dave morgan wrote:
I am experimenting with some new firewall software -
this is the 3rd report it has generated from this netblock in 24 hrs
all other reports from other addresses seem like 'normal' abuse.
Is anyone else seeing this, or is it a bug in my software?
(I have checked apache log, one http request in that hour at all)
No, I'm getting this traffic too, but it doesn't look like abuse:
May 17 17:30:05 vash kernel: IN=eth0 OUT=
MAC=aa:00:00:11:83:8e:fe:ff:ff:ff:ff:ff:08:00 SRC=216.239.35.28
DST=65.254.37.170 LEN=76 TOS=0x00 PREC=0x00 TTL=55 ID=64328 DF PROTO=UDP
SPT=35387 DPT=123 LEN=56
May 17 17:30:05 vash kernel: IN=eth0 OUT=
MAC=aa:00:00:11:83:8e:fe:ff:ff:ff:ff:ff:08:00 SRC=216.239.35.28
DST=65.254.37.170 LEN=76 TOS=0x00 PREC=0x00 TTL=55 ID=64594 DF PROTO=UDP
SPT=35377 DPT=123 LEN=56
Here's the breakdown per client since 5/17, 06:26 CDT
vash:~# ntp-clients
148 216.239.35.28
4 216.239.45.4
4 216.239.71.65
_______________________________________________
timekeepers mailing list
[email protected]
https://fortytwo.ch/mailman/cgi-bin/listinfo/timekeepers