0

after looking for stuff with Debian "netstat" and try list stuff with "nestat -r" my main Server out a Long list of unkown Hosts ( mostly hacked IP´s by looking on abuseDB )

here a small example for the Output ( cut )

ild.static.gvt -               255.255.255.255 !H        - -          - -
181.214.50.103  -               255.255.255.255 !H        - -          - -
182.92.168.83   -               255.255.255.255 !H        - -          - -
scan-01.shadows -               255.255.255.255 !H        - -          - -
67.c4.acb8.ip4. -               255.255.255.255 !H        - -          - -
185.94.111.1    -               255.255.255.255 !H        - -          - -
187.110.70.211  -               255.255.255.255 !H        - -          - -
56.195.62.188.d -               255.255.255.255 !H        - -          - -
188.72.46.202   -               255.255.255.255 !H        - -          - -
balticom-92-20- -               255.255.255.255 !H        - -          - -
atlantic381.ded -               255.255.255.255 !H        - -          - -
atlantic.census -               255.255.255.255 !H        - -          - -
190.4.119.142   -               255.255.255.255 !H        - -          - -
190.196.59.34   -               255.255.255.255 !H        - -          - -
192-3-27-250-ho -               255.255.255.255 !H        - -          - -
census2.shodan. -               255.255.255.255 !H        - -          - -
census3.shodan. -               255.255.255.255 !H        - -          - -
client-198-44-4 -               255.255.255.255 !H        - -          - -
198.50.195.6    -               255.255.255.255 !H        - -          - -
odut3.tudobom.i -               255.255.255.255 !H        - -          - -
200.35.151.179  -               255.255.255.255 !H        - -          - -
200-49-2-30.dyn -               255.255.255.255 !H        - -          - -
201-67-99-238.c -               255.255.255.255 !H        - -          - -
42.202-172-56.n -               255.255.255.255 !H        - -          - -
www.openSNMPpro -               255.255.255.255 !H        - -          - -
207.235.32.158  -               255.255.255.255 !H        - -          - -
ip229.208-100-2 -               255.255.255.255 !H        - -          - -
ip232.208-100-2 -               255.255.255.255 !H        - -          - -
cog.citx.biz    -               255.255.255.255 !H        - -          - -
static.212.56.2 -               255.255.255.255 !H        - -          - -
212.97.160.85.s -               255.255.255.255 !H        - -          - -
213.155.107.180 -               255.255.255.255 !H        - -          - -
localnet        *               255.255.255.128 U         0 0          0 eth0
217.147.86.87   -               255.255.255.255 !H        - -          - -
222.186.56.107  -               255.255.255.255 !H        - -          - -

trying kill host or delete the unkown routes cant be done...!

on my slave Server the Output give right route somthing really wrong with my Debian 6

any help ? ( Google dosent help much )

VBnoob
  • 121
  • 1
  • 2
  • The exclamation mark `!H` is a **reject route** for a specific **H**ost address. I can't test now but [`ip route add -host 122.186.56.107 reject`](http://serverfault.com/questions/337410/how-to-remove-route-with-ip) or a black hole route can achieve such [null routing](https://en.m.wikipedia.org/wiki/Null_route) – HBruijn Dec 06 '15 at 08:17
  • hmm, so why i can read the null routes on my Main Server, but all other Server work propertly .. ? – VBnoob Dec 06 '15 at 18:49
  • ok, iam 100% sure it is "Debian denyhosts" :) – VBnoob Mar 01 '17 at 19:03

0 Answers0