|
|||||||
![]() |
|
|
LinkBack | Thread Tools | Search this Thread | Rate Thread | Display Modes |
|
|
#1 |
|
Member (11 bit)
Join Date: Jul 2006
Location: UK
Posts: 1,220
|
Router security log....?
I just checked the security log for our new wireless router and there are a lot of records for "TCP FIN Scan" and "IP Spoofing".
Are these attempts at accessing the network? Anything to worry about?
__________________
** Custom Desktop: Core i3-530, 4GB Corsair RAM, 500GB WD HDD ** ** Netbook: HP Mini 210 ** |
|
|
|
|
|
#2 |
|
Member (13 bit)
Join Date: Mar 1999
Posts: 6,789
|
Are these coming from external sources or from clients on your network?
|
|
|
|
|
|
#3 |
|
Member (11 bit)
Join Date: Jul 2006
Location: UK
Posts: 1,220
|
The IP Spoofing is inbound from the WAN and the TCP Fin Scan is going outbound from my sisters IP address.
I have switched back to the wired router and it is also logging similar behaviour. Here is a small section of my security log on the hard-wired router: strangePackets.txt Last edited by AnotherMuggle; 12-27-2006 at 07:24 AM. |
|
|
|
|
|
#4 |
|
Member (11 bit)
Join Date: Jul 2006
Location: UK
Posts: 1,220
|
Does anyone have any suggestions on this. I am a little stuck for who I can talk to.
NTL claim it's nothing to do with them and Belkin don't seem keen to help either
|
|
|
|
|
|
#5 |
|
Member (9 bit)
Join Date: May 2006
Location: Spokane, WA
Posts: 367
|
Is this JUST a home network? Do you have a VPN connection or anything like that? UDP is typically a VPN or remote connection protocol.
First thing I would suggest is to close any ports on that router. By default, ports should be closed from the factory, so start with a reset.
__________________
Last edited by telegramsam; 12-30-2006 at 01:43 PM. |
|
|
|
|
|
#6 | |
|
Member (11 bit)
Join Date: Jul 2006
Location: UK
Posts: 1,220
|
Quote:
|
|
|
|
|
|
|
#7 |
|
Member (9 bit)
Join Date: May 2006
Location: Spokane, WA
Posts: 367
|
Ok--I missed the VPN thing;
UDP is VPN protocol-which is normal. Keep Malware and virus scanners running. I don't think you really have anything to worry about. Last edited by telegramsam; 12-31-2006 at 02:32 PM. |
|
|
|
|
|
#8 |
|
Member (11 bit)
Join Date: Jul 2006
Location: UK
Posts: 1,220
|
I have done a little more research and it looks like the address for the "TCP FIN Scan" is for the website www.bebo.com, which my sister regularly uses. This log is always from her IP address, but I don't understand why it is being caught by the firewall.
The IP address that is being logged as "IP Spoofing" is going to our ISP. Again I can't understand why this would be caught in the firewall. Here is a log file from the other router (which is currently in use - no VPN): security.txt Thanks for your help telegramsam
|
|
|
|
|
|
#9 |
|
Member (9 bit)
Join Date: May 2006
Location: Spokane, WA
Posts: 367
|
IP Spoofing is a term that is generally used to describe how 2 or more computers share a single WAN IP. But it's also a pretty well known hacking tool.
So I'm not exactly sure what to think about this. Where is the 127.0.0.1 IP coming from? That's structured like an inside IP...but it appears that your IP scheme is 192.168.... Run an ipconfig on all of your machines so you know what their inside addresses are. |
|
|
|
|
|
#10 |
|
Member (11 bit)
Join Date: Jul 2006
Location: UK
Posts: 1,220
|
I have set the routers DHCP so that it can only dish out 2 addresses, one for each machine on the network...192.168.2.2 and 192.168.2.3.
I have no idea where the 127.0.0.1 address is coming from. I have done DNS lookup on it and all it says is that it's an internet assigned address. |
|
|
|
|
|
#11 |
|
Telcom Tech
Join Date: Feb 2002
Location: Western, Pa.
Posts: 5,409
|
127.0.0.1 is an internal IP adress that I believe is used by windows and or any PC with TCP/IP protocol installed, for things like testing to see if the IP stack is working properly. I know I've used it to ping and it's somehow kind of like pinging yourself and shows that at least your IP stack and NIC card are working properly from your PC's internal perspective. I am pretty certain it is not an internet assigned IP address, it is reserved for the IP stack, much like 10.x.x.x and 192.168.x.x are reserved private addresses and will never be found out on the internet. You can prove this by unplugging your network connection and you should still be able to ping 127.0.0.1.
__________________
If it ain't broke, "TWEAK IT" Last edited by ktkendall; 12-31-2006 at 07:00 PM. |
|
|
|
|
|
#12 | |
|
Member (11 bit)
Join Date: Jul 2006
Location: UK
Posts: 1,220
|
Quote:
I just checked again and the firewall is still logging TCP FIN Scan and IP Spoofing, and it seems to be for various different IP addresses. |
|
|
|
|
|
|
#13 |
|
Telcom Tech
Join Date: Feb 2002
Location: Western, Pa.
Posts: 5,409
|
Looking at the log file you posted it looks like the ones with 127.0.0.1 might be your router rejecting requests coming in on the wan port, or inother words it looks to me like it might be the routers' internal hardware firewall doing it's job and protecting you from those unwanted wan requests.
|
|
|
|
|
|
#14 |
|
Member (11 bit)
Join Date: Jul 2006
Location: UK
Posts: 1,220
|
Latest Update:
The firewall is now logging "Smurf" attacks. I am a little concerned about all these things that are getting logged. Can anyone suggest what I should do to get to the bottom of this? I have phoned my ISP and they have said it is not something they can help with. |
|
|
|
|
|
#15 |
|
Forum Administrator
Staff
Premium Member
Join Date: May 2000
Location: Joplin MO
Posts: 36,460
|
Let the firewall do its job and stop worrying. This is like obsessing about CPU temperatures.
|
|
|
|
|
|
#16 | |
|
Member (11 bit)
Join Date: Jul 2006
Location: UK
Posts: 1,220
|
Quote:
Thanks, Tom. |
|
|
|
|
|
|
#17 |
|
Forum Administrator
Staff
Premium Member
Join Date: May 2000
Location: Joplin MO
Posts: 36,460
|
If you want another line of defense, then install a good 3rd party software firewall such as Zone Alarm. Note that this will cause file and print sharing headaches. The XP SP2 firewall is an excellent firewall for blocking incoming if you carefully configure the exception list, but does not monitor outgoing.
|
|
|
|
![]() |
| Bookmarks |
| Thread Tools | Search this Thread |
| Display Modes | Rate This Thread |
|
|
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| How to Secure a Network | Statica | Networking & Online Security | 20 | 03-13-2006 05:05 PM |
| Belkin Pre-N Router | Klutz_atlantis | Computer Hardware | 6 | 11-13-2005 05:20 PM |
| FireFox 1.0.2 and Router DI-704 | Burn | Networking & Online Security | 3 | 04-13-2005 01:05 AM |
| Linux in the Security Crosshairs | morriswindgate | Networking & Online Security | 6 | 12-16-2003 01:33 AM |
| Audit/Security Log | qsnurses | Windows Legacy Support (XP and earlier) | 0 | 12-03-2002 01:39 PM |