Cái này chắc không liên quan gì tới Cisco, nhưng không biết hỏi ai, nên em hỏi đại, admin đừng xáo bài nha, cảm ơn nhiều.
Ai rành vụ này xin cho em biết. Máy em đang xài KIS. Anti-Hack của KIS từ hôm qua tới hôm nay cứ báo là bị attack. Em không hiểu lám về cái vụ này. Ai biết chỉ dùm, cảm ơn rất nhiều. Scan thì không thấy virus hay là Spy gì hết
Copy ra dây cho mọi người xem luôn nha:
Anti-Hacker
-----------
Attacks detected: 32
Time of last attack: 1/30/2007 8:50:18 PM
Start time: 1/29/2007 7:18:39 PM
Duration: 1 days 01:36:47
Network attacks
---------------
Time Attack description Source Protocol Local port
---- ------------------ ------ -------- ----------
1/30/2007 8:36:54 AM DoS.Generic.SYNFlood 210.245.35.65 TCP 5800
1/30/2007 8:36:54 AM DoS.Generic.SYNFlood 58.186.240.15 TCP 5800
1/30/2007 8:36:54 AM DoS.Generic.SYNFlood 58.186.115.2 TCP 5800
1/30/2007 8:36:54 AM DoS.Generic.SYNFlood 125.234.80.109 TCP 5800
1/30/2007 8:36:56 AM DoS.Generic.SYNFlood 210.245.136.130 TCP 1433
1/30/2007 9:04:09 AM DoS.Generic.ICMPFlood 210.245.35.65 ICMP
1/30/2007 9:04:09 AM DoS.Generic.ICMPFlood 125.234.80.109 ICMP
1/30/2007 9:04:10 AM DoS.Generic.ICMPFlood 58.186.115.2 ICMP
1/30/2007 9:04:10 AM DoS.Generic.ICMPFlood 58.186.240.15 ICMP
1/30/2007 10:53:48 AM DoS.Generic.SYNFlood 58.186.240.15 TCP 1433
1/30/2007 10:53:48 AM DoS.Generic.SYNFlood 125.234.80.109 TCP 1433
1/30/2007 10:53:48 AM DoS.Generic.SYNFlood 58.186.115.2 TCP 1433
1/30/2007 10:53:48 AM DoS.Generic.SYNFlood 210.245.35.65 TCP 1433
1/30/2007 11:04:01 AM DoS.Generic.ICMPFlood 125.234.80.109 ICMP
1/30/2007 11:04:01 AM DoS.Generic.ICMPFlood 58.186.240.15 ICMP
1/30/2007 11:04:01 AM DoS.Generic.ICMPFlood 210.245.35.65 ICMP
1/30/2007 11:14:55 AM DoS.Generic.ICMPFlood 58.186.115.2 ICMP
1/30/2007 12:41:40 PM DoS.Generic.SYNFlood 58.186.115.2 TCP 135
1/30/2007 12:41:40 PM DoS.Generic.SYNFlood 210.245.35.65 TCP 135
1/30/2007 12:41:40 PM DoS.Generic.SYNFlood 58.186.240.15 TCP 135
1/30/2007 12:41:41 PM DoS.Generic.SYNFlood 210.245.33.179 TCP 135
1/30/2007 1:22:29 PM DoS.Generic.SYNFlood 125.234.80.109 TCP 2967
1/30/2007 4:46:40 PM DoS.Generic.SYNFlood 121.126.54.57 TCP 4899
1/30/2007 5:19:25 PM DoS.Generic.ICMPFlood 58.186.115.2 ICMP
1/30/2007 5:19:26 PM DoS.Generic.ICMPFlood 125.234.80.109 ICMP
1/30/2007 5:19:26 PM DoS.Generic.ICMPFlood 58.186.240.15 ICMP
1/30/2007 5:19:26 PM DoS.Generic.ICMPFlood 210.245.35.65 ICMP
1/30/2007 7:59:38 PM DoS.Generic.SYNFlood 58.186.240.15 TCP 1433
1/30/2007 8:50:18 PM DoS.Generic.ICMPFlood 58.186.115.2 ICMP
1/30/2007 8:50:18 PM DoS.Generic.ICMPFlood 58.186.240.15 ICMP
1/30/2007 8:50:18 PM DoS.Generic.ICMPFlood 125.234.80.109 ICMP
1/30/2007 8:50:18 PM DoS.Generic.ICMPFlood 210.245.35.65 ICMP
Banned hosts
------------
Time Host
---- ----
1/30/2007 8:50:19 PM 58.186.115.2
1/30/2007 8:50:19 PM 210.245.35.65
1/30/2007 8:50:19 PM 125.234.80.109
1/30/2007 8:50:19 PM 58.186.240.15
Application activity
--------------------
Time Application name Command line Rule name Application PID Action Direction Protocol Remote host Remote port Local host Local port
---- ---------------- ------------ --------- --------------- ------ --------- -------- ----------- ----------- ---------- ----------
Packet filtering
----------------
Time Rule name Action Direction Protocol Remote host Remote port Local host Local port
---- --------- ------ --------- -------- ----------- ----------- ---------- ----------
Ai rành vụ này xin cho em biết. Máy em đang xài KIS. Anti-Hack của KIS từ hôm qua tới hôm nay cứ báo là bị attack. Em không hiểu lám về cái vụ này. Ai biết chỉ dùm, cảm ơn rất nhiều. Scan thì không thấy virus hay là Spy gì hết
Copy ra dây cho mọi người xem luôn nha:
Anti-Hacker
-----------
Attacks detected: 32
Time of last attack: 1/30/2007 8:50:18 PM
Start time: 1/29/2007 7:18:39 PM
Duration: 1 days 01:36:47
Network attacks
---------------
Time Attack description Source Protocol Local port
---- ------------------ ------ -------- ----------
1/30/2007 8:36:54 AM DoS.Generic.SYNFlood 210.245.35.65 TCP 5800
1/30/2007 8:36:54 AM DoS.Generic.SYNFlood 58.186.240.15 TCP 5800
1/30/2007 8:36:54 AM DoS.Generic.SYNFlood 58.186.115.2 TCP 5800
1/30/2007 8:36:54 AM DoS.Generic.SYNFlood 125.234.80.109 TCP 5800
1/30/2007 8:36:56 AM DoS.Generic.SYNFlood 210.245.136.130 TCP 1433
1/30/2007 9:04:09 AM DoS.Generic.ICMPFlood 210.245.35.65 ICMP
1/30/2007 9:04:09 AM DoS.Generic.ICMPFlood 125.234.80.109 ICMP
1/30/2007 9:04:10 AM DoS.Generic.ICMPFlood 58.186.115.2 ICMP
1/30/2007 9:04:10 AM DoS.Generic.ICMPFlood 58.186.240.15 ICMP
1/30/2007 10:53:48 AM DoS.Generic.SYNFlood 58.186.240.15 TCP 1433
1/30/2007 10:53:48 AM DoS.Generic.SYNFlood 125.234.80.109 TCP 1433
1/30/2007 10:53:48 AM DoS.Generic.SYNFlood 58.186.115.2 TCP 1433
1/30/2007 10:53:48 AM DoS.Generic.SYNFlood 210.245.35.65 TCP 1433
1/30/2007 11:04:01 AM DoS.Generic.ICMPFlood 125.234.80.109 ICMP
1/30/2007 11:04:01 AM DoS.Generic.ICMPFlood 58.186.240.15 ICMP
1/30/2007 11:04:01 AM DoS.Generic.ICMPFlood 210.245.35.65 ICMP
1/30/2007 11:14:55 AM DoS.Generic.ICMPFlood 58.186.115.2 ICMP
1/30/2007 12:41:40 PM DoS.Generic.SYNFlood 58.186.115.2 TCP 135
1/30/2007 12:41:40 PM DoS.Generic.SYNFlood 210.245.35.65 TCP 135
1/30/2007 12:41:40 PM DoS.Generic.SYNFlood 58.186.240.15 TCP 135
1/30/2007 12:41:41 PM DoS.Generic.SYNFlood 210.245.33.179 TCP 135
1/30/2007 1:22:29 PM DoS.Generic.SYNFlood 125.234.80.109 TCP 2967
1/30/2007 4:46:40 PM DoS.Generic.SYNFlood 121.126.54.57 TCP 4899
1/30/2007 5:19:25 PM DoS.Generic.ICMPFlood 58.186.115.2 ICMP
1/30/2007 5:19:26 PM DoS.Generic.ICMPFlood 125.234.80.109 ICMP
1/30/2007 5:19:26 PM DoS.Generic.ICMPFlood 58.186.240.15 ICMP
1/30/2007 5:19:26 PM DoS.Generic.ICMPFlood 210.245.35.65 ICMP
1/30/2007 7:59:38 PM DoS.Generic.SYNFlood 58.186.240.15 TCP 1433
1/30/2007 8:50:18 PM DoS.Generic.ICMPFlood 58.186.115.2 ICMP
1/30/2007 8:50:18 PM DoS.Generic.ICMPFlood 58.186.240.15 ICMP
1/30/2007 8:50:18 PM DoS.Generic.ICMPFlood 125.234.80.109 ICMP
1/30/2007 8:50:18 PM DoS.Generic.ICMPFlood 210.245.35.65 ICMP
Banned hosts
------------
Time Host
---- ----
1/30/2007 8:50:19 PM 58.186.115.2
1/30/2007 8:50:19 PM 210.245.35.65
1/30/2007 8:50:19 PM 125.234.80.109
1/30/2007 8:50:19 PM 58.186.240.15
Application activity
--------------------
Time Application name Command line Rule name Application PID Action Direction Protocol Remote host Remote port Local host Local port
---- ---------------- ------------ --------- --------------- ------ --------- -------- ----------- ----------- ---------- ----------
Packet filtering
----------------
Time Rule name Action Direction Protocol Remote host Remote port Local host Local port
---- --------- ------ --------- -------- ----------- ----------- ---------- ----------