cancel
Showing results for 
Search instead for 
Did you mean: 

Apparent DoS attack from PN ?

Sir_Lurkalot
Grafter
Posts: 42
Registered: 30-07-2007

Apparent DoS attack from PN ?

Hi
I've just corrected my email entries in my new Netgear router and am getting one of these every couple of minutes.
[DoS attack: ACK Scan] from source: 84.93.229.133:14300
These are interspersed with other odd non-PN address, far more than I ever noticed with my previous router, when I might get a couple of odd ones a month.
Is there anything I can do to stop the PN ones and OOI what are they?
Cheers
6 REPLIES
Sir_Lurkalot
Grafter
Posts: 42
Registered: 30-07-2007

Re: Apparent DoS attack from PN ?

Further to the above, some are from port 80
Plusnet Help Team
Plusnet Help Team
Posts: 13,491
Thanks: 248
Fixes: 68
Registered: 27-04-2007

Re: Apparent DoS attack from PN ?

Quote
84.93.229.133

That's part of our mail platform, do you have anything set up that's automatically checking for mail?
If this post resolved your issue please click the 'This fixed my problem' button
 Adam Walker
 Plusnet Help Team
Sir_Lurkalot
Grafter
Posts: 42
Registered: 30-07-2007

Re: Apparent DoS attack from PN ?

Hi
It looks as if my incorrect mail server setting initiated the reports and it took a few minutes to straighten itself out.
Thanks
Sir_Lurkalot
Grafter
Posts: 42
Registered: 30-07-2007

Re: Apparent DoS attack from PN ?

My hopes were premature !  This is just a small section of yesterday's log.
[DoS attack: ACK Scan] from source: 84.93.238.164:14300 Thursday, August 15,2013 06:18:51       
[DoS attack: ACK Scan] from source: 84.93.238.164:14300 Thursday, August 15,2013 06:18:14       
[DoS attack: ACK Scan] from source: 84.93.238.164:14300 Thursday, August 15,2013 06:17:38       
[DoS attack: ACK Scan] from source: 84.93.229.195:14300 Thursday, August 15,2013 05:48:21       
[DoS attack: ACK Scan] from source: 84.93.229.195:14300 Thursday, August 15,2013 05:47:43       
[DoS attack: ACK Scan] from source: 84.93.229.195:14300 Thursday, August 15,2013 05:47:06       
[DHCP IP: (192.168.0.5)] to MAC address 1C:5A:3E:4F:5CCheesy0 Thursday, August 15,2013 05:33:31       
[DoS attack: ACK Scan] from source: 84.93.238.68:14300 Thursday, August 15,2013 05:17:38       
[DoS attack: ACK Scan] from source: 84.93.238.68:14300 Thursday, August 15,2013 05:17:06       
[DoS attack: ACK Scan] from source: 84.93.238.68:14300 Thursday, August 15,2013 05:16:34       
[DoS attack: ACK Scan] from source: 84.93.229.227:14300 Thursday, August 15,2013 05:07:14       
[DoS attack: ACK Scan] from source: 84.93.229.227:14300 Thursday, August 15,2013 05:06:40       
[DoS attack: ACK Scan] from source: 84.93.229.227:14300 Thursday, August 15,2013 05:06:06       
[DoS attack: ACK Scan] from source: 84.93.229.131:14300 Thursday, August 15,2013 04:46:51       
[DoS attack: ACK Scan] from source: 84.93.229.131:14300 Thursday, August 15,2013 04:46:15       
[DoS attack: ACK Scan] from source: 84.93.229.131:14300 Thursday, August 15,2013 04:45:39       
[DoS attack: ACK Scan] from source: 84.93.238.164:14300 Thursday, August 15,2013 04:16:21       
[DoS attack: ACK Scan] from source: 84.93.238.164:14300 Thursday, August 15,2013 04:15:44       
[DoS attack: ACK Scan] from source: 84.93.238.164:14300 Thursday, August 15,2013 04:15:08       
[DHCP IP: (192.168.0.5)] to MAC address 1C:5A:3E:4F:5CCheesy0 Thursday, August 15,2013 03:55:35       
[DoS attack: ACK Scan] from source: 84.93.238.136:14300 Thursday, August 15,2013 03:45:51       
[DoS attack: ACK Scan] from source: 84.93.238.136:14300 Thursday, August 15,2013 03:45:15       
[DoS attack: ACK Scan] from source: 84.93.238.136:14300 Thursday, August 15,2013 03:44:39       
[DoS attack: ACK Scan] from source: 212.28.230.162:80 Thursday, August 15,2013 03:33:28       
[DoS attack: ACK Scan] from source: 84.93.229.69:14300 Thursday, August 15,2013 03:15:14       
[DoS attack: ACK Scan] from source: 84.93.229.69:14300 Thursday, August 15,2013 03:14:40       
[DoS attack: ACK Scan] from source: 84.93.229.69:14300 Thursday, August 15,2013 03:14:06       
[DoS attack: ACK Scan] from source: 84.93.238.228:14300 Thursday, August 15,2013 02:44:52       
[DoS attack: ACK Scan] from source: 84.93.238.228:14300 Thursday, August 15,2013 02:44:14       
[DoS attack: ACK Scan] from source: 84.93.238.228:14300 Thursday, August 15,2013 02:43:37       
[DoS attack: ACK Scan] from source: 212.28.230.162:80 Thursday, August 15,2013 02:20:29       
[DoS attack: ACK Scan] from source: 84.93.229.69:14300 Thursday, August 15,2013 02:14:28       
[DoS attack: ACK Scan] from source: 84.93.229.69:14300 Thursday, August 15,2013 02:13:49       
[DoS attack: ACK Scan] from source: 84.93.229.69:14300 Thursday, August 15,2013 02:13:11       
[DoS attack: ACK Scan] from source: 84.93.238.168:14300 Thursday, August 15,2013 01:44:07       
[DoS attack: ACK Scan] from source: 84.93.238.168:14300 Thursday, August 15,2013 01:43:35   
Has anyone an explanation please ?
Cheers
Plusnet Alumni (retired) orbrey
Plusnet Alumni (retired)
Posts: 10,540
Registered: 18-07-2007

Re: Apparent DoS attack from PN ?

Hi there,
ACK hints that the server is trying to respond to something, so either there is something on your network trying to access your mail via IMAP or packets are getting dropped somewhere - if you're not seeing many errors on your router stats then chances are it's the former and something is trying to get mail which the ACKs are in response to.
Sir_Lurkalot
Grafter
Posts: 42
Registered: 30-07-2007

Re: Apparent DoS attack from PN ?


Thanks for the pointer. It was my wife's new out of control tablet.  Now tamed.