I'm being constantly DoS attacked, my router manages to block most of it but sometimes the odd one gets through and knocks me off the net/FFXI, I know the IP it's coming from.
Is there a way to fsck them up/block them?
Thanks in advance.
I'm being constantly DoS attacked, my router manages to block most of it but sometimes the odd one gets through and knocks me off the net/FFXI, I know the IP it's coming from.
Is there a way to fsck them up/block them?
Thanks in advance.
Make a rule in the router to drop or reject packets from said IP maybe, im not too router savvy ; ;
Here's a sample of the log, it goes on like this from 8am this morning.
Firewall log:
Thu May 3 15:47:50 2007 1 Blocked by DoS protection 10.24.64.1
Thu May 3 15:47:50 2007 1 Blocked by DoS protection 10.24.64.1
Thu May 3 15:47:52 2007 1 Blocked by DoS protection 10.24.64.1
Thu May 3 15:47:52 2007 1 Blocked by DoS protection 10.24.64.1
Thu May 3 15:47:52 2007 1 Blocked by DoS protection 10.24.64.1
Thu May 3 15:47:53 2007 1 Blocked by DoS protection 10.24.64.1
Thu May 3 15:47:55 2007 1 Blocked by DoS protection 10.24.64.1
Thu May 3 15:47:57 2007 1 Blocked by DoS protection 10.24.64.1
Thu May 3 15:47:59 2007 1 Blocked by DoS protection 10.24.64.1
Thu May 3 15:48:05 2007 1 Blocked by DoS protection 10.24.64.1
Thu May 3 15:48:07 2007 1 Blocked by DoS protection 10.24.64.1
Thu May 3 15:48:08 2007 1 Blocked by DoS protection 10.24.64.1
Thu May 3 15:48:09 2007 1 Blocked by DoS protection 10.24.64.1
Thu May 3 15:48:10 2007 1 Blocked by DoS protection 10.24.64.1
Thu May 3 15:48:10 2007 1 Blocked by DoS protection 10.24.64.1
Thu May 3 15:48:12 2007 1 Blocked by DoS protection 10.24.64.1
Thu May 3 15:48:15 2007 1 Blocked by DoS protection 10.24.64.1
Thu May 3 15:48:23 2007 1 Blocked by DoS protection 10.24.64.1
Thu May 3 15:48:23 2007 1 Blocked by DoS protection 10.24.64.1
Thu May 3 15:48:24 2007 1 Blocked by DoS protection 10.24.64.1
Thu May 3 15:48:24 2007 1 Blocked by DoS protection 10.24.64.1
Thu May 3 15:48:31 2007 1 Blocked by DoS protection 10.24.64.1
Thu May 3 15:48:33 2007 1 Blocked by DoS protection 10.24.64.1
Thu May 3 15:48:36 2007 1 Blocked by DoS protection 10.24.64.1
Thu May 3 15:48:38 2007 1 Blocked by DoS protection 10.24.64.1
Thu May 3 15:48:38 2007 1 Blocked by DoS protection 10.24.64.1
Thu May 3 15:48:39 2007 1 Blocked by DoS protection 10.24.64.1
Thu May 3 15:48:40 2007 1 Blocked by DoS protection 10.24.64.1
Thu May 3 15:48:41 2007 1 Blocked by DoS protection 10.24.64.1
Thu May 3 15:48:43 2007 1 Blocked by DoS protection 10.24.64.1
Thu May 3 15:48:45 2007 1 Blocked by DoS protection 10.24.64.1
Thu May 3 15:48:45 2007 1 Blocked by DoS protection 10.24.64.1
10.*.*.* is designated for private use ... is it a computer on your LAN?
I've only got one other computer on my network, that's my Mothers and this started before she came back from Holiday a few days ago. Certain it's not her computer. The only other thing I have hooked up to wireless is my Wii.Originally Posted by Ichthyos
Check the router client table to make sure it's not an IP in use on your LAN. Assuming it's not, the packets' source IP is spoofed. Make a rule on your router's firewall to drop any inbound packets from 10.* (because the addresses don't exist on the public network), and then call your ISP to report a DoS with spoofed packets. If they really want to, they can log in to their routers and trace the packets as long as the attack is ongoing.
Well it's been going on for a month or so now, non stop, thankfully my router firewall is really good and it's only knocked me off a handful of times. I'm looking around on how to drop packets but I can't see where to input that lol, have to search a bit more.Originally Posted by Ichthyos
Oh, and another thing you might ask them to do is to just give you a new IP address.
Ok, just got another one from a different IP. 221.12.113.246 Halp?
Right ok..getting about 6 different ones now, wtf @_@
Any given ip address is being attacked by thousands of computers at the same time.
The rest of us deal with it just fine.
This, I did not know. D:Originally Posted by Devek
So..there's no way to stop it and I just have to put up with it when I get knocked off?
Call your ISP and ask for a new IP if it's affecting your connectivity. Tell them how long it's been going on and give them some source IPs (to show that you've put in effort to solve the problem yourself). There's not much else you can do.
use tracert and ARIN whois to trace the IP source. Even if it's being spoofed or going through a proxy, you can still trace it back to the source(most people use only basic scripts and don't really know what they are doing). When you do so, contact your ISP's abuse group (Earthlink's address for reporting such things is mailto:[email protected] btw) and the source ISP for the IP spamming you. Usually this stops the problem, especially since an ISP does NOT want the negative PR!
Try a different router until you find one that doesn't freak out. As long as the attacks are not taking up so much bandwidth that you can't do anything else there isn't anything to worry about.
It isn't a dlink, linksys, etc issue.. various models from the same manufactures are 100% different. Find a specific model that is good/stable and stick with it.
Oh ya, and to the guy who posted above me.. good luck crying to an ISP in China![]()
Gonna call them now. -_-;
Actually, I was lucky and the attack's source was coming from South Carolina on an Earthlink account. Needless to say, no more attacks ^_^
Ok..appears my attack is coming from the Internet Assigned Numbers Authority. Gonna email em and ask them what the fuck they think they're up to.
10.* is for private use. Read the comments in the WHOIS entry. The IANA isn't DoS'ing you--someone's spoofing the source address on the packets.
Selective reading ftw -_-;
Ohh well IP address getting changed so hopefully that'll fix it.