Hello out there,
please forgive my long post, but since I am a rather fresh admin of a nice, well running GNAT Box, I need a second opinion on this.
When I woke up this morning, I got about ten warning mails.
The warnings startet around 0:05 and ended around 0:15 and look like the forwarded message.
This looks like an DDoS attempt to me. What do you think?
Thank you & once again, sorry, for the long post.
yours,
Nick
PS: To be registered, one has to send in the post card or is an email also ok?
Ursprüngliche Nachricht:
> -----------------------------------------------------------------------------
> NOTIFICATION TYPE: GNAT Box FILTER ALARM
> NAME: shield
> CONFIGURATION: EXTERNAL=62.24.3.34
> PROTECTED=192.168.0.1
> PSN=192.168.1.1
> -----------------------------------------------------------------------------
>
> ALARM NO: 1
> DATE: Friday, Mar 24, 2000
> TIME: 00:10:26
> INTERFACE: EXT (fxp0)
> ALARM TYPE: Block
> IP PACKET: TCP [206.65.72.216/2817]-->[62.24.3.34/6699] l=0 f=0x2
> [asd.cajun.net/2817]-->[62.24.3.34/6699]
>
> DETAILED DESCRIPTION:
> IP packet was rejected.
>
> -----------------------------------------------------------------------------
>
> ALARM NO: 2
> DATE: Friday, Mar 24, 2000
> TIME: 00:10:26
> INTERFACE: EXT (fxp0)
> ALARM TYPE: Block
> IP PACKET: TCP [63.23.189.88/1719]-->[62.24.3.34/6699] l=0 f=0x2
> [1Cust88.tnt5.tampa.fl.da.uu.net/1719]-->[62.24.3.34/6699]
>
> DETAILED DESCRIPTION:
> IP packet was rejected.
>
> -----------------------------------------------------------------------------
>
> ALARM NO: 3
> DATE: Friday, Mar 24, 2000
> TIME: 00:10:32
> INTERFACE: EXT (fxp0)
> ALARM TYPE: Block
> IP PACKET: TCP [63.23.189.88/1719]-->[62.24.3.34/6699] l=0 f=0x2
> [1Cust88.tnt5.tampa.fl.da.uu.net/1719]-->[62.24.3.34/6699]
>
> DETAILED DESCRIPTION:
> IP packet was rejected.
>
> -----------------------------------------------------------------------------
>
> ALARM NO: 4
> DATE: Friday, Mar 24, 2000
> TIME: 00:10:34
> INTERFACE: EXT (fxp0)
> ALARM TYPE: Block
> IP PACKET: TCP [131.231.232.60/1522]-->[62.24.3.34/6699] l=0 f=0x2
> [fc-ro-hall-student-232-60.lut.ac.uk/1522]-->[62.24.3.34/6699]
>
> DETAILED DESCRIPTION:
> IP packet was rejected.
>
> -----------------------------------------------------------------------------
>
> ALARM NO: 5
> DATE: Friday, Mar 24, 2000
> TIME: 00:10:37
> INTERFACE: EXT (fxp0)
> ALARM TYPE: Block
> IP PACKET: TCP [131.231.232.60/1522]-->[62.24.3.34/6699] l=0 f=0x2
> [fc-ro-hall-student-232-60.lut.ac.uk/1522]-->[62.24.3.34/6699]
>
> DETAILED DESCRIPTION:
> IP packet was rejected.
>
> -----------------------------------------------------------------------------
>
> ALARM NO: 6
> DATE: Friday, Mar 24, 2000
> TIME: 00:10:43
> INTERFACE: EXT (fxp0)
> ALARM TYPE: Block
> IP PACKET: TCP [131.231.232.60/1522]-->[62.24.3.34/6699] l=0 f=0x2
> [fc-ro-hall-student-232-60.lut.ac.uk/1522]-->[62.24.3.34/6699]
>
> DETAILED DESCRIPTION:
> IP packet was rejected.
>
> -----------------------------------------------------------------------------
>
> ALARM NO: 7
> DATE: Friday, Mar 24, 2000
> TIME: 00:10:44
> INTERFACE: EXT (fxp0)
> ALARM TYPE: Block
> IP PACKET: TCP [207.176.153.77/1173]-->[62.24.3.34/6699] l=0 f=0x2
> [dialin77.ottawa.globalserve.net/1173]-->[62.24.3.34/6699]
>
> DETAILED DESCRIPTION:
> IP packet was rejected.
>
> -----------------------------------------------------------------------------
>
> ALARM NO: 8
> DATE: Friday, Mar 24, 2000
> TIME: 00:10:44
> INTERFACE: EXT (fxp0)
> ALARM TYPE: Block
> IP PACKET: TCP [63.23.189.88/1719]-->[62.24.3.34/6699] l=0 f=0x2
> [1Cust88.tnt5.tampa.fl.da.uu.net/1719]-->[62.24.3.34/6699]
>
> DETAILED DESCRIPTION:
> IP packet was rejected.
>
> -----------------------------------------------------------------------------
>
> ALARM NO: 9
> DATE: Friday, Mar 24, 2000
> TIME: 00:10:47
> INTERFACE: EXT (fxp0)
> ALARM TYPE: Block
> IP PACKET: TCP [207.176.153.77/1173]-->[62.24.3.34/6699] l=0 f=0x2
> [dialin77.ottawa.globalserve.net/1173]-->[62.24.3.34/6699]
>
> DETAILED DESCRIPTION:
> IP packet was rejected.
>
> -----------------------------------------------------------------------------
>
> ALARM NO: 10
> DATE: Friday, Mar 24, 2000
> TIME: 00:10:53
> INTERFACE: EXT (fxp0)
> ALARM TYPE: Block
> IP PACKET: TCP [216.207.10.32/1050]-->[62.24.3.34/6699] l=0 f=0x2
> [ip-010-032.oak.total-web.net/1050]-->[62.24.3.34/6699]
>
> DETAILED DESCRIPTION:
> IP packet was rejected.
>
> -----------------------------------------------------------------------------
>
> ALARM NO: 11
> DATE: Friday, Mar 24, 2000
> TIME: 00:10:53
> INTERFACE: EXT (fxp0)
> ALARM TYPE: Block
> IP PACKET: TCP [207.176.153.77/1173]-->[62.24.3.34/6699] l=0 f=0x2
> [dialin77.ottawa.globalserve.net/1173]-->[62.24.3.34/6699]
>
> DETAILED DESCRIPTION:
> IP packet was rejected.
>
> -----------------------------------------------------------------------------
>
> ALARM NO: 12
> DATE: Friday, Mar 24, 2000
> TIME: 00:10:55
> INTERFACE: EXT (fxp0)
> ALARM TYPE: Block
> IP PACKET: TCP [131.231.232.60/1522]-->[62.24.3.34/6699] l=0 f=0x2
> [fc-ro-hall-student-232-60.lut.ac.uk/1522]-->[62.24.3.34/6699]
>
> DETAILED DESCRIPTION:
> IP packet was rejected.
>
> -----------------------------------------------------------------------------
>
> ALARM NO: 13
> DATE: Friday, Mar 24, 2000
> TIME: 00:10:56
> INTERFACE: EXT (fxp0)
> ALARM TYPE: Block
> IP PACKET: TCP [216.207.10.32/1050]-->[62.24.3.34/6699] l=0 f=0x2
> [ip-010-032.oak.total-web.net/1050]-->[62.24.3.34/6699]
>
> DETAILED DESCRIPTION:
> IP packet was rejected.
>
> -----------------------------------------------------------------------------
>
> ALARM NO: 14
> DATE: Friday, Mar 24, 2000
> TIME: 00:10:59
> INTERFACE: EXT (fxp0)
> ALARM TYPE: Block
> IP PACKET: p=9 [212.6.140.1/0]-->[255.255.255.255/0] l=60
> [karlsruhe1.cnt.net/0]-->[255.255.255.255/0]
>
> DETAILED DESCRIPTION:
> IP packet was rejected.
>
> -----------------------------------------------------------------------------
>
> ALARM NO: 15
> DATE: Friday, Mar 24, 2000
> TIME: 00:11:02
> INTERFACE: EXT (fxp0)
> ALARM TYPE: Block
> IP PACKET: TCP [216.207.10.32/1050]-->[62.24.3.34/6699] l=0 f=0x2
> [ip-010-032.oak.total-web.net/1050]-->[62.24.3.34/6699]
>
> DETAILED DESCRIPTION:
> IP packet was rejected.
>
> -----------------------------------------------------------------------------
>
> ALARM NO: 16
> DATE: Friday, Mar 24, 2000
> TIME: 00:11:03
> INTERFACE: EXT (fxp0)
> ALARM TYPE: Block
> IP PACKET: TCP [63.210.168.69/4866]-->[62.24.3.34/6699] l=0 f=0x2
> [itvu-63-210-168-69.intervu.net/4866]-->[62.24.3.34/6699]
>
> DETAILED DESCRIPTION:
> IP packet was rejected.
>
> -----------------------------------------------------------------------------
>
> ALARM NO: 17
> DATE: Friday, Mar 24, 2000
> TIME: 00:11:06
> INTERFACE: EXT (fxp0)
> ALARM TYPE: Block
> IP PACKET: TCP [207.176.153.77/1173]-->[62.24.3.34/6699] l=0 f=0x2
> [dialin77.ottawa.globalserve.net/1173]-->[62.24.3.34/6699]
>
> DETAILED DESCRIPTION:
> IP packet was rejected.
>
> -----------------------------------------------------------------------------
>
> ALARM NO: 18
> DATE: Friday, Mar 24, 2000
> TIME: 00:11:06
> INTERFACE: EXT (fxp0)
> ALARM TYPE: Block
> IP PACKET: TCP [63.210.168.69/4866]-->[62.24.3.34/6699] l=0 f=0x2
> [itvu-63-210-168-69.intervu.net/4866]-->[62.24.3.34/6699]
>
> DETAILED DESCRIPTION:
> IP packet was rejected.
>
> -----------------------------------------------------------------------------
>
> ALARM NO: 19
> DATE: Friday, Mar 24, 2000
> TIME: 00:11:12
> INTERFACE: EXT (fxp0)
> ALARM TYPE: Block
> IP PACKET: TCP [63.210.168.69/4866]-->[62.24.3.34/6699] l=0 f=0x2
> [itvu-63-210-168-69.intervu.net/4866]-->[62.24.3.34/6699]
>
> DETAILED DESCRIPTION:
> IP packet was rejected.
>
> -----------------------------------------------------------------------------
>
> ALARM NO: 20
> DATE: Friday, Mar 24, 2000
> TIME: 00:11:13
> INTERFACE: EXT (fxp0)
> ALARM TYPE: Block
> IP PACKET: TCP [24.200.32.173/2461]-->[62.24.3.34/6699] l=0 f=0x2
> [modemcable173.32-200-24.mtl.mc.videotron.net/2461]-->[62.24.3.34/6699]
>
> DETAILED DESCRIPTION:
> IP packet was rejected.
>
> -----------------------------------------------------------------------------
>
> ALARM NO: 21
> DATE: Friday, Mar 24, 2000
> TIME: 00:11:14
> INTERFACE: EXT (fxp0)
> ALARM TYPE: Block
> IP PACKET: TCP [216.207.10.32/1050]-->[62.24.3.34/6699] l=0 f=0x2
> [ip-010-032.oak.total-web.net/1050]-->[62.24.3.34/6699]
>
> DETAILED DESCRIPTION:
> IP packet was rejected.
>
> -----------------------------------------------------------------------------
>
> ALARM NO: 22
> DATE: Friday, Mar 24, 2000
> TIME: 00:11:16
> INTERFACE: EXT (fxp0)
> ALARM TYPE: Block
> IP PACKET: TCP [24.200.32.173/2461]-->[62.24.3.34/6699] l=0 f=0x2
> [modemcable173.32-200-24.mtl.mc.videotron.net/2461]-->[62.24.3.34/6699]
>
> DETAILED DESCRIPTION:
> IP packet was rejected.
>
> -----------------------------------------------------------------------------
>
> ALARM NO: 23
> DATE: Friday, Mar 24, 2000
> TIME: 00:11:22
> INTERFACE: EXT (fxp0)
> ALARM TYPE: Block
> IP PACKET: TCP [24.200.32.173/2461]-->[62.24.3.34/6699] l=0 f=0x2
> [modemcable173.32-200-24.mtl.mc.videotron.net/2461]-->[62.24.3.34/6699]
>
> DETAILED DESCRIPTION:
> IP packet was rejected.
>
> -----------------------------------------------------------------------------
>
> ALARM NO: 24
> DATE: Friday, Mar 24, 2000
> TIME: 00:11:24
> INTERFACE: EXT (fxp0)
> ALARM TYPE: Block
> IP PACKET: TCP [63.210.168.69/4866]-->[62.24.3.34/6699] l=0 f=0x2
> [itvu-63-210-168-69.intervu.net/4866]-->[62.24.3.34/6699]
>
> DETAILED DESCRIPTION:
> IP packet was rejected.
>
> -----------------------------------------------------------------------------
>
> ALARM NO: 25
> DATE: Friday, Mar 24, 2000
> TIME: 00:11:32
> INTERFACE: EXT (fxp0)
> ALARM TYPE: Block
> IP PACKET: TCP [193.173.112.7/1072]-->[62.24.3.34/6699] l=0 f=0x2
> [uds7-112.dial.hccnet.nl/1072]-->[62.24.3.34/6699]
>
> DETAILED DESCRIPTION:
> IP packet was rejected.
>
> -----------------------------------------------------------------------------
>
> ALARM NO: 26
> DATE: Friday, Mar 24, 2000
> TIME: 00:11:34
> INTERFACE: EXT (fxp0)
> ALARM TYPE: Block
> IP PACKET: TCP [24.200.32.173/2461]-->[62.24.3.34/6699] l=0 f=0x2
> [modemcable173.32-200-24.mtl.mc.videotron.net/2461]-->[62.24.3.34/6699]
>
> DETAILED DESCRIPTION:
> IP packet was rejected.
>
> -----------------------------------------------------------------------------
>
> ALARM NO: 27
> DATE: Friday, Mar 24, 2000
> TIME: 00:11:35
> INTERFACE: EXT (fxp0)
> ALARM TYPE: Block
> IP PACKET: TCP [193.173.112.7/1072]-->[62.24.3.34/6699] l=0 f=0x2
> [uds7-112.dial.hccnet.nl/1072]-->[62.24.3.34/6699]
>
> DETAILED DESCRIPTION:
> IP packet was rejected.
>
> -----------------------------------------------------------------------------
>
> ALARM NO: 28
> DATE: Friday, Mar 24, 2000
> TIME: 00:11:41
> INTERFACE: EXT (fxp0)
> ALARM TYPE: Block
> IP PACKET: TCP [193.173.112.7/1072]-->[62.24.3.34/6699] l=0 f=0x2
> [uds7-112.dial.hccnet.nl/1072]-->[62.24.3.34/6699]
>
> DETAILED DESCRIPTION:
> IP packet was rejected.
>
> -----------------------------------------------------------------------------
>
> ALARM NO: 29
> DATE: Friday, Mar 24, 2000
> TIME: 00:11:45
> INTERFACE: EXT (fxp0)
> ALARM TYPE: Block
> IP PACKET: TCP [63.28.109.154/1235]-->[62.24.3.34/6688] l=0 f=0x2
> [1Cust154.tnt2.nyc3.da.uu.net/1235]-->[62.24.3.34/6688]
>
> DETAILED DESCRIPTION:
> IP packet was rejected.
>
> -----------------------------------------------------------------------------
>
> ALARM NO: 30
> DATE: Friday, Mar 24, 2000
> TIME: 00:11:48
> INTERFACE: EXT (fxp0)
> ALARM TYPE: Block
> IP PACKET: TCP [63.28.109.154/1235]-->[62.24.3.34/6688] l=0 f=0x2
> [1Cust154.tnt2.nyc3.da.uu.net/1235]-->[62.24.3.34/6688]
>
> DETAILED DESCRIPTION:
> IP packet was rejected.
>
> -----------------------------------------------------------------------------
>
> ALARM NO: 31
> DATE: Friday, Mar 24, 2000
> TIME: 00:11:53
> INTERFACE: EXT (fxp0)
> ALARM TYPE: Block
> IP PACKET: TCP [193.173.112.7/1072]-->[62.24.3.34/6699] l=0 f=0x2
> [uds7-112.dial.hccnet.nl/1072]-->[62.24.3.34/6699]
>
> DETAILED DESCRIPTION:
> IP packet was rejected.
>
> -----------------------------------------------------------------------------
>
> ALARM NO: 32
> DATE: Friday, Mar 24, 2000
> TIME: 00:11:54
> INTERFACE: EXT (fxp0)
> ALARM TYPE: Block
> IP PACKET: TCP [63.28.109.154/1235]-->[62.24.3.34/6688] l=0 f=0x2
> [1Cust154.tnt2.nyc3.da.uu.net/1235]-->[62.24.3.34/6688]
>
> DETAILED DESCRIPTION:
> IP packet was rejected.
>
> -----------------------------------------------------------------------------
>
> ALARM NO: 33
> DATE: Friday, Mar 24, 2000
> TIME: 00:12:01
> INTERFACE: EXT (fxp0)
> ALARM TYPE: Block
> IP PACKET: TCP [142.165.183.113/1867]-->[62.24.3.34/6688] l=0 f=0x2
> [hss-183-113.sk.sympatico.ca/1867]-->[62.24.3.34/6688]
>
> DETAILED DESCRIPTION:
> IP packet was rejected.
>
> -----------------------------------------------------------------------------
>
> ALARM NO: 34
> DATE: Friday, Mar 24, 2000
> TIME: 00:12:04
> INTERFACE: EXT (fxp0)
> ALARM TYPE: Block
> IP PACKET: TCP [142.165.183.113/1867]-->[62.24.3.34/6688] l=0 f=0x2
> [hss-183-113.sk.sympatico.ca/1867]-->[62.24.3.34/6688]
>
> DETAILED DESCRIPTION:
> IP packet was rejected.
>
> -----------------------------------------------------------------------------
>
> ALARM NO: 35
> DATE: Friday, Mar 24, 2000
> TIME: 00:12:06
> INTERFACE: EXT (fxp0)
> ALARM TYPE: Block
> IP PACKET: TCP [63.28.109.154/1235]-->[62.24.3.34/6688] l=0 f=0x2
> [1Cust154.tnt2.nyc3.da.uu.net/1235]-->[62.24.3.34/6688]
>
> DETAILED DESCRIPTION:
> IP packet was rejected.
>
> -----------------------------------------------------------------------------
>
> ALARM NO: 36
> DATE: Friday, Mar 24, 2000
> TIME: 00:12:11
> INTERFACE: EXT (fxp0)
> ALARM TYPE: Block
> IP PACKET: TCP [142.165.183.113/1867]-->[62.24.3.34/6688] l=0 f=0x2
> [hss-183-113.sk.sympatico.ca/1867]-->[62.24.3.34/6688]
>
> DETAILED DESCRIPTION:
> IP packet was rejected.
>
> -----------------------------------------------------------------------------
>
> ALARM NO: 37
> DATE: Friday, Mar 24, 2000
> TIME: 00:12:16
> INTERFACE: EXT (fxp0)
> ALARM TYPE: Block
> IP PACKET: p=9 [212.6.140.1/0]-->[255.255.255.255/0] l=60
> [karlsruhe1.cnt.net/0]-->[255.255.255.255/0]
>
> DETAILED DESCRIPTION:
> IP packet was rejected.
>
> -----------------------------------------------------------------------------
>
> ALARM NO: 38
> DATE: Friday, Mar 24, 2000
> TIME: 00:12:23
> INTERFACE: EXT (fxp0)
> ALARM TYPE: Block
> IP PACKET: TCP [142.165.183.113/1867]-->[62.24.3.34/6688] l=0 f=0x2
> [hss-183-113.sk.sympatico.ca/1867]-->[62.24.3.34/6688]
>
> DETAILED DESCRIPTION:
> IP packet was rejected.
>
> -----------------------------------------------------------------------------
>
> ALARM NO: 39
> DATE: Friday, Mar 24, 2000
> TIME: 00:12:24
> INTERFACE: EXT (fxp0)
> ALARM TYPE: Block
> IP PACKET: TCP [171.225.183.104/1091]-->[62.24.3.34/6688] l=0 f=0x2
> [ABE1B768.ipt.aol.com/1091]-->[62.24.3.34/6688]
>
> DETAILED DESCRIPTION:
> IP packet was rejected.
>
> -----------------------------------------------------------------------------
>
> ALARM NO: 40
> DATE: Friday, Mar 24, 2000
> TIME: 00:12:27
> INTERFACE: EXT (fxp0)
> ALARM TYPE: Block
> IP PACKET: TCP [171.225.183.104/1091]-->[62.24.3.34/6688] l=0 f=0x2
> [ABE1B768.ipt.aol.com/1091]-->[62.24.3.34/6688]
>
> DETAILED DESCRIPTION:
> IP packet was rejected.
>
> -----------------------------------------------------------------------------
>
> ALARM NO: 41
> DATE: Friday, Mar 24, 2000
> TIME: 00:12:31
> INTERFACE: EXT (fxp0)
> ALARM TYPE: Block
> IP PACKET: TCP [192.112.2.153/2022]-->[62.24.3.34/6688] l=0 f=0x2
> [192.112.2.153/2022]-->[62.24.3.34/6688]
>
> DETAILED DESCRIPTION:
> IP packet was rejected.
>
> -----------------------------------------------------------------------------
>
> ALARM NO: 42
> DATE: Friday, Mar 24, 2000
> TIME: 00:12:33
> INTERFACE: EXT (fxp0)
> ALARM TYPE: Block
> IP PACKET: TCP [171.225.183.104/1091]-->[62.24.3.34/6688] l=0 f=0x2
> [ABE1B768.ipt.aol.com/1091]-->[62.24.3.34/6688]
>
> DETAILED DESCRIPTION:
> IP packet was rejected.
>
> -----------------------------------------------------------------------------
>
> ALARM NO: 43
> DATE: Friday, Mar 24, 2000
> TIME: 00:12:34
> INTERFACE: EXT (fxp0)
> ALARM TYPE: Block
> IP PACKET: TCP [192.112.2.153/2022]-->[62.24.3.34/6688] l=0 f=0x2
> [192.112.2.153/2022]-->[62.24.3.34/6688]
>
> DETAILED DESCRIPTION:
> IP packet was rejected.
>
> -----------------------------------------------------------------------------
>
> ALARM NO: 44
> DATE: Friday, Mar 24, 2000
> TIME: 00:12:40
> INTERFACE: EXT (fxp0)
> ALARM TYPE: Block
> IP PACKET: TCP [192.112.2.153/2022]-->[62.24.3.34/6688] l=0 f=0x2
> [192.112.2.153/2022]-->[62.24.3.34/6688]
>
> DETAILED DESCRIPTION:
> IP packet was rejected.
>
> -----------------------------------------------------------------------------
>
> ALARM NO: 45
> DATE: Friday, Mar 24, 2000
> TIME: 00:12:42
> INTERFACE: EXT (fxp0)
> ALARM TYPE: Block
> IP PACKET: TCP [142.165.183.113/1877]-->[62.24.3.34/6688] l=0 f=0x2
> [hss-183-113.sk.sympatico.ca/1877]-->[62.24.3.34/6688]
>
> DETAILED DESCRIPTION:
> IP packet was rejected.
>
> -----------------------------------------------------------------------------
>
> ALARM NO: 46
> DATE: Friday, Mar 24, 2000
> TIME: 00:12:42
> INTERFACE: EXT (fxp0)
> ALARM TYPE: Block
> IP PACKET: TCP [208.21.142.172/1397]-->[62.24.3.34/6688] l=0 f=0x2
> [log172.2fords.net/1397]-->[62.24.3.34/6688]
>
> DETAILED DESCRIPTION:
> IP packet was rejected.
>
> -----------------------------------------------------------------------------
> This report was automatically generated by GNAT Box.
> -----------------------------------------------------------------------------
>
>
> ùL
_______________________________________________________________________
1.000.000 DM gewinnen - kostenlos tippen - http://millionenklick.web.de
IhrName_at_web_dot_de, 8MB Speicher, Verschluesselung - http://freemail.web.de
|