This evening, my firewall has blocked fif* (15) attempted "Smurf
amplifier" attacks involving 24.6.230.169
(c806401-a.whtrdg1.co.home.com), 24.8.22.81
(c737994-a.aurora1.co.home.com), 24.1.13.39
(c968902-a.whtrdg1.co.home.com), 24.1.13.39
(c968902-a.whtrdg1.co.home.com), 24.13.156.131
(c914014-a.aurora1.co.home.com), and 24.8.18.47
(c39150-a.aurora1.co.home.com) - see "firewall log" below. All times
reply as of yet.
These attacks are still occuring (see "forwarded email alert", at
bottom of message).
Any comments on what's happening? Are others being attacked?
----- Begin firewall log -----
Date: Sat, 26 Feb 2000 22:10:41 -0800
Log (part 1) dumped to email at 02/26/2000 23:10:39.720
02/26/2000 16:19:16.752 - Smurf Amplification Attack Dropped -
Source:24.6.230.169, 8, WAN - Destination:255.255.255.255, 8, LAN -
-
02/26/2000 16:19:17.176 - IP spoof detected -
Source:192.168.1.22, WAN - Destination:24.6.230.169, WAN -
-
02/26/2000 16:25:18.288 - Smurf Amplification Attack Dropped -
Source:24.8.22.81, 8, WAN - Destination:255.255.255.255, 8, LAN -
-
02/26/2000 16:25:18.576 - IP spoof detected -
Source:192.168.1.22, WAN - Destination:24.8.22.81, WAN - -
02/26/2000 16:53:37.416 - UDP packet dropped -
Source:24.1.8.33, 53, WAN - Destination:24.x.y.z, 10568, LAN -
- Rule 0
02/26/2000 16:53:40.416 - UDP packet dropped -
Source:24.1.8.34, 53, WAN - Destination:24.x.y.z, 10570, LAN -
- Rule 0
02/26/2000 16:53:41.432 - UDP packet dropped -
Source:24.0.0.27, 53, WAN - Destination:24.x.y.z, 10572, LAN -
- Rule 0
02/26/2000 16:55:43.096 - Smurf Amplification Attack Dropped -
Source:24.8.22.81, 8, WAN - Destination:255.255.255.255, 8, LAN -
-
02/26/2000 17:02:40.304 - UDP packet dropped -
Source:24.1.8.33, 53, WAN - Destination:24.x.y.z, 10756, LAN -
- Rule 0
02/26/2000 17:02:41.448 - UDP packet dropped -
Source:24.13.86.175, 31790, WAN - Destination:24.x.y.z, 31789,
LAN - - Rule 0
02/26/2000 17:02:42.288 - UDP packet dropped -
Source:24.1.8.34, 53, WAN - Destination:24.x.y.z, 10758, LAN -
- Rule 0
02/26/2000 17:02:43.304 - UDP packet dropped -
Source:24.0.0.27, 53, WAN - Destination:24.x.y.z, 10760, LAN -
- Rule 0
02/26/2000 17:08:40.656 - Smurf Amplification Attack Dropped -
Source:24.8.22.81, 8, WAN - Destination:255.255.255.255, 8, LAN -
-
02/26/2000 17:29:24.752 - Smurf Amplification Attack Dropped -
Source:24.8.22.81, 8, WAN - Destination:255.255.255.255, 8, LAN -
-
02/26/2000 17:58:55.368 - Smurf Amplification Attack Dropped -
Source:24.6.230.169, 8, WAN - Destination:255.255.255.255, 8, LAN -
-
02/26/2000 18:17:28.384 - Smurf Amplification Attack Dropped -
Source:24.6.230.169, 8, WAN - Destination:255.255.255.255, 8, LAN -
-
02/26/2000 19:55:12.368 - Smurf Amplification Attack Dropped -
Source:24.1.13.39, 8, WAN - Destination:24.1.15.255, 8, WAN -
-
02/26/2000 20:21:38.704 - Smurf Amplification Attack Dropped -
Source:24.8.22.81, 8, WAN - Destination:255.255.255.255, 8, LAN -
-
02/26/2000 20:45:19.352 - Smurf Amplification Attack Dropped -
Source:24.8.22.81, 8, WAN - Destination:255.255.255.255, 8, LAN -
-
02/26/2000 20:53:30.064 - Smurf Amplification Attack Dropped -
Source:24.8.22.81, 8, WAN - Destination:255.255.255.255, 8, LAN -
-
02/26/2000 21:19:21.512 - Smurf Amplification Attack Dropped -
Source:24.13.156.131, 8, WAN - Destination:24.13.157.255, 8, WAN -
-
02/26/2000 21:43:05.672 - Smurf Amplification Attack Dropped -
Source:24.8.18.47, 8, WAN - Destination:255.255.255.255, 8, LAN -
-
02/26/2000 22:02:10.448 - Smurf Amplification Attack Dropped -
Source:24.8.18.47, 8, WAN - Destination:255.255.255.255, 8, LAN -
-
----- End firewall log -----
----- Begin forwarded alert email -----
Subject: *** Alert from [firewall] ***
Date: Sat, 26 Feb 2000 22:38:47 -0800
02/26/2000 23:38:46.032 - Smurf Amplification Attack Dropped -
Source:24.8.22.81, 8, WAN - Destination:255.255.255.255, 8, LAN -
-
----- End forwarded alert email -----