[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Quienes son?



Curioseando en la salida de mesg me encuentro con que mi firewall ha 
"dropeado" unos cuantos paquetes.  Mando whois y resulta que el primero es el 
IANA, que parece bastante inocuo pero no sé qué tiene que hacer mi sistema 
enviándole nada. Otros son Verio Inc. y Schlund+Partners AG que ya me 
preocupan un poco más.
Alguien sabe algo de esto? O tiene alguna acción para sugerir?

Mando el listado de mesg :

---------------------------------------------------------------------------------------------------------------------
 -> GSI 21 (level, high) -> IRQ 177
ACPI: PCI Interrupt Link [LNKE] enabled at IRQ 19
ACPI: PCI interrupt 0000:02:00.0[A] -> GSI 19 (level, high) -> IRQ 193
number of MP IRQ sources: 15.
number of IO-APIC #2 registers: 24.
testing the IO APIC.......................
IO APIC #2......
.... register #00: 02000000
.......    : physical APIC id: 02
.......    : Delivery Type: 0
.......    : LTS          : 0
.... register #01: 00170011
.......     : max redirection entries: 0017
.......     : PRQ implemented: 0
.......     : IO APIC version: 0011
.... register #02: 00000000
.......     : arbitration: 00
.... IRQ redirection table:
 NR Log Phy Mask Trig IRR Pol Stat Dest Deli Vect:
 00 000 00  1    0    0   0   0    0    0    00
 01 001 01  0    0    0   0   0    1    1    39
 02 000 00  1    0    0   0   0    0    0    00
 03 001 01  0    0    0   0   0    1    1    41
 04 001 01  0    0    0   0   0    1    1    49
 05 001 01  0    0    0   0   0    1    1    51
 06 001 01  0    0    0   0   0    1    1    59
 07 001 01  1    0    0   0   0    1    1    61
 08 001 01  0    0    0   0   0    1    1    69
 09 001 01  0    1    0   0   0    1    1    71
 0a 001 01  0    0    0   0   0    1    1    79
 0b 001 01  0    0    0   0   0    1    1    81
 0c 001 01  0    0    0   0   0    1    1    89
 0d 001 01  0    0    0   0   0    1    1    91
 0e 001 01  0    0    0   0   0    1    1    99
 0f 001 01  0    0    0   0   0    1    1    A1
 10 000 00  1    0    0   0   0    0    0    00
 11 000 00  1    0    0   0   0    0    0    00
 12 000 00  1    0    0   0   0    0    0    00
 13 001 01  1    1    0   0   0    1    1    C1
 14 001 01  1    1    0   0   0    1    1    B9
 15 001 01  1    1    0   0   0    1    1    B1
 16 001 01  1    1    0   0   0    1    1    A9
 17 000 00  1    0    0   0   0    0    0    00
Using vector-based indexing
IRQ to pin mappings:
IRQ0 -> 0:2
IRQ1 -> 0:1
IRQ3 -> 0:3
IRQ4 -> 0:4
IRQ5 -> 0:5
IRQ6 -> 0:6
IRQ7 -> 0:7
IRQ8 -> 0:8
IRQ9 -> 0:9
IRQ10 -> 0:10
IRQ11 -> 0:11
IRQ12 -> 0:12
IRQ13 -> 0:13
IRQ14 -> 0:14
IRQ15 -> 0:15
IRQ193 -> 0:19
IRQ185 -> 0:20
IRQ177 -> 0:21
IRQ169 -> 0:22
.................................... done.
Simple Boot Flag at 0x3f set to 0x1
VFS: Disk quotas dquot_6.5.1
Dquot-cache hash table entries: 1024 (order 0, 4096 bytes)
devfs: 2004-01-31 Richard Gooch (rgooch@atnf.csiro.au)
devfs: boot_options: 0x0
Initializing Cryptographic API
isapnp: Scanning for PnP cards...
isapnp: No Plug & Play device found
Serial: 8250/16550 driver $Revision: 1.90 $ 54 ports, IRQ sharing enabled
ttyS0 at I/O 0x3f8 (irq = 4) is a 16550A
ttyS1 at I/O 0x2f8 (irq = 3) is a 16550A
RAMDISK driver initialized: 16 RAM disks of 8192K size 1024 blocksize
serio: i8042 AUX port at 0x60,0x64 irq 12
serio: i8042 KBD port at 0x60,0x64 irq 1
input: AT Translated Set 2 keyboard on isa0060/serio0
EISA: Probing bus 0 at eisa0
Cannot allocate resource for EISA slot 5
EISA: Detected 0 cards.
NET: Registered protocol family 2
IP: routing cache hash table of 4096 buckets, 32Kbytes
TCP: Hash tables configured (established 32768 bind 65536)
NET: Registered protocol family 8
NET: Registered protocol family 20
ACPI: (supports S0 S1 S4 S5)
RAMDISK: cramfs filesystem found at block 0
RAMDISK: Loading 4216 blocks [1 disk] into ram disk... done.
VFS: Mounted root (cramfs filesystem) readonly.
Freeing unused kernel memory: 204k freed
vesafb: probe of vesafb0 failed with error -6
NET: Registered protocol family 1
Uniform Multi-Platform E-IDE driver Revision: 7.00alpha2
ide: Assuming 33MHz system bus speed for PIO modes; override with idebus=xx
NFORCE: IDE controller at PCI slot 0000:00:09.0
NFORCE: chipset revision 195
NFORCE: not 100% native mode: will probe irqs later
NFORCE: BIOS didn't set cable bits correctly. Enabling workaround.
NFORCE: 0000:00:09.0 (rev c3) UDMA100 controller
    ide0: BM-DMA at 0xb800-0xb807, BIOS settings: hda:DMA, hdb:pio
    ide1: BM-DMA at 0xb808-0xb80f, BIOS settings: hdc:DMA, hdd:pio
hda: WDC WD800BB-00DKA0, ATA DISK drive
hda: IRQ probe failed (0xfffffdfc)
Using anticipatory io scheduler
ide0 at 0x1f0-0x1f7,0x3f6 on irq 14
hda: max request size: 1024KiB
hda: 156301488 sectors (80026 MB) w/2048KiB Cache, CHS=16383/255/63, UDMA(100)
 /dev/ide/host0/bus0/target0/lun0: p1 p2 < p5 p6 p7 >
hdc: SAMSUNG CDRW/DVD SM-352B, ATAPI CD/DVD-ROM drive
ide1 at 0x170-0x177,0x376 on irq 15
kjournald starting.  Commit interval 5 seconds
EXT3-fs: mounted filesystem with ordered data mode.
Adding 1052216k swap on /dev/hda5.  Priority:-1 extents:1
EXT3 FS on hda6, internal journal
Generic RTC Driver v1.07
hdc: ATAPI 52X DVD-ROM CD-R/RW drive, 8192kB Cache, UDMA(33)
Uniform CD-ROM driver Revision: 3.20
input: ImPS/2 Generic Wheel Mouse on isa0060/serio1
Capability LSM initialized
mice: PS/2 mouse device common for all mice
ts: Compaq touchscreen protocol output
device-mapper: 4.1.0-ioctl (2003-12-10) initialised: dm@uk.sistina.com
kjournald starting.  Commit interval 5 seconds
EXT3 FS on hda7, internal journal
EXT3-fs: mounted filesystem with ordered data mode.
forcedeth.c: Reverse Engineered nForce ethernet driver. Version 0.29.
ACPI: PCI interrupt 0000:00:04.0[A] -> GSI 20 (level, high) -> IRQ 185
PCI: Setting latency timer of device 0000:00:04.0 to 64
eth0: forcedeth.c: subsystem: 01043:0c11 bound to 0000:00:04.0
Intel 810 + AC97 Audio, version 1.01, 13:08:13 Aug 16 2005
PCI: Enabling device 0000:00:06.0 (0005 -> 0007)
ACPI: PCI interrupt 0000:00:06.0[A] -> GSI 21 (level, high) -> IRQ 177
PCI: Setting latency timer of device 0000:00:06.0 to 64
i810: NVIDIA nForce Audio found at IO 0xe000 and 0xe100, MEM 0x0000 and 
0x0000,IRQ 177
i810_audio: Audio Controller supports 6 channels.
i810_audio: Defaulting to base 2 channel mode.
i810_audio: Resetting connection 0
ac97_codec: AC97 Audio codec, id: ALG32 (ALC650)
i810_audio: AC'97 codec 0, new EID value = 0x05c7
i810_audio: AC'97 codec 0, DAC map configured, total channels = 6
Linux agpgart interface v0.100 (c) Dave Jones
agpgart: Detected NVIDIA nForce chipset
agpgart: Maximum main memory to use for agp memory: 409M
agpgart: AGP aperture is 64M @ 0xf8000000
usbcore: registered new driver usbfs
usbcore: registered new driver hub
ohci_hcd: 2004 Feb 02 USB 1.1 'Open' Host Controller (OHCI) Driver (PCI)
ohci_hcd: block sizes: ed 64 td 64
ACPI: PCI interrupt 0000:00:02.0[A] -> GSI 21 (level, high) -> IRQ 177
ohci_hcd 0000:00:02.0: nVidia Corporation nForce USB Controller
PCI: Setting latency timer of device 0000:00:02.0 to 64
ohci_hcd 0000:00:02.0: irq 177, pci mem de87e000
ohci_hcd 0000:00:02.0: new USB bus registered, assigned bus number 1
hub 1-0:1.0: USB hub found
hub 1-0:1.0: 3 ports detected
ACPI: PCI interrupt 0000:00:03.0[A] -> GSI 21 (level, high) -> IRQ 177
ohci_hcd 0000:00:03.0: nVidia Corporation nForce USB Controller (#2)
PCI: Setting latency timer of device 0000:00:03.0 to 64
ohci_hcd 0000:00:03.0: irq 177, pci mem de948000
ohci_hcd 0000:00:03.0: new USB bus registered, assigned bus number 2
hub 2-0:1.0: USB hub found
hub 2-0:1.0: 3 ports detected
cpci_hotplug: CompactPCI Hot Plug Core version: 0.2
pci_hotplug: PCI Hot Plug PCI Core version: 0.5
pciehp: acpi_pciehprm:\_SB_.PCI0 evaluate _BBN fail=0x5
pciehp: acpi_pciehprm:get_device PCI ROOT HID fail=0x5
shpchp: acpi_shpchprm:\_SB_.PCI0 evaluate _BBN fail=0x5
shpchp: acpi_shpchprm:get_device PCI ROOT HID fail=0x5
pciehp: acpi_pciehprm:\_SB_.PCI0 evaluate _BBN fail=0x5
pciehp: acpi_pciehprm:get_device PCI ROOT HID fail=0x5
shpchp: acpi_shpchprm:\_SB_.PCI0 evaluate _BBN fail=0x5
shpchp: acpi_shpchprm:get_device PCI ROOT HID fail=0x5
parport: PnPBIOS parport detected.
parport0: PC-style at 0x378, irq 7 [PCSPP,TRISTATE,EPP]
inserting floppy driver for 2.6.8-2-386
Floppy drive(s): fd0 is 1.44M
FDC 0 is a post-1991 82077
input: PC Speaker
ip_tables: (C) 2000-2002 Netfilter core team
ip_conntrack version 2.1 (3839 buckets, 30712 max) - 296 bytes per conntrack
lp0: using parport0 (interrupt-driven).
NET: Registered protocol family 10
Disabled Privacy Extensions on device c02cc960(lo)
IPv6 over IPv4 tunneling driver
vmmon: module license 'unspecified' taints kernel.
/dev/vmmon[3256]: Module vmmon: registered with major=10 minor=165
/dev/vmmon[3256]: Module vmmon: initialized
/dev/vmnet: open called by PID 3279 (vmnet-bridge)
/dev/vmnet: hub 0 does not exist, allocating memory.
/dev/vmnet: port on hub 0 successfully opened
bridge-eth0: enabling the bridge
bridge-eth0: up
bridge-eth0: already up
bridge-eth0: attached
DROPPED IN= OUT=eth0 SRC=192.168.1.58 DST=192.168.232.1 LEN=84 TOS=0x00 
PREC=0x00 TTL=64 ID=0 DF PROTO=ICMP TYPE=8 CODE=0 ID=55308 SEQ=0
DROPPED IN= OUT=eth0 SRC=192.168.1.58 DST=192.168.165.1 LEN=84 TOS=0x00 
PREC=0x00 TTL=64 ID=0 DF PROTO=ICMP TYPE=8 CODE=0 ID=54284 SEQ=0
/dev/vmnet: open called by PID 3293 (vmnet-netifup)
/dev/vmnet: hub 1 does not exist, allocating memory.
/dev/vmnet: port on hub 1 successfully opened
/dev/vmnet: open called by PID 3289 (vmnet-netifup)
/dev/vmnet: hub 8 does not exist, allocating memory.
/dev/vmnet: port on hub 8 successfully opened
/dev/vmnet: open called by PID 3344 (vmnet-natd)
/dev/vmnet: port on hub 8 successfully opened
/dev/vmnet: open called by PID 3333 (vmnet-dhcpd)
/dev/vmnet: port on hub 1 successfully opened
/dev/vmnet: open called by PID 3343 (vmnet-dhcpd)
/dev/vmnet: port on hub 8 successfully opened
eth0: no IPv6 routers present
vmnet8: no IPv6 routers present
vmnet1: no IPv6 routers present
NET: Registered protocol family 4
NET: Registered protocol family 3
NET: Registered protocol family 5
ABORTED IN=eth0 OUT= MAC=00:0c:6e:89:0b:f6:00:14:bf:44:04:fd:08:00 
SRC=209.238.245.203 DST=192.168.1.58 LEN=40 TOS=0x00 PREC=0x00 TTL=40 
ID=26912 PROTO=TCP SPT=80 DPT=1095 SEQ=3727287694 ACK=0 WINDOW=0 RES=0x00 RST 
URGP=0
ABORTED IN=eth0 OUT= MAC=00:0c:6e:89:0b:f6:00:14:bf:44:04:fd:08:00 
SRC=212.227.64.170 DST=192.168.1.58 LEN=40 TOS=0x00 PREC=0x00 TTL=42 ID=35364 
DF PROTO=TCP SPT=80 DPT=1059 SEQ=2587004962 ACK=0 WINDOW=0 RES=0x00 RST 
URGP=0
ABORTED IN=eth0 OUT= MAC=00:0c:6e:89:0b:f6:00:14:bf:44:04:fd:08:00 
SRC=66.240.252.32 DST=192.168.1.58 LEN=40 TOS=0x00 PREC=0x00 TTL=44 ID=2262 
DF PROTO=TCP SPT=80 DPT=1109 SEQ=282870046 ACK=0 WINDOW=0 RES=0x00 RST URGP=0
DROPPED IN=eth0 OUT= MAC=ff:ff:ff:ff:ff:ff:1e:00:d7:df:15:bf:08:00 SRC=0.0.0.0 
DST=255.255.255.255 LEN=328 TOS=0x00 PREC=0x00 TTL=128 ID=0 PROTO=UDP SPT=68 
DPT=67 LEN=308
DROPPED IN=eth0 OUT= MAC=ff:ff:ff:ff:ff:ff:00:14:bf:44:04:fd:08:00 
SRC=192.168.1.1 DST=255.255.255.255 LEN=576 TOS=0x00 PREC=0x00 TTL=64 ID=0 
PROTO=UDP SPT=67 DPT=68 LEN=556
ABORTED IN=eth0 OUT= MAC=00:0c:6e:89:0b:f6:00:14:bf:44:04:fd:08:00 
SRC=64.130.15.248 DST=192.168.1.58 LEN=40 TOS=0x00 PREC=0x00 TTL=45 ID=32753 
PROTO=TCP SPT=80 DPT=1927 SEQ=601133326 ACK=0 WINDOW=0 RES=0x00 RST URGP=0
DROPPED IN=eth0 OUT= MAC=ff:ff:ff:ff:ff:ff:00:d0:09:e2:e6:59:08:00 SRC=0.0.0.0 
DST=255.255.255.255 LEN=328 TOS=0x00 PREC=0x00 TTL=128 ID=0 PROTO=UDP SPT=68 
DPT=67 LEN=308
DROPPED IN=eth0 OUT= MAC=ff:ff:ff:ff:ff:ff:00:14:bf:44:04:fd:08:00 
SRC=192.168.1.1 DST=255.255.255.255 LEN=576 TOS=0x00 PREC=0x00 TTL=64 ID=0 
PROTO=UDP SPT=67 DPT=68 LEN=556
DROPPED IN=eth0 OUT= MAC=ff:ff:ff:ff:ff:ff:00:d0:09:e2:e6:59:08:00 SRC=0.0.0.0 
DST=255.255.255.255 LEN=328 TOS=0x00 PREC=0x00 TTL=128 ID=256 PROTO=UDP 
SPT=68 DPT=67 LEN=308
DROPPED IN=eth0 OUT= MAC=ff:ff:ff:ff:ff:ff:00:14:bf:44:04:fd:08:00 
SRC=192.168.1.1 DST=255.255.255.255 LEN=576 TOS=0x00 PREC=0x00 TTL=64 ID=0 
PROTO=UDP SPT=67 DPT=68 LEN=556
DROPPED IN=eth0 OUT= MAC=ff:ff:ff:ff:ff:ff:00:00:e8:57:98:b3:08:00 SRC=0.0.0.0 
DST=255.255.255.255 LEN=328 TOS=0x00 PREC=0x00 TTL=128 ID=0 PROTO=UDP SPT=68 
DPT=67 LEN=308
DROPPED IN=eth0 OUT= MAC=ff:ff:ff:ff:ff:ff:00:14:bf:44:04:fd:08:00 
SRC=192.168.1.1 DST=255.255.255.255 LEN=576 TOS=0x00 PREC=0x00 TTL=64 ID=0 
PROTO=UDP SPT=67 DPT=68 LEN=556
DROPPED IN=eth0 OUT= MAC=ff:ff:ff:ff:ff:ff:00:00:e8:57:98:b3:08:00 SRC=0.0.0.0 
DST=255.255.255.255 LEN=330 TOS=0x00 PREC=0x00 TTL=128 ID=256 PROTO=UDP 
SPT=68 DPT=67 LEN=310
DROPPED IN=eth0 OUT= MAC=ff:ff:ff:ff:ff:ff:00:14:bf:44:04:fd:08:00 
SRC=192.168.1.1 DST=255.255.255.255 LEN=576 TOS=0x00 PREC=0x00 TTL=64 ID=0 
PROTO=UDP SPT=67 DPT=68 LEN=556
DROPPED IN=eth0 OUT= MAC=ff:ff:ff:ff:ff:ff:00:0b:6a:d5:10:cd:08:00 SRC=0.0.0.0 
DST=255.255.255.255 LEN=328 TOS=0x00 PREC=0x00 TTL=128 ID=256 PROTO=UDP 
SPT=68 DPT=67 LEN=308
DROPPED IN=eth0 OUT= MAC=ff:ff:ff:ff:ff:ff:00:14:bf:44:04:fd:08:00 
SRC=192.168.1.1 DST=255.255.255.255 LEN=576 TOS=0x00 PREC=0x00 TTL=64 ID=0 
PROTO=UDP SPT=67 DPT=68 LEN=556
DROPPED IN=eth0 OUT= MAC=ff:ff:ff:ff:ff:ff:00:0b:6a:d5:10:cd:08:00 SRC=0.0.0.0 
DST=255.255.255.255 LEN=336 TOS=0x00 PREC=0x00 TTL=128 ID=512 PROTO=UDP 
SPT=68 DPT=67 LEN=316
DROPPED IN=eth0 OUT= MAC=ff:ff:ff:ff:ff:ff:00:14:bf:44:04:fd:08:00 
SRC=192.168.1.1 DST=255.255.255.255 LEN=576 TOS=0x00 PREC=0x00 TTL=64 ID=0 
PROTO=UDP SPT=67 DPT=68 LEN=556
Inbound IN=eth0 OUT= MAC=00:0c:6e:89:0b:f6:00:14:bf:44:04:fd:08:00 
SRC=87.6.165.209 DST=192.168.1.58 LEN=60 TOS=0x00 PREC=0x00 TTL=42 ID=51217 
DF PROTO=TCP SPT=46595 DPT=443 WINDOW=5840 RES=0x00 SYN URGP=0
Inbound IN=eth0 OUT= MAC=00:0c:6e:89:0b:f6:00:14:bf:44:04:fd:08:00 
SRC=87.6.165.209 DST=192.168.1.58 LEN=60 TOS=0x00 PREC=0x00 TTL=42 ID=51218 
DF PROTO=TCP SPT=46595 DPT=443 WINDOW=5840 RES=0x00 SYN URGP=0
Inbound IN=eth0 OUT= MAC=00:0c:6e:89:0b:f6:00:14:bf:44:04:fd:08:00 
SRC=87.6.165.209 DST=192.168.1.58 LEN=60 TOS=0x00 PREC=0x00 TTL=42 ID=51219 
DF PROTO=TCP SPT=46595 DPT=443 WINDOW=5840 RES=0x00 SYN URGP=0
Inbound IN=eth0 OUT= MAC=00:0c:6e:89:0b:f6:00:14:bf:44:04:fd:08:00 
SRC=4.79.142.206 DST=192.168.1.58 LEN=40 TOS=0x00 PREC=0x00 TTL=109 ID=32768 
PROTO=TCP SPT=36298 DPT=443 WINDOW=8192 RES=0x00 SYN URGP=0
Inbound IN=eth0 OUT= MAC=00:0c:6e:89:0b:f6:00:14:bf:44:04:fd:08:00 
SRC=4.79.142.206 DST=192.168.1.58 LEN=40 TOS=0x00 PREC=0x00 TTL=109 ID=32768 
PROTO=TCP SPT=36298 DPT=443 WINDOW=8192 RES=0x00 SYN URGP=0
Inbound IN=eth0 OUT= MAC=00:0c:6e:89:0b:f6:00:14:bf:44:04:fd:08:00 
SRC=4.79.142.206 DST=192.168.1.58 LEN=40 TOS=0x00 PREC=0x00 TTL=109 ID=32768 
PROTO=TCP SPT=36298 DPT=443 WINDOW=8192 RES=0x00 SYN URGP=0
Inbound IN=eth0 OUT= MAC=00:0c:6e:89:0b:f6:00:14:bf:44:04:fd:08:00 
SRC=4.79.142.206 DST=192.168.1.58 LEN=40 TOS=0x00 PREC=0x00 TTL=109 ID=32768 
PROTO=TCP SPT=36298 DPT=443 WINDOW=8192 RES=0x00 SYN URGP=0
Inbound IN=eth0 OUT= MAC=00:0c:6e:89:0b:f6:00:14:bf:44:04:fd:08:00 
SRC=4.79.142.206 DST=192.168.1.58 LEN=40 TOS=0x00 PREC=0x00 TTL=109 ID=32768 
PROTO=TCP SPT=36393 DPT=443 WINDOW=8192 RES=0x00 SYN URGP=0
Inbound IN=eth0 OUT= MAC=00:0c:6e:89:0b:f6:00:14:bf:44:04:fd:08:00 
SRC=4.79.142.206 DST=192.168.1.58 LEN=40 TOS=0x00 PREC=0x00 TTL=109 ID=32768 
PROTO=TCP SPT=36393 DPT=443 WINDOW=8192 RES=0x00 SYN URGP=0
Inbound IN=eth0 OUT= MAC=00:0c:6e:89:0b:f6:00:14:bf:44:04:fd:08:00 
SRC=4.79.142.206 DST=192.168.1.58 LEN=40 TOS=0x00 PREC=0x00 TTL=109 ID=32768 
PROTO=TCP SPT=36393 DPT=443 WINDOW=8192 RES=0x00 SYN URGP=0
Inbound IN=eth0 OUT= MAC=00:0c:6e:89:0b:f6:00:14:bf:44:04:fd:08:00 
SRC=4.79.142.206 DST=192.168.1.58 LEN=40 TOS=0x00 PREC=0x00 TTL=109 ID=32768 
PROTO=TCP SPT=36393 DPT=443 WINDOW=8192 RES=0x00 SYN URGP=0

---------------------------------------------------------------------------------------------------------------------------------------

Gracias por cualquier ayuda

Ricardo



Reply to: