Wankwood Associates
Firewall Activity
September 30, 1999

[Alerts] [Alert] [Totals] [Protocol] [Time of Day] [Interface] [Host] [User] [Domain] [Mobile] [Message] [History]

Alerts
Reason Time Duration Protocol Bytes
Sent
Bytes
Received
Bytes
Total
Source
Interface
Source
Host
Destination
Interface
Destination
Host
Argument
Volume 03:57:09 000:01:05 smtp 2.50 Mb 411 2.50 Mb Outside spectgw01.spectrian.com Inside mail.zeeko.com <77CD2E3425DED1119F2400A0C9B40AF572F8FE@spectexmsg02.spectrian.com>
Volume 03:59:36 000:03:11 smtp 9.58 Mb 411 9.58 Mb Outside spectgw01.spectrian.com Inside mail.zeeko.com <77CD2E3425DED1119F2400A0C9B40AF572F8FD@spectexmsg02.spectrian.com>
Volume 05:45:56 000:02:30 smtp 1.04 Mb 359 1.04 Mb Outside host1.2037747.gcn.net.tw Inside mail.zeeko.com <NBBBLIJAOPEPPFHCKKFGGEGDCFAA.julie@chinnan.com.tw>
Time 05:56:16 000:00:01 ftp 5.3 Kb 5.3 Kb Inside [192.168.2.87] Unidentified ins1.netins.net /showcase/glitch/.web/public/graph/misc/cool/pentacle.gif
Time 05:57:12 000:00:59 ftp 119 1.1 Kb 1.2 Kb Inside pillar Outside ins1.netins.net
Time 05:58:09 000:00:01 ftp 5.3 Kb 5.3 Kb Inside [192.168.2.87] Unidentified ins1.netins.net /showcase/glitch/.web/public/graph/misc/cool/pentacle.gif
Time 05:58:49 000:00:01 ftp 5.3 Kb 5.3 Kb Inside [192.168.2.87] Unidentified ins1.netins.net /showcase/glitch/.web/public/graph/misc/cool/pentacle.gif
Time 06:00:01 000:00:01 ftp 5.3 Kb 5.3 Kb Inside [192.168.2.87] Unidentified ins1.netins.net /showcase/glitch/.web/public/graph/misc/cool/pentacle.gif
Volume 06:07:31 000:00:11 smtp 1.58 Mb 409 1.58 Mb Inside mail.zeeko.com Outside rly-yd03.mx.aol.com <699538F7E6AAD011AC0D00A0C94AEFBF7FB21F@zeek.zeeko.com>
Volume 06:08:29 000:00:11 smtp 1.58 Mb 409 1.58 Mb Inside mail.zeeko.com Outside rly-yg03.mx.aol.com <699538F7E6AAD011AC0D00A0C94AEFBF7FB220@zeek.zeeko.com>
Duration 06:13:09 000:15:03 ftp 120 1.1 Kb 1.2 Kb Inside pillar Outside ins1.netins.net
Duration 06:13:50 000:15:03 ftp 120 1.1 Kb 1.2 Kb Inside pillar Outside ins1.netins.net
Duration 06:15:01 000:15:03 ftp 110 1.1 Kb 1.2 Kb Inside pillar Outside ins1.netins.net
Volume 07:08:50 000:01:32 smtp 1.86 Mb 435 1.86 Mb Outside mta1.tm.net.my Inside mail.zeeko.com <000901bf0b29$fb618460$ded3fea9@tlkhl>
Volume 08:43:39 000:00:24 smtp 1.59 Mb 365 1.59 Mb Outside e2.ny.us.ibm.com Inside mail.zeeko.com <852567FC.0045D70E.00@D51MTA09.pok.ibm.com>
Word 09:22:16 000:00:00 http 256 12.0 Kb 12.2 Kb Inside phi Outside www.doverdowns.com http://www.doverdowns.com/casino.jpg
Volume 11:28:26 000:00:22 http 3.5 Kb 5.71 Mb 5.71 Mb Inside wally Outside test.zeeko.com http://test.zeeko.com/drawings/C-Press.pdf
Volume 12:12:24 000:01:54 smtp 2.36 Mb 369 2.36 Mb Outside spectgw01.spectrian.com Inside mail.zeeko.com <77CD2E3425DED1119F2400A0C9B40AF572F8FF@spectexmsg02.spectrian.com>
Volume 12:12:25 000:01:55 smtp 2.36 Mb 365 2.36 Mb Outside spectgw01.spectrian.com Inside mail.zeeko.com <77CD2E3425DED1119F2400A0C9B40AF572F8FF@spectexmsg02.spectrian.com>
Volume 12:23:55 000:00:35 http 380 5.08 Mb 5.08 Mb Inside fallen Outside zappo.com http://www.zappo.com/quake/files/q2-3.20-x86.exe
Word 14:06:21 000:00:00 http 365 11.3 Kb 11.7 Kb Inside rennta Outside ny450cd3vip.doubleclick.net http://ad.doubleclick.net/viewad/336515-90445-93277_casinoonnet052099_onnetsaveadaa2.gif
Volume 15:30:14 000:02:44 http 384 6.02 Mb 6.02 Mb Inside fallen Outside mschus4.www.conxion.com http://mschus.www.conxion.com/download/win98SE/Update/7.0/W9X/EN-US/DX70eng.exe
Volume 15:41:26 000:00:53 smtp 1.66 Mb 289 1.66 Mb Inside mail.zeeko.com Outside sbs1.msbs.com <699538F7E6AAD011AC0D00A0C94AEFBF4E5898@zeek.zeeko.com>
Volume 15:50:39 000:00:57 smtp 1.59 Mb 390 1.59 Mb Inside mail.zeeko.com Outside e3.ny.us.ibm.com <699538F7E6AAD011AC0D00A0C94AEFBF7F71E8@zeek.zeeko.com>
Volume 15:50:40 000:00:57 smtp 1.58 Mb 387 1.58 Mb Inside mail.zeeko.com Outside e4.ny.us.ibm.com <699538F7E6AAD011AC0D00A0C94AEFBF7F71E8@zeek.zeeko.com>
Word 16:30:13 000:00:01 http 379 11.1 Kb 11.5 Kb Inside damu Outside m.doubleclick.net http://m.doubleclick.net/viewad/337128-gamble.gif
Volume 16:47:41 000:12:31 ftp 18.09 Mb 18.09 Mb Inside [192.168.2.73] Unidentified vftp-mv4.netscape.com /pub/communicator/english/4.7/windows/windows95_or_nt/complete_install/cc32e47.exe
Volume 16:54:40 000:04:14 http 270 6.20 Mb 6.20 Mb Inside fallen Outside tucows.cows.net http://tucows.cows.net/files/xwp32.exe
Duration 17:54:57 000:24:25 ftp 1.1 Kb 1.9 Kb 3.0 Kb Inside fallen Outside [205.188.247.193]
Volume 18:10:14 000:11:24 ftp 18.46 Mb 18.46 Mb Inside [192.168.2.73] Unidentified prune.epix.net /pub/3dfiles/games/rcdemo2.zip
Volume 18:16:42 000:04:40 ftp 8.47 Mb 8.47 Mb Inside [192.168.2.73] Unidentified hpcc926.external.hp.com /pub/printers/software/lj620en.exe
Duration 19:06:50 000:15:06 ftp 90 2.1 Kb 2.2 Kb Inside [192.168.2.76] Outside rufus.w3.org
Duration 19:07:33 000:15:01 ftp 81 2.1 Kb 2.1 Kb Inside [192.168.2.76] Outside rufus.w3.org
Duration 19:09:47 000:16:17 ftp 94 2.1 Kb 2.2 Kb Inside [192.168.2.76] Outside rufus.w3.org
Duration 19:11:26 000:14:28 http 321 321 Inside saxon Outside windowsupdate.microsoft.com http://windowsupdate.microsoft.com/selfupd.cab
Duration 19:26:22 000:15:02 http 321 862 1.2 Kb Inside saxon Outside windowsupdate.microsoft.com http://windowsupdate.microsoft.com/selfupd.cab
Duration 19:53:17 000:15:01 http 321 862 1.2 Kb Inside saxon Outside windowsupdate.microsoft.com http://windowsupdate.microsoft.com/selfupd.cab
Duration 20:23:10 000:05:03 smtp 25 267 292 Outside [38.157.94.2] Inside mail.zeeko.com
Duration 20:29:12 000:05:07 smtp 25 267 292 Outside [38.157.94.2] Inside mail.zeeko.com
Volume 21:25:58 000:01:09 smtp 1.23 Mb 361 1.23 Mb Outside imo-d10.mx.aol.com Inside mail.zeeko.com <6dc1ece5.252546a7@aol.com>

[Alerts] [Alert] [Totals] [Protocol] [Time of Day] [Interface] [Host] [User] [Domain] [Mobile] [Message] [History]

Alert Summary
Host Alerts
mail.zeeko.com 5
spectgw01.spectrian.com 4
pillar 4
fallen 4
[192.168.2.87] 4

[Alerts] [Alert] [Totals] [Protocol] [Time of Day] [Interface] [Host] [User] [Domain] [Mobile] [Message] [History]

Totals
Hits 41755
Duration 064:34:41
Bytes 362.17 Mb
Hosts [DMZ] 1
Hosts [Inside] 125
Hosts [Outside] 1474

[Alerts] [Alert] [Totals] [Protocol] [Time of Day] [Interface] [Host] [User] [Domain] [Mobile] [Message] [History]

Protocol Summary
Protocol Hits Duration Bytes
Sent
Bytes
Received
Bytes
Total
Percent of Total Bytes
http 37543 028:07:05 14.77 Mb 223.79 Mb 238.56 Mb 65.87
ftp 221 004:40:44 5.34 Mb 74.99 Mb 80.33 Mb 22.18
smtp 3662 015:57:29 40.92 Mb 410.1 Kb 41.32 Mb 11.41
ssh 12 012:57:25 263.1 Kb 898.0 Kb 1.13 Mb 0.31
imap 5 000:00:36 16.6 Kb 787.7 Kb 804.2 Kb 0.22
pop3 310 002:51:09 8.9 Kb 33.2 Kb 42.0 Kb 0.01
telnet 2 000:00:13 38 144 182 0.00

[Alerts] [Alert] [Totals] [Protocol] [Time of Day] [Interface] [Host] [User] [Domain] [Mobile] [Message] [History]

Time of Day Summary
Hour Hits Duration Bytes
Sent
Bytes
Received
Bytes
Total
Percent of Total Bytes
00:00 - 00:59 163 000:28:08 40.4 Kb 16.3 Kb 56.6 Kb 0.02
01:00 - 01:59 147 000:22:09 18.9 Kb 13.2 Kb 32.1 Kb 0.01
02:00 - 02:59 151 000:25:19 44.9 Kb 15.1 Kb 60.0 Kb 0.02
03:00 - 03:59 154 000:29:45 12.13 Mb 15.8 Kb 12.14 Mb 3.35
04:00 - 04:59 149 000:22:06 793.6 Kb 14.1 Kb 807.7 Kb 0.22
05:00 - 05:59 458 000:33:23 1.29 Mb 1.24 Mb 2.53 Mb 0.70
06:00 - 06:59 865 001:26:05 3.66 Mb 2.07 Mb 5.73 Mb 1.58
07:00 - 07:59 798 000:46:38 2.15 Mb 1.73 Mb 3.88 Mb 1.07
08:00 - 08:59 2716 002:06:15 2.50 Mb 8.90 Mb 11.40 Mb 3.15
09:00 - 09:59 3131 003:31:22 1.31 Mb 27.48 Mb 28.79 Mb 7.95
10:00 - 10:59 4215 004:08:20 7.66 Mb 29.14 Mb 36.80 Mb 10.16
11:00 - 11:59 2375 005:57:00 2.66 Mb 14.64 Mb 17.30 Mb 4.78
12:00 - 12:59 4925 009:42:57 7.67 Mb 26.46 Mb 34.13 Mb 9.42
13:00 - 13:59 2336 002:50:36 858.7 Kb 20.32 Mb 21.16 Mb 5.84
14:00 - 14:59 3812 003:23:25 2.46 Mb 35.98 Mb 38.44 Mb 10.61
15:00 - 15:59 6193 006:06:05 7.55 Mb 32.00 Mb 39.55 Mb 10.92
16:00 - 16:59 3995 008:39:23 4.06 Mb 41.80 Mb 45.85 Mb 12.66
17:00 - 17:59 1243 003:35:19 613.7 Kb 14.26 Mb 14.86 Mb 4.10
18:00 - 18:59 1331 002:26:47 1.04 Mb 36.18 Mb 37.22 Mb 10.28
19:00 - 19:59 1542 003:13:59 874.2 Kb 7.10 Mb 7.95 Mb 2.20
20:00 - 20:59 177 001:22:51 115.6 Kb 17.3 Kb 132.9 Kb 0.04
21:00 - 21:59 527 001:05:30 1.39 Mb 1.45 Mb 2.84 Mb 0.78
22:00 - 22:59 175 000:45:47 427.2 Kb 17.7 Kb 444.9 Kb 0.12
23:00 - 23:59 177 000:45:32 86.0 Kb 17.1 Kb 103.1 Kb 0.03

[Alerts] [Alert] [Totals] [Protocol] [Time of Day] [Interface] [Host] [User] [Domain] [Mobile] [Message] [History]

Interface Summary
Interface Hits Duration Bytes
Sent
Bytes
Received
Bytes
Total
Percent of Total Bytes
Inside 42892 064:37:33 35.68 Mb 327.20 Mb 362.88 Mb 100.20
Outside 40343 063:21:58 250.78 Mb 28.77 Mb 279.55 Mb 77.19
Unidentified 148 001:05:23 74.92 Mb 5.34 Mb 80.27 Mb 22.16
DMZ 127 000:04:28 802.4 Kb 885.2 Kb 1.65 Mb 0.46

[Alerts] [Alert] [Totals] [Protocol] [Time of Day] [Interface] [Host] [User] [Domain] [Mobile] [Message] [History]

Host Summary [DMZ]
Host Hits Duration Bytes
Sent
Bytes
Received
Bytes
Total
Percent of Total Bytes
philko.zeeko.com 127 000:04:28 802.4 Kb 885.2 Kb 1.65 Mb 0.46

Host Summary [Inside]
Host Hits Duration Bytes
Sent
Bytes
Received
Bytes
Total
Percent of Total Bytes
[192.168.2.73] 37 000:54:52 0 64.22 Mb 64.22 Mb 17.73
mail.zeeko.com 3663 016:00:28 13.57 Mb 27.76 Mb 41.33 Mb 11.41
fallen 2123 003:55:47 754.8 Kb 31.14 Mb 31.88 Mb 8.80
spackle 721 000:58:34 225.3 Kb 25.50 Mb 25.72 Mb 7.10
me1 424 000:26:19 121.6 Kb 23.89 Mb 24.00 Mb 6.63
wally 1577 012:38:13 981.0 Kb 17.13 Mb 18.09 Mb 4.99
otar 1868 000:38:40 680.8 Kb 9.07 Mb 9.74 Mb 2.69
undul 1291 001:23:23 455.6 Kb 8.14 Mb 8.59 Mb 2.37
qaaz.zeeko.com 2033 001:04:20 814.5 Kb 6.25 Mb 7.04 Mb 1.94
niko 1549 001:32:30 715.4 Kb 5.87 Mb 6.57 Mb 1.81

Host Summary [Outside]
Host Hits Duration Bytes
Sent
Bytes
Received
Bytes
Total
Percent of Total Bytes
spectgw01.spectrian.com 7 000:08:18 16.81 Mb 5.3 Kb 16.82 Mb 4.64
test.zeeko.com 363 000:04:14 10.75 Mb 250.8 Kb 10.99 Mb 3.04
tucows.cows.net 58 000:09:34 8.19 Mb 17.2 Kb 8.20 Mb 2.27
mswusvca0.www.conxion.com 6 000:08:33 6.97 Mb 1.1 Kb 6.97 Mb 1.92
mschus4.www.conxion.com 1 000:02:44 6.02 Mb 384 6.02 Mb 1.66
mswusvca7.www.conxion.com 5 000:02:11 5.25 Mb 1.2 Kb 5.25 Mb 1.45
zappo.com 34 000:00:38 5.20 Mb 8.9 Kb 5.21 Mb 1.44
mswuheva8.www.conxion.com 5 000:05:42 5.15 Mb 938 5.15 Mb 1.42
mail2.3dgreetings.com 2 000:12:47 4.75 Mb 818 4.75 Mb 1.31
mswuheva3.www.conxion.com 8 000:03:11 4.58 Mb 1.5 Kb 4.58 Mb 1.27

[Alerts] [Alert] [Totals] [Protocol] [Time of Day] [Interface] [Host] [User] [Domain] [Mobile] [Message] [History]

User Summary
User Hits Duration Bytes
Sent
Bytes
Received
Bytes
Total
Percent of Total Bytes
lance 4 000:08:05 16.81 Mb 1.5 Kb 16.81 Mb 4.64
sandy 2 000:01:54 3.16 Mb 777 3.16 Mb 0.87
james 3 000:00:25 3.16 Mb 1.0 Kb 3.16 Mb 0.87
ken 1 000:01:32 1.86 Mb 435 1.86 Mb 0.51
bruce 2 000:00:55 1.67 Mb 716 1.67 Mb 0.46
kim 4 000:00:44 1.59 Mb 1.4 Kb 1.59 Mb 0.44
doug 1 000:01:09 1.23 Mb 361 1.23 Mb 0.34
sarah 10 000:00:43 1.05 Mb 3.7 Kb 1.05 Mb 0.29
julie 1 000:02:30 1.04 Mb 359 1.04 Mb 0.29
diane 8 000:03:19 1.00 Mb 1.9 Kb 1.00 Mb 0.28

[Alerts] [Alert] [Totals] [Protocol] [Time of Day] [Interface] [Host] [User] [Domain] [Mobile] [Message] [History]

Top Level Domain Summary
Domain Hits Duration Bytes
Sent
Bytes
Received
Bytes
Total
Percent of Total Bytes
com 37119 057:09:36 198.82 Mb 83.20 Mb 282.03 Mb 77.87
net 7163 009:09:46 23.25 Mb 2.42 Mb 25.66 Mb 7.09
org 870 001:22:53 4.50 Mb 310.9 Kb 4.81 Mb 1.33
mx 380 000:22:46 2.75 Mb 131.9 Kb 2.88 Mb 0.80
my 2 000:01:37 1.87 Mb 796 1.87 Mb 0.52

[Alerts] [Alert] [Totals] [Protocol] [Time of Day] [Interface] [Host] [User] [Domain] [Mobile] [Message] [History]

Raptor Mobile Summary
Net Entity Connections
em-albe 7
em-secvar 5
em-poklar 5
em-nu 3
em-lac 3
em-yun 3
em-larr 1
em-bijo 1
em-itimi 1
em-nazgul 1

[Alerts] [Alert] [Totals] [Protocol] [Time of Day] [Interface] [Host] [User] [Domain] [Mobile] [Message] [History]

Message Summary
Message Severity Hits Description
120 Information 330 Application information
121 Information 41806 Statistics
218 Notice 1 Invalid protocol
226 Notice 525 IP packet dropped [restricted port]
227 Notice 1 VPN packet dropped
228 Notice 3488 Can't connect to destination
238 Notice 15 Application notice
301 Warning 18 Internal warning
308 Warning 11 Can't lookup hostname
310 Warning 822 Can't verify reverse address
334 Warning 4 Denied access to protocol command
343 Warning 1 Software problem
344 Warning 7 Non-transparent call
347 Warning 894 Possible port scan detected
401 Error 2 Internal error
457 Error 1 Application error
513 Alert 1 Saved SMTP trace file
515 Alert 4 User attempted to connect to control port

[Alerts] [Alert] [Totals] [Protocol] [Time of Day] [Interface] [Host] [User] [Domain] [Mobile] [Message] [History]

History Summary [hits]
38956
29 28 27 26 25 24 23 22 21 20 19 18 17 16 15 14 13 12 11 10 09 08 07 06 05 04 03 02 01 00
Days Ago

History Summary [total]
362.06 Mb
29 28 27 26 25 24 23 22 21 20 19 18 17 16 15 14 13 12 11 10 09 08 07 06 05 04 03 02 01 00
Days Ago

Generated by Reptor version 0.97