We’d like to remind Forumites to please avoid political debate on the Forum.

This is to keep it a safe and useful space for MoneySaving discussions. Threads that are – or become – political in nature may be removed in line with the Forum’s rules. Thank you for your understanding.

📨 Have you signed up to the Forum's new Email Digest yet? Get a selection of trending threads sent straight to your inbox daily, weekly or monthly!

kernel: Intrusion->[SYN]

Jaffa.
Jaffa. Posts: 1,193 Forumite
My internet just went down for about 10 seconds so I thought I would have a look in the routers log to see what happened... I have about 30 entries saying:
kernel: Intrusion->[SYN]IN=ppp_0_0_38_1 OUT= MAC= SRC=212.116.68.118 DST=92.2.21.79 LEN=64 TOS=0x00 PREC=0x00 TTL=53 ID=26580 DF PROTO=TCP SPT=50564 DPT=30577 WINDOW=65535 RES=0x00 SYN URGP=0

What the hell :mad: this is a dos attack right? What does all the other stuff mean like LEN?

Comments

  • [Deleted User]
    [Deleted User] Posts: 0 Newbie
    Part of the Furniture 1,000 Posts Name Dropper Combo Breaker
    edited 27 April 2009 at 4:58PM
    These might help:

    http://www.skyuser.co.uk/forum/sky-router/20360-router-intrusion.html
    http://www.skyuser.co.uk/forum/sky-broadband-help/23976-adsl-link-down.html
    http://broadbandforum.in/bsnl-broadband/38328-frequently-loosing-adsl-link/

    If I were you I'd reset the router, update the firmware, setup / change the WPA password then finally change the defaul admin password for the router's logon page.
  • Duk
    Duk Posts: 117 Forumite
    Part of the Furniture 10 Posts Combo Breaker
    Is theory a DDOS attack is just a bunch of SYN requests to a host without an ACK being sent back. But if its only 30 log entries i wouldnt worry, a usual DDOS attack will send tens of thousands of SYN requests.

    No doubt this is prob just your router mistaking something. I wouldnt worry about it.
  • Jaffa.
    Jaffa. Posts: 1,193 Forumite
    Thanks for them links, the last one didnt work though :( So basically it attempted, but didn't succeed. Blocked it, still the internet went down...

    The routers got a random WPA2 password and admin password anyway, firmware is all up-to-date. Theres some that say kernel: Intrusion->[PING] too...
  • fwor
    fwor Posts: 6,872 Forumite
    Part of the Furniture 1,000 Posts Name Dropper
    It's true that 30 entries seems too low for a DDOS attempt, unless the router fell over and was rebooting while the rest came in. It does seem to have some of the indications of a SYN attack - the source and destination ports seem to have been chosen at random and don't correspond to any well-known services.

    The other stuff is just describing the parameters of the packet, such as its LENgth, source and destination ports, etc. None of it is particularly useful - one of the characteristics of a SYN attack is that the source IP is always faked, so you've no way of knowing where it came from.

    If you're not on a static IP address, it may be worth forcing a different IP address. How you do that appears to vary from ISP to ISP, but turning off your router overnight will often do it.

    If you're on a static IP address and you keep getting similar outages you may need to contact your ISP to get it changed.
  • Jaffa.
    Jaffa. Posts: 1,193 Forumite
    edited 27 April 2009 at 5:24PM
    No my ip address is non static and it's now changed (turning the router on and off seems to have done the trick)

    I guess this is good as any to ask this. In the router theres a Firewall setting and theres loads of options to tick:

    Enable DOS and Portscan Protection :
    SYN attack : FIN/URG/PSH attack :
    Ping Attack : Xmas Tree attack :
    TCP reset attack :
    Null scanning attack :
    Ping of Death attack :
    SYN/RST SYN/FIN attack :

    They should all be ticked right? Or does ticking them make an exception to the rule because without the top one ticked you can't tick any of the others...

    The routers a Dlink DSL-2640B
  • Duk
    Duk Posts: 117 Forumite
    Part of the Furniture 10 Posts Combo Breaker
    It could be something as simple as your ISP changing your DHCP lease, that would also explain why your internet went down.
  • GunJack
    GunJack Posts: 11,864 Forumite
    Part of the Furniture 10,000 Posts Name Dropper Photogenic
    I've got a 2640, good little router...switch your firewall on and tick SYN attack protection, should stop it happening again :)
    ......Gettin' There, Wherever There is......

    I have a dodgy "i" key, so ignore spelling errors due to "i" issues, ...I blame Apple :D
This discussion has been closed.
Meet your Ambassadors

🚀 Getting Started

Hi new member!

Our Getting Started Guide will help you get the most out of the Forum

Categories

  • All Categories
  • 351.7K Banking & Borrowing
  • 253.4K Reduce Debt & Boost Income
  • 454K Spending & Discounts
  • 244.7K Work, Benefits & Business
  • 600.1K Mortgages, Homes & Bills
  • 177.3K Life & Family
  • 258.4K Travel & Transport
  • 1.5M Hobbies & Leisure
  • 16.2K Discuss & Feedback
  • 37.6K Read-Only Boards

Is this how you want to be seen?

We see you are using a default avatar. It takes only a few seconds to pick a picture.