Forums

Resolved
0 votes
Hello all,
I've a problem on my network and here my knowledges are limited so ...
First we have been blocked by spamhaus project using the XBL tool. It seems a computer of my newtork sent some spam 3 days ago. the problem for me is to know which one ... so I began to have a look on the my COS logs files and I discovered I could not start the intrusion and detection components !
in my logs, I've the following :

pr 18 08:50:01 srv-cos systemd: Starting Session 11429 of user root.
Apr 18 08:50:01 srv-cos systemd: Started Session 11430 of user root.
Apr 18 08:50:01 srv-cos systemd: Starting Session 11430 of user root.
Apr 18 08:50:01 srv-cos systemd: Started Session 11428 of user root.
Apr 18 08:50:01 srv-cos systemd: Starting Session 11428 of user root.
Apr 18 08:50:01 srv-cos arpwatch: bogon 192.168.0.120 d4:ae:52:9f:57:c9
Apr 18 08:50:31 srv-cos systemd: Stopping SYSV: SnortSAM dynamic firewall plug-in for Snort...
Apr 18 08:50:31 srv-cos snortsam: /etc/rc.d/init.d/snortsam: ligne 15 : [: = : opérateur unaire attendu
Apr 18 08:50:31 srv-cos snortsam: Stopping snortsam: [ÉCHOUÉ]
Apr 18 08:50:31 srv-cos systemd: Stopped SYSV: SnortSAM dynamic firewall plug-in for Snort.
Apr 18 08:50:32 srv-cos arpwatch: bogon 192.168.0.120 d4:ae:52:9f:57:c9
Apr 18 08:50:33 srv-cos systemd: Starting SYSV: SnortSAM dynamic firewall plug-in for Snort...
Apr 18 08:50:33 srv-cos snortsam: /etc/rc.d/init.d/snortsam: ligne 15 : [: = : opérateur unaire attendu
Apr 18 08:50:33 srv-cos snortsam: Starting snortsam: ... delaying[ OK ]
Apr 18 08:50:33 srv-cos systemd: Started SYSV: SnortSAM dynamic firewall plug-in for Snort.
Apr 18 08:51:02 srv-cos arpwatch: bogon 192.168.0.120 d4:ae:52:9f:57:c9
Apr 18 08:51:03 srv-cos systemd: Stopping SYSV: Snort Network Intrusion Detection System...
Apr 18 08:51:04 srv-cos systemd: Stopped SYSV: Snort Network Intrusion Detection System.
Apr 18 08:51:06 srv-cos systemd: Starting SYSV: Snort Network Intrusion Detection System...
Apr 18 08:51:06 srv-cos systemd: Started SYSV: Snort Network Intrusion Detection System.
Apr 18 08:51:21 srv-cos systemd: Stopping SYSV: Snort Network Intrusion Detection System...
Apr 18 08:51:21 srv-cos systemd: Stopped SYSV: Snort Network Intrusion Detection System.
Apr 18 08:51:21 srv-cos systemd: Starting SYSV: Snort Network Intrusion Detection System...
Apr 18 08:51:21 srv-cos systemd: Started SYSV: Snort Network Intrusion Detection System.

it seems the the IP adress is used by another system because when I do a #arp -n on my ClearOS server, I don't get the same mac address as the one on the log ...
#arp -n : 192.168.100.120 ether 3c:d9:2b:58:33:5d C eth6

I dont know here if got my system hacked ... and what to do ..

Thanks for your help
Tuesday, April 18 2017, 07:10 AM
Share this post:
Responses (2)
  • Accepted Answer

    Tuesday, April 18 2017, 03:00 PM - #Permalink
    Resolved
    0 votes
    Hello Nick,
    Yes, the logs come from my clearos system ; the arp -n came from my workstation. Can't make a new one yet because the computer is halted .. I'll see tomorrow .. but my knowledges are here limited ...:(
    Thanks for your help :)
    The reply is currently minimized Show
  • Accepted Answer

    Tuesday, April 18 2017, 11:22 AM - #Permalink
    Resolved
    0 votes
    Can you confirm the IP address? The one you've used for the arp command is different from the one in the log.
    The reply is currently minimized Show
Your Reply