Go Back   Velocity Reviews > Newsgroups > Computer Security
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply

Computer Security - Am I subject of hachers attack ?

 
Thread Tools Search this Thread
Old 05-28-2006, 05:20 PM   #1
Default Am I subject of hachers attack ?


Hi all,

I got a USR router and I see some suspect log messages:

Could someone help me to understand if someone ore more are trying to
find a bug in the router software to hack my network ?

May 28 18:14:35 user warning dnsprobe[505]: dns query failed
May 28 18:10:13 user alert kernel: Intrusion -> IN=ppp_8_35_1 OUT=
MAC= SRC=87.10.216.156 DST=87.11.150.32 LEN=48 TOS=0x00 PREC=0x00 TTL=58
ID=48499 DF PROTO=TCP SPT=2615 DPT=135 WINDOW=64800 RES=0x00 SYN URGP=0
May 28 18:09:55 user alert kernel: Intrusion -> IN=ppp_8_35_1 OUT=
MAC= SRC=87.11.97.13 DST=87.11.150.32 LEN=48 TOS=0x00 PREC=0x00 TTL=121
ID=24803 DF PROTO=TCP SPT=2180 DPT=135 WINDOW=16384 RES=0x00 SYN URGP=0
May 28 18:09:52 user alert kernel: Intrusion -> IN=ppp_8_35_1 OUT=
MAC= SRC=87.11.97.13 DST=87.11.150.32 LEN=48 TOS=0x00 PREC=0x00 TTL=121
ID=24484 DF PROTO=TCP SPT=2180 DPT=135 WINDOW=16384 RES=0x00 SYN URGP=0
May 28 18:09:46 user alert kernel: Intrusion -> IN=ppp_8_35_1 OUT=
MAC= SRC=87.11.52.56 DST=87.11.150.32 LEN=64 TOS=0x00 PREC=0x00 TTL=41
ID=25213 DF PROTO=TCP SPT=3716 DPT=445 WINDOW=53760 RES=0x00 SYN URGP=0
May 28 18:09:38 user alert kernel: Intrusion -> IN=ppp_8_35_1 OUT=
MAC= SRC=87.11.165.246 DST=87.11.150.32 LEN=48 TOS=0x00 PREC=0x00
TTL=121 ID=31069 PROTO=TCP SPT=28824 DPT=445 WINDOW=64240 RES=0x00 SYN
URGP=0
May 28 18:08:53 user warning dnsprobe[505]: dns query


buffer overflow
  Reply With Quote
Old 06-05-2006, 04:25 PM   #2
Todd H.
 
Posts: n/a
Default Re: Am I subject of hachers attack ?
buffer overflow <> writes:
> Hi all,
>
> I got a USR router and I see some suspect log messages:
>
> Could someone help me to understand if someone ore more are trying to
> find a bug in the router software to hack my network ?
>
> May 28 18:14:35 user warning dnsprobe[505]: dns query failed
> May 28 18:10:13 user alert kernel: Intrusion -> IN=ppp_8_35_1
> OUT= MAC= SRC=87.10.216.156 DST=87.11.150.32 LEN=48 TOS=0x00 PREC=0x00
> TTL=58 ID=48499 DF PROTO=TCP SPT=2615 DPT=135 WINDOW=64800 RES=0x00
> SYN URGP=0
> May 28 18:09:55 user alert kernel: Intrusion -> IN=ppp_8_35_1
> OUT= MAC= SRC=87.11.97.13 DST=87.11.150.32 LEN=48 TOS=0x00 PREC=0x00
> TTL=121 ID=24803 DF PROTO=TCP SPT=2180 DPT=135 WINDOW=16384 RES=0x00
> SYN URGP=0
> May 28 18:09:52 user alert kernel: Intrusion -> IN=ppp_8_35_1
> OUT= MAC= SRC=87.11.97.13 DST=87.11.150.32 LEN=48 TOS=0x00 PREC=0x00
> TTL=121 ID=24484 DF PROTO=TCP SPT=2180 DPT=135 WINDOW=16384 RES=0x00
> SYN URGP=0


All probes for a windows share on port 135. Script kiddie stuff the
world over. Not a big deal so long as you aren't running a windows
share out to the internet.

> May 28 18:09:46 user alert kernel: Intrusion -> IN=ppp_8_35_1
> OUT= MAC= SRC=87.11.52.56 DST=87.11.150.32 LEN=64 TOS=0x00 PREC=0x00
> TTL=41 ID=25213 DF PROTO=TCP SPT=3716 DPT=445 WINDOW=53760 RES=0x00
> SYN URGP=0


> May 28 18:09:38 user alert kernel: Intrusion -> IN=ppp_8_35_1
> OUT= MAC= SRC=87.11.165.246 DST=87.11.150.32 LEN=48 TOS=0x00 PREC=0x00
> TTL=121 ID=31069 PROTO=TCP SPT=28824 DPT=445 WINDOW=64240 RES=0x00 SYN
> URGP=0


Similar probe on port 445, no worries.

> May 28 18:08:53 user warning dnsprobe[505]: dns query


Automated tool seeing if you have a dns server running. NOt a big
deal either assuming your router is blocking it, and you don't have
anything in your DMZ.


--
Todd H.
http://www.toddh.net/


Todd H.
  Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off

Similar Threads
Thread Thread Starter Forum Replies Last Post
Tremors Attack Pack, all 16x9 ? WanderinRoy DVD Video 0 09-08-2007 08:57 PM
DVD Verdict reviews: CRUNCH: FAT BURNING AB ATTACK and more! DVD Verdict DVD Video 0 11-05-2005 09:18 AM
Sunil Dutt dies of heart attack habshi DVD Video 3 05-25-2005 03:28 PM
DVD Verdict reviews: A CINDERELLA STORY, THE HOLE, THE ADVENTURES OF JIMMY NEUTRON: ATTACK OF THE TWONKIES, and more! DVD Verdict DVD Video 0 11-26-2004 10:09 AM
DVD Verdict reviews: GODZILLA, MOTHRA AND KING GHIDORAH: GIANT MONSTERS ALL-OUT ATTACK and more! DVD Verdict DVD Video 0 02-18-2004 10:05 AM




SEO by vBSEO 3.3.2 ©2009, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46