Welcome to Linux Forums!

With a comprehensive Linux Forum, information on various types of Linux software and many Linux Reviews articles, we have all the knowledge you need a click away, or accessible via our knowledgeable members.

Linux Forum ArticlesLinux ForumsLinux Forum DownloadsLinux Hosts
Home|Register|FAQ|Member List|Calendar|Unanswered Posts|Forum Rules|Today's Posts|Advanced Search|
SEARCH FOR IN
Go Back   Linux Forums > GNU Linux Zone > Linux Security
Reload this Page Routing tables misteriously reloaded
Linux Forums
Linux Forums
Welcome To The Linux Forums!
Welcome to Linux Forums. We pride ourselves in being one of the largest Linux communities on the web, we encourage you to REGISTER on our forums and participate in the community. There are over 150,000 members ready to answer your questions. JOINING US today will allow you to make new posts, get support, send messages to other members and submit downloads to our downloads directory and many other great features!

Linux Security Discussion about keeping your machines secure, and the crackers out.

Reply
 
Thread Tools Display Modes
Old 07-11-2007   #1 (permalink)
DJJoe
Just Joined!
 
Join Date: Jul 2007
Posts: 1
Routing tables misteriously reloaded

Hi

A few days ago my server suddenly went offline out of the blue, after over a year of uptime. RHEL 4. I could get the ISP to ping it from the switch, but from outside the subnet ping requests were being ignored. The machine was up and running, and when I got to the console I noticed a few "Neighbour table overflow" entries on the console.

After a few hours of struggling, I eventually found that the default route in the routing table was incorrectly set to the IP of the server and not the IP of the gateway. So all packets to the subnet were getting out, but no others. My /etc/sysconfig/network file had an incorrectly set GATEWAY setting, which must have been there since I installed over a year ago (the date of the file pretty much confirms this), and I must have adjusted the routing tables by hand.

I can only think that for some reason the routing tables where suddenly reloaded, and the incorrect gateway was loaded from the /etc/sysconfig/network file. Does anyone know why this might have happened?

I think it's pretty unlikely that I've been hacked (although always possible). The firewall is configured well, very few ports open, and there seem to be no other signs of a hack - I would have expected more than a routing table change / reload in that case.

What could cause the reload? IPTables throwing a wobbly? TCP stack? Kernel? Malicious packets, ICMP or otherwise?

Any suggestions/ideas would be appreciated!

-------------------
P.S. pls ignore typo in title!

Last edited by DJJoe; 07-12-2007 at 07:16 AM. Reason: Typo in heading
DJJoe is offline   Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off

Similar Threads
Thread Thread Starter Forum Replies Last Post
Static IP / Routing table problem devashish Linux Networking 8 07-04-2007 04:44 PM
FTP & IP tables issues Yalu Linux Networking 1 01-01-2007 08:14 AM
debian-sys-maint doesn't close mysql tables when quitting? Blue Beret Debian Linux Help 0 11-01-2006 12:13 PM
Accessing four tables at the same time? Nomad Linux Programming & Scripting 2 04-19-2003 12:41 PM




All times are GMT. The time now is 05:58 AM.




© 2000 - 2008 - All Rights Reserved - Property of  MAS Media

Content Relevant URLs by vBSEO 3.0.0