1 04/29/2006 13:43:35 Successful WEB login 192.168.1.102 User:xyf
2 04/29/2006 13:40:40 Remote Management: ICMP Ping response denied 206.117.25.91 84.2.159.40 ACCESS BLOCK
3 04/29/2006 13:29:24 Remote Management: ICMP Ping response denied 206.117.25.91 84.2.159.40 ACCESS BLOCK
4 04/29/2006 13:18:17 DHCP server assigns 192.168.1.102 to X60
5 04/29/2006 13:18:09 WLAN STA Association MACAddr:xyxyxyxy
6 04/29/2006 13:18:08 Remote Management: ICMP Ping response denied 206.117.25.91 84.2.159.40 ACCESS BLOCK
7 04/29/2006 13:07:00 Remote Management: ICMP Ping response denied 206.117.25.91 84.2.159.40 ACCESS BLOCK
8 04/29/2006 12:55:48 Remote Management: ICMP Ping response denied 206.117.25.91 84.2.159.40 ACCESS BLOCK
9 04/29/2006 12:44:27 Remote Management: ICMP Ping response denied 206.117.25.91 84.2.159.40 ACCESS BLOCK
10 04/29/2006 12:33:17 Remote Management: ICMP Ping response denied 206.117.25.91 84.2.159.40 ACCESS BLOCK
11 04/29/2006 12:22:10 Remote Management: ICMP Ping response denied 206.117.25.91 84.2.159.40 ACCESS BLOCK
12 04/29/2006 12:10:56 Remote Management: ICMP Ping response denied 206.117.25.91 84.2.159.40 ACCESS BLOCK
13 04/29/2006 11:59:38 Remote Management: ICMP Ping response denied 206.117.25.91 84.2.159.40 ACCESS BLOCK
14 04/29/2006 11:48:17 Remote Management: ICMP Ping response denied 206.117.25.91 84.2.159.40 ACCESS BLOCK
15 04/29/2006 11:36:50 Remote Management: ICMP Ping response denied 206.117.25.91 84.2.159.40 ACCESS BLOCK
16 04/29/2006 11:25:26 Remote Management: ICMP Ping response denied 206.117.25.91 84.2.159.40 ACCESS BLOCK
17 04/29/2006 11:14:11 Remote Management: ICMP Ping response denied 206.117.25.91 84.2.159.40 ACCESS BLOCK
18 04/29/2006 11:02:51 Remote Management: ICMP Ping response denied 206.117.25.91 84.2.159.40 ACCESS BLOCK
19 04/29/2006 10:51:38 Remote Management: ICMP Ping response denied 206.117.25.91 84.2.159.40 ACCESS BLOCK
Látható hogy 11 percenként ICMP pingel....
OrgName: Los Nettos
OrgID: LNET
Address: USC Information Services Division
Address: University Park Campus
City: Los Angeles
StateProv: CA
PostalCode: 90089-0251
Country: US
NetRange: 206.117.0.0 - 206.117.255.255
CIDR: 206.117.0.0/16
NetName: LOS-NETTOS-BLK4
NetHandle: NET-206-117-0-0-1
Parent: NET-206-0-0-0-0
NetType: Direct Allocation
NameServer: CATA.LN.NET
NameServer: C30.LN.NET
Comment:
RegDate: 1995-08-21
Updated: 2005-01-07
RTechHandle: LH-ORG-ARIN
RTechName: LosNettos Hostmaster
RTechPhone: +1-310-822-1511
RTechEmail: hostmaster@ln.net
OrgAbuseHandle: LNAT-ARIN
OrgAbuseName: Los Nettos Abuse Team
OrgAbusePhone: +1-213-740-1531
OrgAbuseEmail: abuse@ln.net
OrgNOCHandle: LNN1-ARIN
OrgNOCName: Los Nettos NOC
OrgNOCPhone: +1-213-740-1531
OrgNOCEmail: noc@ln.net
OrgTechHandle: LH-ORG-ARIN
OrgTechName: LosNettos Hostmaster
OrgTechPhone: +1-310-822-1511
OrgTechEmail: hostmaster@ln.net
# ARIN WHOIS database, last updated 2006-04-28 19:10
# Enter ? for additional hints on searching ARIN's WHOIS database.
A ping eredménye:
PING 206.117.25.91 (206.117.25.91) from 195.70.57.5 : 56(84) bytes of data.
64 bytes from 206.117.25.91: ICMP üzenet sorszáma=0 ttl=49 válaszidő=180.886 msec
64 bytes from 206.117.25.91: ICMP üzenet sorszáma=1 ttl=49 válaszidő=178.743 msec
64 bytes from 206.117.25.91: ICMP üzenet sorszáma=2 ttl=49 válaszidő=180.360 msec
--- 206.117.25.91 ping statisztikái: ---
3 teszt-üzenet elkülve, ebből 3 válasz visszaérkezett, 0% veszteség.
statisztika: min/átlag/max/szórás = 178.743/179.996/180.886/0.975 ms
A traceroute eredménye:
1 kocsonya.itc.hu (195.70.57.1) 0.272 ms 0.167 ms 0.136 ms
2 FE-0-0-111.apache.interware.hu (195.70.58.46) 1.068 ms 0.699 ms 0.719 ms
3 GE-V10.core0.interware.hu (195.70.32.18) 0.696 ms 0.516 ms 0.899 ms
4 GE-0-0-12.border0.interware.hu (195.70.32.4) 0.655 ms 0.784 ms 0.765 ms
5 ge-0-1-0-318.bud4core1.pantel.net (213.253.207.73) 76.701 ms 1.066 ms 0.996 ms
6 bpt-b2-geth2-2.telia.net (213.248.76.41) 1.110 ms 1.261 ms 1.086 ms
7 hbg-bb1-pos7-2-2.telia.net (213.248.64.17) 21.083 ms 20.952 ms 21.481 ms
8 adm-bb1-pos7-0-0.telia.net (213.248.65.153) 26.896 ms ldn-bb1-link.telia.net (80.91.249.10) 34.278 ms adm-bb1-pos7-0-0.telia.net (213.248.65.153) 27.175 ms
9 nyk-bb1-pos0-2-0.telia.net (213.248.65.90) 103.147 ms 103.006 ms ldn-bb1-pos7-0-0.telia.net (213.248.65.149) 34.436 ms
10 ash-bb1-link.telia.net (213.248.83.22) 110.521 ms nyk-bb1-link.telia.net (213.248.65.98) 101.565 ms 101.579 ms
11 ge-2-0-0.r01.asbnva01.us.bb.verio.net (129.250.9.25) 109.070 ms ash-bb1-link.telia.net (213.248.83.22) 107.158 ms ge-2-0-0.r01.asbnva01.us.bb.verio.net (129.250.9.25) 110.458 ms
12 p16-0-1-2.r20.asbnva01.us.bb.verio.net (129.250.2.60) 109.959 ms ge-2-0-0.r01.asbnva01.us.bb.verio.net (129.250.9.25) 108.883 ms p16-0-1-2.r20.asbnva01.us.bb.verio.net (129.250.2.60) 109.549 ms
13 p16-0-1-2.r20.asbnva01.us.bb.verio.net (129.250.2.60) 108.483 ms 108.328 ms p64-2-2-0.r20.mlpsca01.us.bb.verio.net (129.250.2.10) 172.009 ms
14 p64-2-2-0.r20.mlpsca01.us.bb.verio.net (129.250.2.10) 170.615 ms p64-1-2-0.r20.lsanca03.us.bb.verio.net (129.250.4.115) 177.783 ms 179.258 ms
15 p64-1-2-0.r20.lsanca03.us.bb.verio.net (129.250.4.115) 175.999 ms xe-4-1.r00.lsanca03.us.bb.verio.net (129.250.5.33) 179.286 ms p64-1-2-0.r20.lsanca03.us.bb.verio.net (129.250.4.115) 176.209 ms
16 xe-4-1.r00.lsanca03.us.bb.verio.net (129.250.5.33) 175.703 ms 198.172.117.163 (198.172.117.163) 179.588 ms xe-4-1.r00.lsanca03.us.bb.verio.net (129.250.5.33) 176.022 ms
17 130.152.181.169 (130.152.181.169) 181.381 ms 180.567 ms 198.172.117.163 (198.172.117.163) 178.066 ms
18 206.117.25.91 (206.117.25.91) 179.676 ms !<10> 130.152.181.169 (130.152.181.169) 179.072 ms 206.117.25.91 (206.117.25.91) 180.392 ms
Mi ez az IP? Nem találtam mást.
Mit akar az ICMP pinggel?
A logot természetesen elküldtem az abuse@ln.net címre is.
Trójai vagy egyáb backdoor nincs rajtam, egyenként végignéztem minden connected és listening portot.
Napi 24 órában jön.
Szerkesztette: FőDudu 2006. 04. 29. 14:22 -kor