PLEX86  x86- Virtual Machine (VM) Program
 Plex86  |  CVS  |  Mailing List  |  Download  |  Linux  |  Newsgroups

weird SMBD make_connection errors


Your Ad Here

Your Ad Here

So I'm looking at the traffic logs for our router, and I found something odd. Every morning at 2am until 3:45am there's a consistant load of traffic coming from somewhere on the LAN to one of the machines in the DMZ.

Yet Another Linux Migration Put On Hold!! Anyone else see a pattern here
Here we go again..... A snippet!!! "The next stage of the project was to be a Linux migration on the desktop. The suspension...

I'm still looking into trying to figure out which machines are the sender and receivers. But in the processes of looking into it, I found on BOTH of the two servers in the DMZ sections in theirvar-log-messages like this:

weird packet sends to various services
I'm trying to find out why every morning from 2am to 3:45am some machine on our LAN is sending consistant data to a machine on...
Yet Another Linux Migration Put On Hold!! Anyone else see a pattern here
notbob Good for you... That's arguable at best. The chances are that corporation do not want to...

Sep 4 03:33:39 webserve smbd10943: 2006-09-04 03:33:39, 0 smbd-service.c:makeconnection(1102) Sep 4 03:33:39 webserve smbd10943: designer04 (192.168.0.18) couldn't find service printprep.bat Sep 4 03:33:39 webserve smbd10943: 2006-09-04 03:33:39, 0 smbd-service.c:makeconnection(1102) Sep 4 03:33:39 webserve smbd10943: designer04 (192.168.0.18) couldn't find service printprep.cmd Sep 4 03:33:39 webserve smbd10943: 2006-09-04 03:33:39, 0 smbd-service.c:makeconnection(1102) Sep 4 03:33:39 webserve smbd10943: designer04 (192.168.0.18) couldn't find service printprep.exe Sep 4 03:33:39 webserve smbd10943: 2006-09-04 03:33:39, 0 smbd-service.c:makeconnection(1102) Sep 4 03:33:39 webserve smbd10943: designer04 (192.168.0.18) couldn't find service printprep.com Sep 4 03:33:39 webserve smbd10943: 2006-09-04 03:33:39, 0 smbd-service.c:makeconnection(1102) Sep 4 03:33:39 webserve smbd10943: designer04 (192.168.0.18) couldn't find service printprep.pif Sep 4 03:33:39 webserve smbd10943: 2006-09-04 03:33:39, 0 smbd-service.c:makeconnection(1102) Sep 4 03:33:39 webserve smbd10943: designer04 (192.168.0.18) couldn't find service printprep.lnk Sep 4 03:36:04 webserve smbd10943: 2006-09-04 03:36:04, 0 smbd-service.c:makeconnection(1102) Sep 4 03:36:04 webserve smbd10943: designer04 (192.168.0.18) couldn't find service printprep.bat Sep 4 03:36:04 webserve smbd10943: 2006-09-04 03:36:04, 0 smbd-service.c:makeconnection(1102) Sep 4 03:36:04 webserve smbd10943: designer04 (192.168.0.18) couldn't find service printprep.cmd Sep 4 03:36:04 webserve smbd10943: 2006-09-04 03:36:04, 0 smbd-service.c:makeconnection(1102) Sep 4 03:36:04 webserve smbd10943: designer04 (192.168.0.18) couldn't find service printprep.exe Sep 4 03:36:04 webserve smbd10943: 2006-09-04 03:36:04, 0 smbd-service.c:makeconnection(1102) Sep 4 03:36:04 webserve smbd10943: designer04 (192.168.0.18) couldn't find service printprep.com Sep 4 03:36:04 webserve smbd10943: 2006-09-04 03:36:04, 0 smbd-service.c:makeconnection(1102) Sep 4 03:36:04 webserve smbd10943: designer04 (192.168.0.18) couldn't find service printprep.pif Sep 4 03:36:04 webserve smbd10943: 2006-09-04 03:36:04, 0 smbd-service.c:makeconnection(1102) Sep 4 03:36:04 webserve smbd10943: designer04 (192.168.0.18) couldn't find service printprep.lnk

is compiling your own kernel useless or smart
On 6 Sep 2006 13:17:00 -0700, gavino staggered into the Black Sun and said: It's so poorly documented that there's been a Kernel-HOWTO that explains the whole process since at least...

Now, "printprep" is actually two things: There's a shared (SAMBA) folder on one of the two servers named "printprep" and there's a Web page named printprep.php, both of which that employee on PC "designer04" uses. What in the world is causing that one out of several WindowsXP PC's to spam the Fedora Core 5 servers for two minutes each day with these makeconnections for files that don't exist?

I don't know if this is tied to the huge nearly two hour data transfer each morning, but I can't find anything else suspicious in the FC5 logs, and I'm turing on more auditing options on the WindowsXP PC's tonight so I can look it their Event Viewers. I was just wondering if someone could give me a pointer on what the above might be about. Thanks! -Liam



Your Ad Here

List | Previous | Next

weird packet sends to various services

Linux groups from Newsgroups

The #1 Usenet Provider on the Internet

Reading from USB 2433