Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #205567

Strange attacks in my log

From Hans <hans.ullrich@loop.de>
Newsgroups linux.debian.user
Subject Strange attacks in my log
Date 2019-02-21 10:40 +0100
Message-ID <xtSZH-4w1-3@gated-at.bofh.it> (permalink)
Organization linux.* mail to news gateway

Show all headers | View raw


[Multipart message — attachments visible in raw view] - view raw

Hi folks,

I discovered some strange log entries, which are created by "portsentry" (a tool for 
wathing port accesses).

It looks like whenever I insert an USB-drive or a SD-Card, the own system wants to 
access on an UDP-Port (69 or 161). It tries also to access all other computers in the 
network. 

This looks strange for me, because I can not reproduce, why inserting a memeory 
device, network activies are started. 

With wireshark I could see, this is "BJNP" (whatever this means)

Same happens, when pulling the USB-stick or the sd-card out.

This is, what is in the log:

---------------- snip ----------

Feb 21 10:14:39 localhost udisksd[13607]: g_object_unref: assertion'G_IS_OBJECT 
(object)' failed Feb 21 10:14:44 localhost scanbd: /usr/sbin/scanbd: no devices, not 
starting any polling thread Feb 21 10:14:47 localhost portsentry[6172]: attackalert: 
Connect from host: 192.168.2.117/192.168.2.117 to UDP port: 161 Feb 21 10:14:47 
localhost portsentry[6172]: attackalert: Host: 192.168.2.117 is already blocked. 
Ignoring Feb 21 10:14:48 localhost portsentry[6172]: attackalert: Connect from host: 
192.168.2.117/192.168.2.117 to UDP port: 161 Feb 21 10:14:48 localhost 
portsentry[6172]: attackalert: Host: 192.168.2.117 is already blocked. Ignoring Feb 
21 10:14:53 localhost scanbd: /usr/sbin/scanbd: no devices, not starting any polling 
thread Feb 21 10:15:01 localhost CRON[27395]: (root) CMD (if [ -x /usr/bin/
gsmsmsrequeue ]; then /us


---------- snap -----------------

Same log appeares on the other computers (with the same source). I inserted the 
card in the computer with the ip "192.168.2.117".

Can anybody confirm this, or does know some background?

Thanks for enlightening me.

Best regards

Hans

Back to linux.debian.user | Previous | Next — Next in thread | Find similar | Unroll thread


Thread

Strange attacks in my log Hans <hans.ullrich@loop.de> - 2019-02-21 10:40 +0100
  Re: Strange attacks in my log Reco <recoverym4n@enotuniq.net> - 2019-02-21 11:20 +0100
    Re: Strange attacks in my log Hans <hans.ullrich@loop.de> - 2019-02-21 11:50 +0100
      Re: Strange attacks in my log Reco <recoverym4n@enotuniq.net> - 2019-02-21 13:10 +0100
    Re: Strange attacks in my log Hans <hans.ullrich@loop.de> - 2019-02-21 16:30 +0100
      Re: Strange attacks in my log Reco <recoverym4n@enotuniq.net> - 2019-02-21 16:50 +0100
        Re: Strange attacks in my log Hans <hans.ullrich@loop.de> - 2019-02-21 17:40 +0100
          Re: Strange attacks in my log Reco <recoverym4n@enotuniq.net> - 2019-02-21 18:30 +0100
  Re: Strange attacks in my log Dan Purgert <dan@djph.net> - 2019-02-21 11:30 +0100

csiph-web