please read this packet log: Crack attempt?

please read this packet log: Crack attempt?

Post by mr.e » Mon, 26 Mar 2001 07:08:51




I=36770 F=0x0000 T=64 (#16)

I=36778 F=0x0000 T=64 (#16)

I=36785 F=0x0000 T=64 (#16)

I=36793 F=0x0000 T=64 (#16)

This just doesn't look right and coincientally my internal LAN is now
down and can't connect to the net.  Ifconfig -a shows all up and
addressed as they should be, however there is no link light on eth1.
This is not anomalous as the LAN has been up and operating for weeks
with no link light on eth1.  Link lights are lit on both internal masqed
machines.  IS someone playing with both my head and my toys?
Opinions and help appreciated
Cheers
BM

 
 
 

please read this packet log: Crack attempt?

Post by Rick Matthe » Mon, 26 Mar 2001 09:55:54




>I=36770 F=0x0000 T=64 (#16)

>I=36778 F=0x0000 T=64 (#16)

The ipchains log entries are not really that difficult to read if
you'll put a little time into it. This page contains almost everything
you'll need (Don't miss the section on logging near the bottom of the -
page):
http://www.linuxdoc.org/HOWTO/IPCHAINS-HOWTO-4.html#ss4.1

Save this link, too:
http://www.robertgraham.com/pubs/firewall-seen.html


>I=36770 F=0x0000 T=64 (#16)

proto=1
Protocol=1
Look in /etc/protocols:
icmp    1   ICMP     # internet control message protocol

With ICMP, the numbers after the colons are not ports; the first is the
type and the second is the code. An ICMP 0 0 is a ping response. You
were probably pinging your gateway, they were responding, and your
firewall was blocking it and logging the block.

You may return to DEFCON 5.

--
Thought for the day:
<http://mysite.directlink.net/matthews/smiles/started.htm>

 
 
 

1. Apache Logs, Possible Crack/Overflow attempt?

Hi,

I was presented with a set of apache logs which were showing some out of
character lines, as in - not thenormal file reauest line sthat you would
expect to see.

Upon further investigation, it would appear that the lines are generated
when a user has .htaccess in their directory defining custom error pages (
401. 403 etc ) however, upon examining the users directory, these error page
types have not been defined in the users .htaccess, which leads me to
believe that these logs are the result of some type of server DoS or buffer
over flow attempt.

I'll paste the logs below, if anyone has seen this before and the end result
was some type of attack... i'd be grateful for information.

Regards,

Stewart Dalzell
Stystems Administrator
XCalibre Communications Ltd

------- SNIP --------

[Sun Aug 18 15:23:43 2002] [notice] cannot use a full URL in a 401
ErrorDocument directive --- ignoring!
[Sun Aug 18 15:23:43 2002] [notice] cannot use a full URL in a 401
ErrorDocument directive --- ignoring!
[Sun Aug 18 15:23:44 2002] [notice] cannot use a full URL in a 401
ErrorDocument directive --- ignoring!
[Sun Aug 18 15:23:44 2002] [notice] cannot use a full URL in a 401
ErrorDocument directive --- ignoring!
[Sun Aug 18 15:23:44 2002] [notice] cannot use a full URL in a 401
ErrorDocument directive --- ignoring!
[Sun Aug 18 15:23:44 2002] [notice] cannot use a full URL in a 401
ErrorDocument directive --- ignoring!
[Sun Aug 18 15:23:44 2002] [notice] cannot use a full URL in a 401
ErrorDocument directive --- ignoring!
[Sun Aug 18 15:23:44 2002] [notice] cannot use a full URL in a 401
ErrorDocument directive --- ignoring!
[Sun Aug 18 15:23:46 2002] [notice] cannot use a full URL in a 401
ErrorDocument directive --- ignoring!
[Sun Aug 18 15:23:46 2002] [notice] cannot use a full URL in a 401
ErrorDocument directive --- ignoring!
[Sun Aug 18 15:23:46 2002] [notice] cannot use a full URL in a 401
ErrorDocument directive --- ignoring!
[Sun Aug 18 15:23:46 2002] [notice] cannot use a full URL in a 401
ErrorDocument directive --- ignoring!
[Sun Aug 18 15:23:46 2002] [notice] cannot use a full URL in a 401
ErrorDocument directive --- ignoring!
[Sun Aug 18 15:23:46 2002] [notice] cannot use a full URL in a 401
ErrorDocument directive --- ignoring!
[Sun Aug 18 15:23:47 2002] [notice] cannot use a full URL in a 401
ErrorDocument directive --- ignoring!
[Sun Aug 18 15:23:47 2002] [notice] cannot use a full URL in a 401
ErrorDocument directive --- ignoring!
[Sun Aug 18 15:23:48 2002] [notice] cannot use a full URL in a 401
ErrorDocument directive --- ignoring!
[Sun Aug 18 15:23:48 2002] [notice] cannot use a full URL in a 401
ErrorDocument directive --- ignoring!
[Sun Aug 18 15:23:48 2002] [notice] cannot use a full URL in a 401

------- SNIP ------

P.S. There are pages upon pages of this, usually with the odd entry of
server denied IP addresses ( Addresses that have hammered forums, or failed
to log in 5 times etc ).

2. kernel sound and ppp

3. Could someone please tell me if this is this an attempted crack ?

4. RH 6.2, emu10k1, and RTL 8139

5. Need help reading ipchains packet log.

6. KerNel-ComPile-mini-HowTo [STABLE 4-14-96]

7. Logging failed log-in attempts

8. Man Page Editor needed? or new project.

9. imapd Crack attempt?

10. Crack attempt?

11. Crack attempt??

12. imapd crack attempt

13. What happened? Cracking attempt?