Tracking hit - UDP OUT flood?
Posted: 29 Sep 2013, 09:26
Hello,
What is this all about? We receive this when our clients install a new San Andreas server
We receice this email:
Sample of port hits:
Sep 29 11:03:10 server1 kernel: Firewall: *UDP_OUT Blocked* IN= OUT=eth0 SRC=94.176.*.* DST=83.103.133.168 LEN=117 TOS=0x00 PREC=0x00 TTL=64 ID=0 DF PROTO=UDP SPT=7777 DPT=52209 LEN=97 UID=32043 GID=32044
Sep 29 11:03:12 server1 kernel: Firewall: *UDP_OUT Blocked* IN= OUT=eth0 SRC=94.176.*.* DST=83.103.133.168 LEN=43 TOS=0x00 PREC=0x00 TTL=64 ID=0 DF PROTO=UDP SPT=7777 DPT=52209 LEN=23 UID=32043 GID=32044
There are many ip's, I provided only the first 2 lines
And we have this in /var/log/lfd.log
Sep 29 11:02:05 server1 lfd[24302]: *UID Tracking* 11 blocks for UID 32043 (username)
Sep 29 11:02:25 server1 lfd[24431]: *UID Tracking* 11 blocks for UID 32043 (username)
I hardly beleive this could be an outgoing flood, because this started since the last csf update, and this thing happens on many of our clients, not just one.
What is this all about? We receive this when our clients install a new San Andreas server
We receice this email:
Sample of port hits:
Sep 29 11:03:10 server1 kernel: Firewall: *UDP_OUT Blocked* IN= OUT=eth0 SRC=94.176.*.* DST=83.103.133.168 LEN=117 TOS=0x00 PREC=0x00 TTL=64 ID=0 DF PROTO=UDP SPT=7777 DPT=52209 LEN=97 UID=32043 GID=32044
Sep 29 11:03:12 server1 kernel: Firewall: *UDP_OUT Blocked* IN= OUT=eth0 SRC=94.176.*.* DST=83.103.133.168 LEN=43 TOS=0x00 PREC=0x00 TTL=64 ID=0 DF PROTO=UDP SPT=7777 DPT=52209 LEN=23 UID=32043 GID=32044
There are many ip's, I provided only the first 2 lines
And we have this in /var/log/lfd.log
Sep 29 11:02:05 server1 lfd[24302]: *UID Tracking* 11 blocks for UID 32043 (username)
Sep 29 11:02:25 server1 lfd[24431]: *UID Tracking* 11 blocks for UID 32043 (username)
I hardly beleive this could be an outgoing flood, because this started since the last csf update, and this thing happens on many of our clients, not just one.