network attack
Napsal: 15 Dec 2011 11:43
Viete prosim poradit pravidlo vo fw, ktore by zamezilo aby mi liezlo zo siete von taketo nieco dole priklad co je, a postihnutu zdrojovu ip na lokalnej sieti svihlo do black listu? Postinuty PC generuje niekolko desiatok spojeni so zdrojovym nahodne generovanym portom a skenuje cielovy ip rozsah na porte 80.
Diky.
Netscan detected from host 8x.8x.xxx.10 #
##########################################################################
time protocol src_ip src_port dest_ip dest_port
---------------------------------------------------------------------------
Wed Dec 14 17:25:12 2011 TCP 8x.xx.xxx.10 52227 => 7x.4x.1xx.80 80
Wed Dec 14 17:25:12 2011 TCP 8x.xx.xxx.10 43350 => 7x.4x.1xx.81 80
Wed Dec 14 17:25:12 2011 TCP 8x.xx.xxx.10 45370 => 7x.4x.1xx.82 80
Wed Dec 14 17:25:12 2011 TCP 8x.xx.xxx.10 44718 => 7x.4x.1xx.83 80
Wed Dec 14 17:25:12 2011 TCP 8x.xx.xxx.10 59181 => 7x.4x.1xx.84 80
Wed Dec 14 17:25:12 2011 TCP 8x.xx.xxx.10 40092 => 7x.4x.1xx.85 80
Wed Dec 14 17:25:12 2011 TCP 8x.xx.xxx.10 48450 => 7x.4x.1xx.86 80
Wed Dec 14 17:25:12 2011 TCP 8x.xx.xxx.10 37336 => 7x.4x.1xx.87 80
atd atd
Diky.
Netscan detected from host 8x.8x.xxx.10 #
##########################################################################
time protocol src_ip src_port dest_ip dest_port
---------------------------------------------------------------------------
Wed Dec 14 17:25:12 2011 TCP 8x.xx.xxx.10 52227 => 7x.4x.1xx.80 80
Wed Dec 14 17:25:12 2011 TCP 8x.xx.xxx.10 43350 => 7x.4x.1xx.81 80
Wed Dec 14 17:25:12 2011 TCP 8x.xx.xxx.10 45370 => 7x.4x.1xx.82 80
Wed Dec 14 17:25:12 2011 TCP 8x.xx.xxx.10 44718 => 7x.4x.1xx.83 80
Wed Dec 14 17:25:12 2011 TCP 8x.xx.xxx.10 59181 => 7x.4x.1xx.84 80
Wed Dec 14 17:25:12 2011 TCP 8x.xx.xxx.10 40092 => 7x.4x.1xx.85 80
Wed Dec 14 17:25:12 2011 TCP 8x.xx.xxx.10 48450 => 7x.4x.1xx.86 80
Wed Dec 14 17:25:12 2011 TCP 8x.xx.xxx.10 37336 => 7x.4x.1xx.87 80
atd atd