LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 12-13-2010, 05:21 PM   #1
eRJe
Member
 
Registered: May 2005
Location: Netherlands
Distribution: Slackware 14.1 Kernel 3.12.1
Posts: 103

Rep: Reputation: 16
intruder alert in /var/log/messages


Hi,

I have noticed some possible security issues in my /var/log.messages log but i'm not sure how to read the messages. I'm getting the following lines:

Code:
Dec 13 23:14:07 AIF:PRIV TCP packet: IN=eth1 SRC=41.205.116.116 DST=xx.xx.xx.xx  PROTO=TCP DPT=Telnet(23) SPT=4184 TTL=52 SYN
Dec 13 23:14:43 AIF:PRIV TCP packet: IN=eth1 SRC=46.41.76.166   DST=xx.xx.xx.xx  PROTO=TCP DPT=Telnet(23) SPT=3282 TTL=52 SYN
Dec 13 23:14:55 AIF:PRIV TCP packet: IN=eth1 SRC=200.121.207.59 DST=xx.xx.xx.xx  PROTO=TCP DPT=Telnet(23) SPT=4026 TTL=48 SYN

Dec 13 23:16:43 AIF:PRIV UDP packet: IN=eth1 SRC=xx.xx.xx.xx DST=xx.xx.xx.255  PROTO=UDP DPT=SMB Data(138) SPT=SMB Data(138) TTL=64

Dec 13 23:27:14 AIF:ICMP-request: IN=eth1 SRC=209.170.120.50 DST=xx.xx.xx.xx  PROTO=ICMP TYPE/CODE=Echo request(8,0) TTL=22 SEQ=0
Dec 13 23:27:35 AIF:ICMP-request: IN=eth1 SRC=66.114.48.31   DST=xx.xx.xx.xx  PROTO=ICMP TYPE/CODE=Echo request(8,0) TTL=1 SEQ=7
Dec 13 23:27:55 AIF:ICMP-request: IN=eth1 SRC=66.114.48.31   DST=xx.xx.xx.xx  PROTO=ICMP TYPE/CODE=Echo request(8,0) TTL=6 SEQ=12
Dec 13 23:28:15 AIF:ICMP-request: IN=eth1 SRC=66.114.50.67   DST=xx.xx.xx.xx  PROTO=ICMP TYPE/CODE=Echo request(8,0) TTL=1 SEQ=6
Dec 13 23:28:35 AIF:ICMP-request: IN=eth1 SRC=66.114.50.67   DST=xx.xx.xx.xx  PROTO=ICMP TYPE/CODE=Echo request(8,0) TTL=6 SEQ=11

Dec 13 23:49:17 AIF:UNPRIV TCP packet: IN=eth1 SRC=124.133.2.2 DST=xx.xx.xx.xx  PROTO=TCP DPT=4899 SPT=6000 TTL=106 SYN
As I said I'm not to sure what I'm seeing here but I think I'm being "probed" where it says PROTO=ICMP TYPE/CODE=Echo request(8,0)? Some of the IP's I traced end up in China.

I assume the line with PROTO=UDP DPT=SMB Data(138) SPT=SMB Data(138) is coming from samba and should not be an issue. However the destination IP is (slightly) different then the source IP (my server)ie SRC=xx.xx.214.167 and DST=xx.xx.215.255

What do these lines in my log mean and is there anything else I can check for security issues other then the log files in /var/log?

Thanks!
Robbert
 
Old 12-13-2010, 05:28 PM   #2
win32sux
LQ Guru
 
Registered: Jul 2003
Location: Los Angeles
Distribution: Ubuntu
Posts: 9,870

Rep: Reputation: 380Reputation: 380Reputation: 380Reputation: 380
Those look like firewall log entries for filtered packets. If that's the case, it would seem that you were port scanned and pinged and your firewall did what was expected of it. This sort of thing is quite common on Internet-enabled hosts. You should check your firewall script's documentation to make sure the messages mean the packets were filtered.

Running Nmap against your host might also be a good idea, as it'll let you verify things are working properly.

Last edited by win32sux; 12-13-2010 at 05:33 PM.
 
Old 12-14-2010, 07:08 AM   #3
eRJe
Member
 
Registered: May 2005
Location: Netherlands
Distribution: Slackware 14.1 Kernel 3.12.1
Posts: 103

Original Poster
Rep: Reputation: 16
Hi Win32sux,

Thanks! I guess you are right. It is indeed log output from my firewall. I just did a ping from a different remote computer and PROTO=ICMP TYPE/CODE=Echo request(8,0) TTL=116 SEQ=1024 seems to be the response in the log file.

I actually think it could have been related to some spyware because after a few good cleanups, it appears that i'm getting a lot less entries in my logfile.

Thanks for the nmap hint. I will have a look at this.

Robbert
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
/var/adm/messages vs /var/log/messages gomes1333 Linux - General 1 04-06-2010 04:08 AM
Location of messages other than /var/log/messages? HelpMe2877 Linux - General 1 07-06-2009 09:52 AM
/var/log/messages and /var/log/cron not working sigkill Linux - Software 6 08-09-2008 01:08 PM
Redirecting the kernel messages to file other than /var/log/messages jyotika_b83 Linux - General 3 04-28-2005 06:39 PM
/var/log/messages full of these messages. Should I be concerned? mdavis Linux - Security 5 04-16-2004 10:08 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 04:20 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration