Moor3z Posted April 30, 2019 Share Posted April 30, 2019 I've had a guy message me a few days saying 'rip your internet' then I found these logs. Any suggestions on how to stop this? [DoS Attack: RST Scan] from source: 188.121.36.237, port 80, Tuesday, April 30, 2019 12:49:51 [DumaOS] DHCP lease change., Tuesday, April 30, 2019 12:08:44 [DumaOS] DHCP new event., Tuesday, April 30, 2019 12:08:44 [DHCP IP: 192.168.1.16] to MAC address 84:c0:ef:4d:99:87, Tuesday, April 30, 2019 12:08:44 [DoS Attack: SYN/ACK Scan] from source: 142.44.143.238, port 25565, Tuesday, April 30, 2019 11:44:04 [DoS Attack: SYN/ACK Scan] from source: 118.180.56.231, port 80, Tuesday, April 30, 2019 10:49:35 [DoS Attack: SYN/ACK Scan] from source: 42.81.4.99, port 80, Tuesday, April 30, 2019 10:48:23 [DumaOS] Cloudsync Themes result 'false','All mirrors are down', Tuesday, April 30, 2019 10:35:27 [DoS Attack: RST Scan] from source: 188.121.36.237, port 80, Tuesday, April 30, 2019 09:03:39 [DumaOS] config write 'com.netdumasoftware.devicemanager.database', Tuesday, April 30, 2019 09:03:08 [DumaOS] DHCP lease change., Tuesday, April 30, 2019 09:03:08 [DumaOS] DHCP new event., Tuesday, April 30, 2019 09:03:08 [DHCP IP: 192.168.1.2] to MAC address 48:6d:bb:65:7b:31, Tuesday, April 30, 2019 09:03:08 [DumaOS] config write 'com.netdumasoftware.devicemanager.database', Tuesday, April 30, 2019 09:02:16 [DumaOS] DHCP lease change., Tuesday, April 30, 2019 09:01:50 [DumaOS] DHCP new event., Tuesday, April 30, 2019 09:01:50 [DHCP IP: 192.168.1.4] to MAC address f0:6e:0b:47:eb:e5, Tuesday, April 30, 2019 09:01:50 [DoS Attack: SYN/ACK Scan] from source: 120.55.31.87, port 80, Tuesday, April 30, 2019 08:57:13 [DoS Attack: SYN/ACK Scan] from source: 107.149.247.178, port 80, Tuesday, April 30, 2019 08:54:16 [DoS Attack: SYN/ACK Scan] from source: 203.107.43.194, port 1321, Tuesday, April 30, 2019 08:18:24 [DoS Attack: SYN/ACK Scan] from source: 103.9.177.49, port 80, Tuesday, April 30, 2019 08:04:07 [DumaOS] DHCP lease change., Tuesday, April 30, 2019 07:52:37 [DumaOS] DHCP new event., Tuesday, April 30, 2019 07:52:37 [DHCP IP: 192.168.1.6] to MAC address a0:c9:a0:f9:38:9e, Tuesday, April 30, 2019 07:52:37 [DumaOS] DHCP lease change., Tuesday, April 30, 2019 07:52:36 [DumaOS] DHCP new event., Tuesday, April 30, 2019 07:52:36 [DHCP IP: 192.168.1.6] to MAC address a0:c9:a0:f9:38:9e, Tuesday, April 30, 2019 07:52:36 [DoS Attack: SYN/ACK Scan] from source: 103.9.177.49, port 80, Tuesday, April 30, 2019 07:45:20 [DoS Attack: ACK Scan] from source: 157.240.1.54, port 443, Tuesday, April 30, 2019 07:36:55 [DoS Attack: ACK Scan] from source: 157.240.1.54, port 443, Tuesday, April 30, 2019 07:34:52 [DoS Attack: ACK Scan] from source: 157.240.1.54, port 443, Tuesday, April 30, 2019 07:32:49 [DoS Attack: ACK Scan] from source: 157.240.1.54, port 443, Tuesday, April 30, 2019 07:30:46 [DoS Attack: ACK Scan] from source: 157.240.1.54, port 443, Tuesday, April 30, 2019 07:28:43 [DoS Attack: ACK Scan] from source: 157.240.1.54, port 443, Tuesday, April 30, 2019 07:26:40 [DoS Attack: ACK Scan] from source: 157.240.1.54, port 443, Tuesday, April 30, 2019 07:24:37 [DoS Attack: ACK Scan] from source: 157.240.1.54, port 443, Tuesday, April 30, 2019 07:23:11 [DoS Attack: SYN/ACK Scan] from source: 103.9.177.49, port 80, Tuesday, April 30, 2019 07:18:15 [DoS Attack: SYN/ACK Scan] from source: 192.151.231.137, port 80, Tuesday, April 30, 2019 07:14:08 [DoS Attack: RST Scan] from source: 85.10.206.164, port 999, Tuesday, April 30, 2019 07:01:04 [DoS Attack: TCP/UDP Chargen] from source: 71.6.232.5, port 57018, Tuesday, April 30, 2019 06:55:13 There's a lot more this started on the 3rd April. Link to comment Share on other sites More sharing options...
pollutionblues Posted April 30, 2019 Share Posted April 30, 2019 Don’t panic, It’s nothing to worry about, those logs are perfectly normal, it’s just the router doing its job. The logs are only for the developers and are verbose. Link to comment Share on other sites More sharing options...
Administrators Netduma Fraser Posted April 30, 2019 Administrators Share Posted April 30, 2019 Hey, welcome to the forum! Exactly as above, nothing to worry about. Have you actually had any issues with your internet? You would certainly know about it if they did something because you wouldn't be able to get a connection at all. They're just trying to intimidate you. Link to comment Share on other sites More sharing options...
Guest Killhippie Posted May 2, 2019 Share Posted May 2, 2019 On 4/30/2019 at 6:37 PM, Netduma Fraser said: Hey, welcome to the forum! Exactly as above, nothing to worry about. Have you actually had any issues with your internet? You would certainly know about it if they did something because you wouldn't be able to get a connection at all. They're just trying to intimidate you. Fraser is spot on, most are just internet traffic and Netgears firewall labels them as DoS attacks I had a WinNuke this morning, which is for windows 95! Also pure intimidation, just ignore the logs and the author of that threat. Link to comment Share on other sites More sharing options...
Recommended Posts
Archived
This topic is now archived and is closed to further replies.