[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
what attack is this ?
Hi
I need your help on this:
my firewall logs show someone (192.114.175.59:1117)
that sent udp packets to all our computers to
ports 22 and 5632.
i know port 22 is for ssh, but is it udp or tcp ?
i have no idea about port 5632 though.
anybody has an idea what he wanted to do ?
if scan, then scan what ?
do you think the packets are spoofed ?
dns lookup on the source gave nothing.
though the source ip answered ping, and only ping.
frame0 is my frame-relay interface.
here is a part of my log:
Oct 19 17:49:26 aristo kernel: IP fw-in deny frame0 UDP
192.114.175.59:1117 192.114.175.153:22 L=30 S=0x00 I=61466 F=0x0000
T=125
Oct 19 17:49:26 aristo kernel: IP fw-in deny frame0 UDP
192.114.175.59:1117 192.114.175.154:5632 L=30 S=0x00 I=61722 F=0x0000
T=125
Oct 19 17:49:26 aristo kernel: IP fw-in deny frame0 UDP
192.114.175.59:1117 192.114.175.154:22 L=30 S=0x00 I=61978 F=0x0000
T=125
Oct 19 17:49:26 aristo kernel: IP fw-in deny frame0 UDP
192.114.175.59:1117 192.114.175.155:5632 L=30 S=0x00 I=62234 F=0x0000
T=125
Oct 19 17:49:26 aristo kernel: IP fw-in deny frame0 UDP
192.114.175.59:1117 192.114.175.155:22 L=30 S=0x00 I=62490 F=0x0000
T=125
Oct 19 17:49:26 aristo kernel: IP fw-in deny frame0 UDP
192.114.175.59:1117 192.114.175.156:5632 L=30 S=0x00 I=62746 F=0x0000
T=125
Oct 19 17:49:26 aristo kernel: IP fw-in deny frame0 UDP
192.114.175.59:1117 192.114.175.156:22 L=30 S=0x00 I=63002 F=0x0000
T=125
Oct 19 17:49:26 aristo kernel: IP fw-in deny frame0 UDP
192.114.175.59:1117 192.114.175.157:5632 L=30 S=0x00 I=63258 F=0x0000
T=125
Oct 19 17:49:26 aristo kernel: IP fw-in deny frame0 UDP
192.114.175.59:1117 192.114.175.157:22 L=30 S=0x00 I=63514 F=0x0000
T=125
Oct 19 17:49:26 aristo kernel: IP fw-in deny frame0 UDP
192.114.175.59:1117 192.114.175.158:5632 L=30 S=0x00 I=63770 F=0x0000
T=125
Oct 19 17:49:26 aristo kernel: IP fw-in deny frame0 UDP
192.114.175.59:1117 192.114.175.158:22 L=30 S=0x00 I=64026 F=0x0000
T=125
Oct 19 17:49:26 aristo kernel: IP fw-in deny frame0 UDP
192.114.175.59:1117 192.114.175.159:5632 L=30 S=0x00 I=64282 F=0x0000
T=125
Oct 19 17:49:26 aristo kernel: IP fw-in deny frame0 UDP
192.114.175.59:1117 192.114.175.159:22 L=30 S=0x00 I=64538 F=0x0000
T=125
Oct 19 17:49:26 aristo kernel: IP fw-in deny frame0 UDP
192.114.175.59:1117 192.114.175.160:5632 L=30 S=0x00 I=64794 F=0x0000
T=125
Oct 19 17:49:26 aristo kernel: IP fw-in deny frame0 UDP
192.114.175.59:1117 192.114.175.160:22 L=30 S=0x00 I=65050 F=0x0000
T=125
Oct 19 17:49:26 aristo kernel: IP fw-in deny frame0 UDP
192.114.175.59:1117 192.114.175.161:5632 L=30 S=0x00 I=65306 F=0x0000
T=125
Oct 19 17:49:26 aristo kernel: IP fw-in deny frame0 UDP
192.114.175.59:1117 192.114.175.161:22 L=30 S=0x00 I=27 F=0x0000 T=125
Oct 19 17:49:26 aristo kernel: IP fw-in deny frame0 UDP
192.114.175.59:1117 192.114.175.162:5632 L=30 S=0x00 I=283 F=0x0000
T=125
Oct 19 17:49:26 aristo kernel: IP fw-in deny frame0 UDP
192.114.175.59:1117 192.114.175.162:22 L=30 S=0x00 I=539 F=0x0000 T=125
Oct 19 17:49:26 aristo kernel: IP fw-in deny frame0 UDP
192.114.175.59:1117 192.114.175.163:5632 L=30 S=0x00 I=795 F=0x0000
T=125
Oct 19 17:49:26 aristo kernel: IP fw-in deny frame0 UDP
192.114.175.59:1117 192.114.175.163:22 L=30 S=0x00 I=1051 F=0x0000 T=125
Oct 19 17:49:26 aristo kernel: IP fw-in deny frame0 UDP
192.114.175.59:1117 192.114.175.164:5632 L=30 S=0x00 I=1307 F=0x0000
T=125
Oct 19 17:49:26 aristo kernel: IP fw-in deny frame0 UDP
192.114.175.59:1117 192.114.175.164:22 L=30 S=0x00 I=1563 F=0x0000 T=125
Oct 19 17:49:27 aristo kernel: IP fw-in deny frame0 UDP
192.114.175.59:1117 192.114.175.165:5632 L=30 S=0x00 I=1819 F=0x0000
T=125
Oct 19 17:49:27 aristo kernel: IP fw-in deny frame0 UDP
192.114.175.59:1117 192.114.175.165:22 L=30 S=0x00 I=2075 F=0x0000 T=125
Oct 19 17:49:27 aristo kernel: IP fw-in deny frame0 UDP
192.114.175.59:1117 192.114.175.166:5632 L=30 S=0x00 I=2331 F=0x0000
T=125
Oct 19 17:49:27 aristo kernel: IP fw-in deny frame0 UDP
192.114.175.59:1117 192.114.175.166:22 L=30 S=0x00 I=2587 F=0x0000 T=125
Oct 19 17:49:27 aristo kernel: IP fw-in deny frame0 UDP
192.114.175.59:1117 192.114.175.167:5632 L=30 S=0x00 I=2843 F=0x0000
T=125
Oct 19 17:49:27 aristo kernel: IP fw-in deny frame0 UDP
192.114.175.59:1117 192.114.175.168:5632 L=30 S=0x00 I=3355 F=0x0000
T=125
Oct 19 17:49:27 aristo kernel: IP fw-in deny frame0 UDP
192.114.175.59:1117 192.114.175.168:22 L=30 S=0x00 I=3611 F=0x0000 T=125
Oct 19 17:49:27 aristo kernel: IP fw-in deny frame0 UDP
192.114.175.59:1117 192.114.175.169:5632 L=30 S=0x00 I=3867 F=0x0000
T=125
Oct 19 17:49:27 aristo kernel: IP fw-in deny frame0 UDP
192.114.175.59:1117 192.114.175.169:22 L=30 S=0x00 I=4123 F=0x0000 T=125
Oct 19 17:49:27 aristo kernel: IP fw-in deny frame0 UDP
192.114.175.59:1117 192.114.175.170:5632 L=30 S=0x00 I=4379 F=0x0000
T=125
Oct 19 17:49:27 aristo kernel: IP fw-in deny frame0 UDP
192.114.175.59:1117 192.114.175.170:22 L=30 S=0x00 I=4635 F=0x0000 T=125
Oct 19 17:49:27 aristo kernel: IP fw-in deny frame0 UDP
192.114.175.59:1117 192.114.175.171:5632 L=30 S=0x00 I=4891 F=0x0000
T=125
Oct 19 17:49:27 aristo kernel: IP fw-in deny frame0 UDP
192.114.175.59:1117 192.114.175.173:5632 L=30 S=0x00 I=5915 F=0x0000
T=125
Oct 19 17:49:27 aristo kernel: IP fw-in deny frame0 UDP
192.114.175.59:1117 192.114.175.173:22 L=30 S=0x00 I=6171 F=0x0000 T=125
Oct 19 17:49:27 aristo kernel: IP fw-in deny frame0 UDP
192.114.175.59:1117 192.114.175.175:5632 L=30 S=0x00 I=6939 F=0x0000
T=125
Oct 19 17:49:27 aristo kernel: IP fw-in deny frame0 UDP
192.114.175.59:1117 192.114.175.175:22 L=30 S=0x00 I=7195 F=0x0000 T=125
Oct 19 17:49:27 aristo kernel: IP fw-in deny frame0 UDP
192.114.175.59:1117 192.114.175.176:5632 L=30 S=0x00 I=7451 F=0x0000
T=125