<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Problem with Fraggle DDOS attack in Tech Help - Software/Hardware etc</title>
    <link>https://community.plus.net/t5/Tech-Help-Software-Hardware-etc/Problem-with-Fraggle-DDOS-attack/m-p/1566549#M83497</link>
    <description>&lt;P&gt;Handn't considered that&amp;nbsp; yes there are two Draytek VDSL modems - what a plum I am, should have realised. Good of Draytek to record this as an DDOS.&lt;/P&gt;
&lt;P&gt;Cheers!!!&lt;/P&gt;</description>
    <pubDate>Fri, 31 Aug 2018 17:09:25 GMT</pubDate>
    <dc:creator>LODGIE_</dc:creator>
    <dc:date>2018-08-31T17:09:25Z</dc:date>
    <item>
      <title>Problem with Fraggle DDOS attack</title>
      <link>https://community.plus.net/t5/Tech-Help-Software-Hardware-etc/Problem-with-Fraggle-DDOS-attack/m-p/1566217#M83487</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;We have two routers, a Vigor 2850 on a copper cct and a Vigor 2930 on a fibre cct (there's a good reason for this, BT are saying the 2850 has a fault when it's the fibre cct so the 2930 is running fibre only - still getting the fault). These are on the same site and both are logging Fraggle attacks every 10 seconds, this has been happening for the last 36 hours.&lt;BR /&gt;&lt;BR /&gt;Both routers are on static IP's, the 2850 is running 10 VPN's&lt;BR /&gt;&lt;BR /&gt;The 2850 was disconnected from the WAN last night (schedule) but on reconnection started logging an attack straight away.&lt;BR /&gt;&lt;BR /&gt;All the PC's on site have been virus scanned and are clean, although this is not a 100% guarantee&lt;BR /&gt;&lt;BR /&gt;Wireshark is running on a Win 2008 R2 server and is not showing any odd internal traffic so the firewall is working perfectly.&lt;BR /&gt;&lt;BR /&gt;One attack is showing a source of 0.0.0.0:nnnn with the port address incrementing randomly the target address is 255.255.255.255:4944 UDP hlen=20 tlen=144&lt;BR /&gt;The other is the same except the source address is 255.255.255.255&lt;BR /&gt;&lt;BR /&gt;This is not causing problems at the moment but I have a few concerns&lt;BR /&gt;1. It's odd getting an attack on 2 separate circuits at the same time when the only common denominator is the LAN and the kit on it - any advice on further checks I could make locally?&lt;BR /&gt;2. If this is targetted, what are the chances that it will just go away or they may try another method?&lt;BR /&gt;3. Any ideas on the usual delivery method that woud trigger attacks?&lt;/P&gt;</description>
      <pubDate>Thu, 30 Aug 2018 13:09:15 GMT</pubDate>
      <guid>https://community.plus.net/t5/Tech-Help-Software-Hardware-etc/Problem-with-Fraggle-DDOS-attack/m-p/1566217#M83487</guid>
      <dc:creator>LODGIE_</dc:creator>
      <dc:date>2018-08-30T13:09:15Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with Fraggle DDOS attack</title>
      <link>https://community.plus.net/t5/Tech-Help-Software-Hardware-etc/Problem-with-Fraggle-DDOS-attack/m-p/1566232#M83489</link>
      <description>&lt;P&gt;&lt;a href="https://community.plus.net/t5/user/viewprofilepage/user-id/58491"&gt;@LODGIE_&lt;/a&gt; -&amp;nbsp; Assuming you’ve not done it already go to Firewall &amp;gt; DoS Defense enable it and the SYN, UDP and ICMP flood options.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="DoS Defence"&gt;&lt;img src="https://community.plus.net/skins/images/A0C0974F08C2F141307C5AA348823F1B/responsive_peak/images/image_not_found.png" alt="DoS Defence" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Hope this helps.&lt;/P&gt;
&lt;P&gt;Most routers are immune to this but no harm in some belt and braces.&lt;/P&gt;</description>
      <pubDate>Thu, 30 Aug 2018 13:32:56 GMT</pubDate>
      <guid>https://community.plus.net/t5/Tech-Help-Software-Hardware-etc/Problem-with-Fraggle-DDOS-attack/m-p/1566232#M83489</guid>
      <dc:creator>Anonymous</dc:creator>
      <dc:date>2018-08-30T13:32:56Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with Fraggle DDOS attack</title>
      <link>https://community.plus.net/t5/Tech-Help-Software-Hardware-etc/Problem-with-Fraggle-DDOS-attack/m-p/1566367#M83493</link>
      <description>&lt;P&gt;Thanks for the response. All firewalls cranked to max, it's not getting through... Still getting the broadcast packets every 10 sec though. Waiting for a change of attack type now.&lt;/P&gt;</description>
      <pubDate>Fri, 31 Aug 2018 07:17:44 GMT</pubDate>
      <guid>https://community.plus.net/t5/Tech-Help-Software-Hardware-etc/Problem-with-Fraggle-DDOS-attack/m-p/1566367#M83493</guid>
      <dc:creator>LODGIE_</dc:creator>
      <dc:date>2018-08-31T07:17:44Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with Fraggle DDOS attack</title>
      <link>https://community.plus.net/t5/Tech-Help-Software-Hardware-etc/Problem-with-Fraggle-DDOS-attack/m-p/1566517#M83495</link>
      <description>&lt;P&gt;Is there a Draytek VDSL2 modem involved somewhere? Apparently UDP port 4944 is where Draytek modems broadcast their DSL stats to (this can be used by some Draytek routers to display the DSL stats of the separate modem).&lt;/P&gt;</description>
      <pubDate>Fri, 31 Aug 2018 14:56:10 GMT</pubDate>
      <guid>https://community.plus.net/t5/Tech-Help-Software-Hardware-etc/Problem-with-Fraggle-DDOS-attack/m-p/1566517#M83495</guid>
      <dc:creator>ejs</dc:creator>
      <dc:date>2018-08-31T14:56:10Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with Fraggle DDOS attack</title>
      <link>https://community.plus.net/t5/Tech-Help-Software-Hardware-etc/Problem-with-Fraggle-DDOS-attack/m-p/1566549#M83497</link>
      <description>&lt;P&gt;Handn't considered that&amp;nbsp; yes there are two Draytek VDSL modems - what a plum I am, should have realised. Good of Draytek to record this as an DDOS.&lt;/P&gt;
&lt;P&gt;Cheers!!!&lt;/P&gt;</description>
      <pubDate>Fri, 31 Aug 2018 17:09:25 GMT</pubDate>
      <guid>https://community.plus.net/t5/Tech-Help-Software-Hardware-etc/Problem-with-Fraggle-DDOS-attack/m-p/1566549#M83497</guid>
      <dc:creator>LODGIE_</dc:creator>
      <dc:date>2018-08-31T17:09:25Z</dc:date>
    </item>
  </channel>
</rss>

