I keep getting errors from the System integrity monitor as listed below: I have done a google search and search here and the general concensus seems to be that it is a Windows 2K macine. But this happens everynight just after 00:00 and it has originated from 10 or so different IP addresses. It also repeats itself many times. I add the IP's to the APF everyday but it reappears with different IP's the next day. The IP's are mostly asian and Puerto Rico. In the research they state Win 2K only tried this one time and then gives up, but these are presistent enough to cause SIM to restart the HTTP....
WHOIS results for 203.86.45.18Code:System integrity monitor on xxx.xxxx.xxx has taken action in responce to an event. Recent event logs are enclosed below for your inspection. There has been 8 events today, if an average of 8 events is reached, e-mail alerts will be terminated for the duration of the day. - Events Summary: Total event count: 8 Average event count: 1 - Service Summary: HTTP [restarted - 8 events] DNS [online - 0 events] MYSQL [online - 0 events] SMTP [online - 0 events] - System Summary: LOAD [0.04 - status good - 0 events] NETWORK [eth0 - online - 0 events] - SIM Log: [10/11/05 00:30:01]: NETWORK is online. [10/11/05 00:30:01]: HTTP service is online. [10/11/05 00:30:01]: HTTP url request failed, assuming offline. [10/11/05 00:30:01]: Restarted HTTP service (7 HTTP events today). [10/11/05 00:30:01]: DNS service is online. [10/11/05 00:30:01]: MYSQL service is online. [10/11/05 00:30:01]: SMTP service is online. [10/11/05 00:35:00]: LOAD 0.04 (status good) [10/11/05 00:35:00]: NETWORK is online. [10/11/05 00:35:00]: HTTP service is online. [10/11/05 00:35:00]: HTTP url request failed, assuming offline. [10/11/05 00:35:00]: Restarted HTTP service (8 HTTP events today). [10/11/05 00:35:00]: DNS service is online. [10/11/05 00:35:00]: MYSQL service is online. [10/11/05 00:35:00]: SMTP service is online. - System Log: Oct 11 00:26:07 host named[2681]: client 203.86.45.18#2618: update 'xxxxx.xxx/IN' denied Oct 11 00:26:08 host named[2681]: client 203.86.45.18#2526: updating zone 'xxxxx.xxx/IN': update failed: 'RRset exists (value dependent)' prerequisite not satisfied (NXRRSET) Oct 11 00:26:10 host named[2681]: client 203.86.45.18#2529: update 'xxxxx.xxx/IN' denied Oct 11 00:27:11 host named[2681]: client 203.86.45.18#1866: updating zone 'xxxxx.xxx/IN': update failed: 'RRset exists (value dependent)' prerequisite not satisfied (NXRRSET) Oct 11 00:27:12 host named[2681]: client 203.86.45.18#1869: update 'xxxxx.xxx/IN' denied Oct 11 00:27:43 host named[2681]: client 203.86.45.18#3872: update 'xxxxx.xxx/IN' denied Oct 11 00:28:29 host named[2681]: client 203.86.45.18#3884: update 'xxxxx.xxx/IN' denied Oct 11 00:29:38 host named[2681]: client 203.86.45.18#1433: updating zone 'xxxxx.xxx/IN': update failed: 'RRset exists (value dependent)' prerequisite not satisfied (NXRRSET) Oct 11 00:29:38 host named[2681]: client 203.86.45.18#1433: error sending response: host unreachable Oct 11 00:31:12 host pure-ftpd: (?@127.0.0.1) [INFO] New connection from 127.0.0.1 Oct 11 00:31:12 host pure-ftpd: (?@127.0.0.1) [INFO] Logout. Oct 11 00:31:28 host named[2681]: client 203.86.45.18#3892: update 'xxxxx.xxx/IN' denied Oct 11 00:32:09 host named[2681]: client 203.86.45.18#3898: update 'xxxxx.xxx/IN' denied Oct 11 00:33:43 host named[2681]: client 203.86.45.18#1986: updating zone 'xxxxx.xxx/IN': update failed: 'RRset exists (value dependent)' prerequisite not satisfied (NXRRSET) Oct 11 00:33:45 host named[2681]: client 203.86.45.18#1989: update 'xxxxx.xxx/IN' denied ====================================================== SIM 2.5-3 <sim@r-fx.org> 10/11/05 00:35:00
Generated by www.DNSstuff.com
Location: China [City: Beijing, Guangdong]
Any ideals?



LinkBack URL
About LinkBacks
Reply With Quote







