<?xml version="1.0" encoding="utf-8"?><rss xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" version="2.0"><channel><ttl>60</ttl><title>John Dodrill's BLOG</title><link>http://johndodrill.info</link><lastBuildDate>Thu, 23 Feb 2012 11:17:17 GMT</lastBuildDate><pubDate>Thu, 23 Feb 2012 11:17:17 GMT</pubDate><language>en</language><copyright /><itunes:subtitle></itunes:subtitle><itunes:author /><itunes:summary /><description /><itunes:owner><itunes:name /><itunes:email>blog@john.dodrill.name</itunes:email></itunes:owner><itunes:explicit>no</itunes:explicit><itunes:category text="Arts" /><item><title>Disabling The Wireless Link on Cisco 860/880 Access Point</title><link>http://johndodrill.info/2012/02/22/alert-8118240138-penetrating-firewalls.aspx?ref=rss</link><dc:creator>John Dodrill</dc:creator><description>&lt;FONT style="FONT-SIZE: 14px" face=arial&gt;&lt;FONT style="FONT-SIZE: 14px"&gt;&lt;/FONT&gt;&lt;FONT style="FONT-SIZE: 14px"&gt;&lt;/FONT&gt;&lt;FONT style="FONT-SIZE: 14px"&gt;&lt;/FONT&gt;&lt;FONT style="FONT-SIZE: 14px"&gt;&lt;/FONT&gt;&lt;IMG style="BORDER-BOTTOM: 0px solid; BORDER-LEFT: 0px solid; BORDER-TOP: 0px solid; BORDER-RIGHT: 0px solid" alt="" src="http://images.quickblogcast.com/0/1/4/2/9/203072-192410/Cisco860880.gif?a=41"&gt;&lt;BR&gt;&lt;BR&gt;router# &lt;FONT color=#366092&gt;service-module wlan-ap 0 session&lt;BR&gt;&lt;/FONT&gt;Trying XXX.XXX.XXX.XXX 2002...Open&lt;BR&gt;&lt;FONT color=#366092&gt;&amp;lt;another carraige return&amp;gt;&lt;BR&gt;&lt;/FONT&gt;username: &lt;FONT color=#366092&gt;&amp;lt;username&amp;gt;&lt;BR&gt;&lt;/FONT&gt;Password: &lt;FONT color=#366092&gt;&amp;lt;password&amp;gt;&lt;BR&gt;&lt;/FONT&gt;ap# &lt;FONT color=#366092&gt;config terminal&lt;BR&gt;&lt;/FONT&gt;ap (config)# &lt;FONT color=#366092&gt;interface bvi1&lt;BR&gt;&lt;/FONT&gt;ap (config-if)# &lt;FONT color=#366092&gt;shutdown&lt;BR&gt;&lt;/FONT&gt;ap (config-if)# &lt;FONT color=#366092&gt;end&lt;BR&gt;&lt;/FONT&gt;ap# &lt;FONT color=#4f81bd&gt;&lt;FONT color=#366092&gt;logout&lt;BR&gt;&lt;/FONT&gt;&lt;BR&gt;&lt;/FONT&gt;&lt;BR&gt;&lt;BR&gt;Some techs, like myself, are using the Cisco 860 880 Wireless access point as a proving grounds for Cisco IOS, owing to it's sub $1,000 price tag.&lt;BR&gt;&lt;BR&gt;I personally tend to forget that there is are separate rules for the BVI 1 and Gigabitethernet 0 interfaces than there are for the WAN interface Fastethernet 4.&amp;nbsp; As a result, a hacker was apparently able to access the router, possibly using &lt;A href="http://www.kismetwireless.net/download.shtml" target=_blank&gt;Kismet&lt;/A&gt;, wireless &lt;A href="http://www.cacetech.com/downloads.html" target=_blank&gt;PCAP&lt;/A&gt;,&amp;nbsp;&lt;A href="http://sourceforge.net/projects/aircrack-ngwind/files/latest/download" target=_blank&gt;Aircrack&lt;/A&gt; or such similar software.&amp;nbsp; (These are popular amongst the newly and tragically certified.)&amp;nbsp; &lt;BR&gt;&lt;BR&gt;The erroneous assumption that I made was that the hacker was coming in through the Internet, had used loose source routing to tunnel through two other consumer routers (that's how ineffective they are), and was attempting access to some of the inner most firewalls.&amp;nbsp; &lt;BR&gt;&lt;BR&gt;That was a fairly egregious assumption, but it was based on a statement made by Cisco that "&lt;A href="http://www.cisco.com/en/US/docs/routers/access/800/860-880-890/software/configuration/guide/radio_config.html#wp1052852" target=_blank&gt;the wireless device radios are disabled by default&lt;/A&gt;".&amp;nbsp;&amp;nbsp;&lt;BR&gt;&amp;nbsp;&lt;BR&gt;Nonetheless, the access point (ap) was accessed, the running configuration replaced with the default configuration, and that appears to be the source of the below attack, instead of the attack originating over the Internet.&amp;nbsp; if that's true, this hacker is a no-talent, all-software kind of hacker who was already behind the firewall, owing to an oversight on my part.&lt;BR&gt;&lt;BR&gt;One hacker says that it is possible to log into the access point, via the Internet, using a service account.&amp;nbsp; That sounds reasonable, since service accounts&amp;nbsp;are included in Cisco&amp;nbsp;Access Control Lists (ACL) but Cisco says "No": essentialy that can't happen.&amp;nbsp; Well, really, what did I expect them to say?&amp;nbsp; I overheard that same hacker saying that "For the most part, all [he does] is VPN into [whatever] device".&amp;nbsp; Sadly, he's right.&amp;nbsp; The firewall barely made note of it, when I tried to access my own network from the WAN side.&lt;BR&gt;&lt;BR&gt;Anyway, I couldn't find anything on the Internet about shutting down the wireless interface, possibly because it was so obvious.&amp;nbsp; It's just when no one mentioned anything about it on the Internet, it seemed to me that perhaps it either wasn't possible or wasn't necessary, in light of Cisco's statement and in light of CP Light which simply indicates that the AP doesn't have an IP and isn't configured.&lt;BR&gt;&lt;BR&gt;As bad as it would be to come to the realization that the "bad guys" are within 1000m of my wireless device, I'm still hoping that this resolves the problem (see firewall reports below).&amp;nbsp; This (and a related problem) actually took about eight hours out of my day.&amp;nbsp; That's eight hours that I didn't really have to spare.&lt;BR&gt;&lt;BR&gt;On a positive note, I have a friend-of-a-friend in the FCC who tracks these people down by profession.&amp;nbsp; He's really quite adept.&amp;nbsp; If I can track this hacker down, I want to be compensated for my lost time and the effect this has had on my career.&amp;nbsp; &lt;BR&gt;&lt;BR&gt;&lt;BR&gt;&lt;IMG style="BORDER-BOTTOM: 0px solid; BORDER-LEFT: 0px solid; BORDER-TOP: 0px solid; BORDER-RIGHT: 0px solid" alt="" src="http://images.quickblogcast.com/0/1/4/2/9/203072-192410/81_18_240_138.png?a=81"&gt;&lt;/FONT&gt;&lt;FONT style="FONT-SIZE: 14px" face=arial&gt;&lt;BR&gt;&lt;BR&gt;Inner firewall (three firewalls deep) reports:&lt;BR&gt;&lt;BR&gt;000051: Feb 22 03:43:01.679 PCTime: %SEC-6-IPACCESSLOGP: list 110 denied tcp YYY.YYY.YYY.YYY(52735) -&amp;gt; 81.18.240.138(80), 1 packet &amp;nbsp;&lt;BR&gt;000052: Feb 22 03:43:32.347 PCTime: %SEC-6-IPACCESSLOGP: list 120 denied tcp 81.18.240.138(80) -&amp;gt; YYY.YYY.YYY.YYY(52735), 1 packet &amp;nbsp;&lt;BR&gt;000053: Feb 22 03:43:40.607 PCTime: %SEC-6-IPACCESSLOGP: list 110 denied tcp YYY.YYY.YYY.YYY(52756) -&amp;gt; 81.18.240.138(80), 1 packet &amp;nbsp;&lt;BR&gt;000054: Feb 22 03:43:57.255 PCTime: %SEC-6-IPACCESSLOGP: list 110 denied tcp YYY.YYY.YYY.YYY(52763) -&amp;gt; 81.18.240.138(80), 1 packet &amp;nbsp;&lt;BR&gt;000055: Feb 22 03:44:11.259 PCTime: %SEC-6-IPACCESSLOGP: list 120 denied tcp 81.18.240.138(80) -&amp;gt; YYY.YYY.YYY.YYY(52756), 1 packet &amp;nbsp;&lt;BR&gt;000056: Feb 22 03:44:18.303 PCTime: %SEC-6-IPACCESSLOGP: list 110 denied tcp YYY.YYY.YYY.YYY(52769) -&amp;gt; 81.18.240.138(80), 1 packet &amp;nbsp;&lt;BR&gt;000057: Feb 22 03:44:27.755 PCTime: %SEC-6-IPACCESSLOGP: list 120 denied tcp 81.18.240.138(80) -&amp;gt; YYY.YYY.YYY.YYY(52763), 1 packet &amp;nbsp;&lt;BR&gt;000058: Feb 22 03:44:48.747 PCTime: %SEC-6-IPACCESSLOGP: list 120 denied tcp 81.18.240.138(80) -&amp;gt; YYY.YYY.YYY.YYY(52769), 1 packet &amp;nbsp;&lt;BR&gt;000059: Feb 22 03:46:03.143 PCTime: %SEC-6-IPACCESSLOGP: list 110 denied tcp YYY.YYY.YYY.YYY(52797) -&amp;gt; 81.18.240.138(80), 1 packet &amp;nbsp;&lt;BR&gt;000060: Feb 22 03:46:33.195 PCTime: %SEC-6-IPACCESSLOGP: list 120 denied tcp 81.18.240.138(80) -&amp;gt; YYY.YYY.YYY.YYY(52797), 1 packet &amp;nbsp;&lt;BR&gt;000061: Feb 22 03:48:09.391 PCTime: %SEC-6-IPACCESSLOGP: list 110 denied tcp YYY.YYY.YYY.YYY(52735) -&amp;gt; 81.18.240.138(80), 3 packets &amp;nbsp;&lt;BR&gt;000062: Feb 22 03:49:09.391 PCTime: %SEC-6-IPACCESSLOGP: list 110 denied tcp YYY.YYY.YYY.YYY(52756) -&amp;gt; 81.18.240.138(80), 3 packets &amp;nbsp;&lt;BR&gt;000063: Feb 22 03:49:09.391 PCTime: %SEC-6-IPACCESSLOGP: list 110 denied tcp YYY.YYY.YYY.YYY(52763) -&amp;gt; 81.18.240.138(80), 3 packets &amp;nbsp;&lt;BR&gt;000064: Feb 22 03:49:12.439 PCTime: %SEC-6-IPACCESSLOGP: list 110 denied tcp YYY.YYY.YYY.YYY(52904) -&amp;gt; 81.18.240.138(80), 1 packet &amp;nbsp;&lt;BR&gt;000065: Feb 22 03:49:42.771 PCTime: %SEC-6-IPACCESSLOGP: list 120 denied tcp 81.18.240.138(80) -&amp;gt; YYY.YYY.YYY.YYY(52904), 1 packet &amp;nbsp;&lt;BR&gt;000066: Feb 22 03:50:09.391 PCTime: %SEC-6-IPACCESSLOGP: list 110 denied tcp YYY.YYY.YYY.YYY(52769) -&amp;gt; 81.18.240.138(80), 3 packets &amp;nbsp;&lt;BR&gt;000067: Feb 22 03:51:09.391 PCTime: %SEC-6-IPACCESSLOGP: list 110 denied tcp YYY.YYY.YYY.YYY(52797) -&amp;gt; 81.18.240.138(80), 3 packets &amp;nbsp;&lt;BR&gt;000068: Feb 22 03:53:29.411 PCTime: %SEC-6-IPACCESSLOGP: list 110 denied tcp YYY.YYY.YYY.YYY(52918) -&amp;gt; 81.18.240.138(80), 1 packet &amp;nbsp;&lt;BR&gt;000069: Feb 22 03:53:59.907 PCTime: %SEC-6-IPACCESSLOGP: list 120 denied tcp 81.18.240.138(80) -&amp;gt; YYY.YYY.YYY.YYY(52918), 1 packet &amp;nbsp;&lt;BR&gt;000070: Feb 22 03:55:09.391 PCTime: %SEC-6-IPACCESSLOGP: list 110 denied tcp YYY.YYY.YYY.YYY(52904) -&amp;gt; 81.18.240.138(80), 3 packets &amp;nbsp;&lt;BR&gt;000071: Feb 22 03:56:18.599 PCTime: %SEC-6-IPACCESSLOGP: list 110 denied tcp YYY.YYY.YYY.YYY(52942) -&amp;gt; 81.18.240.138(80), 1 packet &amp;nbsp;&lt;BR&gt;000072: Feb 22 03:56:38.683 PCTime: %SEC-6-IPACCESSLOGP: list 110 denied tcp YYY.YYY.YYY.YYY(52962) -&amp;gt; 81.18.240.138(80), 1 packet &amp;nbsp;&lt;BR&gt;000073: Feb 22 03:56:49.419 PCTime: %SEC-6-IPACCESSLOGP: list 120 denied tcp 81.18.240.138(80) -&amp;gt; YYY.YYY.YYY.YYY(52942), 1 packet &amp;nbsp;&lt;BR&gt;000074: Feb 22 03:57:09.395 PCTime: %SEC-6-IPACCESSLOGP: list 120 denied tcp 81.18.240.138(80) -&amp;gt; YYY.YYY.YYY.YYY(52962), 1 packet &amp;nbsp;&lt;BR&gt;000075: Feb 22 03:57:20.655 PCTime: %SEC-6-IPACCESSLOGP: list 120 denied tcp 81.18.240.138(80) -&amp;gt; YYY.YYY.YYY.YYY(52981), 1 packet &amp;nbsp;&lt;BR&gt;000076: Feb 22 03:58:59.463 PCTime: %SEC-6-IPACCESSLOGP: list 110 denied tcp YYY.YYY.YYY.YYY(53006) -&amp;gt; 81.18.240.138(80), 1 packet &amp;nbsp;&lt;BR&gt;000077: Feb 22 03:59:09.391 PCTime: %SEC-6-IPACCESSLOGP: list 110 denied tcp YYY.YYY.YYY.YYY(52918) -&amp;gt; 81.18.240.138(80), 3 packets &amp;nbsp;&lt;BR&gt;000078: Feb 22 03:59:30.195 PCTime: %SEC-6-IPACCESSLOGP: list 120 denied tcp 81.18.240.138(80) -&amp;gt; YYY.YYY.YYY.YYY(53006), 1 packet &amp;nbsp;&lt;BR&gt;000079: Feb 22 04:00:43.579 PCTime: %SEC-6-IPACCESSLOGP: list 110 denied tcp YYY.YYY.YYY.YYY(53031) -&amp;gt; 81.18.240.138(80), 1 packet &amp;nbsp;&lt;BR&gt;000080: Feb 22 04:01:14.163 PCTime: %SEC-6-IPACCESSLOGP: list 120 denied tcp 81.18.240.138(80) -&amp;gt; YYY.YYY.YYY.YYY(53031), 1 packet &amp;nbsp;&lt;BR&gt;000081: Feb 22 04:02:09.391 PCTime: %SEC-6-IPACCESSLOGP: list 110 denied tcp YYY.YYY.YYY.YYY(52981) -&amp;gt; 81.18.240.138(80), 4 packets &amp;nbsp;&lt;BR&gt;000082: Feb 22 04:02:09.391 PCTime: %SEC-6-IPACCESSLOGP: list 110 denied tcp YYY.YYY.YYY.YYY(52942) -&amp;gt; 81.18.240.138(80), 3 packets &amp;nbsp;&lt;BR&gt;000083: Feb 22 04:02:09.391 PCTime: %SEC-6-IPACCESSLOGP: list 110 denied tcp YYY.YYY.YYY.YYY(52962) -&amp;gt; 81.18.240.138(80), 3 packets &amp;nbsp;&lt;BR&gt;000084: Feb 22 04:02:16.007 PCTime: %SEC-6-IPACCESSLOGP: list 110 denied tcp YYY.YYY.YYY.YYY(53055) -&amp;gt; 81.18.240.138(80), 1 packet &amp;nbsp;&lt;BR&gt;000085: Feb 22 04:02:42.931 PCTime: %SEC-6-IPACCESSLOGP: list 110 denied tcp YYY.YYY.YYY.YYY(53076) -&amp;gt; 81.18.240.138(80), 1 packet &amp;nbsp;&lt;BR&gt;000086: Feb 22 04:02:46.835 PCTime: %SEC-6-IPACCESSLOGP: list 120 denied tcp 81.18.240.138(80) -&amp;gt; YYY.YYY.YYY.YYY(53055), 1 packet &amp;nbsp;&lt;BR&gt;000087: Feb 22 04:03:13.459 PCTime: %SEC-6-IPACCESSLOGP: list 120 denied tcp 81.18.240.138(80) -&amp;gt; YYY.YYY.YYY.YYY(53076), 1 packet &amp;nbsp;&lt;BR&gt;000088: Feb 22 04:03:26.875 PCTime: %SEC-6-IPACCESSLOGP: list 110 denied tcp YYY.YYY.YYY.YYY(53091) -&amp;gt; 81.18.240.138(80), 1 packet &amp;nbsp;&lt;BR&gt;000089: Feb 22 04:03:57.491 PCTime: %SEC-6-IPACCESSLOGP: list 120 denied tcp 81.18.240.138(80) -&amp;gt; YYY.YYY.YYY.YYY(53091), 1 packet &amp;nbsp;&lt;BR&gt;000090: Feb 22 04:04:09.391 PCTime: %SEC-6-IPACCESSLOGP: list 110 denied tcp YYY.YYY.YYY.YYY(53006) -&amp;gt; 81.18.240.138(80), 3 packets &amp;nbsp;&lt;BR&gt;000091: Feb 22 04:04:36.695 PCTime: %SEC-6-IPACCESSLOGP: list 110 denied tcp YYY.YYY.YYY.YYY(53108) -&amp;gt; 81.18.240.138(80), 1 packet &amp;nbsp;&lt;BR&gt;000092: Feb 22 04:04:59.599 PCTime: %SEC-6-IPACCESSLOGP: list 110 denied tcp YYY.YYY.YYY.YYY(53120) -&amp;gt; 81.18.240.138(80), 1 packet &amp;nbsp;&lt;BR&gt;000093: Feb 22 04:05:07.131 PCTime: %SEC-6-IPACCESSLOGP: list 120 denied tcp 81.18.240.138(80) -&amp;gt; YYY.YYY.YYY.YYY(53108), 1 packet &amp;nbsp;&lt;BR&gt;000094: Feb 22 04:05:24.267 PCTime: %SEC-6-IPACCESSLOGP: list 110 denied tcp YYY.YYY.YYY.YYY(53126) -&amp;gt; 81.18.240.138(80), 1 packet &amp;nbsp;&lt;BR&gt;000095: Feb 22 04:05:30.195 PCTime: %SEC-6-IPACCESSLOGP: list 120 denied tcp 81.18.240.138(80) -&amp;gt; YYY.YYY.YYY.YYY(53120), 1 packet &amp;nbsp;&lt;BR&gt;000096: Feb 22 04:05:40.343 PCTime: %SEC-6-IPACCESSLOGP: list 110 denied tcp YYY.YYY.YYY.YYY(53130) -&amp;gt; 81.18.240.138(80), 1 packet &amp;nbsp;&lt;BR&gt;000097: Feb 22 04:05:45.291 PCTime: %SEC-6-IPACCESSLOGP: list 110 denied tcp YYY.YYY.YYY.YYY(53132) -&amp;gt; 81.18.240.138(80), 1 packet &amp;nbsp;&lt;BR&gt;000098: Feb 22 04:05:54.771 PCTime: %SEC-6-IPACCESSLOGP: list 120 denied tcp 81.18.240.138(80) -&amp;gt; YYY.YYY.YYY.YYY(53126), 1 packet &amp;nbsp;&lt;BR&gt;000099: Feb 22 04:06:09.391 PCTime: %SEC-6-IPACCESSLOGP: list 110 denied tcp YYY.YYY.YYY.YYY(53031) -&amp;gt; 81.18.240.138(80), 3 packets &amp;nbsp;&lt;BR&gt;000100: Feb 22 04:06:11.155 PCTime: %SEC-6-IPACCESSLOGP: list 120 denied tcp 81.18.240.138(80) -&amp;gt; YYY.YYY.YYY.YYY(53130), 1 packet &amp;nbsp;&lt;BR&gt;000101: Feb 22 04:06:15.763 PCTime: %SEC-6-IPACCESSLOGP: list 120 denied tcp 81.18.240.138(80) -&amp;gt; YYY.YYY.YYY.YYY(53132), 1 packet &amp;nbsp;&lt;BR&gt;000102: Feb 22 04:06:24.111 PCTime: %SEC-6-IPACCESSLOGP: list 110 denied tcp YYY.YYY.YYY.YYY(53136) -&amp;gt; 81.18.240.138(80), 1 packet &amp;nbsp;&lt;BR&gt;000103: Feb 22 04:06:39.995 PCTime: %SEC-6-IPACCESSLOGP: list 110 denied tcp YYY.YYY.YYY.YYY(53142) -&amp;gt; 81.18.240.138(80), 1 packet &amp;nbsp;&lt;BR&gt;000104: Feb 22 04:06:54.031 PCTime: %SEC-6-IPACCESSLOGP: list 110 denied tcp YYY.YYY.YYY.YYY(53146) -&amp;gt; 81.18.240.138(80), 1 packet &amp;nbsp;&lt;BR&gt;000105: Feb 22 04:07:05.091 PCTime: %SEC-6-IPACCESSLOGP: list 110 denied tcp YYY.YYY.YYY.YYY(53157) -&amp;gt; 81.18.240.138(80), 1 packet &amp;nbsp;&lt;BR&gt;000106: Feb 22 04:07:09.391 PCTime: %SEC-6-IPACCESSLOGRL: access-list logging rate-limited or missed 6 packets &lt;BR&gt;000107: Feb 22 04:07:10.547 PCTime: %SEC-6-IPACCESSLOGP: list 120 denied tcp 81.18.240.138(80) -&amp;gt; YYY.YYY.YYY.YYY(53142), 1 packet &amp;nbsp;&lt;BR&gt;000108: Feb 22 04:07:15.067 PCTime: %SEC-6-IPACCESSLOGP: list 110 denied tcp YYY.YYY.YYY.YYY(53166) -&amp;gt; 81.18.240.138(80), 1 packet &amp;nbsp;&lt;BR&gt;000109: Feb 22 04:07:16.727 PCTime: %SEC-6-IPACCESSLOGP: list 110 denied tcp YYY.YYY.YYY.YYY(53169) -&amp;gt; 81.18.240.138(80), 1 packet &amp;nbsp;&lt;BR&gt;000110: Feb 22 04:07:24.883 PCTime: %SEC-6-IPACCESSLOGP: list 120 denied tcp 81.18.240.138(80) -&amp;gt; YYY.YYY.YYY.YYY(53146), 1 packet &amp;nbsp;&lt;BR&gt;000111: Feb 22 04:07:30.239 PCTime: %SEC-6-IPACCESSLOGP: list 110 denied tcp YYY.YYY.YYY.YYY(53173) -&amp;gt; 81.18.240.138(80), 1 packet &amp;nbsp;&lt;BR&gt;000112: Feb 22 04:07:35.635 PCTime: %SEC-6-IPACCESSLOGP: list 120 denied tcp 81.18.240.138(80) -&amp;gt; YYY.YYY.YYY.YYY(53157), 1 packet &amp;nbsp;&lt;BR&gt;000113: Feb 22 04:07:45.875 PCTime: %SEC-6-IPACCESSLOGP: list 120 denied tcp 81.18.240.138(80) -&amp;gt; YYY.YYY.YYY.YYY(53166), 1 packet &amp;nbsp;&lt;BR&gt;000114: Feb 22 04:07:47.411 PCTime: %SEC-6-IPACCESSLOGP: list 120 denied tcp 81.18.240.138(80) -&amp;gt; YYY.YYY.YYY.YYY(53169), 1 packet &amp;nbsp;&lt;BR&gt;000115: Feb 22 04:07:59.519 PCTime: %SEC-6-IPACCESSLOGP: list 110 denied tcp YYY.YYY.YYY.YYY(53182) -&amp;gt; 81.18.240.138(80), 1 packet &amp;nbsp;&lt;BR&gt;000116: Feb 22 04:08:00.723 PCTime: %SEC-6-IPACCESSLOGP: list 120 denied tcp 81.18.240.138(80) -&amp;gt; YYY.YYY.YYY.YYY(53173), 1 packet &amp;nbsp;&lt;BR&gt;000117: Feb 22 04:08:09.391 PCTime: %SEC-6-IPACCESSLOGRL: access-list logging rate-limited or missed 15 packets &lt;BR&gt;000118: Feb 22 04:08:20.555 PCTime: %SEC-6-IPACCESSLOGP: list 110 denied tcp YYY.YYY.YYY.YYY(53187) -&amp;gt; 81.18.240.138(80), 1 packet &amp;nbsp;&lt;BR&gt;000119: Feb 22 04:08:29.907 PCTime: %SEC-6-IPACCESSLOGP: list 120 denied tcp 81.18.240.138(80) -&amp;gt; YYY.YYY.YYY.YYY(53182), 1 packet &amp;nbsp;&lt;BR&gt;000120: Feb 22 04:08:35.247 PCTime: %SEC-6-IPACCESSLOGP: list 110 denied tcp YYY.YYY.YYY.YYY(53189) -&amp;gt; 81.18.240.138(80), 1 packet &amp;nbsp;&lt;BR&gt;000121: Feb 22 04:08:51.411 PCTime: %SEC-6-IPACCESSLOGP: list 120 denied tcp 81.18.240.138(80) -&amp;gt; YYY.YYY.YYY.YYY(53187), 1 packet &amp;nbsp;&lt;BR&gt;000122: Feb 22 04:09:00.651 PCTime: %SEC-6-IPACCESSLOGP: list 110 denied tcp YYY.YYY.YYY.YYY(53199) -&amp;gt; 81.18.240.138(80), 1 packet &amp;nbsp;&lt;BR&gt;000123: Feb 22 04:09:05.747 PCTime: %SEC-6-IPACCESSLOGP: list 120 denied tcp 81.18.240.138(80) -&amp;gt; YYY.YYY.YYY.YYY(53189), 1 packet &amp;nbsp;&lt;BR&gt;000124: Feb 22 04:09:09.391 PCTime: %SEC-6-IPACCESSLOGRL: access-list logging rate-limited or missed 10 packets &lt;BR&gt;000125: Feb 22 04:09:31.363 PCTime: %SEC-6-IPACCESSLOGP: list 120 denied tcp 81.18.240.138(80) -&amp;gt; YYY.YYY.YYY.YYY(53199), 1 packet &amp;nbsp;&lt;BR&gt;000126: Feb 22 04:10:08.847 PCTime: %SEC-6-IPACCESSLOGP: list 110 denied tcp YYY.YYY.YYY.YYY(53213) -&amp;gt; 81.18.240.138(80), 1 packet &amp;nbsp;&lt;BR&gt;000127: Feb 22 04:10:09.391 PCTime: %SEC-6-IPACCESSLOGRL: access-list logging rate-limited or missed 3 packets &lt;BR&gt;000128: Feb 22 04:10:39.483 PCTime: %SEC-6-IPACCESSLOGP: list 120 denied tcp 81.18.240.138(80) -&amp;gt; YYY.YYY.YYY.YYY(53213), 1 packet &amp;nbsp;&lt;BR&gt;000129: Feb 22 04:11:09.391 PCTime: %SEC-6-IPACCESSLOGRL: access-list logging rate-limited or missed 1 packet &lt;BR&gt;&lt;BR&gt;Inner-inner Firewall reports:&lt;BR&gt;&lt;BR&gt;&lt;BR&gt;4:13:13 AM&amp;nbsp;&amp;nbsp; &amp;nbsp;Block&amp;nbsp;&amp;nbsp; &amp;nbsp;IN&amp;nbsp;&amp;nbsp; &amp;nbsp;TCP&amp;nbsp;&amp;nbsp; &amp;nbsp;81.18.240.138&amp;nbsp;&amp;nbsp; &amp;nbsp;80&amp;nbsp;&amp;nbsp; &amp;nbsp;ZZZ.ZZZ.ZZZ.ZZZ&amp;nbsp;&amp;nbsp; &amp;nbsp;53213&amp;nbsp;&amp;nbsp; &amp;nbsp;RST&amp;nbsp;&amp;nbsp; &amp;nbsp;Blocked by the Attack Detecton component&lt;BR&gt;4:12:01 AM&amp;nbsp;&amp;nbsp; &amp;nbsp;Block&amp;nbsp;&amp;nbsp; &amp;nbsp;IN&amp;nbsp;&amp;nbsp; &amp;nbsp;TCP&amp;nbsp;&amp;nbsp; &amp;nbsp;81.18.240.138&amp;nbsp;&amp;nbsp; &amp;nbsp;80&amp;nbsp;&amp;nbsp; &amp;nbsp;ZZZ.ZZZ.ZZZ.ZZZ&amp;nbsp;&amp;nbsp; &amp;nbsp;53199&amp;nbsp;&amp;nbsp; &amp;nbsp;RST&amp;nbsp;&amp;nbsp; &amp;nbsp;Blocked by the Attack Detecton component&lt;BR&gt;4:11:47 AM&amp;nbsp;&amp;nbsp; &amp;nbsp;Block&amp;nbsp;&amp;nbsp; &amp;nbsp;IN&amp;nbsp;&amp;nbsp; &amp;nbsp;TCP&amp;nbsp;&amp;nbsp; &amp;nbsp;81.18.240.138&amp;nbsp;&amp;nbsp; &amp;nbsp;80&amp;nbsp;&amp;nbsp; &amp;nbsp;ZZZ.ZZZ.ZZZ.ZZZ&amp;nbsp;&amp;nbsp; &amp;nbsp;53189&amp;nbsp;&amp;nbsp; &amp;nbsp;RST&amp;nbsp;&amp;nbsp; &amp;nbsp;Blocked by the Attack Detecton component&lt;BR&gt;4:11:32 AM&amp;nbsp;&amp;nbsp; &amp;nbsp;Block&amp;nbsp;&amp;nbsp; &amp;nbsp;IN&amp;nbsp;&amp;nbsp; &amp;nbsp;TCP&amp;nbsp;&amp;nbsp; &amp;nbsp;81.18.240.138&amp;nbsp;&amp;nbsp; &amp;nbsp;80&amp;nbsp;&amp;nbsp; &amp;nbsp;ZZZ.ZZZ.ZZZ.ZZZ&amp;nbsp;&amp;nbsp; &amp;nbsp;53187&amp;nbsp;&amp;nbsp; &amp;nbsp;RST&amp;nbsp;&amp;nbsp; &amp;nbsp;Blocked by the Attack Detecton component&lt;BR&gt;4:11:03 AM&amp;nbsp;&amp;nbsp; &amp;nbsp;Block&amp;nbsp;&amp;nbsp; &amp;nbsp;IN&amp;nbsp;&amp;nbsp; &amp;nbsp;TCP&amp;nbsp;&amp;nbsp; &amp;nbsp;81.18.240.138&amp;nbsp;&amp;nbsp; &amp;nbsp;80&amp;nbsp;&amp;nbsp; &amp;nbsp;ZZZ.ZZZ.ZZZ.ZZZ&amp;nbsp;&amp;nbsp; &amp;nbsp;53182&amp;nbsp;&amp;nbsp; &amp;nbsp;RST&amp;nbsp;&amp;nbsp; &amp;nbsp;Blocked by the Attack Detecton component&lt;BR&gt;4:10:35 AM&amp;nbsp;&amp;nbsp; &amp;nbsp;Block&amp;nbsp;&amp;nbsp; &amp;nbsp;IN&amp;nbsp;&amp;nbsp; &amp;nbsp;TCP&amp;nbsp;&amp;nbsp; &amp;nbsp;81.18.240.138&amp;nbsp;&amp;nbsp; &amp;nbsp;80&amp;nbsp;&amp;nbsp; &amp;nbsp;ZZZ.ZZZ.ZZZ.ZZZ&amp;nbsp;&amp;nbsp; &amp;nbsp;53173&amp;nbsp;&amp;nbsp; &amp;nbsp;RST&amp;nbsp;&amp;nbsp; &amp;nbsp;Blocked by the Attack Detecton component&lt;BR&gt;4:10:20 AM&amp;nbsp;&amp;nbsp; &amp;nbsp;Block&amp;nbsp;&amp;nbsp; &amp;nbsp;IN&amp;nbsp;&amp;nbsp; &amp;nbsp;TCP&amp;nbsp;&amp;nbsp; &amp;nbsp;81.18.240.138&amp;nbsp;&amp;nbsp; &amp;nbsp;80&amp;nbsp;&amp;nbsp; &amp;nbsp;ZZZ.ZZZ.ZZZ.ZZZ&amp;nbsp;&amp;nbsp; &amp;nbsp;53169&amp;nbsp;&amp;nbsp; &amp;nbsp;RST&amp;nbsp;&amp;nbsp; &amp;nbsp;Blocked by the Attack Detecton component&lt;BR&gt;4:10:20 AM&amp;nbsp;&amp;nbsp; &amp;nbsp;Block&amp;nbsp;&amp;nbsp; &amp;nbsp;IN&amp;nbsp;&amp;nbsp; &amp;nbsp;TCP&amp;nbsp;&amp;nbsp; &amp;nbsp;81.18.240.138&amp;nbsp;&amp;nbsp; &amp;nbsp;80&amp;nbsp;&amp;nbsp; &amp;nbsp;ZZZ.ZZZ.ZZZ.ZZZ&amp;nbsp;&amp;nbsp; &amp;nbsp;53166&amp;nbsp;&amp;nbsp; &amp;nbsp;RST&amp;nbsp;&amp;nbsp; &amp;nbsp;Blocked by the Attack Detecton component&lt;BR&gt;4:10:06 AM&amp;nbsp;&amp;nbsp; &amp;nbsp;Block&amp;nbsp;&amp;nbsp; &amp;nbsp;IN&amp;nbsp;&amp;nbsp; &amp;nbsp;TCP&amp;nbsp;&amp;nbsp; &amp;nbsp;81.18.240.138&amp;nbsp;&amp;nbsp; &amp;nbsp;80&amp;nbsp;&amp;nbsp; &amp;nbsp;ZZZ.ZZZ.ZZZ.ZZZ&amp;nbsp;&amp;nbsp; &amp;nbsp;53146&amp;nbsp;&amp;nbsp; &amp;nbsp;RST&amp;nbsp;&amp;nbsp; &amp;nbsp;Blocked by the Attack Detecton component&lt;BR&gt;4:10:06 AM&amp;nbsp;&amp;nbsp; &amp;nbsp;Block&amp;nbsp;&amp;nbsp; &amp;nbsp;IN&amp;nbsp;&amp;nbsp; &amp;nbsp;TCP&amp;nbsp;&amp;nbsp; &amp;nbsp;81.18.240.138&amp;nbsp;&amp;nbsp; &amp;nbsp;80&amp;nbsp;&amp;nbsp; &amp;nbsp;ZZZ.ZZZ.ZZZ.ZZZ&amp;nbsp;&amp;nbsp; &amp;nbsp;53157&amp;nbsp;&amp;nbsp; &amp;nbsp;RST&amp;nbsp;&amp;nbsp; &amp;nbsp;Blocked by the Attack Detecton component&lt;BR&gt;4:09:51 AM&amp;nbsp;&amp;nbsp; &amp;nbsp;Block&amp;nbsp;&amp;nbsp; &amp;nbsp;IN&amp;nbsp;&amp;nbsp; &amp;nbsp;TCP&amp;nbsp;&amp;nbsp; &amp;nbsp;81.18.240.138&amp;nbsp;&amp;nbsp; &amp;nbsp;80&amp;nbsp;&amp;nbsp; &amp;nbsp;ZZZ.ZZZ.ZZZ.ZZZ&amp;nbsp;&amp;nbsp; &amp;nbsp;53142&amp;nbsp;&amp;nbsp; &amp;nbsp;RST&amp;nbsp;&amp;nbsp; &amp;nbsp;Blocked by the Attack Detecton component&lt;BR&gt;4:09:37 AM&amp;nbsp;&amp;nbsp; &amp;nbsp;Block&amp;nbsp;&amp;nbsp; &amp;nbsp;IN&amp;nbsp;&amp;nbsp; &amp;nbsp;TCP&amp;nbsp;&amp;nbsp; &amp;nbsp;81.18.240.138&amp;nbsp;&amp;nbsp; &amp;nbsp;80&amp;nbsp;&amp;nbsp; &amp;nbsp;ZZZ.ZZZ.ZZZ.ZZZ&amp;nbsp;&amp;nbsp; &amp;nbsp;53136&amp;nbsp;&amp;nbsp; &amp;nbsp;RST&amp;nbsp;&amp;nbsp; &amp;nbsp;Blocked by the Attack Detecton component&lt;BR&gt;4:08:54 AM&amp;nbsp;&amp;nbsp; &amp;nbsp;Block&amp;nbsp;&amp;nbsp; &amp;nbsp;IN&amp;nbsp;&amp;nbsp; &amp;nbsp;TCP&amp;nbsp;&amp;nbsp; &amp;nbsp;81.18.240.138&amp;nbsp;&amp;nbsp; &amp;nbsp;80&amp;nbsp;&amp;nbsp; &amp;nbsp;ZZZ.ZZZ.ZZZ.ZZZ&amp;nbsp;&amp;nbsp; &amp;nbsp;53130&amp;nbsp;&amp;nbsp; &amp;nbsp;RST&amp;nbsp;&amp;nbsp; &amp;nbsp;Blocked by the Attack Detecton component&lt;BR&gt;4:08:54 AM&amp;nbsp;&amp;nbsp; &amp;nbsp;Block&amp;nbsp;&amp;nbsp; &amp;nbsp;IN&amp;nbsp;&amp;nbsp; &amp;nbsp;TCP&amp;nbsp;&amp;nbsp; &amp;nbsp;81.18.240.138&amp;nbsp;&amp;nbsp; &amp;nbsp;80&amp;nbsp;&amp;nbsp; &amp;nbsp;ZZZ.ZZZ.ZZZ.ZZZ&amp;nbsp;&amp;nbsp; &amp;nbsp;53132&amp;nbsp;&amp;nbsp; &amp;nbsp;RST&amp;nbsp;&amp;nbsp; &amp;nbsp;Blocked by the Attack Detecton component&lt;BR&gt;4:08:25 AM&amp;nbsp;&amp;nbsp; &amp;nbsp;Block&amp;nbsp;&amp;nbsp; &amp;nbsp;IN&amp;nbsp;&amp;nbsp; &amp;nbsp;TCP&amp;nbsp;&amp;nbsp; &amp;nbsp;81.18.240.138&amp;nbsp;&amp;nbsp; &amp;nbsp;80&amp;nbsp;&amp;nbsp; &amp;nbsp;ZZZ.ZZZ.ZZZ.ZZZ&amp;nbsp;&amp;nbsp; &amp;nbsp;53126&amp;nbsp;&amp;nbsp; &amp;nbsp;RST&amp;nbsp;&amp;nbsp; &amp;nbsp;Blocked by the Attack Detecton component&lt;BR&gt;4:08:11 AM&amp;nbsp;&amp;nbsp; &amp;nbsp;Block&amp;nbsp;&amp;nbsp; &amp;nbsp;IN&amp;nbsp;&amp;nbsp; &amp;nbsp;TCP&amp;nbsp;&amp;nbsp; &amp;nbsp;81.18.240.138&amp;nbsp;&amp;nbsp; &amp;nbsp;80&amp;nbsp;&amp;nbsp; &amp;nbsp;ZZZ.ZZZ.ZZZ.ZZZ&amp;nbsp;&amp;nbsp; &amp;nbsp;53120&amp;nbsp;&amp;nbsp; &amp;nbsp;RST&amp;nbsp;&amp;nbsp; &amp;nbsp;Blocked by the Attack Detecton component&lt;BR&gt;4:07:42 AM&amp;nbsp;&amp;nbsp; &amp;nbsp;Block&amp;nbsp;&amp;nbsp; &amp;nbsp;IN&amp;nbsp;&amp;nbsp; &amp;nbsp;TCP&amp;nbsp;&amp;nbsp; &amp;nbsp;81.18.240.138&amp;nbsp;&amp;nbsp; &amp;nbsp;80&amp;nbsp;&amp;nbsp; &amp;nbsp;ZZZ.ZZZ.ZZZ.ZZZ&amp;nbsp;&amp;nbsp; &amp;nbsp;53108&amp;nbsp;&amp;nbsp; &amp;nbsp;RST&amp;nbsp;&amp;nbsp; &amp;nbsp;Blocked by the Attack Detecton component&lt;BR&gt;4:06:30 AM&amp;nbsp;&amp;nbsp; &amp;nbsp;Block&amp;nbsp;&amp;nbsp; &amp;nbsp;IN&amp;nbsp;&amp;nbsp; &amp;nbsp;TCP&amp;nbsp;&amp;nbsp; &amp;nbsp;81.18.240.138&amp;nbsp;&amp;nbsp; &amp;nbsp;80&amp;nbsp;&amp;nbsp; &amp;nbsp;ZZZ.ZZZ.ZZZ.ZZZ&amp;nbsp;&amp;nbsp; &amp;nbsp;53091&amp;nbsp;&amp;nbsp; &amp;nbsp;RST&amp;nbsp;&amp;nbsp; &amp;nbsp;Blocked by the Attack Detecton component&lt;BR&gt;4:05:47 AM&amp;nbsp;&amp;nbsp; &amp;nbsp;Block&amp;nbsp;&amp;nbsp; &amp;nbsp;IN&amp;nbsp;&amp;nbsp; &amp;nbsp;TCP&amp;nbsp;&amp;nbsp; &amp;nbsp;81.18.240.138&amp;nbsp;&amp;nbsp; &amp;nbsp;80&amp;nbsp;&amp;nbsp; &amp;nbsp;ZZZ.ZZZ.ZZZ.ZZZ&amp;nbsp;&amp;nbsp; &amp;nbsp;53076&amp;nbsp;&amp;nbsp; &amp;nbsp;RST&amp;nbsp;&amp;nbsp; &amp;nbsp;Blocked by the Attack Detecton component&lt;BR&gt;4:05:18 AM&amp;nbsp;&amp;nbsp; &amp;nbsp;Block&amp;nbsp;&amp;nbsp; &amp;nbsp;IN&amp;nbsp;&amp;nbsp; &amp;nbsp;TCP&amp;nbsp;&amp;nbsp; &amp;nbsp;81.18.240.138&amp;nbsp;&amp;nbsp; &amp;nbsp;80&amp;nbsp;&amp;nbsp; &amp;nbsp;ZZZ.ZZZ.ZZZ.ZZZ&amp;nbsp;&amp;nbsp; &amp;nbsp;53055&amp;nbsp;&amp;nbsp; &amp;nbsp;RST&amp;nbsp;&amp;nbsp; &amp;nbsp;Blocked by the Attack Detecton component&lt;BR&gt;4:03:51 AM&amp;nbsp;&amp;nbsp; &amp;nbsp;Block&amp;nbsp;&amp;nbsp; &amp;nbsp;IN&amp;nbsp;&amp;nbsp; &amp;nbsp;TCP&amp;nbsp;&amp;nbsp; &amp;nbsp;81.18.240.138&amp;nbsp;&amp;nbsp; &amp;nbsp;80&amp;nbsp;&amp;nbsp; &amp;nbsp;ZZZ.ZZZ.ZZZ.ZZZ&amp;nbsp;&amp;nbsp; &amp;nbsp;53031&amp;nbsp;&amp;nbsp; &amp;nbsp;RST&amp;nbsp;&amp;nbsp; &amp;nbsp;Blocked by the Attack Detecton component&lt;BR&gt;4:02:10 AM&amp;nbsp;&amp;nbsp; &amp;nbsp;Block&amp;nbsp;&amp;nbsp; &amp;nbsp;IN&amp;nbsp;&amp;nbsp; &amp;nbsp;TCP&amp;nbsp;&amp;nbsp; &amp;nbsp;81.18.240.138&amp;nbsp;&amp;nbsp; &amp;nbsp;80&amp;nbsp;&amp;nbsp; &amp;nbsp;ZZZ.ZZZ.ZZZ.ZZZ&amp;nbsp;&amp;nbsp; &amp;nbsp;53006&amp;nbsp;&amp;nbsp; &amp;nbsp;RST&amp;nbsp;&amp;nbsp; &amp;nbsp;Blocked by the Attack Detecton component&lt;BR&gt;4:00:01 AM&amp;nbsp;&amp;nbsp; &amp;nbsp;Block&amp;nbsp;&amp;nbsp; &amp;nbsp;IN&amp;nbsp;&amp;nbsp; &amp;nbsp;TCP&amp;nbsp;&amp;nbsp; &amp;nbsp;81.18.240.138&amp;nbsp;&amp;nbsp; &amp;nbsp;80&amp;nbsp;&amp;nbsp; &amp;nbsp;ZZZ.ZZZ.ZZZ.ZZZ&amp;nbsp;&amp;nbsp; &amp;nbsp;52981&amp;nbsp;&amp;nbsp; &amp;nbsp;RST&amp;nbsp;&amp;nbsp; &amp;nbsp;Blocked by the Attack Detecton component&lt;BR&gt;3:59:46 AM&amp;nbsp;&amp;nbsp; &amp;nbsp;Block&amp;nbsp;&amp;nbsp; &amp;nbsp;IN&amp;nbsp;&amp;nbsp; &amp;nbsp;TCP&amp;nbsp;&amp;nbsp; &amp;nbsp;81.18.240.138&amp;nbsp;&amp;nbsp; &amp;nbsp;80&amp;nbsp;&amp;nbsp; &amp;nbsp;ZZZ.ZZZ.ZZZ.ZZZ&amp;nbsp;&amp;nbsp; &amp;nbsp;52962&amp;nbsp;&amp;nbsp; &amp;nbsp;RST&amp;nbsp;&amp;nbsp; &amp;nbsp;Blocked by the Attack Detecton component&lt;BR&gt;3:59:32 AM&amp;nbsp;&amp;nbsp; &amp;nbsp;Block&amp;nbsp;&amp;nbsp; &amp;nbsp;IN&amp;nbsp;&amp;nbsp; &amp;nbsp;TCP&amp;nbsp;&amp;nbsp; &amp;nbsp;81.18.240.138&amp;nbsp;&amp;nbsp; &amp;nbsp;80&amp;nbsp;&amp;nbsp; &amp;nbsp;ZZZ.ZZZ.ZZZ.ZZZ&amp;nbsp;&amp;nbsp; &amp;nbsp;52942&amp;nbsp;&amp;nbsp; &amp;nbsp;RST&amp;nbsp;&amp;nbsp; &amp;nbsp;Blocked by the Attack Detecton component&lt;BR&gt;3:56:39 AM&amp;nbsp;&amp;nbsp; &amp;nbsp;Block&amp;nbsp;&amp;nbsp; &amp;nbsp;IN&amp;nbsp;&amp;nbsp; &amp;nbsp;TCP&amp;nbsp;&amp;nbsp; &amp;nbsp;81.18.240.138&amp;nbsp;&amp;nbsp; &amp;nbsp;80&amp;nbsp;&amp;nbsp; &amp;nbsp;ZZZ.ZZZ.ZZZ.ZZZ&amp;nbsp;&amp;nbsp; &amp;nbsp;52918&amp;nbsp;&amp;nbsp; &amp;nbsp;RST&amp;nbsp;&amp;nbsp; &amp;nbsp;Blocked by the Attack Detecton component&lt;BR&gt;3:52:20 AM&amp;nbsp;&amp;nbsp; &amp;nbsp;Block&amp;nbsp;&amp;nbsp; &amp;nbsp;IN&amp;nbsp;&amp;nbsp; &amp;nbsp;TCP&amp;nbsp;&amp;nbsp; &amp;nbsp;81.18.240.138&amp;nbsp;&amp;nbsp; &amp;nbsp;80&amp;nbsp;&amp;nbsp; &amp;nbsp;ZZZ.ZZZ.ZZZ.ZZZ&amp;nbsp;&amp;nbsp; &amp;nbsp;52904&amp;nbsp;&amp;nbsp; &amp;nbsp;RST&amp;nbsp;&amp;nbsp; &amp;nbsp;Blocked by the Attack Detecton component&lt;BR&gt;3:49:13 AM&amp;nbsp;&amp;nbsp; &amp;nbsp;Block&amp;nbsp;&amp;nbsp; &amp;nbsp;IN&amp;nbsp;&amp;nbsp; &amp;nbsp;TCP&amp;nbsp;&amp;nbsp; &amp;nbsp;81.18.240.138&amp;nbsp;&amp;nbsp; &amp;nbsp;80&amp;nbsp;&amp;nbsp; &amp;nbsp;ZZZ.ZZZ.ZZZ.ZZZ&amp;nbsp;&amp;nbsp; &amp;nbsp;52797&amp;nbsp;&amp;nbsp; &amp;nbsp;RST&amp;nbsp;&amp;nbsp; &amp;nbsp;Blocked by the Attack Detecton component&lt;BR&gt;3:47:32 AM&amp;nbsp;&amp;nbsp; &amp;nbsp;Block&amp;nbsp;&amp;nbsp; &amp;nbsp;IN&amp;nbsp;&amp;nbsp; &amp;nbsp;TCP&amp;nbsp;&amp;nbsp; &amp;nbsp;81.18.240.138&amp;nbsp;&amp;nbsp; &amp;nbsp;80&amp;nbsp;&amp;nbsp; &amp;nbsp;ZZZ.ZZZ.ZZZ.ZZZ&amp;nbsp;&amp;nbsp; &amp;nbsp;52769&amp;nbsp;&amp;nbsp; &amp;nbsp;RST&amp;nbsp;&amp;nbsp; &amp;nbsp;Blocked by the Attack Detecton component&lt;BR&gt;3:47:03 AM&amp;nbsp;&amp;nbsp; &amp;nbsp;Block&amp;nbsp;&amp;nbsp; &amp;nbsp;IN&amp;nbsp;&amp;nbsp; &amp;nbsp;TCP&amp;nbsp;&amp;nbsp; &amp;nbsp;81.18.240.138&amp;nbsp;&amp;nbsp; &amp;nbsp;80&amp;nbsp;&amp;nbsp; &amp;nbsp;ZZZ.ZZZ.ZZZ.ZZZ&amp;nbsp;&amp;nbsp; &amp;nbsp;52763&amp;nbsp;&amp;nbsp; &amp;nbsp;RST&amp;nbsp;&amp;nbsp; &amp;nbsp;Blocked by the Attack Detecton component&lt;BR&gt;3:46:49 AM&amp;nbsp;&amp;nbsp; &amp;nbsp;Block&amp;nbsp;&amp;nbsp; &amp;nbsp;IN&amp;nbsp;&amp;nbsp; &amp;nbsp;TCP&amp;nbsp;&amp;nbsp; &amp;nbsp;81.18.240.138&amp;nbsp;&amp;nbsp; &amp;nbsp;80&amp;nbsp;&amp;nbsp; &amp;nbsp;ZZZ.ZZZ.ZZZ.ZZZ&amp;nbsp;&amp;nbsp; &amp;nbsp;52756&amp;nbsp;&amp;nbsp; &amp;nbsp;RST&amp;nbsp;&amp;nbsp; &amp;nbsp;Blocked by the Attack Detecton component&lt;BR&gt;3:46:06 AM&amp;nbsp;&amp;nbsp; &amp;nbsp;Block&amp;nbsp;&amp;nbsp; &amp;nbsp;IN&amp;nbsp;&amp;nbsp; &amp;nbsp;TCP&amp;nbsp;&amp;nbsp; &amp;nbsp;81.18.240.138&amp;nbsp;&amp;nbsp; &amp;nbsp;80&amp;nbsp;&amp;nbsp; &amp;nbsp;ZZZ.ZZZ.ZZZ.ZZZ&amp;nbsp;&amp;nbsp; &amp;nbsp;52735&amp;nbsp;&amp;nbsp; &amp;nbsp;RST&amp;nbsp;&amp;nbsp; &amp;nbsp;Blocked by the Attack Detecton component&lt;BR&gt;&lt;BR&gt;&lt;BR&gt;&lt;BR&gt;&lt;BR&gt;&lt;BR&gt;&lt;BR&gt;&lt;BR&gt;&lt;/FONT&gt;</description><comments>http://johndodrill.info/2012/02/22/alert-8118240138-penetrating-firewalls.aspx#Comments</comments><guid isPermaLink="false">cb23e030-cdf4-4a37-937b-2d0d5b2b24b2</guid><pubDate>Wed, 22 Feb 2012 21:54:00 GMT</pubDate></item><item><title>Intruder 202.176.209.3, of SingTel, Singapore, Uses DNS To Map LAN</title><link>http://johndodrill.info/2012/02/21/intruder-2021762093-of-singtel-singapore-uses-dns-to-map-lan.aspx?ref=rss</link><dc:creator>John Dodrill</dc:creator><description>&lt;FONT style="FONT-SIZE: 14px" face=Arial&gt;
&lt;P&gt;&lt;FONT style="FONT-SIZE: 14px"&gt;&lt;/FONT&gt;&lt;FONT style="FONT-SIZE: 14px"&gt;&lt;/FONT&gt;&lt;FONT style="FONT-SIZE: 14px"&gt;&lt;/FONT&gt;&lt;FONT style="FONT-SIZE: 14px"&gt;&lt;/FONT&gt;&lt;FONT style="FONT-SIZE: 14px"&gt;&lt;/FONT&gt;&lt;FONT style="FONT-SIZE: 14px"&gt;&lt;/FONT&gt;Bear in mind, when reading this, that there is absolutely no other traffic on this LN.&amp;nbsp; The &lt;FONT id=RadESpellError_0 class=RadEWrongWord&gt;LAN&lt;/FONT&gt; is effectively in honey pot mode.&lt;BR&gt;&lt;BR&gt;202.176.209.3 seems to be using DNS to map the network.&amp;nbsp; I've seen this before where the attacker floods the outer router with unsolicited DNS replies, uses an ARP attack (Man-in-the-Middle) to block access to the ISP's DNS &lt;FONT id=RadESpellError_7 class=RadEWrongWord&gt;name servers or otherwise &lt;A href="http://blogs.technet.com/b/srd/archive/2011/08/09/vulnerabilities-in-dns-server-could-allow-remote-code-execution.aspx" target=_blank&gt;crashes the DNS relay&lt;/A&gt;&lt;/FONT&gt;.&amp;nbsp; When&amp;nbsp;an inner&amp;nbsp;Router realizes it has no ability to make DNS requests via DNS relay, it is referred by the next router on the outbound side to it's DNS providers...and the hacker outside watching notes the new requesters IP.&amp;nbsp; &lt;BR&gt;&lt;BR&gt;Then, it seems, after tunneling past two other routers, the intruder attempts to obtain a local IP address on&amp;nbsp;a &lt;FONT id=RadESpellError_14 class=RadEWrongWord&gt;&lt;FONT id=RadESpellError_11 class=RadEWrongWord&gt;4th&lt;/FONT&gt;&lt;/FONT&gt; router, via &lt;FONT id=RadESpellError_15 class=RadEWrongWord&gt;&lt;FONT id=RadESpellError_12 class=RadEWrongWord&gt;DHCP&lt;/FONT&gt;&lt;/FONT&gt;, and fails.&amp;nbsp; Undaunted, the hacker reattempts the attack 4 hours later, and then again in less than two hours.&amp;nbsp; (The IP is again attacking, attempting to interject packets but just unable to get the sequence right.&amp;nbsp; Too bad 202.176.209.3.&amp;nbsp; As a hacker, you suck!)&lt;BR&gt;&lt;BR&gt;Word!&lt;BR&gt;&lt;BR&gt;Tue, 2012-02-21 03:35:40 - [DNS lookup failed, force renew!]&lt;BR&gt;Tue, 2012-02-21 03:35:50 - &lt;FONT id=RadESpellError_17 class=RadEWrongWord&gt;&lt;FONT id=RadESpellError_14 class=RadEWrongWord&gt;UDP&lt;/FONT&gt;&lt;/FONT&gt; packet - Source: &lt;FONT id=RadESpellError_18 class=RadEWrongWord&gt;&lt;FONT id=RadESpellError_15 class=RadEWrongWord&gt;XXX&lt;/FONT&gt;&lt;/FONT&gt;.&lt;FONT id=RadESpellError_19 class=RadEWrongWord&gt;&lt;FONT id=RadESpellError_16 class=RadEWrongWord&gt;XXX&lt;/FONT&gt;&lt;/FONT&gt;.&lt;FONT id=RadESpellError_20 class=RadEWrongWord&gt;&lt;FONT id=RadESpellError_17 class=RadEWrongWord&gt;XXX&lt;/FONT&gt;&lt;/FONT&gt;.&lt;FONT id=RadESpellError_21 class=RadEWrongWord&gt;&lt;FONT id=RadESpellError_18 class=RadEWrongWord&gt;XXX&lt;/FONT&gt;&lt;/FONT&gt; - Destination: &lt;FONT id=RadESpellError_22 class=RadEWrongWord&gt;&lt;FONT id=RadESpellError_19 class=RadEWrongWord&gt;YYY&lt;/FONT&gt;&lt;/FONT&gt;.&lt;FONT id=RadESpellError_23 class=RadEWrongWord&gt;&lt;FONT id=RadESpellError_20 class=RadEWrongWord&gt;YYY&lt;/FONT&gt;&lt;/FONT&gt;.&lt;FONT id=RadESpellError_24 class=RadEWrongWord&gt;&lt;FONT id=RadESpellError_21 class=RadEWrongWord&gt;YYY&lt;/FONT&gt;&lt;/FONT&gt;.&lt;FONT id=RadESpellError_25 class=RadEWrongWord&gt;&lt;FONT id=RadESpellError_22 class=RadEWrongWord&gt;YYY&lt;/FONT&gt;&lt;/FONT&gt; - [Access Policy not found, dropping packet &lt;FONT id=RadESpellError_26 class=RadEWrongWord&gt;&lt;FONT id=RadESpellError_23 class=RadEWrongWord&gt;Src&lt;/FONT&gt;&lt;/FONT&gt; 67 &lt;FONT id=RadESpellError_27 class=RadEWrongWord&gt;&lt;FONT id=RadESpellError_24 class=RadEWrongWord&gt;Dst&lt;/FONT&gt;&lt;/FONT&gt; 68 from WAN]&lt;BR&gt;Tue, 2012-02-21 03:35:53 - &lt;FONT id=RadESpellError_28 class=RadEWrongWord&gt;&lt;FONT id=RadESpellError_25 class=RadEWrongWord&gt;UDP&lt;/FONT&gt;&lt;/FONT&gt; packet - Source: &lt;FONT id=RadESpellError_29 class=RadEWrongWord&gt;&lt;FONT id=RadESpellError_26 class=RadEWrongWord&gt;XXX&lt;/FONT&gt;&lt;/FONT&gt;.&lt;FONT id=RadESpellError_30 class=RadEWrongWord&gt;&lt;FONT id=RadESpellError_27 class=RadEWrongWord&gt;XXX&lt;/FONT&gt;&lt;/FONT&gt;.&lt;FONT id=RadESpellError_31 class=RadEWrongWord&gt;&lt;FONT id=RadESpellError_28 class=RadEWrongWord&gt;XXX&lt;/FONT&gt;&lt;/FONT&gt;.&lt;FONT id=RadESpellError_32 class=RadEWrongWord&gt;&lt;FONT id=RadESpellError_29 class=RadEWrongWord&gt;XXX&lt;/FONT&gt;&lt;/FONT&gt; - Destination: &lt;FONT id=RadESpellError_33 class=RadEWrongWord&gt;&lt;FONT id=RadESpellError_30 class=RadEWrongWord&gt;YYY&lt;/FONT&gt;&lt;/FONT&gt;.&lt;FONT id=RadESpellError_34 class=RadEWrongWord&gt;&lt;FONT id=RadESpellError_31 class=RadEWrongWord&gt;YYY&lt;/FONT&gt;&lt;/FONT&gt;.&lt;FONT id=RadESpellError_35 class=RadEWrongWord&gt;&lt;FONT id=RadESpellError_32 class=RadEWrongWord&gt;YYY&lt;/FONT&gt;&lt;/FONT&gt;.&lt;FONT id=RadESpellError_36 class=RadEWrongWord&gt;&lt;FONT id=RadESpellError_33 class=RadEWrongWord&gt;YYY&lt;/FONT&gt;&lt;/FONT&gt; - [Access Policy not found, dropping packet &lt;FONT id=RadESpellError_37 class=RadEWrongWord&gt;&lt;FONT id=RadESpellError_34 class=RadEWrongWord&gt;Src&lt;/FONT&gt;&lt;/FONT&gt; 67 &lt;FONT id=RadESpellError_38 class=RadEWrongWord&gt;&lt;FONT id=RadESpellError_35 class=RadEWrongWord&gt;Dst&lt;/FONT&gt;&lt;/FONT&gt; 68 from WAN]&lt;/P&gt;
&lt;P&gt;000096: &lt;FONT id=RadESpellError_39 class=RadEWrongWord&gt;&lt;FONT id=RadESpellError_36 class=RadEWrongWord&gt;&lt;FONT id=RadESpellError_35 class=RadEWrongWord&gt;Feb&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt; 21 03:35:54.387 &lt;FONT id=RadESpellError_40 class=RadEWrongWord&gt;&lt;FONT id=RadESpellError_37 class=RadEWrongWord&gt;&lt;FONT id=RadESpellError_36 class=RadEWrongWord&gt;PCTime&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;: %SEC-6-&lt;FONT id=RadESpellError_41 class=RadEWrongWord&gt;&lt;FONT id=RadESpellError_38 class=RadEWrongWord&gt;&lt;FONT id=RadESpellError_37 class=RadEWrongWord&gt;IPACCESSLOGDP&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;: list 120 denied &lt;FONT id=RadESpellError_42 class=RadEWrongWord&gt;&lt;FONT id=RadESpellError_39 class=RadEWrongWord&gt;&lt;FONT id=RadESpellError_38 class=RadEWrongWord&gt;icmp&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt; 202.176.209.3 -&amp;gt; &lt;FONT id=RadESpellError_43 class=RadEWrongWord&gt;&lt;FONT id=RadESpellError_40 class=RadEWrongWord&gt;YYY&lt;/FONT&gt;&lt;/FONT&gt;.&lt;FONT id=RadESpellError_44 class=RadEWrongWord&gt;&lt;FONT id=RadESpellError_41 class=RadEWrongWord&gt;YYY&lt;/FONT&gt;&lt;/FONT&gt;.&lt;FONT id=RadESpellError_45 class=RadEWrongWord&gt;&lt;FONT id=RadESpellError_42 class=RadEWrongWord&gt;YYY&lt;/FONT&gt;&lt;/FONT&gt;.&lt;FONT id=RadESpellError_46 class=RadEWrongWord&gt;&lt;FONT id=RadESpellError_43 class=RadEWrongWord&gt;YYY&lt;/FONT&gt;&lt;/FONT&gt; (11/0), 1 packet&lt;/P&gt;
&lt;P&gt;Tue, 2012-02-21 03:35:54 - [Send out &lt;FONT id=RadESpellError_47 class=RadEWrongWord&gt;&lt;FONT id=RadESpellError_44 class=RadEWrongWord&gt;&lt;FONT id=RadESpellError_43 class=RadEWrongWord&gt;NTP&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt; Request to 216.245.57.38]&lt;BR&gt;Tue, 2012-02-21 03:36:09 - [&lt;FONT id=RadESpellError_48 class=RadEWrongWord&gt;&lt;FONT id=RadESpellError_45 class=RadEWrongWord&gt;&lt;FONT id=RadESpellError_44 class=RadEWrongWord&gt;NTP&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt; Reply Invalid]&lt;BR&gt;Tue, 2012-02-21 03:37:14 - [Send out &lt;FONT id=RadESpellError_49 class=RadEWrongWord&gt;&lt;FONT id=RadESpellError_46 class=RadEWrongWord&gt;&lt;FONT id=RadESpellError_45 class=RadEWrongWord&gt;NTP&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt; Request to 209.249.181.21]&lt;BR&gt;Tue, 2012-02-21 03:37:15 - [Receive &lt;FONT id=RadESpellError_50 class=RadEWrongWord&gt;&lt;FONT id=RadESpellError_47 class=RadEWrongWord&gt;&lt;FONT id=RadESpellError_46 class=RadEWrongWord&gt;NTP&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt; Reply from 209.249.181.21]&lt;/P&gt;
&lt;P&gt;000097: &lt;FONT id=RadESpellError_51 class=RadEWrongWord&gt;&lt;FONT id=RadESpellError_48 class=RadEWrongWord&gt;&lt;FONT id=RadESpellError_47 class=RadEWrongWord&gt;Feb&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt; 21 03:40:54.387 &lt;FONT id=RadESpellError_52 class=RadEWrongWord&gt;&lt;FONT id=RadESpellError_49 class=RadEWrongWord&gt;&lt;FONT id=RadESpellError_48 class=RadEWrongWord&gt;PCTime&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;: %SEC-6-&lt;FONT id=RadESpellError_53 class=RadEWrongWord&gt;&lt;FONT id=RadESpellError_50 class=RadEWrongWord&gt;&lt;FONT id=RadESpellError_49 class=RadEWrongWord&gt;IPACCESSLOGDP&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;: list 120 denied &lt;FONT id=RadESpellError_54 class=RadEWrongWord&gt;&lt;FONT id=RadESpellError_51 class=RadEWrongWord&gt;&lt;FONT id=RadESpellError_50 class=RadEWrongWord&gt;icmp&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt; 202.176.209.3 -&amp;gt; &lt;FONT id=RadESpellError_55 class=RadEWrongWord&gt;&lt;FONT id=RadESpellError_52 class=RadEWrongWord&gt;YYY&lt;/FONT&gt;&lt;/FONT&gt;.&lt;FONT id=RadESpellError_56 class=RadEWrongWord&gt;&lt;FONT id=RadESpellError_53 class=RadEWrongWord&gt;YYY&lt;/FONT&gt;&lt;/FONT&gt;.&lt;FONT id=RadESpellError_57 class=RadEWrongWord&gt;&lt;FONT id=RadESpellError_54 class=RadEWrongWord&gt;YYY&lt;/FONT&gt;&lt;/FONT&gt;.&lt;FONT id=RadESpellError_58 class=RadEWrongWord&gt;&lt;FONT id=RadESpellError_55 class=RadEWrongWord&gt;YYY&lt;/FONT&gt;&lt;/FONT&gt; (11/0), 2 packets&lt;/P&gt;
&lt;P&gt;Tue, 2012-02-21 07:30:54 - [DNS lookup failed, force renew!]&lt;BR&gt;Tue, 2012-02-21 07:31:04 - &lt;FONT id=RadESpellError_60 class=RadEWrongWord&gt;&lt;FONT id=RadESpellError_57 class=RadEWrongWord&gt;UDP&lt;/FONT&gt;&lt;/FONT&gt; packet - Source: &lt;FONT id=RadESpellError_61 class=RadEWrongWord&gt;&lt;FONT id=RadESpellError_58 class=RadEWrongWord&gt;XXX&lt;/FONT&gt;&lt;/FONT&gt;.&lt;FONT id=RadESpellError_62 class=RadEWrongWord&gt;&lt;FONT id=RadESpellError_59 class=RadEWrongWord&gt;XXX&lt;/FONT&gt;&lt;/FONT&gt;.&lt;FONT id=RadESpellError_63 class=RadEWrongWord&gt;&lt;FONT id=RadESpellError_60 class=RadEWrongWord&gt;XXX&lt;/FONT&gt;&lt;/FONT&gt;.&lt;FONT id=RadESpellError_64 class=RadEWrongWord&gt;&lt;FONT id=RadESpellError_61 class=RadEWrongWord&gt;XXX&lt;/FONT&gt;&lt;/FONT&gt; - Destination: &lt;FONT id=RadESpellError_65 class=RadEWrongWord&gt;&lt;FONT id=RadESpellError_62 class=RadEWrongWord&gt;XXX&lt;/FONT&gt;&lt;/FONT&gt;.&lt;FONT id=RadESpellError_66 class=RadEWrongWord&gt;&lt;FONT id=RadESpellError_63 class=RadEWrongWord&gt;XXX&lt;/FONT&gt;&lt;/FONT&gt;.&lt;FONT id=RadESpellError_67 class=RadEWrongWord&gt;&lt;FONT id=RadESpellError_64 class=RadEWrongWord&gt;XXX&lt;/FONT&gt;&lt;/FONT&gt;.&lt;FONT id=RadESpellError_68 class=RadEWrongWord&gt;&lt;FONT id=RadESpellError_65 class=RadEWrongWord&gt;&lt;FONT id=RadESpellError_64 class=RadEWrongWord&gt;XXX45&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt; - [Access Policy not found, dropping packet &lt;FONT id=RadESpellError_69 class=RadEWrongWord&gt;&lt;FONT id=RadESpellError_66 class=RadEWrongWord&gt;Src&lt;/FONT&gt;&lt;/FONT&gt; 67 &lt;FONT id=RadESpellError_70 class=RadEWrongWord&gt;&lt;FONT id=RadESpellError_67 class=RadEWrongWord&gt;Dst&lt;/FONT&gt;&lt;/FONT&gt; 68 from WAN]&lt;BR&gt;Tue, 2012-02-21 07:31:07 - &lt;FONT id=RadESpellError_71 class=RadEWrongWord&gt;&lt;FONT id=RadESpellError_68 class=RadEWrongWord&gt;UDP&lt;/FONT&gt;&lt;/FONT&gt; packet - Source: &lt;FONT id=RadESpellError_72 class=RadEWrongWord&gt;&lt;FONT id=RadESpellError_69 class=RadEWrongWord&gt;XXX&lt;/FONT&gt;&lt;/FONT&gt;.&lt;FONT id=RadESpellError_73 class=RadEWrongWord&gt;&lt;FONT id=RadESpellError_70 class=RadEWrongWord&gt;XXX&lt;/FONT&gt;&lt;/FONT&gt;.&lt;FONT id=RadESpellError_74 class=RadEWrongWord&gt;&lt;FONT id=RadESpellError_71 class=RadEWrongWord&gt;XXX&lt;/FONT&gt;&lt;/FONT&gt;.&lt;FONT id=RadESpellError_75 class=RadEWrongWord&gt;&lt;FONT id=RadESpellError_72 class=RadEWrongWord&gt;XXX&lt;/FONT&gt;&lt;/FONT&gt; - Destination: &lt;FONT id=RadESpellError_76 class=RadEWrongWord&gt;&lt;FONT id=RadESpellError_73 class=RadEWrongWord&gt;XXX&lt;/FONT&gt;&lt;/FONT&gt;.&lt;FONT id=RadESpellError_77 class=RadEWrongWord&gt;&lt;FONT id=RadESpellError_74 class=RadEWrongWord&gt;XXX&lt;/FONT&gt;&lt;/FONT&gt;.&lt;FONT id=RadESpellError_78 class=RadEWrongWord&gt;&lt;FONT id=RadESpellError_75 class=RadEWrongWord&gt;XXX&lt;/FONT&gt;&lt;/FONT&gt;.&lt;FONT id=RadESpellError_79 class=RadEWrongWord&gt;&lt;FONT id=RadESpellError_76 class=RadEWrongWord&gt;&lt;FONT id=RadESpellError_75 class=RadEWrongWord&gt;XXX45&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt; - [Access Policy not found, dropping packet &lt;FONT id=RadESpellError_80 class=RadEWrongWord&gt;&lt;FONT id=RadESpellError_77 class=RadEWrongWord&gt;Src&lt;/FONT&gt;&lt;/FONT&gt; 67 &lt;FONT id=RadESpellError_81 class=RadEWrongWord&gt;&lt;FONT id=RadESpellError_78 class=RadEWrongWord&gt;Dst&lt;/FONT&gt;&lt;/FONT&gt; 68 from WAN]&lt;BR&gt;Tue, 2012-02-21 07:31:08 - [Send out &lt;FONT id=RadESpellError_82 class=RadEWrongWord&gt;&lt;FONT id=RadESpellError_79 class=RadEWrongWord&gt;&lt;FONT id=RadESpellError_78 class=RadEWrongWord&gt;NTP&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt; Request to 216.245.57.38]&lt;BR&gt;Tue, 2012-02-21 07:31:23 - [&lt;FONT id=RadESpellError_83 class=RadEWrongWord&gt;&lt;FONT id=RadESpellError_80 class=RadEWrongWord&gt;&lt;FONT id=RadESpellError_79 class=RadEWrongWord&gt;NTP&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt; Reply Invalid]&lt;/P&gt;
&lt;P&gt;000098: &lt;FONT id=RadESpellError_84 class=RadEWrongWord&gt;&lt;FONT id=RadESpellError_81 class=RadEWrongWord&gt;&lt;FONT id=RadESpellError_80 class=RadEWrongWord&gt;Feb&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt; 21 07:31:54.386 &lt;FONT id=RadESpellError_85 class=RadEWrongWord&gt;&lt;FONT id=RadESpellError_82 class=RadEWrongWord&gt;&lt;FONT id=RadESpellError_81 class=RadEWrongWord&gt;PCTime&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;: %SEC-6-&lt;FONT id=RadESpellError_86 class=RadEWrongWord&gt;&lt;FONT id=RadESpellError_83 class=RadEWrongWord&gt;&lt;FONT id=RadESpellError_82 class=RadEWrongWord&gt;IPACCESSLOGDP&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;: list 120 denied &lt;FONT id=RadESpellError_87 class=RadEWrongWord&gt;&lt;FONT id=RadESpellError_84 class=RadEWrongWord&gt;&lt;FONT id=RadESpellError_83 class=RadEWrongWord&gt;icmp&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt; 202.176.209.3 -&amp;gt; &lt;FONT id=RadESpellError_88 class=RadEWrongWord&gt;&lt;FONT id=RadESpellError_85 class=RadEWrongWord&gt;YYY&lt;/FONT&gt;&lt;/FONT&gt;.&lt;FONT id=RadESpellError_89 class=RadEWrongWord&gt;&lt;FONT id=RadESpellError_86 class=RadEWrongWord&gt;YYY&lt;/FONT&gt;&lt;/FONT&gt;.&lt;FONT id=RadESpellError_90 class=RadEWrongWord&gt;&lt;FONT id=RadESpellError_87 class=RadEWrongWord&gt;YYY&lt;/FONT&gt;&lt;/FONT&gt;.&lt;FONT id=RadESpellError_91 class=RadEWrongWord&gt;&lt;FONT id=RadESpellError_88 class=RadEWrongWord&gt;YYY&lt;/FONT&gt;&lt;/FONT&gt; (11/0), 3 packets&lt;/P&gt;
&lt;P&gt;Tue, 2012-02-21 07:32:28 - [Send out &lt;FONT id=RadESpellError_92 class=RadEWrongWord&gt;&lt;FONT id=RadESpellError_89 class=RadEWrongWord&gt;&lt;FONT id=RadESpellError_88 class=RadEWrongWord&gt;NTP&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt; Request to 209.249.181.21]&lt;BR&gt;Tue, 2012-02-21 07:32:29 - [Receive &lt;FONT id=RadESpellError_93 class=RadEWrongWord&gt;&lt;FONT id=RadESpellError_90 class=RadEWrongWord&gt;&lt;FONT id=RadESpellError_89 class=RadEWrongWord&gt;NTP&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt; Reply from 209.249.181.21]&lt;/P&gt;
&lt;P&gt;000099: &lt;FONT id=RadESpellError_94 class=RadEWrongWord&gt;&lt;FONT id=RadESpellError_91 class=RadEWrongWord&gt;&lt;FONT id=RadESpellError_90 class=RadEWrongWord&gt;Feb&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt; 21 09:12:54.386 &lt;FONT id=RadESpellError_95 class=RadEWrongWord&gt;&lt;FONT id=RadESpellError_92 class=RadEWrongWord&gt;&lt;FONT id=RadESpellError_91 class=RadEWrongWord&gt;PCTime&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;: %SEC-6-&lt;FONT id=RadESpellError_96 class=RadEWrongWord&gt;&lt;FONT id=RadESpellError_93 class=RadEWrongWord&gt;&lt;FONT id=RadESpellError_92 class=RadEWrongWord&gt;IPACCESSLOGDP&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;: list 120 denied &lt;FONT id=RadESpellError_97 class=RadEWrongWord&gt;&lt;FONT id=RadESpellError_94 class=RadEWrongWord&gt;&lt;FONT id=RadESpellError_93 class=RadEWrongWord&gt;icmp&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt; 202.176.209.3 -&amp;gt; &lt;FONT id=RadESpellError_98 class=RadEWrongWord&gt;&lt;FONT id=RadESpellError_95 class=RadEWrongWord&gt;YYY&lt;/FONT&gt;&lt;/FONT&gt;.&lt;FONT id=RadESpellError_99 class=RadEWrongWord&gt;&lt;FONT id=RadESpellError_96 class=RadEWrongWord&gt;YYY&lt;/FONT&gt;&lt;/FONT&gt;.&lt;FONT id=RadESpellError_100 class=RadEWrongWord&gt;&lt;FONT id=RadESpellError_97 class=RadEWrongWord&gt;YYY&lt;/FONT&gt;&lt;/FONT&gt;.&lt;FONT id=RadESpellError_101 class=RadEWrongWord&gt;&lt;FONT id=RadESpellError_98 class=RadEWrongWord&gt;YYY&lt;/FONT&gt;&lt;/FONT&gt; (11/0), 3 packets&lt;/P&gt;
&lt;P&gt;&lt;BR&gt;&amp;nbsp;&lt;/P&gt;&lt;/FONT&gt;</description><comments>http://johndodrill.info/2012/02/21/intruder-2021762093-of-singtel-singapore-uses-dns-to-map-lan.aspx#Comments</comments><guid isPermaLink="false">5648fade-2519-4fcc-bb1f-72aa5cdf9000</guid><pubDate>Tue, 21 Feb 2012 18:20:30 GMT</pubDate></item><item><title>Sender Policy Framework: Protect Your Domain Reputation From SPAM</title><link>http://johndodrill.info/2012/02/18/sender-policy-framework-protect-your-domain-reputation-from-spam.aspx?ref=rss</link><dc:creator>John Dodrill</dc:creator><description>&lt;font style="font-size: 14px;" face="arial"&gt;&lt;font face="arial"&gt;&lt;font style="font-size: 14px;"&gt;&lt;/font&gt;&lt;font style="font-size: 14px;"&gt;&lt;/font&gt;&lt;font style="font-size: 14px;"&gt;&lt;/font&gt;&lt;font style="font-size: 14px;"&gt;&lt;/font&gt;&lt;img style="float: left; border: 0px solid; width: 450px; height: 232px; margin: 5px;" src="http://images.quickblogcast.com/0/1/4/2/9/203072-192410/spf.jpg?a=15" alt="Sender Policy Framework" longdesc="Visual description of a Sender Policy Framework DNS record."&gt;&lt;br&gt;
One of the more correct responses to hackers (computer people) devaluating your assigned IP's, your domain names and your email addresses, by sending SPAM in your name, is called &lt;a target="_blank" href="http://www.openspf.net"&gt;Sender Policy Framework&lt;/a&gt; (RFC 4408).&amp;nbsp; &lt;a href="http://OpenSPF.org" target="_blank" class=""&gt;http://OpenSPF.org&lt;/a&gt; is the most commonly cited authority on the subject, however when their Web site is under attack or otherwise unavailable, there is also &lt;a href="http://OpenSPF.net" target="_blank" class=""&gt;http://OpenSPF.net&lt;/a&gt;, which seems to be a mirror site.&lt;br&gt;
&lt;br&gt;
Sender Policy Framework (SPF) is simply a TXT and / or SPF record that you put in your domain and Web server's &lt;a title="Wikipedia: Domain Name System" href="https://en.wikipedia.org/wiki/Domain_Name_System" target="_blank" class=""&gt;Domain Name System (DNS)&lt;/a&gt;.&amp;nbsp; If you have a hosting company handle that for you, they'll likely do it on request, hopefully without charge.&lt;br&gt;
&lt;/font&gt;&lt;br&gt;
There have been "Wizard's" on the Web, that have come and gone, to help you with the syntax and implementation of SPF.&amp;nbsp; My favorite &lt;i&gt;de jour&lt;/i&gt; is (oddly) from &lt;a target="_blank" href="http://www.microsoft.com/mscorp/safety/content/technologies/senderid/wizard/" title="Microsoft Sender ID Framework SPF Record Wizard "&gt;Microsoft&lt;/a&gt;.&amp;nbsp; The wizard will help you with the syntax of the TXT and / or SPF record for your DNS (intended to support RFC 2822 and / or RFC 2821).&amp;nbsp; Whether you implement SPF yourself or you have your hosting company implement if for you, you can and should test the code, on a domain-by-domain basis from another &lt;a target="_blank" href="http://www.kitterman.com/spf/validate.html" title="SPF Record Testing Tools -- Kitterman.com"&gt;wizard&lt;/a&gt; on the Web, to insure it is at least implemented correctly.&lt;br&gt;
&lt;br&gt;
It seems odd that I would choose Microsoft to support SPF, in light of their competing &lt;a target="_blank" href="http://www.microsoft.com/mscorp/safety/technologies/senderid/default.mspx"&gt;Sender ID&lt;/a&gt;.&amp;nbsp; I think it's because the &lt;a target="_blank" href="http://www.openspf.net/SPF_Record_Syntax" title="SPF Record Syntax"&gt;DNS record syntax&lt;/a&gt;'s are much the same. In example, the SPF code I might chose and that provided by Microsoft's robot seem to differ in approach, more than syntax:&lt;br&gt;
&lt;br&gt;
&lt;a target="_blank" href="http://docs.cpanel.net/twiki/bin/view/AllDocumentation/CpanelDocs/EmailAuthentication#Set%20up%20SPF" title="cPanel Email Authentication "&gt;cPanel&lt;/a&gt; approach: "&lt;code&gt;v=spf1 a mx ip4:XXX.XXX.XXX.XXX ip4:YYY.YYY.YYY.YYY -all
&lt;/code&gt;"&lt;br&gt;
&lt;br&gt;
Microsoft's approach: "v=spf1 ip4:&lt;font style="font-size: 14px;" face="arial"&gt;&lt;code&gt;YYY.YYY.YYY.YYY&lt;/code&gt;&lt;/font&gt; -all"&lt;br&gt;
&lt;br&gt;
cPanel's version (above) says mail can only be sent from the domain's mail server or from the domain server itself, assuming the IP's are not the same.&amp;nbsp; Microsoft's version (above -- depending on the data you put into the wizard) says email may only be sent from the domain server.&lt;br&gt;
&lt;br&gt;
The record is inserted into your DNS, as one example:&lt;br&gt;
&lt;br&gt;
exampledomain.com&amp;nbsp;&amp;nbsp;&amp;nbsp; IN&amp;nbsp;&amp;nbsp;&amp;nbsp; TXT&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;font style="font-size: 14px;" face="arial"&gt;"v=spf1 ip4:&lt;font style="font-size: 14px;" face="arial"&gt;&lt;code&gt;YYY.YYY.YYY.YYY&lt;/code&gt;&lt;/font&gt; -all"&lt;/font&gt;&lt;br&gt;
&lt;font style="font-size: 14px;" face="arial"&gt;exampledomain.com&amp;nbsp;&amp;nbsp;&amp;nbsp; IN&amp;nbsp;&amp;nbsp;&amp;nbsp; SPF &amp;nbsp;&amp;nbsp; &lt;font style="font-size: 14px;" face="arial"&gt;"v=spf1 ip4:&lt;font style="font-size: 14px;" face="arial"&gt;&lt;code&gt;YYY.YYY.YYY.YYY&lt;/code&gt;&lt;/font&gt; -all"&lt;/font&gt;&lt;br&gt;
&lt;/font&gt;&lt;br&gt;
The SPF and TXT records have the same content.&amp;nbsp; According the the &lt;a title="Kitterman.com" href="http://www.kitterman.com/spf/validate.html" target="_blank" class=""&gt;SPF Testing Tools site&lt;/a&gt;, "SPF records should also be published in DNS as type SPF records".&amp;nbsp; That said, cPanel and Web Host Manager don't support "SPF" type DNS records natively, so those users will have to be content with having SPF implemented in a TXT record.&lt;br&gt;&lt;br&gt;&lt;/font&gt;&lt;div align="center"&gt;&lt;font style="font-size: 14px;" face="arial"&gt;&lt;img longdesc="SPAM: Controlling the Assault of Non-Solicited Pornography And Marketing Act of 2003" alt="The other SPAM" src="http://images.quickblogcast.com/0/1/4/2/9/203072-192410/SPAM.jpg?a=40" style="border: 0px solid;"&gt;&lt;/font&gt;&lt;br&gt;&lt;/div&gt;&lt;font style="font-size: 14px;" face="arial"&gt;
&lt;br&gt;
Email was the 3rd attack on my Web presence.&amp;nbsp; SPF, together with a secure certificate on the mail server, seems to have handled the &lt;a title="Wikipedia: Controlling the Assault of Non-Solicited Pornography And Marketing Act of 2003" href="https://en.wikipedia.org/wiki/CAN-SPAM_Act_of_2003" target="_blank" class=""&gt;SPAM&lt;/a&gt; forging problem in large part.&amp;nbsp; &lt;a href="http://www.digitalsanctuary.com/tech-blog/debian/setting-up-spf-senderid-domain-keys-and-dkim.html" target="_blank" class=""&gt;There are other choices that can be made on your mail server which restrict Simple Mail Transport Protocol (SMTP) mailings to those senders that can authenticate their domain and/or IP address, including Domain Keys (DKIM)&lt;/a&gt;.&amp;nbsp; Thereby, &lt;a title="Carnegie Mellon University" href="http://asg.web.cmu.edu/sasl/" target="_blank" class=""&gt;Simple Authentication and Security Layer (SASL) &lt;/a&gt;become's an unnecessary option (unless a secure certificate is not an option, as in the case of shared hosting).&lt;br&gt;
&lt;br&gt;
The 1st type of attack on my Web presence began while attending a local computer certification school, having been exposed to more job competitiveness, I found my Web site under constant attack.&amp;nbsp; No big deal, as the hackers found out: I can bring the Web site up faster than they can take it down, so they turned to attacking my Internet connection.&amp;nbsp; That had been an off-and-on thing that was a major impediment to my getting more certifications, as some of the mandatory training is on the Web.&lt;br&gt;
&lt;br&gt;
I resolved the majority of the 2nd type of Web attacks by writing a&amp;nbsp;&lt;a target="_blank" href="http://johndodrill.info/2012/01/31/script-attempting-cisco-861-and-ios-to-mitigate-hacking.aspx"&gt;script in Cisco IOS&lt;/a&gt; &lt;font style="font-size: 14px;" face="arial"&gt;for a Cisco 860/880
firewall (OK, security device for you Cisco sticklers).&amp;nbsp; The
consumer routers weren't even seeing the hackers as they blew past those
appliances.&amp;nbsp; (Those other routers had been&amp;nbsp;marketed as firewalls and were by no means
inexpensive.)&amp;nbsp; &lt;/font&gt;The script continues to mature as I understand more about the nature of the problem.&amp;nbsp; That router (along with a &lt;u&gt;&lt;a href="http://johndodrill.info/2012/01/26/hacking-updated-script-to-remove-hidden-shares-2.aspx" target="_blank" class=""&gt;Windows script&lt;/a&gt;&lt;/u&gt;) has afforded me the possibility of getting back on the Web without some hacker taking my computers or network apart.&amp;nbsp; (I muse as who whom actually employs these hacker people, who are obviously computer people, and sees fit to allow them behind &lt;i&gt;their&lt;/i&gt; company's firewall....)&amp;nbsp; &lt;br&gt;
&lt;br&gt;
&lt;br&gt;
&lt;/font&gt;
&lt;div style="" align="center"&gt;&lt;font style="font-size: 22px;" color="#002060" face="arial"&gt;My solution for Denial of Service Attacks may be to simply take the Road Runner modem back to Time Warner&lt;/font&gt;....&lt;br&gt;
&lt;/div&gt;
&lt;font style="font-size: 14px;" face="arial"&gt;&lt;br&gt;
One of the most recent attacks seems to be a &lt;a target="_blank" href="http://news.cnet.com/2100-1017-236728.html"&gt;Denial of Service Attack&lt;/a&gt;.&amp;nbsp; According to Carnegie Mellon University's Computer Emergency Response Team (&lt;a target="_blank" href="http://www.us-cert.gov/" title="US-CERT is part of the Department of Homeland Security."&gt;CERT&lt;/a&gt; -- now part of the Department of Homeland Security): "&lt;font face="arial,geneva,helvetica"&gt;&lt;a target="_blank" href="http://www.us-cert.gov/cas/tips/ST04-015.html" title="What is a distributed denial-of-service (DDoS) attack?"&gt;Unfortunately, there are no effective ways to prevent being the victim of a DoS or DDoS attack&lt;/a&gt;".&amp;nbsp; &lt;/font&gt;It's a stand-off.&amp;nbsp; I can't get data out or in past my Road Runner modem, and those out in Road-Runner-land can't get data in past my Cisco firewall.&amp;nbsp; My solution for Denial of Service Attacks may be to simply take the Road Runner modem back to Time Warner and have them seek other customers who &lt;i&gt;are&lt;/i&gt; willing to pay by the month for Internet access that only works &lt;font style="font-size: 14px;" face="arial"&gt; intermittent&lt;/font&gt;ly.&amp;nbsp; &lt;br&gt;
&lt;br&gt;
&lt;font color="#cc0000"&gt;&lt;b&gt;Typical connection&lt;/b&gt;&lt;/font&gt;:&lt;br&gt;
&amp;nbsp;&lt;img alt="" style="border: 0px solid;" src="http://images.quickblogcast.com/0/1/4/2/9/203072-192410/synacknormal.gif?a=82"&gt;&lt;br&gt;
&lt;br&gt;
&lt;br&gt;
&lt;font color="#cc0000"&gt;&lt;b&gt;"Denial of service" attack&lt;/b&gt;&lt;/font&gt;: &lt;br&gt;
&lt;img alt="" style="border: 0px solid;" src="http://images.quickblogcast.com/0/1/4/2/9/203072-192410/synackevil.gif?a=99"&gt;&lt;br&gt;
&lt;br&gt;
(Thanks to &lt;a href="http://news.cnet.com/2100-1017-236728.html"&gt;news.cnet.com/2100-1017-236728.html&lt;/a&gt; for the images.)&lt;br&gt;
&lt;br&gt;
You don't want your only Internet service provider to be Road Runner, as I recently found out.&amp;nbsp; Apparently someone used a Man-in-the-Middle ARP attack to access some of my email accounts, change the password, and delete offers from potential employers.&amp;nbsp; (I have to wonder how many they deleted before an employer finally called to see if I had received their email.)&lt;br&gt;
&lt;br&gt;
I have found &lt;a target="_blank" href="http://arpon.sourceforge.net" title="ArpON (ARP handler inspection) is a portable handler daemon that make ARP protocol secure in order to avoid the Man In The Middle (MITM) attack through ARP Spoofing, ARP Cache Poisoning or ARP Poison Routing (APR) attacks."&gt;ARP protection software&lt;/a&gt; for Linux / Unix (&lt;a target="_blank" href="http://johndodrill.info/2012/02/04/slackware-linux-much-better-than-windows-and-free.aspx" title="SlackWare Linux: Much Better Than Windows And FREE!!!"&gt;Slackware&lt;/a&gt;, in my case), to protect against Man-in-the-Middle attacks, but haven't tested any for Windows, so far.&amp;nbsp; More about ARP and DDOS attacks later.&lt;br&gt;
&lt;br&gt;
&lt;/font&gt;</description><comments>http://johndodrill.info/2012/02/18/sender-policy-framework-protect-your-domain-reputation-from-spam.aspx#Comments</comments><guid isPermaLink="false">8cbfc644-4590-4f7b-b2ac-834af87a2796</guid><pubDate>Sat, 18 Feb 2012 12:07:19 GMT</pubDate></item></channel></rss>
