[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: under attack :-)



Let's see.

TCP traffic to port 80. Hmm.

Lots of different IPs, but not so intensive as to look like an actual 
attack.

Hmm.

Welcome to the wonderful world dominated by IIS, which stood for 
Internet Information Security^H^H^H^H^H^Hrver.

Those are probably a combination of the various Code Red, Blue, Green, 
and Nimda, seeking to infect your machine, oblivious to the fact that 
you are not running IIS.

Yes, we are all affected.

            Shachar


solomon@barak-online.net wrote:

>For the last few days, I've had hundreds of entries like the following in
>/var/log/syslog. I'm not really worried because my firewall seems to be
>rejecting everything, but I am curious if anyone knows what this is. The SRC=
>changes, but otherwise the attack seems to be the same all the time. I tried
>traceroute, whois, and nslookup and found the attack seems to be coming from
>many locations - mostly in the US, but also from other places (like Australia).
>
>Just in the past 6 hours, I counted 590 lines like this in the log.
>
>BTW, I looked at the list archives and Google and found similar but not exactly
>the same log entries.
>
>TIA
>
>//----------  from /var/log/syslog --------//
>
>Sep 26 11:07:44 shlomo1 kernel: TCP Rejected IN=ppp0 OUT= MAC=
>SRC=61.147.15.111 DST=192.117.204.140 LEN=48 TOS=0x00 PREC=0x00 TTL=104
>ID=52540 DF PROTO=TCP SPT=2399 DPT=80 WINDOW=8760 RES=0x00 SYN URGP=0
>
>Sep 26 11:07:49 shlomo1 kernel: TCP Rejected IN=ppp0 OUT= MAC=
>SRC=61.147.15.111 DST=192.117.204.140 LEN=48 TOS=0x00 PREC=0x00 TTL=104
>ID=53164 DF PROTO=TCP SPT=2399 DPT=80 WINDOW=8760 RES=0x00 SYN URGP=0
>
>Sep 26 11:10:00 shlomo1 CROND[12978]: (root) CMD (   /sbin/rmmod -as)
>
>Sep 26 11:11:02 shlomo1 pppd[12033]: rcvd [LCP EchoReq id=0x44 magic=0x26efc424]
>
>Sep 26 11:11:02 shlomo1 pppd[12033]: sent [LCP EchoRep id=0x44 magic=0xf57144b8]
>
>Sep 26 11:12:07 shlomo1 kernel: TCP Rejected IN=ppp0 OUT= MAC=
>SRC=208.134.20.15 DST=192.117.204.140 LEN=44 TOS=0x00 PREC=0x00 TTL=108
>ID=32631 DF PROTO=TCP SPT=31529 DPT=80 WINDOW=8192 RES=0x00 SYN URGP=0
>
>Sep 26 11:12:10 shlomo1 kernel: TCP Rejected IN=ppp0 OUT= MAC=
>SRC=208.134.20.15 DST=192.117.204.140 LEN=44 TOS=0x00 PREC=0x00 TTL=108
>ID=22907 DF PROTO=TCP SPT=31529 DPT=80 WINDOW=8192 RES=0x00 SYN URGP=0
>
>Sep 26 11:12:19 shlomo1 kernel: TCP Rejected IN=ppp0 OUT= MAC=
>SRC=212.150.113.154 DST=192.117.204.140 LEN=48 TOS=0x00 PREC=0x00 TTL=120
>ID=14013 DF PROTO=TCP SPT=2198 DPT=80 WINDOW=16384 RES=0x00 SYN URGP=0
>
>Sep 26 11:12:22 shlomo1 kernel: TCP Rejected IN=ppp0 OUT= MAC=
>SRC=212.150.113.154 DST=192.117.204.140 LEN=48 TOS=0x00 PREC=0x00 TTL=120
>ID=14261 DF PROTO=TCP SPT=2198 DPT=80 WINDOW=16384 RES=0x00 SYN URGP=0
>
>Sep 26 11:16:02 shlomo1 pppd[12033]: rcvd [LCP EchoReq id=0x45 magic=0x26efc424]
>
>Sep 26 11:16:02 shlomo1 pppd[12033]: sent [LCP EchoRep id=0x45 magic=0xf57144b8]
>
>Sep 26 11:20:00 shlomo1 CROND[12981]: (root) CMD (   /sbin/rmmod -as)
>
>Sep 26 11:21:02 shlomo1 pppd[12033]: rcvd [LCP EchoReq id=0x46 magic=0x26efc424]
>
>Sep 26 11:21:02 shlomo1 pppd[12033]: sent [LCP EchoRep id=0x46 magic=0xf57144b8]
>
>Sep 26 11:21:35 shlomo1 kernel: TCP Rejected IN=ppp0 OUT= MAC= SRC=192.1.99.1
>DST=192.117.204.140 LEN=48 TOS=0x00 PREC=0x00 TTL=111 ID=48012 DF PROTO=TCP
>SPT=3793 DPT=80 WINDOW=16384 RES=0x00 SYN URGP=0
>
>Sep 26 11:21:38 shlomo1 kernel: TCP Rejected IN=ppp0 OUT= MAC= SRC=192.1.99.1
>DST=192.117.204.140 LEN=48 TOS=0x00 PREC=0x00 TTL=111 ID=48337 DF PROTO=TCP
>SPT=3793 DPT=80 WINDOW=16384 RES=0x00 SYN URGP=0
>
>Sep 26 11:21:44 shlomo1 kernel: TCP Rejected IN=ppp0 OUT= MAC= SRC=192.1.99.1
>DST=192.117.204.140 LEN=48 TOS=0x00 PREC=0x00 TTL=111 ID=48827 DF PROTO=TCP
>SPT=3793 DPT=80 WINDOW=16384 RES=0x00 SYN URGP=0
>
>Sep 26 11:26:02 shlomo1 pppd[12033]: rcvd [LCP EchoReq id=0x47 magic=0x26efc424]
>
>//-------------------------
>Shlomo Solomon
>E-Mail: solomon@barak-online.net
>http://come.to/shlomo.solomon
>Date: 26-Sep-2001   Time: 11:39:08
>
>Message sent by XFMail on a LINUX Mandrake 8.0 machine
>//-------------------------
>
>
>=================================================================
>To unsubscribe, send mail to linux-il-request@linux.org.il with
>the word "unsubscribe" in the message body, e.g., run the command
>echo unsubscribe | mail linux-il-request@linux.org.il
>
>
>




=================================================================
To unsubscribe, send mail to linux-il-request@linux.org.il with
the word "unsubscribe" in the message body, e.g., run the command
echo unsubscribe | mail linux-il-request@linux.org.il