PDA

Archiv verlassen und diese Seite im Standarddesign anzeigen : Läuft ein Dienst Amok oder hab ich nen Angreifer



Huhn Hur Tu
22.11.10, 11:20
Am WE bin ich per automaischer Mail belästigt worden.
Ein Blick in die Logs offenbarte folgendes.
Ich bin ein wenig verwirrt über die Acont.de und 1a-treff.de einträge.

Gruss Stefan


This response was from IP 192.168.1.11, reporting an IP address of 213.174.140.113.
This response was from IP 192.168.1.11, reporting an IP address of 213.174.140.113.
This response was from IP 192.168.1.11, reporting an IP address of 213.174.140.113.
This response was from IP 192.168.1.11, reporting an IP address of 213.174.140.113.
This response was from IP 192.168.1.11, reporting an IP address of 213.174.140.113.
This response was from IP 192.168.1.11, reporting an IP address of 212.118.246.227.
This response was from IP 192.168.1.11, reporting an IP address of 212.118.246.227.
This response was from IP 192.168.1.11, reporting an IP address of 212.118.246.227.
This response was from IP 192.168.1.11, reporting an IP address of 212.118.246.227.
This response was from IP 192.168.1.11, reporting an IP address of 212.118.246.227.
This response was from IP 192.168.1.11, reporting an IP address of 212.118.246.227.
This response was from IP 192.168.1.11, reporting an IP address of 212.118.246.227.
This response was from IP 192.168.1.11, reporting an IP address of 212.118.246.227.
This response was from IP 192.168.1.11, reporting an IP address of 212.118.246.227.
This response was from IP 192.168.1.11, reporting an IP address of 174.133.221.245.
This response was from IP 192.168.1.11, reporting an IP address of 174.133.221.245.
This response was from IP 192.168.1.11, reporting an IP address of 174.133.221.245.
This response was from IP 192.168.1.11, reporting an IP address of 174.133.221.245.
This response was from IP 192.168.1.11, reporting an IP address of 174.133.221.245.
This response was from IP 192.168.1.11, reporting an IP address of 174.133.221.245.
This response was from IP 192.168.1.11, reporting an IP address of 174.133.221.245.
This response was from IP 192.168.1.11, reporting an IP address of 174.133.221.245.
This response was from IP 192.168.1.11, reporting an IP address of 174.133.221.245.
This response was from IP 192.168.1.11, reporting an IP address of 212.72.185.20.
This response was from IP 192.168.1.11, reporting an IP address of 212.72.185.20.
This response was from IP 192.168.1.11, reporting an IP address of 212.72.185.20.
This response was from IP 192.168.1.11, reporting an IP address of 212.72.185.20.
This response was from IP 192.168.1.11, reporting an IP address of 212.72.185.20.
This response was from IP 192.168.1.11, reporting an IP address of 212.72.185.20.
This response was from IP 192.168.1.11, reporting an IP address of 212.72.185.20.
This response was from IP 192.168.1.11, reporting an IP address of 212.72.185.20.
This response was from IP 192.168.1.11, reporting an IP address of 212.72.185.20.
This response was from IP 192.168.1.11, reporting an IP address of 83.246.66.18.
This response was from IP 192.168.1.11, reporting an IP address of 83.246.66.18.
This response was from IP 192.168.1.11, reporting an IP address of 83.246.66.18.
This response was from IP 192.168.1.11, reporting an IP address of 94.245.123.201.
This response was from IP 192.168.1.11, reporting an IP address of 94.245.123.201.
This response was from IP 192.168.1.11, reporting an IP address of 94.245.123.201.
This response was from IP 192.168.1.11, reporting an IP address of 65.55.116.183.
This response was from IP 192.168.1.11, reporting an IP address of 65.55.116.183.
This response was from IP 192.168.1.11, reporting an IP address of 92.51.189.254.
This response was from IP 192.168.1.11, reporting an IP address of 92.51.189.254.
This response was from IP 192.168.1.11, reporting an IP address of 195.50.164.161.
This response was from IP 192.168.1.11, reporting an IP address of 195.50.164.161.
This response was from IP 192.168.1.11, reporting an IP address of 188.94.254.62.
This response was from IP 192.168.1.11, reporting an IP address of 188.94.254.62.
This response was from IP 192.168.1.11, reporting an IP address of 192.168.1.19.


query_name_response: Multiple (2) responses received for a query on subnet UNICAST_SUBNET for name WWW.ACONT.DE<00>.
query_name_response: Multiple (2) responses received for a query on subnet UNICAST_SUBNET for name WWW.ACONT.DE<00>.
query_name_response: Multiple (2) responses received for a query on subnet UNICAST_SUBNET for name WWW.ACONT.DE<00>.
query_name_response: Multiple (2) responses received for a query on subnet UNICAST_SUBNET for name WWW.HTTP<00>.
query_name_response: Multiple (2) responses received for a query on subnet UNICAST_SUBNET for name WWW.HTTP<00>.
query_name_response: Multiple (2) responses received for a query on subnet UNICAST_SUBNET for name WWW.HTTP<00>.
query_name_response: Multiple (2) responses received for a query on subnet UNICAST_SUBNET for name WWW.1A-TREFF.DE<00>.
query_name_response: Multiple (2) responses received for a query on subnet UNICAST_SUBNET for name WWW.1A-TREFF.DE<00>.
query_name_response: Multiple (2) responses received for a query on subnet UNICAST_SUBNET for name WWW.1A-TREFF.DE<00>.
query_name_response: Multiple (2) responses received for a query on subnet UNICAST_SUBNET for name G.UK.MSN.COM<00>.
query_name_response: Multiple (2) responses received for a query on subnet UNICAST_SUBNET for name WWW.ZOOBI.DE<00>.
query_name_response: Multiple (2) responses received for a query on subnet UNICAST_SUBNET for name WWW.ZOOBI.DE<00>.
query_name_response: Multiple (2) responses received for a query on subnet UNICAST_SUBNET for name WWW.ZOOBI.DE<00>.
query_name_response: Multiple (2) responses received for a query on subnet UNICAST_SUBNET for name WWW.BUECHER.DE<00>.
query_name_response: Multiple (2) responses received for a query on subnet UNICAST_SUBNET for name WWW.BUECHER.DE<00>.
query_name_response: Multiple (2) responses received for a query on subnet UNICAST_SUBNET for name WWW.EDMONTON.CA<00>.
query_name_response: Multiple (2) responses received for a query on subnet UNICAST_SUBNET for name WWW.EDMONTON.CA<00>.
query_name_response: Multiple (2) responses received for a query on subnet UNICAST_SUBNET for name WWW.EDMONTON.CA<00>.
query_name_response: Multiple (2) responses received for a query on subnet UNICAST_SUBNET for name WWW.SCRIBD.COM<00>.
query_name_response: Multiple (2) responses received for a query on subnet UNICAST_SUBNET for name WWW.BASSPRO.COM<00>.
query_name_response: Multiple (2) responses received for a query on subnet UNICAST_SUBNET for name WWW.BASSPRO.COM<00>.
query_name_response: Multiple (2) responses received for a query on subnet UNICAST_SUBNET for name WWW.SCOOP.CO.NZ<00>.
query_name_response: Multiple (2) responses received for a query on subnet UNICAST_SUBNET for name WWW.SCOOP.CO.NZ<00>.
query_name_response: Multiple (2) responses received for a query on subnet UNICAST_SUBNET for name WWW.SCOOP.CO.NZ<00>.
query_name_response: Multiple (2) responses received for a query on subnet UNICAST_SUBNET for name BEEMP3.COM<00>.
query_name_response: Multiple (2) responses received for a query on subnet UNICAST_SUBNET for name BEEMP3.COM<00>.
query_name_response: Multiple (2) responses received for a query on subnet UNICAST_SUBNET for name BEEMP3.COM<00>.
query_name_response: Multiple (2) responses received for a query on subnet UNICAST_SUBNET for name WWW.ZAZZLE.DE<00>.
query_name_response: Multiple (2) responses received for a query on subnet UNICAST_SUBNET for name WWW.ZAZZLE.DE<00>.
query_name_response: Multiple (2) responses received for a query on subnet UNICAST_SUBNET for name WWW.ZAZZLE.DE<00>.
query_name_response: Multiple (2) responses received for a query on subnet UNICAST_SUBNET for name PETICIOUS.COM<00>.
query_name_response: Multiple (2) responses received for a query on subnet UNICAST_SUBNET for name PETICIOUS.COM<00>.
query_name_response: Multiple (2) responses received for a query on subnet UNICAST_SUBNET for name PETICIOUS.COM<00>.
query_name_response: Multiple (2) responses received for a query on subnet UNICAST_SUBNET for name WWW.VERWANDT.DE<00>.
query_name_response: Multiple (2) responses received for a query on subnet UNICAST_SUBNET for name WWW.VERWANDT.DE<00>.
query_name_response: Multiple (2) responses received for a query on subnet UNICAST_SUBNET for name WWW.VERWANDT.DE<00>.
query_name_response: Multiple (2) responses received for a query on subnet UNICAST_SUBNET for name VENYOO.DE<00>.
query_name_response: Multiple (2) responses received for a query on subnet UNICAST_SUBNET for name WWW.CIAO.DE<00>.
query_name_response: Multiple (2) responses received for a query on subnet UNICAST_SUBNET for name VIEW.ATDMT.COM<00>.
query_name_response: Multiple (2) responses received for a query on subnet UNICAST_SUBNET for name VIEW.ATDMT.COM<00>.
query_name_response: Multiple (2) responses received for a query on subnet UNICAST_SUBNET for name ADS.ADTIGER.DE<00>.
query_name_response: Multiple (2) responses received for a query on subnet UNICAST_SUBNET for name ADS.ADTIGER.DE<00>.
query_name_response: Multiple (2) responses received for a query on subnet UNICAST_SUBNET for name TAG.ADMELD.COM<00>.
query_name_response: Multiple (2) responses received for a query on subnet UNICAST_SUBNET for name TAG.ADMELD.COM<00>.
query_name_response: Multiple (2) responses received for a query on subnet UNICAST_SUBNET for name WWW.RINGER.IT<00>.
query_name_response: Multiple (2) responses received for a query on subnet UNICAST_SUBNET for name WWW.RINGER.IT<00>.
query_name_response: Multiple (2) responses received for a query on subnet UNICAST_SUBNET for name BACKUP<00>.
query_name_response: Multiple (3) responses received for a query on subnet UNICAST_SUBNET for name WWW.ACONT.DE<00>.
query_name_response: Multiple (3) responses received for a query on subnet UNICAST_SUBNET for name WWW.ACONT.DE<00>.
query_name_response: Multiple (3) responses received for a query on subnet UNICAST_SUBNET for name WWW.ACONT.DE<00>.
query_name_response: Multiple (3) responses received for a query on subnet UNICAST_SUBNET for name WWW.ZOOBI.DE<00>.
query_name_response: Multiple (3) responses received for a query on subnet UNICAST_SUBNET for name WWW.ZOOBI.DE<00>.
query_name_response: Multiple (3) responses received for a query on subnet UNICAST_SUBNET for name WWW.SCOOP.CO.NZ<00>.
query_name_response: Multiple (3) responses received for a query on subnet UNICAST_SUBNET for name BEEMP3.COM<00>.
query_name_response: Multiple (3) responses received for a query on subnet UNICAST_SUBNET for name BEEMP3.COM<00>.
query_name_response: Multiple (3) responses received for a query on subnet UNICAST_SUBNET for name BEEMP3.COM<00>.
query_name_response: Multiple (3) responses received for a query on subnet UNICAST_SUBNET for name WWW.ZAZZLE.DE<00>.
query_name_response: Multiple (3) responses received for a query on subnet UNICAST_SUBNET for name WWW.ZAZZLE.DE<00>.
query_name_response: Multiple (3) responses received for a query on subnet UNICAST_SUBNET for name WWW.ZAZZLE.DE<00>.
query_name_response: Multiple (3) responses received for a query on subnet UNICAST_SUBNET for name PETICIOUS.COM<00>.
query_name_response: Multiple (3) responses received for a query on subnet UNICAST_SUBNET for name PETICIOUS.COM<00>.
query_name_response: Multiple (3) responses received for a query on subnet UNICAST_SUBNET for name PETICIOUS.COM<00>.
query_name_response: Multiple (3) responses received for a query on subnet UNICAST_SUBNET for name WWW.VERWANDT.DE<00>.
query_name_response: Multiple (3) responses received for a query on subnet UNICAST_SUBNET for name WWW.VERWANDT.DE<00>.
query_name_response: Multiple (3) responses received for a query on subnet UNICAST_SUBNET for name WWW.VERWANDT.DE<00>.
query_name_response: Multiple (3) responses received for a query on subnet UNICAST_SUBNET for name VENYOO.DE<00>.
query_name_response: Multiple (3) responses received for a query on subnet UNICAST_SUBNET for name WWW.CIAO.DE<00>.
query_name_response: Multiple (4) responses received for a query on subnet UNICAST_SUBNET for name WWW.ACONT.DE<00>.
query_name_response: Multiple (4) responses received for a query on subnet UNICAST_SUBNET for name WWW.ACONT.DE<00>.
query_name_response: Multiple (4) responses received for a query on subnet UNICAST_SUBNET for name WWW.ACONT.DE<00>.
query_name_response: Multiple (4) responses received for a query on subnet UNICAST_SUBNET for name WWW.ZAZZLE.DE<00>.
query_name_response: Multiple (4) responses received for a query on subnet UNICAST_SUBNET for name WWW.ZAZZLE.DE<00>.
query_name_response: Multiple (4) responses received for a query on subnet UNICAST_SUBNET for name WWW.ZAZZLE.DE<00>.
query_name_response: Multiple (4) responses received for a query on subnet UNICAST_SUBNET for name PETICIOUS.COM<00>.
query_name_response: Multiple (4) responses received for a query on subnet UNICAST_SUBNET for name PETICIOUS.COM<00>.
query_name_response: Multiple (4) responses received for a query on subnet UNICAST_SUBNET for name PETICIOUS.COM<00>.
query_name_response: Multiple (4) responses received for a query on subnet UNICAST_SUBNET for name WWW.VERWANDT.DE<00>.
query_name_response: Multiple (4) responses received for a query on subnet UNICAST_SUBNET for name WWW.VERWANDT.DE<00>.
query_name_response: Multiple (4) responses received for a query on subnet UNICAST_SUBNET for name WWW.VERWANDT.DE<00>.
query_name_response: Multiple (4) responses received for a query on subnet UNICAST_SUBNET for name VENYOO.DE<00>.
query_name_response: Multiple (4) responses received for a query on subnet UNICAST_SUBNET for name WWW.CIAO.DE<00>.


Nov 19 00:00:50 palm slapd[2728]: conn=1435 op=13 do_search: invalid dn (sambaDomainName=,(null))
Nov 19 00:00:59 palm slapd[2728]: SASL [conn=1436] Failure: realm changed: authentication aborted
Nov 19 00:03:59 palm slapd[2728]: SASL [conn=1438] Failure: realm changed: authentication aborted
Nov 19 00:05:36 palm slapd[2728]: conn=1439 op=2 do_search: invalid dn (sambaDomainName=,(null))
Nov 19 00:05:41 palm slapd[2728]: conn=1439 op=10 do_search: invalid dn (sambaDomainName=,(null))
Nov 19 00:09:11 palm slapd[2728]: SASL [conn=1443] Failure: realm changed: authentication aborted
Nov 19 00:10:14 palm ntpd[2712]: kernel time sync status change 0001
Nov 19 00:15:59 palm slapd[2728]: SASL [conn=1446] Failure: realm changed: authentication aborted
Nov 19 00:17:52 palm slapd[2728]: conn=1450 op=2 do_search: invalid dn (sambaDomainName=,(null))
Nov 19 00:17:57 palm slapd[2728]: conn=1450 op=10 do_search: invalid dn (sambaDomainName=,(null))
Nov 19 00:18:59 palm slapd[2728]: SASL [conn=1451] Failure: realm changed: authentication aborted
Nov 19 00:24:11 palm slapd[2728]: SASL [conn=1454] Failure: realm changed: authentication aborted
Nov 19 00:30:09 palm slapd[2728]: conn=1456 op=2 do_search: invalid dn (sambaDomainName=,(null))


Nov 19 02:00:28 palm nscd: nss_ldap: could not connect to any LDAP server as cn=admin,dc=light,dc=com - Can't contact LDAP server
Nov 19 02:00:28 palm nscd: nss_ldap: failed to bind to LDAP server ldap://127.0.0.1: Can't contact LDAP server
Nov 19 02:00:28 palm nscd: nss_ldap: reconnecting to LDAP server (sleeping 1 seconds)...
Nov 19 02:00:29 palma nscd: nss_ldap: could not connect to any LDAP server as cn=admin,dc=light,dc=com - Can't contact LDAP server
Nov 19 02:00:29 palm nscd: nss_ldap: failed to bind to LDAP server ldap://127.0.0.1: Can't contact LDAP server
Nov 19 02:00:29 palm nscd: nss_ldap: could not search LDAP server - Server is unavailable
Nov 19 02:00:29 palm nscd: nss_ldap: could not connect to any LDAP server as cn=admin,dc=light,dc=com - Can't contact LDAP server
Nov 19 02:00:29 palm nscd: nss_ldap: failed to bind to LDAP server ldap://127.0.0.1: Can't contact LDAP server
Nov 19 02:00:29 palm nscd: nss_ldap: could not connect to any LDAP server as cn=admin,dc=light,dc=com - Can't contact LDAP server
Nov 19 02:00:29 palm nscd: nss_ldap: failed to bind to LDAP server ldap://127.0.0.1: Can't contact LDAP server
Nov 19 02:00:29 palma nscd: nss_ldap: reconnecting to LDAP server (sleeping 1 seconds)...
Nov 19 02:00:30 palm nscd: nss_ldap: could not connect to any LDAP server as cn=admin,dc=light,dc=com - Can't contact LDAP server
Nov 19 02:00:30 palm nscd: nss_ldap: failed to bind to LDAP server ldap://127.0.0.1: Can't contact LDAP server
Nov 19 02:00:30 palm nscd: nss_ldap: could not search LDAP server - Server is unavailable


Nov 19 02:04:00 palm slapd[9352]: SASL [conn=9] Failure: realm changed: authentication aborted
Nov 19 02:08:21 palm slapd[9352]: conn=11 op=2 do_search: invalid dn (sambaDomainName=,(null))
Nov 19 02:08:26 palm slapd[9352]: conn=11 op=10 do_search: invalid dn (sambaDomainName=,(null))
Nov 19 02:09:12 palm slapd[9352]: SASL [conn=12] Failure: realm changed: authentication aborted
Nov 19 02:16:02 palm slapd[9352]: SASL [conn=16] Failure: realm changed: authentication aborted
Nov 19 02:19:00 palm slapd[9352]: SASL [conn=19] Failure: realm changed: authentication aborted
Nov 19 02:19:01 palm slapd[9352]: conn=20 op=2 do_search: invalid dn (sambaDomainName=,(null))
Nov 19 02:19:03 palm slapd[9352]: conn=20 op=10 do_search: invalid dn (sambaDomainName=,(null))
Nov 19 02:20:37 palm slapd[9352]: conn=22 op=2 do_search: invalid dn (sambaDomainName=,(null))
Nov 19 02:20:43 palm slapd[9352]: conn=22 op=10 do_search: invalid dn (sambaDomainName=,(null))
Nov 19 02:24:12 palm slapd[9352]: SASL [conn=25] Failure: realm changed: authentication aborted
Nov 19 02:29:45 palm slapd[9352]: conn=27 op=2 do_search: invalid dn (sambaDomainName=LIGHT,(null))
Nov 19 02:29:45 palm slapd[9352]: conn=27 op=5 do_search: invalid dn (sambaDomainName=LIGHT,(null))
Nov 19 02:31:02 palm slapd[9352]: SASL [conn=28] Failure: realm changed: authentication aborted
Nov 19 02:32:54 palm slapd[9352]: conn=30 op=2 do_search: invalid dn (sambaDomainName=,(null))


Nov 21 09:46:03 palm3 ntop[2556]: **WARNING** packet truncated (18890->8232)
Nov 21 09:46:03 palm3 ntop[2556]: **WARNING** packet truncated (20338->8232)
Nov 21 09:46:03 palm3 ntop[2556]: **WARNING** packet truncated (21786->8232)
Nov 21 09:46:03 palm3 ntop[2556]: **WARNING** packet truncated (23234->8232)
Nov 21 09:46:03 palm3 ntop[2556]: **WARNING** packet truncated (24682->8232)
Nov 21 09:46:03 palm3 ntop[2556]: **WARNING** packet truncated (26130->8232)
Nov 21 09:46:03 palm3 ntop[2556]: **WARNING** packet truncated (27578->8232)
Nov 21 09:46:03 palm3 ntop[2556]: **WARNING** packet truncated (29026->8232)
. . .

. . .

. . .


Nov 21 09:52:10 palm ntpd[2644]: kernel time sync status change 4001
Nov 21 10:09:15 palm ntpd[2644]: kernel time sync status change 0001
Nov 21 11:00:31 palm ntpd[2644]: kernel time sync status change 4001
Nov 21 11:17:33 palm ntpd[2644]: kernel time sync status change 0001
Nov 21 13:17:09 palm ntpd[2644]: kernel time sync status change 4001
Nov 21 16:08:02 palm ntpd[2644]: kernel time sync status change 0001
Nov 21 16:42:10 palm ntpd[2644]: kernel time sync status change 4001
Nov 21 17:16:18 palm ntpd[2644]: kernel time sync status change 0001
Nov 21 18:41:41 palm ntpd[2644]: kernel time sync status change 4001
Nov 21 19:32:53 palm ntpd[2644]: kernel time sync status change 0001
Nov 21 20:07:06 palm ntpd[2644]: kernel time sync status change 4001
Nov 21 21:15:19 palm ntpd[2644]: kernel time sync status change 0001
Nov 21 22:57:44 palm ntpd[2644]: kernel time sync status change 4001
Nov 21 23:31:52 palm ntpd[2644]: kernel time sync status change 0001