|  | 
 
 楼主|
发表于 2007-5-19 12:08:11
|
显示全部楼层 
| 我是虚拟动态IP,被别人攻击`最早都想过,但掉线太频繁太快,10分钟换五个IP了,还一样掉,感觉也不大可能! 我现在用的MONO软路由,防火墙不断拦到这样的包,我跟本没有这个IP段的,我想了很久,问题肯定出在这里`但不知道这个IP段是干什么用`出自哪里,出在设备上还是客户机系统,大家有没有见过这个IP段,希望大家再分析下我抓的那些包,看能否看到这个IP段是怎么形成的`出自哪里!`万分感谢!
 
 03:55:59.919883 rl0 0.0.0.0, port 5678 255.255.255.255, port 5678 UDP
 03:55:19.932752 rl0 192.168.86.92, port 138 192.168.86.255, port 138 UDP
 03:54:59.897362 rl0 0.0.0.0, port 5678 255.255.255.255, port 5678 UDP
 03:54:56.398038 rl0 192.168.86.89, port 138 192.168.86.255, port 138 UDP
 03:53:59.874512 rl0 0.0.0.0, port 5678 255.255.255.255, port 5678 UDP
 03:52:59.851750 rl0 0.0.0.0, port 5678 255.255.255.255, port 5678 UDP
 03:52:14.775001 rl0 192.168.86.81, port 138 192.168.86.255, port 138 UDP
 03:51:59.829043 rl0 0.0.0.0, port 5678 255.255.255.255, port 5678 UDP
 03:51:14.993145 rl0 192.168.86.89, port 138 192.168.86.255, port 138 UDP
 03:50:59.806345 rl0 0.0.0.0, port 5678 255.255.255.255, port 5678 UDP
 03:50:04.659709 rl0 192.168.86.92, port 137 192.168.86.255, port 137 UDP
 03:49:59.783622 rl0 0.0.0.0, port 5678 255.255.255.255, port 5678 UDP
 03:48:59.760911 rl0 0.0.0.0, port 5678 255.255.255.255, port 5678 UDP
 03:48:23.167919 rl0 192.168.86.92, port 137 192.168.86.255, port 137 UDP
 03:48:22.417741 rl0 192.168.86.92, port 137 192.168.86.255, port 137 UDP
 03:48:21.674081 rl0 192.168.86.92, port 137 192.168.86.255, port 137 UDP
 03:47:59.738234 rl0 0.0.0.0, port 5678 255.255.255.255, port 5678 UDP
 | 
 |