Stelix
27-07-2007, 23:25
Più che un problema il mio vuole essere un confronto con voi,
il log del mio router ogni giorno registra decine e decine di "Kernel Intrusion", dai più svariati IP (la maggior parte comuqnue della stessa classe) e nelle più svariate porte, a tutte le ore del giorno (anche quando non c'è nessun PC connesso).
Quasi tutti gli ip sorgenti sono Italiani, molto spesso anche se con ip diversi dalla stessa zona.
Ok, si tratta dei soliti che si divertono a fare port-scanning ma anche voi registrate la stessa quantità di log del genere?
O ci possono essere altre possibili cause?
Sì insomma, è nella norma o il mio è un caso patologico?
Per farvi un esempio questo è il mio report di oggi (ovviamente ho nascosto gli ip) dalle 16:00 alle 23:00...booh....
Jul 27 23:00:07 user alert kernel: Intrusion -> IN=ppp_8_35_1 OUT= MAC= SRC=84.xxx.xxx.xxx DST=151.xxx.xxx.xxx LEN=48 TOS=0x00 PREC=0x00 TTL=114 ID=1795 DF PROTO=TCP SPT=1457 DPT=4662 WINDOW=65535 RES=0x00 SYN URGP=0
Jul 27 22:48:23 user alert kernel: Intrusion -> IN=ppp_8_35_1 OUT= MAC= SRC=151.xxx.xxx.xxx DST=151.xxx.xxx.xxx LEN=48 TOS=0x00 PREC=0x00 TTL=121 ID=7647 DF PROTO=TCP SPT=4948 DPT=5800 WINDOW=16384 RES=0x00 SYN URGP=0
Jul 27 22:44:11 user alert kernel: Intrusion -> IN=ppp_8_35_1 OUT= MAC= SRC=151.xxx.xxx.xxx DST=151.xxx.xxx.xxx LEN=48 TOS=0x00 PREC=0x00 TTL=121 ID=28330 DF PROTO=TCP SPT=4609 DPT=5800 WINDOW=16384 RES=0x00 SYN URGP=0
Jul 27 22:28:24 user alert kernel: Intrusion -> IN=ppp_8_35_1 OUT= MAC= SRC=151.xxx.xxx.xxx DST=151.xxx.xxx.xxx LEN=48 TOS=0x00 PREC=0x00 TTL=121 ID=30229 DF PROTO=TCP SPT=4525 DPT=445 WINDOW=32768 RES=0x00 SYN URGP=0
Jul 27 22:18:57 user alert kernel: Intrusion -> IN=ppp_8_35_1 OUT= MAC= SRC=151.xxx.xxx.xxx DST=151.xxx.xxx.xxx LEN=40 TOS=0x00 PREC=0x00 TTL=121 ID=24588 PROTO=TCP SPT=22608 DPT=139 WINDOW=16384 RES=0x00 SYN URGP=0
Jul 27 22:18:13 user alert kernel: Intrusion -> IN=ppp_8_35_1 OUT= MAC= SRC=151.xxx.xxx.xxx DST=151.xxx.xxx.xxx LEN=48 TOS=0x00 PREC=0x00 TTL=121 ID=65531 DF PROTO=TCP SPT=4100 DPT=135 WINDOW=16384 RES=0x00 SYN URGP=0
Jul 27 22:18:10 user alert kernel: Intrusion -> IN=ppp_8_35_1 OUT= MAC= SRC=151.xxx.xxx.xxx DST=151.xxx.xxx.xxx LEN=48 TOS=0x00 PREC=0x00 TTL=121 ID=65308 DF PROTO=TCP SPT=4100 DPT=135 WINDOW=16384 RES=0x00 SYN URGP=0
Jul 27 22:17:50 user alert kernel: Intrusion -> IN=ppp_8_35_1 OUT= MAC= SRC=151.xxx.xxx.xxx DST=151.xxx.xxx.xxx LEN=48 TOS=0x00 PREC=0x00 TTL=121 ID=63808 DF PROTO=TCP SPT=3766 DPT=139 WINDOW=16384 RES=0x00 SYN URGP=0
Jul 27 22:17:47 user alert kernel: Intrusion -> IN=ppp_8_35_1 OUT= MAC= SRC=151.xxx.xxx.xxx DST=151.xxx.xxx.xxx LEN=48 TOS=0x00 PREC=0x00 TTL=121 ID=63565 DF PROTO=TCP SPT=3766 DPT=139 WINDOW=16384 RES=0x00 SYN URGP=0
Jul 27 22:17:10 user alert kernel: Intrusion -> IN=ppp_8_35_1 OUT= MAC= SRC=151.xxx.xxx.xxx DST=151.xxx.xxx.xxx LEN=48 TOS=0x00 PREC=0x00 TTL=121 ID=60776 DF PROTO=TCP SPT=3194 DPT=139 WINDOW=16384 RES=0x00 SYN URGP=0
Jul 27 22:17:08 user alert kernel: Intrusion -> IN=ppp_8_35_1 OUT= MAC= SRC=151.xxx.xxx.xxx DST=151.xxx.xxx.xxx LEN=48 TOS=0x00 PREC=0x00 TTL=121 ID=60550 DF PROTO=TCP SPT=3194 DPT=139 WINDOW=16384 RES=0x00 SYN URGP=0
Jul 27 22:17:02 user alert kernel: Intrusion -> IN=ppp_8_35_1 OUT= MAC= SRC=151.xxx.xxx.xxx DST=151.xxx.xxx.xxx LEN=48 TOS=0x00 PREC=0x00 TTL=121 ID=60106 DF PROTO=TCP SPT=3070 DPT=445 WINDOW=16384 RES=0x00 SYN URGP=0
Jul 27 22:16:59 user alert kernel: Intrusion -> IN=ppp_8_35_1 OUT= MAC= SRC=151.xxx.xxx.xxx DST=151.xxx.xxx.xxx LEN=48 TOS=0x00 PREC=0x00 TTL=121 ID=59863 DF PROTO=TCP SPT=3070 DPT=445 WINDOW=16384 RES=0x00 SYN URGP=0
Jul 27 22:15:07 user alert kernel: Intrusion -> IN=ppp_8_35_1 OUT= MAC= SRC=151.xxx.xxx.xxx DST=151.xxx.xxx.xxx LEN=40 TOS=0x00 PREC=0x00 TTL=121 ID=27659 PROTO=TCP SPT=24009 DPT=139 WINDOW=16384 RES=0x00 SYN URGP=0
Jul 27 22:04:13 user alert kernel: Intrusion -> IN=ppp_8_35_1 OUT= MAC= SRC=151.xxx.xxx.xxx DST=151.xxx.xxx.xxx LEN=40 TOS=0x00 PREC=0x00 TTL=121 ID=3708 PROTO=TCP SPT=22608 DPT=139 WINDOW=16384 RES=0x00 SYN URGP=0
Jul 27 21:56:08 user alert kernel: Intrusion -> IN=ppp_8_35_1 OUT= MAC= SRC=151.xxx.xxx.xxx DST=151.xxx.xxx.xxx LEN=48 TOS=0x00 PREC=0x00 TTL=121 ID=21229 DF PROTO=TCP SPT=3812 DPT=139 WINDOW=16384 RES=0x00 SYN URGP=0
Jul 27 21:46:51 user alert kernel: Intrusion -> IN=ppp_8_35_1 OUT= MAC= SRC=121.xxx.xxx.xxx DST=151.xxx.xxx.xxx LEN=48 TOS=0x00 PREC=0x00 TTL=100 ID=42509 DF PROTO=TCP SPT=2487 DPT=4662 WINDOW=65535 RES=0x00 SYN URGP=0
Jul 27 21:35:58 user alert kernel: Intrusion -> IN=ppp_8_35_1 OUT= MAC= SRC=81.xxx.xxx.xxx DST=151.xxx.xxx.xxx LEN=48 TOS=0x00 PREC=0x00 TTL=115 ID=43153 DF PROTO=TCP SPT=3681 DPT=4662 WINDOW=65535 RES=0x00 SYN URGP=0
Jul 27 21:35:52 user alert kernel: Intrusion -> IN=ppp_8_35_1 OUT= MAC= SRC=81.xxx.xxx.xxx DST=151.xxx.xxx.xxx LEN=48 TOS=0x00 PREC=0x00 TTL=115 ID=42593 DF PROTO=TCP SPT=3681 DPT=4662 WINDOW=65535 RES=0x00 SYN URGP=0
Jul 27 21:35:49 user alert kernel: Intrusion -> IN=ppp_8_35_1 OUT= MAC= SRC=81.xxx.xxx.xxx DST=151.xxx.xxx.xxx LEN=48 TOS=0x00 PREC=0x00 TTL=115 ID=42301 DF PROTO=TCP SPT=3681 DPT=4662 WINDOW=65535 RES=0x00 SYN URGP=0
Jul 27 21:34:00 user alert kernel: Intrusion -> IN=ppp_8_35_1 OUT= MAC= SRC=81.xxx.xxx.xxx DST=151.xxx.xxx.xxx LEN=48 TOS=0x00 PREC=0x00 TTL=119 ID=23508 DF PROTO=TCP SPT=2395 DPT=4662 WINDOW=16384 RES=0x00 SYN URGP=0
Jul 27 21:33:57 user alert kernel: Intrusion -> IN=ppp_8_35_1 OUT= MAC= SRC=81.xxx.xxx.xxx DST=151.xxx.xxx.xxx LEN=48 TOS=0x00 PREC=0x00 TTL=119 ID=23421 DF PROTO=TCP SPT=2395 DPT=4662 WINDOW=16384 RES=0x00 SYN URGP=0
Jul 27 21:29:46 user alert kernel: Intrusion -> IN=ppp_8_35_1 OUT= MAC= SRC=200.xxx.xxx.xxx DST=151.xxx.xxx.xxx LEN=48 TOS=0x00 PREC=0x00 TTL=116 ID=50857 DF PROTO=TCP SPT=2988 DPT=4662 WINDOW=65535 RES=0x00 SYN URGP=0
Jul 27 21:29:43 user alert kernel: Intrusion -> IN=ppp_8_35_1 OUT= MAC= SRC=200.xxx.xxx.xxx DST=151.xxx.xxx.xxx LEN=48 TOS=0x00 PREC=0x00 TTL=116 ID=50780 DF PROTO=TCP SPT=2988 DPT=4662 WINDOW=65535 RES=0x00 SYN URGP=0
Jul 27 21:29:19 user alert kernel: Intrusion -> IN=ppp_8_35_1 OUT= MAC= SRC=151.xxx.xxx.xxx DST=151.xxx.xxx.xxx LEN=64 TOS=0x00 PREC=0x00 TTL=39 ID=45788 DF PROTO=TCP SPT=4269 DPT=135 WINDOW=53760 RES=0x00 SYN URGP=0
Jul 27 21:29:17 user alert kernel: Intrusion -> IN=ppp_8_35_1 OUT= MAC= SRC=151.xxx.xxx.xxx DST=151.xxx.xxx.xxx LEN=64 TOS=0x00 PREC=0x00 TTL=39 ID=45382 DF PROTO=TCP SPT=4269 DPT=135 WINDOW=53760 RES=0x00 SYN URGP=0
Jul 27 21:29:12 user alert kernel: Intrusion -> IN=ppp_8_35_1 OUT= MAC= SRC=151.xxx.xxx.xxx DST=151.xxx.xxx.xxx LEN=40 TOS=0x00 PREC=0x00 TTL=121 ID=30448 PROTO=TCP SPT=24009 DPT=139 WINDOW=16384 RES=0x00 SYN URGP=0
Jul 27 21:24:21 user alert kernel: Intrusion -> IN=ppp_8_35_1 OUT= MAC= SRC=90.xxx.xxx.xxx DST=151.xxx.xxx.xxx LEN=48 TOS=0x00 PREC=0x00 TTL=116 ID=32477 DF PROTO=TCP SPT=3703 DPT=4662 WINDOW=16384 RES=0x00 SYN URGP=0
Jul 27 21:24:20 user alert kernel: Intrusion -> IN=ppp_8_35_1 OUT= MAC= SRC=84.xxx.xxx.xxx DST=151.xxx.xxx.xxx LEN=48 TOS=0x00 PREC=0x00 TTL=114 ID=4805 DF PROTO=TCP SPT=2972 DPT=4662 WINDOW=65535 RES=0x00 SYN URGP=0
Jul 27 21:24:18 user alert kernel: Intrusion -> IN=ppp_8_35_1 OUT= MAC= SRC=84.xxx.xxx.xxx DST=151.xxx.xxx.xxx LEN=48 TOS=0x00 PREC=0x00 TTL=114 ID=4397 DF PROTO=TCP SPT=2972 DPT=4662 WINDOW=65535 RES=0x00 SYN URGP=0
Jul 27 21:24:15 user alert kernel: Intrusion -> IN=ppp_8_35_1 OUT= MAC= SRC=90.xxx.xxx.xxx DST=151.xxx.xxx.xxx LEN=48 TOS=0x00 PREC=0x00 TTL=116 ID=32327 DF PROTO=TCP SPT=3703 DPT=4662 WINDOW=16384 RES=0x00 SYN URGP=0
Jul 27 21:24:12 user alert kernel: Intrusion -> IN=ppp_8_35_1 OUT= MAC= SRC=90.xxx.xxx.xxx DST=151.xxx.xxx.xxx LEN=48 TOS=0x00 PREC=0x00 TTL=116 ID=32220 DF PROTO=TCP SPT=3703 DPT=4662 WINDOW=16384 RES=0x00 SYN URGP=0
Jul 27 21:14:38 user alert kernel: Intrusion -> IN=ppp_8_35_1 OUT= MAC= SRC=87.xxx.xxx.xxx DST=151.xxx.xxx.xxx LEN=48 TOS=0x00 PREC=0x00 TTL=117 ID=50312 DF PROTO=TCP SPT=3327 DPT=4662 WINDOW=65535 RES=0x00 SYN URGP=0
Jul 27 21:12:10 user alert kernel: Intrusion -> IN=ppp_8_35_1 OUT= MAC= SRC=81.xxx.xxx.xxx DST=151.xxx.xxx.xxx LEN=48 TOS=0x00 PREC=0x00 TTL=115 ID=60073 DF PROTO=TCP SPT=18231 DPT=4662 WINDOW=65535 RES=0x00 SYN URGP=0
Jul 27 21:07:52 user alert kernel: Intrusion -> IN=ppp_8_35_1 OUT= MAC= SRC=151.xxx.xxx.xxx DST=151.xxx.xxx.xxx LEN=40 TOS=0x00 PREC=0x00 TTL=121 ID=32507 PROTO=TCP SPT=24009 DPT=139 WINDOW=16384 RES=0x00 SYN URGP=0
Jul 27 21:03:40 user alert kernel: Intrusion -> IN=ppp_8_35_1 OUT= MAC= SRC=151.xxx.xxx.xxx DST=151.xxx.xxx.xxx LEN=64 TOS=0x00 PREC=0x00 TTL=39 ID=47534 DF PROTO=TCP SPT=4256 DPT=135 WINDOW=53760 RES=0x00 SYN URGP=0
Jul 27 21:03:37 user alert kernel: Intrusion -> IN=ppp_8_35_1 OUT= MAC= SRC=151.xxx.xxx.xxx DST=151.xxx.xxx.xxx LEN=64 TOS=0x00 PREC=0x00 TTL=39 ID=47105 DF PROTO=TCP SPT=4256 DPT=135 WINDOW=53760 RES=0x00 SYN URGP=0
Jul 27 20:51:43 user alert kernel: Intrusion -> IN=ppp_8_35_1 OUT= MAC= SRC=151.xxx.xxx.xxx DST=151.xxx.xxx.xxx LEN=64 TOS=0x00 PREC=0x00 TTL=40 ID=1437 DF PROTO=TCP SPT=1549 DPT=445 WINDOW=53760 RES=0x00 SYN URGP=0
Jul 27 20:51:40 user alert kernel: Intrusion -> IN=ppp_8_35_1 OUT= MAC= SRC=151.xxx.xxx.xxx DST=151.xxx.xxx.xxx LEN=64 TOS=0x00 PREC=0x00 TTL=40 ID=1199 DF PROTO=TCP SPT=1549 DPT=445 WINDOW=53760 RES=0x00 SYN URGP=0
Jul 27 20:34:39 user alert kernel: Intrusion -> IN=ppp_8_35_1 OUT= MAC= SRC=151.xxx.xxx.xxx DST=151.xxx.xxx.xxx LEN=48 TOS=0x00 PREC=0x00 TTL=121 ID=37330 DF PROTO=TCP SPT=4493 DPT=445 WINDOW=32768 RES=0x00 SYN URGP=0
Jul 27 20:34:36 user alert kernel: Intrusion -> IN=ppp_8_35_1 OUT= MAC= SRC=151.xxx.xxx.xxx DST=151.xxx.xxx.xxx LEN=48 TOS=0x00 PREC=0x00 TTL=121 ID=37268 DF PROTO=TCP SPT=4493 DPT=445 WINDOW=32768 RES=0x00 SYN URGP=0
Jul 27 20:16:47 user alert kernel: Intrusion -> IN=ppp_8_35_1 OUT= MAC= SRC=151.xxx.xxx.xxx DST=151.xxx.xxx.xxx LEN=48 TOS=0x00 PREC=0x00 TTL=121 ID=32487 DF PROTO=TCP SPT=4898 DPT=445 WINDOW=65535 RES=0x00 SYN URGP=0
Jul 27 20:16:44 user alert kernel: Intrusion -> IN=ppp_8_35_1 OUT= MAC= SRC=151.xxx.xxx.xxx DST=151.xxx.xxx.xxx LEN=48 TOS=0x00 PREC=0x00 TTL=121 ID=32210 DF PROTO=TCP SPT=4898 DPT=445 WINDOW=65535 RES=0x00 SYN URGP=0
Jul 27 19:54:25 user alert kernel: Intrusion -> IN=ppp_8_35_1 OUT= MAC= SRC=151.xxx.xxx.xxx DST=151.xxx.xxx.xxx LEN=40 TOS=0x00 PREC=0x00 TTL=121 ID=30193 PROTO=TCP SPT=11654 DPT=139 WINDOW=16384 RES=0x00 SYN URGP=0
Jul 27 19:52:08 user alert kernel: Intrusion -> IN=ppp_8_35_1 OUT= MAC= SRC=151.xxx.xxx.xxx DST=151.xxx.xxx.xxx LEN=40 TOS=0x00 PREC=0x00 TTL=121 ID=18044 PROTO=TCP SPT=11654 DPT=139 WINDOW=16384 RES=0x00 SYN URGP=0
Jul 27 19:43:01 user alert kernel: Intrusion -> IN=ppp_8_35_1 OUT= MAC= SRC=151.xxx.xxx.xxx DST=151.xxx.xxx.xxx LEN=48 TOS=0x00 PREC=0x00 TTL=121 ID=35727 DF PROTO=TCP SPT=3748 DPT=445 WINDOW=32768 RES=0x00 SYN URGP=0
Jul 27 19:24:39 user alert kernel: Intrusion -> IN=ppp_8_35_1 OUT= MAC= SRC=151.xxx.xxx.xxx DST=151.xxx.xxx.xxx LEN=40 TOS=0x00 PREC=0x00 TTL=121 ID=6431 PROTO=TCP SPT=28958 DPT=139 WINDOW=16384 RES=0x00 SYN URGP=0
Jul 27 19:17:23 user alert kernel: Intrusion -> IN=ppp_8_35_1 OUT= MAC= SRC=151.xxx.xxx.xxx DST=151.xxx.xxx.xxx LEN=40 TOS=0x00 PREC=0x00 TTL=121 ID=24343 PROTO=TCP SPT=11654 DPT=139 WINDOW=16384 RES=0x00 SYN URGP=0
Jul 27 19:14:06 user alert kernel: Intrusion -> IN=ppp_8_35_1 OUT= MAC= SRC=151.xxx.xxx.xxx DST=151.xxx.xxx.xxx LEN=48 TOS=0x00 PREC=0x00 TTL=119 ID=16831 DF PROTO=TCP SPT=2781 DPT=135 WINDOW=64240 RES=0x00 SYN URGP=0
Jul 27 19:14:03 user alert kernel: Intrusion -> IN=ppp_8_35_1 OUT= MAC= SRC=151.xxx.xxx.xxx DST=151.xxx.xxx.xxx LEN=48 TOS=0x00 PREC=0x00 TTL=119 ID=16660 DF PROTO=TCP SPT=2781 DPT=135 WINDOW=64240 RES=0x00 SYN URGP=0
Jul 27 18:53:11 user alert kernel: Intrusion -> IN=ppp_8_35_1 OUT= MAC= SRC=151.xxx.xxx.xxx DST=151.xxx.xxx.xxx LEN=40 TOS=0x00 PREC=0x00 TTL=121 ID=27147 PROTO=TCP SPT=8403 DPT=139 WINDOW=16384 RES=0x00 SYN URGP=0
Jul 27 18:36:27 user alert kernel: Intrusion -> IN=ppp_8_35_1 OUT= MAC= SRC=151.xxx.xxx.xxx DST=151.xxx.xxx.xxx LEN=64 TOS=0x00 PREC=0x00 TTL=40 ID=3596 DF PROTO=TCP SPT=1125 DPT=445 WINDOW=53760 RES=0x00 SYN URGP=0
Jul 27 18:29:22 user alert kernel: Intrusion -> IN=ppp_8_35_1 OUT= MAC= SRC=151.xxx.xxx.xxx DST=151.xxx.xxx.xxx LEN=40 TOS=0x00 PREC=0x00 TTL=121 ID=16542 PROTO=TCP SPT=8403 DPT=139 WINDOW=16384 RES=0x00 SYN URGP=0
Jul 27 18:15:16 user alert kernel: Intrusion -> IN=ppp_8_35_1 OUT= MAC= SRC=151.xxx.xxx.xxx DST=151.xxx.xxx.xxx LEN=48 TOS=0x00 PREC=0x00 TTL=121 ID=7474 DF PROTO=TCP SPT=4366 DPT=445 WINDOW=32768 RES=0x00 SYN URGP=0
Jul 27 18:03:26 user alert kernel: Intrusion -> IN=ppp_8_35_1 OUT= MAC= SRC=151.xxx.xxx.xxx DST=151.xxx.xxx.xxx LEN=48 TOS=0x00 PREC=0x00 TTL=112 ID=32673 DF PROTO=TCP SPT=4238 DPT=4662 WINDOW=16384 RES=0x00 SYN URGP=0
Jul 27 17:55:03 user alert kernel: Intrusion -> IN=ppp_8_35_1 OUT= MAC= SRC=151.xxx.xxx.xxx DST=151.xxx.xxx.xxx LEN=40 TOS=0x00 PREC=0x00 TTL=121 ID=18571 PROTO=TCP SPT=8403 DPT=139 WINDOW=16384 RES=0x00 SYN URGP=0
Jul 27 17:49:20 user alert kernel: Intrusion -> IN=ppp_8_35_1 OUT= MAC= SRC=151.xxx.xxx.xxx DST=151.xxx.xxx.xxx LEN=40 TOS=0x00 PREC=0x00 TTL=121 ID=4696 PROTO=TCP SPT=8403 DPT=139 WINDOW=16384 RES=0x00 SYN URGP=0
Jul 27 17:33:24 user alert kernel: Intrusion -> IN=ppp_8_35_1 OUT= MAC= SRC=151.xxx.xxx.xxx DST=151.xxx.xxx.xxx LEN=40 TOS=0x00 PREC=0x00 TTL=121 ID=16786 PROTO=TCP SPT=28958 DPT=139 WINDOW=16384 RES=0x00 SYN URGP=0
Jul 27 17:29:53 user alert kernel: Intrusion -> IN=ppp_8_35_1 OUT= MAC= SRC=151.xxx.xxx.xxx DST=151.xxx.xxx.xxx LEN=64 TOS=0x00 PREC=0x00 TTL=40 ID=59296 DF PROTO=TCP SPT=2508 DPT=445 WINDOW=53760 RES=0x00 SYN URGP=0
Jul 27 17:19:31 user alert kernel: Intrusion -> IN=ppp_8_35_1 OUT= MAC= SRC=151.xxx.xxx.xxx DST=151.xxx.xxx.xxx LEN=64 TOS=0x00 PREC=0x00 TTL=41 ID=608 DF PROTO=TCP SPT=1067 DPT=445 WINDOW=53760 RES=0x00 SYN URGP=0
Jul 27 17:08:00 user alert kernel: Intrusion -> IN=ppp_8_35_1 OUT= MAC= SRC=151.xxx.xxx.xxx DST=151.xxx.xxx.xxx LEN=48 TOS=0x00 PREC=0x00 TTL=119 ID=31702 DF PROTO=TCP SPT=4664 DPT=445 WINDOW=64240 RES=0x00 SYN URGP=0
Jul 27 16:58:28 user alert kernel: Intrusion -> IN=ppp_8_35_1 OUT= MAC= SRC=151.xxx.xxx.xxx DST=151.xxx.xxx.xxx LEN=40 TOS=0x00 PREC=0x00 TTL=121 ID=17322 PROTO=TCP SPT=20465 DPT=139 WINDOW=16384 RES=0x00 SYN URGP=0
Jul 27 16:45:51 user alert kernel: Intrusion -> IN=ppp_8_35_1 OUT= MAC= SRC=151.xxx.xxx.xxx DST=151.xxx.xxx.xxx LEN=40 TOS=0x00 PREC=0x00 TTL=121 ID=28826 PROTO=TCP SPT=2643 DPT=139 WINDOW=16384 RES=0x00 SYN URGP=0
Jul 27 16:40:09 user alert kernel: Intrusion -> IN=ppp_8_35_1 OUT= MAC= SRC=151.xxx.xxx.xxx DST=151.xxx.xxx.xxx LEN=40 TOS=0x00 PREC=0x00 TTL=125 ID=11627 PROTO=TCP SPT=15910 DPT=139 WINDOW=16384 RES=0x00 SYN URGP=0
Jul 27 16:28:50 user alert kernel: Intrusion -> IN=ppp_8_35_1 OUT= MAC= SRC=151.xxx.xxx.xxx DST=151.xxx.xxx.xxx LEN=48 TOS=0x00 PREC=0x00 TTL=120 ID=12048 DF PROTO=TCP SPT=3117 DPT=445 WINDOW=16384 RES=0x00 SYN URGP=0
Jul 27 16:13:59 user alert kernel: Intrusion -> IN=ppp_8_35_1 OUT= MAC= SRC=151.xxx.xxx.xxx DST=151.xxx.xxx.xxx LEN=40 TOS=0x00 PREC=0x00 TTL=121 ID=11217 PROTO=TCP SPT=28958 DPT=139 WINDOW=16384 RES=0x00 SYN URGP=0
Jul 27 16:04:10 user alert kernel: Intrusion -> IN=ppp_8_35_1 OUT= MAC= SRC=151.xxx.xxx.xxx DST=151.xxx.xxx.xxx LEN=40 TOS=0x00 PREC=0x00 TTL=121 ID=21421 PROTO=TCP SPT=8403 DPT=139 WINDOW=16384 RES=0x00 SYN URGP=0
Jul 27 16:02:16 user alert kernel: Intrusion -> IN=ppp_8_35_1 OUT= MAC= SRC=151.xxx.xxx.xxx DST=151.xxx.xxx.xxx LEN=48 TOS=0x00 PREC=0x00 TTL=121 ID=274 DF PROTO=TCP SPT=3321 DPT=139 WINDOW=16384 RES=0x00 SYN URGP=0
Jul 27 16:02:12 user alert kernel: Intrusion -> IN=ppp_8_35_1 OUT= MAC= SRC=151.xxx.xxx.xxx DST=151.xxx.xxx.xxx LEN=48 TOS=0x00 PREC=0x00 TTL=121 ID=65421 DF PROTO=TCP SPT=3215 DPT=445 WINDOW=16384 RES=0x00 SYN URGP=0
Jul 27 16:02:09 user alert kernel: Intrusion -> IN=ppp_8_35_1 OUT= MAC= SRC=151.xxx.xxx.xxx DST=151.xxx.xxx.xxx LEN=48 TOS=0x00 PREC=0x00 TTL=121 ID=65131 DF PROTO=TCP SPT=3215 DPT=445 WINDOW=16384 RES=0x00 SYN URGP=0
Jul 27 15:53:16 user alert kernel: Intrusion -> IN=ppp_8_35_1 OUT= MAC= SRC=151.xxx.xxx.xxx DST=151.xxx.xxx.xxx LEN=48 TOS=0x00 PREC=0x00 TTL=121 ID=52557 DF PROTO=TCP SPT=1259 DPT=135 WINDOW=65535 RES=0x00 SYN URGP=0
il log del mio router ogni giorno registra decine e decine di "Kernel Intrusion", dai più svariati IP (la maggior parte comuqnue della stessa classe) e nelle più svariate porte, a tutte le ore del giorno (anche quando non c'è nessun PC connesso).
Quasi tutti gli ip sorgenti sono Italiani, molto spesso anche se con ip diversi dalla stessa zona.
Ok, si tratta dei soliti che si divertono a fare port-scanning ma anche voi registrate la stessa quantità di log del genere?
O ci possono essere altre possibili cause?
Sì insomma, è nella norma o il mio è un caso patologico?
Per farvi un esempio questo è il mio report di oggi (ovviamente ho nascosto gli ip) dalle 16:00 alle 23:00...booh....
Jul 27 23:00:07 user alert kernel: Intrusion -> IN=ppp_8_35_1 OUT= MAC= SRC=84.xxx.xxx.xxx DST=151.xxx.xxx.xxx LEN=48 TOS=0x00 PREC=0x00 TTL=114 ID=1795 DF PROTO=TCP SPT=1457 DPT=4662 WINDOW=65535 RES=0x00 SYN URGP=0
Jul 27 22:48:23 user alert kernel: Intrusion -> IN=ppp_8_35_1 OUT= MAC= SRC=151.xxx.xxx.xxx DST=151.xxx.xxx.xxx LEN=48 TOS=0x00 PREC=0x00 TTL=121 ID=7647 DF PROTO=TCP SPT=4948 DPT=5800 WINDOW=16384 RES=0x00 SYN URGP=0
Jul 27 22:44:11 user alert kernel: Intrusion -> IN=ppp_8_35_1 OUT= MAC= SRC=151.xxx.xxx.xxx DST=151.xxx.xxx.xxx LEN=48 TOS=0x00 PREC=0x00 TTL=121 ID=28330 DF PROTO=TCP SPT=4609 DPT=5800 WINDOW=16384 RES=0x00 SYN URGP=0
Jul 27 22:28:24 user alert kernel: Intrusion -> IN=ppp_8_35_1 OUT= MAC= SRC=151.xxx.xxx.xxx DST=151.xxx.xxx.xxx LEN=48 TOS=0x00 PREC=0x00 TTL=121 ID=30229 DF PROTO=TCP SPT=4525 DPT=445 WINDOW=32768 RES=0x00 SYN URGP=0
Jul 27 22:18:57 user alert kernel: Intrusion -> IN=ppp_8_35_1 OUT= MAC= SRC=151.xxx.xxx.xxx DST=151.xxx.xxx.xxx LEN=40 TOS=0x00 PREC=0x00 TTL=121 ID=24588 PROTO=TCP SPT=22608 DPT=139 WINDOW=16384 RES=0x00 SYN URGP=0
Jul 27 22:18:13 user alert kernel: Intrusion -> IN=ppp_8_35_1 OUT= MAC= SRC=151.xxx.xxx.xxx DST=151.xxx.xxx.xxx LEN=48 TOS=0x00 PREC=0x00 TTL=121 ID=65531 DF PROTO=TCP SPT=4100 DPT=135 WINDOW=16384 RES=0x00 SYN URGP=0
Jul 27 22:18:10 user alert kernel: Intrusion -> IN=ppp_8_35_1 OUT= MAC= SRC=151.xxx.xxx.xxx DST=151.xxx.xxx.xxx LEN=48 TOS=0x00 PREC=0x00 TTL=121 ID=65308 DF PROTO=TCP SPT=4100 DPT=135 WINDOW=16384 RES=0x00 SYN URGP=0
Jul 27 22:17:50 user alert kernel: Intrusion -> IN=ppp_8_35_1 OUT= MAC= SRC=151.xxx.xxx.xxx DST=151.xxx.xxx.xxx LEN=48 TOS=0x00 PREC=0x00 TTL=121 ID=63808 DF PROTO=TCP SPT=3766 DPT=139 WINDOW=16384 RES=0x00 SYN URGP=0
Jul 27 22:17:47 user alert kernel: Intrusion -> IN=ppp_8_35_1 OUT= MAC= SRC=151.xxx.xxx.xxx DST=151.xxx.xxx.xxx LEN=48 TOS=0x00 PREC=0x00 TTL=121 ID=63565 DF PROTO=TCP SPT=3766 DPT=139 WINDOW=16384 RES=0x00 SYN URGP=0
Jul 27 22:17:10 user alert kernel: Intrusion -> IN=ppp_8_35_1 OUT= MAC= SRC=151.xxx.xxx.xxx DST=151.xxx.xxx.xxx LEN=48 TOS=0x00 PREC=0x00 TTL=121 ID=60776 DF PROTO=TCP SPT=3194 DPT=139 WINDOW=16384 RES=0x00 SYN URGP=0
Jul 27 22:17:08 user alert kernel: Intrusion -> IN=ppp_8_35_1 OUT= MAC= SRC=151.xxx.xxx.xxx DST=151.xxx.xxx.xxx LEN=48 TOS=0x00 PREC=0x00 TTL=121 ID=60550 DF PROTO=TCP SPT=3194 DPT=139 WINDOW=16384 RES=0x00 SYN URGP=0
Jul 27 22:17:02 user alert kernel: Intrusion -> IN=ppp_8_35_1 OUT= MAC= SRC=151.xxx.xxx.xxx DST=151.xxx.xxx.xxx LEN=48 TOS=0x00 PREC=0x00 TTL=121 ID=60106 DF PROTO=TCP SPT=3070 DPT=445 WINDOW=16384 RES=0x00 SYN URGP=0
Jul 27 22:16:59 user alert kernel: Intrusion -> IN=ppp_8_35_1 OUT= MAC= SRC=151.xxx.xxx.xxx DST=151.xxx.xxx.xxx LEN=48 TOS=0x00 PREC=0x00 TTL=121 ID=59863 DF PROTO=TCP SPT=3070 DPT=445 WINDOW=16384 RES=0x00 SYN URGP=0
Jul 27 22:15:07 user alert kernel: Intrusion -> IN=ppp_8_35_1 OUT= MAC= SRC=151.xxx.xxx.xxx DST=151.xxx.xxx.xxx LEN=40 TOS=0x00 PREC=0x00 TTL=121 ID=27659 PROTO=TCP SPT=24009 DPT=139 WINDOW=16384 RES=0x00 SYN URGP=0
Jul 27 22:04:13 user alert kernel: Intrusion -> IN=ppp_8_35_1 OUT= MAC= SRC=151.xxx.xxx.xxx DST=151.xxx.xxx.xxx LEN=40 TOS=0x00 PREC=0x00 TTL=121 ID=3708 PROTO=TCP SPT=22608 DPT=139 WINDOW=16384 RES=0x00 SYN URGP=0
Jul 27 21:56:08 user alert kernel: Intrusion -> IN=ppp_8_35_1 OUT= MAC= SRC=151.xxx.xxx.xxx DST=151.xxx.xxx.xxx LEN=48 TOS=0x00 PREC=0x00 TTL=121 ID=21229 DF PROTO=TCP SPT=3812 DPT=139 WINDOW=16384 RES=0x00 SYN URGP=0
Jul 27 21:46:51 user alert kernel: Intrusion -> IN=ppp_8_35_1 OUT= MAC= SRC=121.xxx.xxx.xxx DST=151.xxx.xxx.xxx LEN=48 TOS=0x00 PREC=0x00 TTL=100 ID=42509 DF PROTO=TCP SPT=2487 DPT=4662 WINDOW=65535 RES=0x00 SYN URGP=0
Jul 27 21:35:58 user alert kernel: Intrusion -> IN=ppp_8_35_1 OUT= MAC= SRC=81.xxx.xxx.xxx DST=151.xxx.xxx.xxx LEN=48 TOS=0x00 PREC=0x00 TTL=115 ID=43153 DF PROTO=TCP SPT=3681 DPT=4662 WINDOW=65535 RES=0x00 SYN URGP=0
Jul 27 21:35:52 user alert kernel: Intrusion -> IN=ppp_8_35_1 OUT= MAC= SRC=81.xxx.xxx.xxx DST=151.xxx.xxx.xxx LEN=48 TOS=0x00 PREC=0x00 TTL=115 ID=42593 DF PROTO=TCP SPT=3681 DPT=4662 WINDOW=65535 RES=0x00 SYN URGP=0
Jul 27 21:35:49 user alert kernel: Intrusion -> IN=ppp_8_35_1 OUT= MAC= SRC=81.xxx.xxx.xxx DST=151.xxx.xxx.xxx LEN=48 TOS=0x00 PREC=0x00 TTL=115 ID=42301 DF PROTO=TCP SPT=3681 DPT=4662 WINDOW=65535 RES=0x00 SYN URGP=0
Jul 27 21:34:00 user alert kernel: Intrusion -> IN=ppp_8_35_1 OUT= MAC= SRC=81.xxx.xxx.xxx DST=151.xxx.xxx.xxx LEN=48 TOS=0x00 PREC=0x00 TTL=119 ID=23508 DF PROTO=TCP SPT=2395 DPT=4662 WINDOW=16384 RES=0x00 SYN URGP=0
Jul 27 21:33:57 user alert kernel: Intrusion -> IN=ppp_8_35_1 OUT= MAC= SRC=81.xxx.xxx.xxx DST=151.xxx.xxx.xxx LEN=48 TOS=0x00 PREC=0x00 TTL=119 ID=23421 DF PROTO=TCP SPT=2395 DPT=4662 WINDOW=16384 RES=0x00 SYN URGP=0
Jul 27 21:29:46 user alert kernel: Intrusion -> IN=ppp_8_35_1 OUT= MAC= SRC=200.xxx.xxx.xxx DST=151.xxx.xxx.xxx LEN=48 TOS=0x00 PREC=0x00 TTL=116 ID=50857 DF PROTO=TCP SPT=2988 DPT=4662 WINDOW=65535 RES=0x00 SYN URGP=0
Jul 27 21:29:43 user alert kernel: Intrusion -> IN=ppp_8_35_1 OUT= MAC= SRC=200.xxx.xxx.xxx DST=151.xxx.xxx.xxx LEN=48 TOS=0x00 PREC=0x00 TTL=116 ID=50780 DF PROTO=TCP SPT=2988 DPT=4662 WINDOW=65535 RES=0x00 SYN URGP=0
Jul 27 21:29:19 user alert kernel: Intrusion -> IN=ppp_8_35_1 OUT= MAC= SRC=151.xxx.xxx.xxx DST=151.xxx.xxx.xxx LEN=64 TOS=0x00 PREC=0x00 TTL=39 ID=45788 DF PROTO=TCP SPT=4269 DPT=135 WINDOW=53760 RES=0x00 SYN URGP=0
Jul 27 21:29:17 user alert kernel: Intrusion -> IN=ppp_8_35_1 OUT= MAC= SRC=151.xxx.xxx.xxx DST=151.xxx.xxx.xxx LEN=64 TOS=0x00 PREC=0x00 TTL=39 ID=45382 DF PROTO=TCP SPT=4269 DPT=135 WINDOW=53760 RES=0x00 SYN URGP=0
Jul 27 21:29:12 user alert kernel: Intrusion -> IN=ppp_8_35_1 OUT= MAC= SRC=151.xxx.xxx.xxx DST=151.xxx.xxx.xxx LEN=40 TOS=0x00 PREC=0x00 TTL=121 ID=30448 PROTO=TCP SPT=24009 DPT=139 WINDOW=16384 RES=0x00 SYN URGP=0
Jul 27 21:24:21 user alert kernel: Intrusion -> IN=ppp_8_35_1 OUT= MAC= SRC=90.xxx.xxx.xxx DST=151.xxx.xxx.xxx LEN=48 TOS=0x00 PREC=0x00 TTL=116 ID=32477 DF PROTO=TCP SPT=3703 DPT=4662 WINDOW=16384 RES=0x00 SYN URGP=0
Jul 27 21:24:20 user alert kernel: Intrusion -> IN=ppp_8_35_1 OUT= MAC= SRC=84.xxx.xxx.xxx DST=151.xxx.xxx.xxx LEN=48 TOS=0x00 PREC=0x00 TTL=114 ID=4805 DF PROTO=TCP SPT=2972 DPT=4662 WINDOW=65535 RES=0x00 SYN URGP=0
Jul 27 21:24:18 user alert kernel: Intrusion -> IN=ppp_8_35_1 OUT= MAC= SRC=84.xxx.xxx.xxx DST=151.xxx.xxx.xxx LEN=48 TOS=0x00 PREC=0x00 TTL=114 ID=4397 DF PROTO=TCP SPT=2972 DPT=4662 WINDOW=65535 RES=0x00 SYN URGP=0
Jul 27 21:24:15 user alert kernel: Intrusion -> IN=ppp_8_35_1 OUT= MAC= SRC=90.xxx.xxx.xxx DST=151.xxx.xxx.xxx LEN=48 TOS=0x00 PREC=0x00 TTL=116 ID=32327 DF PROTO=TCP SPT=3703 DPT=4662 WINDOW=16384 RES=0x00 SYN URGP=0
Jul 27 21:24:12 user alert kernel: Intrusion -> IN=ppp_8_35_1 OUT= MAC= SRC=90.xxx.xxx.xxx DST=151.xxx.xxx.xxx LEN=48 TOS=0x00 PREC=0x00 TTL=116 ID=32220 DF PROTO=TCP SPT=3703 DPT=4662 WINDOW=16384 RES=0x00 SYN URGP=0
Jul 27 21:14:38 user alert kernel: Intrusion -> IN=ppp_8_35_1 OUT= MAC= SRC=87.xxx.xxx.xxx DST=151.xxx.xxx.xxx LEN=48 TOS=0x00 PREC=0x00 TTL=117 ID=50312 DF PROTO=TCP SPT=3327 DPT=4662 WINDOW=65535 RES=0x00 SYN URGP=0
Jul 27 21:12:10 user alert kernel: Intrusion -> IN=ppp_8_35_1 OUT= MAC= SRC=81.xxx.xxx.xxx DST=151.xxx.xxx.xxx LEN=48 TOS=0x00 PREC=0x00 TTL=115 ID=60073 DF PROTO=TCP SPT=18231 DPT=4662 WINDOW=65535 RES=0x00 SYN URGP=0
Jul 27 21:07:52 user alert kernel: Intrusion -> IN=ppp_8_35_1 OUT= MAC= SRC=151.xxx.xxx.xxx DST=151.xxx.xxx.xxx LEN=40 TOS=0x00 PREC=0x00 TTL=121 ID=32507 PROTO=TCP SPT=24009 DPT=139 WINDOW=16384 RES=0x00 SYN URGP=0
Jul 27 21:03:40 user alert kernel: Intrusion -> IN=ppp_8_35_1 OUT= MAC= SRC=151.xxx.xxx.xxx DST=151.xxx.xxx.xxx LEN=64 TOS=0x00 PREC=0x00 TTL=39 ID=47534 DF PROTO=TCP SPT=4256 DPT=135 WINDOW=53760 RES=0x00 SYN URGP=0
Jul 27 21:03:37 user alert kernel: Intrusion -> IN=ppp_8_35_1 OUT= MAC= SRC=151.xxx.xxx.xxx DST=151.xxx.xxx.xxx LEN=64 TOS=0x00 PREC=0x00 TTL=39 ID=47105 DF PROTO=TCP SPT=4256 DPT=135 WINDOW=53760 RES=0x00 SYN URGP=0
Jul 27 20:51:43 user alert kernel: Intrusion -> IN=ppp_8_35_1 OUT= MAC= SRC=151.xxx.xxx.xxx DST=151.xxx.xxx.xxx LEN=64 TOS=0x00 PREC=0x00 TTL=40 ID=1437 DF PROTO=TCP SPT=1549 DPT=445 WINDOW=53760 RES=0x00 SYN URGP=0
Jul 27 20:51:40 user alert kernel: Intrusion -> IN=ppp_8_35_1 OUT= MAC= SRC=151.xxx.xxx.xxx DST=151.xxx.xxx.xxx LEN=64 TOS=0x00 PREC=0x00 TTL=40 ID=1199 DF PROTO=TCP SPT=1549 DPT=445 WINDOW=53760 RES=0x00 SYN URGP=0
Jul 27 20:34:39 user alert kernel: Intrusion -> IN=ppp_8_35_1 OUT= MAC= SRC=151.xxx.xxx.xxx DST=151.xxx.xxx.xxx LEN=48 TOS=0x00 PREC=0x00 TTL=121 ID=37330 DF PROTO=TCP SPT=4493 DPT=445 WINDOW=32768 RES=0x00 SYN URGP=0
Jul 27 20:34:36 user alert kernel: Intrusion -> IN=ppp_8_35_1 OUT= MAC= SRC=151.xxx.xxx.xxx DST=151.xxx.xxx.xxx LEN=48 TOS=0x00 PREC=0x00 TTL=121 ID=37268 DF PROTO=TCP SPT=4493 DPT=445 WINDOW=32768 RES=0x00 SYN URGP=0
Jul 27 20:16:47 user alert kernel: Intrusion -> IN=ppp_8_35_1 OUT= MAC= SRC=151.xxx.xxx.xxx DST=151.xxx.xxx.xxx LEN=48 TOS=0x00 PREC=0x00 TTL=121 ID=32487 DF PROTO=TCP SPT=4898 DPT=445 WINDOW=65535 RES=0x00 SYN URGP=0
Jul 27 20:16:44 user alert kernel: Intrusion -> IN=ppp_8_35_1 OUT= MAC= SRC=151.xxx.xxx.xxx DST=151.xxx.xxx.xxx LEN=48 TOS=0x00 PREC=0x00 TTL=121 ID=32210 DF PROTO=TCP SPT=4898 DPT=445 WINDOW=65535 RES=0x00 SYN URGP=0
Jul 27 19:54:25 user alert kernel: Intrusion -> IN=ppp_8_35_1 OUT= MAC= SRC=151.xxx.xxx.xxx DST=151.xxx.xxx.xxx LEN=40 TOS=0x00 PREC=0x00 TTL=121 ID=30193 PROTO=TCP SPT=11654 DPT=139 WINDOW=16384 RES=0x00 SYN URGP=0
Jul 27 19:52:08 user alert kernel: Intrusion -> IN=ppp_8_35_1 OUT= MAC= SRC=151.xxx.xxx.xxx DST=151.xxx.xxx.xxx LEN=40 TOS=0x00 PREC=0x00 TTL=121 ID=18044 PROTO=TCP SPT=11654 DPT=139 WINDOW=16384 RES=0x00 SYN URGP=0
Jul 27 19:43:01 user alert kernel: Intrusion -> IN=ppp_8_35_1 OUT= MAC= SRC=151.xxx.xxx.xxx DST=151.xxx.xxx.xxx LEN=48 TOS=0x00 PREC=0x00 TTL=121 ID=35727 DF PROTO=TCP SPT=3748 DPT=445 WINDOW=32768 RES=0x00 SYN URGP=0
Jul 27 19:24:39 user alert kernel: Intrusion -> IN=ppp_8_35_1 OUT= MAC= SRC=151.xxx.xxx.xxx DST=151.xxx.xxx.xxx LEN=40 TOS=0x00 PREC=0x00 TTL=121 ID=6431 PROTO=TCP SPT=28958 DPT=139 WINDOW=16384 RES=0x00 SYN URGP=0
Jul 27 19:17:23 user alert kernel: Intrusion -> IN=ppp_8_35_1 OUT= MAC= SRC=151.xxx.xxx.xxx DST=151.xxx.xxx.xxx LEN=40 TOS=0x00 PREC=0x00 TTL=121 ID=24343 PROTO=TCP SPT=11654 DPT=139 WINDOW=16384 RES=0x00 SYN URGP=0
Jul 27 19:14:06 user alert kernel: Intrusion -> IN=ppp_8_35_1 OUT= MAC= SRC=151.xxx.xxx.xxx DST=151.xxx.xxx.xxx LEN=48 TOS=0x00 PREC=0x00 TTL=119 ID=16831 DF PROTO=TCP SPT=2781 DPT=135 WINDOW=64240 RES=0x00 SYN URGP=0
Jul 27 19:14:03 user alert kernel: Intrusion -> IN=ppp_8_35_1 OUT= MAC= SRC=151.xxx.xxx.xxx DST=151.xxx.xxx.xxx LEN=48 TOS=0x00 PREC=0x00 TTL=119 ID=16660 DF PROTO=TCP SPT=2781 DPT=135 WINDOW=64240 RES=0x00 SYN URGP=0
Jul 27 18:53:11 user alert kernel: Intrusion -> IN=ppp_8_35_1 OUT= MAC= SRC=151.xxx.xxx.xxx DST=151.xxx.xxx.xxx LEN=40 TOS=0x00 PREC=0x00 TTL=121 ID=27147 PROTO=TCP SPT=8403 DPT=139 WINDOW=16384 RES=0x00 SYN URGP=0
Jul 27 18:36:27 user alert kernel: Intrusion -> IN=ppp_8_35_1 OUT= MAC= SRC=151.xxx.xxx.xxx DST=151.xxx.xxx.xxx LEN=64 TOS=0x00 PREC=0x00 TTL=40 ID=3596 DF PROTO=TCP SPT=1125 DPT=445 WINDOW=53760 RES=0x00 SYN URGP=0
Jul 27 18:29:22 user alert kernel: Intrusion -> IN=ppp_8_35_1 OUT= MAC= SRC=151.xxx.xxx.xxx DST=151.xxx.xxx.xxx LEN=40 TOS=0x00 PREC=0x00 TTL=121 ID=16542 PROTO=TCP SPT=8403 DPT=139 WINDOW=16384 RES=0x00 SYN URGP=0
Jul 27 18:15:16 user alert kernel: Intrusion -> IN=ppp_8_35_1 OUT= MAC= SRC=151.xxx.xxx.xxx DST=151.xxx.xxx.xxx LEN=48 TOS=0x00 PREC=0x00 TTL=121 ID=7474 DF PROTO=TCP SPT=4366 DPT=445 WINDOW=32768 RES=0x00 SYN URGP=0
Jul 27 18:03:26 user alert kernel: Intrusion -> IN=ppp_8_35_1 OUT= MAC= SRC=151.xxx.xxx.xxx DST=151.xxx.xxx.xxx LEN=48 TOS=0x00 PREC=0x00 TTL=112 ID=32673 DF PROTO=TCP SPT=4238 DPT=4662 WINDOW=16384 RES=0x00 SYN URGP=0
Jul 27 17:55:03 user alert kernel: Intrusion -> IN=ppp_8_35_1 OUT= MAC= SRC=151.xxx.xxx.xxx DST=151.xxx.xxx.xxx LEN=40 TOS=0x00 PREC=0x00 TTL=121 ID=18571 PROTO=TCP SPT=8403 DPT=139 WINDOW=16384 RES=0x00 SYN URGP=0
Jul 27 17:49:20 user alert kernel: Intrusion -> IN=ppp_8_35_1 OUT= MAC= SRC=151.xxx.xxx.xxx DST=151.xxx.xxx.xxx LEN=40 TOS=0x00 PREC=0x00 TTL=121 ID=4696 PROTO=TCP SPT=8403 DPT=139 WINDOW=16384 RES=0x00 SYN URGP=0
Jul 27 17:33:24 user alert kernel: Intrusion -> IN=ppp_8_35_1 OUT= MAC= SRC=151.xxx.xxx.xxx DST=151.xxx.xxx.xxx LEN=40 TOS=0x00 PREC=0x00 TTL=121 ID=16786 PROTO=TCP SPT=28958 DPT=139 WINDOW=16384 RES=0x00 SYN URGP=0
Jul 27 17:29:53 user alert kernel: Intrusion -> IN=ppp_8_35_1 OUT= MAC= SRC=151.xxx.xxx.xxx DST=151.xxx.xxx.xxx LEN=64 TOS=0x00 PREC=0x00 TTL=40 ID=59296 DF PROTO=TCP SPT=2508 DPT=445 WINDOW=53760 RES=0x00 SYN URGP=0
Jul 27 17:19:31 user alert kernel: Intrusion -> IN=ppp_8_35_1 OUT= MAC= SRC=151.xxx.xxx.xxx DST=151.xxx.xxx.xxx LEN=64 TOS=0x00 PREC=0x00 TTL=41 ID=608 DF PROTO=TCP SPT=1067 DPT=445 WINDOW=53760 RES=0x00 SYN URGP=0
Jul 27 17:08:00 user alert kernel: Intrusion -> IN=ppp_8_35_1 OUT= MAC= SRC=151.xxx.xxx.xxx DST=151.xxx.xxx.xxx LEN=48 TOS=0x00 PREC=0x00 TTL=119 ID=31702 DF PROTO=TCP SPT=4664 DPT=445 WINDOW=64240 RES=0x00 SYN URGP=0
Jul 27 16:58:28 user alert kernel: Intrusion -> IN=ppp_8_35_1 OUT= MAC= SRC=151.xxx.xxx.xxx DST=151.xxx.xxx.xxx LEN=40 TOS=0x00 PREC=0x00 TTL=121 ID=17322 PROTO=TCP SPT=20465 DPT=139 WINDOW=16384 RES=0x00 SYN URGP=0
Jul 27 16:45:51 user alert kernel: Intrusion -> IN=ppp_8_35_1 OUT= MAC= SRC=151.xxx.xxx.xxx DST=151.xxx.xxx.xxx LEN=40 TOS=0x00 PREC=0x00 TTL=121 ID=28826 PROTO=TCP SPT=2643 DPT=139 WINDOW=16384 RES=0x00 SYN URGP=0
Jul 27 16:40:09 user alert kernel: Intrusion -> IN=ppp_8_35_1 OUT= MAC= SRC=151.xxx.xxx.xxx DST=151.xxx.xxx.xxx LEN=40 TOS=0x00 PREC=0x00 TTL=125 ID=11627 PROTO=TCP SPT=15910 DPT=139 WINDOW=16384 RES=0x00 SYN URGP=0
Jul 27 16:28:50 user alert kernel: Intrusion -> IN=ppp_8_35_1 OUT= MAC= SRC=151.xxx.xxx.xxx DST=151.xxx.xxx.xxx LEN=48 TOS=0x00 PREC=0x00 TTL=120 ID=12048 DF PROTO=TCP SPT=3117 DPT=445 WINDOW=16384 RES=0x00 SYN URGP=0
Jul 27 16:13:59 user alert kernel: Intrusion -> IN=ppp_8_35_1 OUT= MAC= SRC=151.xxx.xxx.xxx DST=151.xxx.xxx.xxx LEN=40 TOS=0x00 PREC=0x00 TTL=121 ID=11217 PROTO=TCP SPT=28958 DPT=139 WINDOW=16384 RES=0x00 SYN URGP=0
Jul 27 16:04:10 user alert kernel: Intrusion -> IN=ppp_8_35_1 OUT= MAC= SRC=151.xxx.xxx.xxx DST=151.xxx.xxx.xxx LEN=40 TOS=0x00 PREC=0x00 TTL=121 ID=21421 PROTO=TCP SPT=8403 DPT=139 WINDOW=16384 RES=0x00 SYN URGP=0
Jul 27 16:02:16 user alert kernel: Intrusion -> IN=ppp_8_35_1 OUT= MAC= SRC=151.xxx.xxx.xxx DST=151.xxx.xxx.xxx LEN=48 TOS=0x00 PREC=0x00 TTL=121 ID=274 DF PROTO=TCP SPT=3321 DPT=139 WINDOW=16384 RES=0x00 SYN URGP=0
Jul 27 16:02:12 user alert kernel: Intrusion -> IN=ppp_8_35_1 OUT= MAC= SRC=151.xxx.xxx.xxx DST=151.xxx.xxx.xxx LEN=48 TOS=0x00 PREC=0x00 TTL=121 ID=65421 DF PROTO=TCP SPT=3215 DPT=445 WINDOW=16384 RES=0x00 SYN URGP=0
Jul 27 16:02:09 user alert kernel: Intrusion -> IN=ppp_8_35_1 OUT= MAC= SRC=151.xxx.xxx.xxx DST=151.xxx.xxx.xxx LEN=48 TOS=0x00 PREC=0x00 TTL=121 ID=65131 DF PROTO=TCP SPT=3215 DPT=445 WINDOW=16384 RES=0x00 SYN URGP=0
Jul 27 15:53:16 user alert kernel: Intrusion -> IN=ppp_8_35_1 OUT= MAC= SRC=151.xxx.xxx.xxx DST=151.xxx.xxx.xxx LEN=48 TOS=0x00 PREC=0x00 TTL=121 ID=52557 DF PROTO=TCP SPT=1259 DPT=135 WINDOW=65535 RES=0x00 SYN URGP=0