Nie jesteś zalogowany.
Jeśli nie posiadasz konta, zarejestruj je już teraz! Pozwoli Ci ono w pełni korzystać z naszego serwisu. Spamerom dziękujemy!
Prosimy o pomoc dla małej Julki — przekaż 1% podatku na Fundacji Dzieciom zdazyć z Pomocą.
Więcej informacji na dug.net.pl/pomagamy/.
Dzień dobry,
Od wczoraj mam ruch na serwerze na porcie UDP 80. Serwer udostępnia pocztę na postfix i dovecot. Nieby nic się nie dzieje, ale co to jest.
Nigdzie tego ruchu nie widać , nic nie słucha na porcie 80, port zamknięty. Czy przypadkiem ktoś mnie nie skanuje? Mam odpalonego file2ban portscan i iptables. Serwer przeskanowałem root-kit i podobnymi wynalazkami, nic nie widać.
Poniżej wynik tcpdump -vvv -i eth0 port 80
08:49:34.713171 IP (tos 0x0, ttl 64, id 0, offset 0, flags [DF], proto UDP (17), length 176) MOJSERWER.domena.pl.sunrpc > c-73-162-36-177.hsd1.ca.comcast.net.http: [bad udp cksum abbc!] UDP, length 148 08:49:34.831906 IP (tos 0x28, ttl 240, id 56849, offset 0, flags [none], proto UDP (17), length 74) 121-75-53-53.dyn.vf.net.nz.http > MOJSERWER.domena.pl.sunrpc: [no cksum] UDP, length 40 08:49:34.832226 IP (tos 0x0, ttl 64, id 0, offset 0, flags [DF], proto UDP (17), length 176) MOJSERWER.domena.pl.sunrpc > 121-75-53-53.dyn.vf.net.nz.http: [bad udp cksum 513c!] UDP, length 148 08:49:35.470300 IP (tos 0x28, ttl 240, id 56855, offset 0, flags [none], proto UDP (17), length 74) 121-75-53-53.dyn.vf.net.nz.http > MOJSERWER.domena.pl.sunrpc: [no cksum] UDP, length 40 08:49:35.470513 IP (tos 0x0, ttl 64, id 0, offset 0, flags [DF], proto UDP (17), length 176) MOJSERWER.domena.pl.sunrpc > 121-75-53-53.dyn.vf.net.nz.http: [bad udp cksum 513c!] UDP, length 148 08:49:38.593929 IP (tos 0x28, ttl 240, id 56916, offset 0, flags [none], proto UDP (17), length 74) c-73-162-36-177.hsd1.ca.comcast.net.http > MOJSERWER.domena.pl.sunrpc: [no cksum] UDP, length 40 08:49:38.594089 IP (tos 0x0, ttl 64, id 0, offset 0, flags [DF], proto UDP (17), length 176) MOJSERWER.domena.pl.sunrpc > c-73-162-36-177.hsd1.ca.comcast.net.http: [bad udp cksum abbc!] UDP, length 148 08:49:40.748279 IP (tos 0x28, ttl 240, id 56956, offset 0, flags [none], proto UDP (17), length 74) 121-75-53-53.dyn.vf.net.nz.http > MOJSERWER.domena.pl.sunrpc: [no cksum] UDP, length 40 08:49:40.748494 IP (tos 0x0, ttl 64, id 0, offset 0, flags [DF], proto UDP (17), length 176) MOJSERWER.domena.pl.sunrpc > 121-75-53-53.dyn.vf.net.nz.http: [bad udp cksum 513c!] UDP, length 148 08:49:40.978449 IP (tos 0x28, ttl 240, id 56964, offset 0, flags [none], proto UDP (17), length 74) 121-75-53-53.dyn.vf.net.nz.http > MOJSERWER.domena.pl.sunrpc: [no cksum] UDP, length 40 08:49:40.978722 IP (tos 0x0, ttl 64, id 0, offset 0, flags [DF], proto UDP (17), length 176) MOJSERWER.domena.pl.sunrpc > 121-75-53-53.dyn.vf.net.nz.http: [bad udp cksum 513c!] UDP, length 148 08:49:41.232961 IP (tos 0x28, ttl 240, id 56966, offset 0, flags [none], proto UDP (17), length 74) c-73-162-36-177.hsd1.ca.comcast.net.http > MOJSERWER.domena.pl.sunrpc: [no cksum] UDP, length 40 08:49:41.233137 IP (tos 0x0, ttl 64, id 0, offset 0, flags [DF], proto UDP (17), length 176) MOJSERWER.domena.pl.sunrpc > c-73-162-36-177.hsd1.ca.comcast.net.http: [bad udp cksum abbc!] UDP, length 148 08:49:43.162789 IP (tos 0x28, ttl 240, id 57001, offset 0, flags [none], proto UDP (17), length 74) 121-75-53-53.dyn.vf.net.nz.http > MOJSERWER.domena.pl.sunrpc: [no cksum] UDP, length 40 08:49:43.163009 IP (tos 0x0, ttl 64, id 0, offset 0, flags [DF], proto UDP (17), length 176) MOJSERWER.domena.pl.sunrpc > 121-75-53-53.dyn.vf.net.nz.http: [bad udp cksum 513c!] UDP, length 148 08:49:44.844968 IP (tos 0x28, ttl 240, id 57034, offset 0, flags [none], proto UDP (17), length 74) c-73-162-36-177.hsd1.ca.comcast.net.http > MOJSERWER.domena.pl.sunrpc: [no cksum] UDP, length 40 08:49:44.845207 IP (tos 0x0, ttl 64, id 0, offset 0, flags [DF], proto UDP (17), length 176) MOJSERWER.domena.pl.sunrpc > c-73-162-36-177.hsd1.ca.comcast.net.http: [bad udp cksum abbc!] UDP, length 148 08:49:45.006139 IP (tos 0x28, ttl 240, id 57040, offset 0, flags [none], proto UDP (17), length 74) 121-75-53-53.dyn.vf.net.nz.http > MOJSERWER.domena.pl.sunrpc: [no cksum] UDP, length 40 08:49:45.006291 IP (tos 0x0, ttl 64, id 0, offset 0, flags [DF], proto UDP (17), length 176) MOJSERWER.domena.pl.sunrpc > 121-75-53-53.dyn.vf.net.nz.http: [bad udp cksum 513c!] UDP, length 148 08:49:45.312976 IP (tos 0x28, ttl 240, id 57041, offset 0, flags [none], proto UDP (17), length 74) c-73-162-36-177.hsd1.ca.comcast.net.http > MOJSERWER.domena.pl.sunrpc: [no cksum] UDP, length 40 08:49:45.313129 IP (tos 0x0, ttl 64, id 0, offset 0, flags [DF], proto UDP (17), length 176) MOJSERWER.domena.pl.sunrpc > c-73-162-36-177.hsd1.ca.comcast.net.http: [bad udp cksum abbc!] UDP, length 148 08:49:46.342412 IP (tos 0x28, ttl 240, id 57062, offset 0, flags [none], proto UDP (17), length 74) 121-75-53-53.dyn.vf.net.nz.http > MOJSERWER.domena.pl.sunrpc: [no cksum] UDP, length 40 08:49:46.342662 IP (tos 0x0, ttl 64, id 0, offset 0, flags [DF], proto UDP (17), length 176) MOJSERWER.domena.pl.sunrpc > 121-75-53-53.dyn.vf.net.nz.http: [bad udp cksum 513c!] UDP, length 148 08:49:48.670899 IP (tos 0x28, ttl 240, id 57104, offset 0, flags [none], proto UDP (17), length 74) c-73-162-36-177.hsd1.ca.comcast.net.http > MOJSERWER.domena.pl.sunrpc: [no cksum] UDP, length 40 08:49:48.671060 IP (tos 0x0, ttl 64, id 0, offset 0, flags [DF], proto UDP (17), length 176) MOJSERWER.domena.pl.sunrpc > c-73-162-36-177.hsd1.ca.comcast.net.http: [bad udp cksum abbc!] UDP, length 148 08:49:48.923774 IP (tos 0x28, ttl 240, id 57114, offset 0, flags [none], proto UDP (17), length 74) c-73-162-36-177.hsd1.ca.comcast.net.http > MOJSERWER.domena.pl.sunrpc: [no cksum] UDP, length 40 08:49:48.923974 IP (tos 0x0, ttl 64, id 0, offset 0, flags [DF], proto UDP (17), length 176) MOJSERWER.domena.pl.sunrpc > c-73-162-36-177.hsd1.ca.comcast.net.http: [bad udp cksum abbc!] UDP, length 148 08:49:49.557529 IP (tos 0x28, ttl 240, id 57126, offset 0, flags [none], proto UDP (17), length 74) 121-75-53-53.dyn.vf.net.nz.http > MOJSERWER.domena.pl.sunrpc: [no cksum] UDP, length 40 08:49:49.557805 IP (tos 0x0, ttl 64, id 0, offset 0, flags [DF], proto UDP (17), length 176) MOJSERWER.domena.pl.sunrpc > 121-75-53-53.dyn.vf.net.nz.http: [bad udp cksum 513c!] UDP, length 148 08:49:50.291666 IP (tos 0x28, ttl 240, id 57137, offset 0, flags [none], proto UDP (17), length 74) c-73-162-36-177.hsd1.ca.comcast.net.http > MOJSERWER.domena.pl.sunrpc: [no cksum] UDP, length 40 08:49:50.291885 IP (tos 0x0, ttl 64, id 0, offset 0, flags [DF], proto UDP (17), length 176) MOJSERWER.domena.pl.sunrpc > c-73-162-36-177.hsd1.ca.comcast.net.http: [bad udp cksum abbc!] UDP, length 148 08:49:50.309339 IP (tos 0x28, ttl 240, id 57139, offset 0, flags [none], proto UDP (17), length 74) c-73-162-36-177.hsd1.ca.comcast.net.http > MOJSERWER.domena.pl.sunrpc: [no cksum] UDP, length 40 08:49:50.309538 IP (tos 0x0, ttl 64, id 0, offset 0, flags [DF], proto UDP (17), length 176) MOJSERWER.domena.pl.sunrpc > c-73-162-36-177.hsd1.ca.comcast.net.http: [bad udp cksum abbc!] UDP, length 148
Pakiety mam aktualne
netstat -ulnp, nie pokazuje portu 80 , że coś na nim jest.
W iptables mam INPUT DROP, więc dlaczego mój serwer na coś odpowiada ? Admini łącza mi zgłosili ten dziwny ruch i pytają się co to.
Dziękuję za pomoc
Offline
Witam pliczek dostępny tutaj
[url]http://lx.waw.pl/mycap.pcap[/url]
Możecie żuciu okiem
Offline
Hm, ruch leci po protokole QUIC (https://en.wikipedia.org/wiki/QUIC), takim nowym wynalazku od gugla. Z samych pakietów za wiele się nie dowiemy bo są zaszyfrowane.
Ihmo, jakaś dziwna próba skanowania ja bym to śmiało blokował.
Offline
Time (s) | Query |
---|---|
0.00009 | SET CHARSET latin2 |
0.00004 | SET NAMES latin2 |
0.00120 | SELECT u.*, g.*, o.logged FROM punbb_users AS u INNER JOIN punbb_groups AS g ON u.group_id=g.g_id LEFT JOIN punbb_online AS o ON o.ident='18.219.214.127' WHERE u.id=1 |
0.00233 | REPLACE INTO punbb_online (user_id, ident, logged) VALUES(1, '18.219.214.127', 1733964776) |
0.00058 | SELECT * FROM punbb_online WHERE logged<1733964476 |
0.00058 | DELETE FROM punbb_online WHERE ident='185.191.171.7' |
0.00054 | DELETE FROM punbb_online WHERE ident='3.145.110.43' |
0.00042 | SELECT topic_id FROM punbb_posts WHERE id=312144 |
0.00083 | SELECT id FROM punbb_posts WHERE topic_id=29693 ORDER BY posted |
0.00035 | SELECT t.subject, t.closed, t.num_replies, t.sticky, f.id AS forum_id, f.forum_name, f.moderators, fp.post_replies, 0 FROM punbb_topics AS t INNER JOIN punbb_forums AS f ON f.id=t.forum_id LEFT JOIN punbb_forum_perms AS fp ON (fp.forum_id=f.id AND fp.group_id=3) WHERE (fp.read_forum IS NULL OR fp.read_forum=1) AND t.id=29693 AND t.moved_to IS NULL |
0.00028 | SELECT search_for, replace_with FROM punbb_censoring |
0.00053 | SELECT u.email, u.title, u.url, u.location, u.use_avatar, u.signature, u.email_setting, u.num_posts, u.registered, u.admin_note, p.id, p.poster AS username, p.poster_id, p.poster_ip, p.poster_email, p.message, p.hide_smilies, p.posted, p.edited, p.edited_by, g.g_id, g.g_user_title, o.user_id AS is_online FROM punbb_posts AS p INNER JOIN punbb_users AS u ON u.id=p.poster_id INNER JOIN punbb_groups AS g ON g.g_id=u.group_id LEFT JOIN punbb_online AS o ON (o.user_id=u.id AND o.user_id!=1 AND o.idle=0) WHERE p.topic_id=29693 ORDER BY p.id LIMIT 0,25 |
0.00076 | UPDATE punbb_topics SET num_views=num_views+1 WHERE id=29693 |
Total query time: 0.00853 s |