Codice: Seleziona tutto
ST=192.168.1.12 LEN=40 TOS=0x00 PREC=0x00 TTL=53 ID=561 DF PROTO=TCP SPT=80 DPT=44709 WINDOW=0 RES=0x00 RST URGP=0
Apr 24 11:58:07 -ldsddd kernel: [ 2329.168205] [UFW BLOCK] IN=eth0 OUT= MAC=56:c2:a7:ae:61:ad:fx:xx:xx:xx:xx:xx:08:00 SRC=109.75.xxx.101 DST=192.168.1.12 LEN=40 TOS=0x00 PREC=0x00 TTL=53 ID=562 DF PROTO=TCP SPT=80 DPT=44710 WINDOW=0 RES=0x00 RST URGP=0
Apr 24 11:58:07 -ldsddd kernel: [ 2329.168414] [UFW BLOCK] IN=eth0 OUT= MAC=56:c2:a7:ae:61:ad:fx:xx:xx:xx:xx:xx:08:00 SRC=109.75.xxx.101 DST=192.168.1.12 LEN=40 TOS=0x00 PREC=0x00 TTL=53 ID=563 DF PROTO=TCP SPT=80 DPT=44711 WINDOW=0 RES=0x00 RST URGP=0
Apr 24 11:58:09 -ldsddd kernel: [ 2331.313942] [UFW BLOCK] IN=eth0 OUT= MAC=56:c2:a7:ae:61:ad:fx:xx:xx:xx:xx:xx:08:00 SRC=109.75.xxx.101 DST=192.168.1.12 LEN=40 TOS=0x00 PREC=0x00 TTL=53 ID=991 DF PROTO=TCP SPT=80 DPT=44709 WINDOW=0 RES=0x00 RST URGP=0
Apr 24 11:58:09 -ldsddd kernel: [ 2331.315498] [UFW BLOCK] IN=eth0 OUT= MAC=56:c2:a7:ae:61:ad:fx:xx:xx:xx:xx:xx:08:00 SRC=109.75.xxx.101 DST=192.168.1.12 LEN=40 TOS=0x00 PREC=0x00 TTL=53 ID=992 DF PROTO=TCP SPT=80 DPT=44710 WINDOW=0 RES=0x00 RST URGP=0
Apr 24 11:58:09 -ldsddd kernel: [ 2331.316886] [UFW BLOCK] IN=eth0 OUT= MAC=56:c2:a7:ae:61:ad:fx:xx:xx:xx:xx:xx:08:00 SRC=109.75.xxx.101 DST=192.168.1.12 LEN=40 TOS=0x00 PREC=0x00 TTL=53 ID=993 DF PROTO=TCP SPT=80 DPT=44711 WINDOW=0 RES=0x00 RST URGP=0
Apr 24 11:58:13 -ldsddd kernel: [ 2335.617782] [UFW BLOCK] IN=eth0 OUT= MAC=56:c2:a7:ae:61:ad:fx:xx:xx:xx:xx:xx:08:00 SRC=109.75.xxx.101 DST=192.168.1.12 LEN=40 TOS=0x00 PREC=0x00 TTL=53 ID=1263 DF PROTO=TCP SPT=80 DPT=44709 WINDOW=0 RES=0x00 RST URGP=0
Apr 24 11:58:13 -ldsddd kernel: [ 2335.619260] [UFW BLOCK] IN=eth0 OUT= MAC=56:c2:a7:ae:61:ad:fx:xx:xx:xx:xx:xx:08:00 SRC=109.75.xxx.101 DST=192.168.1.12 LEN=40 TOS=0x00 PREC=0x00 TTL=53 ID=1264 DF PROTO=TCP SPT=80 DPT=44710 WINDOW=0 RES=0x00 RST URGP=0
Apr 24 12:01:52 -ldsddd dhclient: DHCPREQUEST of 192.168.1.12 on eth0 to 192.168.1.1 port 67 (xid=0x5e9e147)
Apr 24 12:01:52 -ldsddd dhclient: DHCPACK of 192.168.1.12 from 192.168.1.1
Apr 24 12:01:53 -ldsddd NetworkManager[563]: <info> (eth0): DHCPv4 state changed renew -> renew
Apr 24 12:01:53 -ldsddd NetworkManager[563]: <info> address 192.168.1.12
Apr 24 12:01:53 -ldsddd NetworkManager[563]: <info> plen 24 (255.255.255.0)
Apr 24 12:01:53 -ldsddd dhclient: bound to 192.168.1.12 -- ren
Codice: Seleziona tutto
11:57:01 ARP cache, ACCEPT
src HW = <fx:xx:xx:xx:xx:xx>
11:57:01 ARP cache, ACCEPT
src HW = <fx:xx:xx:xx:xx:xx>
src IP = <192.168.1.1>
11:58:02 ARP cache, ACCEPT
src IP = <192.168.1.1>
11:58:02 ARP cache, ACCEPT
src HW = <fx:xx:xx:xx:xx:xx>
src IP = <192.168.1.1>
11:58:36 ARP cache, ACCEPT
src HW = <fx:xx:xx:xx:xx:xx>
src IP = <192.168.1.1>
12:01:57 ARP cache, DENY
src HW = <fx:xx:xx:xx:xx:xx>
src IP = <192.168.1.1>
12:01:58 ARP cache, ACCEPT
src HW = <fx:xx:xx:xx:xx:xx>
src IP = <192.168.1.1>
12:16:22 ARP cache, DENY
src HW = <fx:xx:xx:xx:xx:xx>
src IP = <192.168.1.1>
12:16:22 ARP cache, ACCEPT
src HW = <fx:xx:xx:xx:xx:xx>
src IP = <192.168.1.1>
12:18:33 ARP cache, ACCEPT
Il sito da cui sembra venire la connessione è in manutenzione.
E' un tentativo d'intrusione o cosa?