|
![]() |
Overclock.net - Overclocking.net > Software, Programming and Coding > Networking & Security | |
Constant firewall attacks?
|
||
![]() |
|
|
LinkBack | Thread Tools |
|
|
#1 (permalink) | ||||||||||||
|
News Fiend
|
I just set up my first wireless network yesterday, and the security log is unsettling. Is this normal to experience this many security logs under your firewall?
__________________I have my network secured under 128bit WEP, and MAC address filtering for the three computers being used on my network. I have a Belkin g+ MIMO Code:
Firewall log: Found Syncflood attack from 118.126.3.103 in port 1433 => Sat Aug 9 21:22:02 2008 Found Syncflood attack from 219.138.45.182 in port 5900 => Sat Aug 9 21:22:33 2008 Found Syncflood attack from 222.216.28.161 in port 2967 => Sat Aug 9 21:33:22 2008 Found PortScanner attack from 12.129.242.24 in port 3359 => Sat Aug 9 21:53:30 2008 Found PortScanner attack from 12.129.242.24 in port 3360 => Sat Aug 9 21:53:30 2008 Found PortScanner attack from 12.129.242.24 in port 3362 => Sat Aug 9 21:53:30 2008 Found Syncflood attack from 60.172.222.17 in port 8000 => Sat Aug 9 21:57:06 2008 Found Syncflood attack from 60.172.222.17 in port 1080 => Sat Aug 9 21:57:06 2008 Found Syncflood attack from 60.172.222.17 in port 8888 => Sat Aug 9 21:57:06 2008 Found Syncflood attack from 61.156.238.80 in port 2967 => Sat Aug 9 22:02:15 2008 Found Syncflood attack from 222.186.13.63 in port 1433 => Sat Aug 9 22:04:18 2008 Found Syncflood attack from 87.115.67.40 in port 23 => Sat Aug 9 22:29:06 2008 Found Syncflood attack from 213.8.154.250 in port 22 => Sat Aug 9 22:40:58 2008 Found Syncflood attack from 61.164.117.112 in port 2967 => Sat Aug 9 23:02:09 2008 Found Syncflood attack from 219.234.141.89 in port 2967 => Sat Aug 9 23:03:10 2008 Found Syncflood attack from 222.187.221.27 in port 7212 => Sat Aug 9 23:08:50 2008 Found Syncflood attack from 222.187.221.27 in port 8000 => Sat Aug 9 23:08:50 2008 Found Syncflood attack from 222.216.28.161 in port 2967 => Sat Aug 9 23:20:43 2008 Found PortScanner attack from 4.71.104.187 in port 2392 => Sun Aug 10 00:00:59 2008 Found Syncflood attack from 61.147.115.37 in port 2967 => Sun Aug 10 01:11:17 2008 Found Syncflood attack from 206.163.126.131 in port 110 => Sun Aug 10 01:11:47 2008 Found Syncflood attack from 222.216.28.161 in port 2967 => Sun Aug 10 01:14:52 2008 Found PingDeath attack from 211.148.159.42 in port ICMP => Sun Aug 10 02:14:36 2008 Found PingDeath attack from 211.148.159.42 in port ICMP => Sun Aug 10 02:15:06 2008 Found PingDeath attack from 218.217.112.150 in port ICMP => Sun Aug 10 02:43:00 2008 Found Syncflood attack from 222.216.28.161 in port 2967 => Sun Aug 10 03:00:03 2008 Found Syncflood attack from 222.187.221.27 in port 7212 => Sun Aug 10 03:35:11 2008 Found Syncflood attack from 222.187.221.27 in port 8000 => Sun Aug 10 03:35:41 2008 Found PingDeath attack from 24.80.186.91 in port ICMP => Sun Aug 10 03:37:44 2008 Found PingDeath attack from 24.80.186.91 in port ICMP => Sun Aug 10 03:38:14 2008 Found PortScanner attack from 76.9.1.164 in port 2588 => Sun Aug 10 03:41:50 2008 Found Syncflood attack from 60.172.222.17 in port 8080 => Sun Aug 10 04:33:31 2008 Found Syncflood attack from 60.172.222.17 in port 7788 => Sun Aug 10 04:33:31 2008 Found Syncflood attack from 60.172.222.17 in port 8118 => Sun Aug 10 04:33:31 2008 Found Syncflood attack from 60.172.222.17 in port 8081 => Sun Aug 10 04:33:31 2008 Found PingDeath attack from 71.86.100.90 in port ICMP => Sun Aug 10 04:47:28 2008 Found Syncflood attack from 222.216.28.161 in port 2967 => Sun Aug 10 04:48:29 2008 Found Syncflood attack from 222.186.13.63 in port 1433 => Sun Aug 10 05:23:37 2008 Found PingDeath attack from 122.118.205.127 in port ICMP => Sun Aug 10 05:52:33 2008 Found Syncflood attack from 222.187.105.220 in port 1433 => Sun Aug 10 05:55:07 2008 Found Syncflood attack from 125.65.112.172 in port 1433 => Sun Aug 10 06:09:04 2008 Found Syncflood attack from 222.216.28.161 in port 2967 => Sun Aug 10 06:36:27 2008 Found Syncflood attack from 88.114.145.205 in port 18072 => Sun Aug 10 07:35:08 2008 Found Syncflood attack from 60.172.222.17 in port 8080 => Sun Aug 10 07:51:09 2008 Found Syncflood attack from 60.172.222.17 in port 7788 => Sun Aug 10 07:51:09 2008 Found Syncflood attack from 60.172.222.17 in port 8118 => Sun Aug 10 07:51:09 2008 Found Syncflood attack from 60.172.222.17 in port 8081 => Sun Aug 10 07:51:09 2008 Found Syncflood attack from 93.124.106.78 in port 23 => Sun Aug 10 08:08:43 2008 Found Syncflood attack from 222.216.28.161 in port 2967 => Sun Aug 10 08:09:44 2008 Found Syncflood attack from 72.27.175.153 in port 23 => Sun Aug 10 08:18:30 2008 Found Syncflood attack from 123.18.102.205 in port 23 => Sun Aug 10 08:21:04 2008 Found Syncflood attack from 222.187.221.27 in port 7212 => Sun Aug 10 08:53:06 2008 Found Syncflood attack from 222.187.221.27 in port 8000 => Sun Aug 10 08:53:06 2008 Found Syncflood attack from 218.72.249.88 in port 2967 => Sun Aug 10 09:07:03 2008 Found PingDeath attack from 219.136.146.114 in port ICMP => Sun Aug 10 09:16:20 2008 Found PingDeath attack from 211.229.84.221 in port ICMP => Sun Aug 10 09:25:07 2008 Found PingDeath attack from 189.0.231.232 in port ICMP => Sun Aug 10 09:47:50 2008 Found Syncflood attack from 222.216.28.161 in port 2967 => Sun Aug 10 09:54:02 2008 Found PingDeath attack from 81.26.251.102 in port ICMP => Sun Aug 10 10:24:00 2008 Found Syncflood attack from 201.88.241.11 in port 18072 => Sun Aug 10 10:38:58 2008 Found Syncflood attack from 222.187.221.27 in port 7212 => Sun Aug 10 10:55:30 2008 Found Syncflood attack from 222.187.221.27 in port 8000 => Sun Aug 10 10:55:30 2008 Found Syncflood attack from 222.216.28.161 in port 2967 => Sun Aug 10 11:41:30 2008 Found PingDeath attack from 208.89.0.10 in port ICMP => Sun Aug 10 12:44:19 2008 Found Syncflood attack from 220.249.96.168 in port 2967 => Sun Aug 10 12:51:33 2008 Found PortScanner attack from 76.9.1.158 in port 3365 => Sun Aug 10 12:53:05 2008
|
||||||||||||
|
|
|
|
|
#2 (permalink) | |||||||||||
|
4.0ghz
![]() |
Don't worry about it. There's always somebody scanning your IP range
__________________![]() Here's mine: Code:
2008/08/10 19:22:57 : Blocked access attempt : UDP from 91.6.198.135:64261 to self:42683 2008/08/10 19:23:02 : Blocked access attempt : UDP from 98.200.113.184:5175 to self:42683 2008/08/10 19:23:06 : Blocked access attempt : UDP from 87.88.34.225:53872 to self:42683 2008/08/10 19:23:06 : Blocked access attempt : UDP from 77.178.0.51:63709 to self:42683 2008/08/10 19:23:09 : Blocked access attempt : UDP from 208.192.64.143:19943 to self:42683 2008/08/10 19:23:10 : Blocked access attempt : UDP from 91.121.160.159:47290 to self:42683 2008/08/10 19:23:13 : Blocked access attempt : UDP from 80.247.249.200:53745 to self:42683 2008/08/10 19:23:13 : Blocked access attempt : UDP from 213.37.125.173:12085 to self:42683 2008/08/10 19:23:19 : Blocked access attempt : UDP from 88.111.28.246:24380 to self:42683 2008/08/10 19:23:21 : Blocked access attempt : UDP from 82.236.14.81:53340 to self:42683 2008/08/10 19:23:26 : Blocked access attempt : UDP from 75.37.129.192:57240 to self:42683 2008/08/10 19:23:30 : Blocked access attempt : UDP from 41.203.226.138:10419 to self:42683 2008/08/10 19:23:34 : Blocked access attempt : UDP from 81.208.74.191:49140 to self:42683 2008/08/10 19:23:41 : Blocked access attempt : UDP from 213.22.5.176:54112 to self:42683 2008/08/10 19:23:48 : Blocked access attempt : UDP from 69.111.166.96:18477 to self:42683 2008/08/10 19:23:50 : Blocked access attempt : UDP from 80.128.170.174:62514 to self:42683 2008/08/10 19:23:54 : Blocked access attempt : UDP from 86.134.14.202:65184 to self:42683 2008/08/10 19:24:04 : Blocked access attempt : UDP from 88.160.77.124:54267 to self:42683 2008/08/10 19:24:04 : Blocked access attempt : UDP from 81.158.52.133:38123 to self:42683 2008/08/10 19:24:06 : Blocked access attempt : UDP from 81.225.169.60:34837 to self:42683 2008/08/10 19:24:19 : Blocked access attempt : UDP from 84.244.234.48:11164 to self:42683 2008/08/10 19:24:20 : Blocked access attempt : UDP from 124.104.11.231:49700 to self:42683 2008/08/10 19:24:22 : Blocked access attempt : UDP from 83.5.194.178:62733 to self:42683 2008/08/10 19:24:28 : Blocked access attempt : UDP from 70.249.149.204:14768 to self:42683 2008/08/10 19:24:35 : Blocked access attempt : UDP from 76.213.221.91:29117 to self:42683 2008/08/10 19:24:37 : Blocked access attempt : UDP from 72.91.22.14:33373 to self:42683 2008/08/10 19:24:43 : Blocked access attempt : UDP from 80.179.52.100:53 to self:3356 2008/08/10 19:24:43 : Blocked access attempt : UDP from 80.179.55.101:53 to self:3357 2008/08/10 19:24:43 : Blocked access attempt : UDP from 80.179.55.100:53 to self:3377 2008/08/10 19:24:44 : Blocked access attempt : UDP from 80.179.52.100:53 to self:3358 2008/08/10 19:24:44 : Blocked access attempt : UDP from 72.73.240.254:50850 to self:42683 2008/08/10 19:24:45 : Blocked access attempt : UDP from 80.180.25.17:61908 to self:42683 2008/08/10 19:24:47 : Blocked access attempt : UDP from 80.179.52.100:53 to self:3364 2008/08/10 19:24:50 : Blocked access attempt : UDP from 86.213.194.51:40941 to self:42683 2008/08/10 19:24:58 : Blocked access attempt : UDP from 91.172.240.108:22777 to self:42683 2008/08/10 19:25:03 : Blocked access attempt : UDP from 68.184.113.146:60495 to self:42683 2008/08/10 19:25:05 : Blocked access attempt : UDP from 217.36.214.219:6881 to self:42683 2008/08/10 19:25:12 : Blocked access attempt : UDP from 84.236.27.95:19639 to self:42683 2008/08/10 19:25:15 : Blocked access attempt : UDP from 190.72.207.199:58464 to self:42683 2008/08/10 19:25:18 : Blocked access attempt : UDP from 74.171.218.82:50773 to self:42683 2008/08/10 19:25:19 : Blocked access attempt : UDP from 64.237.144.110:10001 to self:42683 2008/08/10 19:25:23 : Blocked access attempt : UDP from 78.106.175.168:24245 to self:42683 2008/08/10 19:25:30 : Blocked access attempt : UDP from 65.6.139.131:55247 to self:42683 2008/08/10 19:25:39 : Blocked access attempt : UDP from 84.99.241.123:50403 to self:42683 2008/08/10 19:25:43 : Blocked access attempt : UDP from 79.114.225.10:61025 to self:42683 2008/08/10 19:25:49 : Blocked access attempt : UDP from 86.146.144.53:60804 to self:42683 2008/08/10 19:25:56 : Blocked access attempt : UDP from 190.244.19.124:27435 to self:42683 2008/08/10 19:25:57 : Blocked access attempt : UDP from 90.205.24.219:30721 to self:42683 2008/08/10 19:26:06 : Blocked access attempt : UDP from 122.166.145.99:46752 to self:42683 2008/08/10 19:26:14 : Blocked access attempt : UDP from 76.172.140.94:46580 to self:42683 2008/08/10 19:26:17 : Blocked access attempt : UDP from 213.158.196.80:44377 to self:42683 2008/08/10 19:26:18 : Blocked access attempt : UDP from 92.124.104.144:58047 to self:42683 2008/08/10 19:26:21 : Blocked access attempt : UDP from 89.2.241.154:39526 to self:42683 2008/08/10 19:26:23 : Blocked access attempt : UDP from 203.81.197.139:21661 to self:42683 2008/08/10 19:26:24 : Blocked access attempt : UDP from 91.150.165.7:61235 to self:42683 2008/08/10 19:26:25 : Blocked access attempt : UDP from 79.101.77.136:57144 to self:42683 2008/08/10 19:26:28 : Blocked access attempt : UDP from 85.243.208.227:59093 to self:42683 2008/08/10 19:26:28 : Blocked access attempt : UDP from 79.140.12.198:16467 to self:42683 2008/08/10 19:26:42 : Blocked access attempt : UDP from 151.50.57.70:37534 to self:42683 2008/08/10 19:26:44 : Blocked access attempt : UDP from 85.113.32.253:44518 to self:42683 2008/08/10 19:26:48 : Blocked access attempt : UDP from 189.63.195.62:29427 to self:42683 2008/08/10 19:26:48 : Blocked access attempt : TCP from 207.126.64.181:80 to self:1446 2008/08/10 19:26:51 : Blocked access attempt : UDP from 221.222.178.109:30672 to self:42683 2008/08/10 19:26:52 : Blocked access attempt : UDP from 82.5.2.24:46202 to self:42683 2008/08/10 19:26:54 : Blocked access attempt : TCP from 207.126.64.181:80 to self:1446 2008/08/10 19:26:55 : Blocked access attempt : UDP from 217.10.38.224:32376 to self:42683 2008/08/10 19:26:57 : Blocked access attempt : UDP from 221.222.178.109:30672 to self:42683 2008/08/10 19:27:00 : Blocked access attempt : UDP from 201.17.243.158:36763 to self:42683 2008/08/10 19:27:01 : Blocked access attempt : UDP from 24.84.200.77:37644 to self:42683 2008/08/10 19:27:04 : Blocked access attempt : UDP from 221.134.22.237:48733 to self:42683 2008/08/10 19:27:04 : Blocked access attempt : UDP from 83.50.214.181:38454 to self:42683 2008/08/10 19:27:06 : Blocked access attempt : TCP from 207.126.64.181:80 to self:1446 2008/08/10 19:27:07 : Blocked access attempt : UDP from 74.131.225.211:63893 to self:42683 2008/08/10 19:27:08 : Blocked access attempt : UDP from 80.99.137.179:63439 to self:42683 2008/08/10 19:27:12 : Blocked access attempt : UDP from 221.222.178.109:30672 to self:42683 2008/08/10 19:27:14 : Blocked access attempt : UDP from 91.111.62.253:17784 to self:42683 2008/08/10 19:27:15 : Blocked access attempt : UDP from 68.81.29.148:13392 to self:42683 2008/08/10 19:27:20 : Blocked access attempt : UDP from 217.41.29.136:61657 to self:42683 2008/08/10 19:27:21 : Blocked access attempt : UDP from 65.74.84.149:1331 to self:42683 2008/08/10 19:27:22 : Blocked access attempt : UDP from 80.179.52.100:53 to self:3392 2008/08/10 19:27:22 : Blocked access attempt : UDP from 80.179.55.100:53 to self:3393 2008/08/10 19:27:22 : Blocked access attempt : UDP from 221.222.178.109:30672 to self:42683 2008/08/10 19:27:22 : Blocked access attempt : UDP from 83.167.112.29:58776 to self:42683 2008/08/10 19:27:23 : Blocked access attempt : UDP from 80.179.52.100:53 to self:3396 2008/08/10 19:27:23 : Blocked access attempt : UDP from 80.179.55.100:53 to self:3397 2008/08/10 19:27:23 : Blocked access attempt : UDP from 202.63.103.230:57909 to self:42683 2008/08/10 19:27:24 : Blocked access attempt : UDP from 80.179.52.100:53 to self:3400 2008/08/10 19:27:24 : Blocked access attempt : UDP from 212.149.153.137:50492 to self:42683 2008/08/10 19:27:32 : Blocked access attempt : UDP from 88.222.197.17:31409 to self:42683 2008/08/10 19:27:32 : Blocked access attempt : UDP from 85.145.144.219:46607 to self:42683 2008/08/10 19:27:32 : Blocked access attempt : UDP from 88.161.124.165:19302 to self:42683 2008/08/10 19:27:46 : Blocked access attempt : UDP from 24.86.116.253:11815 to self:42683 2008/08/10 19:27:50 : Blocked access attempt : UDP from 76.168.104.24:47262 to self:42683 2008/08/10 19:27:58 : Blocked access attempt : UDP from 83.81.119.85:29130 to self:42683 2008/08/10 19:28:09 : Blocked access attempt : UDP from 219.68.144.50:25277 to self:42683 2008/08/10 19:28:15 : Blocked access attempt : UDP from 118.12.238.171:53092 to self:42683 2008/08/10 19:28:21 : Blocked access attempt : UDP from 66.131.161.103:33132 to self:42683 2008/08/10 19:28:24 : Blocked access attempt : UDP from 116.14.159.232:1264 to self:42683 2008/08/10 19:28:46 : Blocked access attempt : UDP from 24.1.191.214:28618 to self:42683 2008/08/10 19:28:56 : Blocked access attempt : TCP from 66.29.75.40:80 to self:1568 2008/08/10 19:28:57 : Blocked access attempt : UDP from 84.115.83.87:24303 to self:42683 2008/08/10 19:28:59 : Blocked access attempt : UDP from 218.5.109.39:16243 to self:42683 2008/08/10 19:29:02 : Blocked access attempt : TCP from 66.29.75.40:80 to self:1568 2008/08/10 19:29:06 : Blocked access attempt : UDP from 81.153.161.231:60015 to self:42683 2008/08/10 19:29:06 : Blocked access attempt : UDP from 83.33.235.81:19626 to self:42683 2008/08/10 19:29:09 : Blocked access attempt : TCP from 66.29.75.40:80 to self:1627
|
|||||||||||
|
|
|
|
#3 (permalink) | |||||||||||||
|
Overclocker
![]() |
Still I don't have any anti-virus software protecting me...I'm sure it could only help...so the question is what is the best software available right now for protecting pc overall...for everything....virus, hacking(specially when playing in online gaming), email messages, etc.???
__________________
***Everyone wants to be buck rogers...yet no bucks no rogers...vice versa as well*** *qouted from well you know what flict..lol...the right stuff~!!! http://valid.canardpc.com/cache/banner/507958.png http://valid.canardpc.com/show_oc.php?id=507958 http://www.techpowerup.com/gpuz/g8qs9/
|
|||||||||||||
|
|
|
|
|
#4 (permalink) | ||||||||||||
|
News Fiend
|
Thanks. I feel somewhat better. It is disconcerting to know that if you setup an unsecured network, you are pretty much screwed. Now who the heck is this person who sits around attacking wireless all day?
__________________
|
||||||||||||
|
|
|
|
|
#5 (permalink) | ||||||||||||
|
PC Gamer
![]()
Join Date: Mar 2008
Location: Cincinnati/Athens, Ohio
Posts: 589
Rep: 59
![]() Unique Rep: 55
Trader Rating: 3
|
The same lifeless nobodies who sit around all day writing viruses.
__________________
| OU 2012 - Go Bobcats! |
| MR. BUBBLES - Custom Reservoir | | Currently Playing | Infamous (PS3), Neotokyo (PC), Prototype (PC) | Currently Listening | Pink Floyd, Empire of the Sun, Pet Shop Boys | Currently Watching | Blade Runner Final Cut (1080p), THX-1138 (1080p), The Usual Suspects (720p)
|
||||||||||||
|
|
|
|
|
#6 (permalink) | |||||||||||||
|
4387 point(s) total
![]() |
bots, China, or Eastern European.
__________________
FOR SALE: AMD Athlon 64 LE-1620, Silverstone FP53 3.5" Bay Adapter To answer most of your questions: (1) a fridge cannot cool a PC (2) 64-bit OS for over 3.4GB (3) If a PCIe card fits, it should work (4) Resolution, not screen size (5) If you have a question, it is not news (6) Report, not respond to Spam (7) Single-Rail/Non-Modular PSUs are not always better than Multi-Rail/Modular
|
|||||||||||||
|
|
|
|
#7 (permalink) | ||||||||||||
|
News Fiend
|
Since I am not very well experienced in networking, I will ask the following:
__________________While I know there are always possible workarounds, how secure is my new wireless router? I have encryption enabled and a MAC address allow list. I have two laptops that run off wireless, and my wired sig rig. I really shouldn't worry about something getting in?
|
||||||||||||
|
|
|
|
|
#8 (permalink) | ||||||||||||
|
Audiophile
![]() |
IF you have configured your router correctly it should IGNORE all requests for info and not respond to port-scans etc.
Quote:
__________________
The road of excess leads to the Palace of Wisdom - William Blake (Artist, Poet, Visionary). "I am a comedian and poet, so anything that doesn't get a laugh is a poem." Bill Hicks.
|
||||||||||||
|
|
|
|
|
#9 (permalink) | ||||||||||||
|
News Fiend
|
Yepp, blocked. I have a lot of wireless networks in my range, just the ones I can pickup up are 10+, there are probably more that don't broadcast SSID (incl me).
__________________
|
||||||||||||
|
|
|
|
|
#10 (permalink) | |||||||||||||
|
Crimson Mantle Commander
![]() |
The firewall is blocking the attacks so that's a good thing, and as stated above we all get those kinds of logs,so don't worry to much. One thing to consider is if possible changing your encryption to WPA as WEP can be broken by someone who knows nothing about hacking with some simple downloaded software.Using MAC address filtering is a good ideal also,and newphase has a good suggestion as well.
__________________
Q6600@3.9 http://valid.x86-secret.com/show_oc.php?id=383427 WISCONSIN OVERCLOCKERS![]()
Last edited by reezin14 : 08-10-08 at 02:12 PM |
|||||||||||||
|
|
![]() |
| Currently Active Users Viewing This Thread: 1 (0 members and 1 guests) | |
| Thread Tools | |
|
|