NETGEAR is aware of a growing number of phone and online scams. To learn how to stay safe click here.
dos
7 TopicsWhat is happening in my logs for my modem/router? Dos, Remote and other stuff.
So i run malwarebyts rootkit scanner and it found so virus or infected rootkits(idk how or if they are different). Anyways i decided i should also check my logs for my router/modem and sure enough if found so dos, remotes and other things. So my questions are should i be worried? What did it do? Do you guys recommend any other anti virus/rootkit scanners to run or any other useful scanner? So far i used malwarebytes, malwarebytes rootkit scanner and Avast antivirus. before i post the logs of my network is there anything i should censor? Will be here waiting.6.9KViews0likes5CommentsLogs full of DoS attacks
My logs are full of this: Attack: SYN/ACK Scan] from source: 113.17.185.222, port 18783, Friday, July 14, 2017 06:39:35 [DoS Attack: RST Scan] from source: 104.232.163.26, port 11730, Friday, July 14, 2017 06:33:26 [DoS Attack: SYN/ACK Scan] from source: 213.238.35.69, port 21, Friday, July 14, 2017 06:23:27 [DoS Attack: SYN/ACK Scan] from source: 136.243.61.77, port 80, Friday, July 14, 2017 05:59:15 [DoS Attack: SYN/ACK Scan] from source: 136.243.61.77, port 80, Friday, July 14, 2017 05:21:26 [DoS Attack: SYN/ACK Scan] from source: 80.248.168.81, port 443, Friday, July 14, 2017 04:47:18 [DoS Attack: TCP/UDP Echo] from source: 141.212.121.206, port 43516, Friday, July 14, 2017 04:44:30 [DoS Attack: SYN/ACK Scan] from source: 119.167.137.231, port 8085, Friday, July 14, 2017 04:31:55 [DoS Attack: SYN/ACK Scan] from source: 13.75.119.99, port 11783, Friday, July 14, 2017 04:20:23 [DoS Attack: SYN/ACK Scan] from source: 13.94.40.78, port 23674, Friday, July 14, 2017 03:59:14 What am I suppose to do about this?NETGEAR C3700 allowing a 'Denial of Service' attack?
Often early in the morning I experience hangs while using Safari on my Macs and iPads. The hang doesn't last more than 5 minutes, but I've discovered that during that time the router admin 'Attached Devices' page shows a suspicious IP address (81.0.229.0) assigned to one of my iPad devices. This IP also shows up in the 'Logs' page associated with a DoS attack. A 'whois' shows the IP belonging to JanigaLabs-CZ. I have screen prints if anyone thinks they can help.Solved15KViews0likes5CommentsWNDR4300 Dos Attacks
In my logs I see [DoS Attack: Ascend Kill] from source: 85.252.162.7, port 123, Monday, September 26, 2016 17:57:50 [DoS Attack: Ascend Kill] from source: 195.154.174.209, port 123, Monday, September 26, 2016 17:55:03 [DoS Attack: RST Scan] from source: 188.121.36.239, port 80, Monday, September 26, 2016 17:52:32 etc. Is this really DoS attacs. Why would anyone DoS me, and how can I prevent this or secure myself best from it?Solved6.2KViews0likes4CommentsMy DNS servers of my internet provider are being seen as dos attacks!? I am running a C7000
My internet providers DNS servers are being seen as DOS attacks. Not just a few times but litterally hundreds per day! It is affecting my routers efficiency! It makes no sense what so ever, Here is two that just happened, Any help would be greatfully appreciated, I never had these issues with my linksys. The 50.27.189.xxx:xxxxx is my web and mail server [DoS attack: TCP- or UDP-based Port Scan] from 208.180.42.100, port 53 1 Wed Jun 08 23:24:27 2016 50.27.189.xx:xxxxx 208.180.42.100:53 [DoS attack: TCP- or UDP-based Port Scan] from 208.180.42.68, port 53 1 Wed Jun 08 23:13:19 2016 50.27.189.xx:xxxxx 208.180.42.68:53 firmware V1.01.155.1KViews1like6CommentsDos Attacks
[DoS Attack: Land Attack] from source: 255.255.255.255, port 67, Saturday, September 12, 2015 15:58:56 [DoS Attack: Land Attack] from source: 255.255.255.255, port 67, Saturday, September 12, 2015 14:50:46 [DoS Attack: Land Attack] from source: 255.255.255.255, port 67, Saturday, September 12, 2015 13:40:32 [DoS Attack: Land Attack] from source: 255.255.255.255, port 67, Saturday, September 12, 2015 10:54:18 [DoS Attack: Land Attack] from source: 255.255.255.255, port 67, Saturday, September 12, 2015 10:31:24 [Time synchronized with NTP server] Saturday, September 12, 2015 10:20:49 [DoS Attack: Land Attack] from source: 255.255.255.255, port 67, Saturday, September 12, 2015 08:55:26 [DHCP IP: 192.168.1.3] to MAC address b4:79:a7:03:e2:3e, Saturday, September 12, 2015 08:48:07 [DoS Attack: Land Attack] from source: 255.255.255.255, port 67, Saturday, September 12, 2015 08:41:56 [DoS Attack: Land Attack] from source: 255.255.255.255, port 67, Saturday, September 12, 2015 07:32:48 [DoS Attack: Land Attack] from source: 255.255.255.255, port 67, Saturday, September 12, 2015 06:51:22 [DoS Attack: Land Attack] from source: 255.255.255.255, port 67, Saturday, September 12, 2015 06:08:33 [DoS Attack: Land Attack] from source: 255.255.255.255, port 67, Saturday, September 12, 2015 05:29:52 [DoS Attack: Land Attack] from source: 255.255.255.255, port 67, Saturday, September 12, 2015 03:38:12 [DoS Attack: Land Attack] from source: 255.255.255.255, port 67, Friday, September 11, 2015 23:41:12 [DoS Attack: TCP/UDP Chargen] from source: 74.82.47.5, port 59305, Friday, September 11, 2015 23:33:31 [DoS Attack: Land Attack] from source: 255.255.255.255, port 67, Friday, September 11, 2015 23:14:06 [DoS Attack: Land Attack] from source: 255.255.255.255, port 67, Friday, September 11, 2015 21:38:51 There are several more of these on my router log. Is this something to worry about? It has been going on for over a week. I just got a new computer. I've changed my IP address even. Still keeps showing up. I've run AVG scan and Anti-Malware scan. Nothing is showing up. PLUS, my internet has not been interrupted at all during these times. I've been playing games like league of legends, and afterward would log onto my router, and a dos attack with that same repeated IP address shows up. However, nothing happened. What is going on?Solved