Re: log interpreter , for report ...

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



> Hi again ,
> 
> 1°) This is a line of iptables log
> IN=ppp0 OUT= MAC= SRC=80.14.205.152 DST=80.15.220.67 LEN=48 TOS=0x00 PREC=0x00 
> TTL=121 ID=64444 DF PROTO=TCP SPT=4717 DPT=135 WINDOW=16384 RES=0x00 SYN 
> URGP=0
> 
> How to see what port have been attempted ?

SRC=80.14.205.152 	(source IP address)

inetnum:      80.14.205.0 - 80.14.205.255
netname:      IP2000-ADSL-BAS
descr:        BSSTR206 Strasbourg Bloc2
country:      FR
admin-c:      WITR1-RIPE
tech-c:       WITR1-RIPE
status:       ASSIGNED PA
remarks:      for hacking, spamming or security problems send mail to
remarks:      postmaster@xxxxxxxxxx AND abuse@xxxxxxxxxx
mnt-by:       FT-BRX
changed:      gestionip.ft@xxxxxxxxxxxxxxxxx 20020423
changed:      gestionip.ft@xxxxxxxxxxxxxxxxx 20030318
source:       RIPE

DST=80.15.220.67 	(destination IP address)

inetnum:      80.15.220.0 - 80.15.220.127
netname:      IP2000-ADSL-BAS
descr:        BSORL204 Orleans Bloc2
country:      FR
admin-c:      WITR1-RIPE
tech-c:       WITR1-RIPE
status:       ASSIGNED PA
remarks:      for hacking, spamming or security problems send mail to
remarks:      postmaster@xxxxxxxxxx AND abuse@xxxxxxxxxx
mnt-by:       FT-BRX
changed:      gestionip.ft@xxxxxxxxxxxxxxxxx 20020709
changed:      gestionip.ft@xxxxxxxxxxxxxxxxx 20030318
changed:      gestionip.ft@xxxxxxxxxxxxxxxxx 20031007
source:       RIPE


PROTO=TCP	(protocol)
SPT=4717	(source port)
DPT=135		(destination port)

as seen in /etc/services:

pmap           135/tcp         # DCE endpoint resolution

cheers,

+------------------------------------------------+
! Jordi Bruguera i Cortada         jordi@xxxxxx  !
! Cap Tècnic                                     !
! GRN Serveis Telemàtics, SL Tel. +34 972 230000 !
+------------------------------------------------+




[Index of Archives]     [Linux Netfilter Development]     [Linux Kernel Networking Development]     [Netem]     [Berkeley Packet Filter]     [Linux Kernel Development]     [Advanced Routing & Traffice Control]     [Bugtraq]

  Powered by Linux