<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Possible DoS attack from shadowserver.org in Full Fibre</title>
    <link>https://community.plus.net/t5/Full-Fibre/Possible-DoS-attack-from-shadowserver-org/m-p/2024401#M28598</link>
    <description>&lt;P&gt;---&lt;BR /&gt;Hopefully, the OP will heed advice to report&amp;nbsp; the error/fault.&lt;/P&gt;
&lt;P&gt;---&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Reported fault this morning ( 11th October 2025 ), no faults found their end with a quick check, as such they are sending out a new router, so at least if the problem continues, we know it is unlikely to be the router. ( Unless there is a bad batch.. )&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Will know more in a couple of weeks I imagine, as things can take a long time to arrive here !&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
    <pubDate>Sat, 11 Oct 2025 08:45:48 GMT</pubDate>
    <dc:creator>Unst-Shetland</dc:creator>
    <dc:date>2025-10-11T08:45:48Z</dc:date>
    <item>
      <title>Possible DoS attack from shadowserver.org</title>
      <link>https://community.plus.net/t5/Full-Fibre/Possible-DoS-attack-from-shadowserver-org/m-p/2023101#M28485</link>
      <description>&lt;P class="lia-indent-padding-left-60px"&gt;Hello. I am suffering repeated connection drops on my new full fibre/FTTP connection.&lt;BR /&gt;&lt;BR /&gt;I have looked at the router logs (I am using your supplied Plusnet Hub Two router) and it would seem that the router is dropping connection due to a DoS attack. Here is a relevant log extract containing the relevant lines as well as context.&lt;BR /&gt;&lt;BR /&gt;Specifically you will see that the router logs show apparent DoS attacks at:&lt;BR /&gt;&lt;BR /&gt;19:00:01, 02 Oct.&lt;BR /&gt;DoS(UDP Loopback): IN=ppp0 OUT= MAC= src=65.49.1.69 DST=146.199.152.235 LEN=29 TOS=0x00 PREC=0x00 TTL=52 ID=9922 DF PROTO=UDP SPT=26948 DPT=19 LEN=9 MARK=0x8000000&lt;BR /&gt;(Connection dropped just after this line)&lt;BR /&gt;&lt;BR /&gt;18:44:12, 02 Oct.&lt;BR /&gt;DoS(UDP Loopback): IN=ppp0 OUT= MAC= src=65.49.1.72 DST=146.199.152.139 LEN=29 TOS=0x00 PREC=0x00 TTL=52 ID=18983 DF PROTO=UDP SPT=19512 DPT=19 LEN=9 MARK=0x8000000&lt;BR /&gt;(Seemingly connection went down just before this line)&lt;BR /&gt;&lt;BR /&gt;17:00:03, 02 Oct.&lt;BR /&gt;DoS(UDP Loopback): IN=ppp0 OUT= MAC= src=64.62.197.43 DST=146.199.152.193 LEN=51 TOS=0x00 PREC=0x00 TTL=52 ID=57820 DF PROTO=UDP SPT=9225 DPT=7 LEN=31 MARK=0x8000000&lt;BR /&gt;(Connection dropped just after this line)&lt;BR /&gt;&lt;BR /&gt;The source IP addresses for each of these lines are 65.49.1.69, 65.49.1.72 and 64.62.197.43. In all cases, these IPs point back to shadowserver.org (a customer of Hurricane Electric).&lt;BR /&gt;&lt;BR /&gt;Looking at shadowserver.org's website, it seems their speciality is port scanning and identification of exploitable hosts. In fact, this document on their website from 2024 appears to directly correlate with the nature of the above log events: &lt;A href="https://www.shadowserver.org/what-we-do/network-reporting/high-loop-dos-report/" target="_blank" rel="noopener"&gt;https://www.shadowserver.org/what-we-do/network-reporting/high-loop-dos-report/&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;In summary, it would seem that shadowserver.org is DoSing my router and causing repeated connection drops.&lt;BR /&gt;&lt;BR /&gt;Are you aware of this?&lt;BR /&gt;&lt;BR /&gt;Despite their claim on their FAQ page that port scanning is legal under US federal law, their actions are very likely illegal in UK law if done without permission.&lt;BR /&gt;&lt;BR /&gt;Have you given them permission to scan and test exploits on your customers' routers?&lt;BR /&gt;&lt;BR /&gt;Can you block their IP range so that they do not reach your customers' routers?&lt;BR /&gt;&lt;BR /&gt;Can you update the router firmware so as not to be vulnerable to this exploit?&lt;BR /&gt;&lt;BR /&gt;Or is there some other process ongoing?&lt;BR /&gt;&lt;BR /&gt;Thank for your help on this.&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#FF9900"&gt;Post released from Spam Filter.&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 03 Oct 2025 04:39:56 GMT</pubDate>
      <guid>https://community.plus.net/t5/Full-Fibre/Possible-DoS-attack-from-shadowserver-org/m-p/2023101#M28485</guid>
      <dc:creator>Unst-Shetland</dc:creator>
      <dc:date>2025-10-03T04:39:56Z</dc:date>
    </item>
    <item>
      <title>Re: Possible DoS attack from shadowserver.org</title>
      <link>https://community.plus.net/t5/Full-Fibre/Possible-DoS-attack-from-shadowserver-org/m-p/2023104#M28486</link>
      <description>&lt;P&gt;&lt;a href="https://community.plus.net/t5/user/viewprofilepage/user-id/147323"&gt;@Unst-Shetland&lt;/a&gt;&amp;nbsp;Looking at those extracts, yes, they are port scans, which unfortunately everyone suffers, but, as I read them, they haven't found any open ports.&lt;/P&gt;
&lt;P&gt;PN will not have 'given permission' - no sane ISP would do that. How would PN be aware - they do not routinely monitor your connection?&lt;/P&gt;
&lt;P&gt;Plusnet would not block an IP unless it was causing severe damage to a large number of their customers and 'updating the firmware' would not prevent this type of intrusion - numerous bad actors try this from many, many different source IPs.&lt;/P&gt;
&lt;P&gt;Sight of your full log would possibly help knowledgable members to offer advice.&lt;/P&gt;</description>
      <pubDate>Fri, 03 Oct 2025 06:11:53 GMT</pubDate>
      <guid>https://community.plus.net/t5/Full-Fibre/Possible-DoS-attack-from-shadowserver-org/m-p/2023104#M28486</guid>
      <dc:creator>jab1</dc:creator>
      <dc:date>2025-10-03T06:11:53Z</dc:date>
    </item>
    <item>
      <title>Re: Possible DoS attack from shadowserver.org</title>
      <link>https://community.plus.net/t5/Full-Fibre/Possible-DoS-attack-from-shadowserver-org/m-p/2023178#M28488</link>
      <description>&lt;P&gt;Thanks for your reply. Apologies, I missed off the more complete log extract in my previous post. I feel the log extract is a bit long to add directly to the forum so here's a link to it in Pastebin:&lt;BR /&gt;&lt;BR /&gt;&lt;A title="Router Log File" href="https://pastebin.com/iCdzjuJ6" target="_blank" rel="noopener"&gt;Router Log File&lt;/A&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;What is happening is not a matter of a simple port scan and nor are open ports being found of concern here. As you can see from the context in the log extract on Pastebin, each "DoS" line in the log correlates closely with a drop of connection.&lt;BR /&gt;&lt;BR /&gt;What is happening appears in fact to be a crafted attack designed to exploit a vulnerability in some routers. It would seem that shadowserver.org is sending out these attacks (and other scans of course) on a large scale and my router, supplied by Plusnet, just happens to be vulnerable.&lt;BR /&gt;&lt;BR /&gt;Did you read the link I provided?&lt;BR /&gt;&lt;BR /&gt;This one:&amp;nbsp;&lt;A href="https://www.shadowserver.org/what-we-do/network-reporting/high-loop-dos-report/" target="_blank" rel="noopener"&gt;https://www.shadowserver.org/what-we-do/network-reporting/high-loop-dos-report/&lt;/A&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;In part it reads:&lt;BR /&gt;&lt;BR /&gt;---&lt;BR /&gt;&amp;nbsp; &amp;nbsp; This report contains information about hosts that can be abused in a novel type of Denial-of-Service (DoS) attacks: application-layer loop DoS. Such loop DoS attacks become possible if two network services indefinitely respond to each other’s messages. The hosts contained in this file have been found to cause such endless loop patterns. If you receive this report for your network or experience abuse of such hosts, consult the advisory on how to mitigate the resulting attacks.&lt;BR /&gt;---&lt;BR /&gt;&lt;BR /&gt;It is well worth reading the information at the link as well as the "advisory on how to mitigate the resulting attacks" that it further links to.&lt;BR /&gt;&lt;BR /&gt;The router logs I have do not provide enough information to be certain but it does appear that there is a similar (or perhaps the same) UDP-based DoS attack ongoing.&lt;BR /&gt;&lt;BR /&gt;&amp;gt;&amp;nbsp; &amp;nbsp; How would PN be aware - they do not routinely monitor your connection?&lt;BR /&gt;&lt;BR /&gt;Running a large network is complex and in fact both ISPs and corporate networks commonly do run a range of intrusion detection and performance monitoring tools, packet shapers, etc. An ISP definitely should be aware when its supplied CPE is going down repeatedly and what the logs indicate about that.&lt;BR /&gt;&lt;BR /&gt;This is not the same as monitoring the private details of one's connection but they do (or should) monitor connections and large scale trends across their network.&lt;BR /&gt;&lt;BR /&gt;&amp;gt;&amp;nbsp; &amp;nbsp; 'updating the firmware' would not prevent this type of intrusion&lt;BR /&gt;&lt;BR /&gt;As you can see from the link I provided, updating router firmware most certainly can provide protection from crafted attacks of this sort. The attack (either the one described in the link I provided or a similar one) is specifically crafted to exploit vulnerable network firmware.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 03 Oct 2025 10:47:21 GMT</pubDate>
      <guid>https://community.plus.net/t5/Full-Fibre/Possible-DoS-attack-from-shadowserver-org/m-p/2023178#M28488</guid>
      <dc:creator>Unst-Shetland</dc:creator>
      <dc:date>2025-10-03T10:47:21Z</dc:date>
    </item>
    <item>
      <title>Re: Possible DoS attack from shadowserver.org</title>
      <link>https://community.plus.net/t5/Full-Fibre/Possible-DoS-attack-from-shadowserver-org/m-p/2023183#M28489</link>
      <description>&lt;P&gt;&lt;a href="https://community.plus.net/t5/user/viewprofilepage/user-id/147323"&gt;@Unst-Shetland&lt;/a&gt;&amp;nbsp;If you take a look here :&amp;nbsp;&lt;A href="https://www.abuseipdb.com/check/65.49.1.72" target="_self"&gt;https://www.abuseipdb.com&amp;nbsp;&lt;/A&gt;&amp;nbsp; you'll see what others are reporting.&lt;/P&gt;</description>
      <pubDate>Fri, 03 Oct 2025 11:05:31 GMT</pubDate>
      <guid>https://community.plus.net/t5/Full-Fibre/Possible-DoS-attack-from-shadowserver-org/m-p/2023183#M28489</guid>
      <dc:creator>Champnet</dc:creator>
      <dc:date>2025-10-03T11:05:31Z</dc:date>
    </item>
    <item>
      <title>Re: Possible DoS attack from shadowserver.org</title>
      <link>https://community.plus.net/t5/Full-Fibre/Possible-DoS-attack-from-shadowserver-org/m-p/2023195#M28490</link>
      <description>&lt;P&gt;&lt;a href="https://community.plus.net/t5/user/viewprofilepage/user-id/147323"&gt;@Unst-Shetland&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For completeness can you post the exported .CSV event log, there are some many missing messages in what you have provided. This is best done using a browser on a PC rather than a smart device&lt;/P&gt;
&lt;P&gt;Use the paper clip icon found below the reply window.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;These events do not usually cause the connection to drop.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 03 Oct 2025 12:02:48 GMT</pubDate>
      <guid>https://community.plus.net/t5/Full-Fibre/Possible-DoS-attack-from-shadowserver-org/m-p/2023195#M28490</guid>
      <dc:creator>Dan_the_Van</dc:creator>
      <dc:date>2025-10-03T12:02:48Z</dc:date>
    </item>
    <item>
      <title>Re: Possible DoS attack from shadowserver.org</title>
      <link>https://community.plus.net/t5/Full-Fibre/Possible-DoS-attack-from-shadowserver-org/m-p/2023197#M28491</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.plus.net/t5/user/viewprofilepage/user-id/621"&gt;@Dan_the_Van&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;These events do not usually cause the connection to drop.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;My thoughts exactly - which is why I requested the full log earlier.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 03 Oct 2025 12:06:19 GMT</pubDate>
      <guid>https://community.plus.net/t5/Full-Fibre/Possible-DoS-attack-from-shadowserver-org/m-p/2023197#M28491</guid>
      <dc:creator>jab1</dc:creator>
      <dc:date>2025-10-03T12:06:19Z</dc:date>
    </item>
    <item>
      <title>Re: Possible DoS attack from shadowserver.org</title>
      <link>https://community.plus.net/t5/Full-Fibre/Possible-DoS-attack-from-shadowserver-org/m-p/2023275#M28503</link>
      <description>&lt;P&gt;&lt;a href="https://community.plus.net/t5/user/viewprofilepage/user-id/147323"&gt;@Unst-Shetland&lt;/a&gt;&amp;nbsp;Sorry, for some reason, I missed your post timed at 11.47. That Pastebin report is not really helpful, as it is too 'expanded' - a simple attachment to a post is much easier to read and more helpful - if you could oblige, please.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;EDIT:&lt;STRONG&gt; IF&lt;/STRONG&gt; this was true - the HUB2 being vulnerable - we would have seen more reports similar to yours - we haven't.&lt;/P&gt;</description>
      <pubDate>Fri, 03 Oct 2025 19:39:21 GMT</pubDate>
      <guid>https://community.plus.net/t5/Full-Fibre/Possible-DoS-attack-from-shadowserver-org/m-p/2023275#M28503</guid>
      <dc:creator>jab1</dc:creator>
      <dc:date>2025-10-03T19:39:21Z</dc:date>
    </item>
    <item>
      <title>Re: Possible DoS attack from shadowserver.org</title>
      <link>https://community.plus.net/t5/Full-Fibre/Possible-DoS-attack-from-shadowserver-org/m-p/2023295#M28507</link>
      <description>&lt;P&gt;&lt;a href="https://community.plus.net/t5/user/viewprofilepage/user-id/147323"&gt;@Unst-Shetland&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;A nmap UDP port check using the IP Address in your first post reveals this for port 19&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;PORT   STATE         SERVICE
19/udp open|filtered chargen&lt;/LI-CODE&gt;
&lt;P&gt;Importantly; when I have previously used the Hub two on FTTC and FTTP I received a succession of the following messages&lt;/P&gt;
&lt;P&gt;DoS(UDP Loopback),&amp;nbsp;DoS(Spoofing) and&amp;nbsp;DoS(Port Scanning), these DoS messages would usually occur at the start of an hour.&lt;/P&gt;
&lt;P&gt;None were associated with a preceding Link Down messages, so may be in your case it is a coincidence.&lt;/P&gt;
&lt;P&gt;I do note&lt;/P&gt;
&lt;P&gt;17:00:03, 02 Oct.&amp;nbsp;&lt;SPAN&gt;DoS(UDP Loopback): IN=ppp0 OUT= MAC= src=64.62.197.43 DST=146.199.152.193 LEN=51 TOS=0x00 PREC=0x00 TTL=52 ID=57820 DF PROTO=UDP SPT=9225 DPT=7 LEN=31 MARK=0x8000000&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Link down messages start at 18:17&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;This will be the likely cause of your disconnects&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;18:17:24, 02 Oct.&amp;nbsp;&lt;SPAN&gt;WAN connection WAN1_INTERNET_ETH disconnected.[ERROR_NO_CARRIER]&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;ERROR_NO_CARRIER can be caused by a poorly secured Hub WAN port to ONT LAN port, this would result in a flashing orange light on the Hub&lt;/P&gt;
&lt;P&gt;or&lt;/P&gt;
&lt;P&gt;A disconnect between the Hub and the upstream PPPoE&amp;nbsp; server this would result in the Hub light be a solid orange colour&lt;/P&gt;
&lt;P&gt;A previous request for the full event log would be helpful.&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 04 Oct 2025 07:30:16 GMT</pubDate>
      <guid>https://community.plus.net/t5/Full-Fibre/Possible-DoS-attack-from-shadowserver-org/m-p/2023295#M28507</guid>
      <dc:creator>Dan_the_Van</dc:creator>
      <dc:date>2025-10-04T07:30:16Z</dc:date>
    </item>
    <item>
      <title>Re: Possible DoS attack from shadowserver.org</title>
      <link>https://community.plus.net/t5/Full-Fibre/Possible-DoS-attack-from-shadowserver-org/m-p/2023473#M28537</link>
      <description>&lt;P&gt;Log file as requested.&lt;/P&gt;</description>
      <pubDate>Sun, 05 Oct 2025 10:40:37 GMT</pubDate>
      <guid>https://community.plus.net/t5/Full-Fibre/Possible-DoS-attack-from-shadowserver-org/m-p/2023473#M28537</guid>
      <dc:creator>Unst-Shetland</dc:creator>
      <dc:date>2025-10-05T10:40:37Z</dc:date>
    </item>
    <item>
      <title>Re: Possible DoS attack from shadowserver.org</title>
      <link>https://community.plus.net/t5/Full-Fibre/Possible-DoS-attack-from-shadowserver-org/m-p/2023477#M28538</link>
      <description>&lt;P&gt;&lt;a href="https://community.plus.net/t5/user/viewprofilepage/user-id/621"&gt;@Dan_the_Van&lt;/a&gt;&amp;nbsp;Interesting error log, but a very full one. I can't see too much I can safely comment on - never really seen a Hub2 log on FTTP, so I'll leave it to you as you have had more experience.&lt;/P&gt;</description>
      <pubDate>Sun, 05 Oct 2025 11:10:30 GMT</pubDate>
      <guid>https://community.plus.net/t5/Full-Fibre/Possible-DoS-attack-from-shadowserver-org/m-p/2023477#M28538</guid>
      <dc:creator>jab1</dc:creator>
      <dc:date>2025-10-05T11:10:30Z</dc:date>
    </item>
    <item>
      <title>Re: Possible DoS attack from shadowserver.org</title>
      <link>https://community.plus.net/t5/Full-Fibre/Possible-DoS-attack-from-shadowserver-org/m-p/2023486#M28539</link>
      <description>&lt;P&gt;There's a significant number of 'error_no_carrier' logs which&amp;nbsp;&lt;SPAN data-huuid="14745942282420322262"&gt;on an FTTP (Full Fibre) broadband service indicate a disconnect between the router and the Openreach network. They seem to last only for about 6 or 7 seconds.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;They could be caused by :-&lt;/P&gt;
&lt;P&gt;1) An intermittent fault e.g bad connection in the Fibre network&lt;/P&gt;
&lt;P&gt;2) A faulty ONT&lt;/P&gt;
&lt;P&gt;3) Bad cable or connection (as&amp;nbsp;&lt;a href="https://community.plus.net/t5/user/viewprofilepage/user-id/621"&gt;@Dan_the_Van&lt;/a&gt;&amp;nbsp;suggested earlier ) between the router and ONT&lt;/P&gt;
&lt;P&gt;4) Faulty router or WAN port&lt;/P&gt;
&lt;P&gt;&lt;a href="https://community.plus.net/t5/user/viewprofilepage/user-id/147323"&gt;@Unst-Shetland&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;1) would almost certainly show as a change in the lights on the ONT (either LOS red or PON flashing) , do you notice any change when the drops happen ?&lt;/P&gt;
&lt;P&gt;3) could be eliminated by confirming both ends of the cable are properly locked and, if so, then a possible change in cable&lt;/P&gt;</description>
      <pubDate>Sun, 05 Oct 2025 11:39:30 GMT</pubDate>
      <guid>https://community.plus.net/t5/Full-Fibre/Possible-DoS-attack-from-shadowserver-org/m-p/2023486#M28539</guid>
      <dc:creator>MisterW</dc:creator>
      <dc:date>2025-10-05T11:39:30Z</dc:date>
    </item>
    <item>
      <title>Re: Possible DoS attack from shadowserver.org</title>
      <link>https://community.plus.net/t5/Full-Fibre/Possible-DoS-attack-from-shadowserver-org/m-p/2023487#M28540</link>
      <description>&lt;P&gt;&lt;a href="https://community.plus.net/t5/user/viewprofilepage/user-id/1110"&gt;@MisterW&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thanks, you've saved me some typing&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;a href="https://community.plus.net/t5/user/viewprofilepage/user-id/147323"&gt;@Unst-Shetland&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;To me it looks like you upgraded to Full Fibre at&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;09:27:48, 09 Sep. WAN Auto-sensing detected port Ethernet WAN&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;Also keep an eye on the Hub's light, flashing or solid orange.&lt;/P&gt;</description>
      <pubDate>Sun, 05 Oct 2025 11:48:01 GMT</pubDate>
      <guid>https://community.plus.net/t5/Full-Fibre/Possible-DoS-attack-from-shadowserver-org/m-p/2023487#M28540</guid>
      <dc:creator>Dan_the_Van</dc:creator>
      <dc:date>2025-10-05T11:48:01Z</dc:date>
    </item>
    <item>
      <title>Re: Possible DoS attack from shadowserver.org</title>
      <link>https://community.plus.net/t5/Full-Fibre/Possible-DoS-attack-from-shadowserver-org/m-p/2023738#M28546</link>
      <description>&lt;P&gt;Had no internet for a couple of hours yesterday, so was able to check a few things:&lt;BR /&gt;&lt;BR /&gt;---&lt;BR /&gt;A disconnect between the Hub and the upstream PPPoE&amp;nbsp; server this would result in the Hub light be a solid orange colour&lt;BR /&gt;---&lt;BR /&gt;&lt;BR /&gt;Yes, it was a solid orange colour.&lt;BR /&gt;&lt;BR /&gt;Turning the router on and off again did not change this.&lt;BR /&gt;&lt;BR /&gt;---&lt;BR /&gt;1) would almost certainly show as a change in the lights on the ONT (either LOS red or PON flashing) , do you notice any change when the drops happen ?&lt;BR /&gt;---&lt;BR /&gt;&lt;BR /&gt;No change, all 4 lights still green.&lt;BR /&gt;&lt;BR /&gt;Would this issue be detectable by Plusnet further upstream, eg. would it show in their ISP/etc. logs ?&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 07 Oct 2025 08:57:37 GMT</pubDate>
      <guid>https://community.plus.net/t5/Full-Fibre/Possible-DoS-attack-from-shadowserver-org/m-p/2023738#M28546</guid>
      <dc:creator>Unst-Shetland</dc:creator>
      <dc:date>2025-10-07T08:57:37Z</dc:date>
    </item>
    <item>
      <title>Re: Possible DoS attack from shadowserver.org</title>
      <link>https://community.plus.net/t5/Full-Fibre/Possible-DoS-attack-from-shadowserver-org/m-p/2023770#M28547</link>
      <description>&lt;P&gt;&lt;a href="https://community.plus.net/t5/user/viewprofilepage/user-id/147323"&gt;@Unst-Shetland&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;plusnet do not proactively monitor connections, the solid orange light would indicate an upstream issue.&lt;/P&gt;
&lt;P&gt;There is a possibility of an openreach infrastructure issues. The logs show many disconnect since you went live with Full Fibre&lt;/P&gt;
&lt;P&gt;I would suggest reporting the issue to plusnet; follow the instructions here&amp;nbsp;&lt;A href="https://www.plus.net/help/report-a-problem/" target="_self"&gt;https://www.plus.net/help/report-a-problem/&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 07 Oct 2025 11:14:50 GMT</pubDate>
      <guid>https://community.plus.net/t5/Full-Fibre/Possible-DoS-attack-from-shadowserver-org/m-p/2023770#M28547</guid>
      <dc:creator>Dan_the_Van</dc:creator>
      <dc:date>2025-10-07T11:14:50Z</dc:date>
    </item>
    <item>
      <title>Re: Possible DoS attack from shadowserver.org</title>
      <link>https://community.plus.net/t5/Full-Fibre/Possible-DoS-attack-from-shadowserver-org/m-p/2023786#M28548</link>
      <description>&lt;P&gt;Have replaced the network cable between the router and the box on the wall, I'll see if that makes any difference.&lt;BR /&gt;&lt;BR /&gt;Then I'll try a different router.&lt;BR /&gt;&lt;BR /&gt;Then I'll try this route:&lt;BR /&gt;&lt;BR /&gt;---&lt;/P&gt;
&lt;P&gt;I would suggest reporting the issue to plusnet; follow the instructions here&amp;nbsp;&lt;A href="https://www.plus.net/help/report-a-problem/" target="_self" rel="noopener noreferrer"&gt;https://www.plus.net/help/report-a-problem/&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;---&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 07 Oct 2025 13:01:44 GMT</pubDate>
      <guid>https://community.plus.net/t5/Full-Fibre/Possible-DoS-attack-from-shadowserver-org/m-p/2023786#M28548</guid>
      <dc:creator>Unst-Shetland</dc:creator>
      <dc:date>2025-10-07T13:01:44Z</dc:date>
    </item>
    <item>
      <title>Re: Possible DoS attack from shadowserver.org</title>
      <link>https://community.plus.net/t5/Full-Fibre/Possible-DoS-attack-from-shadowserver-org/m-p/2023789#M28549</link>
      <description>&lt;P&gt;&lt;a href="https://community.plus.net/t5/user/viewprofilepage/user-id/147323"&gt;@Unst-Shetland&lt;/a&gt;&amp;nbsp;If the fault is upstream of you, you are wasting your time with those proposals - they will achieve nothing.&lt;/P&gt;
&lt;P&gt;Report your problem now - not in three months time.&lt;/P&gt;</description>
      <pubDate>Tue, 07 Oct 2025 13:06:00 GMT</pubDate>
      <guid>https://community.plus.net/t5/Full-Fibre/Possible-DoS-attack-from-shadowserver-org/m-p/2023789#M28549</guid>
      <dc:creator>jab1</dc:creator>
      <dc:date>2025-10-07T13:06:00Z</dc:date>
    </item>
    <item>
      <title>Re: Possible DoS attack from shadowserver.org</title>
      <link>https://community.plus.net/t5/Full-Fibre/Possible-DoS-attack-from-shadowserver-org/m-p/2024391#M28591</link>
      <description>&lt;P&gt;---&lt;BR /&gt;Report your problem now - not in three months time.&lt;BR /&gt;---&lt;BR /&gt;&lt;BR /&gt;Should I wait until the internet is actually not working, and its between 8am and 7.30pm when Plusnet support is open, or just report it any time during those working hours ?&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Replacement cable appears not to have made any difference, see last day logfile:&lt;BR /&gt;&lt;BR /&gt;9 *&amp;nbsp;WAN connection WAN1_INTERNET_ETH disconnected.[ERROR_NO_CARRIER] since 7th October 2025.&lt;BR /&gt;&lt;BR /&gt;Oh and the Plusnet router has a bug in its log display, it misses a line on the page at the top or bottom, I can't remember which.&lt;BR /&gt;&lt;BR /&gt;I noticed when I compared the downloaded log to the displayed one in the router, since it was missing a [ERROR_NO_CARRIER] which I had seen earlier and suddenly wasn't visible, except in the downloaded copy.&lt;/P&gt;</description>
      <pubDate>Fri, 10 Oct 2025 22:06:09 GMT</pubDate>
      <guid>https://community.plus.net/t5/Full-Fibre/Possible-DoS-attack-from-shadowserver-org/m-p/2024391#M28591</guid>
      <dc:creator>Unst-Shetland</dc:creator>
      <dc:date>2025-10-10T22:06:09Z</dc:date>
    </item>
    <item>
      <title>Re: Possible DoS attack from shadowserver.org</title>
      <link>https://community.plus.net/t5/Full-Fibre/Possible-DoS-attack-from-shadowserver-org/m-p/2024395#M28592</link>
      <description>&lt;P&gt;&lt;EM&gt;Should I wait until the internet is actually not working, and its between 8am and 7.30pm when Plusnet support is open, or just report it any time during those working hours ?&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;No - use the bot to report it - even if it is 'working'&amp;nbsp; - the automated testing doesn't just look at the current state.&lt;/P&gt;</description>
      <pubDate>Sat, 11 Oct 2025 06:10:54 GMT</pubDate>
      <guid>https://community.plus.net/t5/Full-Fibre/Possible-DoS-attack-from-shadowserver-org/m-p/2024395#M28592</guid>
      <dc:creator>jab1</dc:creator>
      <dc:date>2025-10-11T06:10:54Z</dc:date>
    </item>
    <item>
      <title>Re: Possible DoS attack from shadowserver.org</title>
      <link>https://community.plus.net/t5/Full-Fibre/Possible-DoS-attack-from-shadowserver-org/m-p/2024396#M28593</link>
      <description>&lt;P&gt;&lt;a href="https://community.plus.net/t5/user/viewprofilepage/user-id/621"&gt;@Dan_the_Van&lt;/a&gt;&amp;nbsp; /&amp;nbsp;&lt;a href="https://community.plus.net/t5/user/viewprofilepage/user-id/1110"&gt;@MisterW&lt;/a&gt;&amp;nbsp; I think I'll leave this to you.&amp;nbsp; No expert, but those numerous PADI/PADO/PADS entries seem suspicious?&lt;/P&gt;</description>
      <pubDate>Sat, 11 Oct 2025 06:38:15 GMT</pubDate>
      <guid>https://community.plus.net/t5/Full-Fibre/Possible-DoS-attack-from-shadowserver-org/m-p/2024396#M28593</guid>
      <dc:creator>jab1</dc:creator>
      <dc:date>2025-10-11T06:38:15Z</dc:date>
    </item>
    <item>
      <title>Re: Possible DoS attack from shadowserver.org</title>
      <link>https://community.plus.net/t5/Full-Fibre/Possible-DoS-attack-from-shadowserver-org/m-p/2024397#M28594</link>
      <description>&lt;P&gt;&lt;a href="https://community.plus.net/t5/user/viewprofilepage/user-id/18089"&gt;@jab1&lt;/a&gt;&amp;nbsp;they're just another consequence of what seems to be an intermittent WAN connection.&lt;/P&gt;
&lt;P&gt;In previous logs , the WAN connection was lost, fairly quickly came back and the PPPoE session was restored within a few seconds.&lt;/P&gt;
&lt;P&gt;What seems to be happening now is that the PPPoE session is struggling to reestablish.&lt;/P&gt;
&lt;P&gt;It sends the PADI, sometimes it gets the PADO reply, other times it doesnt and continues with PADI. Having got a PADO, it sends PADR expecting a PADS, to then go on complete the PPPoE setup. For many times in the log , it doesnt get the PADS, so times out and goes back to sending PADI. Eventually, it gets the PADS and goes on to setup the PPPoE connection.&lt;/P&gt;
&lt;P&gt;Its all consistent with an intermittent connection somewhere between the router and the head-end.&lt;/P&gt;
&lt;P&gt;As you said previously,&amp;nbsp;&lt;a href="https://community.plus.net/t5/user/viewprofilepage/user-id/147323"&gt;@Unst-Shetland&lt;/a&gt;&amp;nbsp;should report a fault now as whatever the problem was, it seems to be getting worse&lt;/P&gt;</description>
      <pubDate>Sat, 11 Oct 2025 06:57:19 GMT</pubDate>
      <guid>https://community.plus.net/t5/Full-Fibre/Possible-DoS-attack-from-shadowserver-org/m-p/2024397#M28594</guid>
      <dc:creator>MisterW</dc:creator>
      <dc:date>2025-10-11T06:57:19Z</dc:date>
    </item>
  </channel>
</rss>

