[Dshield] Log ID and Template question...
TGeairn at unxpres.com
Mon Jul 23 16:30:46 GMT 2001
In addition to IRC, the MS Exchange Chat client uses 6667 on the client end.
Possibly Chat clients trying to connect to your ip 188.8.131.52.
A quick review of the ip's you listed shows that two of them are running irc
servers and one is acting like an irc client (or an mschat client, can't
Since most of these addresses have junk SOA records (for instance,
184.108.40.206 is in a block of addresses used by mdsog.net...
RP=root at register.com, good luck getting to them), if the traffic is becoming
a problem, you can *try* to get your ISP to block 6667 traffic on their end.
My ISP (Intermedia) has been very cooperative in setting filters on their
end of my poor frame-relay pipes.
From: Dan Stetser [mailto:dan at pacinternet.com]
Sent: Sunday, July 22, 2001 5:04 PM
To: dshield at dshield.org
Subject: [Dshield] Log ID and Template question...
Does anyone recognize what these ip's are trying to do w/ my server?
Jul 22 09:04:44 pohakea kernel: Packet log: input REJECT eth0 PROTO=6
220.127.116.11:6667 18.104.22.168:62539 L=40 S=0x00 I=19378 F=0x4000 T=54
Jul 22 09:27:35 pohakea kernel: Packet log: input REJECT eth0 PROTO=6
22.214.171.124:6667 126.96.36.199:62711 L=40 S=0x00 I=19059 F=0x4000 T=37
Jul 22 09:12:33 pohakea kernel: Packet log: input REJECT eth0 PROTO=6
188.8.131.52:6667 184.108.40.206:62623 L=40 S=0x00 I=22974 F=0x4000 T=43
Jul 22 09:21:51 pohakea kernel: Packet log: input REJECT eth0 PROTO=6
220.127.116.11:6667 18.104.22.168:62640 L=44 S=0x00 I=65459 F=0x4000 T=43
Jul 22 09:03:13 pohakea kernel: Packet log: input REJECT eth0 PROTO=6
22.214.171.124:6667 126.96.36.199:62537 L=40 S=0x00 I=20764 F=0x4000 T=48
Jul 22 09:37:25 pohakea kernel: Packet log: input REJECT eth0 PROTO=6
188.8.131.52:6667 184.108.40.206:62726 L=48 S=0x00 I=0 F=0x4000 T=45
I'm not involved w/IRC clients or servers so don't know what's causing this
I'm getting fed up w/ the dozen or so IP's that continue this barrage....
Does anyone know of any abuse templates I could tweak to forward
to the RP's involved?
Dshield mailing list
Dshield at dshield.org
To change your subscription options (or unsubscribe), see:
More information about the list