我在服务器日志中看到了很多这样的情况
IN=eth0 OUT= MAC= SRC=<my external ip> DST=224.0.0.251 LEN=1126 TOS=0x00 PREC=0x00 TTL=255 ID=0 DF PROTO=UDP SPT=5353 DPT=5353 LEN=1106
IN=eth0 OUT= MAC= SRC=<my external ip> DST=224.0.0.251 LEN=194 TOS=0x00 PREC=0x00 TTL=255 ID=0 DF PROTO=UDP SPT=5353 DPT=5353 LEN=174
IN=eth0 OUT= MAC= SRC=<my external ip> DST=224.0.0.251 LEN=69 TOS=0x00 PREC=0x00 TTL=255 ID=0 DF PROTO=UDP SPT=5353 DPT=5353 LEN=49
IN=eth0 OUT= MAC= SRC=<my external ip> DST=224.0.0.251 LEN=60 TOS=0x00 PREC=0x00 TTL=255 ID=0 DF PROTO=UDP SPT=5353 DPT=5353 LEN=40
IN=eth0 OUT= MAC= SRC=<my external ip> DST=224.0.0.251 LEN=104 TOS=0x00 PREC=0x00 TTL=255 ID=0 DF PROTO=UDP SPT=5353 DPT=5353 LEN=84
IN=eth0 OUT= MAC= SRC=<my external ip> DST=224.0.0.251 LEN=138 TOS=0x00 PREC=0x00 TTL=255 ID=0 DF PROTO=UDP SPT=5353 DPT=5353 LEN=118
IN=eth0 OUT= MAC= SRC=<my external ip> DST=224.0.0.251 LEN=207 TOS=0x00 PREC=0x00 TTL=255 ID=0 DF PROTO=UDP SPT=5353 DPT=5353 LEN=187
IN=eth0 OUT= MAC= SRC=<my external ip> DST=224.0.0.251 LEN=60 TOS=0x00 PREC=0x00 TTL=255 ID=0 DF PROTO=UDP SPT=5353 DPT=5353 LEN=40
IN=eth0 OUT= MAC= SRC=<my external ip> DST=224.0.0.251 LEN=104 TOS=0x00 PREC=0x00 TTL=255 ID=0 DF PROTO=UDP SPT=5353 DPT=5353 LEN=84
IN=eth0 OUT= MAC= SRC=<my external ip> DST=224.0.0.251 LEN=138 TOS=0x00 PREC=0x00 TTL=255 ID=0 DF PROTO=UDP SPT=5353 DPT=5353 LEN=118
IN=eth0 OUT= MAC= SRC=<my external ip> DST=224.0.0.251 LEN=207 TOS=0x00 PREC=0x00 TTL=255 ID=0 DF PROTO=UDP SPT=5353 DPT=5353 LEN=187
IN=eth0 OUT= MAC= SRC=<my external ip> DST=224.0.0.251 LEN=60 TOS=0x00 PREC=0x00 TTL=255 ID=0 DF PROTO=UDP SPT=5353 DPT=5353 LEN=40
IN=eth0 OUT= MAC= SRC=<my external ip> DST=224.0.0.251 LEN=104 TOS=0x00 PREC=0x00 TTL=255 ID=0 DF PROTO=UDP SPT=5353 DPT=5353 LEN=84
IN=eth0 OUT= MAC= SRC=<my external ip> DST=224.0.0.251 LEN=138 TOS=0x00 PREC=0x00 TTL=255 ID=0 DF PROTO=UDP SPT=5353 DPT=5353 LEN=118
IN=eth0 OUT= MAC= SRC=<my external ip> DST=224.0.0.251 LEN=207 TOS=0x00 PREC=0x00 TTL=255 ID=0 DF PROTO=UDP SPT=5353 DPT=5353 LEN=187
IN=eth0 OUT= MAC= SRC=<my external ip> DST=224.0.0.251 LEN=236 TOS=0x00 PREC=0x00 TTL=255 ID=0 DF PROTO=UDP SPT=5353 DPT=5353 LEN=216
IN=eth0 OUT= MAC= SRC=<my external ip> DST=224.0.0.251 LEN=69 TOS=0x00 PREC=0x00 TTL=255 ID=0 DF PROTO=UDP SPT=5353 DPT=5353 LEN=49
IN=eth0 OUT= MAC= SRC=<my external ip> DST=224.0.0.251 LEN=190 TOS=0x00 PREC=0x00 TTL=255 ID=0 DF PROTO=UDP SPT=5353 DPT=5353 LEN=170
IN=eth0 OUT= MAC= SRC=<my external ip> DST=224.0.0.251 LEN=843 TOS=0x00 PREC=0x00 TTL=255 ID=0 DF PROTO=UDP SPT=5353 DPT=5353 LEN=823
IN=eth0 OUT= MAC= SRC=<my external ip> DST=224.0.0.251 LEN=973 TOS=0x00 PREC=0x00 TTL=255 ID=0 DF PROTO=UDP SPT=5353 DPT=5353 LEN=953
IN=eth0 OUT= MAC= SRC=<my external ip> DST=224.0.0.251 LEN=236 TOS=0x00 PREC=0x00 TTL=255 ID=0 DF PROTO=UDP SPT=5353 DPT=5353 LEN=216
IN=eth0 OUT= MAC= SRC=<my external ip> DST=224.0.0.251 LEN=69 TOS=0x00 PREC=0x00 TTL=255 ID=0 DF PROTO=UDP SPT=5353 DPT=5353 LEN=49
IN=eth0 OUT= MAC= SRC=<my external ip> DST=224.0.0.251 LEN=973 TOS=0x00 PREC=0x00 TTL=255 ID=0 DF PROTO=UDP SPT=5353 DPT=5353 LEN=953
IN=eth0 OUT= MAC= SRC=<my external ip> DST=224.0.0.251 LEN=1126 TOS=0x00 PREC=0x00 TTL=255 ID=0 DF PROTO=UDP SPT=5353 DPT=5353 LEN=1106
IN=eth0 OUT= MAC= SRC=<my external ip> DST=224.0.0.251 LEN=69 TOS=0x00 PREC=0x00 TTL=255 ID=0 DF PROTO=UDP SPT=5353 DPT=5353 LEN=49
这些是被 INPUT 链丢弃的数据包。这些看起来像多播 DNS 数据包,但它们来自 eth0,它是 WAN 并直接连接到我的路由器。我是否以某种方式错误配置了某些东西,以至于 LAN mDNS 数据包被路由到 eth0?或者这是一次非常有创意的攻击?