Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #205572

Re: Strange attacks in my log

From Reco <recoverym4n@enotuniq.net>
Newsgroups linux.debian.user
Subject Re: Strange attacks in my log
Date 2019-02-21 13:10 +0100
Message-ID <xtVkR-60t-11@gated-at.bofh.it> (permalink)
References <xtSZH-4w1-3@gated-at.bofh.it> <xtTCp-4XR-11@gated-at.bofh.it> <xtU5r-56E-9@gated-at.bofh.it>
Organization linux.* mail to news gateway

Show all headers | View raw


	Hi.

On Thu, Feb 21, 2019 at 11:42:58AM +0100, Hans wrote:
> Am Donnerstag, 21. Februar 2019, 11:19:08 CET schrieb Reco:
> Hi Reco (and all others),
> 
> sure, I attached the wireshark pcap. Thre is nothing secret in it.

That's interesting. Aforementioned pcap does not contain udp:69, but it
does contain broadcast udp:161 (src: 192.168.2.117 dst:
255.255.255.255), requesting three OIDs via SNMP v2c:

$ snmptranslate -mALL .1.3.6.1.2.1.1.1.0
RFC1213-MIB::sysDescr.0
$ snmptranslate -mALL .1.3.6.1.2.1.1.2.0
RFC1213-MIB::sysObjectID.0
$ snmptranslate -mALL .1.3.6.1.2.1.2.2.1.6.1
RFC1213-MIB::ifPhysAddress.1


A hint. One should not (ab)use SNMP this way. Even if you're doing
device discovery - you're doing it wrong by sending SNMP to broadcast.
Explains why your other hosts see this though.


> However, I know, what the ports are for, but it is not understandable for me, 
> why there are networking protocols are started, when I just put a stick into 
> the required slot. And these devices are still not mounted! There is no sense 
> IMO, why the computer is scanning the network at all.

There can be an explanation, though, but Wireshark/tcpdump in not
suitable to get it.

Install auditd.
Invoke "auditctl -a always,exit -S connect".
Insert any usb stick
Invoke "auditctl -D" to clear the rules.

All the answers should wait one at /var/log/audit/audit.log

Reco

Back to linux.debian.user | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread


Thread

Strange attacks in my log Hans <hans.ullrich@loop.de> - 2019-02-21 10:40 +0100
  Re: Strange attacks in my log Reco <recoverym4n@enotuniq.net> - 2019-02-21 11:20 +0100
    Re: Strange attacks in my log Hans <hans.ullrich@loop.de> - 2019-02-21 11:50 +0100
      Re: Strange attacks in my log Reco <recoverym4n@enotuniq.net> - 2019-02-21 13:10 +0100
    Re: Strange attacks in my log Hans <hans.ullrich@loop.de> - 2019-02-21 16:30 +0100
      Re: Strange attacks in my log Reco <recoverym4n@enotuniq.net> - 2019-02-21 16:50 +0100
        Re: Strange attacks in my log Hans <hans.ullrich@loop.de> - 2019-02-21 17:40 +0100
          Re: Strange attacks in my log Reco <recoverym4n@enotuniq.net> - 2019-02-21 18:30 +0100
  Re: Strange attacks in my log Dan Purgert <dan@djph.net> - 2019-02-21 11:30 +0100

csiph-web