[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: Is this my FW (was Re: whats this?)
- To: <solomon(at-nospam)barak-online.net>
- Subject: Re: Is this my FW (was Re: whats this?)
- From: Dani Arbel <darbel(at-nospam)techunix.technion.ac.il>
- Date: Mon, 6 Aug 2001 08:18:17 +0300 (IDT)
- Cc: ILUG <linux-il(at-nospam)linux.org.il>
- Delivered-To: linux.org.il-linux-il@linux.org.il
- In-Reply-To: <XFMail.20010806065305.solomon@barak-online.net>
- Sender: linux-il-bounce(at-nospam)cs.huji.ac.il
Shlomo,
You reject the syn packets, so you will never know what kind of traffic
you did not receive... Anyway, if you are rate limiting the logs, that
might be a syn attack you are blocking (unfotunatly, AFTER consuming your
internet connection bandwidth ...). If you are not rate limiting , then it
might be the worm hitting you.
note that the lines you saw people sending on the list to show the worm
fingerprints are from the webserver access.log , where the requests are
loged.
Dani
On Mon, 6 Aug 2001 solomon@barak-online.net wrote:
> > On Sun, 5 Aug 2001 18:48:06 +0300, Hetz Ben Hamo <hetz@kde.org> wrote:
> >
> >> I see this line in my log every few minutes - anyone knows whats this?
> >>
> >> 212.143.156.123 - - [05/Aug/2001:18:35:39 +0300] "GET
> >> /default.ida?XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
> >> XXXXXXXXXXXXXXXXXXXXXXX
> >> XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
> >> XXXXXXXXXXXXXXXXXXXX
> >> XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX%u9090%u6858%ucbd3%u7801%u9090%u6858%
> >> ucbd3%u7801%
> >> u9090%u6858%ucbd3%u7801%u9090%u9090%u8190%u00c3%u0003%u8b00%u531b%u53ff%u0078
> >> %u0000%u00=a
> >> HTTP/1.0" 404 271
>
> I feel a bit **left out** :-). I looked for something like this in my log and
> didn't find it. However, I did find thousands (no - I'm not exaggerating) of
> lines like the following. There are a great many SRC addresses here. Is this
> just my firewall doing a good job, or do I have somthing to worry about?
>
> TIA
>
> Aug 6 02:40:23 shlomo1 kernel: TCP Rejected IN=ppp0 OUT= MAC=
> SRC=61.182.248.44 DST=192.117.204.179 LEN=48 TOS=0x00 PREC=0x00 TTL=108
> ID=63129 DF PROTO=TCP SPT=4260 DPT=80 WINDOW=16384 RES=0x00 SYN URGP=0
> Aug 6 02:40:29 shlomo1 kernel: TCP Rejected IN=ppp0 OUT= MAC=
> SRC=151.200.116.84 DST=192.117.204.179 LEN=48 TOS=0x00 PREC=0x00 TTL=106
> ID=30804 DF PROTO=TCP SPT=3960 DPT=80 WINDOW=8760 RES=0x00 SYN URGP=0
> Aug 6 02:40:32 shlomo1 kernel: TCP Rejected IN=ppp0 OUT= MAC=
> SRC=61.182.248.44 DST=192.117.204.179 LEN=48 TOS=0x00 PREC=0x00 TTL=108
> ID=63811 DF PROTO=TCP SPT=4260 DPT=80 WINDOW=16384 RES=0x00 SYN URGP=0
> Aug 6 02:40:32 shlomo1 kernel: TCP Rejected IN=ppp0 OUT= MAC=
> SRC=151.200.116.84 DST=192.117.204.179 LEN=48 TOS=0x00 PREC=0x00 TTL=106
> ID=31124 DF PROTO=TCP SPT=3960 DPT=80 WINDOW=8760 RES=0x00 SYN URGP=0
> Aug 6 02:40:37 shlomo1 kernel: TCP Rejected IN=ppp0 OUT= MAC=
> SRC=151.200.116.84 DST=192.117.204.179 LEN=48 TOS=0x00 PREC=0x00 TTL=106
> ID=31564 DF PROTO=TCP SPT=3960 DPT=80 WINDOW=8760 RES=0x00 SYN URGP=0
> Aug 6 02:48:04 shlomo1 kernel: TCP Rejected IN=ppp0 OUT= MAC=
> SRC=203.76.34.233 DST=192.117.204.179 LEN=48 TOS=0x00 PREC=0x00 TTL=108
> ID=14458 DF PROTO=TCP SPT=3720 DPT=80 WINDOW=8760 RES=0x00 SYN URGP=0
> Aug 6 02:48:07 shlomo1 kernel: TCP Rejected IN=ppp0 OUT= MAC=
> SRC=203.76.34.233 DST=192.117.204.179 LEN=48 TOS=0x00 PREC=0x00 TTL=108
> ID=14745 DF PROTO=TCP SPT=3720 DPT=80 WINDOW=8760 RES=0x00 SYN URGP=0
> Aug 6 02:48:13 shlomo1 kernel: TCP Rejected IN=ppp0 OUT= MAC=
> SRC=203.76.34.233 DST=192.117.204.179 LEN=48 TOS=0x00 PREC=0x00 TTL=108
> ID=15260 DF PROTO=TCP SPT=3720 DPT=80 WINDOW=8760 RES=0x00 SYN URGP=0
>
> //-------------------------
> Shlomo Solomon
> E-Mail: solomon@barak-online.net
> http://come.to/shlomo.solomon
> Date: 06-Aug-2001 Time: 06:41:04
>
> Message sent by XFMail on a LINUX Mandrake 8.0 machine
> //-------------------------
>
>
> =================================================================
> To unsubscribe, send mail to linux-il-request@linux.org.il with
> the word "unsubscribe" in the message body, e.g., run the command
> echo unsubscribe | mail linux-il-request@linux.org.il
>
=================================================================
To unsubscribe, send mail to linux-il-request@linux.org.il with
the word "unsubscribe" in the message body, e.g., run the command
echo unsubscribe | mail linux-il-request@linux.org.il