 |
Welcome to Windows 7 Forums. Our forum is dedicated to helping you find solutions with any problems, errors or issues you are experiencing with Windows 7. The Windows 7 forum also covers news and updates and has an extensive Windows 7 tutorial section that covers a wide range of tips and tricks.
Windows 7 - Multiple DoS Attacks |
02-04-2012
|
#1 | | Windows 7 Ultimate x86/Ubuntu |
Multiple DoS Attacks Hi Guys, I have just had a look at my Router settings from 192.168.0.1 and it shows multiple DoS (Denial Of Service) Attacks from different IP's. Code: [DoS attack]from source:41.232.151.64, destination source:192.168.0.2 LEN=131 TOS=0x00 PREC=0x00 TTL=111 ID=8169 PROTO=UDP SPT=50774 DPT=56669 - Fri, 2012-02-03 19:30:58
[DoS attack]from source:111.251.185.70, destination source:192.168.0.2 LEN=129 TOS=0x00 PREC=0x00 TTL=109 ID=17904 PROTO=UDP SPT=24580 DPT=56669 - Fri, 2012-02-03 19:30:59
[DoS attack]from source:111.251.185.70, destination source:192.168.0.2 LEN=129 TOS=0x00 PREC=0x00 TTL=109 ID=17926 PROTO=UDP SPT=24580 DPT=56669 - Fri, 2012-02-03 19:31:00
[DoS attack]from source:188.27.37.114, destination source:192.168.0.2 LEN=58 TOS=0x00 PREC=0x00 TTL=115 ID=5667 PROTO=UDP SPT=50803 DPT=56669 - Fri, 2012-02-03 19:31:00
[DoS attack]from source:188.244.45.231, destination source:192.168.0.2 LEN=58 TOS=0x00 PREC=0x00 TTL=111 ID=28604 PROTO=UDP SPT=1034 DPT=56669 - Fri, 2012-02-03 19:31:00
[DoS attack]from source:82.36.113.84, destination source:192.168.0.2 LEN=52 TOS=0x00 PREC=0x00 TTL=112 ID=5826 DF PROTO=TCP SPT:62778 DPT:56669 WINDOW=8192 RES=0x00 SYN URGP=0 - Fri, 2012-02-03 19:31:00
[DoS attack]from source:188.244.45.231, destination source:192.168.0.2 LEN=52 TOS=0x00 PREC=0x00 TTL=111 ID=28602 DF PROTO=TCP SPT:64002 DPT:56669 WINDOW=8192 RES=0x00 SYN URGP=0 - Fri, 2012-02-03 19:31:00
[DoS attack]from source:111.251.185.70, destination source:192.168.0.2 LEN=129 TOS=0x00 PREC=0x00 TTL=109 ID=17963 PROTO=UDP SPT=24580 DPT=56669 - Fri, 2012-02-03 19:31:00
[DoS attack]from source:188.237.80.47, destination source:192.168.0.2 LEN=134 TOS=0x00 PREC=0x00 TTL=109 ID=42179 PROTO=UDP SPT=10000 DPT=56669 - Fri, 2012-02-03 19:31:00
[DoS attack]from source:111.251.185.70, destination source:192.168.0.2 LEN=129 TOS=0x00 PREC=0x00 TTL=109 ID=18123 PROTO=UDP SPT=24580 DPT=56669 - Fri, 2012-02-03 19:31:00
[DoS attack]from source:92.114.190.144, destination source:192.168.0.2 LEN=134 TOS=0x00 PREC=0x00 TTL=110 ID=16273 PROTO=UDP SPT=59440 DPT=56669 - Fri, 2012-02-03 19:31:00
[DoS attack]from source:111.251.185.70, destination source:192.168.0.2 LEN=129 TOS=0x00 PREC=0x00 TTL=109 ID=18129 PROTO=UDP SPT=24580 DPT=56669 - Fri, 2012-02-03 19:31:00
[DoS attack]from source:111.251.185.70, destination source:192.168.0.2 LEN=129 TOS=0x00 PREC=0x00 TTL=109 ID=19140 PROTO=UDP SPT=24580 DPT=56669 - Fri, 2012-02-03 19:31:04 I do not have much experience with Routers/Networks, so I need help blocking these or removing them.
I have a NETGEAR DGN1000SP Router with Virgin Media 10MB/s Internet.
I have 1 Netbook, 2 PC's and a iPhone. But I only use 1 PC and my iPhone. My family uses the other 2 computers.
I have installed MSE, Malwarebytes, and Comodo Firewall on the Netbook and 1 PC. Have not done it to the other PC yet, and I don't really need to do anything to my iPhone. | My System Specs | | OS Windows 7 Ultimate x86/Ubuntu CPU Intel Core i5 2500k at 3.3 GhZ Memory 2x4GB DDR3 1333Hz Graphics Card Ati Radeon 6770 Sound Card Speakers Monitor(s) Displays 1x 15" HD 572 Screen Resolution 1024x768 Keyboard Wired Keyboard Mouse Wired Mouse Cooling 3x Fans Hard Drives 2x500GB Internet Speed 10MB/s Other Info Netbook: Dell Inspiron Mini |
02-04-2012
|
#2 | | Windows 7 Ultimate SP1 64-Bit |
The first thing you need to do is contact your ISP as their servers may have been compromised.
Virgin Media should help and advise as to what you can do, but you may have to upgrade your hardware.
Have a look at this article, which describes the different ways these DoS attacks work and possible solutions to get them stopped. How to Prevent Denial of Service Attacks : Learn-Networking.com
This Wiki article has loads of useful information too. http://en.wikipedia.org/wiki/Denial-of-service_attack | My System Specs | | System Manufacturer/Model Number HP Pavilion Elite 495UK OS Windows 7 Ultimate SP1 64-Bit CPU Intel Core i7 870 @ 2.93GHz Motherboard MSI 2A9C (CPU1) Memory 8Gb Dual-Channel DDR3 @ 664MHz Graphics Card nVidia GeForce GTX 460 1024MB dedicated RAM Sound Card Realtek HD Audio Monitor(s) Displays HP2310i Screen Resolution 1920 x 1080 Keyboard Logitech K750 solar-powered keyboard Mouse Logitech Wireless M180 mouse PSU 460W Case HP Elite Cooling Air cooled Hard Drives 1x1954GB Hitachi HDS22020ALA 330 (RAID), 1x1954GB Hitachi External for backup and storage Internet Speed 2Mb Other Info Pure Avanti Flow Internet Radio with iPod Dock, 64Gb iPod, HP USB Speakers, Sony MDR-V500 Headphones, Sony Vaio F-Series Laptop |
02-05-2012
|
#3 | | Windows 7 Home Premium x64 SP1 |
This is apparently not uncommon with Netgear routers. I suspect it is very common, but only Netgear routers are storing them as DOS attacks. They can be random port scans. I would think you will be protected by the NAT firewall in any case. I agree with seavixen32, ask your ISP about it, if they agree it is not an issue, I think you are ok. You could not prevent a DOS from your end anyway, that is a server/ISP issue. If they were being attacked, and their bandwidth compromised, they would be all over it. A Guy
Last edited by A Guy; 02-05-2012 at 12:26 PM..
| My System Specs | | OS Windows 7 Home Premium x64 SP1 CPU INTEL Core i5-750 Quad-Core 3.37GHz Motherboard ASUS P7P55D Memory KINGSTON 4GB (2 x 2GB) HyperX PC3-12800 DDR3 1600MHz CL8 Graphics Card MSI N240GT-MD1G/D5 GeForce GT 240 1GB 128-bit GDDR5 Monitor(s) Displays Samsung SyncMaster B2430H 24" , SyncMaster P2050 20" Screen Resolution 1920 x 1080 , 1440 x 900 PSU ANTEC TruePower New TP-550, 80 PLUS, 550W Case ANTEC Three Hundred Illusion Cooling COOLER MASTER Hyper 212 Plus, 3 x 120mm 1 x 140mm Case Hard Drives Intel X25M Gen2 80GB, SEAGATE 500GB Barracudaź 7200.12, SATA 3 Gb/s, 7200 RPM, 16MB cache Internet Speed 20 + Mbps |
02-05-2012
|
#4 | | Windows 7 Ultimate x86/Ubuntu |
Thanks for the help guys, I will contact my ISP as soon as I can. | My System Specs | | OS Windows 7 Ultimate x86/Ubuntu CPU Intel Core i5 2500k at 3.3 GhZ Memory 2x4GB DDR3 1333Hz Graphics Card Ati Radeon 6770 Sound Card Speakers Monitor(s) Displays 1x 15" HD 572 Screen Resolution 1024x768 Keyboard Wired Keyboard Mouse Wired Mouse Cooling 3x Fans Hard Drives 2x500GB Internet Speed 10MB/s Other Info Netbook: Dell Inspiron Mini |
02-05-2012
|
#5 | | Windows 7 Ultimate SP1 64-Bit |
You're very welcome.
Do let us know what they say as it'll be interesting to know if they take it seriously. | My System Specs | | System Manufacturer/Model Number HP Pavilion Elite 495UK OS Windows 7 Ultimate SP1 64-Bit CPU Intel Core i7 870 @ 2.93GHz Motherboard MSI 2A9C (CPU1) Memory 8Gb Dual-Channel DDR3 @ 664MHz Graphics Card nVidia GeForce GTX 460 1024MB dedicated RAM Sound Card Realtek HD Audio Monitor(s) Displays HP2310i Screen Resolution 1920 x 1080 Keyboard Logitech K750 solar-powered keyboard Mouse Logitech Wireless M180 mouse PSU 460W Case HP Elite Cooling Air cooled Hard Drives 1x1954GB Hitachi HDS22020ALA 330 (RAID), 1x1954GB Hitachi External for backup and storage Internet Speed 2Mb Other Info Pure Avanti Flow Internet Radio with iPod Dock, 64Gb iPod, HP USB Speakers, Sony MDR-V500 Headphones, Sony Vaio F-Series Laptop Multiple DoS Attacks problems? All times are GMT -5. The time now is 01:22 AM. |  |