[这个贴子最后由5d1a6f在 2004/04/04 01:22am 第 1 次编辑]
04/02/2004 10:08:02 **SYN Flood Stop** (from PPPoE Inbound)
04/02/2004 09:47:34 **SYN Flood** 192.168.2.100, 1968->> 192.102.45.147, 6129 (from PPPoE Outbound)
(同步攻击流从192.168.2.100发出,目的地可能是芬兰)
04/02/2004 09:14:59 **SYN Flood to Host** 218.68.245.231, 1203->> 218.68.245.152, 1025 (from PPPoE Inbound)
04/02/2004 09:14:23 **SYN Flood to Host** 218.68.245.173, 4385->> 218.68.245.152, 1025 (from PPPoE Inbound)
04/02/2004 08:56:35 **SYN Flood to Host** 218.68.245.74, 4386->> 218.68.245.152, 445 (from PPPoE Inbound)
04/02/2004 08:56:26 **SYN Flood to Host** 218.68.245.74, 4425->> 218.68.245.152, 6129 (from PPPoE Inbound)
(来自天津的同步攻击流,不一定是人为攻击的真实源地址,也有可能只是病毒,“from PPPoE Inbound”从外网到内网,而且192.168.2.100应该是WIN2000以上的系统,没打补丁的应尽快打)
04/02/2004 08:47:42 NTP Date/Time updated
04/02/2004 08:47:18 PPPoE get IP:218.68.245.152 (猫获得的公网IP)
04/02/2004 08:47:18 PPPoE start PPP
04/02/2004 08:47:18 PPPoE receive PADS
04/02/2004 08:47:18 PPPoE send PADR
04/02/2004 08:47:18 PPPoE receive PADO
04/02/2004 08:47:18 PPPoE send PADI
04/02/2004 08:47:18 Dial On Demand(PPPoE)
你是说防火墙原本就是开的吗,现在起作用只是因为把SYN的时间改为2秒?
|