Forums

Resolved
0 votes
Hello all,
I've a problem on my network and here my knowledges are limited so ...
First we have been blocked by spamhaus project using the XBL tool. It seems a computer of my newtork sent some spam 3 days ago. the problem for me is to know which one ... so I began to have a look on the my COS logs files and I discovered I could not start the intrusion and detection components !
in my logs, I've the following :

pr 18 08:50:01 srv-cos systemd: Starting Session 11429 of user root.
Apr 18 08:50:01 srv-cos systemd: Started Session 11430 of user root.
Apr 18 08:50:01 srv-cos systemd: Starting Session 11430 of user root.
Apr 18 08:50:01 srv-cos systemd: Started Session 11428 of user root.
Apr 18 08:50:01 srv-cos systemd: Starting Session 11428 of user root.
Apr 18 08:50:01 srv-cos arpwatch: bogon 192.168.0.120 d4:ae:52:9f:57:c9
Apr 18 08:50:31 srv-cos systemd: Stopping SYSV: SnortSAM dynamic firewall plug-in for Snort...
Apr 18 08:50:31 srv-cos snortsam: /etc/rc.d/init.d/snortsam: ligne 15 : [: = : opérateur unaire attendu
Apr 18 08:50:31 srv-cos snortsam: Stopping snortsam: [ÉCHOUÉ]
Apr 18 08:50:31 srv-cos systemd: Stopped SYSV: SnortSAM dynamic firewall plug-in for Snort.
Apr 18 08:50:32 srv-cos arpwatch: bogon 192.168.0.120 d4:ae:52:9f:57:c9
Apr 18 08:50:33 srv-cos systemd: Starting SYSV: SnortSAM dynamic firewall plug-in for Snort...
Apr 18 08:50:33 srv-cos snortsam: /etc/rc.d/init.d/snortsam: ligne 15 : [: = : opérateur unaire attendu
Apr 18 08:50:33 srv-cos snortsam: Starting snortsam: ... delaying[ OK ]
Apr 18 08:50:33 srv-cos systemd: Started SYSV: SnortSAM dynamic firewall plug-in for Snort.
Apr 18 08:51:02 srv-cos arpwatch: bogon 192.168.0.120 d4:ae:52:9f:57:c9
Apr 18 08:51:03 srv-cos systemd: Stopping SYSV: Snort Network Intrusion Detection System...
Apr 18 08:51:04 srv-cos systemd: Stopped SYSV: Snort Network Intrusion Detection System.
Apr 18 08:51:06 srv-cos systemd: Starting SYSV: Snort Network Intrusion Detection System...
Apr 18 08:51:06 srv-cos systemd: Started SYSV: Snort Network Intrusion Detection System.
Apr 18 08:51:21 srv-cos systemd: Stopping SYSV: Snort Network Intrusion Detection System...
Apr 18 08:51:21 srv-cos systemd: Stopped SYSV: Snort Network Intrusion Detection System.
Apr 18 08:51:21 srv-cos systemd: Starting SYSV: Snort Network Intrusion Detection System...
Apr 18 08:51:21 srv-cos systemd: Started SYSV: Snort Network Intrusion Detection System.

it seems the the IP adress is used by another system because when I do a #arp -n on my ClearOS server, I don't get the same mac address as the one on the log ...
#arp -n : 192.168.100.120 ether 3c:d9:2b:58:33:5d C eth6

I dont know here if got my system hacked ... and what to do ..

Thanks for your help
Tuesday, April 18 2017, 07:10 AM
Share this post:
Responses (2)
  • Accepted Answer

    Tuesday, April 18 2017, 11:22 AM - #Permalink
    Resolved
    0 votes
    Can you confirm the IP address? The one you've used for the arp command is different from the one in the log.
    The reply is currently minimized Show
  • Accepted Answer

    Tuesday, April 18 2017, 03:00 PM - #Permalink
    Resolved
    0 votes
    Hello Nick,
    Yes, the logs come from my clearos system ; the arp -n came from my workstation. Can't make a new one yet because the computer is halted .. I'll see tomorrow .. but my knowledges are here limited ...:(
    Thanks for your help :)
    The reply is currently minimized Show
Your Reply