Hello,
I think some bastards scanned my server (running shorewall), which i found out
this morning when reading my logwatch mail. The scan sent over 100000
packages to all kind of different ports in my server over a short period of
time. Most of the ports are closed of course, except for the ones I have for
some services (HTTPD, Sendmail).
What I am wondering is, when this happens, in the kernel section of the
logwatch I got a bunch of error like below (this is just a tiny part of it).
This is the second time something like this happen, and each time I got
something similar with the following in the kernel section of my logwatch. I
am wondering if this has anything to do with the fact that shorewall was
getting a very heavy hit.
I am running RHEL 3.0, stock kernel with the latest update, and
shorewall-1.4.8-1. Should I worry about this?
Any help is greatly appreciated. Thanks in advance.
RDB
---- from the Kernel section in logwatch ----- :
Use of uninitialized value in left bitshift (<<) at
/etc/log.d/scripts/services/kernel line 102, <STDIN> line 89542.
Use of uninitialized value in left bitshift (<<) at
/etc/log.d/scripts/services/kernel line 102, <STDIN> line 89542.
Use of uninitialized value in bitwise or (|) at
/etc/log.d/scripts/services/kernel line 102, <STDIN> line 89542.
Use of uninitialized value in left bitshift (<<) at
/etc/log.d/scripts/services/kernel line 102, <STDIN> line 89542.
Use of uninitialized value in left bitshift (<<) at
/etc/log.d/scripts/services/kernel line 102, <STDIN> line 89542.
Use of uninitialized value in bitwise or (|) at
/etc/log.d/scripts/services/kernel line 102, <STDIN> line 89542.
....
and a lot more of that, then the following (notice the funny words after
"Argument")
Argument "eth0" isn''t numeric in numeric comparison
(<=>) at
/etc/log.d/scripts/services/kernel line 92, <STDIN> line 89542.
Argument "28558IN" isn''t numeric in numeric comparison
(<=>) at
/etc/log.d/scripts/services/kernel line 92, <STDIN> line 89542.
Argument "5827RGP" isn''t numeric in numeric comparison
(<=>) at
/etc/log.d/scripts/services/kernel line 92, <STDIN> line 89542.
Argument "4orewall" isn''t numeric in numeric comparison
(<=>) at
/etc/log.d/scripts/services/kernel line 92, <STDIN> line 89542.
Argument "44934OUT" isn''t numeric in numeric comparison
(<=>) at
/etc/log.d/scripts/services/kernel line 92, <STDIN> line 89542.
Argument "4URGP" isn''t numeric in numeric comparison
(<=>) at
/etc/log.d/scripts/services/kernel line 92, <STDIN> line 89542.
Argument "29th0" isn''t numeric in numeric comparison
(<=>) at
/etc/log.d/scripts/services/kernel line 92, <STDIN> line 89542.
Argument "4ROP" isn''t numeric in numeric comparison
(<=>) at
/etc/log.d/scripts/services/kernel line 92, <STDIN> line 89542.
Argument "624ewall" isn''t numeric in numeric comparison
(<=>) at
/etc/log.d/scripts/services/kernel line 92, <STDIN> line 89542.
Argument "4P" isn''t numeric in numeric comparison (<=>)
at
/etc/log.d/scripts/services/kernel line 92, <STDIN> line 89542.
Argument "URGP" isn''t numeric in numeric comparison
(<=>) at
/etc/log.d/scripts/services/kernel line 92, <STDIN> line 89542.
Argument "4RGP" isn''t numeric in numeric comparison
(<=>) at
/etc/log.d/scripts/services/kernel line 92, <STDIN> line 89542.
Argument "534rewall" isn''t numeric in numeric comparison
(<=>) at
/etc/log.d/scripts/services/kernel line 92, <STDIN> line 89542.
Argument "OP" isn''t numeric in numeric comparison (<=>)
at
/etc/log.d/scripts/services/kernel line 92, <STDIN> line 89542.
Argument "GP" isn''t numeric in numeric comparison (<=>)
at
/etc/log.d/scripts/services/kernel line 92, <STDIN> line 89542.
Argument "6279N" isn''t numeric in numeric comparison
(<=>) at
/etc/log.d/scripts/services/kernel line 92, <STDIN> line 89542.
Argument "syn" isn''t numeric in numeric comparison
(<=>) at
/etc/log.d/scripts/services/kernel line 92, <STDIN> line 89542.
Argument "51OUT" isn''t numeric in numeric comparison
(<=>) at
/etc/log.d/scripts/services/kernel line 92, <STDIN> line 89542.
--
Reuben D. Budiardja
Department of Physics and Astronomy
The University of Tennessee, Knoxville, TN
---------------------------------------------------------
"To be a nemesis, you have to actively try to destroy
something, don''t you? Really, I''m not out to destroy
Microsoft. That will just be a completely unintentional
side effect."
- Linus Torvalds -