Strange messages in /var/log/messages

kcdworks

Well-Known Member
Jul 28, 2002
186
0
166
We are having a really strange message in our /var/log/messages file.

Aug 16 10:08:57 server3 kernel: **UDP DROP** IN=eth0 OUT= MAC=00:50:22:9a:d6:37:00:e0:52:08:b8:bd:08:00 SRC=81.101.161.91 DST=64.246.x.x LEN=40 TOS=0x00 PREC=0x00 TTL=7 ID=60403 PROTO=UDP SPT=60341 DPT=33496 LEN=20

The bold IP address is always there. It belongs to RIPE, according to an ARIN whois. I've added it to hosts.deny, but that message contiues to appear at the rate of 1 per second.

Any ideas?

cPanel.net Support Ticket Number:
 

mmkassem

Well-Known Member
Oct 21, 2002
390
0
166
Egypt
Originally posted by kcdworks
We are having a really strange message in our /var/log/messages file.

Aug 16 10:08:57 server3 kernel: **UDP DROP** IN=eth0 OUT= MAC=00:50:22:9a:d6:37:00:e0:52:08:b8:bd:08:00 SRC=81.101.161.91 DST=64.246.x.x LEN=40 TOS=0x00 PREC=0x00 TTL=7 ID=60403 PROTO=UDP SPT=60341 DPT=33496 LEN=20

The bold IP address is always there. It belongs to RIPE, according to an ARIN whois. I've added it to hosts.deny, but that message contiues to appear at the rate of 1 per second.

Any ideas?

cPanel.net Support Ticket Number:
It is owned by:
netname: NTL
descr: NTL Infrastructure - Luton
country: GB

If ARIN tells you it is owned by RIPE you have to check RIPE to know whois the block is assigned to.

PROTO=UDP DPT=33496
It's a high port, UDP and within the range used to traceroute (using UDP not ICMP)

You should not worry.
 

kcdworks

Well-Known Member
Jul 28, 2002
186
0
166
I forgot to come back to this thread, but it stopped about three minutes after I posted that.

Thanks for the reply.

cPanel.net Support Ticket Number: