Security Incidents mailing list archives

route oddness


From: mike () FUBAR KISH CC IL US (Mike)
Date: Wed, 12 Apr 2000 11:42:01 -0500


Been seeing some funny things in my routing table (HP-UX 10.20). Was
hoping someone could give me some ideas about them. What bothers me is
that they are all outside the US and seem to be from the same IP
classes. Are these traces of an exploit or normal traffic? Any ideas would
be helpful.

x.x.x.x = my gateway

...
194.44.35.23/255.255.255.255
                x.x.x.x    UGHD       0       5  lan0       1500
195.16.108.230/255.255.255.255
                x.x.x.x    UGHD       0       4  lan0       1500
195.161.59.38/255.255.255.255
                x.x.x.x    UGHD       0       6  lan0       1500
195.206.226.1/255.255.255.255
                x.x.x.x    UGHD       0       3  lan0       1500
195.206.226.2/255.255.255.255
                x.x.x.x    UGHD       0       3  lan0       1500
195.206.226.3/255.255.255.255
                x.x.x.x    UGHD       0       3  lan0       1500
195.206.226.5/255.255.255.255
                x.x.x.x    UGHD       0      35  lan0       1500
195.206.226.6/255.255.255.255
                x.x.x.x    UGHD       0      15  lan0       1500
195.206.226.7/255.255.255.255
                x.x.x.x    UGHD       0       3  lan0       1500
195.206.226.8/255.255.255.255
                x.x.x.x    UGHD       0       0  lan0       1500
195.206.226.10/255.255.255.255
                x.x.x.x    UGHD       0       3  lan0       1500
195.206.226.18/255.255.255.255
                x.x.x.x    UGHD       0      22  lan0       1500
195.206.226.19/255.255.255.255
                x.x.x.x    UGHD       0      56  lan0       1500
195.206.226.20/255.255.255.255
                x.x.x.x    UGHD       0      11  lan0       1500
195.206.226.22/255.255.255.255
                x.x.x.x    UGHD       0      49  lan0       1500
195.206.226.23/255.255.255.255
                x.x.x.x    UGHD       0       3  lan0       1500
195.206.226.24/255.255.255.255
                x.x.x.x    UGHD       0      16  lan0       1500
212.1.70.133/255.255.255.255
                x.x.x.x    UGHD       0       3  lan0       1500
212.1.70.138/255.255.255.255
                x.x.x.x    UGHD       0       3  lan0       1500
212.1.70.138/255.255.255.255
                x.x.x.x    UGHD       0       3  lan0       1500
212.1.70.142/255.255.255.255
                x.x.x.x    UGHD       0       2  lan0       1500
212.1.70.144/255.255.255.255
                x.x.x.x    UGHD       0       3  lan0       1500
212.248.112.131/255.255.255.255
                x.x.x.x    UGHD       0       3  lan0       1500
212.248.112.137/255.255.255.255
                x.x.x.x    UGHD       0       3  lan0       1500
212.248.112.139/255.255.255.255
                x.x.x.x    UGHD       0       3  lan0       1500
212.248.112.145/255.255.255.255
                x.x.x.x    UGHD       0       5  lan0       1500
212.248.112.149/255.255.255.255
                x.x.x.x    UGHD       0       5  lan0       1500
213.24.169.149/255.255.255.255
                x.x.x.x    UGHD       0       2  lan0       1500
default/0.0.0.0 x.x.x.x    UG      350734154893  lan0       1500
...

Mike


Current thread: