Warning

 

Close
Confirm Action

Are you sure you wish to do this?

Cancel Confirm
AR15.COM
12/7/2006 6:30:34 PM EDT
I have Comcast Internet.  It is very slow atm.  I rebooted all my network hardware and it was still slow.  I logged into my  router and checked the logs.  Under the firewall log it reads:


Thu Dec 7 22:25:13 2006 =>Found attack from 211.162.20.238. Source port is 1511 and destination port is 19306 which use the TCP protocol.
Thu Dec 7 22:25:13 2006 =>Found attack from 211.162.20.238. Source port is 1557 and destination port is 60207 which use the TCP protocol.
Thu Dec 7 22:30:48 2006 =>Found attack from 122.48.116.244. Source port is 51207 and destination port is 3316 which use the TCP protocol.
Thu Dec 7 22:30:48 2006 =>Found attack from 61.230.180.30. Source port is 3383 and destination port is 3559 which use the TCP protocol.
Thu Dec 7 22:30:48 2006 =>Found attack from 68.54.164.1. Source port is 4386 and destination port is 1433 which use the TCP protocol.



Is someone ddos-ing me?  Perhaps port-scanning?  Help!  I know I'm safe behind my NAT/Router but it makes me mad that some1 might be trying to compromise my security and make my connection slow.

What can I do about this "attack"?

Edit to add:
Just got off the phone with Comcast Level 1 support and they told me there is an "outage" in the area.  Didn't even want to bring up the "attacks" with Level 1.  Anyways, I guess I found the source of the slowness.

Can anyone tell me about the security log though?
12/7/2006 6:44:55 PM EDT
[#1]
Used NeoTrace Pro to ping these fuckers and all of the attacks are originating from China or Taiwan.  


My guess is they are compromised zombie computers running automated tasks, but who knows...  maybe i need to stock up on tinfoil and watch out for black helicopters.  
12/7/2006 6:50:56 PM EDT
[#2]
believe it or not you are going to get attacks from the outside world wether you like it or not.


if you use instantmessaging programs, bittorrent, ANY file sharing program your "attacks"  will increase even more.    


if your that worried about it turn your cable/ dsl modem off for a couple hours that will then when you turn it back on it should renew with a new external ip adddress.    

sygate, zonealarm are decent software firewalls you can install in addition to your router
12/7/2006 7:08:32 PM EDT
[#3]

Quoted:
What can I do about this "attack"?


Nothing.  If the firewall has stopped the incoming traffic, it has done it's job.
Plus, that's only 5 hits in 5 minutes, that's nothing. I get hits every second.


Dec  7 23:04:20 router. Dec 07 2006 23:04:21: %FWSM-4-106023: Deny icmp src outside:59.57.180.63 dst localnets:XX.XX.4.210 (type 8, code 0) by access-group "INTERNET_INCOMING"
Dec  7 23:04:20 router. Dec 07 2006 23:04:21: %FWSM-4-106023: Deny tcp src outside:203.81.237.23/2414 dst localnets:XX.XX.5.67/15118 by access-group "INTERNET_INCOMING"
Dec  7 23:04:20 router. Dec 07 2006 23:04:21: %FWSM-4-106023: Deny tcp src outside:65.164.58.201/2526 dst localnets:XX.XX.4.12/445 by access-group "INTERNET_INCOMING"
Dec  7 23:04:22 router. Dec 07 2006 23:04:22: %FWSM-4-106023: Deny tcp src outside:71.42.83.245/4184 dst localnets:XX.XX.5.37/445 by access-group "INTERNET_INCOMING"
Dec  7 23:04:23 router. Dec 07 2006 23:04:23: %FWSM-4-106023: Deny icmp src outside:222.98.205.162 dst localnets:XX.XX.5.122 (type 8, code 0) by access-group "INTERNET_INCOMING"
Dec  7 23:04:24 router. Dec 07 2006 23:04:24: %FWSM-4-106023: Deny tcp src outside:65.164.58.201/2526 dst localnets:XX.XX.4.12/445 by access-group "INTERNET_INCOMING"
Dec  7 23:04:24 router. Dec 07 2006 23:04:25: %FWSM-4-106023: Deny icmp src outside:222.98.205.162 dst localnets:XX.XX.4.206 (type 8, code 0) by access-group "INTERNET_INCOMING"


That is a small sample of my firewall log at work.  7 hits in 4 seconds and I'm a small site.  My firewall generates 30MB (around 240,000 lines or so) of log files a day, all denials.