djuan1988
11-03-11, 12:24
Καλημέρα σε όλους.
Μπορεί κάποιος να μου εξηγήσει τι συμβαίνει; Δέχομαι επίθεση;
Με μια αναζήτηση στο φόρουμ βρήκα αρκετά παρόμοια θέματα, αλλά δεν έχω το απαραίτητο υπόβαθρο για να αξιολογήσω την κατάσταση.
Παραθέτω το security log του router, το οποίο είναι ένα Sagem F@st 1500WG.
03/11/2011 10:54:54 sending ACK to 192.168.2.2
03/11/2011 10:54:53 sending OFFER to 192.168.2.2
03/11/2011 10:52:27 192.168.2.6 login success
03/11/2011 10:33:30 192.168.2.6 login success
03/11/2011 10:33:21 192.168.2.6 login fail
03/11/2011 10:22:47 sending ACK to 192.168.2.6
03/11/2011 10:22:27 192.168.2.6 login success
03/11/2011 10:12:45 sending ACK to 192.168.2.2
03/11/2011 10:12:43 sending OFFER to 192.168.2.2
03/11/2011 10:11:48 sending ACK to 192.168.2.5
03/11/2011 10:11:48 sending OFFER to 192.168.2.5
03/11/2011 10:09:31 192.168.2.6 login success
03/11/2011 10:00:49 sending OFFER to 192.168.2.2
03/11/2011 09:47:59 sending OFFER to 192.168.2.2
03/11/2011 08:59:00 **TCP FIN Scan** 192.168.2.6, 41237->> 209.85.229.99, 80 (from ATM1 Outbound)
03/11/2011 08:59:00 **TCP FIN Scan** 192.168.2.6, 37918->> 209.85.229.101, 80 (from ATM1 Outbound)
03/11/2011 08:59:00 **TCP FIN Scan** 192.168.2.6, 38608->> 209.85.227.191, 80 (from ATM1 Outbound)
03/11/2011 08:59:00 **TCP FIN Scan** 192.168.2.6, 38448->> 72.21.206.177, 80 (from ATM1 Outbound)
03/11/2011 08:59:00 **TCP FIN Scan** 192.168.2.6, 48924->> 74.125.79.95, 80 (from ATM1 Outbound)
03/11/2011 08:59:00 **TCP FIN Scan** 192.168.2.6, 56662->> 209.85.227.101, 80 (from ATM1 Outbound)
03/11/2011 08:59:00 **TCP FIN Scan** 192.168.2.6, 52893->> 157.166.224.32, 80 (from ATM1 Outbound)
03/11/2011 08:59:00 **TCP FIN Scan** 192.168.2.6, 49738->> 209.85.227.132, 80 (from ATM1 Outbound)
03/11/2011 08:25:11 sending ACK to 192.168.2.3
03/11/2011 08:25:11 sending OFFER to 192.168.2.3
03/11/2011 07:25:24 sending ACK to 192.168.2.3
03/11/2011 07:25:24 sending OFFER to 192.168.2.3
03/11/2011 07:04:07 sending ACK to 192.168.2.3
03/11/2011 07:04:07 sending OFFER to 192.168.2.3
03/11/2011 05:36:45 sending ACK to 192.168.2.3
03/11/2011 05:36:45 sending OFFER to 192.168.2.3
03/11/2011 05:21:52 NTP Date/Time updated.
03/10/2011 23:21:27 sending ACK to 192.168.2.3
03/10/2011 23:21:27 sending OFFER to 192.168.2.3
03/10/2011 23:18:30 NTP Date/Time updated.
03/10/2011 22:51:08 sending ACK to 192.168.2.3
03/10/2011 22:51:08 sending OFFER to 192.168.2.3
03/10/2011 21:48:55 sending ACK to 192.168.2.3
03/10/2011 21:48:55 sending OFFER to 192.168.2.3
03/10/2011 21:08:36 sending ACK to 192.168.2.3
03/10/2011 21:08:36 sending OFFER to 192.168.2.3
03/10/2011 19:18:40 sending ACK to 192.168.2.3
03/10/2011 19:18:39 sending OFFER to 192.168.2.3
03/10/2011 18:58:44 sending ACK to 192.168.2.3
03/10/2011 18:58:44 sending OFFER to 192.168.2.3
03/10/2011 17:22:08 sending ACK to 192.168.2.3
03/10/2011 17:22:08 sending OFFER to 192.168.2.3
03/10/2011 17:15:06 NTP Date/Time updated.
03/10/2011 16:58:10 sending ACK to 192.168.2.3
03/10/2011 16:58:10 sending OFFER to 192.168.2.3
03/10/2011 16:26:15 sending ACK to 192.168.2.3
03/10/2011 16:26:15 sending OFFER to 192.168.2.3
03/10/2011 15:43:39 sending ACK to 192.168.2.6
03/10/2011 15:43:39 sending OFFER to 192.168.2.6
03/10/2011 15:28:30 sending ACK to 192.168.2.3
03/10/2011 15:28:30 sending OFFER to 192.168.2.3
03/10/2011 11:24:10 sending ACK to 192.168.2.3
03/10/2011 11:24:10 sending OFFER to 192.168.2.3
03/10/2011 11:11:43 NTP Date/Time updated.
03/10/2011 05:08:20 NTP Date/Time updated.
03/10/2011 00:28:33 sending ACK to 192.168.2.3
03/10/2011 00:28:32 sending OFFER to 192.168.2.3
03/09/2011 23:04:56 NTP Date/Time updated.
03/09/2011 22:51:05 sending ACK to 192.168.2.3
03/09/2011 22:51:05 sending OFFER to 192.168.2.3
03/09/2011 22:24:23 sending ACK to 192.168.2.3
03/09/2011 22:24:23 sending OFFER to 192.168.2.3
03/09/2011 22:02:58 sending ACK to 192.168.2.3
03/09/2011 22:02:58 sending OFFER to 192.168.2.3
03/09/2011 21:56:29 sending ACK to 192.168.2.3
03/09/2011 21:56:29 sending OFFER to 192.168.2.3
03/09/2011 21:50:58 sending ACK to 192.168.2.2
03/09/2011 21:50:57 sending OFFER to 192.168.2.2
03/09/2011 21:34:54 sending ACK to 192.168.2.3
03/09/2011 21:34:53 sending OFFER to 192.168.2.3
03/09/2011 21:23:59 sending ACK to 192.168.2.4
03/09/2011 21:23:58 sending OFFER to 192.168.2.4
03/09/2011 21:06:22 sending ACK to 192.168.2.2
03/09/2011 21:06:21 sending OFFER to 192.168.2.2
03/09/2011 20:25:48 sending ACK to 192.168.2.6
03/09/2011 20:25:48 sending OFFER to 192.168.2.6
03/09/2011 20:06:42 sending ACK to 192.168.2.3
03/09/2011 20:06:42 sending OFFER to 192.168.2.3
03/09/2011 18:52:09 **TCP FIN Scan** 74.201.117.247, 80->> 192.168.2.6, 33729 (from ATM1 Inbound)
03/09/2011 18:52:09 **TCP FIN Scan** 75.101.145.196, 80->> 192.168.2.6, 33202 (from ATM1 Inbound)
03/09/2011 18:52:09 **TCP FIN Scan** 66.220.156.11, 80->> 192.168.2.6, 46606 (from ATM1 Inbound)
03/09/2011 18:52:09 **TCP FIN Scan** 66.220.146.22, 80->> 192.168.2.6, 54629 (from ATM1 Inbound)
03/09/2011 18:25:24 sending ACK to 192.168.2.2
03/09/2011 18:25:24 sending OFFER to 192.168.2.2
03/09/2011 18:03:34 **TCP FIN Scan** 192.168.2.6, 54989->> 88.208.12.5, 80 (from ATM1 Outbound)
03/09/2011 18:03:34 **TCP FIN Scan** 192.168.2.6, 45987->> 88.208.24.50, 80 (from ATM1 Outbound)
03/09/2011 18:03:34 **TCP FIN Scan** 192.168.2.6, 47536->> 88.208.12.3, 80 (from ATM1 Outbound)
03/09/2011 17:54:41 **TCP FIN Scan** 192.168.2.6, 58940->> 88.208.12.5, 80 (from ATM1 Outbound)
03/09/2011 17:54:40 **TCP FIN Scan** 192.168.2.6, 57829->> 88.208.12.2, 80 (from ATM1 Outbound)
03/09/2011 17:34:30 sending ACK to 192.168.2.2
03/09/2011 17:34:30 sending OFFER to 192.168.2.2
03/09/2011 17:04:32 sending ACK to 192.168.2.2
03/09/2011 17:04:32 sending OFFER to 192.168.2.2
Στο router συνδέεται ένα laptop ενσύρματα που τρέχει linux (έχει και windows 7 pro, αλλά δεν έχει γίνει login σε αυτά τουλάχιστον εδώ και 1,5 εβδομάδα) και 2 android κινητά με 2.3.3 gingerbread.
Επίσης προχθές παρατήρησα ότι είχε αλλάξει το theme στο gmail μου, άλλαξα αμέσως κωδικό στο λογαριασμό αυτό, αν και στα logs του gmail δεν είδα κάποια ξένη ή περίεργη ip.
Όποιος γνωρίζει κάτι θα με βοηθήσει πολύ. Ευχαριστώ!
Μπορεί κάποιος να μου εξηγήσει τι συμβαίνει; Δέχομαι επίθεση;
Με μια αναζήτηση στο φόρουμ βρήκα αρκετά παρόμοια θέματα, αλλά δεν έχω το απαραίτητο υπόβαθρο για να αξιολογήσω την κατάσταση.
Παραθέτω το security log του router, το οποίο είναι ένα Sagem F@st 1500WG.
03/11/2011 10:54:54 sending ACK to 192.168.2.2
03/11/2011 10:54:53 sending OFFER to 192.168.2.2
03/11/2011 10:52:27 192.168.2.6 login success
03/11/2011 10:33:30 192.168.2.6 login success
03/11/2011 10:33:21 192.168.2.6 login fail
03/11/2011 10:22:47 sending ACK to 192.168.2.6
03/11/2011 10:22:27 192.168.2.6 login success
03/11/2011 10:12:45 sending ACK to 192.168.2.2
03/11/2011 10:12:43 sending OFFER to 192.168.2.2
03/11/2011 10:11:48 sending ACK to 192.168.2.5
03/11/2011 10:11:48 sending OFFER to 192.168.2.5
03/11/2011 10:09:31 192.168.2.6 login success
03/11/2011 10:00:49 sending OFFER to 192.168.2.2
03/11/2011 09:47:59 sending OFFER to 192.168.2.2
03/11/2011 08:59:00 **TCP FIN Scan** 192.168.2.6, 41237->> 209.85.229.99, 80 (from ATM1 Outbound)
03/11/2011 08:59:00 **TCP FIN Scan** 192.168.2.6, 37918->> 209.85.229.101, 80 (from ATM1 Outbound)
03/11/2011 08:59:00 **TCP FIN Scan** 192.168.2.6, 38608->> 209.85.227.191, 80 (from ATM1 Outbound)
03/11/2011 08:59:00 **TCP FIN Scan** 192.168.2.6, 38448->> 72.21.206.177, 80 (from ATM1 Outbound)
03/11/2011 08:59:00 **TCP FIN Scan** 192.168.2.6, 48924->> 74.125.79.95, 80 (from ATM1 Outbound)
03/11/2011 08:59:00 **TCP FIN Scan** 192.168.2.6, 56662->> 209.85.227.101, 80 (from ATM1 Outbound)
03/11/2011 08:59:00 **TCP FIN Scan** 192.168.2.6, 52893->> 157.166.224.32, 80 (from ATM1 Outbound)
03/11/2011 08:59:00 **TCP FIN Scan** 192.168.2.6, 49738->> 209.85.227.132, 80 (from ATM1 Outbound)
03/11/2011 08:25:11 sending ACK to 192.168.2.3
03/11/2011 08:25:11 sending OFFER to 192.168.2.3
03/11/2011 07:25:24 sending ACK to 192.168.2.3
03/11/2011 07:25:24 sending OFFER to 192.168.2.3
03/11/2011 07:04:07 sending ACK to 192.168.2.3
03/11/2011 07:04:07 sending OFFER to 192.168.2.3
03/11/2011 05:36:45 sending ACK to 192.168.2.3
03/11/2011 05:36:45 sending OFFER to 192.168.2.3
03/11/2011 05:21:52 NTP Date/Time updated.
03/10/2011 23:21:27 sending ACK to 192.168.2.3
03/10/2011 23:21:27 sending OFFER to 192.168.2.3
03/10/2011 23:18:30 NTP Date/Time updated.
03/10/2011 22:51:08 sending ACK to 192.168.2.3
03/10/2011 22:51:08 sending OFFER to 192.168.2.3
03/10/2011 21:48:55 sending ACK to 192.168.2.3
03/10/2011 21:48:55 sending OFFER to 192.168.2.3
03/10/2011 21:08:36 sending ACK to 192.168.2.3
03/10/2011 21:08:36 sending OFFER to 192.168.2.3
03/10/2011 19:18:40 sending ACK to 192.168.2.3
03/10/2011 19:18:39 sending OFFER to 192.168.2.3
03/10/2011 18:58:44 sending ACK to 192.168.2.3
03/10/2011 18:58:44 sending OFFER to 192.168.2.3
03/10/2011 17:22:08 sending ACK to 192.168.2.3
03/10/2011 17:22:08 sending OFFER to 192.168.2.3
03/10/2011 17:15:06 NTP Date/Time updated.
03/10/2011 16:58:10 sending ACK to 192.168.2.3
03/10/2011 16:58:10 sending OFFER to 192.168.2.3
03/10/2011 16:26:15 sending ACK to 192.168.2.3
03/10/2011 16:26:15 sending OFFER to 192.168.2.3
03/10/2011 15:43:39 sending ACK to 192.168.2.6
03/10/2011 15:43:39 sending OFFER to 192.168.2.6
03/10/2011 15:28:30 sending ACK to 192.168.2.3
03/10/2011 15:28:30 sending OFFER to 192.168.2.3
03/10/2011 11:24:10 sending ACK to 192.168.2.3
03/10/2011 11:24:10 sending OFFER to 192.168.2.3
03/10/2011 11:11:43 NTP Date/Time updated.
03/10/2011 05:08:20 NTP Date/Time updated.
03/10/2011 00:28:33 sending ACK to 192.168.2.3
03/10/2011 00:28:32 sending OFFER to 192.168.2.3
03/09/2011 23:04:56 NTP Date/Time updated.
03/09/2011 22:51:05 sending ACK to 192.168.2.3
03/09/2011 22:51:05 sending OFFER to 192.168.2.3
03/09/2011 22:24:23 sending ACK to 192.168.2.3
03/09/2011 22:24:23 sending OFFER to 192.168.2.3
03/09/2011 22:02:58 sending ACK to 192.168.2.3
03/09/2011 22:02:58 sending OFFER to 192.168.2.3
03/09/2011 21:56:29 sending ACK to 192.168.2.3
03/09/2011 21:56:29 sending OFFER to 192.168.2.3
03/09/2011 21:50:58 sending ACK to 192.168.2.2
03/09/2011 21:50:57 sending OFFER to 192.168.2.2
03/09/2011 21:34:54 sending ACK to 192.168.2.3
03/09/2011 21:34:53 sending OFFER to 192.168.2.3
03/09/2011 21:23:59 sending ACK to 192.168.2.4
03/09/2011 21:23:58 sending OFFER to 192.168.2.4
03/09/2011 21:06:22 sending ACK to 192.168.2.2
03/09/2011 21:06:21 sending OFFER to 192.168.2.2
03/09/2011 20:25:48 sending ACK to 192.168.2.6
03/09/2011 20:25:48 sending OFFER to 192.168.2.6
03/09/2011 20:06:42 sending ACK to 192.168.2.3
03/09/2011 20:06:42 sending OFFER to 192.168.2.3
03/09/2011 18:52:09 **TCP FIN Scan** 74.201.117.247, 80->> 192.168.2.6, 33729 (from ATM1 Inbound)
03/09/2011 18:52:09 **TCP FIN Scan** 75.101.145.196, 80->> 192.168.2.6, 33202 (from ATM1 Inbound)
03/09/2011 18:52:09 **TCP FIN Scan** 66.220.156.11, 80->> 192.168.2.6, 46606 (from ATM1 Inbound)
03/09/2011 18:52:09 **TCP FIN Scan** 66.220.146.22, 80->> 192.168.2.6, 54629 (from ATM1 Inbound)
03/09/2011 18:25:24 sending ACK to 192.168.2.2
03/09/2011 18:25:24 sending OFFER to 192.168.2.2
03/09/2011 18:03:34 **TCP FIN Scan** 192.168.2.6, 54989->> 88.208.12.5, 80 (from ATM1 Outbound)
03/09/2011 18:03:34 **TCP FIN Scan** 192.168.2.6, 45987->> 88.208.24.50, 80 (from ATM1 Outbound)
03/09/2011 18:03:34 **TCP FIN Scan** 192.168.2.6, 47536->> 88.208.12.3, 80 (from ATM1 Outbound)
03/09/2011 17:54:41 **TCP FIN Scan** 192.168.2.6, 58940->> 88.208.12.5, 80 (from ATM1 Outbound)
03/09/2011 17:54:40 **TCP FIN Scan** 192.168.2.6, 57829->> 88.208.12.2, 80 (from ATM1 Outbound)
03/09/2011 17:34:30 sending ACK to 192.168.2.2
03/09/2011 17:34:30 sending OFFER to 192.168.2.2
03/09/2011 17:04:32 sending ACK to 192.168.2.2
03/09/2011 17:04:32 sending OFFER to 192.168.2.2
Στο router συνδέεται ένα laptop ενσύρματα που τρέχει linux (έχει και windows 7 pro, αλλά δεν έχει γίνει login σε αυτά τουλάχιστον εδώ και 1,5 εβδομάδα) και 2 android κινητά με 2.3.3 gingerbread.
Επίσης προχθές παρατήρησα ότι είχε αλλάξει το theme στο gmail μου, άλλαξα αμέσως κωδικό στο λογαριασμό αυτό, αν και στα logs του gmail δεν είδα κάποια ξένη ή περίεργη ip.
Όποιος γνωρίζει κάτι θα με βοηθήσει πολύ. Ευχαριστώ!