j***@specsol.spam.sux.com
2014-10-07 01:12:52 UTC
Lately I've been getting lots of log entries like:
Oct 6 17:51:51 mail ipmon[127]: [ID 702911 local0.warning] 17:51:51.658744
e1000g0 @0:78 b 188.132.241.144,0 -> my_ip,0 PR tcp len 20 60 -ARSFEC IN
Oct 6 17:52:15 mail ipmon[127]: [ID 702911 local0.warning] 17:52:15.592072
e1000g0 @0:126 b 58.221.223.253,6000 -> my_ip,1433 PR tcp len 20 40 -S IN
Oct 6 17:52:15 mail ipmon[127]: [ID 702911 local0.warning] 17:52:15.612284
e1000g0 @0:126 b 58.221.223.253,6000 -> my_ip,1433 PR tcp len 20 40 -S IN
Oct 6 17:54:43 mail ipmon[127]: [ID 702911 local0.warning] 17:54:43.961218
e1000g0 @0:135 b 81.91.83.77,0 -> my_ip,0 PR tcp len 20 60 -SUPEC IN bad
Obviously a whole bunch of people are attempting to exploit something, but
what?
Oct 6 17:51:51 mail ipmon[127]: [ID 702911 local0.warning] 17:51:51.658744
e1000g0 @0:78 b 188.132.241.144,0 -> my_ip,0 PR tcp len 20 60 -ARSFEC IN
Oct 6 17:52:15 mail ipmon[127]: [ID 702911 local0.warning] 17:52:15.592072
e1000g0 @0:126 b 58.221.223.253,6000 -> my_ip,1433 PR tcp len 20 40 -S IN
Oct 6 17:52:15 mail ipmon[127]: [ID 702911 local0.warning] 17:52:15.612284
e1000g0 @0:126 b 58.221.223.253,6000 -> my_ip,1433 PR tcp len 20 40 -S IN
Oct 6 17:54:43 mail ipmon[127]: [ID 702911 local0.warning] 17:54:43.961218
e1000g0 @0:135 b 81.91.83.77,0 -> my_ip,0 PR tcp len 20 60 -SUPEC IN bad
Obviously a whole bunch of people are attempting to exploit something, but
what?
--
Jim Pennino
Jim Pennino