Jump to content
We're Hiring! Full Stack Developer ×

Weird logs, am i being hacked?


TUMS

Recommended Posts

First of all everything is behind a NAT router running shibby tomato.  No ports are open including, uPnP/NAT PNP all turned off.

All unraid user shares are locked down to read only.

 

I'm running binhex delugeVPN docker (PIA VPN) downloading a torrent and i'm starting to see these messages i've never seen before in my main unraid log.

 

Sep 22 12:48:12 Tower kernel: TCP: request_sock_TCP: Possible SYN flooding on port 34499. Sending cookies. Check SNMP counters.
Sep 22 16:06:45 Tower kernel: TCP: request_sock_TCP: Possible SYN flooding on port 33276. Sending cookies. Check SNMP counters.
Sep 22 16:50:43 Tower kernel: TCP: request_sock_TCP: Possible SYN flooding on port 33276. Sending cookies. Check SNMP counters.

 

And also...

 

Sep 23 06:33:59 Tower ntpd[1652]: receive: Unexpected origin timestamp 0xdb8fadc1.5c9985f4 does not match aorg 0xdb8fadc7.5c979921 from [email protected] xmt 0xdb8fadc7.21f36638
Sep 23 06:34:01 Tower ntpd[1652]: receive: Unexpected origin timestamp 0xdb8fadc3.5c9b42ef does not match aorg 0xdb8fadc9.5c9b309d from [email protected] xmt 0xdb8fadc9.3484eae4
Sep 23 06:34:03 Tower ntpd[1652]: receive: Unexpected origin timestamp 0xdb8fadc5.5c9b3628 does not match aorg 0xdb8fadc9.5c9b309d from [email protected] xmt 0xdb8fadcb.2f607f95
Sep 23 06:34:05 Tower ntpd[1652]: receive: Unexpected origin timestamp 0xdb8fadc7.5c979921 does not match aorg 0xdb8fadc9.5c9b309d from [email protected] xmt 0xdb8fadcd.19ecf94f

 

Just wondering is this anything to worry about?  It's got to be something to do with the torrent i'm downloading. My guess is that it's harmless but I just want to check.

Link to comment
  • 4 years later...
On 9/23/2016 at 5:53 PM, TUMS said:

 

I'm running binhex delugeVPN docker (PIA VPN) downloading a torrent and i'm starting to see these messages i've never seen before in my main unraid log.

 

 


Sep 22 12:48:12 Tower kernel: TCP: request_sock_TCP: Possible SYN flooding on port 34499. Sending cookies. Check SNMP counters.
Sep 22 16:06:45 Tower kernel: TCP: request_sock_TCP: Possible SYN flooding on port 33276. Sending cookies. Check SNMP counters.
Sep 22 16:50:43 Tower kernel: TCP: request_sock_TCP: Possible SYN flooding on port 33276. Sending cookies. Check SNMP counters.
 

Happening to me too. How did you manage to fix it?

Link to comment

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.
Note: Your post will require moderator approval before it will be visible.

Guest
Reply to this topic...

×   Pasted as rich text.   Restore formatting

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

×
×
  • Create New...