我被種花警告說被當成跳板了 - 資安

Wallis avatar
By Wallis
at 2010-10-14T17:13

Table of Contents

我收到種花電信來信警告

"貴客戶租用之中華電信帳號***** ,遭anti-spam組織uceprotect.net

檢舉透過IP:220.136.48.138 上線期間內,寄送廣告郵件。細詳內容,請您參閱

http://www.uceprotect.net/en/rblcheck.php?ipr=220.136.48.138。"

目前的網路結構是

種花adsl --d-link dir-300 --hub--- 電腦*10

經過掃毒似乎沒發現可以病毒 (江民+木馬期清除大師)

以下是小弟從dir-300取出的紀錄檔

有請大大協助解讀以下紀錄檔

"Oct 14 13:57:48 ","ATTACK Detected: 001[Xmas] attack from WAN
(ip:121.10.139.148) detected. Packet dropped."

"Oct 14 13:56:33 ","ATTACK Detected: 001[Xmas] attack from WAN
(ip:202.39.224.196) detected. Packet dropped."

"Oct 14 13:56:10 ","ATTACK Detected: 001[Xmas] attack from WAN
(ip:168.95.192.1) detected. Packet dropped."

"Oct 14 13:56:00 ","ATTACK Detected: 001[Xmas] attack from WAN
(ip:65.55.15.243) detected. Packet dropped."

"Oct 14 13:55:10 ","ATTACK Detected: 001[SYN-ACK] attack from WAN
(ip:168.95.192.1) detected. Packet dropped."

"Oct 14 13:54:17 ","ATTACK Detected: 001[Xmas] attack from WAN
(ip:124.237.78.87) detected. Packet dropped."

"Oct 14 13:54:10 ","ATTACK Detected: 001[SYN-ACK] attack from WAN
(ip:168.95.192.1) detected. Packet dropped."

"Oct 14 13:54:05 ","ATTACK Detected: 001[Xmas] attack from WAN
(ip:124.237.78.87) detected. Packet dropped."

"Oct 14 13:53:53 ","ATTACK Detected: 001[Xmas] attack from WAN
(ip:124.237.78.87) detected. Packet dropped."

"Oct 14 13:53:45 ","ATTACK Detected: 001[Xmas] attack from WAN
(ip:124.237.78.87) detected. Packet dropped."

"Oct 14 13:53:41 ","ATTACK Detected: 001[Xmas] attack from WAN
(ip:124.237.78.87) detected. Packet dropped."

"Oct 14 13:53:35 ","ATTACK Detected: 001[Xmas] attack from WAN
(ip:124.237.78.87) detected. Packet dropped."

"Oct 14 13:53:32 ","ATTACK Detected: 001[Xmas] attack from WAN
(ip:124.237.78.87) detected. Packet dropped."

"Oct 14 13:53:21 ","ATTACK Detected: 001[Xmas] attack from WAN
(ip:121.10.139.148) detected. Packet dropped."

"Oct 14 13:53:16 ","ATTACK Detected: 001[SYN-ACK] attack from WAN
(ip:168.95.192.1) detected. Packet dropped."

"Oct 14 13:52:49 ","ATTACK Detected: 001[SYN-ACK] attack from WAN
(ip:168.95.192.1) detected. Packet dropped."

"Oct 14 13:52:36 ","ATTACK Detected: 001[SYN-ACK] attack from WAN
(ip:168.95.192.1) detected. Packet dropped."

"Oct 14 13:52:35 ","ATTACK Detected: 001[Xmas] attack from WAN
(ip:168.95.192.1) detected. Packet dropped."

"Oct 14 13:52:29 ","ATTACK Detected: 001[SYN-ACK] attack from WAN
(ip:168.95.192.1) detected. Packet dropped."

"Oct 14 13:52:29 ","ATTACK Detected: 001[Xmas] attack from WAN
(ip:168.95.192.1) detected. Packet dropped."

"Oct 14 13:52:26 ","ATTACK Detected: 001[SYN-ACK] attack from WAN
(ip:168.95.192.1) detected. Packet dropped."

"Oct 14 13:52:18 ","ATTACK Detected: 001[Xmas] attack from WAN
(ip:124.237.121.120) detected. Packet dropped."

"Oct 14 13:51:57 ","ATTACK Detected: 001[Xmas] attack from WAN
(ip:119.127.220.249) detected. Packet dropped."

"Oct 14 13:51:54 ","ATTACK Detected: 001[Xmas] attack from WAN
(ip:124.237.121.120) detected. Packet dropped."

"Oct 14 13:51:45 ","ATTACK Detected: 001[Xmas] attack from WAN
(ip:124.237.121.120) detected. Packet dropped."

"Oct 14 13:51:42 ","ATTACK Detected: 001[Xmas] attack from WAN
(ip:124.237.121.120) detected. Packet dropped."

"Oct 14 13:51:34 ","DHCP: Server sending ACK to 192.168.10.112. (Lease time
= 604800)"

"Oct 14 13:51:34 ","DHCP: Server receive REQUEST from 00:1d:e0:ae:78:b7."

"Oct 14 13:51:33 ","ATTACK Detected: 001[Xmas] attack from WAN
(ip:124.237.121.120) detected. Packet dropped."

"Oct 14 13:51:26 ","DHCP: Server sending ACK to 192.168.10.112. (Lease time
= 604800)"

"Oct 14 13:51:26 ","DHCP: Server receive REQUEST from 00:1d:e0:ae:78:b7."

"Oct 14 13:50:28 ","DHCP: Server sending ACK to 192.168.10.112. (Lease time
= 604800)"

"Oct 14 13:50:28 ","DHCP: Server receive REQUEST from 00:1d:e0:ae:78:b7."

"Oct 14 13:49:57 ","ATTACK Detected: 001[Xmas] attack from WAN
(ip:65.55.15.243) detected. Packet dropped."

"Oct 14 13:48:56 ","DROP: 001. Drop TCP Packet from WAN,
src:220.132.152.183:2156, dst:220.136.40.49:80."

"Oct 14 13:48:50 ","DROP: 001. Drop TCP Packet from WAN,
src:220.132.152.183:2156, dst:220.136.40.49:80."

"Oct 14 13:48:47 ","DROP: 001. Drop TCP Packet from WAN,
src:220.132.152.183:2156, dst:220.136.40.49:80."

"Oct 14 13:46:32 ","ATTACK Detected: 001[Xmas] attack from WAN
(ip:202.39.224.196) detected. Packet dropped."

"Oct 14 13:46:32 ","ATTACK Detected: 001[Xmas] attack from WAN
(ip:202.39.224.196) detected. Packet dropped."

"Oct 14 13:46:32 ","ATTACK Detected: 001[Xmas] attack from WAN
(ip:202.39.224.196) detected. Packet dropped."

"Oct 14 13:46:32 ","ATTACK Detected: 001[Xmas] attack from WAN
(ip:202.39.224.196) detected. Packet dropped."

"Oct 14 13:46:24 ","DHCP: Server sending ACK to 192.168.10.112. (Lease time
= 604800)"

"Oct 14 13:46:24 ","DHCP: Server receive REQUEST from 00:1d:e0:ae:78:b7."

"Oct 14 13:45:44 ","ATTACK Detected: 001[Xmas] attack from WAN
(ip:202.39.224.60) detected. Packet dropped."

"Oct 14 13:43:20 ","ATTACK Detected: 001[Xmas] attack from WAN
(ip:121.10.139.147) detected. Packet dropped."

"Oct 14 13:41:09 ","ATTACK Detected: 001[Xmas] attack from WAN
(ip:168.95.5.218) detected. Packet dropped."

"Oct 14 13:40:17 ","ATTACK Detected: 001[Xmas] attack from WAN
(ip:168.95.5.207) detected. Packet dropped."

"Oct 14 13:39:54 ","ATTACK Detected: 001[Xmas] attack from WAN
(ip:168.95.5.118) detected. Packet dropped."

"Oct 14 13:39:28 ","DROP: 001. Drop TCP Packet from WAN,
src:220.130.128.113:63599, dst:220.136.40.49:80."

"Oct 14 13:39:22 ","DROP: 001. Drop TCP Packet from WAN,
src:220.130.128.113:63599, dst:220.136.40.49:80."

"Oct 14 13:39:19 ","DROP: 001. Drop TCP Packet from WAN,
src:220.130.128.113:63599, dst:220.136.40.49:80."

"Oct 14 13:36:57 ","ATTACK Detected: 001[Xmas] attack from WAN
(ip:119.127.220.249) detected. Packet dropped."

"Oct 14 13:35:09 ","ATTACK Detected: 001[Xmas] attack from WAN
(ip:168.95.5.154) detected. Packet dropped."

"Oct 14 13:34:32 ","ATTACK Detected: 001[Xmas] attack from WAN
(ip:119.127.220.249) detected. Packet dropped."

"Oct 14 13:34:09 ","DROP: 001. Drop TCP Packet from WAN,
src:220.135.80.155:1218, dst:220.136.40.49:80."

"Oct 14 13:34:03 ","DROP: 001. Drop TCP Packet from WAN,
src:220.135.80.155:1218, dst:220.136.40.49:80."

"Oct 14 13:34:00 ","DROP: 001. Drop TCP Packet from WAN,
src:220.135.80.155:1218, dst:220.136.40.49:80."

"Oct 14 13:32:15 ","ATTACK Detected: 001[Xmas] attack from WAN
(ip:119.127.220.249) detected. Packet dropped."

"Oct 14 13:31:56 ","ATTACK Detected: 001[Xmas] attack from WAN
(ip:168.95.5.167) detected. Packet dropped."

"Oct 14 13:27:59 ","ATTACK Detected: 001[Xmas] attack from WAN
(ip:168.95.5.112) detected. Packet dropped."

"Oct 14 13:26:27 ","ATTACK Detected: 001[Xmas] attack from WAN
(ip:168.95.5.103) detected. Packet dropped."

"Oct 14 13:14:45 ","ATTACK Detected: 001[Xmas] attack from WAN
(ip:168.95.5.109) detected. Packet dropped."

"Oct 14 13:13:06 ","ATTACK Detected: 001[Xmas] attack from WAN
(ip:168.95.5.161) detected. Packet dropped."

"Oct 14 13:11:35 ","ATTACK Detected: 001[Xmas] attack from WAN
(ip:168.95.5.159) detected. Packet dropped."

"Oct 14 13:09:00 ","ATTACK Detected: 001[Xmas] attack from WAN
(ip:121.10.139.149) detected. Packet dropped."

"Oct 14 13:08:51 ","ATTACK Detected: 001[Xmas] attack from WAN
(ip:119.127.220.249) detected. Packet dropped."

"Oct 14 13:07:32 ","ATTACK Detected: 001[Xmas] attack from WAN
(ip:168.95.5.206) detected. Packet dropped."

"Oct 14 13:06:06 ","ATTACK Detected: 001[Xmas] attack from WAN
(ip:168.95.192.1) detected. Packet dropped."

"Oct 14 13:05:06 ","ATTACK Detected: 001[SYN-ACK] attack from WAN
(ip:168.95.192.1) detected. Packet dropped."

"Oct 14 13:04:13 ","ATTACK Detected: 001[Xmas] attack from WAN
(ip:209.90.125.254) detected. Packet dropped."

"Oct 14 13:04:06 ","ATTACK Detected: 001[SYN-ACK] attack from WAN
(ip:168.95.192.1) detected. Packet dropped."

"Oct 14 13:03:12 ","ATTACK Detected: 001[SYN-ACK] attack from WAN
(ip:168.95.192.1) detected. Packet dropped."

"Oct 14 13:02:45 ","ATTACK Detected: 001[SYN-ACK] attack from WAN
(ip:168.95.192.1) detected. Packet dropped."

"Oct 14 13:02:32 ","ATTACK Detected: 001[SYN-ACK] attack from WAN
(ip:168.95.192.1) detected. Packet dropped."

"Oct 14 13:02:31 ","ATTACK Detected: 001[Xmas] attack from WAN
(ip:168.95.192.1) detected. Packet dropped."

"Oct 14 13:02:25 ","ATTACK Detected: 001[SYN-ACK] attack from WAN
(ip:168.95.192.1) detected. Packet dropped."

"Oct 14 13:02:25 ","ATTACK Detected: 001[Xmas] attack from WAN
(ip:168.95.192.1) detected. Packet dropped."

"Oct 14 13:02:22 ","ATTACK Detected: 001[SYN-ACK] attack from WAN
(ip:168.95.192.1) detected. Packet dropped."

"Oct 14 13:01:28 ","ATTACK Detected: 001[Xmas] attack from WAN
(ip:65.55.15.243) detected. Packet dropped."

"Oct 14 12:59:10 ","DHCP: Server sending ACK to 192.168.10.112. (Lease time
= 604800)"

"Oct 14 12:59:10 ","DHCP: Server receive REQUEST from 00:1d:e0:ae:78:b7."

"Oct 14 12:59:10 ","DHCP: Server sending OFFER of 192.168.10.112."

"Oct 14 12:59:08 ","DHCP: Server receive DISCOVER from 00:1d:e0:ae:78:b7."

"Oct 14 12:58:03 ","ATTACK Detected: 001[Xmas] attack from WAN
(ip:58.9.120.5) detected. Packet dropped."

"Oct 14 12:51:29 ","ATTACK Detected: 001[Xmas] attack from WAN
(ip:168.95.5.119) detected. Packet dropped."

"Oct 14 12:50:44 ","DROP: 001. Drop TCP Packet from WAN,
src:220.137.65.72:50597, dst:220.136.40.49:80."

"Oct 14 12:50:38 ","DROP: 001. Drop TCP Packet from WAN,
src:220.137.65.72:50597, dst:220.136.40.49:80."

"Oct 14 12:50:35 ","DROP: 001. Drop TCP Packet from WAN,
src:220.137.65.72:50597, dst:220.136.40.49:80."

"Oct 14 12:49:20 ","ATTACK Detected: 001[Xmas] attack from WAN
(ip:65.55.15.243) detected. Packet dropped."

"Oct 14 12:47:29 ","ATTACK Detected: 001[Xmas] attack from WAN
(ip:168.95.192.1) detected. Packet dropped."


被種花警告的時段

"Oct 11 17:46:45 ","DROP: 001. Drop TCP Packet from WAN,
src:117.47.127.237:14549, dst:220.136.48.138:80."

"Oct 11 17:46:28 ","DROP: 001. Drop TCP Packet from WAN,
src:117.47.127.237:14481, dst:220.136.48.138:80."

"Oct 11 17:46:07 ","DROP: 001. Drop TCP Packet from WAN,
src:117.47.127.237:14549, dst:220.136.48.138:80."

"Oct 11 17:45:48 ","DROP: 001. Drop TCP Packet from WAN,
src:117.47.127.237:14549, dst:220.136.48.138:80."

"Oct 11 17:45:40 ","DROP: 001. Drop TCP Packet from WAN,
src:117.47.127.237:14481, dst:220.136.48.138:80."

"Oct 11 17:45:38 ","DROP: 001. Drop TCP Packet from WAN,
src:117.47.127.237:14549, dst:220.136.48.138:80."

"Oct 11 17:45:33 ","DROP: 001. Drop TCP Packet from WAN,
src:117.47.127.237:14549, dst:220.136.48.138:80."

"Oct 11 17:45:16 ","DROP: 001. Drop TCP Packet from WAN,
src:117.47.127.237:14481, dst:220.136.48.138:80."

"Oct 11 17:45:04 ","DROP: 001. Drop TCP Packet from WAN,
src:117.47.127.237:14481, dst:220.136.48.138:80."

"Oct 11 17:44:52 ","DROP: 001. Drop TCP Packet from WAN,
src:117.47.127.237:14481, dst:220.136.48.138:80."

"Oct 11 17:44:40 ","DROP: 001. Drop TCP Packet from WAN,
src:117.47.127.237:14481, dst:220.136.48.138:80."

"Oct 11 17:44:35 ","DROP: 001. Drop TCP Packet from WAN,
src:117.47.127.237:14481, dst:220.136.48.138:80."

"Oct 11 17:44:34 ","DROP: 001. Drop TCP Packet from WAN,
src:117.47.127.237:14481, dst:220.136.48.138:80."

"Oct 11 17:43:04 ","DROP: 001. Drop TCP Packet from WAN,
src:58.114.222.220:1093, dst:220.136.48.138:80."

"Oct 11 17:42:58 ","DROP: 001. Drop TCP Packet from WAN,
src:58.114.222.220:1093, dst:220.136.48.138:80."

"Oct 11 17:42:55 ","DROP: 001. Drop TCP Packet from WAN,
src:58.114.222.220:1093, dst:220.136.48.138:80."

"Oct 11 17:02:25 ","DROP: 001. Drop TCP Packet from WAN,
src:220.143.20.224:3622, dst:220.136.48.138:80."

"Oct 11 17:02:18 ","DROP: 001. Drop TCP Packet from WAN,
src:220.143.20.224:3622, dst:220.136.48.138:80."

"Oct 11 17:02:16 ","DROP: 001. Drop TCP Packet from WAN,
src:220.143.20.224:3622, dst:220.136.48.138:80."

"Oct 11 15:42:44 ","DROP: 001. Drop TCP Packet from WAN,
src:58.114.149.171:54443, dst:220.136.48.138:80."

"Oct 11 15:42:38 ","DROP: 001. Drop TCP Packet from WAN,
src:58.114.149.171:54443, dst:220.136.48.138:80."

"Oct 11 15:42:35 ","DROP: 001. Drop TCP Packet from WAN,
src:58.114.149.171:54443, dst:220.136.48.138:80."

"Oct 11 15:02:05 ","DROP: 001. Drop TCP Packet from WAN,
src:119.120.71.42:3513, dst:220.136.48.138:80."

"Oct 11 15:01:59 ","DROP: 001. Drop TCP Packet from WAN,
src:119.120.71.42:3513, dst:220.136.48.138:80."

"Oct 11 15:01:56 ","DROP: 001. Drop TCP Packet from WAN,
src:119.120.71.42:3513, dst:220.136.48.138:80."

"Oct 11 14:52:38 ","DROP: 001. Drop TCP Packet from WAN,
src:199.86.17.72:4711, dst:220.136.48.138:80."

"Oct 11 14:52:32 ","DROP: 001. Drop TCP Packet from WAN,
src:199.86.17.72:4712, dst:220.136.48.138:80."

"Oct 11 14:52:29 ","DROP: 001. Drop TCP Packet from WAN,
src:199.86.17.72:4711, dst:220.136.48.138:80."

"Oct 11 13:43:00 ","DROP: 001. Drop TCP Packet from WAN,
src:58.114.208.94:4702, dst:220.136.48.138:80."

"Oct 11 13:42:36 ","DROP: 001. Drop TCP Packet from WAN,
src:58.114.208.94:4702, dst:220.136.48.138:80."

"Oct 11 13:42:24 ","DROP: 001. Drop TCP Packet from WAN,
src:58.114.208.94:4702, dst:220.136.48.138:80."

"Oct 11 13:42:18 ","DROP: 001. Drop TCP Packet from WAN,
src:58.114.208.94:4702, dst:220.136.48.138:80."

"Oct 11 13:42:15 ","DROP: 001. Drop TCP Packet from WAN,
src:58.114.208.94:4702, dst:220.136.48.138:80."

"Oct 11 13:01:44 ","DROP: 001. Drop TCP Packet from WAN,
src:220.130.129.91:62445, dst:220.136.48.138:80."

"Oct 11 13:01:38 ","DROP: 001. Drop TCP Packet from WAN,
src:220.130.129.91:62445, dst:220.136.48.138:80."

--
體驗磨練不要一味求快,是否體驗磨練,就像白切肉和滷肉的差別~~~!

--
Tags: 資安

All Comments

Brianna avatar
By Brianna
at 2010-10-18T15:04
format..
Erin avatar
By Erin
at 2010-10-21T03:23
當跳板的資訊沒有在這裡的紀錄檔裏面
Elizabeth avatar
By Elizabeth
at 2010-10-23T16:56
這十台的pc都掃過毒了嗎?
Iris avatar
By Iris
at 2010-10-28T10:04
試試Symantec吧!

msn遭封鎖 網友哀嚎..

Kama avatar
By Kama
at 2010-10-03T03:02
新聞來源: 台視新聞 影響三萬人 民眾求助無門  無事先告知 業者稱安全機制 很多人平常在網路上重要的社交媒介就是MSN,最近有很多民眾MSN帳號突然被封鎖無法登 入,即使向台灣微軟反應也得不到改善,業者表示是因為偵測到帳戶遭受駭客入侵,所以 啟動安全機制,初步估計至才三到五萬名用戶權益受影響,不過有網友的 ...

使用山寨機 的問題!??

Hedda avatar
By Hedda
at 2010-10-02T19:16
行動安全的議題持續受到關注,其中有兩個問題較為嚴重,一是病毒,其二則是手機被控 制的問題。針對防毒的服務,還有很多像是惡意程式的防範,目前像是遠傳也有相關的服 務,可以在網路閘道端幫消費者阻擋威脅,頗類似中華電信的資安艦隊服務。 數聯資安副總張裕敏提到,手機的安全問題可以分做4層:應用程式、作業系統、韌體及 ...

SSG5的設定.

Bennie avatar
By Bennie
at 2010-09-21T22:24
大家好,小弟最近在設定SSG5時遇到一個怪問題. 就是小弟的環境裡有3個實體IP,其中兩個IP分派給兩台SERVER. 所以小弟就設定成... 10.1.1.1 -andgt;SSG5的外部IP 10.1.1.2 -andgt;指給MAIL 10.1.1.3 -andgt;指給OTHER 內部的IP為 ...

鎖白目室友的迅雷

Emily avatar
By Emily
at 2010-09-18T13:13
各位大大好 日前發現我外宿地點的網路 沒有斷線 但是常常必須重新連練 然後房東佛心來的沒有鎖ROSTER 稍微查了一下系統紀錄 發現有個好室友會使用迅雷下載東西 於是我就從防火牆那邊鎖了這段網域 *.sandai.* 但是網路還是會一直斷線 想請教各位大大 封鎖這段網域有沒有辦法鎖住迅雷? 後來網路上爬到 ...

有推荐的 UTM 嗎 ? 20人以下企業 ...

Rosalind avatar
By Rosalind
at 2010-09-17T16:48
最近發現一套免費的UTM產品,介面操作設定蠻人性化的,最近發現一套免費的UTM產品, 叫NUUO UTM, 介面操作設定蠻人性化的, 只不過是全英文的. 裡面的Web Security就有一個IM/P2P的功能, QQ本來就內建在裡面, 只要activate, 就不能login. 這樣應該就可以滿足你老闆的需 ...