graudeejs
April 27th, 2009, 07:23
Hi! today i woke up and my pc was rebooted in single user mode..
fs were damaged pretty ugly
I checked /var/log/all.log
and started to wonder what could the all be:
Apr 27 00:15:02 129 /usr/sbin/cron[76665]: (root) CMD (/usr/libexec/atrun)
Apr 27 00:15:07 129 kernel: TCP: [90.157.62.69]:23422 to [192.168.128.100]:51195 tcpflags 0x18<PUSH,ACK>; tcp_do_segment: FIN_WAIT_1: Received 524 bytes of data after socket was closed, sending RST and removing tcpcb
Apr 27 00:15:25 129 kernel: TCP: [86.100.222.61]:47568 to [192.168.128.100]:57700 tcpflags 0x18<PUSH,ACK>; tcp_do_segment: FIN_WAIT_1: Received 115 bytes of data after socket was closed, sending RST and removing tcpcb
Apr 27 00:16:33 129 kernel: TCP: [188.16.23.91]:14693 to [192.168.128.100]:56003 tcpflags 0x18<PUSH,ACK>; tcp_do_segment: FIN_WAIT_1: Received 202 bytes of data after socket was closed, sending RST and removing tcpcb
Apr 27 00:16:53 129 kernel: Connection attempt to UDP 192.168.128.100:53594 from 217.78.182.149:52090
Apr 27 00:17:35 129 kernel: TCP: [95.68.31.194]:51679 to [192.168.128.100]:63754 tcpflags 0x18<PUSH,ACK>; tcp_do_segment: FIN_WAIT_2: Received 27 bytes of data after socket was closed, sending RST and removing tcpcb
Apr 27 00:17:53 129 kernel: TCP: [82.131.30.140]:60901 to [192.168.128.100]:51219 tcpflags 0x18<PUSH,ACK>; tcp_do_segment: FIN_WAIT_1: Received 236 bytes of data after socket was closed, sending RST and removing tcpcb
Apr 27 00:18:26 129 kernel: TCP: [85.28.39.110]:45737 to [192.168.128.100]:62822 tcpflags 0x18<PUSH,ACK>; tcp_do_segment: FIN_WAIT_1: Received 4 bytes of data after socket was closed, sending RST and removing tcpcb
Apr 27 00:19:21 129 kernel: TCP: [76.119.3.142]:59945 to [192.168.128.100]:52286 tcpflags 0x18<PUSH,ACK>; tcp_do_segment: FIN_WAIT_2: Received 4 bytes of data after socket was closed, sending RST and removing tcpcb
Apr 27 00:19:33 129 kernel: TCP: [88.134.62.25]:18140 to [192.168.128.100]:63876 tcpflags 0x19<FIN,PUSH,ACK>; tcp_do_segment: FIN_WAIT_1: Received 14 bytes of data after socket was closed, sending RST and removing tcpcb
Apr 27 00:20:02 129 /usr/sbin/cron[76764]: (root) CMD (/usr/libexec/atrun)
Apr 27 00:21:04 129 kernel: TCP: [71.226.89.96]:62159 to [192.168.128.100]:51668 tcpflags 0x12<SYN,ACK>; tcp_input: Connection attempt to closed port
Apr 27 00:21:07 129 kernel: TCP: [71.226.89.96]:62159 to [192.168.128.100]:51668 tcpflags 0x12<SYN,ACK>; tcp_input: Connection attempt to closed port
Apr 27 00:21:13 129 kernel: TCP: [71.226.89.96]:62159 to [192.168.128.100]:51668 tcpflags 0x12<SYN,ACK>; tcp_input: Connection attempt to closed port
Apr 27 00:21:27 129 kernel: TCP: [71.226.89.96]:62159 to [192.168.128.100]:51668 tcpflags 0x12<SYN,ACK>; tcp_input: Connection attempt to closed port
Apr 27 00:21:30 129 kernel: TCP: [71.226.89.96]:62159 to [192.168.128.100]:51668 tcpflags 0x12<SYN,ACK>; tcp_input: Connection attempt to closed port
Apr 27 00:21:34 129 kernel: TCP: [77.21.115.100]:54554 to [192.168.128.100]:59471 tcpflags 0x18<PUSH,ACK>; tcp_do_segment: FIN_WAIT_1: Received 184 bytes of data after socket was closed, sending RST and removing tcpcb
Apr 27 00:21:36 129 kernel: TCP: [71.226.89.96]:62159 to [192.168.128.100]:51668 tcpflags 0x12<SYN,ACK>; tcp_input: Connection attempt to closed port
Apr 27 00:22:01 129 /usr/sbin/cron[76792]: (operator) CMD (/usr/libexec/save-entropy)
Apr 27 00:22:47 129 kernel: TCP: [86.18.42.128]:62302 to [192.168.128.100]:64096 tcpflags 0x18<PUSH,ACK>; tcp_do_segment: FIN_WAIT_1: Received 101 bytes of data after socket was closed, sending RST and removing tcpcb
Apr 27 00:22:48 129 kernel: TCP: [77.120.203.130]:34138 to [192.168.128.100]:57949 tcpflags 0x18<PUSH,ACK>; tcp_do_segment: FIN_WAIT_1: Received 17 bytes of data after socket was closed, sending RST and removing tcpcb
Apr 27 00:23:27 129 kernel: TCP: [95.68.31.194]:51679 to [192.168.128.100]:61112 tcpflags 0x18<PUSH,ACK>; tcp_do_segment: FIN_WAIT_2: Received 9 bytes of data after socket was closed, sending RST and removing tcpcb
Apr 27 00:23:35 129 kernel: TCP: [76.119.3.142]:59945 to [192.168.128.100]:61099 tcpflags 0x18<PUSH,ACK>; tcp_do_segment: FIN_WAIT_2: Received 4 bytes of data after socket was closed, sending RST and removing tcpcb
Apr 27 00:23:35 129 kernel: TCP: [85.28.39.110]:45737 to [192.168.128.100]:55083 tcpflags 0x18<PUSH,ACK>; tcp_do_segment: FIN_WAIT_1: Received 9 bytes of data after socket was closed, sending RST and removing tcpcb
Apr 27 00:23:55 129 kernel: TCP: [85.238.107.18]:59954 to [192.168.128.100]:61641 tcpflags 0x18<PUSH,ACK>; tcp_do_segment: FIN_WAIT_2: Received 18 bytes of data after socket was closed, sending RST and removing tcpcb
Apr 27 00:23:59 129 kernel: TCP: [213.164.114.132]:59395 to [192.168.128.100]:49395 tcpflags 0x18<PUSH,ACK>; tcp_do_segment: FIN_WAIT_1: Received 123 bytes of data after socket was closed, sending RST and removing tcpcb
Apr 27 00:25:01 129 /usr/sbin/cron[76805]: (root) CMD (/usr/libexec/atrun)
Apr 27 00:25:11 129 kernel: TCP: [79.65.142.82]:55237 to [192.168.128.100]:61130 tcpflags 0x18<PUSH,ACK>; tcp_do_segment: FIN_WAIT_2: Received 62 bytes of data after socket was closed, sending RST and removing tcpcb
Apr 27 00:25:29 129 kernel: TCP: [94.75.178.128]:34062 to [192.168.128.100]:62653 tcpflags 0x18<PUSH,ACK>; tcp_do_segment: FIN_WAIT_1: Received 4 bytes of data after socket was closed, sending RST and removing tcpcb
Apr 27 00:25:33 129 kernel: TCP: [188.16.23.91]:14693 to [192.168.128.100]:62125 tcpflags 0x18<PUSH,ACK>; tcp_do_segment: FIN_WAIT_1: Received 221 bytes of data after socket was closed, sending RST and removing tcpcb
Apr 27 00:25:42 129 kernel: TCP: [92.241.162.121]:80 to [192.168.128.100]:63958 tcpflags 0x10<ACK>; tcp_do_segment: FIN_WAIT_1: Received 1460 bytes of data after socket was closed, sending RST and removing tcpcb
Apr 27 00:25:53 129 kernel: TCP: [212.150.34.64]:80 to [192.168.128.100]:54069 tcpflags 0x10<ACK>; tcp_do_segment: FIN_WAIT_2: Received 1460 bytes of data after socket was closed, sending RST and removing tcpcb
I have 3 long logfiles (this is just a small peace of it) with this
1) transmission crashed and theses are attempts to connect to it
2) DOS?
3) something else
I'm thinking perhaps i should put firewall (I have never used one, and this might become good reason to do)
EDIT:
Also computer did not reboot because of power fluctuation, because then it would stay shut down
fs were damaged pretty ugly
I checked /var/log/all.log
and started to wonder what could the all be:
Apr 27 00:15:02 129 /usr/sbin/cron[76665]: (root) CMD (/usr/libexec/atrun)
Apr 27 00:15:07 129 kernel: TCP: [90.157.62.69]:23422 to [192.168.128.100]:51195 tcpflags 0x18<PUSH,ACK>; tcp_do_segment: FIN_WAIT_1: Received 524 bytes of data after socket was closed, sending RST and removing tcpcb
Apr 27 00:15:25 129 kernel: TCP: [86.100.222.61]:47568 to [192.168.128.100]:57700 tcpflags 0x18<PUSH,ACK>; tcp_do_segment: FIN_WAIT_1: Received 115 bytes of data after socket was closed, sending RST and removing tcpcb
Apr 27 00:16:33 129 kernel: TCP: [188.16.23.91]:14693 to [192.168.128.100]:56003 tcpflags 0x18<PUSH,ACK>; tcp_do_segment: FIN_WAIT_1: Received 202 bytes of data after socket was closed, sending RST and removing tcpcb
Apr 27 00:16:53 129 kernel: Connection attempt to UDP 192.168.128.100:53594 from 217.78.182.149:52090
Apr 27 00:17:35 129 kernel: TCP: [95.68.31.194]:51679 to [192.168.128.100]:63754 tcpflags 0x18<PUSH,ACK>; tcp_do_segment: FIN_WAIT_2: Received 27 bytes of data after socket was closed, sending RST and removing tcpcb
Apr 27 00:17:53 129 kernel: TCP: [82.131.30.140]:60901 to [192.168.128.100]:51219 tcpflags 0x18<PUSH,ACK>; tcp_do_segment: FIN_WAIT_1: Received 236 bytes of data after socket was closed, sending RST and removing tcpcb
Apr 27 00:18:26 129 kernel: TCP: [85.28.39.110]:45737 to [192.168.128.100]:62822 tcpflags 0x18<PUSH,ACK>; tcp_do_segment: FIN_WAIT_1: Received 4 bytes of data after socket was closed, sending RST and removing tcpcb
Apr 27 00:19:21 129 kernel: TCP: [76.119.3.142]:59945 to [192.168.128.100]:52286 tcpflags 0x18<PUSH,ACK>; tcp_do_segment: FIN_WAIT_2: Received 4 bytes of data after socket was closed, sending RST and removing tcpcb
Apr 27 00:19:33 129 kernel: TCP: [88.134.62.25]:18140 to [192.168.128.100]:63876 tcpflags 0x19<FIN,PUSH,ACK>; tcp_do_segment: FIN_WAIT_1: Received 14 bytes of data after socket was closed, sending RST and removing tcpcb
Apr 27 00:20:02 129 /usr/sbin/cron[76764]: (root) CMD (/usr/libexec/atrun)
Apr 27 00:21:04 129 kernel: TCP: [71.226.89.96]:62159 to [192.168.128.100]:51668 tcpflags 0x12<SYN,ACK>; tcp_input: Connection attempt to closed port
Apr 27 00:21:07 129 kernel: TCP: [71.226.89.96]:62159 to [192.168.128.100]:51668 tcpflags 0x12<SYN,ACK>; tcp_input: Connection attempt to closed port
Apr 27 00:21:13 129 kernel: TCP: [71.226.89.96]:62159 to [192.168.128.100]:51668 tcpflags 0x12<SYN,ACK>; tcp_input: Connection attempt to closed port
Apr 27 00:21:27 129 kernel: TCP: [71.226.89.96]:62159 to [192.168.128.100]:51668 tcpflags 0x12<SYN,ACK>; tcp_input: Connection attempt to closed port
Apr 27 00:21:30 129 kernel: TCP: [71.226.89.96]:62159 to [192.168.128.100]:51668 tcpflags 0x12<SYN,ACK>; tcp_input: Connection attempt to closed port
Apr 27 00:21:34 129 kernel: TCP: [77.21.115.100]:54554 to [192.168.128.100]:59471 tcpflags 0x18<PUSH,ACK>; tcp_do_segment: FIN_WAIT_1: Received 184 bytes of data after socket was closed, sending RST and removing tcpcb
Apr 27 00:21:36 129 kernel: TCP: [71.226.89.96]:62159 to [192.168.128.100]:51668 tcpflags 0x12<SYN,ACK>; tcp_input: Connection attempt to closed port
Apr 27 00:22:01 129 /usr/sbin/cron[76792]: (operator) CMD (/usr/libexec/save-entropy)
Apr 27 00:22:47 129 kernel: TCP: [86.18.42.128]:62302 to [192.168.128.100]:64096 tcpflags 0x18<PUSH,ACK>; tcp_do_segment: FIN_WAIT_1: Received 101 bytes of data after socket was closed, sending RST and removing tcpcb
Apr 27 00:22:48 129 kernel: TCP: [77.120.203.130]:34138 to [192.168.128.100]:57949 tcpflags 0x18<PUSH,ACK>; tcp_do_segment: FIN_WAIT_1: Received 17 bytes of data after socket was closed, sending RST and removing tcpcb
Apr 27 00:23:27 129 kernel: TCP: [95.68.31.194]:51679 to [192.168.128.100]:61112 tcpflags 0x18<PUSH,ACK>; tcp_do_segment: FIN_WAIT_2: Received 9 bytes of data after socket was closed, sending RST and removing tcpcb
Apr 27 00:23:35 129 kernel: TCP: [76.119.3.142]:59945 to [192.168.128.100]:61099 tcpflags 0x18<PUSH,ACK>; tcp_do_segment: FIN_WAIT_2: Received 4 bytes of data after socket was closed, sending RST and removing tcpcb
Apr 27 00:23:35 129 kernel: TCP: [85.28.39.110]:45737 to [192.168.128.100]:55083 tcpflags 0x18<PUSH,ACK>; tcp_do_segment: FIN_WAIT_1: Received 9 bytes of data after socket was closed, sending RST and removing tcpcb
Apr 27 00:23:55 129 kernel: TCP: [85.238.107.18]:59954 to [192.168.128.100]:61641 tcpflags 0x18<PUSH,ACK>; tcp_do_segment: FIN_WAIT_2: Received 18 bytes of data after socket was closed, sending RST and removing tcpcb
Apr 27 00:23:59 129 kernel: TCP: [213.164.114.132]:59395 to [192.168.128.100]:49395 tcpflags 0x18<PUSH,ACK>; tcp_do_segment: FIN_WAIT_1: Received 123 bytes of data after socket was closed, sending RST and removing tcpcb
Apr 27 00:25:01 129 /usr/sbin/cron[76805]: (root) CMD (/usr/libexec/atrun)
Apr 27 00:25:11 129 kernel: TCP: [79.65.142.82]:55237 to [192.168.128.100]:61130 tcpflags 0x18<PUSH,ACK>; tcp_do_segment: FIN_WAIT_2: Received 62 bytes of data after socket was closed, sending RST and removing tcpcb
Apr 27 00:25:29 129 kernel: TCP: [94.75.178.128]:34062 to [192.168.128.100]:62653 tcpflags 0x18<PUSH,ACK>; tcp_do_segment: FIN_WAIT_1: Received 4 bytes of data after socket was closed, sending RST and removing tcpcb
Apr 27 00:25:33 129 kernel: TCP: [188.16.23.91]:14693 to [192.168.128.100]:62125 tcpflags 0x18<PUSH,ACK>; tcp_do_segment: FIN_WAIT_1: Received 221 bytes of data after socket was closed, sending RST and removing tcpcb
Apr 27 00:25:42 129 kernel: TCP: [92.241.162.121]:80 to [192.168.128.100]:63958 tcpflags 0x10<ACK>; tcp_do_segment: FIN_WAIT_1: Received 1460 bytes of data after socket was closed, sending RST and removing tcpcb
Apr 27 00:25:53 129 kernel: TCP: [212.150.34.64]:80 to [192.168.128.100]:54069 tcpflags 0x10<ACK>; tcp_do_segment: FIN_WAIT_2: Received 1460 bytes of data after socket was closed, sending RST and removing tcpcb
I have 3 long logfiles (this is just a small peace of it) with this
1) transmission crashed and theses are attempts to connect to it
2) DOS?
3) something else
I'm thinking perhaps i should put firewall (I have never used one, and this might become good reason to do)
EDIT:
Also computer did not reboot because of power fluctuation, because then it would stay shut down