Attack??

I have a problem with an IP address.
I have drop all traffic in the “Input Firewall Rule”.
the only address who not is drop is my VPN connection.
This is the log:


input->DROP, in DSL, out:(local), src-mac 00:0e:50:3b:xx:xx,prot TCP(syn),
81.169.188.68:50038 → 62.xxx.xxx.xxx:100 (my address), len 40


it is constantly queried, every second.

What is it??

A whois query for this IP address returns an email address for abuse, hacking etc. abuse@serverkompetenz.de

You might try asking them. Don’t forget to include the relevent sections of your system logs.

Regards

Andrew

Thank you.

in the last day, i have some entries in the log file.
i don’t know, what this is.

The log entries is:

  • received ISAKMP packet from 81.155.161.43:500,phase1,Identity Protection

  • peer not configured

  • received ISAKMP packet from 81.155.161.43:500,phase1,Identity Protection

  • peer not configured

  • received ISAKMP packet from 81.155.161.43:500,phase1,Identity Protection

  • peer not configured

  • received ISAKMP packet from 81.155.161.43:500,phase2,Identity informational

  • unexpected Informational exchange (remote unknown)

The same log i have from an other IP address.

What is it??
It is dangerous??

This is the remote system trying to open an IPSEC connection.

As you don’t have a peer configured this is not dangerous. However, you may want to configure your Input chain rules to drop all unwanted connections fro the Internet.

Regards

Andrew

you may want to upgrade to 2.8.27 as there is no ISAKMP problem in there anymore

I had similar “probes” (?) during the past weekend (6-7 May).

Is this a mass scan?

Is Mikrotik vulnurable to this ISAKMP http://www.kb.cert.org/vuls/id/738518 attack ?

it is not vulnerable, plus as i said this is improved in later 2.8 versions

At least quite surely not in the way you think: The vulnerability described in the URL you posted is in tcpdump when decoding ISAKMP packets, not when “natively” receiving ISAKMP packets themselves…

Aaaargh, Normunds just is too fast sometimes :wink:

:smiley: !

yes, i noticed the detail about tcpdump…
just don’t know how m/t works, it could utilise tcpdump for any functionality… who knows (not me) :unamused: