1,[05/Dec/2002 07:08:04] Rule 'Packet to unopened port received': Blocked: In UDP, 10.251.111.42:4682->localhost:27015, Owner: no owner
1,[05/Dec/2002 07:08:04] Rule 'Packet to unopened port received': Blocked: In UDP, 10.251.111.42:4682->localhost:27016, Owner: no owner
1,[05/Dec/2002 07:08:04] Rule 'Packet to unopened port received': Blocked: In UDP, 10.251.111.42:4682->localhost:27017, Owner: no owner
1,[05/Dec/2002 07:08:04] Rule 'Packet to unopened port received': Blocked: In UDP, 10.251.111.42:4682->localhost:27018, Owner: no owner
1,[05/Dec/2002 07:08:04] Rule 'Packet to unopened port received': Blocked: In UDP, 10.251.111.42:4682->localhost:27019, Owner: no owner
1,[05/Dec/2002 07:08:04] Rule 'Packet to unopened port received': Blocked: In UDP, 10.251.111.42:4682->localhost:27020, Owner: no owner
1,[05/Dec/2002 07:08:04] Rule 'Packet to unopened port received': Blocked: In UDP, 10.251.111.42:4682->localhost:27021, Owner: no owner
1,[05/Dec/2002 07:08:04] Rule 'Packet to unopened port received': Blocked: In UDP, 10.251.111.42:4682->localhost:27022, Owner: no owner
1,[05/Dec/2002 07:08:04] Rule 'Packet to unopened port received': Blocked: In UDP, 10.251.111.42:4682->localhost:27023, Owner: no owner
1,[05/Dec/2002 07:08:04] Rule 'Packet to unopened port received': Blocked: In UDP, 10.251.111.42:4682->localhost:27024, Owner: no owner
1,[08/Dec/2002 16:44:25] Rule 'TCP ack packet attack': Blocked: In TCP, 10.251.111.42:139->localhost:1520, Owner: no owner
1,[08/Dec/2002 16:44:27] Rule 'TCP ack packet attack': Blocked: In TCP, 10.251.111.42:139->localhost:1520, Owner: no owner
1,[08/Dec/2002 16:44:29] Rule 'TCP ack packet attack': Blocked: In TCP, 10.251.111.42:139->localhost:1524, Owner: no owner
1,[08/Dec/2002 16:44:32] Rule 'TCP ack packet attack': Blocked: In TCP, 10.251.111.42:139->localhost:1524, Owner: no owner
1,[08/Dec/2002 16:44:33] Rule 'TCP ack packet attack': Blocked: In TCP, 10.251.111.42:139->localhost:1520, Owner: no owner
1,[08/Dec/2002 16:44:38] Rule 'TCP ack packet attack': Blocked: In TCP, 10.251.111.42:139->localhost:1524, Owner: no owner
1,[08/Dec/2002 16:44:25] Rule 'TCP ack packet attack': Blocked: In TCP, 10.251.111.42:139->localhost:1520, Owner: no owner
1,[08/Dec/2002 16:44:27] Rule 'TCP ack packet attack': Blocked: In TCP, 10.251.111.42:139->localhost:1520, Owner: no owner
1,[08/Dec/2002 16:44:29] Rule 'TCP ack packet attack': Blocked: In TCP, 10.251.111.42:139->localhost:1524, Owner: no owner
1,[08/Dec/2002 16:44:32] Rule 'TCP ack packet attack': Blocked: In TCP, 10.251.111.42:139->localhost:1524, Owner: no owner
just a "little" snip from firewall logs. whats going on?
this has been going on from late november. sender uses ports 139, 1035-1038, 1781-1785, 3773-3776, 4678 and 4682. might have missed other ports, but logs are _big_.
since net access goes through lan and nat, i understand that part of the snip could be just normal traffic. however, 10.251.111.42 is sending much more packets to my "comp farm" than any else. maybe in 1000x more than others total. :)
so, should i pick up a baseball bat or just sit tight? :)
