Ich logge da einen riesigen haufen ganz merkwürdige Pakete.
Irgendwie sehen sie aus wie DHCP-Request-Packete. Ich habe jedoch keinen DHCP Client am laufen.
Ich poste mal den iptable log und die laufenden Prozesse:
Code: Alles auswählen
Feb 23 09:44:12 lkoestler kernel: #### IP Header ####IN=eth0 OUT= MAC=ff:ff:ff:ff:ff:ff:00:1c:c5:4b:f7:00:08:00 SRC=0.0.0.0 DST=255.255.255.255 LEN=312 TOS=0x00 PREC=0x00 TTL=128 ID=445 PROTO=UDP SPT=68 DPT=67 LEN=292
Feb 23 09:44:12 lkoestler kernel: #### IP Header ####IN=eth1 OUT= MAC=ff:ff:ff:ff:ff:ff:00:1c:c5:4b:f7:00:08:00 SRC=0.0.0.0 DST=255.255.255.255 LEN=312 TOS=0x00 PREC=0x00 TTL=128 ID=445 PROTO=UDP SPT=68 DPT=67 LEN=292
Feb 23 09:44:13 lkoestler kernel: #### IP Header ####IN=eth1 OUT= MAC=00:16:3e:3a:ff:a1:00:10:db:ff:20:71:08:00 SRC=217.162.85.182 DST=10.2.2.210 LEN=42 TOS=0x00 PREC=0x00 TTL=59 ID=0 PROTO=UDP SPT=32811 DPT=213 LEN=22
Feb 23 09:44:17 lkoestler kernel: #### IP Header ####IN=eth0 OUT= MAC=ff:ff:ff:ff:ff:ff:00:1c:c5:53:85:a0:08:00 SRC=0.0.0.0 DST=255.255.255.255 LEN=312 TOS=0x00 PREC=0x00 TTL=128 ID=14193 PROTO=UDP SPT=68 DPT=67 LEN=292
Feb 23 09:44:17 lkoestler kernel: #### IP Header ####IN=eth1 OUT= MAC=ff:ff:ff:ff:ff:ff:00:1c:c5:53:85:a0:08:00 SRC=0.0.0.0 DST=255.255.255.255 LEN=312 TOS=0x00 PREC=0x00 TTL=128 ID=14193 PROTO=UDP SPT=68 DPT=67 LEN=292
Feb 23 09:44:17 lkoestler kernel: #### IP Header ####IN=eth1 OUT= MAC=00:16:3e:3a:ff:a1:00:10:db:ff:20:71:08:00 SRC=217.162.85.182 DST=10.2.2.210 LEN=42 TOS=0x00 PREC=0x00 TTL=59 ID=0 PROTO=UDP SPT=32811 DPT=213 LEN=22
Feb 23 09:44:18 lkoestler kernel: #### IP Header ####IN=eth0 OUT= MAC=ff:ff:ff:ff:ff:ff:00:1c:c5:53:a0:a0:08:00 SRC=0.0.0.0 DST=255.255.255.255 LEN=312 TOS=0x00 PREC=0x00 TTL=128 ID=55628 PROTO=UDP SPT=68 DPT=67 LEN=292
Feb 23 09:44:18 lkoestler kernel: #### IP Header ####IN=eth1 OUT= MAC=ff:ff:ff:ff:ff:ff:00:1c:c5:53:a0:a0:08:00 SRC=0.0.0.0 DST=255.255.255.255 LEN=312 TOS=0x00 PREC=0x00 TTL=128 ID=55628 PROTO=UDP SPT=68 DPT=67 LEN=292
Feb 23 09:44:20 lkoestler kernel: #### IP Header ####IN=eth1 OUT= MAC=00:16:3e:3a:ff:a1:00:10:db:ff:20:71:08:00 SRC=217.162.85.182 DST=10.2.2.210 LEN=42 TOS=0x00 PREC=0x00 TTL=59 ID=0 PROTO=UDP SPT=32811 DPT=213 LEN=22
Feb 23 09:44:22 lkoestler kernel: #### IP Header ####IN=eth1 OUT= MAC=00:16:3e:3a:ff:a1:00:10:db:ff:20:71:08:00 SRC=217.162.85.182 DST=10.2.2.210 LEN=42 TOS=0x00 PREC=0x00 TTL=59 ID=0 PROTO=UDP SPT=32811 DPT=213 LEN=22
Feb 23 09:44:24 lkoestler kernel: #### IP Header ####IN=eth0 OUT= MAC=ff:ff:ff:ff:ff:ff:00:1c:c5:4b:f7:00:08:00 SRC=0.0.0.0 DST=255.255.255.255 LEN=312 TOS=0x00 PREC=0x00 TTL=128 ID=65432 PROTO=UDP SPT=68 DPT=67 LEN=292
Feb 23 09:44:24 lkoestler kernel: #### IP Header ####IN=eth1 OUT= MAC=ff:ff:ff:ff:ff:ff:00:1c:c5:4b:f7:00:08:00 SRC=0.0.0.0 DST=255.255.255.255 LEN=312 TOS=0x00 PREC=0x00 TTL=128 ID=65432 PROTO=UDP SPT=68 DPT=67 LEN=292
Feb 23 09:44:25 lkoestler kernel: #### IP Header ####IN=eth1 OUT= MAC=00:16:3e:3a:ff:a1:00:10:db:ff:20:71:08:00 SRC=217.162.85.182 DST=10.2.2.210 LEN=42 TOS=0x00 PREC=0x00 TTL=59 ID=0 PROTO=UDP SPT=32811 DPT=213 LEN=22
ps aux:
Code: Alles auswählen
USER PID %CPU %MEM VSZ RSS TTY STAT START TIME COMMAND
root 1 0.0 0.1 6116 668 ? Ss Feb22 0:00 init [2]
root 2 0.0 0.0 0 0 ? S Feb22 0:00 [migration/0]
root 3 0.0 0.0 0 0 ? SN Feb22 0:00 [ksoftirqd/0]
root 4 0.0 0.0 0 0 ? S Feb22 0:00 [watchdog/0]
root 5 0.0 0.0 0 0 ? S< Feb22 0:00 [events/0]
root 6 0.0 0.0 0 0 ? S< Feb22 0:00 [khelper]
root 7 0.0 0.0 0 0 ? S< Feb22 0:00 [kthread]
root 8 0.0 0.0 0 0 ? S< Feb22 0:00 [xenwatch]
root 9 0.0 0.0 0 0 ? S< Feb22 0:00 [xenbus]
root 17 0.0 0.0 0 0 ? S< Feb22 0:00 [kblockd/0]
root 21 0.0 0.0 0 0 ? S< Feb22 0:00 [khubd]
root 23 0.0 0.0 0 0 ? S< Feb22 0:00 [kseriod]
root 66 0.0 0.0 0 0 ? S Feb22 0:00 [pdflush]
root 67 0.0 0.0 0 0 ? S Feb22 0:00 [pdflush]
root 68 0.0 0.0 0 0 ? S< Feb22 0:00 [kswapd0]
root 69 0.0 0.0 0 0 ? S< Feb22 0:00 [aio/0]
root 606 0.0 0.0 0 0 ? S< Feb22 0:00 [kmirrord]
root 665 0.0 0.0 0 0 ? S< Feb22 0:00 [kjournald]
root 1125 0.0 0.1 3724 592 ? Ss Feb22 0:00 /sbin/syslogd
root 1131 0.0 0.0 2652 392 ? Ss Feb22 0:00 /sbin/klogd -x
root 1186 0.0 0.2 10104 1512 ? S Feb22 0:00 /bin/sh /usr/bin/mysqld_safe
mysql 1223 0.0 6.2 148040 32784 ? Sl Feb22 0:07 /usr/sbin/mysqld --basedir=/usr --datadir=/var/lib/mysql --
root 1224 0.0 0.1 2632 532 ? S Feb22 0:00 logger -p daemon.err -t mysqld_safe -i -t mysqld
polw 1275 0.0 2.2 31724 11672 ? Ss Feb22 0:00 policyd-weight (master)
polw 1276 0.0 2.2 31988 11664 ? Ss Feb22 0:00 policyd-weight (cache)
root 1280 0.0 8.6 79020 45488 ? Ss Feb22 0:00 /usr/sbin/spamd --create-prefs --max-children 2 --helper-ho
dcc 1292 0.0 1.6 31108 8492 ? Ssl Feb22 0:00 /usr/sbin/dccifd
root 1438 0.0 0.3 19612 2064 ? Ss Feb22 0:00 /usr/lib/postfix/master
postfix 1445 0.0 0.4 20688 2132 ? S Feb22 0:00 qmgr -l -t fifo -u
root 1453 0.0 0.2 25832 1256 ? Ss Feb22 0:00 /usr/sbin/sshd
root 1489 0.0 0.1 7112 668 ? Ss Feb22 0:01 /usr/sbin/dovecot
root 1499 0.0 10.9 90992 57428 ? S Feb22 0:22 spamd child
root 1500 0.0 9.7 84528 50984 ? S Feb22 0:00 spamd child
root 1511 0.0 0.1 11492 936 ? Ss Feb22 0:00 /usr/sbin/cron
root 1525 0.0 0.5 39368 2996 ? S Feb22 0:01 dovecot-auth
root 1529 0.0 1.9 118812 10456 ? Ss Feb22 0:00 /usr/sbin/apache2 -k start
root 1551 0.0 0.1 2652 532 tty1 Ss+ Feb22 0:00 /sbin/getty 38400 tty1
postfix 1598 0.0 0.4 21724 2128 ? S Feb22 0:00 tlsmgr -l -t unix -u -c
polw 1601 0.0 2.3 32252 12396 ? S Feb22 0:02 policyd-weight (child)
polw 8476 0.0 2.3 32252 12388 ? S Feb22 0:00 policyd-weight (child)
polw 8596 0.0 2.3 32252 12404 ? S Feb22 0:00 policyd-weight (child)
dovecot 13572 0.0 0.3 8892 2016 ? S 08:09 0:00 imap-login
dovecot 13573 0.0 0.3 8896 2024 ? S 08:09 0:00 imap-login
lk 13592 0.0 0.9 12820 4896 ? S 08:36 0:00 imap
lk 13594 0.0 0.2 8940 1568 ? S 08:38 0:00 imap
postfix 13624 0.0 0.3 20648 2068 ? S 08:58 0:00 pickup -l -t fifo -u -c
root 13654 0.0 0.5 36780 2652 ? Ss 09:15 0:00 sshd: lk [priv]
lk 13656 0.0 0.3 36916 1812 ? S 09:15 0:00 sshd: lk@ttyp0
lk 13657 0.0 0.4 14124 2228 ttyp0 Ss 09:15 0:00 -sh
root 13660 0.0 0.2 21260 1128 ttyp0 S 09:15 0:00 su
root 13661 0.0 0.3 13628 2032 ttyp0 S 09:15 0:00 bash
root 14089 0.0 0.4 36784 2616 ? Ss 09:36 0:00 sshd: lk [priv]
lk 14097 0.0 0.3 37076 1780 ? S 09:36 0:00 sshd: lk@notty
lk 14098 0.0 0.3 20988 1660 ? Ss 09:36 0:00 /usr/lib/openssh/sftp-server
www-data 14176 0.1 2.3 127080 12572 ? S 09:40 0:00 /usr/sbin/apache2 -k start
www-data 14294 0.1 2.3 127080 12572 ? S 09:42 0:00 /usr/sbin/apache2 -k start
root 14301 0.0 0.5 36784 2656 ? Ss 09:42 0:00 sshd: lk [priv]
lk 14305 0.0 0.3 36784 1752 ? S 09:42 0:00 sshd: lk@ttyp1
lk 14306 0.0 0.4 14120 2224 ttyp1 Ss 09:42 0:00 -sh
www-data 14309 0.2 2.3 127080 12572 ? S 09:42 0:00 /usr/sbin/apache2 -k start
root 14314 0.0 0.2 21260 1128 ttyp1 S 09:42 0:00 su
root 14315 0.0 0.3 13612 2004 ttyp1 S+ 09:42 0:00 bash
dovecot 14355 0.0 0.3 8760 1788 ? S 09:43 0:00 imap-login
www-data 14357 0.3 2.4 127740 13092 ? S 09:43 0:00 /usr/sbin/apache2 -k start
www-data 14366 0.3 2.4 127740 13092 ? S 09:44 0:00 /usr/sbin/apache2 -k start
dovecot 14370 0.0 0.3 8764 1792 ? S 09:44 0:00 imap-login
www-data 14375 0.4 2.4 127740 13092 ? S 09:44 0:00 /usr/sbin/apache2 -k start
www-data 14384 0.6 2.5 127740 13204 ? S 09:45 0:00 /usr/sbin/apache2 -k start
www-data 14385 0.0 1.9 123772 10072 ? S 09:45 0:00 /usr/sbin/apache2 -k start
dovecot 14391 0.0 0.3 8760 1788 ? S 09:45 0:00 imap-login
www-data 14393 0.0 1.0 118812 5360 ? S 09:45 0:00 /usr/sbin/apache2 -k start
www-data 14394 0.0 1.0 118812 5360 ? S 09:45 0:00 /usr/sbin/apache2 -k start
root 14395 0.0 0.2 11740 1052 ttyp0 R+ 09:47 0:00 ps aux
Grüsse
Lorenz