Ipfw strangeness in SL

hi there,
i just noticed a strange behaviour in SL: when i configure the firewall with system preferences -> security -> firewall and set it to defaults, i.e. allowing certain services, stupid stealth mode off and then do a ipfw list in a terminal window, i just get the kernel-default 65535 allow all rule?!
shouldn't there be the services listed which appear in the firewall configuration pane? when i then click on the "block all external connections" (may be another wording in english, i am on a german system) and do the ipfw list afterwards, i get:
# ipfw list
33300 deny log logamount 5 icmp from any to me in icmptypes 8
65535 allow ip from any to any
that's the stupid "stealth mode" (disabling icmp only!) and the default allow all rule. where is the deny rule?
can anyone help? shouldn't i see a deny ip from any to any in here?
regards
gerd

no one?

Similar Messages

  • Ipfw log strangeness

    Here's a logline from ipfw on a machine I look after (exact dest ip masked for privacy):
    Jan 22 23:50:01 imac-g5 ipfw: 54013 Deny TCP 64.233.167.99:80 68.x.x.x:49725 in via en0
    ... the source IP logged here belongs to Google.
    If the source and destination ports were reversed ie:
    SRC: 64.233.167.99:49725
    DEST: 68.x.x.x:80
    ... then it's be fairly obviously a Googlebot being rebuffed. But they aren't reversed, the source as logged is port 80 on Google's IP, and the destination is a client-port on the local machine.
    Anyone got any clues as to what this traffic may actually be? It's got me baffled.
    Cheers
    S.
    Powerbook G4 1.5GHz 15   Mac OS X (10.4.4)  

    Here's a logline from ipfw on a machine I look after (exact dest ip masked for privacy):
    Jan 22 23:50:01 imac-g5 ipfw: 54013 Deny TCP 64.233.167.99:80 68.x.x.x:49725 in via en0
    ... the source IP logged here belongs to Google.
    If the source and destination ports were reversed ie:
    SRC: 64.233.167.99:49725
    DEST: 68.x.x.x:80
    ... then it's be fairly obviously a Googlebot being rebuffed. But they aren't reversed, the source as logged is port 80 on Google's IP, and the destination is a client-port on the local machine.
    Anyone got any clues as to what this traffic may actually be? It's got me baffled.
    Cheers
    S.
    Powerbook G4 1.5GHz 15   Mac OS X (10.4.4)  

  • Strange SL behavior with other Applications

    For the last couple of days I've been having problems with my SL install. The problem is that its hard to pinpoint where the problems are coming from.
    Some of the 3rd party programs that I have installed all started having problems at the same time so I suspect that SL is the culprit. I have reinstalled all of them with no improvements:
    Microsoft Office:
    Word and Powerpoint freeze when I try quitting them. I have to force quit them to close them completely.
    iStat Menu:
    The memory and cpu usage menus do not display the top 5 processes using memory or CPU. All other functions in iStat Menu work fine. Strange!
    Dropbox:
    Dropbox slows down the Finder (cover flow and general file browsing is slow and jerky) when I launch it. The Dropbox context menu does not work either and no Dropbox related icons are displayed in my dropbox folder. I posted in Dropbox's forum and they helped me some but I'm still not convinced
    http://forums.dropbox.com/topic.php?id=18212&replies=12#post-114185
    Google Video/Audio plugin for Firefox, Google Chrome:
    I am unable to use video/audio conference in either browser. No video icon is displayed in my gmail chat window.
    I understand that this is a long list of somewhat unrelated problems but all them occurred at about the same time which hints to me that there are some kind of system problems (maybe with permissions).
    I have repaired my permissions successfully, deleted the system caches with Onyx, and completely deleted and reinstalled all of the programs that are having problems. I have also started SL in safe boot but that didn't help.
    Please help me! Any suggestions would be greatly appreciated.
    Thanks
    Message was edited by: themacfreak

    This is what I found in my system log:
    Mar 21 10:42:49 NYMBAR com.apple.launchd.peruser.501[345] ([0x0-0x13f13f].com.google.GoogleTalkPluginD[1708]): Exited with exit code: 255
    Mar 21 10:44:06 NYMBAR com.apple.launchd.peruser.501[345] ([0x0-0x140140].com.google.GoogleTalkPluginD[1710]): Exited with exit code: 255
    Mar 21 10:45:23 NYMBAR com.apple.launchd.peruser.501[345] ([0x0-0x141141].com.google.GoogleTalkPluginD[1717]): Exited with exit code: 255
    This error message keeps on repeating. Any suggestions?
    I fixed the iStat Menu problem! The ipfw was blocking port 5204 which iStat needs to use. This error message led me to this conclusion:
    Mar 21 01:09:25 NYMBAR Firewall[59]: 63000 Deny TCP 127.0.0.1:58876 127.0.0.1:5204 in via lo0
    Mar 21 01:09:26 NYMBAR Firewall[59]: 63000 Deny TCP 127.0.0.1:58877 127.0.0.1:5204 in via lo0
    Mar 21 01:09:26 NYMBAR Firewall[59]: 63000 Deny TCP 127.0.0.1:58876 127.0.0.1:5204 in via lo0
    Mar 21 01:09:27 NYMBAR Firewall[59]: 63000 Deny TCP 127.0.0.1:58877 127.0.0.1:5204 in via lo0
    Mar 21 01:09:27 NYMBAR Firewall[59]: 63000 Deny TCP 127.0.0.1:58876 127.0.0.1:5204 in via lo0
    I'm glad that is fixed but I still have the Office problem and the google talk plugin problem. Does anyone have any suggestions?
    Thanks

  • Strange MacJanitor (chron) reports

    Hi, and Happy Holidays. (This is also posted on the Tiger discussion page, but no one there had any ideas.) Recently ran MacJanitor, and got this:
    Rebuilding locate database:
    Rebuilding whatis database:
    find: /usr/local/man: No such file or directory
    makewhatis: /usr/share/man/man1/c++.1: No such file or directory
    makewhatis: /usr/share/man/man1/cc.1: No such file or directory
    makewhatis: /usr/share/man/man1/cpp.1: No such file or directory
    makewhatis: /usr/share/man/man1/g++.1: No such file or directory
    makewhatis: /usr/share/man/man1/gcc.1: No such file or directory
    makewhatis: /usr/share/man/man1/gcov.1: No such file or directory
    Rotating log files: ftp.log lpr.log mail.log netinfo.log ipfw.log secure.log
    Don't recall ever seeing this report before. I then ran the install disc, had Disc Utility repair the volume (no errors found), ran permissions from start-up disc (also fine), and cleaned with OnyX. A second run of MacJanitor gave me the same message. Anyone know what this means, and if I should be concerned? Running an iMac G5 17" PPC iSight 160gb w/1gb of memory, last model before the Intels came out. Machine is running well, no strange behaviors. Haven't thrown out any OS files or changed anything (been using X since 10.0.3, know better!), or even added new apps recently. Did update w/newest Security patch, added the MS Office 2004 update (the one that was recalled) and updated Aperture in the last week. Thanks for the help.

    Since MacJanitor is the only utililty finding any errors, suggest that you cross-post over at the manufacturer's support site forum.
    Hopefully, a knowledgeable user and/or Brian Hill himself will be able to explain what that error means.
    Good luck!

  • Strange MacJanitor report

    Hi, and Happy Holidays. Recently ran MacJanitor, and got this:
    Rebuilding locate database:
    Rebuilding whatis database:
    find: /usr/local/man: No such file or directory
    makewhatis: /usr/share/man/man1/c++.1: No such file or directory
    makewhatis: /usr/share/man/man1/cc.1: No such file or directory
    makewhatis: /usr/share/man/man1/cpp.1: No such file or directory
    makewhatis: /usr/share/man/man1/g++.1: No such file or directory
    makewhatis: /usr/share/man/man1/gcc.1: No such file or directory
    makewhatis: /usr/share/man/man1/gcov.1: No such file or directory
    Rotating log files: ftp.log lpr.log mail.log netinfo.log ipfw.log secure.log
    Don't recall ever seeing this report before. I then ran the install disc, had Disc Utility repair the volume (no errors found), ran permissions from start-up disc (also fine), and cleaned with OnyX. A second run of MacJanitor gave me the same message. Anyone know what this means, and if I should be concerned? Running an iMac 17" PPC iSight 160gb w/1gb of memory, last model before the Intels came out. Machine is running well, no strange behaviors. Haven't thrown out any OS files or changed anything (been using X since 10.0.3, know better!), or even added new apps recently. Did update w/newest Security patch, added the MS Office 2004 update (the one that was recalled) and updated Aperture in the last week. Thanks for the help.

    I don't know MacJanitor, but I suspect those entries are associated with it running the weekly maintenance task. You're getting those messages because those items don't exist. At least, there's no man directory in my /usr/local/ directory and none of the files listed for /usr/share/man/man1/ are on my machine, My perusal of the weekly.out log only shows the first entry.
    Launch the Terminal.app in /Applications/Utilities, enter this command, hit the return key, enter your admin password (carefully, since it doesn't show up on the screen), and hit the return key:
    sudo periodic weekly
    wait until you get the prompt back and then enter this command and hit the return key:
    cat /var/log/weekly.out[b>
    The file that displays should have those same entries.

  • Ipfw Logs and Other Delightful Issues

    So. Frustrated. I've tried so many different things that I'm not really even sure where to start. Disclaimer: I might be a bit too cautious when it comes to security, and I have just enough knowledge to make my paranoia go into overdrive. Hopefully there's nothing seriously wrong here.
    I'm running 10.4 on a MBP. I have the firewall enabled (Apple's and my router's) with all the services turned off, Stealth Mode enabled, block all UDP traffic, etc. A couple of spam emails bounced back to me that had originated from my account. The headers indicated that it was coming from a 10.103.197.1. I ran a traceroute and came up with nothing. After some Googling, I found out it's a blackhole. I got nervous and checked the ipfw logs and found a lot of connection attempts. Most, of course, are from sites I had visited, but a few IP addresses and ports looked strange. The logs are pretty lengthy, but here's a snippet. Again, I know a little, but I don't know enough to be 100% about what's normal and what isn't. I know a lot of them are safe websites, but I don't understand why they're trying to connect to the specific ports - I couldn't find any info on most of the ports. Bear with me if some of this is obviously benign.
    Dec 20 21:11:05 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:51335 from 209.85.225.100:80
    Dec 20 21:11:05 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:51335 from 209.85.225.100:80
    Dec 20 21:11:06 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:51335 from 209.85.225.100:80
    Dec 20 21:11:07 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:51335 from 209.85.225.100:80
    Dec 20 21:11:10 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:51335 from 209.85.225.100:80
    Dec 20 21:11:14 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:51335 from 209.85.225.100:80
    Dec 20 21:14:25 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:51373 from 72.32.194.250:80
    Dec 20 21:14:28 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:51373 from 72.32.194.250:80
    Dec 20 21:14:35 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:51373 from 72.32.194.250:80
    Dec 20 21:15:40 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:51414 from 208.111.168.7:80
    Dec 20 21:15:43 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:51414 from 208.111.168.7:80
    Dec 20 21:15:49 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:51414 from 208.111.168.7:80
    Dec 20 21:16:01 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:51414 from 208.111.168.7:80
    Dec 20 21:41:12 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:51807 from 74.54.212.168:80
    Dec 20 21:41:15 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:51807 from 74.54.212.168:80
    Dec 20 21:41:21 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:51807 from 74.54.212.168:80
    Dec 20 21:41:33 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:51807 from 74.54.212.168:80
    Dec 20 21:41:57 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:51807 from 74.54.212.168:80
    Dec 20 22:28:46 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:52235 from 81.93.57.98:80
    Dec 20 22:28:49 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:52235 from 81.93.57.98:80
    Dec 20 22:28:55 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:52235 from 81.93.57.98:80
    Dec 20 22:29:07 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:52235 from 81.93.57.98:80
    Dec 20 22:29:31 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:52235 from 81.93.57.98:80
    Dec 20 22:30:20 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:52235 from 81.93.57.98:80
    Dec 20 22:51:27 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:52481 from 66.114.53.22:80
    Dec 20 22:51:30 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:52481 from 66.114.53.22:80
    Dec 20 22:51:36 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:52481 from 66.114.53.22:80
    Dec 20 22:51:48 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:52481 from 66.114.53.22:80
    Dec 20 22:52:33 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:52502 from 208.109.107.127:80
    Dec 20 22:52:36 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:52502 from 208.109.107.127:80
    Dec 20 22:52:42 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:52502 from 208.109.107.127:80
    Dec 20 22:52:54 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:52502 from 208.109.107.127:80
    Dec 20 22:53:19 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:52502 from 208.109.107.127:80
    Dec 20 22:54:07 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:52502 from 208.109.107.127:80
    Dec 20 22:54:17 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:52613 from 66.114.53.28:80
    Dec 20 22:54:17 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:52568 from 66.114.53.51:80
    Dec 20 22:54:17 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:52567 from 66.114.53.51:80
    Dec 20 22:54:17 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:52567 from 66.114.53.51:80
    Dec 20 22:54:18 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:52581 from 63.84.95.58:80
    Dec 20 22:54:19 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:52579 from 66.114.53.23:80
    Dec 20 22:54:19 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:52568 from 66.114.53.51:80
    Dec 20 22:54:19 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:52583 from 66.114.53.28:80
    Dec 20 22:54:19 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:52584 from 66.114.53.28:80
    Dec 20 22:54:19 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:52604 from 66.114.53.17:80
    Dec 20 22:54:19 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:52582 from 66.114.53.28:80
    Dec 20 22:54:20 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:52605 from 66.114.53.17:80
    Dec 20 22:54:20 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:52613 from 66.114.53.28:80
    Dec 20 22:54:20 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:52607 from 66.114.53.17:80
    Dec 20 22:54:23 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:52581 from 63.84.95.58:80
    Dec 20 22:54:23 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:52567 from 66.114.53.51:80
    Dec 20 22:54:25 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:52579 from 66.114.53.23:80
    Dec 20 22:54:25 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:52568 from 66.114.53.51:80
    Dec 20 22:54:25 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:52583 from 66.114.53.28:80
    Dec 20 22:54:25 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:52584 from 66.114.53.28:80
    Dec 20 22:54:25 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:52604 from 66.114.53.17:80
    Dec 20 22:54:25 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:52582 from 66.114.53.28:80
    Dec 20 22:54:26 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:52605 from 66.114.53.17:80
    Dec 20 22:54:26 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:52613 from 66.114.53.28:80
    Dec 20 22:54:27 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:52607 from 66.114.53.17:80
    Dec 20 22:54:32 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:52581 from 63.84.95.58:80
    Dec 20 22:54:36 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:52567 from 66.114.53.51:80
    Dec 20 22:54:37 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:52579 from 66.114.53.23:80
    Dec 20 22:54:37 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:52568 from 66.114.53.51:80
    Dec 20 22:54:37 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:52583 from 66.114.53.28:80
    Dec 20 22:54:37 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:52584 from 66.114.53.28:80
    Dec 20 22:54:37 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:52604 from 66.114.53.17:80
    Dec 20 22:54:37 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:52582 from 66.114.53.28:80
    Dec 20 22:54:38 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:52605 from 66.114.53.17:80
    Dec 20 22:54:38 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:52613 from 66.114.53.28:80
    Dec 20 22:54:39 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:52607 from 66.114.53.17:80
    Dec 20 22:54:49 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:52581 from 63.84.95.58:80
    Dec 20 22:55:22 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:52581 from 63.84.95.58:80
    Dec 20 23:14:48 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:52900 from 209.85.225.101:80
    Dec 20 23:14:49 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:52900 from 209.85.225.101:80
    Dec 20 23:14:49 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:52900 from 209.85.225.101:80
    Dec 20 23:14:51 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:52900 from 209.85.225.101:80
    Dec 20 23:14:53 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:52900 from 209.85.225.101:80
    Dec 20 23:14:58 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:52900 from 209.85.225.101:80
    Dec 20 23:16:19 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:53022 from 66.114.53.48:80
    Dec 20 23:16:19 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:53023 from 66.114.53.48:80
    Dec 20 23:16:19 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:53025 from 66.114.53.48:80
    Dec 20 23:16:19 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:53026 from 66.114.53.48:80
    Dec 20 23:16:19 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:53027 from 66.114.53.48:80
    Dec 20 23:16:20 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:52986 from 66.114.53.48:80
    Dec 20 23:16:20 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:52989 from 66.114.53.48:80
    Dec 20 23:16:20 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:52985 from 66.114.53.48:80
    Dec 20 23:16:21 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:52996 from 66.114.53.48:80
    Dec 20 23:16:21 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:52987 from 66.114.53.48:80
    Dec 20 23:16:21 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:52990 from 66.114.53.48:80
    Dec 20 23:16:21 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:52988 from 66.114.53.48:80
    Dec 20 23:16:21 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:52995 from 66.114.53.48:80
    Dec 20 23:16:21 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:52993 from 66.114.53.48:80
    Dec 20 23:16:22 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:52994 from 66.114.53.48:80
    Dec 20 23:16:22 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:53018 from 66.114.53.48:80
    Dec 20 23:16:22 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:53021 from 66.114.53.48:80
    Dec 20 23:16:22 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:53020 from 66.114.53.48:80
    Dec 20 23:16:22 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:53026 from 66.114.53.48:80
    Dec 20 23:16:23 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:53025 from 66.114.53.48:80
    Dec 20 23:16:23 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:53022 from 66.114.53.48:80
    Dec 20 23:16:23 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:53023 from 66.114.53.48:80
    Dec 20 23:16:23 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:53019 from 66.114.53.48:80
    Dec 20 23:16:23 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:53027 from 66.114.53.48:80
    Dec 20 23:16:26 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:52986 from 66.114.53.48:80
    Dec 20 23:16:27 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:52996 from 66.114.53.48:80
    Dec 20 23:16:27 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:52992 from 66.114.53.48:80
    Dec 20 23:16:27 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:52987 from 66.114.53.48:80
    Dec 20 23:16:27 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:52988 from 66.114.53.48:80
    Dec 20 23:16:27 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:52995 from 66.114.53.48:80
    Dec 20 23:16:27 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:52993 from 66.114.53.48:80
    Dec 20 23:16:28 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:52994 from 66.114.53.48:80
    Dec 20 23:16:28 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:53018 from 66.114.53.48:80
    Dec 20 23:16:28 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:53021 from 66.114.53.48:80
    Dec 20 23:16:28 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:53020 from 66.114.53.48:80
    Dec 20 23:16:28 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:53026 from 66.114.53.48:80
    Dec 20 23:16:29 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:53025 from 66.114.53.48:80
    Dec 20 23:16:29 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:53023 from 66.114.53.48:80
    Dec 20 23:16:29 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:53022 from 66.114.53.48:80
    Dec 20 23:16:29 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:53019 from 66.114.53.48:80
    Dec 20 23:16:38 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:52989 from 66.114.53.48:80
    Dec 20 23:16:38 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:52985 from 66.114.53.48:80
    Dec 20 23:16:38 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:52986 from 66.114.53.48:80
    Dec 20 23:16:38 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:52996 from 66.114.53.48:80
    Dec 20 23:16:39 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:52987 from 66.114.53.48:80
    Dec 20 23:16:39 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:52992 from 66.114.53.48:80
    Dec 20 23:16:39 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:52988 from 66.114.53.48:80
    Dec 20 23:16:39 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:52995 from 66.114.53.48:80
    Dec 20 23:16:39 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:52993 from 66.114.53.48:80
    Dec 20 23:16:40 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:52994 from 66.114.53.48:80
    Dec 20 23:16:40 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:53020 from 66.114.53.48:80
    Dec 20 23:16:40 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:53021 from 66.114.53.48:80
    Dec 20 23:16:41 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:53025 from 66.114.53.48:80
    Dec 20 23:16:41 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:53026 from 66.114.53.48:80
    Dec 20 23:16:41 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:53023 from 66.114.53.48:80
    Dec 20 23:16:41 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:53022 from 66.114.53.48:80
    Dec 20 23:16:41 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:53019 from 66.114.53.48:80
    Dec 20 23:16:41 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:53027 from 66.114.53.48:80
    Dec 20 23:16:41 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:53078 from 66.114.53.48:80
    Dec 20 23:16:41 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:53079 from 66.114.53.48:80
    Dec 20 23:16:41 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:53080 from 66.114.53.48:80
    Dec 20 23:16:41 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:53081 from 66.114.53.48:80
    Dec 20 23:16:41 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:53082 from 66.114.53.48:80
    Dec 20 23:16:41 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:53083 from 66.114.53.48:80
    Dec 20 23:16:41 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:53084 from 66.114.53.48:80
    Dec 20 23:16:41 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:53085 from 66.114.53.48:80
    Dec 20 23:16:41 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:53086 from 66.114.53.48:80
    Dec 20 23:16:41 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:53087 from 66.114.53.48:80
    Dec 20 23:16:41 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:53088 from 66.114.53.48:80
    Dec 20 23:16:41 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:53089 from 66.114.53.48:80
    Dec 20 23:16:41 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:53090 from 66.114.53.48:80
    Dec 20 23:16:41 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:53091 from 66.114.53.48:80
    Dec 20 23:16:41 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:53092 from 66.114.53.48:80
    Dec 20 23:16:41 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:53093 from 66.114.53.48:80
    Dec 20 23:16:41 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:53094 from 66.114.53.48:80
    Dec 20 23:16:41 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:53095 from 66.114.53.48:80
    Dec 20 23:16:41 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:53096 from 66.114.53.48:80
    Dec 20 23:16:41 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:53097 from 66.114.53.48:80
    Dec 20 23:16:41 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:53098 from 66.114.53.48:80
    Dec 20 23:16:44 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:53077 from 66.114.53.48:80
    Dec 20 23:16:45 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:53081 from 66.114.53.48:80
    Dec 20 23:16:45 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:53085 from 66.114.53.48:80
    Dec 20 23:16:45 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:53095 from 66.114.53.48:80
    Dec 20 23:16:45 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:53083 from 66.114.53.48:80
    Dec 20 23:16:45 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:53089 from 66.114.53.48:80
    Dec 20 23:16:45 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:53080 from 66.114.53.48:80
    Dec 20 23:16:45 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:53092 from 66.114.53.48:80
    Dec 20 23:16:45 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:53090 from 66.114.53.48:80
    Dec 20 23:16:45 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:53088 from 66.114.53.48:80
    Dec 20 23:16:45 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:53096 from 66.114.53.48:80
    Dec 20 23:16:45 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:53078 from 66.114.53.48:80
    Dec 20 23:16:45 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:53097 from 66.114.53.48:80
    Dec 20 23:16:45 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:53084 from 66.114.53.48:80
    Dec 20 23:16:45 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:53082 from 66.114.53.48:80
    Dec 20 23:16:45 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:53091 from 66.114.53.48:80
    Dec 20 23:16:45 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:53087 from 66.114.53.48:80
    Dec 20 23:16:45 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:53098 from 66.114.53.48:80
    Dec 20 23:16:46 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:53079 from 66.114.53.48:80
    Dec 20 23:16:46 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:53086 from 66.114.53.48:80
    Dec 20 23:16:46 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:53093 from 66.114.53.48:80
    Dec 20 23:16:46 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:53094 from 66.114.53.48:80
    Dec 20 23:16:50 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:53077 from 66.114.53.48:80
    Dec 20 23:16:51 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:53081 from 66.114.53.48:80
    Dec 20 23:16:51 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:53083 from 66.114.53.48:80
    Dec 20 23:16:51 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:53085 from 66.114.53.48:80
    Dec 20 23:16:51 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:53095 from 66.114.53.48:80
    Dec 20 23:16:51 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:53089 from 66.114.53.48:80
    Dec 20 23:16:51 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:53080 from 66.114.53.48:80
    Dec 20 23:16:51 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:53092 from 66.114.53.48:80
    Dec 20 23:16:51 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:53090 from 66.114.53.48:80
    Dec 20 23:16:51 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:53088 from 66.114.53.48:80
    Dec 20 23:16:51 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:53096 from 66.114.53.48:80
    Dec 20 23:16:51 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:53078 from 66.114.53.48:80
    Dec 20 23:16:51 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:53084 from 66.114.53.48:80
    Dec 20 23:16:51 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:53097 from 66.114.53.48:80
    Dec 20 23:16:51 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:53082 from 66.114.53.48:80
    Dec 20 23:16:51 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:53087 from 66.114.53.48:80
    Dec 20 23:16:51 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:53091 from 66.114.53.48:80
    Dec 20 23:16:52 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:53098 from 66.114.53.48:80
    Dec 20 23:16:52 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:53079 from 66.114.53.48:80
    Dec 20 23:16:52 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:53086 from 66.114.53.48:80
    Dec 20 23:16:52 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:53093 from 66.114.53.48:80
    Dec 20 23:16:52 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:53094 from 66.114.53.48:80
    Dec 20 23:17:02 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:53077 from 66.114.53.48:80
    Dec 20 23:17:03 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:53081 from 66.114.53.48:80
    Dec 20 23:17:03 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:53085 from 66.114.53.48:80
    Dec 20 23:17:03 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:53095 from 66.114.53.48:80
    Dec 20 23:17:03 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:53083 from 66.114.53.48:80
    Dec 20 23:17:03 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:53089 from 66.114.53.48:80
    Dec 20 23:17:03 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:53080 from 66.114.53.48:80
    Dec 20 23:17:03 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:53092 from 66.114.53.48:80
    Dec 20 23:17:03 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:53090 from 66.114.53.48:80
    Dec 20 23:17:03 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:53088 from 66.114.53.48:80
    Dec 20 23:17:03 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:53096 from 66.114.53.48:80
    Dec 20 23:17:03 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:53078 from 66.114.53.48:80
    Dec 20 23:17:03 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:53084 from 66.114.53.48:80
    Dec 20 23:17:03 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:53082 from 66.114.53.48:80
    Dec 20 23:17:03 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:53097 from 66.114.53.48:80
    Dec 20 23:17:04 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:53087 from 66.114.53.48:80
    Dec 20 23:17:04 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:53091 from 66.114.53.48:80
    Dec 20 23:17:04 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:53098 from 66.114.53.48:80
    Dec 20 23:17:04 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:53079 from 66.114.53.48:80
    Dec 20 23:17:04 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:53086 from 66.114.53.48:80
    Dec 20 23:17:04 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:53094 from 66.114.53.48:80
    Dec 20 23:17:04 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:53093 from 66.114.53.48:80
    Dec 20 23:37:58 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:53642 from 195.24.233.53:80
    Dec 20 23:38:02 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:53642 from 195.24.233.53:80
    Dec 20 23:38:08 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:53642 from 195.24.233.53:80
    Dec 20 23:38:20 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:53642 from 195.24.233.53:80
    Dec 20 23:38:44 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:53642 from 195.24.233.53:80
    Dec 20 23:39:10 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:53669 from 208.109.107.127:80
    Dec 20 23:39:10 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:53676 from 208.109.107.127:80
    Dec 20 23:39:10 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:53677 from 208.109.107.127:80
    Dec 20 23:39:10 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:53678 from 208.109.107.127:80
    Dec 20 23:39:11 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:53669 from 208.109.107.127:80
    Dec 20 23:39:13 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:53678 from 208.109.107.127:80
    Dec 20 23:39:13 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:53674 from 208.109.107.127:80
    Dec 20 23:39:14 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:53677 from 208.109.107.127:80
    Dec 20 23:39:14 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:53676 from 208.109.107.127:80
    Dec 20 23:39:16 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:53669 from 208.109.107.127:80
    Dec 20 23:39:19 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:53678 from 208.109.107.127:80
    Dec 20 23:39:19 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:53674 from 208.109.107.127:80
    Dec 20 23:39:20 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:53677 from 208.109.107.127:80
    Dec 20 23:39:20 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:53676 from 208.109.107.127:80
    Dec 20 23:39:28 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:53669 from 208.109.107.127:80
    Dec 20 23:39:31 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:53678 from 208.109.107.127:80
    Dec 20 23:39:31 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:53674 from 208.109.107.127:80
    Dec 20 23:39:32 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:53677 from 208.109.107.127:80
    Dec 20 23:39:32 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:53676 from 208.109.107.127:80
    Dec 20 23:39:32 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:53642 from 195.24.233.53:80
    Dec 20 23:39:53 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:53669 from 208.109.107.127:80
    Dec 20 23:39:55 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:53678 from 208.109.107.127:80
    Dec 20 23:39:55 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:53674 from 208.109.107.127:80
    Dec 20 23:39:56 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:53677 from 208.109.107.127:80
    Dec 20 23:39:56 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:53676 from 208.109.107.127:80
    Dec 20 23:40:41 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:53669 from 208.109.107.127:80
    Dec 20 23:40:43 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:53678 from 208.109.107.127:80
    Dec 20 23:40:44 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:53674 from 208.109.107.127:80
    Dec 20 23:40:44 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:53677 from 208.109.107.127:80
    Dec 20 23:40:44 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:53676 from 208.109.107.127:80
    Dec 20 23:58:08 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:53817 from 209.85.225.113:80
    Dec 20 23:58:08 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:53817 from 209.85.225.113:80
    Dec 20 23:58:10 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:53817 from 209.85.225.113:80
    Dec 20 23:58:12 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:53817 from 209.85.225.113:80
    Dec 20 23:58:17 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:53817 from 209.85.225.113:80
    Dec 21 00:01:11 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:53919 from 208.69.36.230:80
    Dec 21 00:01:14 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:53919 from 208.69.36.230:80
    Dec 21 00:01:20 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:53919 from 208.69.36.230:80
    Dec 21 00:01:32 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:53919 from 208.69.36.230:80
    Dec 21 00:11:48 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:53967 from 208.69.36.231:80
    Dec 21 00:11:51 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:53967 from 208.69.36.231:80
    Dec 21 00:11:57 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:53967 from 208.69.36.231:80
    Dec 21 00:12:09 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:53967 from 208.69.36.231:80
    Dec 21 00:25:14 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:54092 from 209.85.225.100:80
    Dec 21 00:25:15 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:54092 from 209.85.225.100:80
    Dec 21 00:25:15 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:54092 from 209.85.225.100:80
    Dec 21 00:25:17 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:54092 from 209.85.225.100:80
    Dec 21 00:25:19 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:54092 from 209.85.225.100:80
    Dec 21 00:25:24 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:54092 from 209.85.225.100:80
    Dec 21 00:26:42 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:54106 from 216.119.110.211:80
    Dec 21 00:26:44 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:54106 from 216.119.110.211:80
    Dec 21 00:26:51 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:54106 from 216.119.110.211:80
    Dec 21 00:29:43 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:54147 from 69.90.98.85:80
    Dec 21 00:29:46 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:54147 from 69.90.98.85:80
    Dec 21 00:29:52 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:54147 from 69.90.98.85:80
    Dec 21 00:30:04 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:54147 from 69.90.98.85:80
    Dec 21 23:58:12 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:56927 from 168.143.171.84:80
    In an attempt to keep this as short as I can, I'm just going to list the repeat hits.
    209.85.225.100 (Go Daddy - no reason for this to be on here, is there?) attempting to connect to 54458, 54459, 55509, etc. There are quite a few of these.
    Dec 22 05:26:48 abcd ipfw: 12190 Deny TCP 85.17.154.200:63777 192.168.1.xxx:22 in via en1 This one particularly disturbed me. Does it mean my computer was trying to connect to 85.17.154 from PORT 22?! That's not good, is it? What's more, I have Little Snitch, so I'm not really sure how this didn't pop up.
    Dec 22 21:43:41 abcd ipfw: 35000 Deny UDP 208.67.222.222:53 192.168.1.xxx:52910 in via en1
    Dec 22 21:43:41 abcd ipfw: 35000 Deny UDP 208.67.222.222:53 192.168.1.xxx:52910 in via en1
    Dec 22 21:47:18 abcd ipfw: Stealth Mode connection attempt to UDP 192.168.1.xxx:61905 from 192.168.1.xxx:53
    Dec 22 21:47:23 abcd ipfw: Stealth Mode connection attempt to UDP 192.168.1.xxx:49775 from 208.67.222.222:53
    Dec 22 21:55:47 abcd ipfw: Stealth Mode connection attempt to UDP 192.168.1.xxx:64315 from 192.168.1.xxx:53
    Dec 22 21:55:49 abcd ipfw: Stealth Mode connection attempt to UDP 192.168.1.xxx:62435 from 208.67.222.222:53
    Dec 22 22:58:08 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:59718 from 72.47.236.203:80
    Dec 22 22:58:12 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:59718 from 72.47.236.203:80
    Dec 22 22:58:18 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:59718 from 72.47.236.203:80
    Dec 22 22:58:30 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:59718 from 72.47.236.203:80
    Dec 22 22:58:54 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:59718 from 72.47.236.203:80
    Dec 22 22:59:42 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:59718 from 72.47.236.203:80
    Dec 22 23:02:39 abcd ipfw: 35000 Deny UDP 208.67.222.222:53 192.168.1.xxx:58538 in via en1
    Dec 22 23:02:39 abcd ipfw: 35000 Deny UDP 208.67.222.220:53 192.168.1.xxx:51316 in via en1
    Dec 22 21:47:18 abcd ipfw: Stealth Mode connection attempt to UDP 192.168.1.xxx:61905 from 192.168.1.xxx:53
    Dec 22 21:47:23 abcd ipfw: Stealth Mode connection attempt to UDP 192.168.1.xxx:49775 from 208.67.222.222:53
    Dec 22 21:55:47 abcd ipfw: Stealth Mode connection attempt to UDP 192.168.1.xxx:64315 from 192.168.1.xxx:53
    Dec 22 21:55:49 abcd ipfw: Stealth Mode connection attempt to UDP 192.168.1.xxx:62435 from 208.67.222.222:53
    Dec 22 22:58:08 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:59718 from 72.47.236.203:80
    Dec 22 22:58:12 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:59718 from 72.47.236.203:80
    Dec 22 22:58:18 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:59718 from 72.47.236.203:80
    Dec 22 22:58:30 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:59718 from 72.47.236.203:80
    Dec 22 22:58:54 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:59718 from 72.47.236.203:80
    Dec 22 22:59:42 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:59718 from 72.47.236.203:80
    Dec 22 23:02:39 abcd ipfw: 35000 Deny UDP 208.67.222.222:53 192.168.1.xxx:58538 in via en1
    Dec 22 23:02:39 abcd ipfw: 35000 Deny UDP 208.67.222.220:53 192.168.1.xxx:51316 in via en1
    Dec 23 21:28:47 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:60980 from 140.239.191.10:80
    Dec 23 21:28:47 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:60981 from 140.239.191.10:80
    Dec 23 21:28:47 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:60982 from 140.239.191.10:80
    Dec 23 21:28:47 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:60983 from 140.239.191.10:80
    Dec 23 21:28:47 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:60984 from 140.239.191.10:80
    Dec 23 21:28:48 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:60984 from 140.239.191.10:80
    Dec 23 21:28:48 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:60983 from 140.239.191.10:80
    Dec 23 21:28:48 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:60982 from 140.239.191.10:80
    Dec 23 21:28:48 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:60981 from 140.239.191.10:80
    Dec 23 21:28:48 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:60980 from 140.239.191.10:80
    Dec 23 21:28:50 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:60984 from 140.239.191.10:80
    Dec 23 21:28:50 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:60983 from 140.239.191.10:80
    Dec 23 21:28:50 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:60982 from 140.239.191.10:80
    Dec 23 21:28:50 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:60981 from 140.239.191.10:80
    Dec 23 21:28:50 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:60980 from 140.239.191.10:80
    Dec 23 21:28:54 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:60984 from 140.239.191.10:80 (Lots more of these)
    Dec 23 21:32:37 abcd ipfw: Stealth Mode connection attempt to UDP 192.168.1.xxx:51887 from 192.168.1.xxx:53
    Dec 23 23:26:13 abcd ipfw: Stealth Mode connection attempt to UDP 192.168.1.xxx:62632 from 192.168.1.xxx:53
    Dec 24 00:00:29 abcd ipfw: 10100 Deny TCP 212.18.195.102:16955 192.168.1.xxx:22 in via en1
    Dec 24 03:37:08 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:49322 from 208.69.36.231:80
    Dec 24 03:53:44 abcd ipfw: 12190 Deny TCP 66.230.207.58:54229 192.168.1.xxx:53 in via en1
    Dec 24 03:53:44 abcd ipfw: 12190 Deny TCP 66.230.207.58:54229 192.168.1.xxx:443 in via en1
    Dec 24 03:53:44 abcd ipfw: 12190 Deny TCP 66.230.207.58:54229 192.168.1.xxx:25 in via en1
    Dec 24 03:53:44 abcd ipfw: 12190 Deny TCP 66.230.207.58:54229 192.168.1.xxx:22 in via en1
    Dec 24 03:53:45 abcd ipfw: 12190 Deny TCP 66.230.207.58:54230 192.168.1.xxx:443 in via en1
    Dec 24 03:53:45 abcd ipfw: 12190 Deny TCP 66.230.207.58:54230 192.168.1.xxx:53 in via en1
    Dec 24 03:53:45 abcd ipfw: 12190 Deny TCP 66.230.207.58:54230 192.168.1.xxx:22 in via en1
    Dec 24 03:53:45 abcd ipfw: 12190 Deny TCP 66.230.207.58:54230 192.168.1.xxx:25 in via en1
    Dec 24 03:53:45 abcd ipfw: 12190 Deny TCP 66.230.207.58:54229 192.168.1.xxx:143 in via en1
    Dec 24 03:53:45 abcd ipfw: 12190 Deny TCP 66.230.207.58:54230 192.168.1.xxx:143 in via en1
    Dec 24 03:53:51 abcd ipfw: Stealth Mode connection attempt to UDP 192.168.1.xxx:53 from 66.230.207.58:54229
    Dec 24 03:53:52 abcd ipfw: Stealth Mode connection attempt to UDP 192.168.1.xxx:53 from 66.230.207.58:54230
    Dec 24 03:57:16 abcd ipfw: 12190 Deny TCP 66.230.207.58:44027 192.168.1.xxx:53 in via en1
    Dec 24 03:57:16 abcd ipfw: 12190 Deny TCP 66.230.207.58:44028 192.168.1.xxx:53 in via en1
    Dec 24 03:57:16 abcd ipfw: Stealth Mode connection attempt to UDP 192.168.1.xxx:53 from 66.230.207.58:44027
    Dec 24 03:57:17 abcd ipfw: Stealth Mode connection attempt to UDP 192.168.1.xxx:53 from 66.230.207.58:44028
    Dec 24 04:03:06 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:49397 from 87.230.55.47:80
    Dec 24 04:03:10 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:49397 from 87.230.55.47:80
    Dec 24 04:03:16 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:49397 from 87.230.55.47:80
    Dec 24 04:03:18 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:49401 from 87.230.55.47:80
    Dec 24 04:03:22 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:49401 from 87.230.55.47:80
    Dec 24 04:03:28 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:49401 from 87.230.55.47:80
    Dec 24 04:03:28 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:49397 from 87.230.55.47:80
    Dec 24 04:03:39 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:49403 from 87.230.55.47:80
    Dec 24 04:03:40 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:49401 from 87.230.55.47:80
    Dec 24 04:03:42 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:49403 from 87.230.55.47:80
    Dec 24 04:03:43 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:49405 from 87.230.55.47:80
    Dec 24 04:03:48 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:49405 from 87.230.55.47:80
    Dec 24 04:03:48 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:49403 from 87.230.55.47:80
    Dec 24 04:03:52 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:49397 from 87.230.55.47:80
    Dec 24 04:03:54 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:49405 from 87.230.55.47:80
    Dec 24 04:04:00 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:49407 from 87.230.55.47:80
    Dec 24 04:04:00 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:49403 from 87.230.55.47:80
    Dec 24 04:04:04 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:49407 from 87.230.55.47:80
    Dec 24 04:04:04 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:49401 from 87.230.55.47:80
    Dec 24 04:04:06 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:49405 from 87.230.55.47:80
    Dec 24 04:04:07 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:49410 from 87.230.55.47:80
    Dec 24 04:04:10 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:49407 from 87.230.55.47:80
    Dec 24 04:04:10 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:49410 from 87.230.55.47:80
    Dec 24 04:04:16 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:49410 from 87.230.55.47:80
    Dec 24 04:04:22 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:49407 from 87.230.55.47:80
    Dec 24 04:04:25 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:49403 from 87.230.55.47:80
    Dec 24 04:04:28 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:49410 from 87.230.55.47:80
    Dec 24 04:04:30 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:49405 from 87.230.55.47:80
    Dec 24 04:04:33 abcd ipfw: Stealth Mode connection attempt to TCP 192.168.1.xxx:49414 from 87.230.55.47:80
    It keeps going on and on. Here's a Netstat:
    NETSTAT:
    Active Internet connections (including servers)
    Proto Recv-Q Send-Q  Local Address          Foreign Address        (state)
    tcp4       0      0  192.168.1.xxx.54159    209.85.225.101.80      ESTABLISHED
    tcp4       0      0  192.168.1.xxx.54158    209.85.225.101.80      ESTABLISHED
    tcp4       0      0  192.168.1.xxx.54157    209.85.225.100.80      ESTABLISHED
    tcp4       0      0  192.168.1.xxx.54156    209.85.225.100.80      ESTABLISHED
    tcp4       0      0  192.168.1.xxx.54155    209.85.225.100.80      ESTABLISHED
    tcp4       0      0  192.168.1.xxx.54154    209.85.225.100.80      ESTABLISHED
    tcp4       0      0  192.168.1.xxx.54153    209.85.225.101.80      ESTABLISHED
    tcp4       0      0  192.168.1.xxx.54152    209.85.225.101.80      ESTABLISHED
    tcp4       0      0  192.168.1.xxx.54151    209.85.225.101.80      ESTABLISHED
    tcp4       0      0  192.168.1.xxx.54150    209.85.225.101.80      ESTABLISHED
    tcp4       0      0  192.168.1.xxx.54149    208.69.36.230.80       ESTABLISHED
    tcp4       0      0  192.168.1.xxx.54140    209.85.225.113.80      ESTABLISHED
    tcp4       0      0  192.168.1.xxx.54099    63.84.95.75.80         ESTABLISHED
    tcp4       0      0  192.168.1.xxx.54098    63.84.95.75.80         ESTABLISHED
    tcp4       0      0  192.168.1.xxx.54038    63.84.95.75.80         ESTABLISHED
    tcp4       0      0  192.168.1.xxx.54034    63.84.59.50.80         ESTABLISHED
    tcp4       0      0  192.168.1.xxx.54033    63.84.59.50.80         ESTABLISHED
    tcp4       0      0  127.0.0.1.1033         127.0.0.1.920          ESTABLISHED
    tcp4       0      0  127.0.0.1.920          127.0.0.1.1033         ESTABLISHED
    tcp4       0      0  .                    .                    CLOSED
    tcp4       0      0  127.0.0.1.631          .                    LISTEN
    tcp4       0      0  .                    .                    CLOSED
    tcp4       0      0  127.0.0.1.1033         127.0.0.1.1021         ESTABLISHED
    tcp4       0      0  127.0.0.1.1021         127.0.0.1.1033         ESTABLISHED
    tcp4       0      0  127.0.0.1.1033         .                    LISTEN
    udp4       0      0  *.5353                 .                    
    udp4       0      0  .                    .                    
    udp4       0      0  .                    .                    
    udp4       0      0  *.631                  .                    
    udp4       0      0  .                    .                    
    udp4       0      0  127.0.0.1.49164        127.0.0.1.1022         
    udp4       0      0  127.0.0.1.49163        127.0.0.1.1022         
    udp4       0      0  127.0.0.1.1022         .                    
    udp4       0      0  127.0.0.1.49162        127.0.0.1.1023         
    udp4       0      0  127.0.0.1.1023         .                    
    udp4       0      0  192.168.1.85.123       .                    
    udp6       0      0  fe80:5::214:51ff.123   .                    
    udp4       0      0  127.0.0.1.123          .                    
    udp6       0      0  fe80:1::1.123          .                    
    udp6       0      0  ::1.123                .                    
    udp6       0      0  *.123                  .                    
    udp4       0      0  *.123                  .                    
    udp6       0      0  *.5353                 .                    
    udp4       0      0  *.5353                 .                    
    udp4       0      0  127.0.0.1.1033         .                    
    icm6       0      0  .                    .      
    63.84.59.50 is blacklisted as are some others - can't remember exactly what they are. I got a little discouraged and stopped checking all the IPs. Okay, so here's what I've done: Ran Clam (clean results), ran MacScan and found 1 tracking cookie that I removed, reconfigured Little Snitch and blocked the majority of the IPs. Oh - how do you manually block an IP range from the firewall? I can't figure that out.
    OH - one more thing that I thought was really strange: I was poking around in Terminal and ran the who command just out of curiosity.
    17:49 up 13:20, 3 users, load averages: 0.18 0.24 0.29
    USER TTY FROM LOGIN@ IDLE WHAT
    janed console - 13:35 4:13 -
    janed p1 - 17:49 - w
    janed p2 - 13:51 3:56 -
    Let's pretend my user name name is janedoe. Why would it only show janed? There IS no user named janed. So I tried to investigate more:
    abcd:~ abcd$ whoami
    abcd
    abcd:~ janedoe$ who
    janed console Dec 24 13:35
    janed ttyp1 Dec 24 17:49
    janed ttyp2 Dec 24 13:51
    I'm really hoping this is just a fluke. I'm sorry this is so long, but I'm desperate here. I appreciate any input that you guys can give me! Many thanks.

    Hi warren.peace, and a warm welcome to the forums!
    A couple of spam emails bounced back to me that had originated from my account. The headers indicated that it was coming from a 10.103.197.1. I ran a traceroute and came up with nothing.
    Not to worry on that one, many Spammers fake//spoof the IP to get it delivered by returning it!
    I don't understand why they're trying to connect to the specific ports - I couldn't find any info on most of the ports
    I'm on Dial-up & get thousands of attempts some days
    Run this on some of the ports you're worried about, click on SG security scan: port 51335 here for instance...
    http://www.speedguide.net/port.php?port=51335&print=friendly
    Dec 22 05:26:48 abcd ipfw: 12190 Deny TCP 85.17.154.200:63777 192.168.1.xxx:22 in via en1 This one particularly disturbed me. Does it mean my computer was trying to connect to 85.17.154 from PORT 22?! That's not good, is it? What's more, I have Little Snitch, so I'm not really sure how this didn't pop up.
    No, it means 85.17.154.200...
    ** Registrant:
    Trends Yaz�l�m
    Cemal Pa�a Mahallesi Bahar Caddesi Ne�e Apartman�
    alt� No : 3/A
    Adana,
    T�rkiye
    Was trying to see if they could connect to you by ftp. Little Snitch is great.
    208.67.222.222 is OpenDNS, no worry really.
    On the janed thing, what do these 2 report in terminal...
    w
    who

  • Snow Leopard & IPFW logging

    Hello,
    Just wondering if IPFW logging is broken in 10.6. I'm using my own IPFW firewall since 10.5 and I noticed that after the 10.6 upgrade, IPFW is still working but doesn't log anything anymore. I noticed that the /etc/syslog seems to have changed at some point. Here's an extract from the backed up one that was working on 10.5:
    install.* /var/log/install.log
    install.* @127.0.0.1:32376
    local0.* /var/log/ipfw.log
    Now in 10.6 this looks like this:
    install.* /var/log/install.log
    install.* @127.0.0.1:32376
    local0.* /var/log/appfirewall.log
    local1.* /var/log/ipfw.log
    And I haven't changed that because then I would have backed it up. So for instance my SSH rule looks like this:
    # Allow SSH inbound
    add 00700 set 3 count log tcp from any to any dst-port 22 in setup
    add 00701 set 3 allow tcp from any to any dst-port 22 in setup keep-state
    But my ipfw.log is exactly 0 bytes long and empty... and I definitely get hits on the rules. Here an extract form 'ipfw show':
    00700 2 104 count log logamount 100 tcp from any to any dst-port 22 in setup
    00701 1888 250506 allow tcp from any to any dst-port 22 in setup keep-state
    And yes, the appfirewall.log is also empty which seems to have now taken over the local0 log facility... (the App firewall is not enabled)
    Any help is appreciated.
    Thanks!
    Frank

    piknyc wrote:
    I had the same problem and can't remember exactly what I did to fix it but I think this was it.
    I added the below to /etc/syslog.conf and restarted:
    put this at the top
    !ipfw
    this at the bottom
    \. /var/log/ipfw.log
    This had strange effects in snow leopard. It had no effect on the output of appfirewall.log, but now ipfw.log fills up with everything.
    All i want is a clean logfile with my ipfw logs not spammed by the appfirewall. I've tried changing /usr/libexec/ApplicationFirewall/com.apple.alf.plist loggingenabled key to 0 and restarting but it had no effect.

  • Help with getting values from request. Very Strange!!

    Hello,
    My very strange problem is the following.
    I have created three dynamic list boxes. When the user select
    the first list box, the second becomes populated with stuff
    from a database. The third becomes populated when the second
    is selected. Now, I have used hidden values in order for
    me to get the selected value from the first listbox. The
    following code is my first listbox:
    <SELECT NAME="resources" onChange="document.hiddenform.hiddenObject.value = this.option [this.selectedIndex].value; document.hiddenform.submit();">
    <OPTION VALUE =""> Resource</OPTION>
    <OPTION VALUE ="soil"> Soil </OPTION>
    <OPTION VALUE ="water"> Water </OPTION>
    <OPTION VALUE ="air"> Air </OPTION>
    <OPTION VALUE ="plants"> Plants </OPTION>
    <OPTION VALUE ="animals"> Animals </OPTION>
    </SELECT>
    I use the getRequest method to get the value of hiddenObject.
    At this time I am able to get the value of hiddenObject to populate
    the second list box.
    But, when the user selects an item from the second list box
    and the second form is also submitted,
    I lose the value of hiddenObject. Why is this??
    The code to populate my second listbox is the following:
    <SELECT NAME ="res_categories" onChange="document.hiddenform2.hiddenObject2.value = this.options[this.selectedIndex].value; document.hiddenform2.submit(); ">
    <OPTION VALUE ="" SELECTED> Category</OPTION>
    Here I access a result set to populate the list box.
    Please help!!

    Form parameters are request-scoped, hence the request.getParameter("hiddenObject"); call after the submission of the second form returns a null value because the hiddenObject parameter does not exist within the second request.
    A solution would be to add a hiddenObject field to your second form and alter the onChange event for res_categories to read
    document.hiddenform2.hiddenObject.value=document.1stvisibleformname.resources.option[document.1stvisibleformname.resources.selectedIndex].value;
    document.hiddenform2.hiddenObject2.value = this.options[this.selectedIndex].value;
    document.hiddenform2.submit();You will then come across a similar problem with your third drop-down if indeed you need to resubmit the form...
    A far better approach would be to create a session scoped bean, and a servlet to handle these requests. Then when the servlet is called, it would set the value of the bean property, thus making it available for this request, and all subsequent requests within the current session. This approach would eliminate the need for the clunky javascript, making your application far more stable.

  • How can I buy films in languages other than German in Germany? Quite disappointed, i would line to watch films in Original language and not dubbed in strange ways...

    How can I buy films in languages other than German in Germany? Quite disappointed, i would like
    to watch films in Original language and not dubbed in strange ways...

    You are at the mercy of the content owners/copyright holders. They decide what the Apple can sell in each iTS.
    MJ

  • I am facing a strange problem on new iphone 5 that I bought last week. The maps app and the places in photo gallery shows the pin and my location, however there is no information of locations. Tried to close the apps, phone restart, reset etc. Please help

    I am facing a strange problem on new iphone 5 that I bought last week. The maps app and the places in photo gallery shows the pin and my location, however there is no information of locations. Tried to close the apps, phone restart, reset etc. I am accessing it via strong wireless connection and it works fine on other devices. Please help.

    zapgrap wrote:
    there is no information of locations.
    Then no information exists.  Use the Report a Problem button within the app to report it.

  • Strange discrepancy in report painter

    Hi everyone,
    I've designed a report painter with all the respective columns & formulas intact but at the Grand Total col (summation of all the sub-totals), the figure doesn't tally with all the sub-totals. All sub-totals have been added correctly but when they are added up to the Grand Total, the fig doesn't tie.
    Any clues? Have I missed out something?

    Hi Andrew,
    I've checked the sub-totals and apparently, when i double click on a sub-total to drill down to line item lvl, the fig doesn't seem to tie in with what I see in the report painter report. It's real strange that the correct fig appears upon drilling down to line item level but at a higher level, the fig isn't right. It's short of a fig which is in relation to another column.
    I've double checked the formula at the sub-total col and all the cols in the formula are present. This is the bizarre thing which I've been trying to resolve for the past few days.
    Best Regards,
    Ethan

  • Capturing DVCAM in FCP 6.0.2 and encountering strange capture behavior

    I have FCP 6.0.2 and OSX 10.5.2 and QT 7.3.1. I have been capturing several DVCAM cassettes using my Sony DSR-20 deck. Although I have done this countless times before in earlier versions of FCP, I am encountering some strange repetitive behavior. I am capturing 30 minute clips one at a time. When I use batch capture it will cue the tape up properly to the in point...and then start capturing until it gets to about 10-12 minutes in, and then capture unexpectedly stops, no dialogue box, the tape rewinds and starts capturing again from the original in point. On this second capture, the tape sails past the 10 minute mark and keeps going to the end of the 30 minute clip. It then stops, gives me the dialogue box that it has successfully captured. And it has.
    But every DVCAM tape I captured today exhibited the same behavior. Capture would be successful until about about 10 minutes in, then FCP aborts (no dropped frame message, no dialogue box) rewinds the tape back to the in point, tries again, and this time succeeds with the second pass capturing the entire clip. Note at the 10 minute mark there is no scene change or no camera start/stop.
    Have other users experienced this issue? And if so, is there a workaround or a possible patch forthcoming from FCP?
    Many thanks,
    John

    Yes, each tape has an in and out point defined. In my 6 years of editing with Final Cut and DVCAM tapes I've never encountered this issue before in the capturing process until now. I will have to see in future weeks with other captures whether this is an on-going issue or not, but at least I can capture for now.

  • Strange green lines with ATI 4850 iMac in Aperture, then crash.

    Well, I have been running my iMac, 3GHZ, ATI 4850 for about a week now. I have had 2 lockups in OSX, 1 in boot camp and 1 graphics crash.
    In OSX, all the crashes/lock-ups happen after I get these strange green lines, artifacts, that run across part of my screen. They change in length but generally always run horizontal. I can seem to find a way to post pictures here, but I have a couple screen grabs here:
    http://atothe420k.blogspot.com/
    Since I have to power off in the middle of Aperture, I am also getting corrupt databases, which take forever to rebuild.

    Well, I called into Apple Care, after my machine crashed again twice today, once in a web browser and once under EveOnline. The person said to download and use some fan control software. It installed, but didn't do much, couldn't get it to change fan speed or anything else.
    I installed iStatPro, which is great, and kept checking the temp of the ATI card, it would crash when the temp was up around 65-70 degrees C. Not sure if that is high or not.

  • Strange keyboard behavior after OS 4.2.1 upgrade

    When typing (at least, so far, in Safari) the keyboard will randomly (or so it seems) retract after typing a letter, instead of that letter being registered in the text box. It's necessary to re-locate the insertion point back in the text box to bring the keyboard back. And when I do, then the caps lock is on even though it wasn't before. This happens every few characters, but unpredictably.

    I'm getting this too. Been looking all over the Internet to find other people with the same problem.
    Its very annoying, and I'm not touching any other part of the screen - it does exactly what the OP describes, and it seems to do it all the time, when I'm typing. Only noticed it in safari because that is all I type in, and strangely enough it is not happening as I type this, and when it does happen i make sure the webpages are fully loaded. Very strange and very frustrating
    I'm also finding that rss feeds aren't updating, but thats a different problem.

  • K7N2 Delta ILSR Strange network problems

    K7N2 Delta ILSR
    2500+ AMD Barton
    Radeon 9600 PRO
    Windows XP
    Hi there,
    My network was working fine yesterday but now whenever I plug a cable into the onboard network card, my computer starts having these strange flucuations...Every few seconds the CPU usage jumps from 0% to about 50% which causes the system to freeze for a second, making it a real pain to do anything.
    Does anyone have any idea whats causing this?
    Thanks,
    Shim

    Quote
    Originally posted by deftonie
    The kingston memory I have is on the memory compatibility list.
    kingston removed k7n2 from their supported list.
    kingston is not on the Good Memory Choices for ALL K7N2 nF2 released boards
    for some reason msi have not removed kingston from their supported list.
    Quote
    Originally posted by pseudemys
    So (and I'm addressing the question in particular to Raven): shoud i wait for a some kinda accident, crash, whatever sooner or later? I'm really scared about such things. You know... everything seems ok and then, suddenly, a nasty surprise. Which is the problem with kingston and k7n2 series? Further, I'd like to buy another 512 M stick and honestly it seems more sensible to me to mount two equal sticks. And I feel somewhat stuck...
    a memory can be incompatible but still work.
    alot of people buy any memory they can and throw in and it may work.
    but it can start crashing after installing some program or updating bios or drivers.
    thats the reason i posted the memtest program.
    worry about a crash....no reason for that as you self said memtest reported no errors prime95 no errors and doom3 worked good.
    kingston uses many different chips on their memory and its those chips that is the problem.
    one guy found out that on the specific memory he bought kingston used 3 different chips on.
    only 1 of them worked good on k7n2.
    so a 33% chans of success in getting a good module is considered bad.
    so write down the numbers on the chips and take it with you to the store and compare it to the memories they got.

Maybe you are looking for

  • ORA-01017: invalid username/password; logon denied FOR SYS USER

    Hello, I was usually login through the same password for sys user to log on to the database as sysdba, but last time i used " / as sysdba" to connect using local system administrative account which is connected very well and still connecting in the s

  • Minimum order quantity ignored when past due

    SAP Business One 8.81 PL09 When running MRP for an item, the Minimum Order Quantity is ignored if an item is past due, meaning, the lead time makes it impossible to meet current requirements on time. From what I read, this appears to be by design in

  • Bug? Deploy RPM created with Alien

    Hello, I use ZLM 7.2. I try to deploy SAPGui to SLED 10 SP2 Workstations. I created a custom RPM with Alien. Code: tar zcvf sapgui.tgz /opt/sapgui alien --description="Custome SAPGui 7.10.4" --version=7 -r sapgui.tgz When I check my rpm with Code: rp

  • How to install D2K 6i on REd Hat LInux?

    How to install D2K 6i on REd Hat LInux version 7.3? I have .tar file/

  • Can we use the  iPhone 4 in Israel?

    Hi. I have an iPhone 4 through Verizon; can I take it to Israel and use it there? Thanks.