NetStumbler.org Forums

Go Back   NetStumbler.org Forums > WiFi Forums > Hardware
Register Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
Old 02-27-2007   #1 (permalink)
yeehi
Registered Member
 
Join Date: Feb 2007
Posts: 12
Question I am attacked

I am sorry to ask about this one, but you know well how to fix this sort of problem.

My wireless router is working intermittantly. I have tried everything to fix it, but I just got two more clues, which I didn't know about before:

1. The security report in the wireless router says there is an attack:

Tue Feb 27 17:43:54 2007 =>Found attack from 60.51.54.64. Source port is 3978 and destination port is 48475 which use the TCP protocol.

Just now there is only one attack. A few days ago, there were many, many similar ones, all happening at the same time, going for the same port.

Sun Feb 25 10:56:30 2007 =>Found attack from 203.122.247.41. Source port is 1642 and destination port is 35192 which use the TCP protocol. Sun Feb 25 10:56:30 2007 =>Found attack from 12.214.248.81. Source port is 3654 and destination port is 35192 which use the TCP protocol. Sun Feb 25 10:56:30 2007 =>Found attack from 74.117.49.2. Source port is 33337 and destination port is 35192 which use the TCP protocol. Sun Feb 25 10:56:30 2007 =>Found attack from 72.76.28.88. Source port is 4744 and destination port is 35192 which use the TCP protocol. Sun Feb 25 10:56:30 2007 =>Found attack from 80.166.178.76. Source port is 1797 and destination port is 35192 which use the TCP protocol. Sun Feb 25 10:56:30 2007 =>Found attack from 74.12.56.118. Source port is 60976 and destination port is 35192 which use the TCP protocol. Sun Feb 25 10:56:30 2007 =>Found attack from 84.94.61.198 . Source port is 1656 and destination port is 35192 which use the TCP protocol. Sun Feb 25 10:56:30 2007 =>Found attack from 83.101.25.76. Source port is 46351 and destination port is 35192 which use the TCP protocol. Sun Feb 25 10:56:30 2007 =>Found attack from 82.239.208.201. Source port is 2049 and destination port is 35192 which use the TCP protocol. Sun Feb 25 10:56:30 2007 =>Found attack from 172.213.41.60 . Source port is 4701 and destination port is 35192 which use the TCP protocol. Sun Feb 25 10:56:30 2007 =>Found attack from 70.71.15.211. Source port is 60927 and destination port is 35192 which use the TCP protocol. Sun Feb 25 10:56:30 2007 =>Found attack from 195.132.203.205. Source port is 3777 and destination port is 35192 which use the TCP protocol. Sun Feb 25 10:56:30 2007 =>Found attack from 69.249.14.191 . Source port is 4583 and destination port is 35192 which use the TCP protocol. Sun Feb 25 10:56:30 2007 =>Found attack from 68.168.216.73. Source port is 59049 and destination port is 35192 which use the TCP protocol. Sun Feb 25 10:56:30 2007 =>Found attack from 84.94.184.42. Source port is 1497 and destination port is 35192 which use the TCP protocol. Sun Feb 25 10:56:30 2007 =>Found attack from 222.93.12.125 . Source port is 19527 and destination port is 35192 which use the TCP protocol. Sun Feb 25 10:56:30 2007 =>Found attack from 206.209.15.62. Source port is 59411 and destination port is 35192 which use the TCP protocol. Sun Feb 25 10:56:30 2007 =>Found attack from 87.65.178.106. Source port is 32560 and destination port is 35192 which use the TCP protocol. Sun Feb 25 10:56:30 2007 =>Found attack from 128.113.198.173 . Source port is 63716 and destination port is 35192 which use the TCP protocol. Sun Feb 25 10:56:30 2007 =>Found attack from 84.196.168.156. Source port is 33106 and destination port is 35192 which use the TCP protocol.

Could this be why the connection is being lost all the time?

2. In the course of trying to solve this probem, I deleted the network and started it again, with a new name. I tried this several times. To make sure the new settings had got installed, i gave each newly configured wireless network a new name.

Now, when I check what networks are available, i can see some of the names of the earlier networks being listed as broadcast. I can never connect with these though, if I try.

I also noticed that some networks are being created with names that I didn't devise. eg. I created one called network and now i see ones being called network 1 network 1 2 .

It seems that there is a program in Vista that is incrementally increasing the name of the network. Sometimes i can connect to such a newly named network, using the password...

I am completely lost, but if somebody could help me i would be very grateful. If i don't get an answer here, I don't know what to do.

Last edited by yeehi : 02-27-2007 at 04:43 AM.
yeehi is offline   Reply With Quote
Old 02-27-2007   #2 (permalink)
Starpoint
Pr0nStumbler Expert Level
 
Starpoint's Avatar
 
Join Date: Apr 2003
Location: Houston
Posts: 2,536
Quote:
Originally Posted by yeehi
I am sorry to ask about this one, but you know well how to fix this sort of problem.

My wireless router is working intermittantly. I have tried everything to fix it, but I just got two more clues, which I didn't know about before:

1. The security report in the wireless router says there is an attack:

Tue Feb 27 17:43:54 2007 =>Found attack from 60.51.54.64. Source port is 3978 and destination port is 48475 which use the TCP protocol.

Just now there is only one attack. A few days ago, there were many, many similar ones, all happening at the same time, going for the same port.

Sun Feb 25 10:56:30 2007 =>Found attack from 203.122.247.41. Source port is 1642 and destination port is 35192 which use the TCP protocol. Sun Feb 25 10:56:30 2007 =>Found attack from 12.214.248.81. Source port is 3654 and destination port is 35192 which use the TCP protocol. Sun Feb 25 10:56:30 2007 =>Found attack from 74.117.49.2. Source port is 33337 and destination port is 35192 which use the TCP protocol. Sun Feb 25 10:56:30 2007 =>Found attack from 72.76.28.88. Source port is 4744 and destination port is 35192 which use the TCP protocol. Sun Feb 25 10:56:30 2007 =>Found attack from 80.166.178.76. Source port is 1797 and destination port is 35192 which use the TCP protocol. Sun Feb 25 10:56:30 2007 =>Found attack from 74.12.56.118. Source port is 60976 and destination port is 35192 which use the TCP protocol. Sun Feb 25 10:56:30 2007 =>Found attack from 84.94.61.198 . Source port is 1656 and destination port is 35192 which use the TCP protocol. Sun Feb 25 10:56:30 2007 =>Found attack from 83.101.25.76. Source port is 46351 and destination port is 35192 which use the TCP protocol. Sun Feb 25 10:56:30 2007 =>Found attack from 82.239.208.201. Source port is 2049 and destination port is 35192 which use the TCP protocol. Sun Feb 25 10:56:30 2007 =>Found attack from 172.213.41.60 . Source port is 4701 and destination port is 35192 which use the TCP protocol. Sun Feb 25 10:56:30 2007 =>Found attack from 70.71.15.211. Source port is 60927 and destination port is 35192 which use the TCP protocol. Sun Feb 25 10:56:30 2007 =>Found attack from 195.132.203.205. Source port is 3777 and destination port is 35192 which use the TCP protocol. Sun Feb 25 10:56:30 2007 =>Found attack from 69.249.14.191 . Source port is 4583 and destination port is 35192 which use the TCP protocol. Sun Feb 25 10:56:30 2007 =>Found attack from 68.168.216.73. Source port is 59049 and destination port is 35192 which use the TCP protocol. Sun Feb 25 10:56:30 2007 =>Found attack from 84.94.184.42. Source port is 1497 and destination port is 35192 which use the TCP protocol. Sun Feb 25 10:56:30 2007 =>Found attack from 222.93.12.125 . Source port is 19527 and destination port is 35192 which use the TCP protocol. Sun Feb 25 10:56:30 2007 =>Found attack from 206.209.15.62. Source port is 59411 and destination port is 35192 which use the TCP protocol. Sun Feb 25 10:56:30 2007 =>Found attack from 87.65.178.106. Source port is 32560 and destination port is 35192 which use the TCP protocol. Sun Feb 25 10:56:30 2007 =>Found attack from 128.113.198.173 . Source port is 63716 and destination port is 35192 which use the TCP protocol. Sun Feb 25 10:56:30 2007 =>Found attack from 84.196.168.156. Source port is 33106 and destination port is 35192 which use the TCP protocol.

Could this be why the connection is being lost all the time?

2. In the course of trying to solve this probem, I deleted the network and started it again, with a new name. I tried this several times. To make sure the new settings had got installed, i gave each newly configured wireless network a new name.

Now, when I check what networks are available, i can see some of the names of the earlier networks being listed as broadcast. I can never connect with these though, if I try.

I also noticed that some networks are being created with names that I didn't devise. eg. I created one called network and now i see ones being called network 1 network 1 2 .

It seems that there is a program in Vista that is incrementally increasing the name of the network. Sometimes i can connect to such a newly named network, using the password...

I am completely lost, but if somebody could help me i would be very grateful. If i don't get an answer here, I don't know what to do.

renaming the network won't help since most attacks are from an IP.. so its possible they are causing your router issues and its resetting/rebooting or just panicing
__________________
Against the run of the mill, static as it seems

We break the surface tension with our wild kinetic dreams
Curves and lines -- of grand designs...


Tonight's movie "Soylent Green" has been brought to you by our sponsor - Waste Management

My mind is like a Steel trap - Rusty and Illegal in most states
Starpoint is offline   Reply With Quote
Old 02-27-2007   #3 (permalink)
Thorn
Did you do the math?
 
Thorn's Avatar
 
Join Date: Apr 2002
Location: Villa Straylight
Posts: 10,358
Quote:
Originally Posted by yeehi
Could this be why the connection is being lost all the time?
No.

The attack has nothing to do with the wireless side of your network. You were port scanned from your Internet connection. Based on the multiple incoming IPs, a good guess is that it was done a bot net.

Make sure that Port 35192 is closed for both TCP and UDP and be done with it. In fact, I'd strongly suggest you review you router settings and close ALL ports that are not required. Running the router in a default closed state is much, much safer than default open. Also, you might want to considered setting up a firewall.

Quote:
Originally Posted by yeehi
2. In the course of trying to solve this probem, I deleted the network and started it again, with a new name. I tried this several times. To make sure the new settings had got installed, i gave each newly configured wireless network a new name.

Now, when I check what networks are available, i can see some of the names of the earlier networks being listed as broadcast. I can never connect with these though, if I try.

I also noticed that some networks are being created with names that I didn't devise. eg. I created one called network and now i see ones being called network 1 network 1 2 .

It seems that there is a program in Vista that is incrementally increasing the name of the network. Sometimes i can connect to such a newly named network, using the password...

I am completely lost, but if somebody could help me i would be very grateful. If i don't get an answer here, I don't know what to do.
That sounds as if the old network names are just being maintained in a prior connections list. If they no longer exist, then there is nothing really to worry about.

Vista may also be increasing the names for ad hoc networks, which is proper behavior under 802.11 Standard. Ad-Hoc weirdness - multiplying clients
__________________
Thorn
"Read Altas Shrugged. Compare it to today. Repeat as necessary"
Thorn is offline   Reply With Quote
Old 03-07-2007   #4 (permalink)
yeehi
Registered Member
 
Join Date: Feb 2007
Posts: 12
I thought I would write up what has happened, in case any of you were curious, and it may help others, though i don't know how.

I tried to reinstall the latest drivers. i established that i have version 2 of the n-1 (the sticker on the back says 1000) (Version 2 is 2000).

I had a bad flash!

Router is banjaxed. Belkin support sent info, stick safety pin in 15 seconds, that takes it to factory default. It doesn't / didnt.

I tried tftp to upgrade BIOS. Vista needs that ability activated! From the control panel remove programs section, add features.

The tftp times out.

I am going to send the router back to the shop.

THanks for your interest in this. I got the impression some v able people were trying to help me out!
yeehi is offline   Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



Google
 
Web NetStumbler.org

All times are GMT -7. The time now is 06:00 AM.


Powered by vBulletin® Version 3.6.8
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.0.0 ©2007, Crawlability, Inc.


All messages express the views of the author and are for entertainment purposes only. Netstumbler.org cannot be held responsible for the authenticity of the content or the actions of its members. By using this site and its services, you warrant that you will not post any messages that are discriminating, obscene, hateful, threatening, or otherwise violates any laws and you release Netstumbler.org from any future claims of any kind whatsoever including, but not limited to, addiction and loss of productivity. All forum messages, private messages and any other content are properties of Netstumbler.org. Even if publicly available, personal or copyrighted information are not to be posted without the consent of the owner. Distribution of licensed and copyrighted materials in any way not endorsed by the copyright owner is strictly prohibited. You may not use this site and its resources to spam other sites or individuals or perform any action that violates any law. Items sold or bought in the For Sale forum are sold as is and no warranty or insurance of any kind is provided. Netstumbler.org cannot be held responsible for the outcome of any transactions and no warranty of any kind is provided, either express or implied. Vulgar words are not allowed in the subject lines ; they may be used in the message body in any forum. The Administrator, Super Moderators and Moderators of Netstumbler.org have the right to remove, edit, move or close any thread for any reason and to reveal your identity and other known information in the event of a complaint or legal action arising from any message posted by you.