cancel
Showing results for 
Search instead for 
Did you mean: 

Is my plusnet router being Hacked?

agbaka
Newbie
Posts: 2
Registered: 03-12-2016

Is my plusnet router being Hacked?

Hello community, 

I have the new plusnet router and I am on the business package. Looking at the below logs, I get the impression that someone is remotely logging into my router? Is this a hack?  195.154.50.178 is particularly disturbing to me because as soon as I put it on google, I see tones of people talking about it being a hacker's well know ip. 

 

   
13:20:28, 03 Dec. IN: BLOCK [16] Remote administration (TCP [195.154.50.178]:44296-​>[81.174.143.210]:22 on ppp3)
11:13:09, 03 Dec. ath10: STA a4:db:30:81:72:95 IEEE 802.11: Client associated
11:04:37, 03 Dec. IN: BLOCK [16] Remote administration (TCP [123.31.34.213]:62120-​>[81.174.143.210]:22 on ppp3)
11:04:31, 03 Dec. IN: BLOCK [16] Remote administration (TCP [194.74.181.123]:35340-​>[81.174.143.210]:443 on ppp3)
10:55:11, 03 Dec. IN: BLOCK [16] Remote administration (TCP [74.82.47.55]:46157-​>[81.174.143.210]:443 on ppp3)
10:48:59, 03 Dec. IN: BLOCK [16] Remote administration (TCP [23.254.198.242]:41188-​>[81.174.143.210]:80 on ppp3)
10:46:16, 03 Dec. IN: BLOCK [16] Remote administration (TCP [194.74.181.123]:59628-​>[81.174.143.210]:80 on ppp3)
10:41:08, 03 Dec. IN: BLOCK [16] Remote administration (TCP [117.3.197.218]:52515-​>[81.174.143.210]:22 on ppp3)
6 REPLIES
Community Veteran
Posts: 4,766
Thanks: 1,051
Fixes: 27
Registered: 16-10-2014

Re: Is my plusnet router being Hacked?

As I read it I see there is BLOCK instruction so it would appear that someone is trying to gain access via HTTP / HTTPS and SSH but are being blocked by the router.

agbaka
Newbie
Posts: 2
Registered: 03-12-2016

Re: Is my plusnet router being Hacked?

If the  "BLOCK"   log entry implies a successful block action, then I'm relieved and definately inclined to agree with you. I have also raised a case with plus-net  support. I'll see what  their take on this is too. 

Cheers for responding so quickly   :-)

Much appreciated

Community Veteran
Posts: 4,766
Thanks: 1,051
Fixes: 27
Registered: 16-10-2014

Re: Is my plusnet router being Hacked?

@agbaka - Well if you don't ask you don't get, you are more than welcome.

Gel
Pro
Posts: 1,386
Thanks: 133
Fixes: 10
Registered: 02-08-2007

Re: Is my plusnet router being Hacked?

Len2
Dabbler
Posts: 21
Thanks: 3
Registered: 01-04-2009

Re: Is my plusnet router being Hacked?

Looking at router logs can be scarey.  In the last few minutes I had attempts at unauthorised access from S. Korea, France, China and Chicago.  You can become quite paranoid if you look at it too much, which is probably a good thing.

In general, your router firewall should drop all packets which originate from the internet as opposed to packets coming in response to your actions, like web browsing.  Also remote admin should be explicitly disabled unless you have a VERY good reason to need to reconfigure your router when you are not at home.  I don't know if your router allows it but I have mine set up to allow admin only from 2 specified IP addresses on my home (wired) network.

There are sites which will probe your internet IP and see if there are any holes in your filewall (ie open ports etc).  Ideally the router will not respond at all and will be invisible to unwanted visitors.

Gel
Pro
Posts: 1,386
Thanks: 133
Fixes: 10
Registered: 02-08-2007