Page is a not externally linkable
- Hardware and OS Related Technologies
-- Linux, Unix, and *nix like Operating Systems
---- IPTables: Upto 30,000 Invalid packets logged per week


AlexK - 4:15 pm on Jan 28, 2006 (gmt 0)


Finally, and for the last time, here is a duplicate of the mind-numbing detail also offered in msg #:7, but this time for a period whilst the DROP command was not operative; it is a different range of IPs, and thus includes a number of ISPs sharing IPs amongst their customers (not the case with the earlier ones):

Thu Jan 26 - one day in the life of a web-server:
sample of 36 of 408 TCP:80 IPs logged due to Invalid Packets:
(547 total when none-TCP:80 packets included)
(40 visitors due to IP-sharing)
5 have no entry in the access_log
18 make 1 page request
4 make 2 page requests
7 make 3 page requests
2 make 4 page requests
1 make 6 page requests
1 make 7 page requests
1 make 10 page requests
1 make 12 page requests
.
(ignoring the 5 no-access-log, and considering the 35 others):
No of Invalid packets AFTER successful page request: 28
No of Invalid packets DURING successful page request: 7
.
MSIE 6.0; Windows NT 5.1 26
MSIE 6.0; Windows NT 5.0 3
MSIE 5.5; Windows NT 5.0 2
MSIE 6.0; Windows 98 1
Firefox/1.0.4 Windows NT 5.0 1
Firefox/1.5 Windows NT 5.1 3

IP-Address  No of Invalid packets Page-access Time - Browser + OS  Packet Time (first-last) 
4.153.84.204 1 packet to tcp(80) 03:07:10 MSIE 6.0; Windows 98 03:11:00 Invalid
03:08:14
03:13:12
12.19.113.105 2 packets to tcp(80) 17:59:43 MSIE 6.0; Windows NT 5.1 20:25:48 Invalid
12.46.111.83 2 packets to tcp(80) 20:20:40 MSIE 6.0; Windows NT 5.1 20:28:09 Invalid
12.47.172.138 2 packets to tcp(80) 23:44:16 MSIE 6.0; Windows NT 5.1 23:50:07 Invalid
12.129.230.13 2 packets to tcp(80) 03:04:02 MSIE 6.0; Windows NT 5.1 03:13:01 Invalid
12.145.168.100 2 packets to tcp(80) 15:04:50 MSIE 6.0; Windows NT 5.0 15:09:17 Invalid
12.152.251.106 2 packets to tcp(80) 17:53:15 MSIE 6.0; Windows NT 5.1 18:00:21 Invalid
12.161.66.6 1 packet to tcp(80) 17:45:39 Firefox/1.0.4 Windows NT 5.0 17:53:10 Invalid
17:45:54
17:46:12
12.170.50.206 2 packets to tcp(80) 20:20:42 MSIE 6.0; Windows NT 5.1 20:27:26 Invalid
15.203.169.126 54 packets to tcp(80,80)09:07:41 MSIE 6.0; Windows NT 5.1 09:09:58-09:18:43 (New not syn)
09:19:58 (Invalid)
16:33:44 MSIE 6.0; Windows NT 5.0 16:35:59-16:44:48 (New not syn)
16:33:44 16:45:59-16:46:03 (Invalid)
16:33:45
15.219.201.70 16 packets to tcp(80,80)03:44:53 MSIE 6.0; Windows NT 5.1 03:47:09-03:56:00 (New not syn)
03:57:09-03:57:15 (Invalid)
15.235.153.102 2 packets to tcp(80) 20:22:20 MSIE 6.0; Windows NT 5.1 20:29:27 Invalid
20.133.0.13 4 packets to tcp(80,80) 13:20:26 MSIE 5.5; Windows NT 5.0 13:22:53-13:25:23 (New not syn)
13:26:14 (Invalid)
20.133.0.14 9 packets to tcp(80,80) 12:07:06 MSIE 5.5; Windows NT 5.0 13:22:42-13:22:51 (New not syn)
13:20:24 13:23:41-13:23:45 (Invalid)
20.138.246.89 20 packets to tcp(80,80)13:23:36 MSIE 6.0; Windows NT 5.1 13:25:53-21:50:28 (Invalid)
13:25:53 13:28:09-21:49:13 (New not syn)
24.18.141.111 1 packet to tcp(80) 23:12:38 MSIE 6.0; Windows NT 5.1 23:22:48-02:28:21 Invalid
23:22:48
24.75.123.98 2 packets to tcp(80) 14:04:03 MSIE 6.0; Windows NT 5.1 14:13:07-14:13:09 Invalid
24.105.193.23 1 packet to tcp(80) 23:46:38 MSIE 6.0; Windows NT 5.1 00:03:27 Invalid
23:46:39
23:47:02
24.237.168.13 1 packet to tcp(80) 03:00:22 MSIE 6.0; Windows NT 5.1 03:03:02 Invalid
03:00:36
03:00:39
03:20:24 Firefox/1.5 Windows NT 5.1
38.119.107.81 36 packets to tcp(80) 15:42:50 MSIE 6.0; Windows NT 5.1 15:42:59-15:45:05 Invalid
15:44:05
15:44:25
15:44:31
15:44:44
15:44:56
58.65.199.228 5 packets to tcp(80) 07:11:16 Firefox/1.5 Windows NT 5.1 07:14:03-07:19:47 Invalid
07:14:03
58.147.0.42 22 packets to tcp(80,80)09:57:48 MSIE 6.0; Windows NT 5.1 10:01:13-10:04:58 (New not syn)
09:58:36 10:05:58 Invalid
09:58:51 12:01:00-12:04:46 (New not syn)
09:58:58 12:05:18 Invalid
11:56:57 MSIE 6.0; Windows NT 5.1 15:27:25-15:29:55 (New not syn)
11:57:54
11:58:43
15:25:04 MSIE 6.0; Windows NT 5.1 15:30:52-15:31:00 Invalid
58.186.23.199 1 packet to tcp(80) 17:06:40 Invalid
59.113.2.89 4 packets to tcp(80) 07:06:07 MSIE 6.0; Windows NT 5.1 07:08:54-07:31:23 Invalid
07:06:43
07:07:03
07:07:10
07:07:19
07:07:35
07:08:54
07:10:22
07:11:37
07:12:31
07:15:58
07:16:14
61.1.196.111 1 packet to tcp(80) 07:21:11 MSIE 6.0; Windows NT 5.1 07:23:17 Invalid
61.68.11.131 2 packets to tcp(80) 05:02:25 MSIE 6.0; Windows NT 5.1 05:04:15 Invalid
61.173.31.54 2 packets to tcp(80) 01:47:14 MSIE 6.0; Windows NT 5.1 01:51:20 Invalid
01:49:28
01:49:42
61.175.193.132 1 packet to tcp(80) 12:28:03 Invalid
61.218.223.67 1 packet to tcp(80) 01:45:01 Invalid
61.221.196.67 1 packet to tcp(80) 01:45:01 Invalid
61.241.79.3 1 packet to tcp(80) 12:28:03 Invalid
61.246.92.193 4 packets to tcp(80) 12:56:26 MSIE 6.0; Windows NT 5.0 13:05:42-13:09:47 Invalid
12:58:40
13:02:14
13:05:42
13:08:00
13:09:51
13:10:54
62.25.109.195 18 packets to tcp(80,80)08:32:59 MSIE 6.0; Windows NT 5.1 08:35:16-08:44:01 (New not syn)
08:45:16 Invalid
62.38.20.196 1 packet to tcp(80) 08:36:00 Firefox/1.5 Windows NT 5.1 09:19:48 Invalid
08:36:55
08:37:45
08:38:47
08:39:12
08:39:23
08:39:49
08:40:00
08:40:22
08:40:53
09:10:21 MSIE 6.0; Windows NT 5.1
09:10:56
62.38.254.39 2 packets to tcp(80) 16:52:44 MSIE 6.0; Windows NT 5.1 17:05:48 Invalid
16:53:13
16:54:33
16:54:43
62.90.217.106 2 packets to tcp(80) 13:11:59 MSIE 6.0; Windows NT 5.1 13:21:46 Invalid


Thread source:: http://www.webmasterworld.com/linux/1642.htm
Brought to you by WebmasterWorld: http://www.webmasterworld.com