On Wed, Mar 20, 2002 at 10:45:25AM +0100, Lionel Elie Mamane wrote: > Has anyone any idea why a machine get such a packet? > > Packet log: input *ACTION* *iface* PROTO=6 207.46.197.102:65535 *my_machine_ip*:65535 L=756 S=0x00 I=33890 F=0x005D T=51 (#20) > > whois 207.46.197.102 > Microsoft (NETBLK-MICROSOFT-GLOBAL-NET) Perhaps the source address is spoofed? Or it's some Microsoft automatic software update thingie? Machine 207.46.197.102 is unreachable now, btw. Anyway, I don't get these. A lot of other misdirected packets 'though, mostly for port tcp 1080 and tcp 3128. Bye, Joost
<<inline: application/pgp-signature>>