Проработал 16 часов. Биллинг. Инета нет.
Админы: Вас самим не по себе не становится? Что я не сплю до 5, жду биллинга, чтобы ребутнуть сеть и со спокойной душой лечь спать.
Код:
System Log
Date/Time Facility Severity Message
Aug 22 22:04:37 user alert kernel: Intrusion -> IN=ppp_0_0_35_1 OUT= MAC= SRC=92.62.16.80 DST=92.125.126.33 LEN=64 TOS=0x00 PREC=0x00 TTL=36 ID=13706 DF PROTO=TCP SPT=4990 DPT=135 WINDOW=53760 RES=0x00 SYN URGP=0
Aug 22 22:16:06 user alert kernel: Intrusion -> IN=ppp_0_0_35_1 OUT= MAC= SRC=92.125.59.9 DST=92.125.126.33 LEN=48 TOS=0x00 PREC=0x00 TTL=120 ID=26522 DF PROTO=TCP SPT=28133 DPT=135 WINDOW=64240 RES=0x00 SYN URGP=0
Aug 22 22:18:16 syslog info -- MARK --
Aug 22 22:23:45 user warn syslog: dns query failed
Aug 22 22:23:47 user warn syslog: dns query failed
Aug 22 22:23:49 user warn syslog: dns query failed
Aug 22 22:24:22 user warn syslog: dns query failed
Aug 22 22:24:24 user warn syslog: dns query failed
Aug 22 22:24:26 user warn syslog: dns query failed
Aug 22 22:24:42 user alert kernel: Intrusion -> IN=ppp_0_0_35_1 OUT= MAC= SRC=92.125.71.202 DST=92.125.126.33 LEN=48 TOS=0x00 PREC=0x00 TTL=127 ID=65168 DF PROTO=TCP SPT=4050 DPT=135 WINDOW=64800 RES=0x00 SYN URGP=0
Aug 22 22:24:59 user warn syslog: dns query failed
Aug 22 22:25:01 user warn syslog: dns query failed
Aug 22 22:25:03 user warn syslog: dns query failed
Aug 22 22:25:36 user warn syslog: dns query failed
Aug 22 22:25:38 user warn syslog: dns query failed
Aug 22 22:25:40 user warn syslog: dns query failed
Aug 22 22:26:13 user warn syslog: dns query failed
Aug 22 22:26:15 user warn syslog: dns query failed
Aug 22 22:26:17 user warn syslog: dns query failed
Aug 22 22:27:23 user warn syslog: dns query failed
Aug 22 22:27:25 user warn syslog: dns query failed
Aug 22 22:37:16 user alert kernel: Intrusion -> IN=ppp_0_0_35_1 OUT= MAC= SRC=92.112.194.32 DST=92.125.126.33 LEN=48 TOS=0x00 PREC=0x00 TTL=115 ID=16736 DF PROTO=TCP SPT=3107 DPT=135 WINDOW=64800 RES=0x00 SYN URGP=0
Aug 22 22:47:08 user alert kernel: Intrusion -> IN=ppp_0_0_35_1 OUT= MAC= SRC=92.125.66.58 DST=92.125.126.33 LEN=52 TOS=0x00 PREC=0x00 TTL=63 ID=60096 DF PROTO=TCP SPT=7344 DPT=135 WINDOW=60352 RES=0x00 SYN URGP=0
Aug 22 22:54:44 user alert kernel: Intrusion -> IN=ppp_0_0_35_1 OUT= MAC= SRC=92.125.250.1 DST=92.125.126.33 LEN=48 TOS=0x00 PREC=0x00 TTL=122 ID=25355 DF PROTO=TCP SPT=26161 DPT=135 WINDOW=64800 RES=0x00 SYN URGP=0
Aug 22 23:04:11 user alert kernel: Intrusion -> IN=ppp_0_0_35_1 OUT= MAC= SRC=92.125.76.200 DST=92.125.126.33 LEN=48 TOS=0x00 PREC=0x00 TTL=127 ID=19196 DF PROTO=TCP SPT=2079 DPT=445 WINDOW=64800 RES=0x00 SYN URGP=0
Aug 22 23:15:41 user alert kernel: Intrusion -> IN=ppp_0_0_35_1 OUT= MAC= SRC=212.233.205.89 DST=92.125.126.33 LEN=48 TOS=0x00 PREC=0x00 TTL=113 ID=57294 DF PROTO=TCP SPT=2680 DPT=445 WINDOW=65280 RES=0x00 SYN URGP=0
Aug 22 23:18:16 syslog info -- MARK --
Aug 22 23:23:50 user alert kernel: Intrusion -> IN=ppp_0_0_35_1 OUT= MAC= SRC=92.125.71.94 DST=92.125.126.33 LEN=52 TOS=0x00 PREC=0x00 TTL=63 ID=26720 DF PROTO=TCP SPT=41312 DPT=135 WINDOW=60352 RES=0x00 SYN URGP=0
Aug 22 23:34:22 user alert kernel: Intrusion -> IN=ppp_0_0_35_1 OUT= MAC= SRC=92.125.72.63 DST=92.125.126.33 LEN=48 TOS=0x00 PREC=0x00 TTL=127 ID=42251 DF PROTO=TCP SPT=3666 DPT=445 WINDOW=64800 RES=0x00 SYN URGP=0
Aug 22 23:34:47 user warn syslog: dns query failed
Aug 22 23:44:44 user alert kernel: Intrusion -> IN=ppp_0_0_35_1 OUT= MAC= SRC=92.125.30.26 DST=92.125.126.33 LEN=48 TOS=0x00 PREC=0x00 TTL=121 ID=46978 DF PROTO=TCP SPT=3831 DPT=135 WINDOW=65280 RES=0x00 SYN URGP=0
Aug 22 23:53:51 user alert kernel: Intrusion -> IN=ppp_0_0_35_1 OUT= MAC= SRC=92.125.74.24 DST=92.125.126.33 LEN=48 TOS=0x00 PREC=0x00 TTL=127 ID=56955 DF PROTO=TCP SPT=4231 DPT=135 WINDOW=64800 RES=0x00 SYN URGP=0
Aug 23 00:04:17 user alert kernel: Intrusion -> IN=ppp_0_0_35_1 OUT= MAC= SRC=92.125.69.22 DST=92.125.126.33 LEN=48 TOS=0x00 PREC=0x00 TTL=127 ID=62257 DF PROTO=TCP SPT=1745 DPT=135 WINDOW=65535 RES=0x00 SYN URGP=0
Aug 23 00:09:18 user warn syslog: dns query failed
Aug 23 00:09:20 user warn syslog: dns query failed
Aug 23 00:09:22 user warn syslog: dns query failed
Aug 23 00:09:56 user warn syslog: dns query failed
Aug 23 00:09:58 user warn syslog: dns query failed
Aug 23 00:10:00 user warn syslog: dns query failed
Aug 23 00:10:33 user warn syslog: dns query failed
Aug 23 00:10:35 user warn syslog: dns query failed
Aug 23 00:10:37 user warn syslog: dns query failed
Aug 23 00:11:11 user warn syslog: dns query failed
Aug 23 00:11:13 user warn syslog: dns query failed
Aug 23 00:11:15 user warn syslog: dns query failed
Aug 23 00:11:48 user warn syslog: dns query failed
Aug 23 00:11:50 user warn syslog: dns query failed
Aug 23 00:11:52 user warn syslog: dns query failed
Aug 23 00:11:54 user warn syslog: dns query failed
Aug 23 00:12:27 user warn syslog: dns query failed
Aug 23 00:12:29 user warn syslog: dns query failed
Aug 23 00:12:31 user warn syslog: dns query failed
Aug 23 00:14:10 user alert kernel: Intrusion -> IN=ppp_0_0_35_1 OUT= MAC= SRC=92.125.30.229 DST=92.125.126.33 LEN=52 TOS=0x00 PREC=0x00 TTL=57 ID=8618 DF PROTO=TCP SPT=13706 DPT=135 WINDOW=60352 RES=0x00 SYN URGP=0
Aug 23 00:18:16 syslog info -- MARK --
Aug 23 00:27:00 user alert kernel: Intrusion -> IN=ppp_0_0_35_1 OUT= MAC= SRC=92.125.68.141 DST=92.125.126.33 LEN=52 TOS=0x00 PREC=0x00 TTL=63 ID=30940 DF PROTO=TCP SPT=9835 DPT=135 WINDOW=60352 RES=0x00 SYN URGP=0
Aug 23 00:34:32 user alert kernel: Intrusion -> IN=ppp_0_0_35_1 OUT= MAC= SRC=65.244.122.162 DST=92.125.126.33 LEN=48 TOS=0x00 PREC=0x00 TTL=111 ID=13445 DF PROTO=TCP SPT=58098 DPT=445 WINDOW=64240 RES=0x00 SYN URGP=0
Aug 23 00:44:00 user alert kernel: Intrusion -> IN=ppp_0_0_35_1 OUT= MAC= SRC=92.125.111.90 DST=92.125.126.33 LEN=48 TOS=0x00 PREC=0x00 TTL=127 ID=17112 DF PROTO=TCP SPT=1197 DPT=135 WINDOW=64800 RES=0x00 SYN URGP=0
Aug 23 00:54:04 user alert kernel: Intrusion -> IN=ppp_0_0_35_1 OUT= MAC= SRC=92.125.120.198 DST=92.125.126.33 LEN=48 TOS=0x00 PREC=0x00 TTL=127 ID=35477 DF PROTO=TCP SPT=3768 DPT=1433 WINDOW=64800 RES=0x00 SYN URGP=0
Aug 23 01:06:46 user alert kernel: Intrusion -> IN=ppp_0_0_35_1 OUT= MAC= SRC=92.125.68.141 DST=92.125.126.33 LEN=52 TOS=0x00 PREC=0x00 TTL=63 ID=26251 DF PROTO=TCP SPT=27068 DPT=135 WINDOW=60352 RES=0x00 SYN URGP=0
Aug 23 01:14:06 user alert kernel: Intrusion -> IN=ppp_0_0_35_1 OUT= MAC= SRC=66.29.244.202 DST=92.125.126.33 LEN=48 TOS=0x00 PREC=0x00 TTL=117 ID=57123 DF PROTO=TCP SPT=1354 DPT=445 WINDOW=64240 RES=0x00 SYN URGP=0
Aug 23 01:18:15 syslog info -- MARK --
Aug 23 01:24:34 user alert kernel: Intrusion -> IN=ppp_0_0_35_1 OUT= MAC= SRC=92.125.74.60 DST=92.125.126.33 LEN=48 TOS=0x00 PREC=0x00 TTL=127 ID=23490 DF PROTO=TCP SPT=1453 DPT=445 WINDOW=64800 RES=0x00 SYN URGP=0
Aug 23 01:36:07 user alert kernel: Intrusion -> IN=ppp_0_0_35_1 OUT= MAC= SRC=92.125.68.141 DST=92.125.126.33 LEN=52 TOS=0x00 PREC=0x00 TTL=63 ID=56404 DF PROTO=TCP SPT=40501 DPT=135 WINDOW=60352 RES=0x00 SYN URGP=0
Aug 23 01:44:15 user alert kernel: Intrusion -> IN=ppp_0_0_35_1 OUT= MAC= SRC=92.125.75.122 DST=92.125.126.33 LEN=40 TOS=0x00 PREC=0x00 TTL=127 ID=26632 PROTO=TCP SPT=29807 DPT=139 WINDOW=16384 RES=0x00 SYN URGP=0
Aug 23 01:54:23 user alert kernel: Intrusion -> IN=ppp_0_0_35_1 OUT= MAC= SRC=92.125.120.198 DST=92.125.126.33 LEN=48 TOS=0x00 PREC=0x00 TTL=127 ID=30954 DF PROTO=TCP SPT=3514 DPT=1433 WINDOW=64800 RES=0x00 SYN URGP=0
Aug 23 02:04:05 user alert kernel: Intrusion -> IN=ppp_0_0_35_1 OUT= MAC= SRC=92.125.41.174 DST=92.125.126.33 LEN=48 TOS=0x00 PREC=0x00 TTL=120 ID=3752 DF PROTO=TCP SPT=4538 DPT=1433 WINDOW=65535 RES=0x00 SYN URGP=0
Aug 23 02:15:13 user alert kernel: Intrusion -> IN=ppp_0_0_35_1 OUT= MAC= SRC=92.125.68.141 DST=92.125.126.33 LEN=52 TOS=0x00 PREC=0x00 TTL=63 ID=46968 DF PROTO=TCP SPT=58799 DPT=135 WINDOW=60352 RES=0x00 SYN URGP=0
Aug 23 02:18:16 syslog info -- MARK --
Aug 23 02:24:01 user alert kernel: Intrusion -> IN=ppp_0_0_35_1 OUT= MAC= SRC=194.29.186.201 DST=92.125.126.33 LEN=48 TOS=0x00 PREC=0x00 TTL=119 ID=19816 DF PROTO=TCP SPT=2464 DPT=57885 WINDOW=65535 RES=0x00 SYN URGP=0
Aug 23 02:34:33 user alert kernel: Intrusion -> IN=ppp_0_0_35_1 OUT= MAC= SRC=92.125.71.234 DST=92.125.126.33 LEN=48 TOS=0x00 PREC=0x00 TTL=127 ID=22449 DF PROTO=TCP SPT=4083 DPT=135 WINDOW=64800 RES=0x00 SYN URGP=0
Aug 23 02:43:56 user alert kernel: Intrusion -> IN=ppp_0_0_35_1 OUT= MAC= SRC=92.72.55.6 DST=92.125.126.33 LEN=52 TOS=0x00 PREC=0x00 TTL=53 ID=59266 DF PROTO=TCP SPT=2107 DPT=445 WINDOW=32767 RES=0x00 SYN URGP=0
Aug 23 02:54:19 user alert kernel: Intrusion -> IN=ppp_0_0_35_1 OUT= MAC= SRC=92.125.68.141 DST=92.125.126.33 LEN=52 TOS=0x00 PREC=0x00 TTL=63 ID=33283 DF PROTO=TCP SPT=14634 DPT=135 WINDOW=60352 RES=0x00 SYN URGP=0
Aug 23 03:04:04 user alert kernel: Intrusion -> IN=ppp_0_0_35_1 OUT= MAC= SRC=92.125.68.141 DST=92.125.126.33 LEN=52 TOS=0x00 PREC=0x00 TTL=63 ID=63007 DF PROTO=TCP SPT=19490 DPT=135 WINDOW=60352 RES=0x00 SYN URGP=0
Aug 23 03:13:51 user alert kernel: Intrusion -> IN=ppp_0_0_35_1 OUT= MAC= SRC=92.125.68.141 DST=92.125.126.33 LEN=52 TOS=0x00 PREC=0x00 TTL=63 ID=26973 DF PROTO=TCP SPT=24229 DPT=135 WINDOW=60352 RES=0x00 SYN URGP=0
Aug 23 03:18:15 syslog info -- MARK --
Aug 23 03:19:46 user warn syslog: dns query failed
Aug 23 03:29:14 user alert kernel: Intrusion -> IN=ppp_0_0_35_1 OUT= MAC= SRC=92.125.75.122 DST=92.125.126.33 LEN=52 TOS=0x00 PREC=0x00 TTL=63 ID=47161 DF PROTO=TCP SPT=40307 DPT=135 WINDOW=60352 RES=0x00 SYN URGP=0
Aug 23 03:39:03 user alert kernel: Intrusion -> IN=ppp_0_0_35_1 OUT= MAC= SRC=92.125.75.122 DST=92.125.126.33 LEN=52 TOS=0x00 PREC=0x00 TTL=63 ID=51977 DF PROTO=TCP SPT=26655 DPT=135 WINDOW=60352 RES=0x00 SYN URGP=0
Aug 23 03:46:39 user alert kernel: Intrusion -> IN=ppp_0_0_35_1 OUT= MAC= SRC=92.125.75.122 DST=92.125.126.33 LEN=40 TOS=0x00 PREC=0x00 TTL=127 ID=21222 PROTO=TCP SPT=29807 DPT=139 WINDOW=16384 RES=0x00 SYN URGP=0
Aug 23 03:47:55 user warn syslog: dns query failed
Aug 23 03:47:57 user warn syslog: dns query failed
Aug 23 03:47:59 user warn syslog: dns query failed
Aug 23 03:48:32 user warn syslog: dns query failed
Aug 23 03:48:34 user warn syslog: dns query failed
Aug 23 03:48:36 user warn syslog: dns query failed
Aug 23 03:49:09 user warn syslog: dns query failed
Aug 23 03:49:11 user warn syslog: dns query failed
Aug 23 03:49:13 user warn syslog: dns query failed
Aug 23 03:49:46 user warn syslog: dns query failed
Aug 23 03:49:48 user warn syslog: dns query failed
Aug 23 03:49:50 user warn syslog: dns query failed
Aug 23 03:50:23 user warn syslog: dns query failed
Aug 23 03:50:25 user warn syslog: dns query failed
Aug 23 03:50:27 user warn syslog: dns query failed
Aug 23 03:51:00 user warn syslog: dns query failed
Aug 23 03:51:02 user warn syslog: dns query failed
Aug 23 03:51:04 user warn syslog: dns query failed
Aug 23 04:02:44 user alert kernel: Intrusion -> IN=ppp_0_0_35_1 OUT= MAC= SRC=92.125.68.141 DST=92.125.126.33 LEN=52 TOS=0x00 PREC=0x00 TTL=63 ID=38216 DF PROTO=TCP SPT=47919 DPT=135 WINDOW=60352 RES=0x00 SYN URGP=0
Aug 23 04:08:25 user alert kernel: Intrusion -> IN=ppp_0_0_35_1 OUT= MAC= SRC=92.125.75.122 DST=92.125.126.33 LEN=52 TOS=0x00 PREC=0x00 TTL=63 ID=65007 DF PROTO=TCP SPT=52773 DPT=135 WINDOW=60352 RES=0x00 SYN URGP=0
Aug 23 04:18:16 syslog info -- MARK --
Aug 23 04:24:58 user warn syslog: dns query failed
Aug 23 04:32:08 user alert kernel: Intrusion -> IN=ppp_0_0_35_1 OUT= MAC= SRC=92.125.68.141 DST=92.125.126.33 LEN=52 TOS=0x00 PREC=0x00 TTL=63 ID=51151 DF PROTO=TCP SPT=62272 DPT=135 WINDOW=60352 RES=0x00 SYN URGP=0
Aug 23 04:35:03 user alert kernel: Intrusion -> IN=ppp_0_0_35_1 OUT= MAC= SRC=92.125.75.122 DST=92.125.126.33 LEN=40 TOS=0x00 PREC=0x00 TTL=127 ID=28290 PROTO=TCP SPT=29807 DPT=139 WINDOW=16384 RES=0x00 SYN URGP=0
Aug 23 04:36:34 user alert kernel: Intrusion -> IN=ppp_0_0_35_1 OUT= MAC= SRC=92.125.75.122 DST=92.125.126.33 LEN=40 TOS=0x00 PREC=0x00 TTL=127 ID=3889 PROTO=TCP SPT=29807 DPT=139 WINDOW=16384 RES=0x00 SYN URGP=0
Aug 23 04:45:58 user warn syslog: dns query failed
Aug 23 04:46:00 user warn syslog: dns query failed
Aug 23 04:46:02 user warn syslog: dns query failed
Aug 23 04:46:04 user warn syslog: dns query failed
Aug 23 04:46:06 user warn syslog: dns query failed
Aug 23 04:46:08 user warn syslog: dns query failed
Aug 23 04:46:41 user warn syslog: dns query failed
Aug 23 04:46:43 user warn syslog: dns query failed
Aug 23 04:46:45 user warn syslog: dns query failed
Aug 23 04:47:13 daemon info pppd[241]: No response to 3 echo-requests
Aug 23 04:47:13 daemon notice pppd[241]: Serial link appears to be disconnected.
Aug 23 04:47:14 daemon info pppd[241]: Connect time 974.1 minutes.
Aug 23 04:47:14 daemon info pppd[241]: Sent 133837097 bytes, received 833031404 bytes.
Aug 23 04:47:17 daemon warn pppd[241]: Couldn't increase MRU to 1500
Aug 23 04:47:18 daemon notice pppd[241]: Connection terminated....
Aug 23 04:47:19 user warn syslog: dns query failed
Aug 23 04:47:21 user warn syslog: dns query failed
Aug 23 04:47:23 daemon info pppd[241]: Sent PADT
Aug 23 04:47:23 user warn syslog: dns query failed
Aug 23 04:47:23 daemon info pppd[241]: PPP session is 2303
Aug 23 04:47:23 daemon info pppd[241]: Using interface ppp0_0_35_1
Aug 23 04:47:24 daemon notice pppd[241]: Connect: ppp_0_0_35_1 <--> nas_0_0_35
Aug 23 04:47:24 daemon warn pppd[241]: Couldn't increase MRU to 1500
Aug 23 04:47:24 daemon warn pppd[241]: Couldn't increase MRU to 1500
Aug 23 04:47:24 daemon notice pppd[241]: PAP authentication succeeded
Aug 23 04:47:24 daemon notice pppd[241]: peer from calling number 00:90:1A:42:B8:EF authorized
Aug 23 04:47:25 user warn syslog: dns query failed
Aug 23 04:47:25 daemon notice pppd[241]: local IP address 92.125.67.199
Aug 23 04:47:25 daemon notice pppd[241]: remote IP address 213.228.116.68
Aug 23 04:47:25 daemon notice pppd[241]: primary DNS address 212.94.96.70
Aug 23 04:47:25 daemon notice pppd[241]: secondary DNS address 212.94.96.124
Aug 23 04:47:27 user warn syslog: dns query failed
Aug 23 04:47:29 user warn syslog: dns query failed
Aug 23 04:47:54 user alert kernel: Intrusion -> IN=ppp_0_0_35_1 OUT= MAC= SRC=67.208.236.71 DST=92.125.67.199 LEN=48 TOS=0x00 PREC=0x00 TTL=115 ID=53927 DF PROTO=TCP SPT=2321 DPT=445 WINDOW=64240 RES=0x00 SYN URGP=0
Aug 23 04:48:02 user warn syslog: dns query failed
Aug 23 04:48:04 user warn syslog: dns query failed
Aug 23 04:48:06 user warn syslog: dns query failed
Aug 23 04:48:08 user warn syslog: dns query failed
Aug 23 04:48:10 user warn syslog: dns query failed
Aug 23 04:48:12 user warn syslog: dns query failed