Jesper Jensen wrote:
> Jeg har netop blokeret for en forespørgsel til lsaa.exe.
> Forespørgslen kom fra "Technische Universitaet Braunschweig".
>
> Hvad går dette ud på ? Er jeg blevet angrebet eller ???
Det tror jeg ikke, i det øjeblik du prøver at tilgå IP adressen, prøver
den at lave en VPN forbindelse, heraf UDP 500 pakken,
$ tcpdump -r q
15:44:42.048637 quark.wmsecurity.dk.5587 > 134.169.18.26.www: S
298605355:1298605355(0) win 16384 <mss 1460,nop,nop,sackOK,nop,wscale
0,nop,nop,timestamp 1842121298 0> (DF) [tos 0x10]
15:44:42.094630 134.169.18.26.isakmp > quark.wmsecurity.dk.isakmp:
isakmp v1.0 exchange ID_PROT cookie:
bf211e952aac93b0->0000000000000000 msgid: 00000000 len: 904
15:44:42.094697 quark.wmsecurity.dk > 134.169.18.26: icmp:
quark.wmsecurity.dk udp port isakmp unreachable
15:44:43.140005 134.169.18.26.isakmp > quark.wmsecurity.dk.isakmp:
isakmp v1.0 exchange ID_PROT cookie:
bf211e952aac93b0->0000000000000000 msgid: 00000000 len: 904
15:44:43.140065 quark.wmsecurity.dk > 134.169.18.26: icmp:
quark.wmsecurity.dk udp port isakmp unreachable
15:44:45.186338 134.169.18.26.www > quark.wmsecurity.dk.5587: R 0:0(0)
ack 1298605356 win 0
15:44:45.195967 134.169.18.26.isakmp > quark.wmsecurity.dk.isakmp:
isakmp v1.0 exchange ID_PROT cookie:
bf211e952aac93b0->0000000000000000 msgid: 00000000 len: 904
15:44:45.196037 quark.wmsecurity.dk > 134.169.18.26: icmp:
quark.wmsecurity.dk udp port isakmp unreachable
Det er nok en Windows 2000 maskine, der kører ISA:
$ sudo nmap -sS -O -p 1-500 134.169.18.26
Starting nmap V. 2.54BETA25 (
www.insecure.org/nmap/ )
Interesting ports on (134.169.18.26):
(The 489 ports scanned but not shown below are in state: closed)
Port State Service
11/tcp filtered systat
15/tcp filtered netstat
25/tcp filtered smtp
111/tcp filtered sunrpc
135/tcp open loc-srv
137/tcp filtered netbios-ns
138/tcp filtered netbios-dgm
139/tcp filtered netbios-ssn
161/tcp filtered snmp
162/tcp filtered snmptrap
445/tcp filtered microsoft-ds
Remote OS guesses: Windows Me or Windows 2000 RC1 through final release,
MS Windows2000 Professional RC1/W2K Advance Server Beta3, Windows
Millenium Edition v4.90.3000