Security Incidents mailing list archives
Tons of ping activity?
From: Steve Cody <security () GULBRANDSEN COM>
Date: Thu, 28 Dec 2000 09:09:32 -0500
I have been noticing this activity in my logs more recently. Last night seems to have been the most active. Is this normal ping activity, or what? Yesterday, I was checking one of the sources of this traffic, and it was a Cisco router. I have not changed any addresses. These are call coming to "255.255.255.255:0". This is only a portion of the activity. There was about 200 pages worth in my firewall log for yesterday and last night. Am I wrong about the type of traffic that I think this is? Dec 27 16:19:26 brimstone kernel: Packet log: input DENY eth0 PROTO=1 207.239.230.33:11 255.255.255.255:0 L=56 S=0xC0 I=43238 F=0x0000 T=244 Dec 27 16:19:26 brimstone kernel: Packet log: input DENY eth1 PROTO=1 207.239.230.33:11 255.255.255.255:0 L=56 S=0xC0 I=43238 F=0x0000 T=244 Dec 27 16:21:12 brimstone kernel: Packet log: input DENY eth0 PROTO=1 202.178.243.254:11 255.255.255.255:0 L=56 S=0xC0 I=42007 F=0x0000 T=233 Dec 27 16:21:12 brimstone kernel: Packet log: input DENY eth1 PROTO=1 202.178.243.254:11 255.255.255.255:0 L=56 S=0xC0 I=42007 F=0x0000 T=233 Dec 27 16:45:41 brimstone kernel: Packet log: input DENY eth0 PROTO=1 210.57.16.44:11 255.255.255.255:0 L=56 S=0xC0 I=25285 F=0x0000 T=243 Dec 27 16:45:41 brimstone kernel: Packet log: input DENY eth1 PROTO=1 210.57.16.44:11 255.255.255.255:0 L=56 S=0xC0 I=25285 F=0x0000 T=243 Dec 27 17:07:50 brimstone kernel: Packet log: input DENY eth0 PROTO=1 202.178.243.254:11 255.255.255.255:0 L=56 S=0xC0 I=27205 F=0x0000 T=233 Dec 27 17:07:50 brimstone kernel: Packet log: input DENY eth1 PROTO=1 202.178.243.254:11 255.255.255.255:0 L=56 S=0xC0 I=27205 F=0x0000 T=233 Any ideas? Thanks! Steve Cody
Current thread:
- Tons of ping activity? Steve Cody (Dec 28)
- Re: Tons of ping activity? Pavel Kankovsky (Dec 30)
- Re: Tons of ping activity? Rob (Dec 30)
- Re: Tons of ping activity? Pavel Kankovsky (Dec 30)