Go Back   PCMech Forums > Help & Discussion > Networking & Online Security

Need Some Help? Type Your Keywords Here:

Reply
 
LinkBack Thread Tools Search this Thread Rate Thread Display Modes
Old 02-01-2005, 06:15 AM   #1
Member (8 bit)
 
Join Date: Aug 2000
Location: Cedar Rapids, IA, USA
Posts: 241
Send a message via AIM to ChromWolf
Excess net activity on cable modem

For maybe 30 or so minutes, my internet connection was down. Cable Modem had to re-establish connection, which it did. However, now the activity light is constantly on, as though I'm downloading something---but that's not the case. Downloading websites in order to browse is extremely slow, and my computer couldn't stay connected to AIM for more than about 5 minutes.

My ISP is Mediacom, and I've got two computers networked (not wireless) behind a LinkSys router. The router's incomming logs note several dozens of attempts at inbound access; many of the IP's listed have the same first two octets as my Cable Modem's IP, but some do not. Common ports access is attempted through are 135, 445, 3677-3678, 3713-3714, and 3754-3755. Out of curiosity, I tried pinging a couple; most timed out, but a couple gave me a responses of less than 200 ms.

What could be going on here? Is this a DoS attack, and if so, beyond calling Mediacom (it's a bit late, but I'm being bad and posting anyway), how can I find out what this is, and how to put a stop it? Is there any way to know if this is targetted at me specifically, or someone's just scanning large IP blocks with my first two IP octets?

For the record, I've done pretty much all the applicable steps recommended in the sticked "how to secure a network" thread...

What can I do?
ChromWolf is offline   Reply With Quote
Old 02-01-2005, 08:04 AM   #2
I am, in reality, a moose
Staff
Premium Member
 
mbossman2's Avatar
 
Join Date: Aug 1999
Location: RTP, NC
Posts: 2,439
it could be a lot of things:
-your ISP could be doing an update to the modem (but that shouldn't take more than 5-10 minutes, unless you have a bad modem)
-it could be a DoS attack and the best solution for that is to notify the ISP and let them handle it

My advice is to rely on your firewall defenses and have the ISP check their logs to see if they see something out of the ordinary and then let them act on it..
__________________
Veritas Principium Libertas

Traveling Moose
mbossman2 is offline   Reply With Quote
Reply

Bookmarks

Still Need Help? Type Your Keywords Here:


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is On
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -5. The time now is 02:24 AM.
Powered by vBulletin® Version 3.8.6
Copyright ©2000 - 2012, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.6.0