I recently set up HomeSeer and got the web access working. Recent entries in my HS and Firewall logs have wondering if I should be concerned about web intrusions. For example, my HS log shows the following entries a few days ago:
8/7/2004 11:20:14 PM~!~Info~!~ Got data but was not PUT or GET, from: 67.124.241.125 Data:
8/8/2004 3:15:46 AM~!~Info~!~ Got data but was not PUT or GET, from: 62.43.113.62 Data: CONNECT login.icq.com:443 HTTP/1.0
8/8/2004 7:09:58 AM~!~Info~!~ Got data but was not PUT or GET, from: 82.125.132.88 Data: CONNECT login.icq.com:443 HTTP/1.0
For the same time period, my firewall log shows the following:
2004/08/07 23:21:04 CDT low src=67.124.241.125 dst=67.35.233.73 ipprot=6 sport=4318 dport=1025 TCP Port Scan Detected, Packet Dropped 2004/08/08 21:05:34 CDT low src=67.208.165.29 dst=67.35.233.73 ipprot=6 sport=1354 dport=6129 TCP Port Scan Detected, Packet Dropped
My layman's brain is interpreting this as:
The firewall rejecting the first intrusion (8/7 PM), but missing the second two (8/8 AM),since there is nothing in the firewall log for 8/8 in the AM, and
HomeSeer allowed the 2 early morning logins.
Is this a correct interpretation? Should I be concerned?
Thanks in avance for help.
Joe
8/7/2004 11:20:14 PM~!~Info~!~ Got data but was not PUT or GET, from: 67.124.241.125 Data:
8/8/2004 3:15:46 AM~!~Info~!~ Got data but was not PUT or GET, from: 62.43.113.62 Data: CONNECT login.icq.com:443 HTTP/1.0
8/8/2004 7:09:58 AM~!~Info~!~ Got data but was not PUT or GET, from: 82.125.132.88 Data: CONNECT login.icq.com:443 HTTP/1.0
For the same time period, my firewall log shows the following:
2004/08/07 23:21:04 CDT low src=67.124.241.125 dst=67.35.233.73 ipprot=6 sport=4318 dport=1025 TCP Port Scan Detected, Packet Dropped 2004/08/08 21:05:34 CDT low src=67.208.165.29 dst=67.35.233.73 ipprot=6 sport=1354 dport=6129 TCP Port Scan Detected, Packet Dropped
My layman's brain is interpreting this as:
The firewall rejecting the first intrusion (8/7 PM), but missing the second two (8/8 AM),since there is nothing in the firewall log for 8/8 in the AM, and
HomeSeer allowed the 2 early morning logins.
Is this a correct interpretation? Should I be concerned?
Thanks in avance for help.
Joe
Comment