|

楼主 |
发表于 2004-2-12 09:35:01
|
显示全部楼层
这是我看到的ipf的日志 代表什么? 使用还是扫描?
11/02/2004 13:22:49.347675 fxp0 @0:5 P 0.0.0.0,68 -> 255.255.255.255,67 PR udp len 20 604 IN
11/02/2004 13:22:49.535238 fxp1 @0:7 P 192.168.0.253,138 -> 192.168.1.255,138 PR udp len 20 229 IN
11/02/2004 13:22:51.410828 fxp0 @0:5 P 0.0.0.0,68 -> 255.255.255.255,67 PR udp len 20 604 IN
11/02/2004 13:22:53.503927 fxp0 @0:5 P 0.0.0.0,68 -> 255.255.255.255,67 PR udp len 20 604 IN
11/02/2004 13:22:54.589876 fxp0 @0:5 P 62.73.175.206 -> 218.4.58.36 PR icmp len 20 92 icmp echo/0 IN
11/02/2004 13:22:54.589934 fxp0 @0:1 P 218.4.58.36 -> 62.73.175.206 PR icmp len 20 92 icmp echoreply/0 OUT
11/02/2004 13:22:55.334406 fxp0 @0:5 P 62.73.175.206,3585 -> 192.168.1.16,80 PR tcp len 20 48 -S IN
11/02/2004 13:22:55.334449 fxp1 @0:3 P 62.73.175.206,3585 -> 192.168.1.16,80 PR tcp len 20 48 -S OUT
11/02/2004 13:22:55.539678 fxp0 @0:5 P 0.0.0.0,68 -> 255.255.255.255,67 PR udp len 20 604 IN
11/02/2004 20:39:09.666894 fxp0 @0:2 b 219.138.237.251 -> 218.4.58.36 PR udp len 20 (112) frag 92@1432 IN
11/02/2004 20:44:27.674161 fxp0 @0:2 b 219.138.237.197,5188 -> 218.4.58.36,135 PR udp len 20 1452 IN
11/02/2004 20:44:27.675776 fxp0 @0:2 b 219.138.237.197 -> 218.4.58.36 PR udp len 20 (112) frag 92@1432 IN
12/02/2004 00:56:00.014091 fxp0 @0:2 b 218.47.189.170 -> 218.4.58.36 PR tcp len 20 (40) frag 20@264 IN |
|