[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

under attack :-)



For the last few days, I've had hundreds of entries like the following in
/var/log/syslog. I'm not really worried because my firewall seems to be
rejecting everything, but I am curious if anyone knows what this is. The SRC=
changes, but otherwise the attack seems to be the same all the time. I tried
traceroute, whois, and nslookup and found the attack seems to be coming from
many locations - mostly in the US, but also from other places (like Australia).

Just in the past 6 hours, I counted 590 lines like this in the log.

BTW, I looked at the list archives and Google and found similar but not exactly
the same log entries.

TIA

//----------  from /var/log/syslog --------//

Sep 26 11:07:44 shlomo1 kernel: TCP Rejected IN=ppp0 OUT= MAC=
SRC=61.147.15.111 DST=192.117.204.140 LEN=48 TOS=0x00 PREC=0x00 TTL=104
ID=52540 DF PROTO=TCP SPT=2399 DPT=80 WINDOW=8760 RES=0x00 SYN URGP=0

Sep 26 11:07:49 shlomo1 kernel: TCP Rejected IN=ppp0 OUT= MAC=
SRC=61.147.15.111 DST=192.117.204.140 LEN=48 TOS=0x00 PREC=0x00 TTL=104
ID=53164 DF PROTO=TCP SPT=2399 DPT=80 WINDOW=8760 RES=0x00 SYN URGP=0

Sep 26 11:10:00 shlomo1 CROND[12978]: (root) CMD (   /sbin/rmmod -as)

Sep 26 11:11:02 shlomo1 pppd[12033]: rcvd [LCP EchoReq id=0x44 magic=0x26efc424]

Sep 26 11:11:02 shlomo1 pppd[12033]: sent [LCP EchoRep id=0x44 magic=0xf57144b8]

Sep 26 11:12:07 shlomo1 kernel: TCP Rejected IN=ppp0 OUT= MAC=
SRC=208.134.20.15 DST=192.117.204.140 LEN=44 TOS=0x00 PREC=0x00 TTL=108
ID=32631 DF PROTO=TCP SPT=31529 DPT=80 WINDOW=8192 RES=0x00 SYN URGP=0

Sep 26 11:12:10 shlomo1 kernel: TCP Rejected IN=ppp0 OUT= MAC=
SRC=208.134.20.15 DST=192.117.204.140 LEN=44 TOS=0x00 PREC=0x00 TTL=108
ID=22907 DF PROTO=TCP SPT=31529 DPT=80 WINDOW=8192 RES=0x00 SYN URGP=0

Sep 26 11:12:19 shlomo1 kernel: TCP Rejected IN=ppp0 OUT= MAC=
SRC=212.150.113.154 DST=192.117.204.140 LEN=48 TOS=0x00 PREC=0x00 TTL=120
ID=14013 DF PROTO=TCP SPT=2198 DPT=80 WINDOW=16384 RES=0x00 SYN URGP=0

Sep 26 11:12:22 shlomo1 kernel: TCP Rejected IN=ppp0 OUT= MAC=
SRC=212.150.113.154 DST=192.117.204.140 LEN=48 TOS=0x00 PREC=0x00 TTL=120
ID=14261 DF PROTO=TCP SPT=2198 DPT=80 WINDOW=16384 RES=0x00 SYN URGP=0

Sep 26 11:16:02 shlomo1 pppd[12033]: rcvd [LCP EchoReq id=0x45 magic=0x26efc424]

Sep 26 11:16:02 shlomo1 pppd[12033]: sent [LCP EchoRep id=0x45 magic=0xf57144b8]

Sep 26 11:20:00 shlomo1 CROND[12981]: (root) CMD (   /sbin/rmmod -as)

Sep 26 11:21:02 shlomo1 pppd[12033]: rcvd [LCP EchoReq id=0x46 magic=0x26efc424]

Sep 26 11:21:02 shlomo1 pppd[12033]: sent [LCP EchoRep id=0x46 magic=0xf57144b8]

Sep 26 11:21:35 shlomo1 kernel: TCP Rejected IN=ppp0 OUT= MAC= SRC=192.1.99.1
DST=192.117.204.140 LEN=48 TOS=0x00 PREC=0x00 TTL=111 ID=48012 DF PROTO=TCP
SPT=3793 DPT=80 WINDOW=16384 RES=0x00 SYN URGP=0

Sep 26 11:21:38 shlomo1 kernel: TCP Rejected IN=ppp0 OUT= MAC= SRC=192.1.99.1
DST=192.117.204.140 LEN=48 TOS=0x00 PREC=0x00 TTL=111 ID=48337 DF PROTO=TCP
SPT=3793 DPT=80 WINDOW=16384 RES=0x00 SYN URGP=0

Sep 26 11:21:44 shlomo1 kernel: TCP Rejected IN=ppp0 OUT= MAC= SRC=192.1.99.1
DST=192.117.204.140 LEN=48 TOS=0x00 PREC=0x00 TTL=111 ID=48827 DF PROTO=TCP
SPT=3793 DPT=80 WINDOW=16384 RES=0x00 SYN URGP=0

Sep 26 11:26:02 shlomo1 pppd[12033]: rcvd [LCP EchoReq id=0x47 magic=0x26efc424]

//-------------------------
Shlomo Solomon
E-Mail: solomon@barak-online.net
http://come.to/shlomo.solomon
Date: 26-Sep-2001   Time: 11:39:08

Message sent by XFMail on a LINUX Mandrake 8.0 machine
//-------------------------


=================================================================
To unsubscribe, send mail to linux-il-request@linux.org.il with
the word "unsubscribe" in the message body, e.g., run the command
echo unsubscribe | mail linux-il-request@linux.org.il