[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
under attack :-)
- To: linux-il(at-nospam)cs.huji.ac.il
- Subject: under attack :-)
- From: solomon(at-nospam)barak-online.net
- Date: Wed, 26 Sep 2001 11:52:46 -0000 (UTC)
- Organization: Shlomo Solomon
- Sender: root(at-nospam)shlomo1.solomon
- Sender: linux-il-bounce(at-nospam)cs.huji.ac.il
For the last few days, I've had hundreds of entries like the following in
/var/log/syslog. I'm not really worried because my firewall seems to be
rejecting everything, but I am curious if anyone knows what this is. The SRC=
changes, but otherwise the attack seems to be the same all the time. I tried
traceroute, whois, and nslookup and found the attack seems to be coming from
many locations - mostly in the US, but also from other places (like Australia).
Just in the past 6 hours, I counted 590 lines like this in the log.
BTW, I looked at the list archives and Google and found similar but not exactly
the same log entries.
TIA
//---------- from /var/log/syslog --------//
Sep 26 11:07:44 shlomo1 kernel: TCP Rejected IN=ppp0 OUT= MAC=
SRC=61.147.15.111 DST=192.117.204.140 LEN=48 TOS=0x00 PREC=0x00 TTL=104
ID=52540 DF PROTO=TCP SPT=2399 DPT=80 WINDOW=8760 RES=0x00 SYN URGP=0
Sep 26 11:07:49 shlomo1 kernel: TCP Rejected IN=ppp0 OUT= MAC=
SRC=61.147.15.111 DST=192.117.204.140 LEN=48 TOS=0x00 PREC=0x00 TTL=104
ID=53164 DF PROTO=TCP SPT=2399 DPT=80 WINDOW=8760 RES=0x00 SYN URGP=0
Sep 26 11:10:00 shlomo1 CROND[12978]: (root) CMD ( /sbin/rmmod -as)
Sep 26 11:11:02 shlomo1 pppd[12033]: rcvd [LCP EchoReq id=0x44 magic=0x26efc424]
Sep 26 11:11:02 shlomo1 pppd[12033]: sent [LCP EchoRep id=0x44 magic=0xf57144b8]
Sep 26 11:12:07 shlomo1 kernel: TCP Rejected IN=ppp0 OUT= MAC=
SRC=208.134.20.15 DST=192.117.204.140 LEN=44 TOS=0x00 PREC=0x00 TTL=108
ID=32631 DF PROTO=TCP SPT=31529 DPT=80 WINDOW=8192 RES=0x00 SYN URGP=0
Sep 26 11:12:10 shlomo1 kernel: TCP Rejected IN=ppp0 OUT= MAC=
SRC=208.134.20.15 DST=192.117.204.140 LEN=44 TOS=0x00 PREC=0x00 TTL=108
ID=22907 DF PROTO=TCP SPT=31529 DPT=80 WINDOW=8192 RES=0x00 SYN URGP=0
Sep 26 11:12:19 shlomo1 kernel: TCP Rejected IN=ppp0 OUT= MAC=
SRC=212.150.113.154 DST=192.117.204.140 LEN=48 TOS=0x00 PREC=0x00 TTL=120
ID=14013 DF PROTO=TCP SPT=2198 DPT=80 WINDOW=16384 RES=0x00 SYN URGP=0
Sep 26 11:12:22 shlomo1 kernel: TCP Rejected IN=ppp0 OUT= MAC=
SRC=212.150.113.154 DST=192.117.204.140 LEN=48 TOS=0x00 PREC=0x00 TTL=120
ID=14261 DF PROTO=TCP SPT=2198 DPT=80 WINDOW=16384 RES=0x00 SYN URGP=0
Sep 26 11:16:02 shlomo1 pppd[12033]: rcvd [LCP EchoReq id=0x45 magic=0x26efc424]
Sep 26 11:16:02 shlomo1 pppd[12033]: sent [LCP EchoRep id=0x45 magic=0xf57144b8]
Sep 26 11:20:00 shlomo1 CROND[12981]: (root) CMD ( /sbin/rmmod -as)
Sep 26 11:21:02 shlomo1 pppd[12033]: rcvd [LCP EchoReq id=0x46 magic=0x26efc424]
Sep 26 11:21:02 shlomo1 pppd[12033]: sent [LCP EchoRep id=0x46 magic=0xf57144b8]
Sep 26 11:21:35 shlomo1 kernel: TCP Rejected IN=ppp0 OUT= MAC= SRC=192.1.99.1
DST=192.117.204.140 LEN=48 TOS=0x00 PREC=0x00 TTL=111 ID=48012 DF PROTO=TCP
SPT=3793 DPT=80 WINDOW=16384 RES=0x00 SYN URGP=0
Sep 26 11:21:38 shlomo1 kernel: TCP Rejected IN=ppp0 OUT= MAC= SRC=192.1.99.1
DST=192.117.204.140 LEN=48 TOS=0x00 PREC=0x00 TTL=111 ID=48337 DF PROTO=TCP
SPT=3793 DPT=80 WINDOW=16384 RES=0x00 SYN URGP=0
Sep 26 11:21:44 shlomo1 kernel: TCP Rejected IN=ppp0 OUT= MAC= SRC=192.1.99.1
DST=192.117.204.140 LEN=48 TOS=0x00 PREC=0x00 TTL=111 ID=48827 DF PROTO=TCP
SPT=3793 DPT=80 WINDOW=16384 RES=0x00 SYN URGP=0
Sep 26 11:26:02 shlomo1 pppd[12033]: rcvd [LCP EchoReq id=0x47 magic=0x26efc424]
//-------------------------
Shlomo Solomon
E-Mail: solomon@barak-online.net
http://come.to/shlomo.solomon
Date: 26-Sep-2001 Time: 11:39:08
Message sent by XFMail on a LINUX Mandrake 8.0 machine
//-------------------------
=================================================================
To unsubscribe, send mail to linux-il-request@linux.org.il with
the word "unsubscribe" in the message body, e.g., run the command
echo unsubscribe | mail linux-il-request@linux.org.il