<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: DDOS to my router in Tech Help - Software/Hardware etc</title>
    <link>https://community.plus.net/t5/Tech-Help-Software-Hardware-etc/DDOS-to-my-router/m-p/1488427#M79909</link>
    <description>&lt;P&gt;&amp;nbsp;So get yourself a plusnet hubone. That has no visible logging so you won't be able to see the attacks to worry about them&amp;nbsp;&lt;img class="lia-deferred-image lia-image-emoji" src="https://community.plus.net/html/@8BBE3DF35B52AAD1B52BEBDC4974E1AD/images/emoticons/tongue.gif" alt="Tongue" title="Tongue" /&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#FF0000"&gt;EDIT: Actually it does log stuff.. sorry i only found that around 10 minutes later when trying to do something else in the admin pages.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;Incidentally I have port 80 open and redirected to my desktop PC for the apache webserver. When i look in the database i can see loads of bots have been trying to exploit phpmyadmin setup script logs and various other things. People are out there scanning and attempting to attack all the time. In my case they make contact with the default host on my apache which has one web page and nothing else. My actual websites are all on virtual hosts and the admin site with phpmyadmin installed is on a virtual host only accessible to the local network.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I've accepted that they'll always be there trying.. it's just one of those things.&lt;/P&gt;</description>
    <pubDate>Thu, 02 Nov 2017 20:48:10 GMT</pubDate>
    <dc:creator>7up</dc:creator>
    <dc:date>2017-11-02T20:48:10Z</dc:date>
    <item>
      <title>DDOS to my router</title>
      <link>https://community.plus.net/t5/Tech-Help-Software-Hardware-etc/DDOS-to-my-router/m-p/1488010#M79894</link>
      <description>&lt;P&gt;Why would someone attack my router continuously for the last several days (at least)?&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;[DoS attack: TCP SYN Flood] multi-source syn flood attack in last 20 sec , Tuesday, Oct 31,2017 23:02:57&lt;BR /&gt;[DoS attack: TCP SYN Flood] multi-source syn flood attack in last 20 sec , Tuesday, Oct 31,2017 23:02:44&lt;BR /&gt;[DoS attack: TCP SYN Flood] multi-source syn flood attack in last 20 sec , Tuesday, Oct 31,2017 23:02:33&lt;BR /&gt;[DoS attack: TCP SYN Flood] multi-source syn flood attack in last 20 sec , Tuesday, Oct 31,2017 23:02:19&lt;BR /&gt;[DoS attack: TCP SYN Flood] multi-source syn flood attack in last 20 sec , Tuesday, Oct 31,2017 23:02:09&lt;BR /&gt;[DoS attack: TCP SYN Flood] multi-source syn flood attack in last 20 sec , Tuesday, Oct 31,2017 23:01:58&lt;BR /&gt;[DoS attack: TCP SYN Flood] multi-source syn flood attack in last 20 sec , Tuesday, Oct 31,2017 23:01:48&lt;BR /&gt;[DoS attack: TCP SYN Flood] multi-source syn flood attack in last 20 sec , Tuesday, Oct 31,2017 23:01:35&lt;BR /&gt;[DoS attack: TCP SYN Flood] multi-source syn flood attack in last 20 sec , Tuesday, Oct 31,2017 23:01:23&lt;BR /&gt;[DoS attack: TCP SYN Flood] multi-source syn flood attack in last 20 sec , Tuesday, Oct 31,2017 23:01:13&lt;BR /&gt;[DoS attack: TCP SYN Flood] multi-source syn flood attack in last 20 sec , Tuesday, Oct 31,2017 23:01:03&lt;BR /&gt;[DoS attack: TCP SYN Flood] multi-source syn flood attack in last 20 sec , Tuesday, Oct 31,2017 23:00:50&lt;BR /&gt;[DoS attack: TCP SYN Flood] multi-source syn flood attack in last 20 sec , Tuesday, Oct 31,2017 23:00:40&lt;BR /&gt;[DoS attack: TCP SYN Flood] multi-source syn flood attack in last 20 sec , Tuesday, Oct 31,2017 23:00:27&lt;BR /&gt;[DoS attack: TCP SYN Flood] multi-source syn flood attack in last 20 sec , Tuesday, Oct 31,2017 23:00:14&lt;/P&gt;
&lt;P&gt;etc...&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;</description>
      <pubDate>Tue, 31 Oct 2017 23:03:31 GMT</pubDate>
      <guid>https://community.plus.net/t5/Tech-Help-Software-Hardware-etc/DDOS-to-my-router/m-p/1488010#M79894</guid>
      <dc:creator>VileReynard</dc:creator>
      <dc:date>2017-10-31T23:03:31Z</dc:date>
    </item>
    <item>
      <title>Re: DDOS to my router</title>
      <link>https://community.plus.net/t5/Tech-Help-Software-Hardware-etc/DDOS-to-my-router/m-p/1488012#M79895</link>
      <description>&lt;P&gt;Who have you been upsetting now?&amp;nbsp;&lt;img class="lia-deferred-image lia-image-emoji" src="https://community.plus.net/html/@97BD05876B0DD98759CC3DB9CDDC9852/images/emoticons/knuppel2.gif" alt="Knuppel" title="Knuppel" /&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 31 Oct 2017 23:41:45 GMT</pubDate>
      <guid>https://community.plus.net/t5/Tech-Help-Software-Hardware-etc/DDOS-to-my-router/m-p/1488012#M79895</guid>
      <dc:creator>7up</dc:creator>
      <dc:date>2017-10-31T23:41:45Z</dc:date>
    </item>
    <item>
      <title>Re: DDOS to my router</title>
      <link>https://community.plus.net/t5/Tech-Help-Software-Hardware-etc/DDOS-to-my-router/m-p/1488020#M79896</link>
      <description>Perhaps they know you?</description>
      <pubDate>Wed, 01 Nov 2017 00:37:14 GMT</pubDate>
      <guid>https://community.plus.net/t5/Tech-Help-Software-Hardware-etc/DDOS-to-my-router/m-p/1488020#M79896</guid>
      <dc:creator>Browni</dc:creator>
      <dc:date>2017-11-01T00:37:14Z</dc:date>
    </item>
    <item>
      <title>Re: DDOS to my router</title>
      <link>https://community.plus.net/t5/Tech-Help-Software-Hardware-etc/DDOS-to-my-router/m-p/1488039#M79897</link>
      <description>&lt;P&gt;the anti fox hunting brigade &lt;img class="lia-deferred-image lia-image-emoji" src="https://community.plus.net/html/@D10385D46FF09B2E8FF20B0746B65E6F/images/emoticons/shocked.gif" alt="Shocked" title="Shocked" /&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 01 Nov 2017 08:24:08 GMT</pubDate>
      <guid>https://community.plus.net/t5/Tech-Help-Software-Hardware-etc/DDOS-to-my-router/m-p/1488039#M79897</guid>
      <dc:creator>Oldjim</dc:creator>
      <dc:date>2017-11-01T08:24:08Z</dc:date>
    </item>
    <item>
      <title>Re: DDOS to my router</title>
      <link>https://community.plus.net/t5/Tech-Help-Software-Hardware-etc/DDOS-to-my-router/m-p/1488050#M79898</link>
      <description>&lt;P&gt;I think you can report that by email to abuse@plus.net&lt;/P&gt;
&lt;P&gt;Do you have the Plusnet firewall on?&lt;/P&gt;</description>
      <pubDate>Wed, 01 Nov 2017 09:17:47 GMT</pubDate>
      <guid>https://community.plus.net/t5/Tech-Help-Software-Hardware-etc/DDOS-to-my-router/m-p/1488050#M79898</guid>
      <dc:creator>jelv</dc:creator>
      <dc:date>2017-11-01T09:17:47Z</dc:date>
    </item>
    <item>
      <title>Re: DDOS to my router</title>
      <link>https://community.plus.net/t5/Tech-Help-Software-Hardware-etc/DDOS-to-my-router/m-p/1488111#M79900</link>
      <description>&lt;P&gt;I don't have the Plusnet firewall switched on, I never had had.&lt;/P&gt;
&lt;P&gt;A SYN attack uses random ports in an attempt to overload a connection.&lt;/P&gt;
&lt;P&gt;My 65/18 connection was severely impacted at times.&lt;/P&gt;
&lt;P&gt;I've just tried disconnecting the router for a few minutes and Plusnet have finally allocated me a new IP address.&lt;/P&gt;
&lt;P&gt;So it is now "cured".&lt;/P&gt;
&lt;P&gt;But if your IP address is x.x.89.61 then you may encounter problems.&lt;img class="lia-deferred-image lia-image-emoji" src="https://community.plus.net/html/@5CA762C7B9B1D4AB36AAB959133ED0B4/images/emoticons/angry.gif" alt="Angry" title="Angry" /&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 01 Nov 2017 13:15:32 GMT</pubDate>
      <guid>https://community.plus.net/t5/Tech-Help-Software-Hardware-etc/DDOS-to-my-router/m-p/1488111#M79900</guid>
      <dc:creator>VileReynard</dc:creator>
      <dc:date>2017-11-01T13:15:32Z</dc:date>
    </item>
    <item>
      <title>Re: DDOS to my router</title>
      <link>https://community.plus.net/t5/Tech-Help-Software-Hardware-etc/DDOS-to-my-router/m-p/1488327#M79907</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.plus.net/t5/user/viewprofilepage/user-id/5427"&gt;@VileReynard&lt;/a&gt; wrote:&lt;BR /&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;But if your IP address is x.x.89.61 then you may encounter problems.&lt;img class="lia-deferred-image lia-image-emoji" src="https://community.plus.net/html/@5CA762C7B9B1D4AB36AAB959133ED0B4/images/emoticons/angry.gif" alt="Angry" title="Angry" /&gt;&lt;/P&gt;
&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;So for your sins you've passed the buck to some other poor soul.&lt;/P&gt;</description>
      <pubDate>Thu, 02 Nov 2017 12:20:44 GMT</pubDate>
      <guid>https://community.plus.net/t5/Tech-Help-Software-Hardware-etc/DDOS-to-my-router/m-p/1488327#M79907</guid>
      <dc:creator>7up</dc:creator>
      <dc:date>2017-11-02T12:20:44Z</dc:date>
    </item>
    <item>
      <title>Re: DDOS to my router</title>
      <link>https://community.plus.net/t5/Tech-Help-Software-Hardware-etc/DDOS-to-my-router/m-p/1488354#M79908</link>
      <description>&lt;P&gt;And after a few hours delay it followed me to my IP address (146.198.x.x) - there doesn't appear to be much point in secrecy since every man and his dog has decided to practice SYN attacks on it.&lt;/P&gt;
&lt;P&gt;I expect the entire Plusnet IP range is being attacked?&lt;/P&gt;
&lt;P&gt;It's so pointless, especially when I have no port forwarding.&lt;/P&gt;
&lt;P&gt;A whois gives&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;whois 146.198.x.x&lt;/P&gt;
&lt;P&gt;...&lt;/P&gt;
&lt;P&gt;NetRange:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 146.198.0.0 - 146.198.255.255&lt;BR /&gt;CIDR:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 146.198.0.0/16&lt;BR /&gt;NetName:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; PLUSNET3&lt;BR /&gt;NetHandle:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; NET-146-198-0-0-1&lt;BR /&gt;Parent:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; NET146 (NET-146-0-0-0-0)&lt;BR /&gt;NetType:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Direct Assignment&lt;BR /&gt;OriginAS:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; AS6871&lt;BR /&gt;Organization:&amp;nbsp;&amp;nbsp; INFONET Services Corporation (INFO)&lt;BR /&gt;RegDate:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1991-02-28&lt;BR /&gt;Updated:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 2015-03-12&lt;BR /&gt;Ref:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;A href="https://whois.arin.net/rest/net/NET-146-198-0-0-1" target="_blank"&gt;https://whois.arin.net/rest/net/NET-146-198-0-0-1&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;OrgName:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; INFONET Services Corporation&lt;BR /&gt;OrgId:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; INFO&lt;BR /&gt;Address:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 2160 East Grand Avenue&lt;BR /&gt;City:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; El Segundo&lt;BR /&gt;StateProv:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; CA&lt;BR /&gt;PostalCode:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 90245-1022&lt;BR /&gt;Country:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; US&lt;BR /&gt;RegDate:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&lt;BR /&gt;Updated:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 2017-01-28&lt;BR /&gt;Ref:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; &lt;A href="https://whois.arin.net/rest/org/INFO" target="_blank"&gt;https://whois.arin.net/rest/org/INFO&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;...&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;P&gt;Is this right?&lt;/P&gt;
&lt;P&gt;&lt;FONT color="green"&gt;Moderator's note by Mike (Mav): Full IP address edited in a public forum.&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 03 Nov 2017 07:18:57 GMT</pubDate>
      <guid>https://community.plus.net/t5/Tech-Help-Software-Hardware-etc/DDOS-to-my-router/m-p/1488354#M79908</guid>
      <dc:creator>VileReynard</dc:creator>
      <dc:date>2017-11-03T07:18:57Z</dc:date>
    </item>
    <item>
      <title>Re: DDOS to my router</title>
      <link>https://community.plus.net/t5/Tech-Help-Software-Hardware-etc/DDOS-to-my-router/m-p/1488427#M79909</link>
      <description>&lt;P&gt;&amp;nbsp;So get yourself a plusnet hubone. That has no visible logging so you won't be able to see the attacks to worry about them&amp;nbsp;&lt;img class="lia-deferred-image lia-image-emoji" src="https://community.plus.net/html/@8BBE3DF35B52AAD1B52BEBDC4974E1AD/images/emoticons/tongue.gif" alt="Tongue" title="Tongue" /&gt;&lt;/P&gt;
&lt;P&gt;&lt;FONT color="#FF0000"&gt;EDIT: Actually it does log stuff.. sorry i only found that around 10 minutes later when trying to do something else in the admin pages.&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;Incidentally I have port 80 open and redirected to my desktop PC for the apache webserver. When i look in the database i can see loads of bots have been trying to exploit phpmyadmin setup script logs and various other things. People are out there scanning and attempting to attack all the time. In my case they make contact with the default host on my apache which has one web page and nothing else. My actual websites are all on virtual hosts and the admin site with phpmyadmin installed is on a virtual host only accessible to the local network.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I've accepted that they'll always be there trying.. it's just one of those things.&lt;/P&gt;</description>
      <pubDate>Thu, 02 Nov 2017 20:48:10 GMT</pubDate>
      <guid>https://community.plus.net/t5/Tech-Help-Software-Hardware-etc/DDOS-to-my-router/m-p/1488427#M79909</guid>
      <dc:creator>7up</dc:creator>
      <dc:date>2017-11-02T20:48:10Z</dc:date>
    </item>
    <item>
      <title>Re: DDOS to my router</title>
      <link>https://community.plus.net/t5/Tech-Help-Software-Hardware-etc/DDOS-to-my-router/m-p/1488438#M79910</link>
      <description>&lt;P&gt;I would be checking my PC's/Laptops with Malwarebytes ad all the antivirus software I could find, there is a good chance that something on one of your devices is call somewhere to start these DDOS attacks.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As for the IP address, it is well known that PN have used other BT division addresses when they expanded their network, and that many of the IP address checkers are out of date. It can cause access difficulty's with some sites, but these seem to be getting less troublesome.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 02 Nov 2017 20:44:13 GMT</pubDate>
      <guid>https://community.plus.net/t5/Tech-Help-Software-Hardware-etc/DDOS-to-my-router/m-p/1488438#M79910</guid>
      <dc:creator>Mustrum</dc:creator>
      <dc:date>2017-11-02T20:44:13Z</dc:date>
    </item>
  </channel>
</rss>

