School Assignment? Project Due Tomorrow? Chat LIVE With A Programming Expert!

Welcome to Dream.In.Code
Become an Expert!

Join 300,475 Programmers for FREE! Get instant access to thousands of experts, tutorials, code snippets, and more! There are 1,740 people online right now. Registration is fast and FREE... Join Now!




DoS attack?

 

DoS attack?

D1gitalIce

11 Nov, 2008 - 08:57 AM
Post #1

New D.I.C Head
*

Joined: 29 Oct, 2008
Posts: 20

I took a look at my routers security log last night, and it was littered with this:

Tue Nov 11 10:37:57 2008 1 Blocked by DoS protection 76.35.112.1
Tue Nov 11 10:37:57 2008 1 Blocked by DoS protection 76.35.112.1
Tue Nov 11 10:38:16 2008 1 Blocked by DoS protection 76.35.112.1
Tue Nov 11 10:38:16 2008 1 Blocked by DoS protection 76.35.112.1
Tue Nov 11 10:38:35 2008 1 Blocked by DoS protection 76.35.112.1
Tue Nov 11 10:38:35 2008 1 Blocked by DoS protection 76.35.112.1

I do not know how long this has been going on, but I have been watching it happen for a good 16 hours now... Thousands of these entries are made in the logs.

My internet connection has not slowed down, or at least not that I can notice. I did visit an old IRC channel with people I used to know way back when just yesterday, however I cannot identify that as the source of this. Is this just random internet clutter hitting my Belkin router? Or a small DoS attempt from a single ip?

Thanks

User is offlineProfile CardPM
+Quote Post


jjsaw5

RE: DoS Attack?

11 Nov, 2008 - 09:27 AM
Post #2

I must break you
Group Icon

Joined: 4 Jan, 2008
Posts: 2,656



Thanked: 25 times
Dream Kudos: 125
My Contributions
It could be a DOS attack. But I don’t think you will be able to track it to one single IP address. Usually when people do things like this they have hacked into other people computer and then use their machines to attack yours. So it makes tracking the original IP address pretty hard.

It appears from you log that you have some kind of protection against this. I would keep an eye on it and maybe check out what you can do about it if it really is a denial of service attack. FBI has a cyber crime division and I would check with your local law enforcement or do some research on the internet about what you can do.

Are you running some kind of site that these people would be interested in taking down? A lot of time they try to bring your site down and then they tell you that they will stop the attacks for money or something like that. Just wondering if that could be the reason.

User is offlineProfile CardPM
+Quote Post

D1gitalIce

RE: DoS Attack?

11 Nov, 2008 - 09:46 AM
Post #3

New D.I.C Head
*

Joined: 29 Oct, 2008
Posts: 20

No, I don't operate a website. This my home network.

The IRC channel I visited was on the star-fleet network, the channel consisted of maybe 5 or 6 people, 3 of which I used to help "fix" roms for NES and N64 emulation years ago (like 8 or 9 years ago). I did not really say anything to provoke any of them, just general chat, catching up on things. Out of the 6, only 2 where actually active in the channel. I did a whois on myself and found my IP to be visible so I did a whois on the person who runs the channel to see if it was visible for everyone (me being paranoid did not want to get into the mess that I am possibly in now).

This also could just be some random computer zoning in on my connection. The trace route results say that there are no hops between my network and that IP. A search on the general IP info points to Road Runner in VA. Further lookups revealed the source location to be from just outside of Wichita, KS.

I have always understood a real DoS attack to completely bring down an internet connection, and that instead of 3-6 hits per minute that it would be hundreds per minute. I won't dismiss the idea of it being a real one, but I am looking for confirmation whether it is or not.

This post has been edited by D1gitalIce: 11 Nov, 2008 - 09:53 AM
User is offlineProfile CardPM
+Quote Post

D1gitalIce

RE: DoS Attack?

11 Nov, 2008 - 12:06 PM
Post #4

New D.I.C Head
*

Joined: 29 Oct, 2008
Posts: 20

Rates are increasing. Went from 4-5 per minute to about 10 - 15 per minute. At this point I am helpless, since my ISP assigns static IP addresses. Web sites are running slower as well.
User is offlineProfile CardPM
+Quote Post

no2pencil

RE: DoS Attack?

11 Nov, 2008 - 12:09 PM
Post #5

i R L33t Skiddie, k?
Group Icon

Joined: 10 May, 2007
Posts: 13,234



Thanked: 289 times
Dream Kudos: 2875
Expert In: Goofing Off

My Contributions
You may want to contact your ISP. Just being on IRC will expose your address, & this was probably not provoked by anyone in that specific chat room.
User is online!Profile CardPM
+Quote Post

baavgai

RE: DoS Attack?

11 Nov, 2008 - 12:38 PM
Post #6

Dreaming Coder
Group Icon

Joined: 16 Oct, 2007
Posts: 4,261



Thanked: 389 times
Dream Kudos: 550
Expert In: C, C++, Java, C#, ASP.NET, PHP, Perl, Python, Oracle, SQL Server, MySql, HTML, JavaScript, Lua, Cheese

My Contributions
QUOTE(jjsaw5 @ 11 Nov, 2008 - 11:27 AM) *

Usually when people do things like this they have hacked into other people computer and then use their machines to attack yours.


Zombie nets are bad. And the most common method of hurting the big guys.

However, DoS attacks can come from a single point with little fear of exposure. MAC, IP source and destination are easily spoofed. So, I send you a crap packet. You SYN/ACK back to either a non existent computer or someone who's never heard of you. That other guy will send you a WTF ACK, so you actually get traffic from complete random strangers. Or you wait the ACK that will never come, which is probably worse.

This, boys and girls, it why IPv6 is a "good thing." tongue.gif Of course, it will cost billions to get it working universally, so don't hold your breath.

User is offlineProfile CardPM
+Quote Post

Hary

RE: DoS Attack?

12 Nov, 2008 - 12:31 PM
Post #7

D.I.C Regular
Group Icon

Joined: 23 Sep, 2008
Posts: 411



Thanked: 40 times
My Contributions
Hm, .1 is normally a router, probably your ISP's router is sending some packets your router does not understand and the "look-i-m-amazing" DoS protection wants to show it exists? Is the IP address in your IP range?
User is offlineProfile CardPM
+Quote Post

computer112

RE: DoS Attack?

16 Nov, 2008 - 05:09 PM
Post #8

New D.I.C Head
*

Joined: 16 Nov, 2008
Posts: 1

Simply the Dos Protection software was faking your own network!
76.35.112.1 is your current IP address.

(I checked and reattack again! It's fine), may be the incoming packets from the local ISP were blocked by your firewall or proxy.

Check the network log file again, because the intruder was simple target your network like this. If you are affair something gonna happen to your network, then contact with your network admin!

Good luck!
User is offlineProfile CardPM
+Quote Post

Reply to this topicStart new topic

Time is now: 11/8/09 03:28AM

Live Help!

Be Social

Dream.In.Code RSS Feed Dream.In.Code LinkedIn Group Follow Us On Twitter Fan Us On Facebook

Tutorials

Programming

Web Development

Reference Sheets

Code Snippets

DIC Chatroom

Bye Bye Ads

Monthly Drawing

Thumb Drive

Top Contributors

Top 10 Kudos This Month