> Also wenn nach Freischalten der Ports ein Programm oder eine Erweiterung installiert wird die auch aktiv ist, wenn Sipgate beendet wird. Dieses Programm könnte dann über den offenen Port jemandem Zugang zum Computer schaffen.
so arbeiten trojaner und bots, soweit ich das verstanden habe.
ergaenzung zum posting von gestern: bei halbwegs brauchbaren routern kann man auch ausgehende verbindungen blocken. aber da sollte man halbwegs wissen, was man will und tut, sonst ist das lan ploetzlich so sicher, dass man ueberhaupt nicht mehr raus kommt.
da hatte ich zb tcp port 25 ausgehend geblockt, weil ich mir einen wurm eingefangen hatte, der mails versenden wollte und natuerlich als allererstes virenscanner und sw-firewall schachmatt gesetzt und noch ein paar programme ausgeschaltet hatte
- Code: Alles auswählen
No. Time Source IP Destination IP Note
1|10/03/2004 10:49:31 |192.168.0.5:4035 |129.59.1.22:25
|ACCESS BLOCK Firewall rule match: TCP (L to W, rule:1)
2|10/03/2004 10:49:30 |192.168.0.5:4027 |132.236.56.25:25
|ACCESS BLOCK Firewall rule match: TCP (L to W, rule:1)
3|10/03/2004 10:49:29 |192.168.0.5:4033 |198.174.169.145:25
|ACCESS BLOCK Firewall rule match: TCP (L to W, rule:1)
4|10/03/2004 10:49:29 |192.168.0.5:4017 |209.196.77.100:25
|ACCESS BLOCK Firewall rule match: TCP (L to W, rule:1)
5|10/03/2004 10:49:29 |192.168.0.5:4031 |142.150.98.171:25
|ACCESS BLOCK Firewall rule match: TCP (L to W, rule:1)
6|10/03/2004 10:49:29 |192.168.0.5:4012 |142.150.98.171:25
|ACCESS BLOCK Firewall rule match: TCP (L to W, rule:1)
7|10/03/2004 10:49:27 |192.168.0.5:4027 |132.236.56.25:25
|ACCESS BLOCK Firewall rule match: TCP (L to W, rule:1)
8|10/03/2004 10:49:27 |192.168.0.5:4002 |128.230.18.29:25
|ACCESS BLOCK Firewall rule match: TCP (L to W, rule:1)
9|10/03/2004 10:49:26 |192.168.0.5:4017 |209.196.77.100:25
|ACCESS BLOCK Firewall rule match: TCP (L to W, rule:1)
10|10/03/2004 10:49:26 |192.168.0.5:4012 |142.150.98.171:25
|ACCESS BLOCK Firewall rule match: TCP (L to W, rule:1)
11|10/03/2004 10:49:24 |192.168.0.5:4002 |128.230.18.29:25
|ACCESS BLOCK Firewall rule match: TCP (L to W, rule:1)
12|10/03/2004 10:49:24 |192.168.0.5:3974 |130.85.12.6:25
|ACCESS BLOCK Firewall rule match: TCP (L to W, rule:1)
13|10/03/2004 10:49:23 |192.168.0.5:3973 |150.131.192.157:25
|ACCESS BLOCK Firewall rule match: TCP (L to W, rule:1)
14|10/03/2004 10:49:20 |195.58.161.5:1049 |172.16.201.4:161
|ATTACK ip spoofing - WAN UDP
15|10/03/2004 10:49:19 |192.168.0.5:3953 |213.52.211.139:25
|ACCESS BLOCK Firewall rule match: TCP (L to W, rule:1)
16|10/03/2004 10:49:19 |192.168.0.5:3952 |132.181.2.36:25
|ACCESS BLOCK Firewall rule match: TCP (L to W, rule:1)
17|10/03/2004 10:49:18 |192.168.0.5:3974 |130.85.12.6:25
|ACCESS BLOCK Firewall rule match: TCP (L to W, rule:1)
18|10/03/2004 10:49:17 |192.168.0.5:3942 |129.71.2.2:25
|ACCESS BLOCK Firewall rule match: TCP (L to W, rule:1)
19|10/03/2004 10:49:17 |192.168.0.5:3938 |129.110.10.17:25
|ACCESS BLOCK Firewall rule match: TCP (L to W, rule:1)
20|10/03/2004 10:49:17 |192.168.0.5:3973 |150.131.192.157:25
|ACCESS BLOCK Firewall rule match: TCP (L to W, rule:1)
21|10/03/2004 10:49:15 |192.168.0.5:3932 |207.172.4.98:25
|ACCESS BLOCK Firewall rule match: TCP (L to W, rule:1)
22|10/03/2004 10:49:15 |192.168.0.5:3974 |130.85.12.6:25
|ACCESS BLOCK Firewall rule match: TCP (L to W, rule:1)
23|10/03/2004 10:49:14 |192.168.0.5:3924 |209.196.77.100:25
|ACCESS BLOCK Firewall rule match: TCP (L to W, rule:1)
24|10/03/2004 10:49:14 |192.168.0.5:3973 |150.131.192.157:25
|ACCESS BLOCK Firewall rule match: TCP (L to W, rule:1)
25|10/03/2004 10:49:14 |192.168.0.5:3920 |129.110.10.17:25
|ACCESS BLOCK Firewall rule match: TCP (L to W, rule:1)
26|10/03/2004 10:49:13 |192.168.0.5:3953 |213.52.211.139:25
|ACCESS BLOCK Firewall rule match: TCP (L to W, rule:1)
27|10/03/2004 10:49:13 |192.168.0.5:3952 |132.181.2.36:25
|ACCESS BLOCK Firewall rule match: TCP (L to W, rule:1)
28|10/03/2004 10:49:12 |192.168.0.5:3908 |205.188.159.217:25
|ACCESS BLOCK Firewall rule match: TCP (L to W, rule:1)
29|10/03/2004 10:49:12 |192.168.0.5 |
|User:admin Successful WEB login
30|10/03/2004 10:49:11 |192.168.0.5:3942 |129.71.2.2:25
|ACCESS BLOCK Firewall rule match: TCP (L to W, rule:1)
31|10/03/2004 10:49:11 |192.168.0.5:3938 |129.110.10.17:25
|ACCESS BLOCK Firewall rule match: TCP (L to W, rule:1)
32|10/03/2004 10:49:10 |192.168.0.5:3953 |213.52.211.139:25
|ACCESS BLOCK Firewall rule match: TCP (L to W, rule:1)
33|10/03/2004 10:49:10 |192.168.0.5:3952 |132.181.2.36:25
|ACCESS BLOCK Firewall rule match: TCP (L to W, rule:1)
34|10/03/2004 10:49:09 |192.168.0.5:3932 |207.172.4.98:25
|ACCESS BLOCK Firewall rule match: TCP (L to W, rule:1)
35|10/03/2004 10:49:08 |192.168.0.5:3942 |129.71.2.2:25
|ACCESS BLOCK Firewall rule match: TCP (L to W, rule:1)
36|10/03/2004 10:49:08 |192.168.0.5:3924 |209.196.77.100:25
|ACCESS BLOCK Firewall rule match: TCP (L to W, rule:1)
37|10/03/2004 10:49:08 |192.168.0.5:3938 |129.110.10.17:25
|ACCESS BLOCK Firewall rule match: TCP (L to W, rule:1)
38|10/03/2004 10:49:08 |192.168.0.5:3920 |129.110.10.17:25
|ACCESS BLOCK Firewall rule match: TCP (L to W, rule:1)
39|10/03/2004 10:49:07 |195.58.161.5:1049 |172.16.201.4:161
|ATTACK ip spoofing - WAN UDP
40|10/03/2004 10:49:06 |192.168.0.5:3932 |207.172.4.98:25
|ACCESS BLOCK Firewall rule match: TCP (L to W, rule:1)
41|10/03/2004 10:49:06 |192.168.0.5:3908 |205.188.159.217:25
|ACCESS BLOCK Firewall rule match: TCP (L to W, rule:1)
42|10/03/2004 10:49:05 |192.168.0.5:3924 |209.196.77.100:25
|ACCESS BLOCK Firewall rule match: TCP (L to W, rule:1)
43|10/03/2004 10:49:05 |192.168.0.5:3920 |129.110.10.17:25
|ACCESS BLOCK Firewall rule match: TCP (L to W, rule:1)
44|10/03/2004 10:49:03 |192.168.0.5:3908 |205.188.159.217:25
|ACCESS BLOCK Firewall rule match: TCP (L to W, rule:1)
45|10/03/2004 10:49:03 |192.168.0.5:3849 |140.141.2.47:25
|ACCESS BLOCK Firewall rule match: TCP (L to W, rule:1)
46|10/03/2004 10:49:02 |192.168.0.5:3842 |129.81.255.234:25
|ACCESS BLOCK Firewall rule match: TCP (L to W, rule:1)
47|10/03/2004 10:48:58 |192.168.0.5:3819 |134.117.1.18:25
|ACCESS BLOCK Firewall rule match: TCP (L to W, rule:1)
48|10/03/2004 10:48:58 |192.168.0.5:3816 |198.17.40.7:25
|ACCESS BLOCK Firewall rule match: TCP (L to W, rule:1)
49|10/03/2004 10:48:57 |192.168.0.5:3849 |140.141.2.47:25
|ACCESS BLOCK Firewall rule match: TCP (L to W, rule:1)
50|10/03/2004 10:48:56 |192.168.0.5:3806 |129.71.2.2:25
|ACCESS BLOCK Firewall rule match: TCP (L to W, rule:1)
51|10/03/2004 10:48:56 |192.168.0.5:3803 |216.17.3.38:25
|ACCESS BLOCK Firewall rule match: TCP (L to W, rule:1)
52|10/03/2004 10:48:56 |192.168.0.5:3842 |129.81.255.234:25
|ACCESS BLOCK Firewall rule match: TCP (L to W, rule:1)
53|10/03/2004 10:48:55 |195.58.161.5:1049 |172.16.201.4:161
|ATTACK ip spoofing - WAN UDP
54|10/03/2004 10:48:54 |192.168.0.5:3791 |159.28.1.93:25
|ACCESS BLOCK Firewall rule match: TCP (L to W, rule:1)
55|10/03/2004 10:48:54 |192.168.0.5:3849 |140.141.2.47:25
|ACCESS BLOCK Firewall rule match: TCP (L to W, rule:1)
56|10/03/2004 10:48:53 |192.168.0.5:3785 |131.96.5.77:25
|ACCESS BLOCK Firewall rule match: TCP (L to W, rule:1)
57|10/03/2004 10:48:53 |192.168.0.5:3842 |129.81.255.234:25
|ACCESS BLOCK Firewall rule match: TCP (L to W, rule:1)
58|10/03/2004 10:48:53 |192.168.0.5:3780 |129.89.169.226:25
|ACCESS BLOCK Firewall rule match: TCP (L to W, rule:1)
59|10/03/2004 10:48:52 |192.168.0.5:3819 |134.117.1.18:25
|ACCESS BLOCK Firewall rule match: TCP (L to W, rule:1)
60|10/03/2004 10:48:52 |192.168.0.5:3816 |198.17.40.7:25
|ACCESS BLOCK Firewall rule match: TCP (L to W, rule:1)
61|10/03/2004 10:48:51 |192.168.0.5:3772 |128.8.10.164:25
|ACCESS BLOCK Firewall rule match: TCP (L to W, rule:1)
62|10/03/2004 10:48:50 |192.168.0.5:3806 |129.71.2.2:25
|ACCESS BLOCK Firewall rule match: TCP (L to W, rule:1)
63|10/03/2004 10:48:50 |192.168.0.5:3803 |216.17.3.38:25
|ACCESS BLOCK Firewall rule match: TCP (L to W, rule:1)
64|10/03/2004 10:48:49 |192.168.0.5:3819 |134.117.1.18:25
|ACCESS BLOCK Firewall rule match: TCP (L to W, rule:1)
65|10/03/2004 10:48:49 |192.168.0.5:3816 |198.17.40.7:25
|ACCESS BLOCK Firewall rule match: TCP (L to W, rule:1)
66|10/03/2004 10:48:48 |192.168.0.5:3791 |159.28.1.93:25
|ACCESS BLOCK Firewall rule match: TCP (L to W, rule:1)
67|10/03/2004 10:48:47 |192.168.0.5:3806 |129.71.2.2:25
|ACCESS BLOCK Firewall rule match: TCP (L to W, rule:1)
68|10/03/2004 10:48:47 |192.168.0.5:3785 |131.96.5.77:25
|ACCESS BLOCK Firewall rule match: TCP (L to W, rule:1)
69|10/03/2004 10:48:47 |192.168.0.5:3803 |216.17.3.38:25
|ACCESS BLOCK Firewall rule match: TCP (L to W, rule:1)
70|10/03/2004 10:48:47 |192.168.0.5:3780 |129.89.169.226:25
|ACCESS BLOCK Firewall rule match: TCP (L to W, rule:1)
71|10/03/2004 10:48:45 |192.168.0.5:3791 |159.28.1.93:25
|ACCESS BLOCK Firewall rule match: TCP (L to W, rule:1)
72|10/03/2004 10:48:45 |192.168.0.5:3772 |128.8.10.164:25
|ACCESS BLOCK Firewall rule match: TCP (L to W, rule:1)
73|10/03/2004 10:48:44 |192.168.0.5:3785 |131.96.5.77:25
|ACCESS BLOCK Firewall rule match: TCP (L to W, rule:1)
74|10/03/2004 10:48:44 |192.168.0.5:3780 |129.89.169.226:25
|ACCESS BLOCK Firewall rule match: TCP (L to W, rule:1)
75|10/03/2004 10:48:42 |192.168.0.5:3772 |128.8.10.164:25
|ACCESS BLOCK Firewall rule match: TCP (L to W, rule:1)
76|10/03/2004 10:48:42 |192.168.0.5:3730 |205.188.159.217:25
|ACCESS BLOCK Firewall rule match: TCP (L to W, rule:1)
77|10/03/2004 10:48:41 |192.168.0.5:3721 |128.230.18.5:25
|ACCESS BLOCK Firewall rule match: TCP (L to W, rule:1)
78|10/03/2004 10:48:37 |192.168.0.5:3698 |192.207.174.6:25
|ACCESS BLOCK Firewall rule match: TCP (L to W, rule:1)
79|10/03/2004 10:48:37 |192.168.0.5:3695 |65.54.190.179:25
|ACCESS BLOCK Firewall rule match: TCP (L to W, rule:1)
80|10/03/2004 10:48:36 |192.168.0.5:3730 |205.188.159.217:25
|ACCESS BLOCK Firewall rule match: TCP (L to W, rule:1)
81|10/03/2004 10:48:35 |192.168.0.5:3677 |129.74.250.225:25
|ACCESS BLOCK Firewall rule match: TCP (L to W, rule:1)
82|10/03/2004 10:48:35 |192.168.0.5:3672 |66.153.24.5:25
|ACCESS BLOCK Firewall rule match: TCP (L to W, rule:1)
83|10/03/2004 10:48:35 |192.168.0.5:3721 |128.230.18.5:25
|ACCESS BLOCK Firewall rule match: TCP (L to W, rule:1)
84|10/03/2004 10:48:33 |192.168.0.5:3654 |207.188.202.86:25
|ACCESS BLOCK Firewall rule match: TCP (L to W, rule:1)
85|10/03/2004 10:48:33 |192.168.0.5:3730 |205.188.159.217:25
|ACCESS BLOCK Firewall rule match: TCP (L to W, rule:1)
86|10/03/2004 10:48:32 |192.168.0.5:3641 |128.122.2.137:25
|ACCESS BLOCK Firewall rule match: TCP (L to W, rule:1)
87|10/03/2004 10:48:32 |192.168.0.5:3721 |128.230.18.5:25
|ACCESS BLOCK Firewall rule match: TCP (L to W, rule:1)
88|10/03/2004 10:48:32 |192.168.0.5:3638 |66.153.24.5:25
|ACCESS BLOCK Firewall rule match: TCP (L to W, rule:1)
89|10/03/2004 10:48:31 |192.168.0.5:3698 |192.207.174.6:25
|ACCESS BLOCK Firewall rule match: TCP (L to W, rule:1)
90|10/03/2004 10:48:31 |192.168.0.5:3695 |65.54.190.179:25
|ACCESS BLOCK Firewall rule match: TCP (L to W, rule:1)
91|10/03/2004 10:48:31 |192.168.0.5:3626 |136.142.186.16:25
|ACCESS BLOCK Firewall rule match: TCP (L to W, rule:1)
92|10/03/2004 10:48:30 |192.168.0.5:3677 |129.74.250.225:25
|ACCESS BLOCK Firewall rule match: TCP (L to W, rule:1)
93|10/03/2004 10:48:30 |192.168.0.5:3672 |66.153.24.5:25
|ACCESS BLOCK Firewall rule match: TCP (L to W, rule:1)
94|10/03/2004 10:48:29 |192.168.0.5:3698 |192.207.174.6:25
|ACCESS BLOCK Firewall rule match: TCP (L to W, rule:1)
95|10/03/2004 10:48:29 |192.168.0.5:3695 |65.54.190.179:25
|ACCESS BLOCK Firewall rule match: TCP (L to W, rule:1)
96|10/03/2004 10:48:28 |192.168.0.5:3654 |207.188.202.86:25
|ACCESS BLOCK Firewall rule match: TCP (L to W, rule:1)
97|10/03/2004 10:48:27 |192.168.0.5:3677 |129.74.250.225:25
|ACCESS BLOCK Firewall rule match: TCP (L to W, rule:1)
98|10/03/2004 10:48:27 |192.168.0.5:3672 |66.153.24.5:25
|ACCESS BLOCK Firewall rule match: TCP (L to W, rule:1)
99|10/03/2004 10:48:27 |192.168.0.5:3641 |128.122.2.137:25
|ACCESS BLOCK Firewall rule match: TCP (L to W, rule:1)
100|10/03/2004 10:48:27 |192.168.0.5:3638 |66.153.24.5:25
|ACCESS BLOCK Firewall rule match: TCP (L to W, rule:1)
101|10/03/2004 10:48:25 |192.168.0.5:3654 |207.188.202.86:25
|ACCESS BLOCK Firewall rule match: TCP (L to W, rule:1)
102|10/03/2004 10:48:25 |192.168.0.5:3626 |136.142.186.16:25
|ACCESS BLOCK Firewall rule match: TCP (L to W, rule:1)
103|10/03/2004 10:48:24 |192.168.0.5:3641 |128.122.2.137:25
|ACCESS BLOCK Firewall rule match: TCP (L to W, rule:1)
104|10/03/2004 10:48:24 |192.168.0.5:3638 |66.153.24.5:25
|ACCESS BLOCK Firewall rule match: TCP (L to W, rule:1)
105|10/03/2004 10:48:22 |192.168.0.5:3626 |136.142.186.16:25
|ACCESS BLOCK Firewall rule match: TCP (L to W, rule:1)
106|10/03/2004 10:48:22 |192.168.0.5:3549 |128.32.61.103:25
|ACCESS BLOCK Firewall rule match: TCP (L to W, rule:1)
107|10/03/2004 10:48:20 |192.168.0.5:3533 |64.12.137.184:25
|ACCESS BLOCK Firewall rule match: TCP (L to W, rule:1)
108|10/03/2004 10:48:17 |192.168.0.5:3519 |149.174.40.183:25
|ACCESS BLOCK Firewall rule match: TCP (L to W, rule:1)
109|10/03/2004 10:48:17 |192.168.0.5:3520 |130.63.236.137:25
|ACCESS BLOCK Firewall rule match: TCP (L to W, rule:1)
110|10/03/2004 10:48:16 |192.168.0.5:3549 |128.32.61.103:25
|ACCESS BLOCK Firewall rule match: TCP (L to W, rule:1)
111|10/03/2004 10:48:15 |192.168.0.5:3515 |142.150.98.171:25
|ACCESS BLOCK Firewall rule match: TCP (L to W, rule:1)
112|10/03/2004 10:48:15 |192.168.0.5:3510 |24.215.46.10:25
|ACCESS BLOCK Firewall rule match: TCP (L to W, rule:1)
113|10/03/2004 10:48:15 |192.168.0.5:3533 |64.12.137.184:25
|ACCESS BLOCK Firewall rule match: TCP (L to W, rule:1)
114|10/03/2004 10:48:13 |192.168.0.5:3492 |132.72.138.160:25
|ACCESS BLOCK Firewall rule match: TCP (L to W, rule:1)
115|10/03/2004 10:48:13 |192.168.0.5:3549 |128.32.61.103:25
|ACCESS BLOCK Firewall rule match: TCP (L to W, rule:1)
116|10/03/2004 10:48:12 |192.168.0.5:3478 |144.96.128.14:25
|ACCESS BLOCK Firewall rule match: TCP (L to W, rule:1)
117|10/03/2004 10:48:12 |192.168.0.5:3533 |64.12.137.184:25
|ACCESS BLOCK Firewall rule match: TCP (L to W, rule:1)
118|10/03/2004 10:48:12 |192.168.0.5:3475 |24.215.46.10:25
|ACCESS BLOCK Firewall rule match: TCP (L to W, rule:1)
119|10/03/2004 10:48:11 |192.168.0.5:3520 |130.63.236.137:25
|ACCESS BLOCK Firewall rule match: TCP (L to W, rule:1)
120|10/03/2004 10:48:11 |192.168.0.5:3519 |149.174.40.183:25
|ACCESS BLOCK Firewall rule match: TCP (L to W, rule:1)
121|10/03/2004 10:48:10 |192.168.0.5:3463 |144.92.9.33:25
|ACCESS BLOCK Firewall rule match: TCP (L to W, rule:1)
122|10/03/2004 10:48:09 |192.168.0.5:3515 |142.150.98.171:25
|ACCESS BLOCK Firewall rule match: TCP (L to W, rule:1)
123|10/03/2004 10:48:09 |192.168.0.5:3510 |24.215.46.10:25
|ACCESS BLOCK Firewall rule match: TCP (L to W, rule:1)
124|10/03/2004 10:48:08 |192.168.0.5:3520 |130.63.236.137:25
|ACCESS BLOCK Firewall rule match: TCP (L to W, rule:1)
125|10/03/2004 10:48:08 |192.168.0.5:3519 |149.174.40.183:25
|ACCESS BLOCK Firewall rule match: TCP (L to W, rule:1)
126|10/03/2004 10:48:07 |192.168.0.5:3492 |132.72.138.160:25
|ACCESS BLOCK Firewall rule match: TCP (L to W, rule:1)
127|10/03/2004 10:48:06 |192.168.0.5:3515 |142.150.98.171:25
|ACCESS BLOCK Firewall rule match: TCP (L to W, rule:1)
128|10/03/2004 10:48:06 |192.168.0.5:3510 |24.215.46.10:25
|ACCESS BLOCK Firewall rule match: TCP (L to W, rule:1)
End of Logs
wurm war der bagle /beagle / win.32beagle.ab@mm router war der zyair b2000 und der hat den bagle ganz ordentlich behindert