[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: WTF, a new IIS worm?



On Wed, Sep 08, 2004 at 10:23:02PM +0200, Han Boetes wrote:

> > Sep 08 18:00:03.522998 rule 0/0(match): block in on fxp1:
> > 199.237.51.7.3983 > 10.0.0.2.18969: S 3594171567:3594171567(0) win
> > 16384 <mss 1400,nop,nop,sackOK>
> 
> 
> In my pf.conf this is the first rule after passing in the natted traffic:
[..]
I'll try it, let's see if will be useful to me, THNX.

-- 
Pierluigi De Rosa (thorin_(_at_)_durin_(_dot_)_khazad-dum_(_dot_)_net).