Hi! today i woke up and my pc was rebooted in single user mode..
fs were damaged pretty ugly
I checked /var/log/all.log
and started to wonder what could the all be:
I have 3 long logfiles (this is just a small peace of it) with this
1) transmission crashed and theses are attempts to connect to it
2) DOS?
3) something else
I'm thinking perhaps i should put firewall (I have never used one, and this might become good reason to do)
EDIT:
Also computer did not reboot because of power fluctuation, because then it would stay shut down
fs were damaged pretty ugly
I checked /var/log/all.log
and started to wonder what could the all be:
Code:
Apr 27 00:15:02 129 /usr/sbin/cron[76665]: (root) CMD (/usr/libexec/atrun)
Apr 27 00:15:07 129 kernel: TCP: [90.157.62.69]:23422 to [192.168.128.100]:51195 tcpflags 0x18<PUSH,ACK>; tcp_do_segment: FIN_WAIT_1: Received 524 bytes of data after socket was closed, sending RST and removing tcpcb
Apr 27 00:15:25 129 kernel: TCP: [86.100.222.61]:47568 to [192.168.128.100]:57700 tcpflags 0x18<PUSH,ACK>; tcp_do_segment: FIN_WAIT_1: Received 115 bytes of data after socket was closed, sending RST and removing tcpcb
Apr 27 00:16:33 129 kernel: TCP: [188.16.23.91]:14693 to [192.168.128.100]:56003 tcpflags 0x18<PUSH,ACK>; tcp_do_segment: FIN_WAIT_1: Received 202 bytes of data after socket was closed, sending RST and removing tcpcb
Apr 27 00:16:53 129 kernel: Connection attempt to UDP 192.168.128.100:53594 from 217.78.182.149:52090
Apr 27 00:17:35 129 kernel: TCP: [95.68.31.194]:51679 to [192.168.128.100]:63754 tcpflags 0x18<PUSH,ACK>; tcp_do_segment: FIN_WAIT_2: Received 27 bytes of data after socket was closed, sending RST and removing tcpcb
Apr 27 00:17:53 129 kernel: TCP: [82.131.30.140]:60901 to [192.168.128.100]:51219 tcpflags 0x18<PUSH,ACK>; tcp_do_segment: FIN_WAIT_1: Received 236 bytes of data after socket was closed, sending RST and removing tcpcb
Apr 27 00:18:26 129 kernel: TCP: [85.28.39.110]:45737 to [192.168.128.100]:62822 tcpflags 0x18<PUSH,ACK>; tcp_do_segment: FIN_WAIT_1: Received 4 bytes of data after socket was closed, sending RST and removing tcpcb
Apr 27 00:19:21 129 kernel: TCP: [76.119.3.142]:59945 to [192.168.128.100]:52286 tcpflags 0x18<PUSH,ACK>; tcp_do_segment: FIN_WAIT_2: Received 4 bytes of data after socket was closed, sending RST and removing tcpcb
Apr 27 00:19:33 129 kernel: TCP: [88.134.62.25]:18140 to [192.168.128.100]:63876 tcpflags 0x19<FIN,PUSH,ACK>; tcp_do_segment: FIN_WAIT_1: Received 14 bytes of data after socket was closed, sending RST and removing tcpcb
Apr 27 00:20:02 129 /usr/sbin/cron[76764]: (root) CMD (/usr/libexec/atrun)
Apr 27 00:21:04 129 kernel: TCP: [71.226.89.96]:62159 to [192.168.128.100]:51668 tcpflags 0x12<SYN,ACK>; tcp_input: Connection attempt to closed port
Apr 27 00:21:07 129 kernel: TCP: [71.226.89.96]:62159 to [192.168.128.100]:51668 tcpflags 0x12<SYN,ACK>; tcp_input: Connection attempt to closed port
Apr 27 00:21:13 129 kernel: TCP: [71.226.89.96]:62159 to [192.168.128.100]:51668 tcpflags 0x12<SYN,ACK>; tcp_input: Connection attempt to closed port
Apr 27 00:21:27 129 kernel: TCP: [71.226.89.96]:62159 to [192.168.128.100]:51668 tcpflags 0x12<SYN,ACK>; tcp_input: Connection attempt to closed port
Apr 27 00:21:30 129 kernel: TCP: [71.226.89.96]:62159 to [192.168.128.100]:51668 tcpflags 0x12<SYN,ACK>; tcp_input: Connection attempt to closed port
Apr 27 00:21:34 129 kernel: TCP: [77.21.115.100]:54554 to [192.168.128.100]:59471 tcpflags 0x18<PUSH,ACK>; tcp_do_segment: FIN_WAIT_1: Received 184 bytes of data after socket was closed, sending RST and removing tcpcb
Apr 27 00:21:36 129 kernel: TCP: [71.226.89.96]:62159 to [192.168.128.100]:51668 tcpflags 0x12<SYN,ACK>; tcp_input: Connection attempt to closed port
Apr 27 00:22:01 129 /usr/sbin/cron[76792]: (operator) CMD (/usr/libexec/save-entropy)
Apr 27 00:22:47 129 kernel: TCP: [86.18.42.128]:62302 to [192.168.128.100]:64096 tcpflags 0x18<PUSH,ACK>; tcp_do_segment: FIN_WAIT_1: Received 101 bytes of data after socket was closed, sending RST and removing tcpcb
Apr 27 00:22:48 129 kernel: TCP: [77.120.203.130]:34138 to [192.168.128.100]:57949 tcpflags 0x18<PUSH,ACK>; tcp_do_segment: FIN_WAIT_1: Received 17 bytes of data after socket was closed, sending RST and removing tcpcb
Apr 27 00:23:27 129 kernel: TCP: [95.68.31.194]:51679 to [192.168.128.100]:61112 tcpflags 0x18<PUSH,ACK>; tcp_do_segment: FIN_WAIT_2: Received 9 bytes of data after socket was closed, sending RST and removing tcpcb
Apr 27 00:23:35 129 kernel: TCP: [76.119.3.142]:59945 to [192.168.128.100]:61099 tcpflags 0x18<PUSH,ACK>; tcp_do_segment: FIN_WAIT_2: Received 4 bytes of data after socket was closed, sending RST and removing tcpcb
Apr 27 00:23:35 129 kernel: TCP: [85.28.39.110]:45737 to [192.168.128.100]:55083 tcpflags 0x18<PUSH,ACK>; tcp_do_segment: FIN_WAIT_1: Received 9 bytes of data after socket was closed, sending RST and removing tcpcb
Apr 27 00:23:55 129 kernel: TCP: [85.238.107.18]:59954 to [192.168.128.100]:61641 tcpflags 0x18<PUSH,ACK>; tcp_do_segment: FIN_WAIT_2: Received 18 bytes of data after socket was closed, sending RST and removing tcpcb
Apr 27 00:23:59 129 kernel: TCP: [213.164.114.132]:59395 to [192.168.128.100]:49395 tcpflags 0x18<PUSH,ACK>; tcp_do_segment: FIN_WAIT_1: Received 123 bytes of data after socket was closed, sending RST and removing tcpcb
Apr 27 00:25:01 129 /usr/sbin/cron[76805]: (root) CMD (/usr/libexec/atrun)
Apr 27 00:25:11 129 kernel: TCP: [79.65.142.82]:55237 to [192.168.128.100]:61130 tcpflags 0x18<PUSH,ACK>; tcp_do_segment: FIN_WAIT_2: Received 62 bytes of data after socket was closed, sending RST and removing tcpcb
Apr 27 00:25:29 129 kernel: TCP: [94.75.178.128]:34062 to [192.168.128.100]:62653 tcpflags 0x18<PUSH,ACK>; tcp_do_segment: FIN_WAIT_1: Received 4 bytes of data after socket was closed, sending RST and removing tcpcb
Apr 27 00:25:33 129 kernel: TCP: [188.16.23.91]:14693 to [192.168.128.100]:62125 tcpflags 0x18<PUSH,ACK>; tcp_do_segment: FIN_WAIT_1: Received 221 bytes of data after socket was closed, sending RST and removing tcpcb
Apr 27 00:25:42 129 kernel: TCP: [92.241.162.121]:80 to [192.168.128.100]:63958 tcpflags 0x10<ACK>; tcp_do_segment: FIN_WAIT_1: Received 1460 bytes of data after socket was closed, sending RST and removing tcpcb
Apr 27 00:25:53 129 kernel: TCP: [212.150.34.64]:80 to [192.168.128.100]:54069 tcpflags 0x10<ACK>; tcp_do_segment: FIN_WAIT_2: Received 1460 bytes of data after socket was closed, sending RST and removing tcpcb
1) transmission crashed and theses are attempts to connect to it
2) DOS?
3) something else
I'm thinking perhaps i should put firewall (I have never used one, and this might become good reason to do)
EDIT:
Also computer did not reboot because of power fluctuation, because then it would stay shut down