![]() |
|
|
#1 (permalink) |
|
Registered Member
Join Date: Feb 2007
Posts: 12
|
I am sorry to ask about this one, but you know well how to fix this sort of problem.
My wireless router is working intermittantly. I have tried everything to fix it, but I just got two more clues, which I didn't know about before: 1. The security report in the wireless router says there is an attack: Tue Feb 27 17:43:54 2007 =>Found attack from 60.51.54.64. Source port is 3978 and destination port is 48475 which use the TCP protocol. Just now there is only one attack. A few days ago, there were many, many similar ones, all happening at the same time, going for the same port. Sun Feb 25 10:56:30 2007 =>Found attack from 203.122.247.41. Source port is 1642 and destination port is 35192 which use the TCP protocol. Sun Feb 25 10:56:30 2007 =>Found attack from 12.214.248.81. Source port is 3654 and destination port is 35192 which use the TCP protocol. Sun Feb 25 10:56:30 2007 =>Found attack from 74.117.49.2. Source port is 33337 and destination port is 35192 which use the TCP protocol. Sun Feb 25 10:56:30 2007 =>Found attack from 72.76.28.88. Source port is 4744 and destination port is 35192 which use the TCP protocol. Sun Feb 25 10:56:30 2007 =>Found attack from 80.166.178.76. Source port is 1797 and destination port is 35192 which use the TCP protocol. Sun Feb 25 10:56:30 2007 =>Found attack from 74.12.56.118. Source port is 60976 and destination port is 35192 which use the TCP protocol. Sun Feb 25 10:56:30 2007 =>Found attack from 84.94.61.198 . Source port is 1656 and destination port is 35192 which use the TCP protocol. Sun Feb 25 10:56:30 2007 =>Found attack from 83.101.25.76. Source port is 46351 and destination port is 35192 which use the TCP protocol. Sun Feb 25 10:56:30 2007 =>Found attack from 82.239.208.201. Source port is 2049 and destination port is 35192 which use the TCP protocol. Sun Feb 25 10:56:30 2007 =>Found attack from 172.213.41.60 . Source port is 4701 and destination port is 35192 which use the TCP protocol. Sun Feb 25 10:56:30 2007 =>Found attack from 70.71.15.211. Source port is 60927 and destination port is 35192 which use the TCP protocol. Sun Feb 25 10:56:30 2007 =>Found attack from 195.132.203.205. Source port is 3777 and destination port is 35192 which use the TCP protocol. Sun Feb 25 10:56:30 2007 =>Found attack from 69.249.14.191 . Source port is 4583 and destination port is 35192 which use the TCP protocol. Sun Feb 25 10:56:30 2007 =>Found attack from 68.168.216.73. Source port is 59049 and destination port is 35192 which use the TCP protocol. Sun Feb 25 10:56:30 2007 =>Found attack from 84.94.184.42. Source port is 1497 and destination port is 35192 which use the TCP protocol. Sun Feb 25 10:56:30 2007 =>Found attack from 222.93.12.125 . Source port is 19527 and destination port is 35192 which use the TCP protocol. Sun Feb 25 10:56:30 2007 =>Found attack from 206.209.15.62. Source port is 59411 and destination port is 35192 which use the TCP protocol. Sun Feb 25 10:56:30 2007 =>Found attack from 87.65.178.106. Source port is 32560 and destination port is 35192 which use the TCP protocol. Sun Feb 25 10:56:30 2007 =>Found attack from 128.113.198.173 . Source port is 63716 and destination port is 35192 which use the TCP protocol. Sun Feb 25 10:56:30 2007 =>Found attack from 84.196.168.156. Source port is 33106 and destination port is 35192 which use the TCP protocol. Could this be why the connection is being lost all the time? 2. In the course of trying to solve this probem, I deleted the network and started it again, with a new name. I tried this several times. To make sure the new settings had got installed, i gave each newly configured wireless network a new name. Now, when I check what networks are available, i can see some of the names of the earlier networks being listed as broadcast. I can never connect with these though, if I try. I also noticed that some networks are being created with names that I didn't devise. eg. I created one called network and now i see ones being called network 1 network 1 2 . It seems that there is a program in Vista that is incrementally increasing the name of the network. Sometimes i can connect to such a newly named network, using the password... I am completely lost, but if somebody could help me i would be very grateful. If i don't get an answer here, I don't know what to do. Last edited by yeehi : 02-27-2007 at 04:43 AM. |
|
|
|
|
|
#2 (permalink) | |
|
Pr0nStumbler Expert Level
Join Date: Apr 2003
Location: Houston
Posts: 2,536
|
Quote:
renaming the network won't help since most attacks are from an IP.. so its possible they are causing your router issues and its resetting/rebooting or just panicing
__________________
Against the run of the mill, static as it seems We break the surface tension with our wild kinetic dreams Curves and lines -- of grand designs... Tonight's movie "Soylent Green" has been brought to you by our sponsor - Waste Management My mind is like a Steel trap - Rusty and Illegal in most states |
|
|
|
|
|
|
#3 (permalink) | ||
|
Did you do the math?
Join Date: Apr 2002
Location: Villa Straylight
Posts: 10,358
|
Quote:
The attack has nothing to do with the wireless side of your network. You were port scanned from your Internet connection. Based on the multiple incoming IPs, a good guess is that it was done a bot net. Make sure that Port 35192 is closed for both TCP and UDP and be done with it. In fact, I'd strongly suggest you review you router settings and close ALL ports that are not required. Running the router in a default closed state is much, much safer than default open. Also, you might want to considered setting up a firewall. Quote:
Vista may also be increasing the names for ad hoc networks, which is proper behavior under 802.11 Standard. Ad-Hoc weirdness - multiplying clients
__________________
Thorn "Read Altas Shrugged. Compare it to today. Repeat as necessary" |
||
|
|
|
|
|
#4 (permalink) |
|
Registered Member
Join Date: Feb 2007
Posts: 12
|
I thought I would write up what has happened, in case any of you were curious, and it may help others, though i don't know how.
I tried to reinstall the latest drivers. i established that i have version 2 of the n-1 (the sticker on the back says 1000) (Version 2 is 2000). I had a bad flash! Router is banjaxed. Belkin support sent info, stick safety pin in 15 seconds, that takes it to factory default. It doesn't / didnt. I tried tftp to upgrade BIOS. Vista needs that ability activated! From the control panel remove programs section, add features. The tftp times out. I am going to send the router back to the shop. THanks for your interest in this. I got the impression some v able people were trying to help me out! |
|
|
|