| From | Subject | Date |
|---|---|---|
| packetfilter.1@gmail.com | SIP VoIP botnet question
Hi
Can someone shed some light on the following (pfSense) PF log entries;
36. 281054 rule 80/0(match): block in on ng0: (tos 0x0, ttl 45, id
51305, offset 0, flags [DF], proto UDP (17), length 437) 124.92.251.2.5060
> 91.84.205.47.5060: SIP, length: 409
...
| Sep 18, 2:29 pm 2010 |
| Imre Oolberg | Re: choosing outgoing interface based on process uid
Hi!
I try to describe my understanding out the situation more closely and
hope you can guide me further
1. since packets are generated locally packet filter match them only on
outgoing direction
2. locally generated packets are routed according to the default routing
table
3. using route-to ($if_ext $if_ext_gw) construct on the pass out rule i
can't change the interface the packet it getting out, its already
decided, i can only choose the next hop gateway address with-in the
network the ...
| Sep 18, 2:59 pm 2010 |
| Imre Oolberg | choosing outgoing interface based on process uid
Hallo!
I have OpenBSD v. 4.7 i386 firewall with two outgoing internet
connections (of which one is default gateway and the other could be used
with route-to, for example) and serveral networks behind it. On the
firewall runs Squid process as user _squid and it does transparent http
proxy for inner networks. I tried to read man route and man pf.conf but
cant figure out on my own whether it is possible or how to set up my
firewall so that Squid's requests go out thru that internet ...
| Sep 18, 10:12 am 2010 |
| roberth | Re: choosing outgoing interface based on process uid
On Sat, 18 Sep 2010 20:12:32 +0300
search the pf.conf manpage for the "user" parameter.
| Sep 18, 12:33 pm 2010 |
| KibaHub News | KibaHub.com is born !
Saturday, 18 September 2010
Click here to view it online (
http://kibahub.com/index.php?option=com_acymailing&ctrl=archive&task=view&...
)
MORE GAMES NEWS ( http://www.kibahub.com )
MORE FUNNY VIDEO ( http://www.kibahub.com )
* DANCING in the RAIN | DANSE SOUS LA PLUIE ( http://kibahub.com/index.php?option=com_hwdvideoshare&task=viewvideo&Itemid=91... )
for Dreal, stay up my brother. ...
| Sep 18, 12:00 am 2010 |
| Joe Martel | Re: hostapd deauthentication every 5 seconds
Interesting, thanks for the info - should I post a new bug report as that one
is closed?
Afaik my stations are not using power-saving mode (they all have a power cord,
so I assume they would not need to save power)
* Macbook Pro
* Cisco WVC2300
Yes it does, thanks.
Have added a cron job to run this every 24hrs.
| Sep 18, 5:01 am 2010 |
| Todd Carson | Re: hostapd deauthentication every 5 seconds
I have a similar problem against which ifconfig down; up isn't effective.
My card is an RT2561, and when I turn on ifconfig debug on both the client
and AP, I see that the AP responds to the association request and sends
the first packet of the 4-way handshake. The client receives the
association response, fails to receive the handshake initiation, and
receives a deauth after timing out.
AP side:
ral0: received assoc_req from xx:xx:xx:xx:xx:xx rssi 105 mode 11g
ral0: sending assoc_resp to ...
| Sep 18, 8:14 am 2010 |
| Joe Martel | Re: hostapd deauthentication every 5 seconds
Interesting, thanks for the info - should I post a new bug report as that one
is closed?
Afaik my stations are not using power-saving mode (they all have a power cord,
so I assume they would not need to save power)
* Macbook Pro
* Cisco WVC2300
Yes it does, thanks.
Have added a cron job to run this every 24hrs.
| Sep 18, 5:00 am 2010 |
| Jasper Valentijn | Re: Suggest, Recomendations and advices
+1
--
We spend the first twelve months of our children's lives teaching
them to walk and talk and the next twelve telling them to sit down and
shut up.
| Sep 18, 9:00 am 2010 |
| Jordi Espasa | Re: Suggest, Recomendations and advices
Francisco,
I'm sorry but Jacob words' are correct.
I've not so much simpathy for the author, but anyway it's a good start
point to correct your manners:
http://www.catb.org/esr/faqs/smart-questions.html
--
I will face my fear. I will permit it to pass over me and through me.
And when it has gone past I will turn the inner eye to see its path.
Where the fear has gone there will be nothing. Only I will remain.
| Sep 18, 5:11 am 2010 |
| previous day | today | next day |
|---|---|---|
| September 17, 2010 | September 18, 2010 | September 19, 2010 |
