I've just signed up for my first dedicated server and know nothing about them.
I'm receiving 4 to 5 emails a day with alerts and I have NO idea what they are and if I should be worried about them. If you know anything about hosting, can you help a brother out?
Here are some of the alerts I'm getting:
--------------
Time: Tue Jan 15 13:02:06 2013 -0600
IP: 194.127.5.247 (DE/Germany/-)
Connections: 62
Blocked: Temporary Block
Connections:
tcp: 194.127.5.247:52617 -> XX.XXX.XXX.XX:80 (FIN_WAIT2)
tcp: 194.127.5.247:53047 -> XX.XXX.XXX.XX:80 (ESTABLISHED)
tcp: 194.127.5.247:52595 -> XX.XXX.XXX.XX:80 (FIN_WAIT2)
tcp: 194.127.5.247:53053 -> XX.XXX.XXX.XX:80 (ESTABLISHED)
tcp: 194.127.5.247:52602 -> XX.XXX.XXX.XX:80 (FIN_WAIT2)
tcp: 194.127.5.247:52596 -> XX.XXX.XXX.XX:80 (FIN_WAIT2)
tcp: 194.127.5.247:52869 -> XX.XXX.XXX.XX:80 (FIN_WAIT2)
tcp: 194.127.5.247:53038 -> XX.XXX.XXX.XX:80 (ESTABLISHED)
tcp: 194.127.5.247:52621 -> XX.XXX.XXX.XX:80 (FIN_WAIT2)
tcp: 194.127.5.247:52872 -> XX.XXX.XXX.XX:80 (FIN_WAIT2)
tcp: 194.127.5.247:52607 -> XX.XXX.XXX.XX:80 (FIN_WAIT2)
tcp: 194.127.5.247:53048 -> XX.XXX.XXX.XX:80 (ESTABLISHED)
tcp: 194.127.5.247:52894 -> XX.XXX.XXX.XX:80 (FIN_WAIT2)
tcp: 194.127.5.247:52604 -> XX.XXX.XXX.XX:80 (FIN_WAIT2)
----------
Time: Tue Jan 15 10:44:21 2013 -0600
IP: 76.30.171.72 (US/United States/c-76-30-171-72.hsd1.tx.comcast.net)
Hits: 11
Blocked: Temporary Block
Sample of block hits:
Jan 15 10:43:27 host kernel: Firewall: *UDP_IN Blocked* IN=eth0 OUT= MAC=00:23:ae:6b:d6:93:5c:5e:ab:d0:66:f0:08:00 SRC=76.30.171.72 DST=XX.XXX.XXX.XX LEN=84 TOS=0x00 PREC=0x00 TTL=118 ID=5737 PROTO=UDP SPT=56568 DPT=3544 LEN=64
Jan 15 10:43:30 host kernel: Firewall: *UDP_IN Blocked* IN=eth0 OUT= MAC=00:23:ae:6b:d6:93:5c:5e:ab:d0:66:f0:08:00 SRC=76.30.171.72 DST=XX.XXX.XXX.XX LEN=84 TOS=0x00 PREC=0x00 TTL=118 ID=7136 PROTO=UDP SPT=56568 DPT=3544 LEN=64
Jan 15 10:43:56 host kernel: Firewall: *UDP_IN Blocked* IN=eth0 OUT= MAC=00:23:ae:6b:d6:93:5c:5e:ab:d0:66:f0:08:00 SRC=76.30.171.72 DST=XX.XXX.XXX.XX LEN=84 TOS=0x00 PREC=0x00 TTL=118 ID=16817 PROTO=UDP SPT=56568 DPT=3544 LEN=64
Jan 15 10:43:57 host kernel: Firewall: *UDP_IN Blocked* IN=eth0 OUT= MAC=00:23:ae:6b:d6:93:5c:5e:ab:d0:66:f0:08:00 SRC=76.30.171.72 DST=XX.XXX.XXX.XX LEN=84 TOS=0x00 PREC=0x00 TTL=118 ID=17469 PROTO=UDP SPT=56568 DPT=3544 LEN=64
Jan 15 10:43:59 host kernel: Firewall: *UDP_IN Blocked* IN=eth0 OUT= MAC=00:23:ae:6b:d6:93:5c:5e:ab:d0:66:f0:08:00 SRC=76.30.171.72 DST=XX.XXX.XXX.XX LEN=84 TOS=0x00 PREC=0x00 TTL=118 ID=18167 PROTO=UDP SPT=56568 DPT=3544 LEN=64
---------
What are these and should I be worried about them?
I'm receiving 4 to 5 emails a day with alerts and I have NO idea what they are and if I should be worried about them. If you know anything about hosting, can you help a brother out?
Here are some of the alerts I'm getting:
--------------
Time: Tue Jan 15 13:02:06 2013 -0600
IP: 194.127.5.247 (DE/Germany/-)
Connections: 62
Blocked: Temporary Block
Connections:
tcp: 194.127.5.247:52617 -> XX.XXX.XXX.XX:80 (FIN_WAIT2)
tcp: 194.127.5.247:53047 -> XX.XXX.XXX.XX:80 (ESTABLISHED)
tcp: 194.127.5.247:52595 -> XX.XXX.XXX.XX:80 (FIN_WAIT2)
tcp: 194.127.5.247:53053 -> XX.XXX.XXX.XX:80 (ESTABLISHED)
tcp: 194.127.5.247:52602 -> XX.XXX.XXX.XX:80 (FIN_WAIT2)
tcp: 194.127.5.247:52596 -> XX.XXX.XXX.XX:80 (FIN_WAIT2)
tcp: 194.127.5.247:52869 -> XX.XXX.XXX.XX:80 (FIN_WAIT2)
tcp: 194.127.5.247:53038 -> XX.XXX.XXX.XX:80 (ESTABLISHED)
tcp: 194.127.5.247:52621 -> XX.XXX.XXX.XX:80 (FIN_WAIT2)
tcp: 194.127.5.247:52872 -> XX.XXX.XXX.XX:80 (FIN_WAIT2)
tcp: 194.127.5.247:52607 -> XX.XXX.XXX.XX:80 (FIN_WAIT2)
tcp: 194.127.5.247:53048 -> XX.XXX.XXX.XX:80 (ESTABLISHED)
tcp: 194.127.5.247:52894 -> XX.XXX.XXX.XX:80 (FIN_WAIT2)
tcp: 194.127.5.247:52604 -> XX.XXX.XXX.XX:80 (FIN_WAIT2)
----------
Time: Tue Jan 15 10:44:21 2013 -0600
IP: 76.30.171.72 (US/United States/c-76-30-171-72.hsd1.tx.comcast.net)
Hits: 11
Blocked: Temporary Block
Sample of block hits:
Jan 15 10:43:27 host kernel: Firewall: *UDP_IN Blocked* IN=eth0 OUT= MAC=00:23:ae:6b:d6:93:5c:5e:ab:d0:66:f0:08:00 SRC=76.30.171.72 DST=XX.XXX.XXX.XX LEN=84 TOS=0x00 PREC=0x00 TTL=118 ID=5737 PROTO=UDP SPT=56568 DPT=3544 LEN=64
Jan 15 10:43:30 host kernel: Firewall: *UDP_IN Blocked* IN=eth0 OUT= MAC=00:23:ae:6b:d6:93:5c:5e:ab:d0:66:f0:08:00 SRC=76.30.171.72 DST=XX.XXX.XXX.XX LEN=84 TOS=0x00 PREC=0x00 TTL=118 ID=7136 PROTO=UDP SPT=56568 DPT=3544 LEN=64
Jan 15 10:43:56 host kernel: Firewall: *UDP_IN Blocked* IN=eth0 OUT= MAC=00:23:ae:6b:d6:93:5c:5e:ab:d0:66:f0:08:00 SRC=76.30.171.72 DST=XX.XXX.XXX.XX LEN=84 TOS=0x00 PREC=0x00 TTL=118 ID=16817 PROTO=UDP SPT=56568 DPT=3544 LEN=64
Jan 15 10:43:57 host kernel: Firewall: *UDP_IN Blocked* IN=eth0 OUT= MAC=00:23:ae:6b:d6:93:5c:5e:ab:d0:66:f0:08:00 SRC=76.30.171.72 DST=XX.XXX.XXX.XX LEN=84 TOS=0x00 PREC=0x00 TTL=118 ID=17469 PROTO=UDP SPT=56568 DPT=3544 LEN=64
Jan 15 10:43:59 host kernel: Firewall: *UDP_IN Blocked* IN=eth0 OUT= MAC=00:23:ae:6b:d6:93:5c:5e:ab:d0:66:f0:08:00 SRC=76.30.171.72 DST=XX.XXX.XXX.XX LEN=84 TOS=0x00 PREC=0x00 TTL=118 ID=18167 PROTO=UDP SPT=56568 DPT=3544 LEN=64
---------
What are these and should I be worried about them?