Every two hours or so my servers are set to email me a summary of events and other misc. information. Some of the information is memory/cpu utilization, which processes are running, a list of listening services, which cron-jobs ran, who logged in, etc. My favorite part of the script is the "INBOUND DROPPED" portion.
This portion of the email includes all the packets that were dropped by the firewall. This week I've noticed a dramatic increase in dropped packets from IPs all over the world. Frustrated and confused by the annoyances, I started sending emails to abuse departments requesting they stop.
Here's an email sent 2 days ago:
MIME-Version: 1.0 Sender: security at nullamatix dot com Received: by 10.100.140.11 with HTTP; Wed, 22 Apr 2009 09:59:19 -0700 (PDT) Date: Wed, 22 Apr 2009 12:59:19 -0400 X-Google-Sender-Auth: 49f446 Message-ID: <88e844b40904220959l6061@mail.gmail.com> Subject: Unnecessary Traffic From: 66.129.65.84 From: Security Operations <security at nullamatix dot com> To: abuse at peak10 Cc: chris.martin at peak10, don.lundquist at peak10, devon.true at peak10, john.willingham at peak10, ronnie.frames at peak10 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 7bit ----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Seriously, there's no service listening on port 33435, I promise... 03:29:46 SRC=66.129.65.84 DST=209.40.196.119 SPT=12495 DPT=33435 03:29:51 SRC=66.129.65.84 DST=209.40.196.119 SPT=12495 DPT=33435 03:29:56 SRC=66.129.65.84 DST=209.40.196.119 SPT=12495 DPT=33435 03:30:01 SRC=66.129.65.84 DST=209.40.196.119 SPT=12495 DPT=33435 03:30:06 SRC=66.129.65.84 DST=209.40.196.119 SPT=12495 DPT=33435 03:30:11 SRC=66.129.65.84 DST=209.40.196.119 SPT=12495 DPT=33435 05:23:46 SRC=66.129.65.84 DST=209.40.196.119 SPT=11746 DPT=33435 05:23:51 SRC=66.129.65.84 DST=209.40.196.119 SPT=11746 DPT=33435 05:23:56 SRC=66.129.65.84 DST=209.40.196.119 SPT=11746 DPT=33435 05:24:01 SRC=66.129.65.84 DST=209.40.196.119 SPT=11746 DPT=33435 05:24:06 SRC=66.129.65.84 DST=209.40.196.119 SPT=11746 DPT=33435 05:24:11 SRC=66.129.65.84 DST=209.40.196.119 SPT=11746 DPT=33435 06:28:50 SRC=66.129.65.84 DST=209.40.196.119 SPT=11736 DPT=33435 06:28:58 SRC=66.129.65.84 DST=209.40.196.119 SPT=11736 DPT=33435 06:29:00 SRC=66.129.65.84 DST=209.40.196.119 SPT=11736 DPT=33435 06:29:05 SRC=66.129.65.84 DST=209.40.196.119 SPT=11736 DPT=33435 06:29:11 SRC=66.129.65.84 DST=209.40.196.119 SPT=11736 DPT=33435 06:29:15 SRC=66.129.65.84 DST=209.40.196.119 SPT=11736 DPT=33435 07:14:50 SRC=66.129.65.84 DST=209.40.196.119 SPT=12015 DPT=33435 07:14:55 SRC=66.129.65.84 DST=209.40.196.119 SPT=12015 DPT=33435 07:15:00 SRC=66.129.65.84 DST=209.40.196.119 SPT=12015 DPT=33435 07:15:05 SRC=66.129.65.84 DST=209.40.196.119 SPT=12015 DPT=33435 07:15:10 SRC=66.129.65.84 DST=209.40.196.119 SPT=12015 DPT=33435 07:15:15 SRC=66.129.65.84 DST=209.40.196.119 SPT=12015 DPT=33435 08:14:47 SRC=66.129.65.84 DST=209.40.196.119 SPT=10025 DPT=33435 08:14:51 SRC=66.129.65.84 DST=209.40.196.119 SPT=10025 DPT=33435 08:14:56 SRC=66.129.65.84 DST=209.40.196.119 SPT=10025 DPT=33435 08:15:01 SRC=66.129.65.84 DST=209.40.196.119 SPT=10025 DPT=33435 08:15:07 SRC=66.129.65.84 DST=209.40.196.119 SPT=10025 DPT=33435 08:15:11 SRC=66.129.65.84 DST=209.40.196.119 SPT=10025 DPT=33435 09:41:56 SRC=66.129.65.84 DST=209.40.196.119 SPT=12250 DPT=33435 09:42:01 SRC=66.129.65.84 DST=209.40.196.119 SPT=12250 DPT=33435 09:42:06 SRC=66.129.65.84 DST=209.40.196.119 SPT=12250 DPT=33435 09:42:11 SRC=66.129.65.84 DST=209.40.196.119 SPT=12250 DPT=33435 09:42:16 SRC=66.129.65.84 DST=209.40.196.119 SPT=12250 DPT=33435 09:42:21 SRC=66.129.65.84 DST=209.40.196.119 SPT=12250 DPT=33435 Thanks, Guy https://www.nullamatix.com/pubkey.txt -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.7 (MingW32) - WinPT 1.2.0 iQEVAwUBSe9MW8LX50JovmoJAQJFAAf+Kkx1pedIL++zVf0pDc70PGqWhpVQUPKS OiT64L8XJ9BJbC7X+lhSGGpLacpE9+uY5ShpGgBGOi+cVtie+hzZFSb7EPaF+5xJ qgr2rGCGdYAaWmfvwVKvNCCdllymC8WYCywbExCrTwrZKUWA8K5+st2MPGJ16V5A +QLyAEE0oJSfQIurs4ZhBtRnMGqokcKeoPiokelLagkH+cri8STNOUxOM6XQu3AZ xUsKvt3TkemUpB/hZQhu0TstxGrAygXgEbO8H8K7p6J5HzNUbCm7nNMdpk2hZNuz BrMMX3NrQVxA/8GqeJmoljF/a1IxUaVfekN9cco/jJVqE2M816pgSg== =COtU -----END PGP SIGNATURE-----
Devon True responded quickly - within twenty minutes (good host?):
From: NetworkEngineering at peak10 dot come Network Engineering To: security at nullamatix dot com Security Operations Date: Wed, 22 Apr 2009 13:16:54 -0400 Subject: RE: Unnecessary Traffic From: 66.129.65.84 [TID:430679] Guy, The host at IP 66.129.65.84 is a Flow Control Platform (FCP) that optimizes our outbound traffic based on load, latency, packet loss, etc. The traffic that is hitting your system are the probes from the unit to test those criteria. If you want those probes stopped, please reply with the network to exclude. -- Devon True Peak 10 Network Engineer || Peak 10 Data Center Solutions Email: devon.true at peak10 dot com || Direct: XXX-XXX-6007 Peak 10 Support: 866-PEAK-TEN support at peak10 dot c0m URI: http://www.peak10.com/
So I replied and all appears well. Logs and emails went back to the usual Chinese, Russian, Romanian brute-force attacks, no more flood of useless traffic to ports that aren't listening. wrong.
I came home on my lunch break today and started examining the couple status reports in my inbox, and to my surprise, this is what's inside for the INBOUND DROPPED portion...
* I altered the DST= column to display 67.200.200.00
April 24th 2009 - 00:00:01
00:00:01 SRC=76.3.140.205 DST=67.200.200.00 SPT=2345 DPT=39172 00:00:01 SRC=76.3.140.205 DST=67.200.200.00 SPT=3345 DPT=39172 00:00:01 SRC=76.3.140.205 DST=67.200.200.00 SPT=4345 DPT=39172 00:00:01 SRC=76.3.140.205 DST=67.200.200.00 SPT=5345 DPT=39172 00:00:01 SRC=76.3.140.205 DST=67.200.200.00 SPT=6345 DPT=39172 00:00:01 SRC=76.3.140.205 DST=67.200.200.00 SPT=7345 DPT=39172 00:00:01 SRC=76.3.140.205 DST=67.200.200.00 SPT=8345 DPT=39172 00:00:01 SRC=76.3.140.205 DST=67.200.200.00 SPT=9345 DPT=39172 00:00:01 SRC=76.3.140.205 DST=67.200.200.00 SPT=1345 DPT=39172 00:00:01 SRC=189.176.195.229 DST=67.200.200.00 SPT=1345 DPT=39172 00:00:01 SRC=189.176.195.229 DST=67.200.200.00 SPT=2345 DPT=39172 00:00:01 SRC=189.176.195.229 DST=67.200.200.00 SPT=3345 DPT=39172 00:00:01 SRC=189.176.195.229 DST=67.200.200.00 SPT=4345 DPT=39172 00:00:01 SRC=189.176.195.229 DST=67.200.200.00 SPT=5345 DPT=39172 00:00:01 SRC=189.176.195.229 DST=67.200.200.00 SPT=6345 DPT=39172 00:00:01 SRC=189.176.195.229 DST=67.200.200.00 SPT=7345 DPT=39172 00:00:01 SRC=189.176.195.229 DST=67.200.200.00 SPT=8345 DPT=39172 00:00:01 SRC=189.176.195.229 DST=67.200.200.00 SPT=9345 DPT=39172 00:00:01 SRC=98.207.90.174 DST=67.200.200.00 SPT=1345 DPT=39172 00:00:01 SRC=98.207.90.174 DST=67.200.200.00 SPT=2345 DPT=39172 00:00:01 SRC=98.207.90.174 DST=67.200.200.00 SPT=3345 DPT=39172 00:00:01 SRC=98.207.90.174 DST=67.200.200.00 SPT=4345 DPT=39172 00:00:01 SRC=98.207.90.174 DST=67.200.200.00 SPT=5345 DPT=39172 00:00:01 SRC=98.207.90.174 DST=67.200.200.00 SPT=6345 DPT=39172 00:00:01 SRC=98.207.90.174 DST=67.200.200.00 SPT=7345 DPT=39172 00:00:01 SRC=98.207.90.174 DST=67.200.200.00 SPT=8345 DPT=39172 00:00:01 SRC=98.207.90.174 DST=67.200.200.00 SPT=9345 DPT=39172 00:00:01 SRC=67.80.17.61 DST=67.200.200.00 SPT=1345 DPT=39172 00:00:01 SRC=67.80.17.61 DST=67.200.200.00 SPT=2345 DPT=39172 00:00:01 SRC=67.80.17.61 DST=67.200.200.00 SPT=3345 DPT=39172 00:00:01 SRC=67.80.17.61 DST=67.200.200.00 SPT=4345 DPT=39172 00:00:01 SRC=67.80.17.61 DST=67.200.200.00 SPT=5345 DPT=39172 00:00:01 SRC=67.80.17.61 DST=67.200.200.00 SPT=6345 DPT=39172 00:00:01 SRC=67.80.17.61 DST=67.200.200.00 SPT=7345 DPT=39172 00:00:01 SRC=67.80.17.61 DST=67.200.200.00 SPT=8345 DPT=39172 00:00:01 SRC=67.80.17.61 DST=67.200.200.00 SPT=9345 DPT=39172
April 24th 2009 - 00:00:08
00:00:08 SRC=98.227.224.66 DST=67.200.200.00 SPT=1345 DPT=39172 00:00:08 SRC=98.227.224.66 DST=67.200.200.00 SPT=2345 DPT=39172 00:00:08 SRC=98.227.224.66 DST=67.200.200.00 SPT=3345 DPT=39172 00:00:08 SRC=98.227.224.66 DST=67.200.200.00 SPT=4345 DPT=39172 00:00:08 SRC=98.227.224.66 DST=67.200.200.00 SPT=5345 DPT=39172 00:00:08 SRC=98.227.224.66 DST=67.200.200.00 SPT=6345 DPT=39172 00:00:08 SRC=98.227.224.66 DST=67.200.200.00 SPT=7345 DPT=39172 00:00:08 SRC=98.227.224.66 DST=67.200.200.00 SPT=8345 DPT=39172 00:00:08 SRC=98.227.224.66 DST=67.200.200.00 SPT=9345 DPT=39172 00:00:08 SRC=69.115.175.27 DST=67.200.200.00 SPT=1345 DPT=39172 00:00:08 SRC=69.115.175.27 DST=67.200.200.00 SPT=2345 DPT=39172 00:00:08 SRC=69.115.175.27 DST=67.200.200.00 SPT=3345 DPT=39172 00:00:08 SRC=69.115.175.27 DST=67.200.200.00 SPT=4345 DPT=39172 00:00:08 SRC=69.115.175.27 DST=67.200.200.00 SPT=5345 DPT=39172 00:00:08 SRC=69.115.175.27 DST=67.200.200.00 SPT=6345 DPT=39172 00:00:08 SRC=69.115.175.27 DST=67.200.200.00 SPT=7345 DPT=39172 00:00:08 SRC=69.115.175.27 DST=67.200.200.00 SPT=8345 DPT=39172 00:00:08 SRC=69.115.175.27 DST=67.200.200.00 SPT=9345 DPT=39172 00:00:08 SRC=69.231.217.167 DST=67.200.200.00 SPT=1345 DPT=39172 00:00:08 SRC=69.231.217.167 DST=67.200.200.00 SPT=2345 DPT=39172 00:00:08 SRC=69.231.217.167 DST=67.200.200.00 SPT=3345 DPT=39172 00:00:08 SRC=69.231.217.167 DST=67.200.200.00 SPT=4345 DPT=39172 00:00:08 SRC=69.231.217.167 DST=67.200.200.00 SPT=5345 DPT=39172 00:00:08 SRC=69.231.217.167 DST=67.200.200.00 SPT=6345 DPT=39172 00:00:08 SRC=69.231.217.167 DST=67.200.200.00 SPT=7345 DPT=39172 00:00:08 SRC=69.231.217.167 DST=67.200.200.00 SPT=8345 DPT=39172 00:00:08 SRC=69.231.217.167 DST=67.200.200.00 SPT=9345 DPT=39172 00:00:08 SRC=70.45.57.125 DST=67.200.200.00 SPT=1345 DPT=39172 00:00:08 SRC=70.45.57.125 DST=67.200.200.00 SPT=2345 DPT=39172 00:00:08 SRC=70.45.57.125 DST=67.200.200.00 SPT=3345 DPT=39172 00:00:08 SRC=70.45.57.125 DST=67.200.200.00 SPT=4345 DPT=39172 00:00:08 SRC=70.45.57.125 DST=67.200.200.00 SPT=5345 DPT=39172 00:00:08 SRC=70.45.57.125 DST=67.200.200.00 SPT=6345 DPT=39172 00:00:08 SRC=70.45.57.125 DST=67.200.200.00 SPT=7345 DPT=39172 00:00:08 SRC=70.45.57.125 DST=67.200.200.00 SPT=8345 DPT=39172 00:00:08 SRC=70.45.57.125 DST=67.200.200.00 SPT=9345 DPT=39172
April 24th 2009 - 00:00:29
00:00:29 SRC=71.236.251.165 DST=67.200.200.00 SPT=1345 DPT=39172 00:00:29 SRC=71.236.251.165 DST=67.200.200.00 SPT=2345 DPT=39172 00:00:29 SRC=71.236.251.165 DST=67.200.200.00 SPT=3345 DPT=39172 00:00:29 SRC=71.236.251.165 DST=67.200.200.00 SPT=4345 DPT=39172 00:00:29 SRC=71.236.251.165 DST=67.200.200.00 SPT=5345 DPT=39172 00:00:29 SRC=71.236.251.165 DST=67.200.200.00 SPT=6345 DPT=39172 00:00:29 SRC=71.236.251.165 DST=67.200.200.00 SPT=7345 DPT=39172 00:00:29 SRC=71.236.251.165 DST=67.200.200.00 SPT=8345 DPT=39172 00:00:29 SRC=71.236.251.165 DST=67.200.200.00 SPT=9345 DPT=39172 00:00:29 SRC=67.80.17.61 DST=67.200.200.00 SPT=1345 DPT=39172 00:00:29 SRC=67.80.17.61 DST=67.200.200.00 SPT=2345 DPT=39172 00:00:29 SRC=67.80.17.61 DST=67.200.200.00 SPT=3345 DPT=39172 00:00:29 SRC=67.80.17.61 DST=67.200.200.00 SPT=4345 DPT=39172 00:00:29 SRC=67.80.17.61 DST=67.200.200.00 SPT=5345 DPT=39172 00:00:29 SRC=67.80.17.61 DST=67.200.200.00 SPT=6345 DPT=39172 00:00:29 SRC=67.80.17.61 DST=67.200.200.00 SPT=7345 DPT=39172 00:00:29 SRC=67.80.17.61 DST=67.200.200.00 SPT=8345 DPT=39172 00:00:29 SRC=67.80.17.61 DST=67.200.200.00 SPT=9345 DPT=39172 00:00:29 SRC=67.53.4.151 DST=67.200.200.00 SPT=1345 DPT=39172 00:00:29 SRC=67.53.4.151 DST=67.200.200.00 SPT=2345 DPT=39172 00:00:29 SRC=67.53.4.151 DST=67.200.200.00 SPT=3345 DPT=39172 00:00:29 SRC=67.53.4.151 DST=67.200.200.00 SPT=4345 DPT=39172 00:00:29 SRC=67.53.4.151 DST=67.200.200.00 SPT=5345 DPT=39172 00:00:29 SRC=67.53.4.151 DST=67.200.200.00 SPT=6345 DPT=39172 00:00:29 SRC=67.53.4.151 DST=67.200.200.00 SPT=7345 DPT=39172 00:00:29 SRC=67.53.4.151 DST=67.200.200.00 SPT=8345 DPT=39172 00:00:29 SRC=67.53.4.151 DST=67.200.200.00 SPT=9345 DPT=39172 00:00:29 SRC=203.189.32.234 DST=67.200.200.00 SPT=1345 DPT=39172 00:00:29 SRC=203.189.32.234 DST=67.200.200.00 SPT=2345 DPT=39172 00:00:29 SRC=203.189.32.234 DST=67.200.200.00 SPT=3345 DPT=39172 00:00:29 SRC=203.189.32.234 DST=67.200.200.00 SPT=4345 DPT=39172 00:00:29 SRC=203.189.32.234 DST=67.200.200.00 SPT=5345 DPT=39172 00:00:29 SRC=203.189.32.234 DST=67.200.200.00 SPT=6345 DPT=39172 00:00:29 SRC=203.189.32.234 DST=67.200.200.00 SPT=7345 DPT=39172 00:00:29 SRC=203.189.32.234 DST=67.200.200.00 SPT=8345 DPT=39172 00:00:29 SRC=203.189.32.234 DST=67.200.200.00 SPT=9345 DPT=39172
April 24th 2009 - 00:01:07
00:01:07 SRC=201.24.3.234 DST=67.200.200.00 SPT=1345 DPT=39172 00:01:07 SRC=201.24.3.234 DST=67.200.200.00 SPT=2345 DPT=39172 00:01:07 SRC=201.24.3.234 DST=67.200.200.00 SPT=3345 DPT=39172 00:01:07 SRC=201.24.3.234 DST=67.200.200.00 SPT=4345 DPT=39172 00:01:07 SRC=201.24.3.234 DST=67.200.200.00 SPT=5345 DPT=39172 00:01:07 SRC=201.24.3.234 DST=67.200.200.00 SPT=6345 DPT=39172 00:01:07 SRC=201.24.3.234 DST=67.200.200.00 SPT=7345 DPT=39172 00:01:07 SRC=201.24.3.234 DST=67.200.200.00 SPT=8345 DPT=39172 00:01:07 SRC=201.24.3.234 DST=67.200.200.00 SPT=9345 DPT=39172 00:01:07 SRC=68.204.68.82 DST=67.200.200.00 SPT=1345 DPT=39172 00:01:07 SRC=68.204.68.82 DST=67.200.200.00 SPT=2345 DPT=39172 00:01:07 SRC=68.204.68.82 DST=67.200.200.00 SPT=3345 DPT=39172 00:01:07 SRC=68.204.68.82 DST=67.200.200.00 SPT=4345 DPT=39172 00:01:07 SRC=68.204.68.82 DST=67.200.200.00 SPT=5345 DPT=39172 00:01:07 SRC=68.204.68.82 DST=67.200.200.00 SPT=6345 DPT=39172 00:01:07 SRC=68.204.68.82 DST=67.200.200.00 SPT=7345 DPT=39172 00:01:07 SRC=68.204.68.82 DST=67.200.200.00 SPT=8345 DPT=39172 00:01:07 SRC=68.204.68.82 DST=67.200.200.00 SPT=9345 DPT=39172 00:01:07 SRC=203.189.32.234 DST=67.200.200.00 SPT=1345 DPT=39172 00:01:07 SRC=203.189.32.234 DST=67.200.200.00 SPT=2345 DPT=39172 00:01:07 SRC=203.189.32.234 DST=67.200.200.00 SPT=3345 DPT=39172 00:01:07 SRC=203.189.32.234 DST=67.200.200.00 SPT=4345 DPT=39172 00:01:07 SRC=203.189.32.234 DST=67.200.200.00 SPT=5345 DPT=39172 00:01:07 SRC=203.189.32.234 DST=67.200.200.00 SPT=6345 DPT=39172 00:01:07 SRC=203.189.32.234 DST=67.200.200.00 SPT=7345 DPT=39172 00:01:07 SRC=203.189.32.234 DST=67.200.200.00 SPT=8345 DPT=39172 00:01:07 SRC=203.189.32.234 DST=67.200.200.00 SPT=9345 DPT=39172 00:01:07 SRC=98.162.240.76 DST=67.200.200.00 SPT=1345 DPT=39172 00:01:07 SRC=98.162.240.76 DST=67.200.200.00 SPT=2345 DPT=39172 00:01:07 SRC=98.162.240.76 DST=67.200.200.00 SPT=3345 DPT=39172 00:01:07 SRC=98.162.240.76 DST=67.200.200.00 SPT=4345 DPT=39172 00:01:07 SRC=98.162.240.76 DST=67.200.200.00 SPT=5345 DPT=39172 00:01:07 SRC=98.162.240.76 DST=67.200.200.00 SPT=6345 DPT=39172 00:01:07 SRC=98.162.240.76 DST=67.200.200.00 SPT=7345 DPT=39172 00:01:07 SRC=98.162.240.76 DST=67.200.200.00 SPT=8345 DPT=39172 00:01:07 SRC=98.162.240.76 DST=67.200.200.00 SPT=9345 DPT=39172
April 24th 2009 - 00:01:28
00:01:28 SRC=201.160.203.114 DST=67.200.200.00 SPT=1345 DPT=39172 00:01:28 SRC=201.160.203.114 DST=67.200.200.00 SPT=2345 DPT=39172 00:01:28 SRC=201.160.203.114 DST=67.200.200.00 SPT=3345 DPT=39172 00:01:28 SRC=201.160.203.114 DST=67.200.200.00 SPT=4345 DPT=39172 00:01:28 SRC=201.160.203.114 DST=67.200.200.00 SPT=5345 DPT=39172 00:01:28 SRC=201.160.203.114 DST=67.200.200.00 SPT=6345 DPT=39172 00:01:28 SRC=201.160.203.114 DST=67.200.200.00 SPT=7345 DPT=39172 00:01:28 SRC=201.160.203.114 DST=67.200.200.00 SPT=8345 DPT=39172 00:01:28 SRC=201.160.203.114 DST=67.200.200.00 SPT=9345 DPT=39172 00:01:28 SRC=68.33.192.177 DST=67.200.200.00 SPT=1345 DPT=39172 00:01:28 SRC=68.33.192.177 DST=67.200.200.00 SPT=2345 DPT=39172 00:01:28 SRC=68.33.192.177 DST=67.200.200.00 SPT=3345 DPT=39172 00:01:28 SRC=68.33.192.177 DST=67.200.200.00 SPT=4345 DPT=39172 00:01:28 SRC=68.33.192.177 DST=67.200.200.00 SPT=5345 DPT=39172 00:01:28 SRC=68.33.192.177 DST=67.200.200.00 SPT=6345 DPT=39172 00:01:28 SRC=68.33.192.177 DST=67.200.200.00 SPT=7345 DPT=39172 00:01:28 SRC=68.33.192.177 DST=67.200.200.00 SPT=8345 DPT=39172 00:01:28 SRC=68.33.192.177 DST=67.200.200.00 SPT=9345 DPT=39172 00:01:28 SRC=69.133.95.19 DST=67.200.200.00 SPT=1345 DPT=39172 00:01:28 SRC=69.133.95.19 DST=67.200.200.00 SPT=2345 DPT=39172 00:01:28 SRC=69.133.95.19 DST=67.200.200.00 SPT=3345 DPT=39172 00:01:28 SRC=69.133.95.19 DST=67.200.200.00 SPT=4345 DPT=39172 00:01:28 SRC=69.133.95.19 DST=67.200.200.00 SPT=5345 DPT=39172 00:01:28 SRC=69.133.95.19 DST=67.200.200.00 SPT=6345 DPT=39172 00:01:28 SRC=69.133.95.19 DST=67.200.200.00 SPT=7345 DPT=39172 00:01:28 SRC=69.133.95.19 DST=67.200.200.00 SPT=8345 DPT=39172 00:01:28 SRC=69.133.95.19 DST=67.200.200.00 SPT=9345 DPT=39172 00:01:28 SRC=24.125.136.43 DST=67.200.200.00 SPT=1345 DPT=39172 00:01:28 SRC=24.125.136.43 DST=67.200.200.00 SPT=2345 DPT=39172 00:01:28 SRC=24.125.136.43 DST=67.200.200.00 SPT=3345 DPT=39172 00:01:28 SRC=24.125.136.43 DST=67.200.200.00 SPT=4345 DPT=39172 00:01:28 SRC=24.125.136.43 DST=67.200.200.00 SPT=5345 DPT=39172 00:01:28 SRC=24.125.136.43 DST=67.200.200.00 SPT=6345 DPT=39172 00:01:28 SRC=24.125.136.43 DST=67.200.200.00 SPT=7345 DPT=39172 00:01:28 SRC=24.125.136.43 DST=67.200.200.00 SPT=8345 DPT=39172 00:01:28 SRC=24.125.136.43 DST=67.200.200.00 SPT=9345 DPT=39172
April 24th 2009 - 00:02:02
00:02:02 SRC=189.216.93.18 DST=67.200.200.00 SPT=1345 DPT=39172 00:02:02 SRC=189.216.93.18 DST=67.200.200.00 SPT=2345 DPT=39172 00:02:02 SRC=189.216.93.18 DST=67.200.200.00 SPT=3345 DPT=39172 00:02:02 SRC=189.216.93.18 DST=67.200.200.00 SPT=4345 DPT=39172 00:02:02 SRC=189.216.93.18 DST=67.200.200.00 SPT=5345 DPT=39172 00:02:02 SRC=189.216.93.18 DST=67.200.200.00 SPT=6345 DPT=39172 00:02:02 SRC=189.216.93.18 DST=67.200.200.00 SPT=7345 DPT=39172 00:02:02 SRC=189.216.93.18 DST=67.200.200.00 SPT=8345 DPT=39172 00:02:02 SRC=189.216.93.18 DST=67.200.200.00 SPT=9345 DPT=39172 00:02:02 SRC=68.103.145.120 DST=67.200.200.00 SPT=1345 DPT=39172 00:02:02 SRC=68.103.145.120 DST=67.200.200.00 SPT=2345 DPT=39172 00:02:02 SRC=68.103.145.120 DST=67.200.200.00 SPT=3345 DPT=39172 00:02:02 SRC=68.103.145.120 DST=67.200.200.00 SPT=4345 DPT=39172 00:02:02 SRC=68.103.145.120 DST=67.200.200.00 SPT=5345 DPT=39172 00:02:02 SRC=68.103.145.120 DST=67.200.200.00 SPT=6345 DPT=39172 00:02:02 SRC=68.103.145.120 DST=67.200.200.00 SPT=7345 DPT=39172 00:02:02 SRC=68.103.145.120 DST=67.200.200.00 SPT=8345 DPT=39172 00:02:02 SRC=68.103.145.120 DST=67.200.200.00 SPT=9345 DPT=39172 00:02:02 SRC=92.96.17.155 DST=67.200.200.00 SPT=1345 DPT=39172 00:02:02 SRC=92.96.17.155 DST=67.200.200.00 SPT=2345 DPT=39172 00:02:02 SRC=92.96.17.155 DST=67.200.200.00 SPT=3345 DPT=39172 00:02:02 SRC=92.96.17.155 DST=67.200.200.00 SPT=4345 DPT=39172 00:02:02 SRC=92.96.17.155 DST=67.200.200.00 SPT=5345 DPT=39172 00:02:02 SRC=92.96.17.155 DST=67.200.200.00 SPT=6345 DPT=39172 00:02:02 SRC=92.96.17.155 DST=67.200.200.00 SPT=7345 DPT=39172 00:02:02 SRC=92.96.17.155 DST=67.200.200.00 SPT=8345 DPT=39172 00:02:02 SRC=92.96.17.155 DST=67.200.200.00 SPT=9345 DPT=39172 00:02:02 SRC=69.133.95.19 DST=67.200.200.00 SPT=1345 DPT=39172 00:02:02 SRC=69.133.95.19 DST=67.200.200.00 SPT=2345 DPT=39172 00:02:02 SRC=69.133.95.19 DST=67.200.200.00 SPT=3345 DPT=39172 00:02:02 SRC=69.133.95.19 DST=67.200.200.00 SPT=4345 DPT=39172 00:02:02 SRC=69.133.95.19 DST=67.200.200.00 SPT=5345 DPT=39172 00:02:02 SRC=69.133.95.19 DST=67.200.200.00 SPT=6345 DPT=39172 00:02:02 SRC=69.133.95.19 DST=67.200.200.00 SPT=7345 DPT=39172 00:02:02 SRC=69.133.95.19 DST=67.200.200.00 SPT=8345 DPT=39172 00:02:02 SRC=69.133.95.19 DST=67.200.200.00 SPT=9345 DPT=39172
April 24th 2009 - 00:02:19
00:02:19 SRC=69.115.175.27 DST=67.200.200.00 SPT=1345 DPT=39172 00:02:19 SRC=69.115.175.27 DST=67.200.200.00 SPT=2345 DPT=39172 00:02:19 SRC=69.115.175.27 DST=67.200.200.00 SPT=3345 DPT=39172 00:02:19 SRC=69.115.175.27 DST=67.200.200.00 SPT=4345 DPT=39172 00:02:19 SRC=69.115.175.27 DST=67.200.200.00 SPT=5345 DPT=39172 00:02:19 SRC=69.115.175.27 DST=67.200.200.00 SPT=6345 DPT=39172 00:02:19 SRC=69.115.175.27 DST=67.200.200.00 SPT=7345 DPT=39172 00:02:19 SRC=69.115.175.27 DST=67.200.200.00 SPT=8345 DPT=39172 00:02:19 SRC=69.115.175.27 DST=67.200.200.00 SPT=9345 DPT=39172 00:02:19 SRC=83.114.40.4 DST=67.200.200.00 SPT=1345 DPT=39172 00:02:19 SRC=83.114.40.4 DST=67.200.200.00 SPT=2345 DPT=39172 00:02:19 SRC=83.114.40.4 DST=67.200.200.00 SPT=3345 DPT=39172 00:02:19 SRC=83.114.40.4 DST=67.200.200.00 SPT=4345 DPT=39172 00:02:19 SRC=83.114.40.4 DST=67.200.200.00 SPT=5345 DPT=39172 00:02:19 SRC=83.114.40.4 DST=67.200.200.00 SPT=6345 DPT=39172 00:02:19 SRC=83.114.40.4 DST=67.200.200.00 SPT=7345 DPT=39172 00:02:19 SRC=83.114.40.4 DST=67.200.200.00 SPT=8345 DPT=39172 00:02:19 SRC=83.114.40.4 DST=67.200.200.00 SPT=9345 DPT=39172 00:02:19 SRC=69.231.217.167 DST=67.200.200.00 SPT=1345 DPT=39172 00:02:19 SRC=69.231.217.167 DST=67.200.200.00 SPT=2345 DPT=39172 00:02:19 SRC=69.231.217.167 DST=67.200.200.00 SPT=3345 DPT=39172 00:02:19 SRC=69.231.217.167 DST=67.200.200.00 SPT=4345 DPT=39172 00:02:19 SRC=69.231.217.167 DST=67.200.200.00 SPT=5345 DPT=39172 00:02:19 SRC=69.231.217.167 DST=67.200.200.00 SPT=6345 DPT=39172 00:02:19 SRC=69.231.217.167 DST=67.200.200.00 SPT=7345 DPT=39172 00:02:19 SRC=69.231.217.167 DST=67.200.200.00 SPT=8345 DPT=39172 00:02:19 SRC=69.231.217.167 DST=67.200.200.00 SPT=9345 DPT=39172 00:02:19 SRC=68.1.81.23 DST=67.200.200.00 SPT=1345 DPT=39172 00:02:19 SRC=68.1.81.23 DST=67.200.200.00 SPT=2345 DPT=39172 00:02:19 SRC=68.1.81.23 DST=67.200.200.00 SPT=3345 DPT=39172 00:02:19 SRC=68.1.81.23 DST=67.200.200.00 SPT=4345 DPT=39172 00:02:19 SRC=68.1.81.23 DST=67.200.200.00 SPT=5345 DPT=39172 00:02:19 SRC=68.1.81.23 DST=67.200.200.00 SPT=6345 DPT=39172 00:02:19 SRC=68.1.81.23 DST=67.200.200.00 SPT=7345 DPT=39172 00:02:19 SRC=68.1.81.23 DST=67.200.200.00 SPT=8345 DPT=39172 00:02:19 SRC=68.1.81.23 DST=67.200.200.00 SPT=9345 DPT=39172
Are you fucking kidding me? I've been on the Internet for over 12 years and have never seen any shit like this, not anything that was considered legitimate traffic anyway. After bringing this to the attention of a few people I converse with, someone sent me this: http://www.internap.com/flash/fcp/fcp.swf
WTF is this, some kind of joke? Not sure if anyone put forth the thought toward considering this, but technology is advancing - getting better. The entire concept sounds like a big ass sales pitch, and if you think for one second the available capacity for the global infrastructure is anywhere near the maximum, you're sadly mistaken.
You do know there's hardware capable of moving up to 400 million packets a second across 32, 10-Gb trunks, right? If your provider has "traffic congestion" problems, it's time to reconsider.
Seriously, who on earth thinks sending traffic like this to not just my IP, but every intended destination IP on the Internet, is a good idea?
Word Count: 1990




2 (Comments|Trackbacks)
[ RSS feed | Trackback URI | Leave a Comment ]
Guypat -
In someways I can see your frustration in regards to the "unwanted" traffic that the FCP's are causing and yes, it is a little dis concerning to see that amount of traffic your not used to seeing on a regular basis. Get used to it! FCP has just recently in the past few years been made available for use by private corporations and in the next 2 years will be used by every major ISP, Data Center, and Network Solutions company in the world. It has in the past only been used by government and military agencies to increase private connection across WAN Links. The fact that we have devices that can transmit Gigs and Gigs of data mean nothing when the city you live in can barley offer you a 6Mb connection and that every surrounding city still has 20-40% of its population on Dial Up. If the US would stop hoarding all the darkfiber and stop holding us back, Technology like FCP would not be needed and would definitley not be in place. But the fact is, the US is nowhere near the top when it comes to pipes and available speeds. Companies that rely 100% solely on their internet connection NEED faster, more reliable, smarter connections. FCP may cause unwanted traffic, so what? It's for a greater good and an attempt to help people like me and you achieve what we truly believe we deserve when it comes to our interwebz... SPEED!. You get hit thousands if not millions of times a day by automated nmap scans, Trojans, viruses, and broadcast traffic that have no true value to them. So why care about some traffic that is actually helping the Internet? I would assume you want Google, MSN, Yahoo and others to hit Nullamatix.com every second of every day, why, because its helping you get indexed and ranked, and the traffic is considered useful, not a nuisance. Think of FCP as a google scrape for a Sr. Networking Engineer that works at a Level V DC, or is a Chief Technology Architect for a major ISP, FCP is to them what a google scrape is to you... a good packet. Point being, yes, unwanted traffic is being caused and being noticed by people like me and you that actually look at firewall logs and notice traffic patterns, however you can't honestly tell me that if the company that Nullamatix.com is hosted off of says they are going to implement FCP to help YOU, that you would disagree.
Does anyone know of the location of any whitepapers detailing the port broadcasting portion of FCP appliances?
Leave a Comment
Trackback Responses to This Post: