Fant ikke noe post for dette så jeg prøver meg her.
jeg fikk nylig problemer med en annen datamaskin og da jeg sjekket loggen på brannmuren kom dette frem. XX i parantes er en IP adresse, en meget interessant en.
Har noen peiling på dette? Og hvorfor kommer dette frem uten at jeg har endret noe? IDS is turn off - operation GAME mode
2012/08/18 12:30:09 detected scan packet: 4102; packet recv TCP 109.205.184.65:80 -> 2.150.140.31:4102 (40) [ RST ACK ]
2012/08/18 12:36:31 detected scan packet: 4846; packet recv TCP 109.205.186.65:80 -> 2.150.140.31:4846 (40) [ RST ACK ]
2012/08/18 12:55:41 IDS is turn off - operation GAME mode
2012/08/18 14:05:40 IDS is turn off - operation GAME mode
2012/08/18 14:12:04 IDS is turn off - operation GAME mode
-------------------------------------------------------------------------------
Init log session
2012/08/18 16:55:59 attack detection: enabled
2012/08/18 16:55:59 IDS level: Low Security
2012/08/18 16:59:03 IDS is turn off - operation GAME mode
2012/08/18 17:02:26 IDS is turn off - operation GAME mode
2012/08/18 17:03:22 IDS is turn off - operation GAME mode
2012/08/18 17:06:22 IDS is turn off - operation GAME mode
2012/08/18 17:15:59 IDS is turn off - operation GAME mode
2012/08/18 17:29:09 detected scan packet: 1891; packet recv TCP 109.205.186.65:80 -> 2.150.76.221:1891 (40) [ RST ACK ]
2012/08/18 17:31:21 detected scan packet: 2247; packet recv TCP 199.59.149.235:80 -> 2.150.76.221:2247 (40) [ RST ACK ]
2012/08/16 07:40:28 detected scan packet: 4045; packet recv TCP 89.151.66.198:80 -> 46.67.123.186:4045 (40) [ RST ACK ]
2012/08/16 08:11:31 detected scan packet: 1176; packet recv TCP 109.205.186.65:80 -> 109.179.143.12:1176 (40) [ RST ACK ]
2012/08/16 08:19:33 detected scan packet: 1707; packet recv TCP 195.88.55.59:80 -> 109.179.143.12:1707 (40) [ RST ACK ]
2012/08/16 08:19:40 detected scan packet: 1723; packet recv TCP 195.88.55.72:80 -> 109.179.143.12:1723 (40) [ RST ACK ]
2012/08/16 08:21:38 detected port scanning: 1723, 1716, 1713, 1719, 1715, 1718, 1747, 1749, 1750, 1748; packet recv TCP (xxx.xx.xx.xx:xx) -> 109.179.143.12:1761 (40) [ RST ACK ]
2012/08/16 08:21:38 Attack SCAN (47878, 46086, 45318, 46854, 45830, 46598, 54022, 54534, 54790, 54278) detected from (xxx.xx.xx.xx) {host blocked for 5 min} [00000170]
2012/08/16 08:21:38 Show PROTECT alert sound: E:\PROGRA~1\Agnitum\OUTPOS~1\warning.wav
2012/08/16 08:26:33 [~] deinit data...
2012/08/16 08:26:33 intruder( xxx.xx.xx.xx) unblocked [00000170]
2012/08/16 08:26:34 [~] deinit...
-------------------------------------------------------------------------------
xx er ipn, og det er mulig dette er helt normalt da jeg er helt grønn på slikt.
Tips mottas med stor takk
jeg fikk nylig problemer med en annen datamaskin og da jeg sjekket loggen på brannmuren kom dette frem. XX i parantes er en IP adresse, en meget interessant en.
Har noen peiling på dette? Og hvorfor kommer dette frem uten at jeg har endret noe? IDS is turn off - operation GAME mode
2012/08/18 12:30:09 detected scan packet: 4102; packet recv TCP 109.205.184.65:80 -> 2.150.140.31:4102 (40) [ RST ACK ]
2012/08/18 12:36:31 detected scan packet: 4846; packet recv TCP 109.205.186.65:80 -> 2.150.140.31:4846 (40) [ RST ACK ]
2012/08/18 12:55:41 IDS is turn off - operation GAME mode
2012/08/18 14:05:40 IDS is turn off - operation GAME mode
2012/08/18 14:12:04 IDS is turn off - operation GAME mode
-------------------------------------------------------------------------------
Init log session
2012/08/18 16:55:59 attack detection: enabled
2012/08/18 16:55:59 IDS level: Low Security
2012/08/18 16:59:03 IDS is turn off - operation GAME mode
2012/08/18 17:02:26 IDS is turn off - operation GAME mode
2012/08/18 17:03:22 IDS is turn off - operation GAME mode
2012/08/18 17:06:22 IDS is turn off - operation GAME mode
2012/08/18 17:15:59 IDS is turn off - operation GAME mode
2012/08/18 17:29:09 detected scan packet: 1891; packet recv TCP 109.205.186.65:80 -> 2.150.76.221:1891 (40) [ RST ACK ]
2012/08/18 17:31:21 detected scan packet: 2247; packet recv TCP 199.59.149.235:80 -> 2.150.76.221:2247 (40) [ RST ACK ]
2012/08/16 07:40:28 detected scan packet: 4045; packet recv TCP 89.151.66.198:80 -> 46.67.123.186:4045 (40) [ RST ACK ]
2012/08/16 08:11:31 detected scan packet: 1176; packet recv TCP 109.205.186.65:80 -> 109.179.143.12:1176 (40) [ RST ACK ]
2012/08/16 08:19:33 detected scan packet: 1707; packet recv TCP 195.88.55.59:80 -> 109.179.143.12:1707 (40) [ RST ACK ]
2012/08/16 08:19:40 detected scan packet: 1723; packet recv TCP 195.88.55.72:80 -> 109.179.143.12:1723 (40) [ RST ACK ]
2012/08/16 08:21:38 detected port scanning: 1723, 1716, 1713, 1719, 1715, 1718, 1747, 1749, 1750, 1748; packet recv TCP (xxx.xx.xx.xx:xx) -> 109.179.143.12:1761 (40) [ RST ACK ]
2012/08/16 08:21:38 Attack SCAN (47878, 46086, 45318, 46854, 45830, 46598, 54022, 54534, 54790, 54278) detected from (xxx.xx.xx.xx) {host blocked for 5 min} [00000170]
2012/08/16 08:21:38 Show PROTECT alert sound: E:\PROGRA~1\Agnitum\OUTPOS~1\warning.wav
2012/08/16 08:26:33 [~] deinit data...
2012/08/16 08:26:33 intruder( xxx.xx.xx.xx) unblocked [00000170]
2012/08/16 08:26:34 [~] deinit...
-------------------------------------------------------------------------------
xx er ipn, og det er mulig dette er helt normalt da jeg er helt grønn på slikt.
Tips mottas med stor takk