[GTER] RES: TCP: Treason uncloaked

Fabio fabio.corp2 at gmail.com
Tue Jul 4 17:33:17 -03 2006


Se voce rodar algum IDS/IPS poderia identificar
melhor
oque esta acontecendo na sua rede. Caso seja
ataque.

Abs,
Fabio

-----Mensagem original-----
De: gter-bounces at eng.registro.br
[mailto:gter-bounces at eng.registro.br] Em nome de
Rafael Sanches
Enviada em: terça-feira, 4 de julho de 2006 17:27
Para: Grupo de Trabalho de Engenharia e Operacao
de Redes
Assunto: Re: [GTER] TCP: Treason uncloaked

pode ser....

pacote danificado

pode ser ataque

pode ser scan de porta

----- Original Message -----
From: "Welington F.J" <welingtonfj at gmail.com>
To: "Grupo de Trabalho de Engenharia e Operacao de
Redes" 
<gter at eng.registro.br>
Sent: Tuesday, July 04, 2006 5:13 PM
Subject: Re: [GTER] TCP: Treason uncloaked


Será que isto é algum tipo de ataque?

TCP: Treason uncloaked! Peer
200.218.184.94:2115/80 shrinks window
898022887:898022888. Repaired.
TCP: Treason uncloaked! Peer
200.218.184.94:2114/80 shrinks window
899050744:899050745. Repaired.
TCP: Treason uncloaked! Peer
200.218.184.94:2113/80 shrinks window
898743032:898743033. Repaired.
TCP: Treason uncloaked! Peer
200.218.184.94:2115/80 shrinks window
898022887:898022888. Repaired.
TCP: Treason uncloaked! Peer
200.218.184.94:2117/80 shrinks window
912089373:912089374. Repaired.
TCP: Treason uncloaked! Peer
200.218.184.94:2117/80 shrinks window
912089373:912089374. Repaired.
TCP: Treason uncloaked! Peer
200.218.184.94:2134/80 shrinks window
925263449:925263450. Repaired.
TCP: Treason uncloaked! Peer
200.218.184.94:2134/80 shrinks window
925263449:925263450. Repaired.
TCP: Treason uncloaked! Peer
200.219.181.31:63707/80 shrinks window
526537549:526537639. Repaired.
TCP: Treason uncloaked! Peer
200.219.162.76:57051/80 shrinks window
4265127851:4265127852. Repaired.
TCP: Treason uncloaked! Peer
200.219.162.76:57049/80 shrinks window
4269572713:4269572714. Repaired.
TCP: Treason uncloaked! Peer
200.219.162.76:57049/80 shrinks window
4269572713:4269572714. Repaired.
TCP: Treason uncloaked! Peer
200.219.181.37:43369/80 shrinks window
3508056182:3508056183. Repaired.
TCP: Treason uncloaked! Peer
200.219.181.37:43379/80 shrinks window
3601401975:3601401976. Repaired.
TCP: Treason uncloaked! Peer
200.219.181.37:43380/80 shrinks window
3589344350:3589344351. Repaired.
TCP: Treason uncloaked! Peer 200.219.181.37:4338

como Juliano disse,  a maioria são do range
200.219.0/16, mas teve de
outras localidades também
TCP: Treason uncloaked! Peer
200.142.162.230:59333/80 shrinks window 
1547792657
TCP: Treason uncloaked! Peer
217.26.84.214:54741/80 shrinks window
2063957622:2063958958. Repaired


Alguém sabe responder o porque dessas msg?


On 7/4/06, juliano at cyberweb.com.br
<juliano at cyberweb.com.br> wrote:
> Senhores,
>
> E alguém sabe por que em 95% das vezes que
aparecem estas mensagens, são
> do range 200.219.0/16?
>
> Juliano
>
> > Senhores,
> >  Alguém sabe pq fica aparecendo esta mensagem
no dmesg
> >
> > TCP: Treason uncloaked! Peer
200.219.162.76:47844/80 shrinks window
> > 676889573:676889574. Repaired.
> > TCP: Treason uncloaked! Peer
200.219.162.76:47844/80 shrinks window
> > 676889573:676889574. Repaired.
> > TCP: Treason uncloaked! Peer
200.219.162.76:47865/80 shrinks window
> > 748892456:748892457. Repaired.
> > TCP: Treason uncloaked! Peer
200.219.162.76:47882/80 shrinks window
> > 800682022:800682023. Repaired.
> > TCP: Treason uncloaked! Peer
200.219.162.76:47882/80 shrinks window
> > 800682022:800682023. Repaired.
> > TCP: Treason uncloaked! Peer
200.219.162.76:47902/80 shrinks window
> > 824555134:824555135. Repaired.
> > TCP: Treason uncloaked! Peer
200.219.162.76:47904/80 shrinks window
> > 850905032:850905033. Repaired.
> >
> >
> > Att,
> > --
> > Welington F.J
> > BSD User: 51392
> > ICQ: 31320518
> > MSN: welingtonfj at hotmail.com
> > Drogas ? Pra que? Já Tenho Meu Windows!!
> > --
> > gter list
https://eng.registro.br/mailman/listinfo/gter
> >
>
>
> --
> gter list
https://eng.registro.br/mailman/listinfo/gter
>


-- 
Welington F.J
BSD User: 51392
ICQ: 31320518
MSN: welingtonfj at hotmail.com
Drogas ? Pra que? Já Tenho Meu Windows!!
--
gter list
https://eng.registro.br/mailman/listinfo/gter

--
gter list
https://eng.registro.br/mailman/listinfo/gter




More information about the gter mailing list