[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[cobalt-security] After checking logs found this...



Hi Yah,

This evening after checking my logs I found several attempts to break in via
FTP hacks - but what was unusual and has me a bit concerned is the following
found also in the log:- xxx denoting one of our IP's

Sep  5 20:36:54 ns kernel: Suspect short first fragment.
Sep  5 20:36:54 ns kernel: eth0 PROTO=6 212.113.188.46:0 xxx.xxx.xxx.xxx:0
L=20 S=0x00 I=26716 F=0x6000 T=116 (#0)

The other IP was from one of those IP's trying to get in via FTP

Can someone shed a light on this for me please :>

Regards

Chae