silvadouglas
(usa Linux Mint)
Enviado em 23/06/2010 - 10:40h
dei umas olhadas nesses log's e aparecem sempre mensagens repetidas como:
Em kern.log aparecem:
Jun 21 21:21:13 douglas-desktop kernel: [ 910.553254] [UFW AUDIT] IN= OUT=eth0 SRC=192.168.1.2 DST=91.189.92.166 LEN=52 TOS=0x00 PREC=0x00 TTL=64 ID=53220 DF PROTO=TCP SPT=43910 DPT=80 WINDOW=8257 RES=0x00 ACK URGP=0
Jun 21 21:21:13 douglas-desktop kernel: [ 910.559230] [UFW AUDIT] IN=eth0 OUT= MAC=00:13:d4:bb:fc:5e:00:1d:20:9b:5f:41:08:00 SRC=91.189.92.166 DST=192.168.1.2 LEN=1492 TOS=0x00 PREC=0x00 TTL=49 ID=37935 DF PROTO=TCP SPT=80 DPT=43910 WINDOW=54 RES=0x00 ACK URGP=0
Jun 21 21:21:13 douglas-desktop kernel: [ 910.565661] [UFW AUDIT] IN=eth0 OUT= MAC=00:13:d4:bb:fc:5e:00:1d:20:9b:5f:41:08:00 SRC=91.189.92.166 DST=192.168.1.2 LEN=1492 TOS=0x00 PREC=0x00 TTL=49 ID=37936 DF PROTO=TCP SPT=80 DPT=43910 WINDOW=54 RES=0x00 ACK URGP=0
Jun 21 21:21:13 douglas-desktop kernel: [ 910.565695] [UFW AUDIT] IN= OUT=eth0 SRC=192.168.1.2 DST=91.189.92.166 LEN=52 TOS=0x00 PREC=0x00 TTL=64 ID=53221 DF PROTO=TCP SPT=43910 DPT=80 WINDOW=8257 RES=0x00 ACK URGP=0
Em Messages:
Jun 21 21:14:02 douglas-desktop kernel: [ 479.175129] [UFW AUDIT] IN=eth0 OUT= MAC=00:13:d4:bb:fc:5e:00:1d:20:9b:5f:41:08:00 SRC=208.131.188.203 DST=192.168.1.2 LEN=52 TOS=0x00 PREC=0x00 TTL=106 ID=15067 DF PROTO=TCP SPT=50003 DPT=45663 WINDOW=309 RES=0x00 ACK URGP=0
Jun 21 21:14:02 douglas-desktop kernel: [ 479.175158] [UFW AUDIT] IN= OUT=eth0 SRC=192.168.1.2 DST=208.131.188.203 LEN=1492 TOS=0x00 PREC=0x00 TTL=64 ID=7351 DF PROTO=TCP SPT=45663 DPT=50003 WINDOW=698 RES=0x00 ACK URGP=0
Jun 21 21:14:02 douglas-desktop kernel: [ 479.175172] [UFW AUDIT] IN= OUT=eth0 SRC=192.168.1.2 DST=208.131.188.203 LEN=1492 TOS=0x00 PREC=0x00 TTL=64 ID=7352 DF PROTO=TCP SPT=45663 DPT=50003 WINDOW=698 RES=0x00 ACK URGP=0
Jun 21 21:14:02 douglas-desktop kernel: [ 479.187570] [UFW AUDIT] IN=eth0 OUT= MAC=00:13:d4:bb:fc:5e:00:1d:20:9b:5f:41:08:00 SRC=208.131.188.203 DST=192.168.1.2 LEN=52 TOS=0x00 PREC=0x00 TTL=106 ID=15074 DF PROTO=TCP SPT=50003 DPT=45663 WINDOW=309 RES=0x00 ACK URGP=0
Jun 21 21:14:02 douglas-desktop kernel: [ 479.187591] [UFW AUDIT] IN= OUT=eth0 SRC=192.168.1.2 DST=208.131.188.203 LEN=1492 TOS=0x00 PREC=0x00 TTL=64 ID=7353 DF PROTO=TCP SPT=45663 DPT=50003 WINDOW=698 RES=0x00 ACK URGP=0
Em syslog:
Jun 23 07:44:35 douglas-desktop kernel: [59599.725924] [UFW AUDIT] IN=eth0 OUT= MAC=00:13:d4:bb:fc:5e:00:1d:20:9b:5f:41:08:00 SRC=66.117.43.57 DST=192.168.1.2 LEN=1492 TOS=0x00 PREC=0x00 TTL=51 ID=11201 DF PROTO=TCP SPT=80 DPT=45664 WINDOW=54 RES=0x00 ACK URGP=0
Jun 23 07:44:35 douglas-desktop kernel: [59599.725989] [UFW AUDIT] IN= OUT=eth0 SRC=192.168.1.2 DST=66.117.43.57 LEN=80 TOS=0x00 PREC=0x00 TTL=64 ID=47267 DF PROTO=TCP SPT=45664 DPT=80 WINDOW=24975 RES=0x00 ACK URGP=0
Jun 23 07:44:35 douglas-desktop kernel: [59599.726261] [UFW AUDIT] IN=eth0 OUT= MAC=00:13:d4:bb:fc:5e:00:1d:20:9b:5f:41:08:00 SRC=188.4.119.187 DST=192.168.1.2 LEN=52 TOS=0x00 PREC=0x00 TTL=110 ID=19019 PROTO=TCP SPT=17070 DPT=34103 WINDOW=65535 RES=0x00 ACK URGP=0
Jun 23 07:44:35 douglas-desktop kernel: [59599.726289] [UFW AUDIT] IN= OUT=eth0 SRC=192.168.1.2 DST=188.4.119.187 LEN=1492 TOS=0x00 PREC=0x00 TTL=64 ID=5014 DF PROTO=TCP SPT=34103 DPT=17070 WINDOW=1002 RES=0x00 ACK URGP=0
Em ufw.log:
Jun 21 21:07:40 douglas-desktop kernel: [ 96.844255] [UFW AUDIT] IN=eth0 OUT= MAC=00:13:d4:bb:fc:5e:00:1d:20:9b:5f:41:08:00 SRC=91.189.92.166 DST=192.168.1.2 LEN=1492 TOS=0x00 PREC=0x00 TTL=47 ID=7647 DF PROTO=TCP SPT=80 DPT=38011 WINDOW=113 RES=0x00 ACK URGP=0
Jun 21 21:07:40 douglas-desktop kernel: [ 96.851201] [UFW AUDIT] IN=eth0 OUT= MAC=00:13:d4:bb:fc:5e:00:1d:20:9b:5f:41:08:00 SRC=91.189.92.166 DST=192.168.1.2 LEN=1492 TOS=0x00 PREC=0x00 TTL=47 ID=7648 DF PROTO=TCP SPT=80 DPT=38011 WINDOW=113 RES=0x00 ACK URGP=0
Jun 21 21:07:40 douglas-desktop kernel: [ 96.851222] [UFW AUDIT] IN= OUT=eth0 SRC=192.168.1.2 DST=91.189.92.166 LEN=52 TOS=0x00 PREC=0x00 TTL=64 ID=14334 DF PROTO=TCP SPT=38011 DPT=80 WINDOW=10125 RES=0x00 ACK URGP=0
Jun 21 21:07:40 douglas-desktop kernel: [ 96.857975] [UFW AUDIT] IN=eth0 OUT= MAC=00:13:d4:bb:fc:5e:00:1d:20:9b:5f:41:08:00 SRC=91.189.92.166 DST=192.168.1.2 LEN=1492 TOS=0x00 PREC=0x00 TTL=47 ID=7649 DF PROTO=TCP SPT=80 DPT=38011 WINDOW=113 RES=0x00 ACK URGP=0
O que é isso???? Tem a ver com firewall ou coisa do tipo?
Desculpem o tamanho do post mas esta me dando nos nervos isso...
Desde ja agradeço.