What's happening here?

SlackRat ab460-0l1pH2CMacvR7s880joybQ at public.gmane.org
Mon Jul 20 06:51:39 UTC 2009


Does anyone know why I should be getting hit by Microsoft every 
few seconds?

I do occasionally run Gaim/Pidgin, but the hits come in whether 
they are loaded or not.

The Source IP varies, DPT doesn't, and the interval between hits 
varies but is never more than a few minutes but more usually 
just a few seconds

They are all dropped, but neverthless a nuisance

[SNIP k^n from Syslog]
Jul 19 14:55:48 darkstar kernel: MSOFT:IN=eth0 OUT=
MAC=00:14:c2:0a:24:74:00:24:d4:b1:72:bc:08:00 SRC=65.55.67.197
DST=82.242.109.147 LEN=48 TOS=0x00 PREC=0x00 TTL=115 ID=757 DF
PROTO=TCP SPT=49636 DPT=6080 WINDOW=65535 RES=0x00 SYN URGP=0

Jul 19 14:58:49 darkstar kernel: MSOFT:IN=eth0 OUT=
MAC=00:14:c2:0a:24:74:00:24:d4:b1:72:bc:08:00 SRC=65.55.106.115
DST=82.242.109.147 LEN=48 TOS=0x00 PREC=0x00 TTL=117 ID=11782 DF
PROTO=TCP SPT=48208 DPT=80 WINDOW=65535 RES=0x00 SYN URGP=0

Jul 19 14:58:52 darkstar kernel: MSOFT:IN=eth0 OUT=
MAC=00:14:c2:0a:24:74:00:24:d4:b1:72:bc:08:00 SRC=65.55.106.115
DST=82.242.109.147 LEN=48 TOS=0x00 PREC=0x00 TTL=117 ID=17750 DF
PROTO=TCP SPT=48208 DPT=80 WINDOW=65535 RES=0x00 SYN URGP=0

Jul 19 14:58:58 darkstar kernel: MSOFT:IN=eth0 OUT=
MAC=00:14:c2:0a:24:74:00:24:d4:b1:72:bc:08:00 SRC=65.55.106.182
DST=82.242.109.147 LEN=48 TOS=0x00 PREC=0x00 TTL=116 ID=890 DF
PROTO=TCP SPT=23028 DPT=80 WINDOW=65535 RES=0x00 SYN URGP=0

-- 
Slackrat
--
The Toronto Linux Users Group.      Meetings: http://gtalug.org/
TLUG requests: Linux topics, No HTML, wrap text below 80 columns
How to UNSUBSCRIBE: http://gtalug.org/wiki/Mailing_lists





More information about the Legacy mailing list