Die erste Meldung war eine IP aus Frankreich incoming, 3:45 Uhr:
IPS Alert 2: Misc Attack. Signature ET CINS Active Threat Intelligence Poor Reputation IP group 89. From: 62.169.18.104:41923, to: meinesynology:6881, protocol: UDP
Systemkommentar dazu: This indicates that someone may be attempting to exploit an application's vulnerabilities.
Tatsächlich gehört die IP wohl zu Contabo, München
xxxxxxxxxxxxxxxxxx
Um kurz vor 06:00 Uhr habe ich zunächst die Kontoverbindung von Synology in den Einstellungen (von meinem Handy aus) deaktiviert. Kurz danach kam diese Meldung:
Incoming, 62.169.18.104; Ziel: Mein Handy
IPS Alert 2: Misc Attack. Signature ET CINS Active Threat Intelligence Poor Reputation IP group 90. From: 62.169.18.104:80, to: meinhandy:51560, protocol: TCP
xxxxxxxxxxxxxxxxxx
Um 07:51, outgoing, ip in South Korea, Korea Telekom:
IPS Alert 1: Potential Corporate Privacy Violation. Signature ET P2P BitTorrent DHT ping request. From: meinesynology:6881, to: 118.46.53.80:6881, protocol: UDP
Kommentar: This indicates potential use of applications that may not be appropriate for corporate environments. This is usually more acceptable for home environments.
xxxxxxxxxxxxxxxxxx
Um 7:56 Uhr, outgoing, ip aus Deutschland, Hetzner
IPS Alert 1: Potential Corporate Privacy Violation. Signature ET P2P BitTorrent DHT ping request. From: meinesynology:6881, to: 88.99.251.24:25794, protocol: UDP
Systemkommentar: This indicates potential use of applications that may not be appropriate for corporate environments. This is usually more acceptable for home environments.
xxxxxxxxxxxxxxxxxxxxx
Um 08:01, outgoing, ip in Russland
IPS Alert 1: Potential Corporate Privacy Violation. Signature ET P2P BitTorrent DHT ping request. From: meinesynology:6881, to: 95.31.240.6:41607, protocol: UDP
Systemkommentar: This indicates potential use of applications that may not be appropriate for corporate environments. This is usually more acceptable for home environments.
xxxxxxxxxxxxxxxxxxx
Seitdem habe ich abgeschaltet.