring on screen...I was even unable to login..

The messages were something like that:
10.0.1.255 LEN=78 TOS=0x00 PREC=0x00 TTL=128 ID=22244 PROTO=UDP SPT=137 DPT=137 LEN=58
Jul 26 12:17:51 mail1 kernel: IPTABLES UDP-IN: IN=eth0 OUT= MAC=ff:ff:ff:ff:ff:ff:00:0d:61:2f:06:19:08:00 SRC=10.0.1.49 DST=10.0.1.255 LEN=78 TOS=0x00 PREC=0x00 TTL=128 ID=16750 PROTO=UDP SPT=137 DPT=137 LEN=58


Can anyone tell me is it h/w issue or kernel..?
And if h/w is it with n/w card...?

Thanks..

Hello,

I think, you are running samba service. It is trying to register the netbios name server of a windows network.
SRC= source Ip [Your machine Ip]
DST= destination [It is a broad cast message]
Protocol= UDP
SPT=sourceport=137
DPT=Destination port=137

You can check it by stop the smb service on your box.
Let me know the status

With regards,
Bijo.

Reply With Quote
Reply

Related posts from TheWhir.com
Title Type Date Posted
Host1Plus Offers SmarterTools Email and Collaboration Services Web Hosting News 2012-06-08 15:06:38
SmarterTools Launches Cloud-based Help Desk SmarterTrack.com Web Hosting News 2011-10-11 19:55:47
Perimeter E-Security Launches SaaS-Based Log Management Solution Web Hosting News 2011-09-27 19:54:12
Indian Web Host ZNet Offers SmarterTools Products to Customers Web Hosting News 2011-07-12 19:58:10
FBI Questions Iowa Woman on LulzSec Involvement Web Hosting News 2011-06-29 19:46:20


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes
Postbit Selector

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off

Forum Jump
Login:
Log in with your username and password
Username:
Password:



Forgot Password?
Advertisement:
Web Hosting News:



 

X

Welcome to WebHostingTalk.com

Create your username to jump into the discussion!

WebHostingTalk.com is the largest, most influentual web hosting community on the Internet. Join us by filling in the form below.


(4 digit year)

Already a member?