xaviercharles
Regular Contributor
I noticed in my System Log that there are PPTPD entries. With some of the following concerning entries:-
Oct 10 21:12:34 pptpd[928]: CTRL: Client 183.60.48.25 control connection started
Oct 10 21:12:34 pptpd[928]: CTRL: EOF or bad error reading ctrl packet length.
Oct 10 21:12:34 pptpd[928]: CTRL: couldn't read packet header (exit)
Oct 10 21:12:34 pptpd[928]: CTRL: CTRL read failed
Oct 12 21:11:10 pptpd[1128]: CTRL: Client 183.60.48.25 control connection started
Oct 12 21:11:10 pptpd[1128]: CTRL: EOF or bad error reading ctrl packet length.
Oct 12 21:11:10 pptpd[1128]: CTRL: couldn't read packet header (exit)
Oct 12 21:11:10 pptpd[1128]: CTRL: CTRL read failed
Oct 12 21:11:10 pptpd[1128]: CTRL: Client 183.60.48.25 control connection finished
Oct 13 21:18:54 pptpd[1225]: CTRL: Client 183.60.48.25 control connection started
Oct 13 21:18:54 pptpd[1225]: CTRL: EOF or bad error reading ctrl packet length.
Oct 13 21:18:54 pptpd[1225]: CTRL: couldn't read packet header (exit)
Oct 13 21:18:54 pptpd[1225]: CTRL: CTRL read failed
Oct 13 21:18:54 pptpd[1225]: CTRL: Client 183.60.48.25 control connection finished
Oct 14 21:18:47 pptpd[1322]: CTRL: Client 183.60.48.25 control connection started
Oct 14 21:18:47 pptpd[1322]: CTRL: EOF or bad error reading ctrl packet length.
Oct 14 21:18:47 pptpd[1322]: CTRL: couldn't read packet header (exit)
Oct 14 21:18:47 pptpd[1322]: CTRL: CTRL read failed
Oct 14 21:18:47 pptpd[1322]: CTRL: Client 183.60.48.25 control connection finished
Oct 15 04:17:29 pptpd[1351]: CTRL: Client 206.47.252.49 control connection started
Oct 15 04:17:29 pptpd[1351]: CTRL: EOF or bad error reading ctrl packet length.
Oct 15 04:17:29 pptpd[1351]: CTRL: couldn't read packet header (exit)
Oct 15 04:17:29 pptpd[1351]: CTRL: CTRL read failed
Oct 15 04:17:29 pptpd[1351]: CTRL: Client 206.47.252.49 control connection finished
Oct 15 21:17:23 pptpd[1422]: CTRL: Client 183.60.48.25 control connection started
Oct 15 21:17:23 pptpd[1422]: CTRL: EOF or bad error reading ctrl packet length.
Oct 15 21:17:23 pptpd[1422]: CTRL: couldn't read packet header (exit)
Oct 15 21:17:23 pptpd[1422]: CTRL: CTRL read failed
Oct 15 21:17:23 pptpd[1422]: CTRL: Client 183.60.48.25 control connection finished
Oct 17 21:17:23 pptpd[1666]: CTRL: Client 183.60.48.25 control connection started
Oct 17 21:17:23 pptpd[1666]: CTRL: EOF or bad error reading ctrl packet length.
Oct 17 21:17:23 pptpd[1666]: CTRL: couldn't read packet header (exit)
Oct 17 21:17:23 pptpd[1666]: CTRL: CTRL read failed
Oct 17 21:17:23 pptpd[1666]: CTRL: Client 183.60.48.25 control connection finished
I've run a reverse ip lookup on both 183.60.48.25 and 206.47.252.49
183.60.48.25 Seems to be from China Telecom Guangdong
206.47.252.49 Seems to be from Bell Canada
Oct 10 21:12:34 pptpd[928]: CTRL: Client 183.60.48.25 control connection started
Oct 10 21:12:34 pptpd[928]: CTRL: EOF or bad error reading ctrl packet length.
Oct 10 21:12:34 pptpd[928]: CTRL: couldn't read packet header (exit)
Oct 10 21:12:34 pptpd[928]: CTRL: CTRL read failed
Oct 12 21:11:10 pptpd[1128]: CTRL: Client 183.60.48.25 control connection started
Oct 12 21:11:10 pptpd[1128]: CTRL: EOF or bad error reading ctrl packet length.
Oct 12 21:11:10 pptpd[1128]: CTRL: couldn't read packet header (exit)
Oct 12 21:11:10 pptpd[1128]: CTRL: CTRL read failed
Oct 12 21:11:10 pptpd[1128]: CTRL: Client 183.60.48.25 control connection finished
Oct 13 21:18:54 pptpd[1225]: CTRL: Client 183.60.48.25 control connection started
Oct 13 21:18:54 pptpd[1225]: CTRL: EOF or bad error reading ctrl packet length.
Oct 13 21:18:54 pptpd[1225]: CTRL: couldn't read packet header (exit)
Oct 13 21:18:54 pptpd[1225]: CTRL: CTRL read failed
Oct 13 21:18:54 pptpd[1225]: CTRL: Client 183.60.48.25 control connection finished
Oct 14 21:18:47 pptpd[1322]: CTRL: Client 183.60.48.25 control connection started
Oct 14 21:18:47 pptpd[1322]: CTRL: EOF or bad error reading ctrl packet length.
Oct 14 21:18:47 pptpd[1322]: CTRL: couldn't read packet header (exit)
Oct 14 21:18:47 pptpd[1322]: CTRL: CTRL read failed
Oct 14 21:18:47 pptpd[1322]: CTRL: Client 183.60.48.25 control connection finished
Oct 15 04:17:29 pptpd[1351]: CTRL: Client 206.47.252.49 control connection started
Oct 15 04:17:29 pptpd[1351]: CTRL: EOF or bad error reading ctrl packet length.
Oct 15 04:17:29 pptpd[1351]: CTRL: couldn't read packet header (exit)
Oct 15 04:17:29 pptpd[1351]: CTRL: CTRL read failed
Oct 15 04:17:29 pptpd[1351]: CTRL: Client 206.47.252.49 control connection finished
Oct 15 21:17:23 pptpd[1422]: CTRL: Client 183.60.48.25 control connection started
Oct 15 21:17:23 pptpd[1422]: CTRL: EOF or bad error reading ctrl packet length.
Oct 15 21:17:23 pptpd[1422]: CTRL: couldn't read packet header (exit)
Oct 15 21:17:23 pptpd[1422]: CTRL: CTRL read failed
Oct 15 21:17:23 pptpd[1422]: CTRL: Client 183.60.48.25 control connection finished
Oct 17 21:17:23 pptpd[1666]: CTRL: Client 183.60.48.25 control connection started
Oct 17 21:17:23 pptpd[1666]: CTRL: EOF or bad error reading ctrl packet length.
Oct 17 21:17:23 pptpd[1666]: CTRL: couldn't read packet header (exit)
Oct 17 21:17:23 pptpd[1666]: CTRL: CTRL read failed
Oct 17 21:17:23 pptpd[1666]: CTRL: Client 183.60.48.25 control connection finished
I've run a reverse ip lookup on both 183.60.48.25 and 206.47.252.49
183.60.48.25 Seems to be from China Telecom Guangdong
206.47.252.49 Seems to be from Bell Canada