What's new

New info in system log. Does anyone know what it might be?

  • SNBForums Code of Conduct

    SNBForums is a community for everyone, no matter what their level of experience.

    Please be tolerant and patient of others, especially newcomers. We are all here to share and learn!

    The rules are simple: Be patient, be nice, be helpful or be gone!

DAVID LONG

Regular Contributor
Jan 2 13:00:14 kernel: [BLOCKED - INBOUND] IN=eth0 OUT= MAC=0c:9d:92:45:99:b0:70:01:b5:cd:2c:19:08:00 SRC=94.232.46.216 DST=35.***.***.*** LEN=40 TOS=0x00 PREC=0x00 TTL=239 ID=12652 PROTO=TCP SPT=55488 DPT=28939 SEQ=724863677 ACK=0 WINDOW=1024 RES=0x00 SYN URGP=0 MARK=0x8000000

Never seen this in the log before, but it is in there constantly, now. Flooding the log.


AC86U

Merlin 386.1 Alpha

Thanks in advance.
 
Last edited:
It's a bot scanning for open ports.

SPDmitriy Panchenko
Usage TypeData Center/Web Hosting/Transit
Domain Nameitservicecom.ru
Country
blank.gif
Poland
CityWarsaw, Mazowieckie


David, edit your post to remove your IP address 35.136.xxx.xxx
 
Ok, done and thanks.

Any idea why they just started?

Will they stop?
 
Unlikely that it just started, it's been going on for year ... decades even.

If you just updated the router software / added skynet, you're just seeing it now. Before it wouldn't have been registered, but it always happened.
 
Been running Skynet for several years. Firmware was updated in November. Only thing I can think of is the level of reporting has changed in the log.

Is there a setting that will make it go away without restricting good or need to know reporting?

Right now it's info/debug
 

Similar threads

Latest threads

Support SNBForums w/ Amazon

If you'd like to support SNBForums, just use this link and buy anything on Amazon. Thanks!

Sign Up For SNBForums Daily Digest

Get an update of what's new every day delivered to your mailbox. Sign up here!
Top