| Linode Forum https://forum.linode.com/ |
|
| Strange packets https://forum.linode.com/viewtopic.php?f=19&t=931 |
Page 1 of 1 |
| Author: | sufehmi [ Tue Jun 08, 2004 7:05 am ] |
| Post subject: | Strange packets |
This morning I noticed that logcheck is sending me huge notification emails. There are a lot of messages from the kernel. This worries me, so I logged on to Linode's remote console. Then I saw messages like this, scrolling very quickly on the screen: Code: OUT-internet:IN= OUT=eth0 SRC=66.160.141.215 DST=66.237.60.101 LEN=52 TOS=0x00 PREC=0x00 TTL=64 ID=0 DF PROTO=TCP SPT=80 DPT=3078 WINDOW=6432 RES=0x00 ACK PSH FIN URGP=0 If I'm not mistaken, it means that 66.237.60.101 is putting HTTP requests to my server - but very rapidly. Here's the whois result for 66.237.60.101 Code: OrgName: XO Communications Does anyone know what's going on here ? At the moment I'm trying to restart the server, but it's been 15 minutes and it's not even shut down yet. Below is a more complete details from the Linode remote console. Thanks, Harry Code: OUT-internet:IN= OUT=eth0 SRC=66.160.141.215 DST=66.237.60.101 LEN=52 TOS=0x00 PREC=0x00 TTL=64 ID=0 DF PROTO=TCP SPT=80 DPT=3078 WINDOW=6432 RES=0x00 ACK PSH FIN URGP=0 |
|
| Author: | lurkus [ Tue Jun 08, 2004 12:17 pm ] |
| Post subject: | |
I've had this happen to me before. I'm using Shorewall as my iptables frontend. I just added the offending IP to the dynamic block list. Shorewall will let me know how many times the IP is being blocked, so I waited until it stopped (a few days usually) then I removed the dynamic block. There is probably some software out there that will do this for you automatically, but that has certain risks as well... so as far as I know you will just have to block the IP manually. If anyone has any better suggestions please post them. |
|
| Author: | sufehmi [ Tue Jun 08, 2004 11:54 pm ] |
| Post subject: | |
lurkus wrote: I've had this happen to me before. I'm using Shorewall as my iptables frontend. I just added the offending IP to the dynamic block list. Shorewall will let me know how many times the IP is being blocked, so I waited until it stopped (a few days usually) then I removed the dynamic block. There is probably some software out there that will do this for you automatically, but that has certain risks as well... so as far as I know you will just have to block the IP manually. Alright... thanks lurkus, I was worried that I did something wrong. Quote: If anyone has any better suggestions please post them.
Yes, please do Thanks again, Harry |
|
| Page 1 of 1 | All times are UTC-04:00 |
| Powered by phpBB® Forum Software © phpBB Group http://www.phpbb.com/ |
|