What does all this mean and how to I fix it so my server can come back online?
-----------------
AUP Violations - Unplugged
Problem Description: 12/24/03 11:12:36 AM
i pulled 66.98.180.16 for an aup./tos violation a denial of service packet flood attack
source ip 66.98.180.16
destination ip 201.4.236.1
sample of cap
1 2003-12-24 10:22:14.6607 66.98.180.26 -> 64.246.1.58 TCP 3306 > 37218 [ACK] Seq=4066722647 Ack=2004030929 Win=5792 Len=1448
2 2003-12-24 10:22:14.6608 66.98.180.16 -> 201.4.236.1 UDP Source port: 34725 Destination port: 6843
3 2003-12-24 10:22:14.6608 66.98.180.26 -> 64.246.1.58 TCP 3306 > 37218 [PSH, ACK] Seq=4066724095 Ack=2004030929 Win=5792 Len=569
4 2003-12-24 10:22:14.6608 66.98.180.16 -> 201.4.236.1 UDP Source port: 34725 Destination port: 64149
5 2003-12-24 10:22:14.6608 66.98.180.16 -> 201.4.236.1 UDP Source port: 34725 Destination port: 42858
6 2003-12-24 10:22:14.6608 66.98.180.16 -> 201.4.236.1 UDP Source port: 34725 Destination port: 41678
7 2003-12-24 10:22:14.6608 66.98.180.16 -> 201.4.236.1 UDP Source port: 34725 Destination port: 8630
8 2003-12-24 10:22:14.6608 66.98.180.16 -> 201.4.236.1 UDP Source port: 34725 Destination port: 13831
9 2003-12-24 10:22:14.6608 66.98.180.16 -> 201.4.236.1 UDP Source port: 34725 Destination port: 14449
10 2003-12-24 10:22:14.6608 66.98.180.16 -> 201.4.236.1 UDP Source port: 34725 Destination port: 23310
11 2003-12-24 10:22:14.6608 66.98.180.16 -> 201.4.236.1 UDP Source port: 34725 Destination port: 29563
12 2003-12-24 10:22:14.6608 66.98.180.16 -> 201.4.236.1 UDP Source port: 34725 Destination port: 63342
13 2003-12-24 10:22:14.6608 66.98.180.16 -> 201.4.236.1 UDP Source port: 34725 Destination port: 19316
14 2003-12-24 10:22:14.6608 66.98.180.15 -> 171.75.215.245 TCP 80 > 2611 [ACK] Seq=1131677400 Ack=2039209923 Win=7504 Len=0
15 2003-12-24 10:22:14.6608 66.98.180.16 -> 201.4.236.1 UDP Source port: 34725 Destination port: 42626
16 2003-12-24 10:22:14.6608 66.98.180.16 -> 201.4.236.1 UDP Source port: 34725 Destination port: 39422
17 2003-12-24 10:22:14.6608 66.98.180.16 -> 201.4.236.1 UDP Source port: 34725 Destination port: 54413
18 2003-12-24 10:22:14.6608 139.55.218.242 -> 66.98.180.7 TCP 1034 > 80 [ACK] Seq=126888180 Ack=1681209442 Win=17424 Len=0
19 2003-12-24 10:22:14.6608 66.98.180.16 -> 201.4.236.1 UDP Source port: 34725 Destination port: 60170
20 2003-12-24 10:22:14.6608 66.98.180.16 -> 201.4.236.1 UDP Source port: 34725 Destination port: 31770
21 2003-12-24 10:22:14.6608 66.98.180.16 -> 201.4.236.1 UDP Source port: 34725 Destination port: 42345
22 2003-12-24 10:22:14.6608 66.98.180.16 -> 201.4.236.1 UDP Source port: 34725 Destination port: 23420
23 2003-12-24 10:22:14.6608 66.98.180.16 -> 201.4.236.1 UDP Source port: 34725 Destination port: 10840
24 2003-12-24 10:22:14.6608 66.98.180.16 -> 201.4.236.1 UDP Source port: 34725 Destination port: 845
25 2003-12-24 10:22:14.6608 66.98.180.16 -> 201.4.236.1 UDP Source port: 34725 Destination port: 6567
26 2003-12-24 10:22:14.6609 66.98.180.16 -> 201.4.236.1 UDP Source port: 34725 Destination port: 58096
27 2003-12-24 10:22:14.6609 66.98.180.16 -> 201.4.236.1 UDP Source port: 34725 Destination port: 2432
28 2003-12-24 10:22:14.6609 66.98.180.16 -> 201.4.236.1 UDP Source port: 34725 Destination port: 12009
29 2003-12-24 10:22:14.6609 66.98.180.16 -> 201.4.236.1 UDP Source port: 34725 Destination port: 11660
30 2003-12-24 10:22:14.6609 66.98.180.16 -> 201.4.236.1 UDP Source port: 34725 Destination port: 45272
31 2003-12-24 10:22:14.6609 66.98.180.16 -> 201.4.236.1 UDP Source port: 34725 Destination port: 21865
32 2003-12-24 10:22:14.6609 66.98.180.16 -> 201.4.236.1 UDP Source port: 34725 Destination port: 43574
33 2003-12-24 10:22:14.6609 66.98.180.16 -> 201.4.236.1 UDP Source port: 34725 Destination port: 9162
34 2003-12-24 10:22:14.6609 66.98.180.16 -> 201.4.236.1 UDP Source port: 34725 Destination port: 48223
35 2003-12-24 10:22:14.6609 66.98.180.16 -> 201.4.236.1 UDP Source port: 34725 Destination port: 27115
36 2003-12-24 10:22:14.6609 66.98.180.16 -> 201.4.236.1 UDP Source port: 34725 Destination port: 6853
37 2003-12-24 10:22:14.6609 66.98.180.15 -> 171.75.215.245 HTTP HTTP/1.1 200 OK
38 2003-12-24 10:22:14.6609 69.15.30.139 -> 66.98.180.7 TCP 17055 > 22 [ACK] Seq=2059589946 Ack=3098770208 Win=63680 Len=1460
39 2003-12-24 10:22:14.6609 66.98.180.16 -> 201.4.236.1 UDP Source port: 34725 Destination port: 2448
40 2003-12-24 10:22:14.6609 66.98.180.16 -> 201.4.236.1 UDP Source port: 34725 Destination port: 53540
41 2003-12-24 10:22:14.6609 66.98.180.15 -> 171.75.215.245 HTTP Continuation
42 2003-12-24 10:22:14.6609 66.98.180.16 -> 201.4.236.1 UDP Source port: 34725 Destination port: 6873
43 2003-12-24 10:22:14.6610 66.98.180.16 -> 201.4.236.1 UDP Source port: 34725 Destination port: 28738
frame used for mac
Frame 4 (314 on wire, 314 captured)
Arrival Time: Dec 24, 2003 10:22:14.660816000
Time delta from previous packet: 0.000004000 seconds
Time relative to first packet: 0.000017000 seconds
Frame Number: 4
Packet Length: 314 bytes
Capture Length: 314 bytes
Ethernet II
Destination: 00:e0:52:0c:24:da (00:e0:52:0c:24:da)
Source: 00:0c:76:51:f4:08 (00:0c:76:51:f4:08)
mac to ip conversion
Mac address: 000c.7651.f408
IP: 66.98.180.225
IP: 66.98.180.227
IP: 66.98.180.226
IP: 66.98.180.16
IP: 66.98.180.230
Last Updated: 2003-12-23
Date Time Switch Port InPPS OutPPS InMBPS OutMBPS MAC
2003/12/24 10:30:14 66.98.180.245 19 31042.25 14.75 75.4589 0.0101 000c.7651.f408
allen
dc noc