
Код: Выделить всё
21:55:29.049736 PPPoE PADI [Service-Name] [Host-Uniq "2041"] [AC-Cookie 0x3A0953F19BDDCCAF2934DB015E22DD50] и много-много хекс-кодов...
А вот потом начинается подобное:
Код: Выделить всё
21:56:05.885893 PPPoE [ses 0x1c63] IP 65.Red-83-54-241.dynamicIP.rima-tde.net.4662 > unknown.telecom.gomel.by.28088: . 532500270:532501722(1452) ack 122171415 win 65535
Код: Выделить всё
<9> kernel: Intrusion -> IN=ppp_0_33_1 OUT= MAC= SRC=86.57.145.165
DST=86.57.138.203 LEN=48 TOS=0x00 PREC=0x00 TTL=121 ID=18219 DF
PROTO=TCP SPT=1195 DPT=445 WINDOW=8760 RES=0x00 SYN URGP=0
Код: Выделить всё
# Generated by iptables-save v1.2.11 on Thu Nov 9 22:28:21 2006
*filter
:INPUT DROP [30:1896]
:FORWARD ACCEPT [0:0]
:OUTPUT ACCEPT [1199:163907]
-A INPUT -m state --state RELATED,ESTABLISHED -j ACCEPT
-A INPUT -i lo -j ACCEPT
Код: Выделить всё
> iptables -L
Chain INPUT (policy ACCEPT) # а если сделать policy DROP?
target prot opt source destination
ACCEPT 2 -- anywhere anywhere
FWINPUTChain all -- anywhere anywhere
RAChain all -- anywhere anywhere
ReaimINPUTChain all -- anywhere anywhere
ACCEPT all -- anywhere anywhere state RELATED,ESTABLISHED
LOG tcp -- anywhere anywhere tcp flags:SYN,RST,ACK/SYN limit: avg 6/hour burst 5 LOG level alert prefix `Intrusion -> '
DROP all -- anywhere anywhere
DROP all -- anywhere 86.57.138.18
DROP all -- anywhere 192.168.1.1
Chain FORWARD (policy ACCEPT)
target prot opt source destination
DROP all -- anywhere 224.0.0.22 # RTFM :?:
ACCEPT all -- anywhere 224.0.0.22
ACCEPT all -- anywhere 224.0.0.2
ACCEPT all -- anywhere 224.0.0.1
TCPMSS tcp -- anywhere anywhere tcp flags:SYN,RST/SYN TCPMSS clamp to PMTU
TCPMSS tcp -- anywhere anywhere tcp flags:SYN,RST/SYN TCPMSS clamp to PMTU
VSChain all -- anywhere anywhere
FWChain all -- anywhere anywhere
DmzChain all -- anywhere anywhere
ACCEPT all -- anywhere anywhere state RELATED,ESTABLISHED
LOG tcp -- anywhere anywhere tcp flags:SYN,RST,ACK/SYN limit: avg 6/hour burst 5 LOG level alert prefix `Intrusion -> '
DROP all -- anywhere anywhere
Chain OUTPUT (policy ACCEPT)
target prot opt source destination
Chain DmzChain (1 references)
target prot opt source destination
Chain FWChain (1 references)
target prot opt source destination
Chain FWINPUTChain (1 references)
target prot opt source destination
Chain RAChain (1 references)
target prot opt source destination
Chain ReaimINPUTChain (1 references)
target prot opt source destination
Chain VSChain (1 references)
target prot opt source destination