Ich habe in letzter Zeit mehre merkwürdige Log Einträge im messages Log und im warn log gefunden.
messages Auszug:
Code: Select all
Jan 4 23:03:01 * kernel: printk: 1 messages suppressed.
Jan 4 23:03:01 * kernel: TCP: Treason uncloaked! Peer 84.177.228.121:2289/13000 shrinks window 2863943461:2863944913. Repaired.
Jan 4 23:03:07 * kernel: printk: 2 messages suppressed.
Jan 4 23:03:07 * kernel: TCP: Treason uncloaked! Peer 84.177.228.121:2289/13000 shrinks window 2864007349:2864010253. Repaired.
Jan 4 23:03:12 * kernel: printk: 3 messages suppressed.
Jan 4 23:03:12 * kernel: TCP: Treason uncloaked! Peer 84.177.228.121:2289/13000 shrinks window 2864069785:2864074141. Repaired.
Jan 4 23:03:17 * kernel: printk: 4 messages suppressed.
Jan 4 23:03:17 * kernel: TCP: Treason uncloaked! Peer 84.177.228.121:2289/13000 shrinks window 2864139481:2864143837. Repaired.
Jan 4 23:03:21 * kernel: printk: 3 messages suppressed.
Jan 4 23:03:21 * kernel: TCP: Treason uncloaked! Peer 84.9.37.113:63491/13000 shrinks window 2673474114:2673479814. Repaired.
Jan 4 23:03:26 * kernel: printk: 2 messages suppressed.
Jan 4 23:03:26 * kernel: TCP: Treason uncloaked! Peer 84.9.37.113:63491/13000 shrinks window 2673539649:2673544054. Repaired.
Jan 4 23:03:31 * kernel: printk: 5 messages suppressed.
Jan 4 23:03:31 * kernel: TCP: Treason uncloaked! Peer 84.177.228.121:2289/13000 shrinks window 2864293393:2864299201. Repaired.
Jan 4 23:03:37 * kernel: printk: 3 messages suppressed.
Jan 4 23:03:37 * kernel: TCP: Treason uncloaked! Peer 84.177.228.121:2289/13000 shrinks window 2864361637:2864367445. Repaired.
Jan 4 23:03:42 * kernel: printk: 1 messages suppressed.
Jan 4 23:03:42 * kernel: TCP: Treason uncloaked! Peer 84.177.228.121:2289/13000 shrinks window 2864426977:2864434237. Repaired.
Jan 4 23:03:47 * kernel: TCP: Treason uncloaked! Peer 84.177.228.121:2289/13000 shrinks window 2864496673:2864498125. Repaired.
Jan 4 23:03:51 * kernel: printk: 2 messages suppressed.
Jan 4 23:03:51 * kernel: TCP: Treason uncloaked! Peer 84.9.37.113:63491/13000 shrinks window 2673867324:2673868174. Repaired.
Jan 4 23:03:56 * kernel: printk: 5 messages suppressed.
Jan 4 23:03:56 * kernel: TCP: Treason uncloaked! Peer 84.177.228.121:2289/13000 shrinks window 2864609929:2864617189. Repaired.
Code: Select all
Jan 5 00:05:49 * kernel: printk: 1 messages suppressed.
Jan 5 00:06:16 * kernel: printk: 1 messages suppressed.
Jan 5 00:06:22 * kernel: printk: 2 messages suppressed.
Jan 5 00:06:29 * kernel: printk: 2 messages suppressed.
Jan 5 00:06:37 * kernel: printk: 1 messages suppressed.
Jan 5 00:06:42 * kernel: printk: 2 messages suppressed.
Jan 5 00:06:51 * kernel: printk: 1 messages suppressed.
Jan 5 00:06:56 * kernel: printk: 1 messages suppressed.
Jan 5 00:07:05 * kernel: printk: 3 messages suppressed.
Jan 5 00:07:11 * kernel: printk: 1 messages suppressed.
Ich habe pro Tag ca. 100 Einträge in beiden Logs von unterschiedlichen ips meistens aber von der Deutschen Telekom.
Ich habe gelesen das es Anzeichen sein können für einen DDOS Angriff, gibt es noch andere Ursachen für diese Meldungen ?