LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 03-08-2005, 02:19 PM   #1
HunterS
LQ Newbie
 
Registered: Mar 2005
Posts: 3

Rep: Reputation: 0
Is this box owned? Please Help!!


The following is showing up in my logs daily(the exact content does vary). I know the basics to maintaining a server, but that just makes me dangerous. What do these entries represent? I am running a webserver on port 80, but this looks like strange traffic. If you need any more information please let me know.

My IP in the log is 2.7.3.248
eth0 and loopback are my only interfaces

Logged 16 packets on interface eth0
From 4.7.173.26 - 1 packet
To 2.7.3.248 - 1 packet
Service: http (tcp/80) (TH_IN:,eth0,none) - 1 packet
From 24.77.12.96 - 1 packet
To 2.7.3.248 - 1 packet
Service: http (tcp/80) (DTH_IN:,eth0,none) - 1 packet
From 24.180.136.141 - 1 packet
To 2.7.3.248 - 1 packet
Service: http (tcp/80) (ANDWIDTH_IN:,eth0,none) - 1 packet
From 63.93.96.62 - 1 packet
To 2.7.3.248 - 1 packet
Service: http (tcp/80) (DWIDTH_IN:,eth0,none) - 1 packet
From 64.175.250.19 - 2 packets
To 2.7.3.248 - 2 packets
Service: smtp (tcp/25) (NDWIDTH_IN:,eth0,none) - 1 packet
Service: pop3 (tcp/110) (NDWIDTH_IN:,eth0,none) - 1 packet
From 67.49.25.90 - 1 packet
To 2.7.3.248 - 1 packet
Service: http (tcp/80) (_IN:,eth0,none) - 1 packet
From 68.233.210.45 - 1 packet
To 2.7.3.248 - 1 packet
Service: http (tcp/80) (_IN:,eth0,none) - 1 packet
From 2.7.3.248 - 8 packets
To 64.175.250.19 - 1 packet
Service: 47846 (tcp/47846) (NDWIDTH_OUT:,none,eth0) - 1 packet
To 66.75.133.176 - 1 packet
Service: 2932 (tcp/2932) (>BANDWIDTH_OUT:,none,eth0) - 1 packet
To 67.35.114.195 - 1 packet
Service: 2240 (tcp/2240) (:,none,eth0) - 1 packet
To 68.115.49.141 - 1 packet
Service: 4544 (tcp/4544) (T:,none,eth0) - 1 packet
To 69.110.70.141 - 1 packet
Service: 3950 (tcp/3950) (OUT:,none,eth0) - 1 packet
To 152.163.100.132 - 1 packet
Service: 53951 (tcp53951/) (UT:,none,eth0) - 1 packet
To 216.16.89.13 - 1 packet
Service: 4790 (tcp/4790) (,none,eth0) - 1 packet
To 220.253.60.67 - 1 packet
Service: 1820 (tcp/1820) (DWIDTH_OUT:,none,eth0) - 1 packet

Last edited by HunterS; 03-08-2005 at 03:29 PM.
 
Old 03-08-2005, 10:19 PM   #2
Capt_Caveman
Senior Member
 
Registered: Mar 2003
Distribution: Fedora
Posts: 3,658

Rep: Reputation: 69
I don't really see anything in the log that looks blatantly malicious. Do you have any other reason to think you might have been cracked? Any other log messages, odd system behavior or processes, any modifications to system or password files? Also might help if you told us what linux distribution/version and firewall tools you're using, (APF)?
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Microsoft owned! greygoose80 General 1 01-29-2005 04:25 AM
List files owned by user/group guideweb Linux - General 1 09-18-2004 08:18 PM
Make a file owned by root owned by a user sharpie Linux - Newbie 2 02-26-2004 01:26 AM
qmail acting funny maybe box owned zuessh Linux - Software 2 09-22-2003 09:49 PM
Un-Owned files? Half_Elf Linux - General 3 05-18-2003 11:26 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 08:44 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration