<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Ongoing DOS attack from Iran in Full Fibre</title>
    <link>https://community.plus.net/t5/Full-Fibre/Ongoing-DOS-attack-from-Iran/m-p/1828494#M126684</link>
    <description>&lt;P&gt;If your system's secure, sit tight, eventually they'll give up and move on to someone else..........&lt;/P&gt;</description>
    <pubDate>Wed, 15 Sep 2021 12:11:29 GMT</pubDate>
    <dc:creator>Champnet</dc:creator>
    <dc:date>2021-09-15T12:11:29Z</dc:date>
    <item>
      <title>Ongoing DOS attack from Iran</title>
      <link>https://community.plus.net/t5/Full-Fibre/Ongoing-DOS-attack-from-Iran/m-p/1828457#M126679</link>
      <description>&lt;P&gt;Since yesterday morning I'm experiencing ongoing DOS/Brute-Force attack lunched from Iranian IP&amp;nbsp;31.130.184.212 against my smtp server (I have static IP).&amp;nbsp; I'm not the only one person who is targeted by this attack&amp;nbsp;&lt;A href="https://www.abuseipdb.com/check/31.130.184.212" target="_blank"&gt;https://www.abuseipdb.com/check/31.130.184.212&lt;/A&gt;.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Of course fail2ban blocked this IP and I moved this blocking to my router's firewall but looks like attacker running some script in loop which doesn't check response even if I'm specifically dropping incoming traffic.&lt;/P&gt;
&lt;P&gt;Writing email to provider is pointless as in countries like Iran or China they never responding or acting on it.&lt;/P&gt;
&lt;P&gt;Now question is: does Plusnet NOC/SOC is able to react on this kind of attacks ?&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It's not massive flood of traffic (around 42 connections per minute) but still bringing unwanted traffic to internet connection.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;09:59:00.131270 IP 31.130.184.212.20412 &amp;gt; xyz.plus.com.25: Flags [S], seq 1759048769, win 29200, options [mss 1460,sackOK,TS val 105182304 ecr 0,nop,wscale 10], length 0&lt;BR /&gt;09:59:01.581052 IP 31.130.184.212.12758 &amp;gt; xyz.plus.com.25: Flags [S], seq 2161857530, win 29200, options [mss 1460,sackOK,TS val 105183754 ecr 0,nop,wscale 10], length 0&lt;BR /&gt;09:59:02.586174 IP 31.130.184.212.12758 &amp;gt; xyz.plus.com.25: Flags [S], seq 2161857530, win 29200, options [mss 1460,sackOK,TS val 105184757 ecr 0,nop,wscale 10], length 0&lt;BR /&gt;09:59:04.587528 IP 31.130.184.212.12758 &amp;gt; xyz.plus.com.25: Flags [S], seq 2161857530, win 29200, options [mss 1460,sackOK,TS val 105186760 ecr 0,nop,wscale 10], length 0&lt;BR /&gt;09:59:05.916015 IP 31.130.184.212.5070 &amp;gt; xyz.plus.com.25: Flags [S], seq 2397665211, win 29200, options [mss 1460,sackOK,TS val 105188086 ecr 0,nop,wscale 10], length 0&lt;BR /&gt;09:59:06.916354 IP 31.130.184.212.5070 &amp;gt; xyz.plus.com.25: Flags [S], seq 2397665211, win 29200, options [mss 1460,sackOK,TS val 105189088 ecr 0,nop,wscale 10], length 0&lt;BR /&gt;09:59:08.918840 IP 31.130.184.212.5070 &amp;gt; xyz.plus.com.25: Flags [S], seq 2397665211, win 29200, options [mss 1460,sackOK,TS val 105191092 ecr 0,nop,wscale 10], length 0&lt;BR /&gt;09:59:10.025226 IP 31.130.184.212.61926 &amp;gt; xyz.plus.com.25: Flags [S], seq 1179237925, win 29200, options [mss 1460,sackOK,TS val 105192199 ecr 0,nop,wscale 10], length 0&lt;BR /&gt;09:59:11.026244 IP 31.130.184.212.61926 &amp;gt; xyz.plus.com.25: Flags [S], seq 1179237925, win 29200, options [mss 1460,sackOK,TS val 105193201 ecr 0,nop,wscale 10], length 0&lt;BR /&gt;09:59:13.033311 IP 31.130.184.212.61926 &amp;gt; xyz.plus.com.25: Flags [S], seq 1179237925, win 29200, options [mss 1460,sackOK,TS val 105195208 ecr 0,nop,wscale 10], length 0&lt;BR /&gt;09:59:14.178819 IP 31.130.184.212.54306 &amp;gt; xyz.plus.com.25: Flags [S], seq 2295214912, win 29200, options [mss 1460,sackOK,TS val 105196350 ecr 0,nop,wscale 10], length 0&lt;BR /&gt;09:59:15.180074 IP 31.130.184.212.54306 &amp;gt; xyz.plus.com.25: Flags [S], seq 2295214912, win 29200, options [mss 1460,sackOK,TS val 105197352 ecr 0,nop,wscale 10], length 0&lt;BR /&gt;09:59:17.182134 IP 31.130.184.212.54306 &amp;gt; xyz.plus.com.25: Flags [S], seq 2295214912, win 29200, options [mss 1460,sackOK,TS val 105199357 ecr 0,nop,wscale 10], length 0&lt;BR /&gt;09:59:18.537651 IP 31.130.184.212.46624 &amp;gt; xyz.plus.com.25: Flags [S], seq 1909957441, win 29200, options [mss 1460,sackOK,TS val 105200711 ecr 0,nop,wscale 10], length 0&lt;BR /&gt;09:59:19.538220 IP 31.130.184.212.46624 &amp;gt; xyz.plus.com.25: Flags [S], seq 1909957441, win 29200, options [mss 1460,sackOK,TS val 105201713 ecr 0,nop,wscale 10], length 0&lt;BR /&gt;09:59:21.545366 IP 31.130.184.212.46624 &amp;gt; xyz.plus.com.25: Flags [S], seq 1909957441, win 29200, options [mss 1460,sackOK,TS val 105203720 ecr 0,nop,wscale 10], length 0&lt;BR /&gt;09:59:22.899012 IP 31.130.184.212.38966 &amp;gt; xyz.plus.com.25: Flags [S], seq 2644661936, win 29200, options [mss 1460,sackOK,TS val 105205072 ecr 0,nop,wscale 10], length 0&lt;BR /&gt;09:59:23.902775 IP 31.130.184.212.38966 &amp;gt; xyz.plus.com.25: Flags [S], seq 2644661936, win 29200, options [mss 1460,sackOK,TS val 105206074 ecr 0,nop,wscale 10], length 0&lt;BR /&gt;09:59:25.909606 IP 31.130.184.212.38966 &amp;gt; xyz.plus.com.25: Flags [S], seq 2644661936, win 29200, options [mss 1460,sackOK,TS val 105208080 ecr 0,nop,wscale 10], length 0&lt;BR /&gt;09:59:27.020314 IP 31.130.184.212.31310 &amp;gt; xyz.plus.com.25: Flags [S], seq 1540021690, win 29200, options [mss 1460,sackOK,TS val 105209192 ecr 0,nop,wscale 10], length 0&lt;BR /&gt;09:59:28.020188 IP 31.130.184.212.31310 &amp;gt; xyz.plus.com.25: Flags [S], seq 1540021690, win 29200, options [mss 1460,sackOK,TS val 105210194 ecr 0,nop,wscale 10], length 0&lt;BR /&gt;09:59:30.026550 IP 31.130.184.212.31310 &amp;gt; xyz.plus.com.25: Flags [S], seq 1540021690, win 29200, options [mss 1460,sackOK,TS val 105212200 ecr 0,nop,wscale 10], length 0&lt;BR /&gt;09:59:31.285418 IP 31.130.184.212.23640 &amp;gt; xyz.plus.com.25: Flags [S], seq 1475033534, win 29200, options [mss 1460,sackOK,TS val 105213458 ecr 0,nop,wscale 10], length 0&lt;BR /&gt;09:59:32.286407 IP 31.130.184.212.23640 &amp;gt; xyz.plus.com.25: Flags [S], seq 1475033534, win 29200, options [mss 1460,sackOK,TS val 105214460 ecr 0,nop,wscale 10], length 0&lt;BR /&gt;09:59:34.292119 IP 31.130.184.212.23640 &amp;gt; xyz.plus.com.25: Flags [S], seq 1475033534, win 29200, options [mss 1460,sackOK,TS val 105216464 ecr 0,nop,wscale 10], length 0&lt;BR /&gt;09:59:35.882036 IP 31.130.184.212.15960 &amp;gt; xyz.plus.com.25: Flags [S], seq 3569014455, win 29200, options [mss 1460,sackOK,TS val 105218055 ecr 0,nop,wscale 10], length 0&lt;BR /&gt;09:59:36.883784 IP 31.130.184.212.15960 &amp;gt; xyz.plus.com.25: Flags [S], seq 3569014455, win 29200, options [mss 1460,sackOK,TS val 105219057 ecr 0,nop,wscale 10], length 0&lt;BR /&gt;09:59:38.891272 IP 31.130.184.212.15960 &amp;gt; xyz.plus.com.25: Flags [S], seq 3569014455, win 29200, options [mss 1460,sackOK,TS val 105221064 ecr 0,nop,wscale 10], length 0&lt;BR /&gt;09:59:40.067320 IP 31.130.184.212.8300 &amp;gt; xyz.plus.com.25: Flags [S], seq 479345639, win 29200, options [mss 1460,sackOK,TS val 105222238 ecr 0,nop,wscale 10], length 0&lt;BR /&gt;09:59:41.066942 IP 31.130.184.212.8300 &amp;gt; xyz.plus.com.25: Flags [S], seq 479345639, win 29200, options [mss 1460,sackOK,TS val 105223240 ecr 0,nop,wscale 10], length 0&lt;BR /&gt;09:59:43.069036 IP 31.130.184.212.8300 &amp;gt; xyz.plus.com.25: Flags [S], seq 479345639, win 29200, options [mss 1460,sackOK,TS val 105225244 ecr 0,nop,wscale 10], length 0&lt;BR /&gt;09:59:44.316678 IP 31.130.184.212.65130 &amp;gt; xyz.plus.com.25: Flags [S], seq 2057365693, win 29200, options [mss 1460,sackOK,TS val 105226491 ecr 0,nop,wscale 10], length 0&lt;BR /&gt;09:59:45.317048 IP 31.130.184.212.65130 &amp;gt; xyz.plus.com.25: Flags [S], seq 2057365693, win 29200, options [mss 1460,sackOK,TS val 105227492 ecr 0,nop,wscale 10], length 0&lt;BR /&gt;09:59:47.322705 IP 31.130.184.212.65130 &amp;gt; xyz.plus.com.25: Flags [S], seq 2057365693, win 29200, options [mss 1460,sackOK,TS val 105229496 ecr 0,nop,wscale 10], length 0&lt;BR /&gt;09:59:48.902652 IP 31.130.184.212.57472 &amp;gt; xyz.plus.com.25: Flags [S], seq 3052536268, win 29200, options [mss 1460,sackOK,TS val 105231077 ecr 0,nop,wscale 10], length 0&lt;BR /&gt;09:59:49.905247 IP 31.130.184.212.57472 &amp;gt; xyz.plus.com.25: Flags [S], seq 3052536268, win 29200, options [mss 1460,sackOK,TS val 105232080 ecr 0,nop,wscale 10], length 0&lt;BR /&gt;09:59:51.909787 IP 31.130.184.212.57472 &amp;gt; xyz.plus.com.25: Flags [S], seq 3052536268, win 29200, options [mss 1460,sackOK,TS val 105234084 ecr 0,nop,wscale 10], length 0&lt;BR /&gt;09:59:53.069672 IP 31.130.184.212.49828 &amp;gt; xyz.plus.com.25: Flags [S], seq 4179197362, win 29200, options [mss 1460,sackOK,TS val 105235244 ecr 0,nop,wscale 10], length 0&lt;BR /&gt;09:59:54.071154 IP 31.130.184.212.49828 &amp;gt; xyz.plus.com.25: Flags [S], seq 4179197362, win 29200, options [mss 1460,sackOK,TS val 105236246 ecr 0,nop,wscale 10], length 0&lt;BR /&gt;09:59:56.075674 IP 31.130.184.212.49828 &amp;gt; xyz.plus.com.25: Flags [S], seq 4179197362, win 29200, options [mss 1460,sackOK,TS val 105238248 ecr 0,nop,wscale 10], length 0&lt;BR /&gt;09:59:57.120618 IP 31.130.184.212.42130 &amp;gt; xyz.plus.com.25: Flags [S], seq 3530178217, win 29200, options [mss 1460,sackOK,TS val 105239293 ecr 0,nop,wscale 10], length 0&lt;BR /&gt;09:59:58.125054 IP 31.130.184.212.42130 &amp;gt; xyz.plus.com.25: Flags [S], seq 3530178217, win 29200, options [mss 1460,sackOK,TS val 105240296 ecr 0,nop,wscale 10], length 0&lt;/P&gt;</description>
      <pubDate>Wed, 15 Sep 2021 09:03:21 GMT</pubDate>
      <guid>https://community.plus.net/t5/Full-Fibre/Ongoing-DOS-attack-from-Iran/m-p/1828457#M126679</guid>
      <dc:creator>Monsoft</dc:creator>
      <dc:date>2021-09-15T09:03:21Z</dc:date>
    </item>
    <item>
      <title>Re: Ongoing DOS attack from Iran</title>
      <link>https://community.plus.net/t5/Full-Fibre/Ongoing-DOS-attack-from-Iran/m-p/1828494#M126684</link>
      <description>&lt;P&gt;If your system's secure, sit tight, eventually they'll give up and move on to someone else..........&lt;/P&gt;</description>
      <pubDate>Wed, 15 Sep 2021 12:11:29 GMT</pubDate>
      <guid>https://community.plus.net/t5/Full-Fibre/Ongoing-DOS-attack-from-Iran/m-p/1828494#M126684</guid>
      <dc:creator>Champnet</dc:creator>
      <dc:date>2021-09-15T12:11:29Z</dc:date>
    </item>
    <item>
      <title>Re: Ongoing DOS attack from Iran</title>
      <link>https://community.plus.net/t5/Full-Fibre/Ongoing-DOS-attack-from-Iran/m-p/1828504#M126687</link>
      <description>&lt;P&gt;I manage and design system for living so I'm not scare. Just was interested if Plusnet SOC/NOC have some IDS/IPS system which can used to prevent this kind of attacks.&lt;/P&gt;</description>
      <pubDate>Wed, 15 Sep 2021 13:04:14 GMT</pubDate>
      <guid>https://community.plus.net/t5/Full-Fibre/Ongoing-DOS-attack-from-Iran/m-p/1828504#M126687</guid>
      <dc:creator>Monsoft</dc:creator>
      <dc:date>2021-09-15T13:04:14Z</dc:date>
    </item>
    <item>
      <title>Re: Ongoing DOS attack from Iran</title>
      <link>https://community.plus.net/t5/Full-Fibre/Ongoing-DOS-attack-from-Iran/m-p/1828506#M126688</link>
      <description>&lt;P&gt;ISPs blocking IP addresses might be a Government decision, not for mere mortals like us.&lt;/P&gt;
&lt;P&gt;As you know, we can only block traffic at the point of entry to our building.&lt;/P&gt;</description>
      <pubDate>Wed, 15 Sep 2021 13:15:16 GMT</pubDate>
      <guid>https://community.plus.net/t5/Full-Fibre/Ongoing-DOS-attack-from-Iran/m-p/1828506#M126688</guid>
      <dc:creator>Champnet</dc:creator>
      <dc:date>2021-09-15T13:15:16Z</dc:date>
    </item>
    <item>
      <title>Re: Ongoing DOS attack from Iran</title>
      <link>https://community.plus.net/t5/Full-Fibre/Ongoing-DOS-attack-from-Iran/m-p/1828604#M126701</link>
      <description>&lt;P&gt;"&lt;SPAN&gt;ISPs blocking IP addresses might be a Government decision, not for mere mortals like us."&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Nah, I use to work for ISP for around 7 years and we use to have bunch of IPS'es which were analysing&amp;nbsp;traffic and blocked attacks. &lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I don't mind using my own solution to keep my network safe &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 16 Sep 2021 08:14:18 GMT</pubDate>
      <guid>https://community.plus.net/t5/Full-Fibre/Ongoing-DOS-attack-from-Iran/m-p/1828604#M126701</guid>
      <dc:creator>Monsoft</dc:creator>
      <dc:date>2021-09-16T08:14:18Z</dc:date>
    </item>
    <item>
      <title>Re: Ongoing DOS attack from Iran</title>
      <link>https://community.plus.net/t5/Full-Fibre/Ongoing-DOS-attack-from-Iran/m-p/1828607#M126703</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.plus.net/t5/user/viewprofilepage/user-id/70856"&gt;@Monsoft&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;
&lt;P&gt;&lt;SPAN&gt;Nah, I use to work for ISP for around 7 years and we use to have bunch of IPS'es which were analysing&amp;nbsp;traffic and blocked attacks. &lt;/SPAN&gt;&lt;/P&gt;
&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;Interesting, I've ran many installations including three Private Banking systems and I've never been able to get any ISP to block incoming traffic. Always given the same excuse...............&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 16 Sep 2021 08:32:50 GMT</pubDate>
      <guid>https://community.plus.net/t5/Full-Fibre/Ongoing-DOS-attack-from-Iran/m-p/1828607#M126703</guid>
      <dc:creator>Champnet</dc:creator>
      <dc:date>2021-09-16T08:32:50Z</dc:date>
    </item>
  </channel>
</rss>

