howardb
Expert Member
Hey all,
Was checking my D-Link ADSL modem logs when I got home to get some detail for OpenWeb re the speed issues, however see some strange entries as follows, with similar values but different IP's in the "SRC=" section - never noticed these before:
kernel: Intrusion -> IN=ppp_0_8_35_1 OUT= MAC= SRC=115.69.210.200 DST=197.87.102.117 LEN=48 TOS=0x18 PREC=0x00 TTL=103 ID=17063 DF PROTO=TCP SPT=3695 DPT=445 WINDOW=65535 RES=0x00 SYN URGP=0
I have no idea what these values mean, however the first IP address on all the logged entries points to some random suspect country... second IP address is Mweb JHB so I assume this is my current connection to them using my backup Mweb account.
Thoughts, ideas, comments welcome.
Was checking my D-Link ADSL modem logs when I got home to get some detail for OpenWeb re the speed issues, however see some strange entries as follows, with similar values but different IP's in the "SRC=" section - never noticed these before:
kernel: Intrusion -> IN=ppp_0_8_35_1 OUT= MAC= SRC=115.69.210.200 DST=197.87.102.117 LEN=48 TOS=0x18 PREC=0x00 TTL=103 ID=17063 DF PROTO=TCP SPT=3695 DPT=445 WINDOW=65535 RES=0x00 SYN URGP=0
I have no idea what these values mean, however the first IP address on all the logged entries points to some random suspect country... second IP address is Mweb JHB so I assume this is my current connection to them using my backup Mweb account.
Thoughts, ideas, comments welcome.