NoTrace Security Forum

NoTrace Security Forum
Home | Discussioni Attive | Discussioni Recenti | Segnalibro | Msg privati | Utenti | Download | cerca | faq | RSS | Security Chat
Nome Utente:
Password:
Salva Password
Password Dimenticata?

 Tutti i Forum
 Security
 FireWall e Protezioni
 Una piccola delucidazione rig. ad un USR XX5462
 Forum Bloccato
 Versione Stampabile Bookmark this Topic Aggiungi Segnalibro
I seguenti utenti stanno leggendo questo Forum Qui c'è:
Autore Discussione Precedente Discussione Discussione Successiva  

Yves
Moderatore


Città: Buenos Aires


6097 Messaggi


Inserito il - 02/12/2005 : 16:39:24  Mostra Profilo
è un router con 4 porte rj45 ed il WiFi 11g, funge perfettamente ed ho impostato i filtri MAC, niente di astronomico...Avendo messo in funzione KMLDonkey sulla Suse (l'unico che realmente sembra che vada, anche se pianino e restando con ID basso..) ho fatto i vari settaggi NAT delle porte ecc. ecc. fino li come da copione, ho pure attivato l'invio di mail a me stesso, cioè i log dei "presunti" attacchi (non lo avevo ancora fatto prima, era giusto per vedere se fungeva..)...

ORRORE!, in poco più di 15 ore di funzionamento 130 mail di avviso con tutti gli IP che ha bloccato, e non scherzo sul numero!

Dico, ok che già il ZA "parava" più che bene, ma questo mi sa di esagerato, come è possibile subire tanti attacchi (o forse il FW integrato è un pò ipersensibile...), oppure mi stanno veramente attaccando con una mitragliatrice di quelle "a nastro"?

Posto un log, e ditemi se vi sembra normale:

The Barricade Router log has reached capacity. To keep your log information up to date the current data will be overwritten with new messages. Below is the complete log file of the data that will be overwritten.

You can save this data for review and take any action needed.

---------------------- LOG FILE ------------------------
2005/12/01 19:16:27 : Blocked access attempt from 138.238.159.58
2005/12/01 19:16:27 : Blocked access attempt from 81.34.42.152
2005/12/01 19:16:29 : Blocked access attempt from 24.160.99.50
2005/12/01 19:16:30 : Blocked access attempt from 220.165.167.3
2005/12/01 19:16:32 : Blocked access attempt from 71.208.105.13
2005/12/01 19:16:32 : Blocked access attempt from 87.204.36.8
2005/12/01 19:16:32 : Blocked access attempt from 82.135.4.23
2005/12/01 19:16:32 : Blocked access attempt from 62.35.92.121
2005/12/01 19:16:33 : Blocked access attempt from 84.145.73.211
2005/12/01 19:16:34 : Blocked access attempt from 83.54.171.175
2005/12/01 19:16:34 : Blocked access attempt from 69.113.239.220
2005/12/01 19:16:34 : Blocked access attempt from 84.4.20.84
2005/12/01 19:16:34 : Blocked access attempt from 84.97.50.13
2005/12/01 19:16:35 : Blocked access attempt from 80.33.191.27
2005/12/01 19:16:35 : Blocked access attempt from 24.15.160.176
2005/12/01 19:16:35 : Blocked access attempt from 80.196.170.202
2005/12/01 19:16:35 : Blocked access attempt from 80.33.191.27
2005/12/01 19:16:36 : Blocked access attempt from 81.38.12.121
2005/12/01 19:16:37 : Blocked access attempt from 62.149.128.206
2005/12/01 19:16:38 : Blocked access attempt from 80.196.170.202
2005/12/01 19:16:39 : Blocked access attempt from 64.34.176.145
2005/12/01 19:16:40 : Blocked access attempt from 61.231.84.191
2005/12/01 19:16:41 : Blocked access attempt from 62.149.128.206
2005/12/01 19:16:43 : Blocked access attempt from 83.81.33.120
2005/12/01 19:16:43 : Blocked access attempt from 85.73.198.214
2005/12/01 19:16:43 : Blocked access attempt from 83.81.33.120
2005/12/01 19:16:44 : Blocked access attempt from 80.196.170.202
2005/12/01 19:16:44 : Blocked access attempt from 81.203.192.57
2005/12/01 19:16:45 : Blocked access attempt from 85.48.135.200
2005/12/01 19:16:45 : Blocked access attempt from 80.145.171.27
2005/12/01 19:16:47 : Blocked access attempt from 62.149.128.206
2005/12/01 19:16:48 : Blocked access attempt from 83.177.59.103
2005/12/01 19:16:53 : Blocked access attempt from 193.77.159.10
2005/12/01 19:16:59 : Blocked access attempt from 62.149.128.206
2005/12/01 19:17:00 : Blocked access attempt from 85.102.102.4
2005/12/01 19:17:02 : Blocked access attempt from 218.147.128.207
2005/12/01 19:17:02 : Blocked access attempt from 83.213.205.137
2005/12/01 19:17:04 : Blocked access attempt from 220.240.158.97
2005/12/01 19:17:06 : Blocked access attempt from 217.165.118.177
2005/12/01 19:17:07 : Blocked access attempt from 201.29.90.35
2005/12/01 19:17:07 : Blocked access attempt from 218.147.128.207
2005/12/01 19:17:08 : Blocked access attempt from 81.38.134.204
2005/12/01 19:17:09 : Blocked access attempt from 201.34.157.151
2005/12/01 19:17:09 : Blocked access attempt from 84.97.54.69
2005/12/01 19:17:10 : Blocked access attempt from 83.36.247.99
2005/12/01 19:17:10 : Blocked access attempt from 220.134.253.16
2005/12/01 19:17:11 : Blocked access attempt from 81.60.47.52
2005/12/01 19:17:12 : Blocked access attempt from 82.216.149.78
2005/12/01 19:17:15 : Blocked access attempt from 80.229.148.150
2005/12/01 19:17:17 : Blocked access attempt from 24.85.133.164
2005/12/01 19:17:21 : Blocked access attempt from 218.147.128.207
2005/12/01 19:17:28 : Blocked access attempt from 84.178.92.35
2005/12/01 19:17:29 : Blocked access attempt from 84.158.116.1
2005/12/01 19:17:30 : Blocked access attempt from 81.66.77.148
2005/12/01 19:17:34 : Blocked access attempt from 81.67.36.99
2005/12/01 19:17:37 : Blocked access attempt from 220.248.79.130
2005/12/01 19:17:39 : Blocked access attempt from 83.152.132.103
2005/12/01 19:17:43 : Blocked access attempt from 84.122.119.247
2005/12/01 19:17:44 : Blocked access attempt from 193.95.194.150
2005/12/01 19:17:45 : Blocked access attempt from 81.172.21.197
2005/12/01 19:17:46 : Blocked access attempt from 85.137.14.239
2005/12/01 19:17:48 : Blocked access attempt from 80.7.122.218
2005/12/01 19:17:49 : Blocked access attempt from 68.7.251.22
2005/12/01 19:17:50 : Blocked access attempt from 87.122.57.172
2005/12/01 19:17:50 : Blocked access attempt from 82.228.240.19
2005/12/01 19:17:52 : Blocked access attempt from 212.53.113.182
2005/12/01 19:17:52 : Blocked access attempt from 84.146.108.226
2005/12/01 19:17:52 : Blocked access attempt from 221.200.105.176
2005/12/01 19:17:52 : Blocked access attempt from 201.124.46.123
2005/12/01 19:17:52 : Blocked access attempt from 81.36.30.159
2005/12/01 19:17:53 : Blocked access attempt from 201.124.46.123
2005/12/01 19:17:54 : Blocked access attempt from 83.197.59.9
2005/12/01 19:17:55 : Blocked access attempt from 216.8.163.32
2005/12/01 19:17:55 : Blocked access attempt from 83.22.224.45
2005/12/01 19:17:55 : Blocked access attempt from 190.48.188.222
2005/12/01 19:17:56 : Blocked access attempt from 66.25.255.88
2005/12/01 19:17:56 : Blocked access attempt from 172.216.228.53
2005/12/01 19:17:56 : Blocked access attempt from 81.49.12.198
2005/12/01 19:17:57 : Blocked access attempt from 210.183.138.158
2005/12/01 19:17:58 : Blocked access attempt from 84.94.44.26
2005/12/01 19:18:00 : Blocked access attempt from 84.101.113.192
2005/12/01 19:18:00 : Blocked access attempt from 68.108.251.23
2005/12/01 19:18:01 : Blocked access attempt from 82.126.225.69
2005/12/01 19:18:02 : Blocked access attempt from 66.25.255.88
2005/12/01 19:18:03 : Blocked access attempt from 83.81.33.120
2005/12/01 19:18:03 : Blocked access attempt from 82.56.124.248
2005/12/01 19:18:03 : Blocked access attempt from 82.126.225.69
2005/12/01 19:18:06 : Blocked access attempt from 86.111.67.139
2005/12/01 19:18:07 : Blocked access attempt from 218.88.33.1
2005/12/01 19:18:09 : Blocked access attempt from 82.135.4.138
2005/12/01 19:18:09 : Blocked access attempt from 82.126.225.69
2005/12/01 19:18:09 : Blocked access attempt from 151.37.227.7
2005/12/01 19:18:09 : Blocked access attempt from 84.164.123.187
2005/12/01 19:18:10 : Blocked access attempt from 212.53.113.182
2005/12/01 19:18:12 : Blocked access attempt from 85.72.173.106
2005/12/01 19:18:13 : Blocked access attempt from 80.132.45.12
2005/12/01 19:18:14 : Blocked access attempt from 66.25.255.88
2005/12/01 19:18:14 : Blocked access attempt from 84.170.253.135
2005/12/01 19:18:19 : Blocked access attempt from 85.72.173.106
2005/12/01 19:18:23 : Blocked access attempt from 204.210.60.60
2005/12/01 19:18:25 : Blocked access attempt from 24.222.223.76
2005/12/01 19:18:26 : Blocked access attempt from 142.177.198.151
2005/12/01 19:18:28 : Blocked access attempt from 84.186.106.33
2005/12/01 19:18:28 : Blocked access attempt from 200.109.201.213
2005/12/01 19:18:30 : Blocked access attempt from 218.234.136.160
2005/12/01 19:18:31 : Blocked access attempt from 71.56.105.50
2005/12/01 19:18:31 : Blocked access attempt from 201.19.210.31
2005/12/01 19:18:31 : Blocked access attempt from 193.205.218.95
2005/12/01 19:18:32 : Blocked access attempt from 85.72.173.106
2005/12/01 19:18:34 : Blocked access attempt from 172.211.135.140
2005/12/01 19:18:36 : Blocked access attempt from 24.29.144.50
2005/12/01 19:18:37 : Blocked access attempt from 216.223.52.244
2005/12/01 19:18:38 : Blocked access attempt from 151.2.68.25
2005/12/01 19:18:39 : Blocked access attempt from 217.51.146.47
2005/12/01 19:18:40 : Blocked access attempt from 220.134.253.16
2005/12/01 19:18:40 : Blocked access attempt from 172.212.91.230
2005/12/01 19:18:40 : Blocked access attempt from 211.195.144.66
2005/12/01 19:18:41 : Blocked access attempt from 172.211.135.140
2005/12/01 19:18:41 : Blocked access attempt from 88.1.218.154
2005/12/01 19:18:42 : Blocked access attempt from 193.92.235.185
2005/12/01 19:18:42 : Blocked access attempt from 80.36.126.236
2005/12/01 19:18:43 : Blocked access attempt from 71.56.105.50
2005/12/01 19:18:43 : Blocked access attempt from 80.93.38.170
2005/12/01 19:18:44 : Blocked access attempt from 220.245.186.115
2005/12/01 19:18:44 : Blocked access attempt from 219.65.29.247
2005/12/01 19:18:46 : Blocked access attempt from 58.164.59.251
2005/12/01 19:18:48 : Blocked access attempt from 81.170.14.246
2005/12/01 19:18:50 : Blocked access attempt from 80.228.179.20

Praticamente sono sotto tiro perennemente, che cosa posso fare? Uccidere il mio provaider (da cosa dicono hanno un FW anche loro...).

Ciao.

Modificato da - Yves in Data 02/12/2005 16:44:38

n/a
deleted

Città: eh eh ti piacerebbe saperlo


2419 Messaggi

Inserito il - 02/12/2005 : 16:44:28  Mostra Profilo
ti sembrera strano ma succede anche a me un po la stessa cosa...

outpost quando emule è acceso mi rileva un sacco di accessi bloccati..un po come la tua lista....

certo che c'è ne di gente che non ha niente da fare....

ciaoooooooooooooooooooooooooo
Torna all'inizio della Pagina

n/a
deleted



1470 Messaggi

Inserito il - 02/12/2005 : 16:53:36  Mostra Profilo
Stranissimo,alcuni IP non risultano attivi,altri riportano in Francia,Olanda, Corea etcc... non ho capito bene il procedimento che hai fatto con Suse(come sai sono espertissima del prodotto).
Per vedere se hai già qualcosa all'interno non creare il log così,ma inventati un contatto nella rubrica falso con un nome inesistente (es.vediamo_se[ presso ]mi_hai_bucato.it) questo genera un errore e ti ritorna il messaggio.
Il resto in MP
Torna all'inizio della Pagina
  Discussione Precedente Discussione Discussione Successiva  

 Forum Bloccato
 Versione Stampabile Bookmark this Topic Aggiungi Segnalibro
Vai a:
NoTrace Security Forum
© Nazzareno Schettino
RSS NEWS
Torna all'inizio della Pagina
Pagina generata in 0,25 secondi. TargatoNA | SuperDeeJay | Snitz Forums 2000