[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: Is this my FW (was Re: whats this?)



Shlomo,
You reject the syn packets, so you will never know what kind of traffic
you did not receive... Anyway, if you are rate limiting the logs, that
might be a syn attack you are blocking (unfotunatly, AFTER consuming your
internet connection bandwidth ...). If you are not rate limiting , then it
might be the worm hitting you.
note that the lines you saw people sending on the list to show the worm
fingerprints are from the webserver access.log , where the requests are
loged.
Dani

On Mon, 6 Aug 2001 solomon@barak-online.net wrote:

> > On Sun, 5 Aug 2001 18:48:06 +0300, Hetz Ben Hamo <hetz@kde.org> wrote:
> >
> >> I see this line in my log every few minutes - anyone knows whats this?
> >>
> >> 212.143.156.123 - - [05/Aug/2001:18:35:39 +0300] "GET
> >> /default.ida?XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
> >> XXXXXXXXXXXXXXXXXXXXXXX
> >> XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
> >> XXXXXXXXXXXXXXXXXXXX
> >> XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX%u9090%u6858%ucbd3%u7801%u9090%u6858%
> >> ucbd3%u7801%
> >> u9090%u6858%ucbd3%u7801%u9090%u9090%u8190%u00c3%u0003%u8b00%u531b%u53ff%u0078
> >> %u0000%u00=a
> >>  HTTP/1.0" 404 271
>
> I feel a bit **left out** :-). I looked for something like this in my log and
> didn't find it. However, I did find thousands (no - I'm not exaggerating)  of
> lines like the following.  There are a great many SRC addresses here. Is this
> just my firewall doing a good job, or do I have somthing to worry about?
>
> TIA
>
> Aug  6 02:40:23 shlomo1 kernel: TCP Rejected IN=ppp0 OUT= MAC=
> SRC=61.182.248.44 DST=192.117.204.179 LEN=48 TOS=0x00 PREC=0x00 TTL=108
> ID=63129 DF PROTO=TCP SPT=4260 DPT=80 WINDOW=16384 RES=0x00 SYN URGP=0
> Aug  6 02:40:29 shlomo1 kernel: TCP Rejected IN=ppp0 OUT= MAC=
> SRC=151.200.116.84 DST=192.117.204.179 LEN=48 TOS=0x00 PREC=0x00 TTL=106
> ID=30804 DF PROTO=TCP SPT=3960 DPT=80 WINDOW=8760 RES=0x00 SYN URGP=0
> Aug  6 02:40:32 shlomo1 kernel: TCP Rejected IN=ppp0 OUT= MAC=
> SRC=61.182.248.44 DST=192.117.204.179 LEN=48 TOS=0x00 PREC=0x00 TTL=108
> ID=63811 DF PROTO=TCP SPT=4260 DPT=80 WINDOW=16384 RES=0x00 SYN URGP=0
> Aug  6 02:40:32 shlomo1 kernel: TCP Rejected IN=ppp0 OUT= MAC=
> SRC=151.200.116.84 DST=192.117.204.179 LEN=48 TOS=0x00 PREC=0x00 TTL=106
> ID=31124 DF PROTO=TCP SPT=3960 DPT=80 WINDOW=8760 RES=0x00 SYN URGP=0
> Aug  6 02:40:37 shlomo1 kernel: TCP Rejected IN=ppp0 OUT= MAC=
> SRC=151.200.116.84 DST=192.117.204.179 LEN=48 TOS=0x00 PREC=0x00 TTL=106
> ID=31564 DF PROTO=TCP SPT=3960 DPT=80 WINDOW=8760 RES=0x00 SYN URGP=0
> Aug  6 02:48:04 shlomo1 kernel: TCP Rejected IN=ppp0 OUT= MAC=
> SRC=203.76.34.233 DST=192.117.204.179 LEN=48 TOS=0x00 PREC=0x00 TTL=108
> ID=14458 DF PROTO=TCP SPT=3720 DPT=80 WINDOW=8760 RES=0x00 SYN URGP=0
> Aug  6 02:48:07 shlomo1 kernel: TCP Rejected IN=ppp0 OUT= MAC=
> SRC=203.76.34.233 DST=192.117.204.179 LEN=48 TOS=0x00 PREC=0x00 TTL=108
> ID=14745 DF PROTO=TCP SPT=3720 DPT=80 WINDOW=8760 RES=0x00 SYN URGP=0
> Aug  6 02:48:13 shlomo1 kernel: TCP Rejected IN=ppp0 OUT= MAC=
> SRC=203.76.34.233 DST=192.117.204.179 LEN=48 TOS=0x00 PREC=0x00 TTL=108
> ID=15260 DF PROTO=TCP SPT=3720 DPT=80 WINDOW=8760 RES=0x00 SYN URGP=0
>
> //-------------------------
> Shlomo Solomon
> E-Mail: solomon@barak-online.net
> http://come.to/shlomo.solomon
> Date: 06-Aug-2001   Time: 06:41:04
>
> Message sent by XFMail on a LINUX Mandrake 8.0 machine
> //-------------------------
>
>
> =================================================================
> To unsubscribe, send mail to linux-il-request@linux.org.il with
> the word "unsubscribe" in the message body, e.g., run the command
> echo unsubscribe | mail linux-il-request@linux.org.il
>


=================================================================
To unsubscribe, send mail to linux-il-request@linux.org.il with
the word "unsubscribe" in the message body, e.g., run the command
echo unsubscribe | mail linux-il-request@linux.org.il