Argonath RPG - A World of its own

Argonath RPG Community => Hardware/Software support => Resolved issues => Topic started by: ROFLCopter on November 12, 2010, 03:36:17 pm

Title: SYN Flooding/Port scanning
Post by: ROFLCopter on November 12, 2010, 03:36:17 pm
hi.

I've spotted on my firewall that I've been having people portscanning and SYN Flooding me.

DescriptionCountLast OccurenceTargetSource
SYN Flood
1
Fri Nov 12 02:06:07 2010    58.165.167.91:50122 192.168.0.2:59186
Illegal TCP header
9
Fri Nov 12 02:06:58 2010    192.168.0.2:0 85.224.59.32:0
SYN Flood
1
Fri Nov 12 02:07:00 2010    94.59.203.176:65440 192.168.0.2:59186
Illegal TCP header
3
Fri Nov 12 02:07:02 2010    192.168.0.2:0 85.224.59.32:0
SYN Flood
1
Fri Nov 12 02:07:09 2010    88.109.59.159:29794 192.168.0.2:59186
Illegal TCP header
3
Fri Nov 12 02:07:12 2010    192.168.0.2:0 85.224.59.32:0
SYN Flood
1
Fri Nov 12 02:07:17 2010    59.93.242.23:47131 192.168.0.2:59186
Illegal TCP header
15
Fri Nov 12 02:08:22 2010    192.168.0.2:0 85.224.59.32:0
SYN Flood
6
Fri Nov 12 02:08:51 2010    122.169.45.88:1186 192.168.0.2:59186
Illegal TCP header
6
Fri Nov 12 02:09:21 2010    192.168.0.2:0 85.224.59.32:0
SYN Flood
1
Fri Nov 12 02:09:24 2010    67.177.105.143:33864 192.168.0.2:59186
Illegal TCP header
3
Fri Nov 12 02:09:33 2010    192.168.0.2:0 85.224.59.32:0
SYN Flood
1
Fri Nov 12 02:09:34 2010    93.137.11.37:59593 192.168.0.2:59186
Illegal TCP header
2
Fri Nov 12 02:09:59 2010    192.168.0.2:0 85.224.59.32:0
SYN Flood
1
Fri Nov 12 02:10:01 2010    68.149.51.33:59140 192.168.0.2:59186
Illegal TCP header
5
Fri Nov 12 02:10:12 2010    192.168.0.2:0 85.224.59.32:0
SYN Flood
2
Fri Nov 12 02:10:19 2010    81.245.237.141:53516 192.168.0.2:59186
Illegal TCP header
2
Fri Nov 12 02:10:27 2010    192.168.0.2:0 85.224.59.32:0
SYN Flood
1
Fri Nov 12 02:10:28 2010    121.214.48.165:57942 192.168.0.2:59186
Illegal TCP header
5
Fri Nov 12 02:10:41 2010    192.168.0.2:0 85.224.59.32:0
SYN Flood
1
Fri Nov 12 02:10:43 2010    81.105.229.199:63665 192.168.0.2:59186
Illegal TCP header
14
Fri Nov 12 02:12:15 2010    192.168.0.2:0 85.224.59.32:0
SYN Flood
1
Fri Nov 12 02:12:16 2010    192.168.0.2:59186 75.64.255.161:52871
Illegal TCP header
7
Fri Nov 12 02:13:11 2010    192.168.0.2:0 85.224.59.32:0
IP packet w/MC or BC SRC addr
1
Fri Nov 12 02:13:20 2010    192.168.0.2:59186 89.241.215.255:28291
Illegal TCP header
12
Fri Nov 12 02:14:21 2010    192.168.0.2:0 85.224.59.32:0
SYN Flood
2
Fri Nov 12 02:14:51 2010    96.249.234.224:57187 192.168.0.2:59186
Illegal TCP header
2
Fri Nov 12 02:14:53 2010    192.168.0.2:0 85.224.59.32:0
SYN Flood
19
Fri Nov 12 02:17:38 2010    192.168.0.2:59186 78.101.18.175:59568
TCP- or UDP-based Port Scan
2
Fri Nov 12 14:31:18 2010    94.175.31.126:56780 194.168.4.100:53

Only lately the attacks have slown down my internet connection. halpzor (Target and Source IP's are mixed around in some tables, don't know why.)
Title: Re: SYN Flooding/Port scanning
Post by: jdixo17 on November 15, 2010, 02:20:48 pm
Your router should have protection against these things.
Title: Re: SYN Flooding/Port scanning
Post by: DellStorm on November 22, 2010, 05:08:55 am
Hi ROFLCopter,


Two Suggestions For You.


As Suggested your router should already be capable of eliminating the problem so I would not worry about it, they should just get timeout errors anyway.


Are you sure it is not coming from your home network? it appears that they are all coming from the same addresses, have a look and see where it is coming from. If its coming from the same country as yourself (check google for ip lookup) then it could be a friend or a member of your house ! make sure you check up.


Generally there should be no slow down, If you do find there is a small slow down, I would not worry, just every other day, reset your router and you will not notice the difference.


Attacks usually happen daily, but if you think about it, I cannot see them knocking on your door in a months time!


Hope that helps


Happy Gaming


Regards,


DellStorm
SimplePortal 2.3.7 © 2008-2025, SimplePortal