Gentoo Forums
Gentoo Forums
Gentoo Forums
Quick Search: in
What is, Treason uncloaked ?
View unanswered posts
View posts from last 24 hours

 
Reply to topic    Gentoo Forums Forum Index Networking & Security
View previous topic :: View next topic  
Author Message
aztech
Tux's lil' helper
Tux's lil' helper


Joined: 29 Jul 2002
Posts: 130
Location: Stenungsund, Sweden

PostPosted: Sun Jul 20, 2008 12:10 pm    Post subject: What is, Treason uncloaked ? Reply with quote

OK .. what does this mean ??
Never seen it before.

Code:

Jul 20 01:14:22 bionic TCP: Treason uncloaked! Peer 90.225.104.170:60095/49139 shrinks window 2119026980:2119029692. Repaired.


Code:

bionic ~ # cat /var/log/messages | grep Treason |wc -l
1302


As you can see, the message occurs kind a often and as far as I can se, it started Jul 15 and has been continuing till now and it's always from the same IP in my logs ..

What can it be ?

BR
Andreas
Back to top
View user's profile Send private message
Hu
Administrator
Administrator


Joined: 06 Mar 2007
Posts: 23062

PostPosted: Sun Jul 20, 2008 3:47 pm    Post subject: Reply with quote

This message comes from net/ipv4/tcp_timer.c in tcp_retransmit_timer. The comment indicates that the receiver tried to shrink the TCP window. What are you doing when these messages appear? Is your ISP violating IP in any way?
Back to top
View user's profile Send private message
zyko
l33t
l33t


Joined: 01 Jun 2008
Posts: 620
Location: Munich, Germany

PostPosted: Sun Jul 20, 2008 4:12 pm    Post subject: Reply with quote

Is this happening on a server or on a desktop machine? Is there more than one IP causing this?

Afaik, this is indicative of someone who isn't quite conforming to TCP/IP standards, either intentionally (exploit attempt) or unintentionally (some sort of firewall maybe?).
Back to top
View user's profile Send private message
djanderson
Tux's lil' helper
Tux's lil' helper


Joined: 24 Mar 2004
Posts: 98
Location: Boulder, CO

PostPosted: Sun Jul 20, 2008 4:17 pm    Post subject: Reply with quote

https://forums.gentoo.org/viewtopic.php?t=354939
Back to top
View user's profile Send private message
aztech
Tux's lil' helper
Tux's lil' helper


Joined: 29 Jul 2002
Posts: 130
Location: Stenungsund, Sweden

PostPosted: Sun Jul 20, 2008 4:40 pm    Post subject: Reply with quote

zyko wrote:
Is this happening on a server or on a desktop machine? Is there more than one IP causing this?

Afaik, this is indicative of someone who isn't quite conforming to TCP/IP standards, either intentionally (exploit attempt) or unintentionally (some sort of firewall maybe?).


This is a server acting as a router/firewall/httpd etc for my local network at home.
I saw this recently when trying to ind out why the server has so high load
compared to normal. The load is above 4.0 now compared to around 1.5 ..
The httpd is very much slower now, than before also ...

Yeah and there are attempts from multiple IP's

Any idéas ??
Back to top
View user's profile Send private message
zyko
l33t
l33t


Joined: 01 Jun 2008
Posts: 620
Location: Munich, Germany

PostPosted: Sun Jul 20, 2008 10:51 pm    Post subject: Reply with quote

Unless you have a reason not to, I'd suggest you ban all the fishy IPs via IPfilter until we maybe find out more about the specifics. This pretty much smells like a generic exploit attempt to me, though I have never myself seen this kind of behaviour in my own server logs.
Back to top
View user's profile Send private message
Display posts from previous:   
Reply to topic    Gentoo Forums Forum Index Networking & Security All times are GMT
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum