help on security logs

Dec 20, 2005 3 Replies

At my place of business, we have received these logs, which are somewhat confusing to us. Could anyone spread some light on these messages, like where an attack like this would be coming from? thanks



Device



NameInterfaceTimestampFacility[-Sub-facility]SeverityMnemonicDescriptionDetails



1.6509-1172.18.0.2Dec 16 2005 07:32:00SEC6IPACCESSLOGPlist net-equip-out denied tcp 217.81.250.217(1245) ->
0.0.0.0(23), 2 packets*
2.6509-1172.18.0.2Dec 16 2005 07:26:13SEC6IPACCESSLOGPlist net-equip-out denied tcp 217.81.250.217(1245) ->
0.0.0.0(23), 1 packet*

3.6509-1172.18.0.2Dec 16 2005 07:11:01SEC6IPACCESSLOGPlist net-equip-out denied tcp 201.3.147.64(2377) -> 0.0.0.0(23),
2 packets*
4.6509-1172.18.0.2Dec 16 2005 07:05:05SEC6IPACCESSLOGPlist net-equip-out denied tcp 201.3.147.64(2377) -> 0.0.0.0(23),
1 packet*

5.6509-2172.18.0.3Dec 16 2005 07:02:36SEC6IPACCESSLOGPlist net-equip-out denied tcp 84.100.208.139(1828) ->
0.0.0.0(23), 2 packets*
6.6509-1172.18.0.2Dec 16 2005 06:58:01SEC6IPACCESSLOGPlist net-equip-out denied tcp 61.223.230.121(4105) ->
0.0.0.0(23), 2 packets*

7.6509-2172.18.0.3Dec 16 2005 06:57:25SEC6IPACCESSLOGPlist net-equip-out denied tcp 84.100.208.139(1828) ->
0.0.0.0(23), 1 packet*
8.6509-1172.18.0.2Dec 16 2005 06:52:39SEC6IPACCESSLOGPlist net-equip-out denied tcp 61.223.230.121(4105) ->
0.0.0.0(23), 1 packet*

9.6509-1172.18.0.2Dec 16 2005 06:45:01SEC6IPACCESSLOGPlist net-equip-out denied tcp 62.183.157.7(1781) -> 0.0.0.0(23),
2 packets*
10.6509-1172.18.0.2Dec 16 2005 06:39:22SEC6IPACCESSLOGPlist

net-equip-out denied tcp 62.183.157.7(1781) -> 0.0.0.0(23),



1 packet*
11.6509-1172.18.0.2Dec 16 2005 06:39:22SEC6IPACCESSLOGPlist

net-equip-out denied tcp 84.103.225.112(4661) ->



0.0.0.0(23), 1 packet*
12.6509-2172.18.0.3Dec 16 2005 06:32:37SEC6IPACCESSLOGPlist

net-equip-out denied tcp 82.172.127.123(3253) ->



0.0.0.0(23), 2 packets*
13.6509-2172.18.0.3Dec 16 2005 06:31:37SEC6IPACCESSLOGPlist

net-equip-out denied tcp 200.181.113.209(2221) ->



0.0.0.0(23), 2 packets*
14.6509-2172.18.0.3Dec 16 2005 06:26:44SEC6IPACCESSLOGPlist

net-equip-out denied tcp 82.172.127.123(3253) ->



0.0.0.0(23), 1 packet*
15.6509-2172.18.0.3Dec 16 2005 06:26:44SEC6IPACCESSLOGPlist

net-equip-out denied tcp 61.216.0.47(4769) -> 0.0.0.0(23),



2 packets*
16.6509-2172.18.0.3Dec 16 2005 06:26:03SEC6IPACCESSLOGPlist

net-equip-out denied tcp 200.181.113.209(2221) ->



0.0.0.0(23), 1 packet*
17.6509-1172.18.0.2Dec 16 2005 06:25:01SEC6IPACCESSLOGPlist

net-equip-out denied tcp 82.76.88.114(4113) -> 0.0.0.0(23),



2 packets*
18.6509-2172.18.0.3Dec 16 2005 06:21:28SEC6IPACCESSLOGPlist

net-equip-out denied tcp 61.216.0.47(4769) -> 0.0.0.0(23),



1 packet*
19.6509-1172.18.0.2Dec 16 2005 06:20:24SEC6IPACCESSLOGPlist

net-equip-out denied tcp 82.76.88.114(4113) -> 0.0.0.0(23),



1 packet*
20.6509-1172.18.0.2Dec 16 2005 06:17:01SEC6IPACCESSLOGPlist

net-equip-out denied tcp 83.100.150.149(2814) ->



0.0.0.0(23), 2 packets*
21.6509-1172.18.0.2Dec 16 2005 06:14:01SEC6IPACCESSLOGPlist

net-equip-out denied tcp 213.73.185.91(4617) ->



0.0.0.0(23), 2 packets*
22.6509-2172.18.0.3Dec 16 2005 06:11:37SEC6IPACCESSLOGPlist

net-equip-out denied tcp 219.86.166.237(3884) ->



0.0.0.0(23), 2 packets*
23.6509-1172.18.0.2Dec 16 2005 06:11:37SEC6IPACCESSLOGPlist

net-equip-out denied tcp 83.100.150.149(2814) ->



0.0.0.0(23), 1 packet*
24.6509-1172.18.0.2Dec 16 2005 06:08:02SEC6IPACCESSLOGPlist

net-equip-out denied tcp 213.73.185.91(4617) ->



0.0.0.0(23), 1 packet*
25.6509-2172.18.0.3Dec 16 2005 06:06:24SEC6IPACCESSLOGPlist

net-equip-out denied tcp 219.86.166.237(3884) ->



0.0.0.0(23), 1 packet*
26.6509-2172.18.0.3Dec 15 2005 19:24:45SEC6IPACCESSLOGPlist

net-equip-out denied tcp 200.162.211.32(3979) ->



0.0.0.0(23), 2 packets*
27.6509-2172.18.0.3Dec 15 2005 19:19:00SEC6IPACCESSLOGPlist

net-equip-out denied tcp 200.162.211.32(3979) ->



0.0.0.0(23), 1 packet*
28.6509-1172.18.0.2Dec 15 2005 18:42:11SEC6IPACCESSLOGPlist

net-equip-out denied tcp 200.117.234.113(46330) ->



0.0.0.0(23), 2 packets*
29.6509-2172.18.0.3Dec 15 2005 18:37:46SEC6IPACCESSLOGPlist

net-equip-out denied tcp 201.24.15.92(3772) -> 0.0.0.0(23),



2 packets*
30.6509-1172.18.0.2Dec 15 2005 18:36:45SEC6IPACCESSLOGPlist

net-equip-out denied tcp 200.117.234.113(46330) ->



0.0.0.0(23), 1 packet*
31.6509-2172.18.0.3Dec 15 2005 18:32:32SEC6IPACCESSLOGPlist

net-equip-out denied tcp 201.24.15.92(3772) -> 0.0.0.0(23),



1 packet*
32.6509-1172.18.0.2Dec 15 2005 18:16:12SEC6IPACCESSLOGPlist

net-equip-out denied tcp 61.216.101.159(4481) ->



0.0.0.0(23), 2 packets*
33.6509-1172.18.0.2Dec 15 2005 18:11:14SEC6IPACCESSLOGPlist

net-equip-out denied tcp 61.216.101.159(4481) ->



0.0.0.0(23), 1 packet*
34.6509-2172.18.0.3Dec 15 2005 17:50:47SEC6IPACCESSLOGPlist

net-equip-out denied tcp 200.147.49.160(4481) ->



0.0.0.0(23), 2 packets*
35.6509-2172.18.0.3Dec 15 2005 17:45:35SEC6IPACCESSLOGPlist

net-equip-out denied tcp 200.147.49.160(4481) ->



0.0.0.0(23), 1 packet*
36.6509-2172.18.0.3Dec 15 2005 17:17:47SEC6IPACCESSLOGPlist

net-equip-out denied tcp 213.47.105.217(4072) ->



0.0.0.0(23), 2 packets*
37.6509-2172.18.0.3Dec 15 2005 17:12:28SEC6IPACCESSLOGPlist

net-equip-out denied tcp 213.47.105.217(4072) ->



0.0.0.0(23), 1 packet*
38.6509-1172.18.0.2Dec 15 2005 16:19:13SEC6IPACCESSLOGPlist

net-equip-out denied tcp 148.244.130.96(1802) ->



0.0.0.0(23), 2 packets*
39.6509-1172.18.0.2Dec 15 2005 16:13:28SEC6IPACCESSLOGPlist

net-equip-out denied tcp 148.244.130.96(1802) ->



0.0.0.0(23), 1 packet*
40.6509-1172.18.0.2Dec 15 2005 16:02:14SEC6IPACCESSLOGPlist

net-equip-out denied tcp 200.162.232.58(2443) ->



0.0.0.0(23), 2 packets*
41.6509-1172.18.0.2Dec 15 2005 15:56:32SEC6IPACCESSLOGPlist

net-equip-out denied tcp 200.162.232.58(2443) ->



0.0.0.0(23), 1 packet*
42.6509-1172.18.0.2Dec 15 2005 15:44:24SEC6IPACCESSLOGPlist

net-equip-out denied tcp 62.175.169.8(1768) -> 0.0.0.0(23),



1 packet*
43.6509-2172.18.0.3Dec 15 2005 15:43:48SEC6IPACCESSLOGPlist

net-equip-out denied tcp 200.180.146.123(2196) ->



0.0.0.0(23), 2 packets*
44.6509-2172.18.0.3Dec 15 2005 15:38:35SEC6IPACCESSLOGPlist

net-equip-out denied tcp 200.180.146.123(2196) ->



0.0.0.0(23), 1 packet*
45.6509-1172.18.0.2Dec 15 2005 15:21:14SEC6IPACCESSLOGPlist

net-equip-out denied tcp 200.63.12.194(3469) ->



0.0.0.0(23), 1 packet*
46.6509-1172.18.0.2Dec 15 2005 15:15:36SEC6IPACCESSLOGPlist

net-equip-out denied tcp 200.63.12.194(3469) ->



0.0.0.0(23), 1 packet*
47.6509-2172.18.0.3Dec 15 2005 15:06:59SEC6IPACCESSLOGPlist

net-equip-out denied tcp 83.144.133.87(4093) ->



0.0.0.0(23), 2 packets*
48.6509-2172.18.0.3Dec 15 2005 15:02:34SEC6IPACCESSLOGPlist

net-equip-out denied tcp 83.144.133.87(4093) ->



0.0.0.0(23), 1 packet*

They are coming from everywhere. Here is one IP info. You can look up the rest the same way...

formatting link
They are all Telnet requests (port 23). Probably routine automated hacker attempts. Your firewall is doing its job.

-Frank

Unfortunately the original poster multi-posted instead of cross-posting. I responded with an analysis in the comp.dcom.sys.cisco edition of the message.

Frank, I would suspect your conclusion is not correct.

Notice that the reporting IP is 172.18.0.2 which is a private IP, and that the acl name is "net-equip-out". That suggests that the packets are (apparently) originating "inside" a LAN, that the LAN interface on the 6509 has an access list named "net-equip-out" applied to it, and that that ACL is filtering out packets that do not originate with one of the known-good internal IP address ranges; and that only packets which pass the basic security filters are submitted for NAT to go to the Internet.

It would not be impossible for 172.18.0.2 to be the "outside" IP of a 6509 when there was another non-filtering WAN router further out, but it is unlikely that any ACL applied to such an interface would be named as whatever-"out" -- people tend to name ACLs using "in" and "out" as directions of motion, and to use "inside" and "outside" when they wish to designated the logical location of an ACL.

Occam's Razor suggests these log entries are rogue packets being blocked from going out, not a "firewall doing its job" of preventing outside systems from telneting inwards.

Yeah, all your suppositions could be right. I considered that too. But I was not as sure of the suppositions. My mind didn't translate the entry "1172.18.0.2" into 172.18.0.2. But, in hindsight, I believe you are right.

-Frank

Join the Discussion

Have something to add? Share your thoughts — no account required.

Didn't find your answer?

Ask the community — no account required