NETGEAR is aware of a growing number of phone and online scams. To learn how to stay safe click here.
Forum Discussion
ethantbk
May 12, 2022Aspirant
Dos attack/back door?
[admin login] from source 192.168.1.2, Thursday, May 12, 2022 18:16:35 [admin login] from source 192.168.1.2, Thursday, May 12, 2022 18:15:54 [DoS attack:ACK_Scan] from source: 185.151.107.102,port...
michaelkenward
May 13, 2022Guru - Experienced User
Probably false positives.
What is the device at 192.168.1.12? Thats on your LAN side of the router.
Do a whois look up on 185.151.107.102
% This is the RIPE Database query service.
% The objects are in RPSL format.
%
% The RIPE Database is subject to Terms and Conditions.
% See http://www.ripe.net/db/support/db-terms-conditions.pdf
% Information related to '185.151.107.96 - 185.151.107.127'
% Abuse contact for '185.151.107.96 - 185.151.107.127' is 'abuse@ukrhub.net'
inetnum: 185.151.107.96 - 185.151.107.127
netname: UKRCOM-CUSTOMER-NET
country: UA
status: ASSIGNED PA
created: 2018-08-09T12:37:38Z
last-modified: 2018-08-09T12:37:38Z
source: RIPE
admin-c: YZ42-RIPE
tech-c: UHUB-RIPE
mnt-by: YZ42-RIPE-MNT
remarks: Customer connection
person: Koblyuk Andrei
address: vul. S. Khokhlovyh, 15
address: Kiev, Ukraine, 04050
phone: +380 44 2055570
e-mail: hostmaster@ukrhub.net
nic-hdl: UHUB-RIPE
notify: yuriz@ukr-com.net
mnt-by: YZ42-RIPE-MNT
created: 2007-05-10T07:08:53Z
last-modified: 2017-03-06T11:32:53Z
source: RIPE
person: Yuri Zlenko
address: 04119, Ukraine, Kiev
address: vul. Simyi Khokhlovyh, 15, 3-rd floor
phone: +380 44 205-5514
fax-no: +380 44 205-5525
e-mail: yuriz@ukr-com.net
nic-hdl: YZ42-RIPE
notify: yuriz@ukr-com.net
mnt-by: YZ42-RIPE-MNT
created: 2001-12-07T15:14:10Z
last-modified: 2017-03-06T11:28:28Z
source: RIPE
% Information related to '185.151.104.0/22AS12593'
route: 185.151.104.0/22
origin: AS12593
descr: Ukrcom, Ltd.
mnt-by: YZ42-RIPE-MNT
created: 2016-05-10T10:02:11Z
last-modified: 2016-05-10T10:02:46Z
source: RIPE
% This query was served by the RIPE Database Query Service version 1.103 (WAGYU)
ethantbk
May 13, 2022Aspirant
That IP is my phone, also when those attacks happen my whole internet service cuts out for 20-30 seconds
- microchip8May 13, 2022Master
Disable DoS protection. 99% of time these are false positives. I've been running for years without DoS protection and never had issues
- ethantbkMay 13, 2022Aspirant
Even if they're from Ukraine and messing up my internet?
- microchip8May 14, 2022Master
It's the "DoS protection" that is cutting your Internet, not Ukraine. They're just scanning. Happens to all every time