[Wolves] smoothwall advice please

kev adams kev at magicmoon.co.uk
Tue Jun 7 22:07:47 BST 2005


On Tuesday 07 Jun 2005 21:41, Andy Wootton wrote:

> Someone else may know better but until they reply -
>
> This could be someone attempting an exploit by a buffer overflow attack.
> I'd guess they haven't got through yet. I would remove the cable from
> Smoothwall to your switch until you are sure if you have another safe
> route to do your research. NMAP is a port scanner so it looks very
> dodgy. I'd be Googling for http buffer-overflow/ill-formed packets
> exploits and checking for patches. The attacking machines could have

I've been watching the thing while I work & unplug the phone line whenever I 
go out.  It's doing my head in as I have quite a lot to get done & now maybe 
this to sort.  It suprised me to see stuff get through as the router has a 
firewall built in too - presumably quite a basic one but all the same a 
firewall/router - smoothwall - independently firewalled systems within the 
LAN made me feel quite safe until the last couple of days - ARRGGHHH ;~)

cheers
kev



More information about the Wolves mailing list