Odd entries in my Security Router logs
I keep seeing these entry in my external routers log files. Does any
one recognize theme and know what type of attack they are. ok is
obviously something to do with DHCP. but i recently had a firewall
compromised and i still don't know how. since that wall had dhcp open
I wounder if this could have been the trick.
I has left the ip number as they are since none of them belong to me or
in any range i use !
# Time Packet Information
Reason Action
1|Dec 8 02 |From:192.168.7.249 To:192.168.255.254 |match
|block
| 09:37:12 |UDP src port:00068 dest port:00067 |service deny
|
2|Dec 8 02 |From:192.168.8.250 To:192.168.255.254 |match
|block
| 09:37:12 |UDP src port:00068 dest port:00067 |service deny
|
3|Dec 8 02 |From:192.168.7.249 To:192.168.255.254 |match
|block
| 15:45:32 |UDP src port:00068 dest port:00067 |service deny
|
----------------------------------------------------------------------------
This list is provided by the SecurityFocus ARIS analyzer service.
For more information on this free incident handling, management
and tracking system please see: http://aris.securityfocus.com
Received on Tue Dec 10 00:21:53 2002
This archive was generated by hypermail 2.1.8
: Wed Aug 23 2006 - 14:01:52 EDT
|