Possible DoS attack from shadowserver.org
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Plusnet Community
- :
- Forum
- :
- Help with my Plusnet services
- :
- Full Fibre
- :
- Re: Possible DoS attack from shadowserver.org
Re: Possible DoS attack from shadowserver.org
07-10-2025 2:06 PM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
@Unst-Shetland If the fault is upstream of you, you are wasting your time with those proposals - they will achieve nothing.
Report your problem now - not in three months time.
Re: Possible DoS attack from shadowserver.org
10-10-2025 11:01 PM - edited 10-10-2025 11:06 PM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
---
Report your problem now - not in three months time.
---
Should I wait until the internet is actually not working, and its between 8am and 7.30pm when Plusnet support is open, or just report it any time during those working hours ?
Replacement cable appears not to have made any difference, see last day logfile:
9 * WAN connection WAN1_INTERNET_ETH disconnected.[ERROR_NO_CARRIER] since 7th October 2025.
Oh and the Plusnet router has a bug in its log display, it misses a line on the page at the top or bottom, I can't remember which.
I noticed when I compared the downloaded log to the displayed one in the router, since it was missing a [ERROR_NO_CARRIER] which I had seen earlier and suddenly wasn't visible, except in the downloaded copy.
Re: Possible DoS attack from shadowserver.org
11-10-2025 7:10 AM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
Should I wait until the internet is actually not working, and its between 8am and 7.30pm when Plusnet support is open, or just report it any time during those working hours ?
No - use the bot to report it - even if it is 'working' - the automated testing doesn't just look at the current state.
Re: Possible DoS attack from shadowserver.org
11-10-2025 7:38 AM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
@Dan_the_Van / @MisterW I think I'll leave this to you. No expert, but those numerous PADI/PADO/PADS entries seem suspicious?
Re: Possible DoS attack from shadowserver.org
11-10-2025 7:54 AM - edited 11-10-2025 7:57 AM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
@jab1 they're just another consequence of what seems to be an intermittent WAN connection.
In previous logs , the WAN connection was lost, fairly quickly came back and the PPPoE session was restored within a few seconds.
What seems to be happening now is that the PPPoE session is struggling to reestablish.
It sends the PADI, sometimes it gets the PADO reply, other times it doesnt and continues with PADI. Having got a PADO, it sends PADR expecting a PADS, to then go on complete the PPPoE setup. For many times in the log , it doesnt get the PADS, so times out and goes back to sending PADI. Eventually, it gets the PADS and goes on to setup the PPPoE connection.
Its all consistent with an intermittent connection somewhere between the router and the head-end.
As you said previously, @Unst-Shetland should report a fault now as whatever the problem was, it seems to be getting worse
Superusers are not staff, but they do have a direct line of communication into the business in order to raise issues, concerns and feedback from the community.
Re: Possible DoS attack from shadowserver.org
11-10-2025 7:58 AM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
Thanks, @MisterW , that is kind of what I thought, but it is good to have it confirmed. Hopefully, the OP will heed advice to report the error/fault.
Re: Possible DoS attack from shadowserver.org
11-10-2025 8:02 AM - edited 11-10-2025 8:04 AM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
I know it's a silly question, but you have removed the DSL cable from the Hub Two?
Please follow the advice to raise a fault, if no fault is detected when working then try when the fault is present.
Superusers are not staff, but they do have a direct line of communication into the business in order to raise issues, concerns and feedback from the community.
Re: Possible DoS attack from shadowserver.org
11-10-2025 8:57 AM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
---
I know it's a silly question, but you have removed the DSL cable from the Hub Two?
---
There are no silly questions. 🙂
Double checked, yes I had disconnected that already.
Reminds me when I used to do IT support and had a user who appeared to have an odd desktop issue, it was only after half an hour, I thought to ask, did they have the mouse the right way up !
As such, never assume anything, always ask. 🙂
Re: Possible DoS attack from shadowserver.org
11-10-2025 9:45 AM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
---
Hopefully, the OP will heed advice to report the error/fault.
---
Reported fault this morning ( 11th October 2025 ), no faults found their end with a quick check, as such they are sending out a new router, so at least if the problem continues, we know it is unlikely to be the router. ( Unless there is a bad batch.. )
Will know more in a couple of weeks I imagine, as things can take a long time to arrive here !
Re: Possible DoS attack from shadowserver.org
11-10-2025 9:51 AM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
Oh dear - the standard 'this will solve the problem' response, when we all know it will just drag the issue out.![]()
Re: Possible DoS attack from shadowserver.org
11-10-2025 10:01 AM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
You never know, this might just be the one time it actually is the router! but I doubt it...
Superusers are not staff, but they do have a direct line of communication into the business in order to raise issues, concerns and feedback from the community.
Re: Possible DoS attack from shadowserver.org
11-10-2025 10:09 AM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
@MisterW 😂
Re: Possible DoS attack from shadowserver.org
17-10-2025 10:18 AM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
Small update.
Router hasn't arrived yet. 🙂
We had a 18 hour power cut the other day, sadly the UPS only had enough battery to keep things working for 5 hours, so need a bigger one of those..
But interestingly, since then, no connection issues.
So maybe turning OpenReach equipment someplace away from the house, off and on again fixed the issue ?
I'd already tried that with the stuff in the house, but it made no difference.
Re: Possible DoS attack from shadowserver.org
17-10-2025 10:24 AM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
@Unst-Shetland What's your event log looking like now?
Re: Possible DoS attack from shadowserver.org
23-10-2025 10:09 AM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
Router has arrived, will fit it later today, for now the log file:
I think the key issues to note are as its the 23rd of October 2025 now:
---
18:11:12, 11 Oct. WAN connection WAN1_INTERNET_ETH disconnected.[ERROR_NO_CARRIER]
21:12:47, 10 Oct. WAN connection WAN1_INTERNET_ETH disconnected.[ERROR_NO_CARRIER]
20:38:18, 09 Oct. WAN connection WAN1_INTERNET_ETH disconnected.[ERROR_NO_CARRIER]
19:59:38, 09 Oct. WAN connection WAN1_INTERNET_ETH disconnected.[ERROR_NO_CARRIER]
19:57:31, 09 Oct. WAN connection WAN1_INTERNET_ETH disconnected.[ERROR_NO_CARRIER]
19:46:40, 09 Oct. WAN connection WAN1_INTERNET_ETH disconnected.[ERROR_NO_CARRIER]
20:01:46, 07 Oct. WAN connection WAN1_INTERNET_ETH disconnected.[ERROR_NO_CARRIER]
17:59:13, 07 Oct. WAN connection WAN1_INTERNET_ETH disconnected.[ERROR_NO_CARRIER]
17:27:54, 07 Oct. WAN connection WAN1_INTERNET_ETH disconnected.[ERROR_NO_CARRIER]
13:53:15, 07 Oct. WAN connection WAN1_INTERNET_ETH disconnected.[ERROR_NO_CARRIER]
19:26:48, 06 Oct. WAN connection WAN1_INTERNET_ETH disconnected.[ERROR_NO_CARRIER]
18:51:50, 06 Oct. WAN connection WAN1_INTERNET_ETH disconnected.[ERROR_NO_CARRIER]
21:05:58, 05 Oct. WAN connection WAN1_INTERNET_ETH disconnected.[ERROR_NO_CARRIER]
20:47:40, 05 Oct. WAN connection WAN1_INTERNET_ETH disconnected.[ERROR_NO_CARRIER]
12:00:54, 05 Oct. WAN connection WAN1_INTERNET_ETH disconnected.[ERROR_NO_CARRIER]
16:37:31, 04 Oct. WAN connection WAN1_INTERNET_ETH disconnected.[ERROR_NO_CARRIER]
15:59:18, 04 Oct. WAN connection WAN1_INTERNET_ETH disconnected.[ERROR_NO_CARRIER]
14:22:25, 04 Oct. WAN connection WAN1_INTERNET_ETH disconnected.[ERROR_NO_CARRIER]
14:20:58, 04 Oct. WAN connection WAN1_INTERNET_ETH disconnected.[ERROR_NO_CARRIER]
14:17:17, 04 Oct. WAN connection WAN1_INTERNET_ETH disconnected.[ERROR_NO_CARRIER]
21:01:02, 03 Oct. WAN connection WAN1_INTERNET_ETH disconnected.[ERROR_NO_CARRIER]
17:37:19, 03 Oct. WAN connection WAN1_INTERNET_ETH disconnected.[ERROR_NO_CARRIER]
19:24:57, 02 Oct. WAN connection WAN1_INTERNET_ETH disconnected.[ERROR_NO_CARRIER]
18:44:12, 02 Oct. WAN connection WAN1_INTERNET_ETH disconnected.[ERROR_NO_CARRIER]
18:17:24, 02 Oct. WAN connection WAN1_INTERNET_ETH disconnected.[ERROR_NO_CARRIER]
18:57:38, 01 Oct. WAN connection WAN1_INTERNET_ETH disconnected.[ERROR_NO_CARRIER]
19:27:23, 30 Sep. WAN connection WAN1_INTERNET_ETH disconnected.[ERROR_NO_CARRIER]
---
12th of October 2025 and onwards, no "[ERROR_NO_CARRIER]" appearing, after the large scale 18 hour powercut here.
So perhaps I should hold off changing the router for now !
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Plusnet Community
- :
- Forum
- :
- Help with my Plusnet services
- :
- Full Fibre
- :
- Re: Possible DoS attack from shadowserver.org