Forum Articles
  Welcome back Join CF
You are here You are here: Home | Forum | DOS ATTACK,should I be worried

You are currently viewing our boards as a guest which gives you limited access to view most of the discussions, articles and other free features. By joining our Virgin Media community you will have full access to all discussions, be able to view and post threads, communicate privately with other members (PM), respond to polls, upload your own images/photos, and access many other special features. Registration is fast, simple and absolutely free so please join our community today.


Welcome to Cable Forum
Go Back   Cable Forum > Computers & IT > Networking
Register FAQ Community Calendar

DOS ATTACK,should I be worried
Reply
 
Thread Tools
Old 21-10-2009, 19:42   #16
budwieser
cf.mega poster
 
budwieser's Avatar
 
Join Date: Jan 2004
Location: Cambridgeshire
Age: 63
Posts: 4,232
budwieser has a nice shiny starbudwieser has a nice shiny starbudwieser has a nice shiny star
budwieser has a nice shiny starbudwieser has a nice shiny starbudwieser has a nice shiny starbudwieser has a nice shiny starbudwieser has a nice shiny starbudwieser has a nice shiny starbudwieser has a nice shiny starbudwieser has a nice shiny starbudwieser has a nice shiny starbudwieser has a nice shiny star
Re: DOS ATTACK,should I be worried

Quote:
Originally Posted by pabscars View Post
Hi Ladies and Gents, Ive just nipped home at lunchtime to see if I'd had a reply from some of the guys on the vm newsgroups, and while I was mooching I had a quick look at the router logs.

It showed a dos attack on port 80 at the weekend, whilst I wasnt using the internet I might add.

Should I be concerned.

any advice for a relative novice.
Head over to www.grc.com and use the free software there.
budwieser is offline   Reply With Quote
Advertisement
Old 22-10-2009, 07:56   #17
pabscars
Inactive
 
Join Date: Oct 2008
Location: warrington
Age: 53
Services: TiVo, 75 Smeg Broadband
Posts: 2,199
pabscars has reached the bronze age
pabscars has reached the bronze agepabscars has reached the bronze agepabscars has reached the bronze agepabscars has reached the bronze agepabscars has reached the bronze agepabscars has reached the bronze agepabscars has reached the bronze agepabscars has reached the bronze agepabscars has reached the bronze agepabscars has reached the bronze agepabscars has reached the bronze agepabscars has reached the bronze agepabscars has reached the bronze agepabscars has reached the bronze agepabscars has reached the bronze agepabscars has reached the bronze agepabscars has reached the bronze age
Re: DOS ATTACK,should I be worried

Quote:
Originally Posted by budwieser View Post
Head over to www.grc.com and use the free software there.
Thanks again guys, I had a quick look last night, and I could only see the one mention of a dos attack, and it mentioned ACK attack whatever that is.

I think it did show the ip address of where the attack came from, so I will nip home at lunch and copy and paste on here for you to peruse.
pabscars is offline   Reply With Quote
Old 22-10-2009, 09:03   #18
Wayfair
Inactive
 
Join Date: Nov 2008
Services: Virgin tinterweb, Tivo with an extra large package 'oh yes' and a speaky thing...
Posts: 923
Wayfair has a bronze arrayWayfair has a bronze arrayWayfair has a bronze array
Wayfair has a bronze arrayWayfair has a bronze arrayWayfair has a bronze arrayWayfair has a bronze arrayWayfair has a bronze arrayWayfair has a bronze arrayWayfair has a bronze arrayWayfair has a bronze arrayWayfair has a bronze arrayWayfair has a bronze array
Re: DOS ATTACK,should I be worried

On the grc.com site pabscars, use the Shields UP thing in the Hot Spots section, proceed / then common ports, what that will do is test your firewall / router settings for you.
Wayfair is offline   Reply With Quote
Old 22-10-2009, 09:12   #19
pabscars
Inactive
 
Join Date: Oct 2008
Location: warrington
Age: 53
Services: TiVo, 75 Smeg Broadband
Posts: 2,199
pabscars has reached the bronze age
pabscars has reached the bronze agepabscars has reached the bronze agepabscars has reached the bronze agepabscars has reached the bronze agepabscars has reached the bronze agepabscars has reached the bronze agepabscars has reached the bronze agepabscars has reached the bronze agepabscars has reached the bronze agepabscars has reached the bronze agepabscars has reached the bronze agepabscars has reached the bronze agepabscars has reached the bronze agepabscars has reached the bronze agepabscars has reached the bronze agepabscars has reached the bronze agepabscars has reached the bronze age
Re: DOS ATTACK,should I be worried

Quote:
Originally Posted by Wayfair View Post
On the grc.com site pabscars, use the Shields UP thing in the Hot Spots section, proceed / then common ports, what that will do is test your firewall / router settings for you.

Cool, I wasnt sure what it was all about,

mucho gratsi
pabscars is offline   Reply With Quote
Old 22-10-2009, 10:38   #20
webcrawler2050
Inactive
 
Join Date: Feb 2008
Location: Swindon
Services: TiVo 110MB BB Phone Line
Posts: 3,087
webcrawler2050 has reached the bronze age
webcrawler2050 has reached the bronze agewebcrawler2050 has reached the bronze agewebcrawler2050 has reached the bronze agewebcrawler2050 has reached the bronze agewebcrawler2050 has reached the bronze agewebcrawler2050 has reached the bronze agewebcrawler2050 has reached the bronze age
Send a message via MSN to webcrawler2050
Re: DOS ATTACK,should I be worried

Quote:
Originally Posted by pabscars View Post
Thanks again guys, I had a quick look last night, and I could only see the one mention of a dos attack, and it mentioned ACK attack whatever that is.

I think it did show the ip address of where the attack came from, so I will nip home at lunch and copy and paste on here for you to peruse.
Let us know, then we can trace the owner of the IP and report it.
webcrawler2050 is offline   Reply With Quote
Old 22-10-2009, 10:44   #21
pabscars
Inactive
 
Join Date: Oct 2008
Location: warrington
Age: 53
Services: TiVo, 75 Smeg Broadband
Posts: 2,199
pabscars has reached the bronze age
pabscars has reached the bronze agepabscars has reached the bronze agepabscars has reached the bronze agepabscars has reached the bronze agepabscars has reached the bronze agepabscars has reached the bronze agepabscars has reached the bronze agepabscars has reached the bronze agepabscars has reached the bronze agepabscars has reached the bronze agepabscars has reached the bronze agepabscars has reached the bronze agepabscars has reached the bronze agepabscars has reached the bronze agepabscars has reached the bronze agepabscars has reached the bronze agepabscars has reached the bronze age
Re: DOS ATTACK,should I be worried

Quote:
Originally Posted by webcrawler2050 View Post
Let us know, then we can trace the owner of the IP and report it.
Does that mean I can then send the boys round
pabscars is offline   Reply With Quote
Old 22-10-2009, 11:03   #22
webcrawler2050
Inactive
 
Join Date: Feb 2008
Location: Swindon
Services: TiVo 110MB BB Phone Line
Posts: 3,087
webcrawler2050 has reached the bronze age
webcrawler2050 has reached the bronze agewebcrawler2050 has reached the bronze agewebcrawler2050 has reached the bronze agewebcrawler2050 has reached the bronze agewebcrawler2050 has reached the bronze agewebcrawler2050 has reached the bronze agewebcrawler2050 has reached the bronze age
Send a message via MSN to webcrawler2050
Re: DOS ATTACK,should I be worried

Quote:
Originally Posted by pabscars View Post
Does that mean I can then send the boys round
Yeah
webcrawler2050 is offline   Reply With Quote
Old 22-10-2009, 12:42   #23
pabscars
Inactive
 
Join Date: Oct 2008
Location: warrington
Age: 53
Services: TiVo, 75 Smeg Broadband
Posts: 2,199
pabscars has reached the bronze age
pabscars has reached the bronze agepabscars has reached the bronze agepabscars has reached the bronze agepabscars has reached the bronze agepabscars has reached the bronze agepabscars has reached the bronze agepabscars has reached the bronze agepabscars has reached the bronze agepabscars has reached the bronze agepabscars has reached the bronze agepabscars has reached the bronze agepabscars has reached the bronze agepabscars has reached the bronze agepabscars has reached the bronze agepabscars has reached the bronze agepabscars has reached the bronze agepabscars has reached the bronze age
Re: DOS ATTACK,should I be worried

Quote:
Originally Posted by webcrawler2050 View Post
Let us know, then we can trace the owner of the IP and report it.
As requested guys

[LAN access from remote] from 121.14.229.199:6000 to 192.168.1.5:80, Wednesday, October 21,2009 04:38:24
[DoS Attack: ACK Scan] from source: 213.199.149.148, port 80, Wednesday, October 21,2009 01:18:40

I dont know if you can glean any info from this, and I didnt want to post any more info from the logs as it contained mac address's.
pabscars is offline   Reply With Quote
Old 22-10-2009, 12:48   #24
webcrawler2050
Inactive
 
Join Date: Feb 2008
Location: Swindon
Services: TiVo 110MB BB Phone Line
Posts: 3,087
webcrawler2050 has reached the bronze age
webcrawler2050 has reached the bronze agewebcrawler2050 has reached the bronze agewebcrawler2050 has reached the bronze agewebcrawler2050 has reached the bronze agewebcrawler2050 has reached the bronze agewebcrawler2050 has reached the bronze agewebcrawler2050 has reached the bronze age
Send a message via MSN to webcrawler2050
Re: DOS ATTACK,should I be worried

213.199.144.0

Code:
netname: MSFT-IDC
org: ORG-MA42-RIPE
descr: Microsoft London Internet Data Center
descr: Distribution of Microsoft content
descr: London
country: GB
admin-c: CXN-RIPE
tech-c: CXN-RIPE
status: ASSIGNED PA
mnt-by: MICROSOFT-MAINT
mnt-domains: MICROSOFT-MAINT
source: RIPE # Filtered

organisation: ORG-MA42-RIPE
org-name: Microsoft Limited
org-type: LIR
address: Microsoft
Allie Settlemyre
One Microsoft Way
WA 98052 Redmond
UNITED STATES
phone: +1 (425) 705 0516
fax-no: +1 425 936 7329
e-mail: [Who Is Domain][trace][Reverse DNS Search]
admin-c: AS9763-RIPE
admin-c: BR329-ARIN
admin-c: EN603-RIPE
mnt-ref: MICROSOFT-MAINT
mnt-ref: RIPE-NCC-HM-MNT
mnt-by: RIPE-NCC-HM-MNT
source: RIPE # Filtered

person: Christian Nielsen
address: One Microsoft Way
address: Redmond, WA 98052
address: US
phone: +1 (425) 706 1083
nic-hdl: CXN-RIPE
source: RIPE # Filtered

% Information related to '213.199.144.0[Who Is IP][trace][Reverse IP Search]/20AS8068'

route: 213.199.144.0/20
descr: Microsoft European IDCs
origin: AS8068
mnt-by: MICROSOFT-MAINT
source: RIPE # Filtered
AS NUMBER: AS8068 = MICROSOFTEU Microsoft European Data Center

Ripe: http://www.db.ripe.net/whois?object_...rchtext=AS8068

http://www.microsoft.com/emea/pressc...PR_240909.mspx

More info:

IP address country: ip address flag United Kingdom
IP address state: London, City of
IP address city: London
IP address latitude: 51.5000
IP address longitude: -0.1167
ISP of this IP [?]: Microsoft
Organization: Microsoft London Internet Data Center
Local time in United Kingdom: 2009-10-22 12:51

Very likely to be MSN / Windows updates - I think - I do believe they have transit in Telehouse


121.14.229.199


Code:
netname: HENGXIN-COMPANY
descr: Shantou Hengxin Techonlogy Co.,Ltd
country: CN
admin-c: ST-AP
tech-c: IC83-AP
mnt-by: MAINT-CHINANET-GD
changed: [Who Is Domain][trace][Reverse DNS Search] 20090122
status: Allocated non-portable
source: APNIC
AS NUMBER: AS4134 role: Asia Pacific Network Information Centre
address: APNIC, see http://www.apnic.net


RIPE: http://www.db.ripe.net/whois?form_ty..._search=Search

CONTACT: helpdesk@apnic.net

Should help
webcrawler2050 is offline   Reply With Quote
Old 22-10-2009, 12:50   #25
danielf
cf.mega poser
 
danielf's Avatar
 
Join Date: Jun 2003
Posts: 16,687
danielf has a golden auradanielf has a golden auradanielf has a golden aura
danielf has a golden auradanielf has a golden auradanielf has a golden auradanielf has a golden auradanielf has a golden auradanielf has a golden auradanielf has a golden auradanielf has a golden auradanielf has a golden auradanielf has a golden auradanielf has a golden auradanielf has a golden auradanielf has a golden auradanielf has a golden auradanielf has a golden aura
Re: DOS ATTACK,should I be worried

I believe the 213.199 range belongs to Microsoft?
__________________
Remember kids: We are blessed with a listening, caring government.
danielf is offline   Reply With Quote
Old 22-10-2009, 12:54   #26
webcrawler2050
Inactive
 
Join Date: Feb 2008
Location: Swindon
Services: TiVo 110MB BB Phone Line
Posts: 3,087
webcrawler2050 has reached the bronze age
webcrawler2050 has reached the bronze agewebcrawler2050 has reached the bronze agewebcrawler2050 has reached the bronze agewebcrawler2050 has reached the bronze agewebcrawler2050 has reached the bronze agewebcrawler2050 has reached the bronze agewebcrawler2050 has reached the bronze age
Send a message via MSN to webcrawler2050
Re: DOS ATTACK,should I be worried

Quote:
Originally Posted by danielf View Post
I believe the 213.199 range belongs to Microsoft?
Yup look above
webcrawler2050 is offline   Reply With Quote
Old 22-10-2009, 13:02   #27
pabscars
Inactive
 
Join Date: Oct 2008
Location: warrington
Age: 53
Services: TiVo, 75 Smeg Broadband
Posts: 2,199
pabscars has reached the bronze age
pabscars has reached the bronze agepabscars has reached the bronze agepabscars has reached the bronze agepabscars has reached the bronze agepabscars has reached the bronze agepabscars has reached the bronze agepabscars has reached the bronze agepabscars has reached the bronze agepabscars has reached the bronze agepabscars has reached the bronze agepabscars has reached the bronze agepabscars has reached the bronze agepabscars has reached the bronze agepabscars has reached the bronze agepabscars has reached the bronze agepabscars has reached the bronze agepabscars has reached the bronze age
Re: DOS ATTACK,should I be worried

Quote:
Originally Posted by webcrawler2050 View Post
213.199.144.0

Code:
netname: MSFT-IDC
org: ORG-MA42-RIPE
descr: Microsoft London Internet Data Center
descr: Distribution of Microsoft content
descr: London
country: GB
admin-c: CXN-RIPE
tech-c: CXN-RIPE
status: ASSIGNED PA
mnt-by: MICROSOFT-MAINT
mnt-domains: MICROSOFT-MAINT
source: RIPE # Filtered

organisation: ORG-MA42-RIPE
org-name: Microsoft Limited
org-type: LIR
address: Microsoft
Allie Settlemyre
One Microsoft Way
WA 98052 Redmond
UNITED STATES
phone: +1 (425) 705 0516
fax-no: +1 425 936 7329
e-mail: [Who Is Domain][trace][Reverse DNS Search]
admin-c: AS9763-RIPE
admin-c: BR329-ARIN
admin-c: EN603-RIPE
mnt-ref: MICROSOFT-MAINT
mnt-ref: RIPE-NCC-HM-MNT
mnt-by: RIPE-NCC-HM-MNT
source: RIPE # Filtered

person: Christian Nielsen
address: One Microsoft Way
address: Redmond, WA 98052
address: US
phone: +1 (425) 706 1083
nic-hdl: CXN-RIPE
source: RIPE # Filtered

% Information related to '213.199.144.0[Who Is IP][trace][Reverse IP Search]/20AS8068'

route: 213.199.144.0/20
descr: Microsoft European IDCs
origin: AS8068
mnt-by: MICROSOFT-MAINT
source: RIPE # Filtered
AS NUMBER: AS8068 = MICROSOFTEU Microsoft European Data Center

Ripe: http://www.db.ripe.net/whois?object_...rchtext=AS8068

http://www.microsoft.com/emea/pressc...PR_240909.mspx

More info:

IP address country: ip address flag United Kingdom
IP address state: London, City of
IP address city: London
IP address latitude: 51.5000
IP address longitude: -0.1167
ISP of this IP [?]: Microsoft
Organization: Microsoft London Internet Data Center
Local time in United Kingdom: 2009-10-22 12:51

Very likely to be MSN / Windows updates - I think - I do believe they have transit in Telehouse


121.14.229.199


Code:
netname: HENGXIN-COMPANY
descr: Shantou Hengxin Techonlogy Co.,Ltd
country: CN
admin-c: ST-AP
tech-c: IC83-AP
mnt-by: MAINT-CHINANET-GD
changed: [Who Is Domain][trace][Reverse DNS Search] 20090122
status: Allocated non-portable
source: APNIC
AS NUMBER: AS4134 role: Asia Pacific Network Information Centre
address: APNIC, see http://www.apnic.net


RIPE: http://www.db.ripe.net/whois?form_ty..._search=Search

CONTACT: helpdesk@apnic.net

Should help
Sorry to be a numb nuts but this doesn't mean much to me, are you saying you don't think its anything malicious.
pabscars is offline   Reply With Quote
Old 22-10-2009, 13:05   #28
webcrawler2050
Inactive
 
Join Date: Feb 2008
Location: Swindon
Services: TiVo 110MB BB Phone Line
Posts: 3,087
webcrawler2050 has reached the bronze age
webcrawler2050 has reached the bronze agewebcrawler2050 has reached the bronze agewebcrawler2050 has reached the bronze agewebcrawler2050 has reached the bronze agewebcrawler2050 has reached the bronze agewebcrawler2050 has reached the bronze agewebcrawler2050 has reached the bronze age
Send a message via MSN to webcrawler2050
Re: DOS ATTACK,should I be worried

Im saying the first one could be MSN / Windows updates etc.

I think the second one, could be anything a very possible DDOS attack..
webcrawler2050 is offline   Reply With Quote
Old 22-10-2009, 13:05   #29
danielf
cf.mega poser
 
danielf's Avatar
 
Join Date: Jun 2003
Posts: 16,687
danielf has a golden auradanielf has a golden auradanielf has a golden aura
danielf has a golden auradanielf has a golden auradanielf has a golden auradanielf has a golden auradanielf has a golden auradanielf has a golden auradanielf has a golden auradanielf has a golden auradanielf has a golden auradanielf has a golden auradanielf has a golden auradanielf has a golden auradanielf has a golden auradanielf has a golden auradanielf has a golden aura
Re: DOS ATTACK,should I be worried

Quote:
Originally Posted by pabscars View Post
Sorry to be a numb nuts but this doesn't mean much to me, are you saying you don't think its anything malicious.
It looks like the 'DOS attack' you experienced originated from Microsoft, which would suggest it was not a DOS attack, but you received a number of hits for some other reason.

What is the reason you suspected a DOS attack?
__________________
Remember kids: We are blessed with a listening, caring government.
danielf is offline   Reply With Quote
Old 22-10-2009, 13:10   #30
pabscars
Inactive
 
Join Date: Oct 2008
Location: warrington
Age: 53
Services: TiVo, 75 Smeg Broadband
Posts: 2,199
pabscars has reached the bronze age
pabscars has reached the bronze agepabscars has reached the bronze agepabscars has reached the bronze agepabscars has reached the bronze agepabscars has reached the bronze agepabscars has reached the bronze agepabscars has reached the bronze agepabscars has reached the bronze agepabscars has reached the bronze agepabscars has reached the bronze agepabscars has reached the bronze agepabscars has reached the bronze agepabscars has reached the bronze agepabscars has reached the bronze agepabscars has reached the bronze agepabscars has reached the bronze agepabscars has reached the bronze age
Re: DOS ATTACK,should I be worried

Quote:
Originally Posted by danielf View Post
It looks like the 'DOS attack' you experienced originated from Microsoft, which would suggest it was not a DOS attack, but you received a number of hits for some other reason.

What is the reason you suspected a DOS attack?
Purely because it says so in the router logs
pabscars is offline   Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT +1. The time now is 02:35.


Server: osmium.zmnt.uk
Powered by vBulletin® Version 3.8.11
Copyright ©2000 - 2025, vBulletin Solutions Inc.
All Posts and Content are © Cable Forum