Solved

message?

Posted on 2004-05-03
13
288 Views
Last Modified: 2010-04-20
Hello experts,

I get a strange message on my linux box. It always pop au on my screen and it says:

172.31.217.5 sent an invalind ICMP error to a broadcast.

Can enybody tell my what it can means?

thanks

Luxana
0
Comment
Question by:Luxana
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 7
  • 6
13 Comments
 
LVL 8

Expert Comment

by:da99rmd
ID: 10976168
Some one is sending an invalid ICMP packet to you, probobly someone infected with some virus or some trojan of some kind.
Do you know the computer with that ip ?

/Rob
0
 
LVL 8

Expert Comment

by:da99rmd
ID: 10976175
Nothing to be alarmed on do you have a firewall up and running ?
ANd what service are appending the message ?

/Rob
0
 
LVL 10

Author Comment

by:Luxana
ID: 10976325
this IP 172.31.217.5 is not on my network at all.

I'm blocking some ports with iptables and I'm traing to get my shorewall on.

I do not know which servise is appendig to this message . How can I found out?
0
Industry Leaders: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

 
LVL 8

Expert Comment

by:da99rmd
ID: 10976403
I guess it appeard in /var/log/messages right ?
if so the [(service)] will tell you what service thats addes this entry.

/Rob
0
 
LVL 10

Author Comment

by:Luxana
ID: 10976509
Rob

here is what I foud in /var/log/messages

May  2 10:52:00 luxana kernel: 172.31.217.5 sent an invalid ICMP error to a broadcast.
May  2 10:55:10 luxana kernel: 172.31.217.5 sent an invalid ICMP error to a broadcast.

it is also from another IP:

May  2 10:55:12 luxana kernel: 172.31.217.1 sent an invalid ICMP error to a broadcast.

what you thing?
0
 
LVL 8

Accepted Solution

by:
da99rmd earned 20 total points
ID: 10976575
Ill just explain this
< --- date ------><--service->  <--------------- message ---------------------------------->
May  2 10:55:12 luxana kernel: 172.31.217.1 sent an invalid ICMP error to a broadcast.

So it was from the kernel the message arrived.

Then it was just so that an invalid ICMP packet arrived from that host 172.31.217.5 the reasons can be:
The host 172.31.217.5 was infected of som virus or trojan.
Or there where some korruption of the packet on the way to your computer.

Are there many entrys or just these ?

/Rob

0
 
LVL 10

Author Comment

by:Luxana
ID: 10976625
there are many entres like this above. It starts

May  2 06:50:04 till now. I have no messages before it starts.

this is firstone:

May  2 06:47:04 luxana syslogd 1.4.1#10: restart.
0
 
LVL 10

Author Comment

by:Luxana
ID: 10976650
Rob I have absolutely different netmask so I have no idea where this IP above is from..
0
 
LVL 10

Author Comment

by:Luxana
ID: 10976651
Rob I have absolutely different netmask so I have no idea where this IP above is from..
0
 
LVL 8

Expert Comment

by:da99rmd
ID: 10976655
Oki,
what ISP do you have ?
And are you on the 172.31.217.0 net ?

YOu can write the ISp and tell them that the host are sending strange packets, just to infomr them.

/Rob
0
 
LVL 8

Expert Comment

by:da99rmd
ID: 10976671
Oki its some kind of broadcast you can just ignore it if its not bursting at your host.
Or just block it in your iptables rules.

/Rob
0
 
LVL 10

Author Comment

by:Luxana
ID: 10976745
My isp is on totally different subnet so really I have no idea whre the meesage is from.

my intternal net is 192.168.0.0
ent extrernal have just 3 hosts


Rob just now I get my firewall working so it seems like I'm filly protected. So now I have to go and I'll check it tomorow and accept your answer.

0
 
LVL 10

Author Comment

by:Luxana
ID: 10984760
rob  for help and patient no messages from yesterday when I start firewall.

thanks you

Luxana

http://www.experts-exchange.com/Operating_Systems/Linux/Q_20976691.html
0

Featured Post

What is SQL Server and how does it work?

The purpose of this paper is to provide you background on SQL Server. It’s your self-study guide for learning fundamentals. It includes both the history of SQL and its technical basics. Concepts and definitions will form the solid foundation of your future DBA expertise.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

The purpose of this article is to fix the unknown display problem in Linux Mint operating system. After installing the OS if you see Display monitor is not recognized then we can install "MESA" utilities to fix this problem or we can install additio…
I. Introduction There's an interesting discussion going on now in an Experts Exchange Group — Attachments with no extension (http://www.experts-exchange.com/discussions/210281/Attachments-with-no-extension.html). This reminded me of questions tha…
Connecting to an Amazon Linux EC2 Instance from Windows Using PuTTY.
Get a first impression of how PRTG looks and learn how it works.   This video is a short introduction to PRTG, as an initial overview or as a quick start for new PRTG users.

733 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question