Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.user > #205572
| From | Reco <recoverym4n@enotuniq.net> |
|---|---|
| Newsgroups | linux.debian.user |
| Subject | Re: Strange attacks in my log |
| Date | 2019-02-21 13:10 +0100 |
| Message-ID | <xtVkR-60t-11@gated-at.bofh.it> (permalink) |
| References | <xtSZH-4w1-3@gated-at.bofh.it> <xtTCp-4XR-11@gated-at.bofh.it> <xtU5r-56E-9@gated-at.bofh.it> |
| Organization | linux.* mail to news gateway |
Hi. On Thu, Feb 21, 2019 at 11:42:58AM +0100, Hans wrote: > Am Donnerstag, 21. Februar 2019, 11:19:08 CET schrieb Reco: > Hi Reco (and all others), > > sure, I attached the wireshark pcap. Thre is nothing secret in it. That's interesting. Aforementioned pcap does not contain udp:69, but it does contain broadcast udp:161 (src: 192.168.2.117 dst: 255.255.255.255), requesting three OIDs via SNMP v2c: $ snmptranslate -mALL .1.3.6.1.2.1.1.1.0 RFC1213-MIB::sysDescr.0 $ snmptranslate -mALL .1.3.6.1.2.1.1.2.0 RFC1213-MIB::sysObjectID.0 $ snmptranslate -mALL .1.3.6.1.2.1.2.2.1.6.1 RFC1213-MIB::ifPhysAddress.1 A hint. One should not (ab)use SNMP this way. Even if you're doing device discovery - you're doing it wrong by sending SNMP to broadcast. Explains why your other hosts see this though. > However, I know, what the ports are for, but it is not understandable for me, > why there are networking protocols are started, when I just put a stick into > the required slot. And these devices are still not mounted! There is no sense > IMO, why the computer is scanning the network at all. There can be an explanation, though, but Wireshark/tcpdump in not suitable to get it. Install auditd. Invoke "auditctl -a always,exit -S connect". Insert any usb stick Invoke "auditctl -D" to clear the rules. All the answers should wait one at /var/log/audit/audit.log Reco
Back to linux.debian.user | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread
Strange attacks in my log Hans <hans.ullrich@loop.de> - 2019-02-21 10:40 +0100
Re: Strange attacks in my log Reco <recoverym4n@enotuniq.net> - 2019-02-21 11:20 +0100
Re: Strange attacks in my log Hans <hans.ullrich@loop.de> - 2019-02-21 11:50 +0100
Re: Strange attacks in my log Reco <recoverym4n@enotuniq.net> - 2019-02-21 13:10 +0100
Re: Strange attacks in my log Hans <hans.ullrich@loop.de> - 2019-02-21 16:30 +0100
Re: Strange attacks in my log Reco <recoverym4n@enotuniq.net> - 2019-02-21 16:50 +0100
Re: Strange attacks in my log Hans <hans.ullrich@loop.de> - 2019-02-21 17:40 +0100
Re: Strange attacks in my log Reco <recoverym4n@enotuniq.net> - 2019-02-21 18:30 +0100
Re: Strange attacks in my log Dan Purgert <dan@djph.net> - 2019-02-21 11:30 +0100
csiph-web