Butterfly Bones
Very Senior Member
Oops, I missed the second one. I never mind helping someone help me! Thank you!All looks fine, very strange as by IPTables logic this should have been DROP'ed at the second rule as the source port matched the defined list, but maybe I'm missing something obvious here. So I'll spend tomorrow looking at possible causes/solutions.
Would you mind also running the second command I posted so I can see if this is happening frequently on your setup on ports that it shouldn't.
Code:
Debug Data Detected in /tmp/mnt/SNB/skynet/skynet.log - 972.0K
Monitoring From Dec 15 04:00:56 To Dec 16 13:23:23
3360 Block Events Detected
901 Unique IPs
242 Autobans Issued
3 Manual Bans Issued
First Autoban Issued On Oct 3 21:04:52
Last Autoban Issued On Dec 16 10:57:34
First Autoban Issued;
Oct 3 21:04:52 kernel: [BLOCKED - NEW BAN] IN=eth0 OUT= MAC=70:8b:cd:2f:b0:88:00:01:5c:6d:22:46:08:00 SRC=164.132.120.90 DST=75.128.66.165 LEN=40 TOS=0x00 PREC=0x00 TTL=52 ID=0 DF PROTO=TCP SPT=6008 DPT=28971 SEQ=2057568776 ACK=2684092417 WINDOW=17520 RES=0x00 ACK SYN URGP=0
10 Most Recent Autobans;
Dec 9 07:53:12 kernel: [BLOCKED - NEW BAN] IN=eth0 OUT= MAC=70:8b:cd:2f:b0:88:00:01:5c:6d:22:46:08:00 SRC=147.135.225.24 DST=75.128.66.165 LEN=40 TOS=0x00 PREC=0x00 TTL=51 ID=0 DF PROTO=TCP SPT=25565 DPT=40264 SEQ=1481334739 ACK=135019169 WINDOW=17520 RES=0x00 ACK SYN URGP=0
Dec 10 06:11:42 kernel: [BLOCKED - NEW BAN] IN=eth0 OUT= MAC=70:8b:cd:2f:b0:88:00:01:5c:6d:22:46:08:00 SRC=109.227.71.234 DST=75.128.66.165 LEN=44 TOS=0x00 PREC=0x00 TTL=46 ID=31778 PROTO=TCP SPT=3601 DPT=23 SEQ=1266696869 ACK=0 WINDOW=59332 RES=0x00 SYN URGP=0 OPT (020405A0)
Dec 10 20:41:44 kernel: [BLOCKED - NEW BAN] IN=eth0 OUT= MAC=70:8b:cd:2f:b0:88:00:01:5c:6d:22:46:08:00 SRC=104.99.238.162 DST=75.128.66.165 LEN=1500 TOS=0x00 PREC=0x00 TTL=56 ID=44553 DF PROTO=TCP SPT=49320 DPT=257 SEQ=3587440720 ACK=2628519796 WINDOW=33043 RES=0x1c CWR ECE URG SYN URGP=237 OPT (D22800000101080A17B446C9)
Dec 11 08:16:03 kernel: [BLOCKED - NEW BAN] IN=eth0 OUT= MAC=70:8b:cd:2f:b0:88:00:01:5c:6d:22:46:08:00 SRC=144.217.15.39 DST=75.128.66.165 LEN=40 TOS=0x00 PREC=0x00 TTL=51 ID=0 DF PROTO=TCP SPT=5000 DPT=39987 SEQ=1810950507 ACK=1281425409 WINDOW=17520 RES=0x00 ACK SYN URGP=0
Dec 12 14:24:55 kernel: [BLOCKED - NEW BAN] IN=eth0 OUT= MAC=70:8b:cd:2f:b0:88:00:01:5c:6d:22:46:08:00 SRC=91.134.188.54 DST=75.128.66.165 LEN=40 TOS=0x00 PREC=0x00 TTL=52 ID=0 DF PROTO=TCP SPT=1370 DPT=3676 SEQ=4043036481 ACK=975503361 WINDOW=17520 RES=0x00 ACK SYN URGP=0
Dec 13 08:38:52 kernel: [BLOCKED - NEW BAN] IN=eth0 OUT= MAC=70:8b:cd:2f:b0:88:00:01:5c:6d:22:46:08:00 SRC=171.244.21.53 DST=75.128.66.165 LEN=40 TOS=0x00 PREC=0x00 TTL=46 ID=0 DF PROTO=TCP SPT=1993 DPT=32065 SEQ=4022603132 ACK=2781347841 WINDOW=0 RES=0x00 ACK SYN URGP=0
Dec 13 19:50:18 kernel: [BLOCKED - NEW BAN] IN=eth0 OUT= MAC=70:8b:cd:2f:b0:88:00:01:5c:6d:22:46:08:00 SRC=192.95.54.21 DST=75.128.66.165 LEN=40 TOS=0x00 PREC=0x00 TTL=51 ID=0 DF PROTO=TCP SPT=25565 DPT=51647 SEQ=5105455 ACK=1518353892 WINDOW=17520 RES=0x00 ACK SYN URGP=0
Dec 14 09:44:09 kernel: [BLOCKED - NEW BAN] IN=eth0 OUT= MAC=70:8b:cd:2f:b0:88:00:01:5c:6d:22:46:08:00 SRC=121.52.205.133 DST=75.128.66.165 LEN=40 TOS=0x00 PREC=0x00 TTL=240 ID=59109 PROTO=TCP SPT=27780 DPT=60389 SEQ=689103479 ACK=688678535 WINDOW=65535 RES=0x00 ACK SYN URGP=0
Dec 15 19:28:22 kernel: [BLOCKED - NEW BAN] IN=eth0 OUT= MAC=70:8b:cd:2f:b0:88:00:01:5c:6d:22:46:08:00 SRC=137.74.4.208 DST=75.128.66.165 LEN=40 TOS=0x00 PREC=0x00 TTL=53 ID=0 DF PROTO=TCP SPT=7777 DPT=54316 SEQ=2420734347 ACK=3122921473 WINDOW=17520 RES=0x00 ACK SYN URGP=0
Dec 16 10:57:34 kernel: [BLOCKED - NEW BAN] IN=eth0 OUT= MAC=70:8b:cd:2f:b0:88:00:01:5c:6d:22:46:08:00 SRC=173.194.166.231 DST=75.128.66.165 LEN=1472 TOS=0x00 PREC=0x00 TTL=56 ID=13745 PROTO=TCP SPT=443 DPT=37566 SEQ=2645267603 ACK=3434604900 WINDOW=123 RES=0x00 ACK URGP=0 OPT (0101080AB5A63D3C6A72EE17)
Skynet: [Complete] 157419 IPs / 2000 Ranges Banned. 0 New IPs / 0 New Ranges Banned. 2387 Inbound / 112 Outbound Connections Blocked! [2s]