Security Incidents mailing list archives

Tons of ping activity?


From: Steve Cody <security () GULBRANDSEN COM>
Date: Thu, 28 Dec 2000 09:09:32 -0500

I have been noticing this activity in my logs more recently.  Last night seems to have been the most active.  Is this 
normal ping activity, or what?  Yesterday, I was checking one of the sources of this traffic, and it was a Cisco 
router.  I have not changed any addresses.  These are call coming to "255.255.255.255:0".  This is only a portion of 
the activity.  There was about 200 pages worth in my firewall log for yesterday and last night.  Am I wrong about the 
type of traffic that I think this is?

Dec 27 16:19:26 brimstone kernel: Packet log: input DENY eth0 PROTO=1 207.239.230.33:11 255.255.255.255:0 L=56 S=0xC0 
I=43238 F=0x0000 T=244
Dec 27 16:19:26 brimstone kernel: Packet log: input DENY eth1 PROTO=1 207.239.230.33:11 255.255.255.255:0 L=56 S=0xC0 
I=43238 F=0x0000 T=244
Dec 27 16:21:12 brimstone kernel: Packet log: input DENY eth0 PROTO=1 202.178.243.254:11 255.255.255.255:0 L=56 S=0xC0 
I=42007 F=0x0000 T=233
Dec 27 16:21:12 brimstone kernel: Packet log: input DENY eth1 PROTO=1 202.178.243.254:11 255.255.255.255:0 L=56 S=0xC0 
I=42007 F=0x0000 T=233
Dec 27 16:45:41 brimstone kernel: Packet log: input DENY eth0 PROTO=1 210.57.16.44:11 255.255.255.255:0 L=56 S=0xC0 
I=25285 F=0x0000 T=243
Dec 27 16:45:41 brimstone kernel: Packet log: input DENY eth1 PROTO=1 210.57.16.44:11 255.255.255.255:0 L=56 S=0xC0 
I=25285 F=0x0000 T=243
Dec 27 17:07:50 brimstone kernel: Packet log: input DENY eth0 PROTO=1 202.178.243.254:11 255.255.255.255:0 L=56 S=0xC0 
I=27205 F=0x0000 T=233
Dec 27 17:07:50 brimstone kernel: Packet log: input DENY eth1 PROTO=1 202.178.243.254:11 255.255.255.255:0 L=56 S=0xC0 
I=27205 F=0x0000 T=233

Any ideas?

Thanks!
Steve Cody

Current thread: