DrayTek UK Users' Community Forum
Help, Advice and Solutions from DrayTek Users
Interpreting DoS reports
- marcw
- Topic Author
- Offline
- Junior Member
Less
More
- Posts: 16
- Thank you received: 0
31 Oct 2011 17:28 #69870
by marcw
--
Marc
Cleopatra Consultants Ltd
Interpreting DoS reports was created by marcw
Hi guys.
I have my router set up to send me reports on DoS attacks, but I'm having difficulty interpreting the content.
Does anyone have a good resource to point me to?
Example:
[DOS][Block][tcp_flag, scanner=fin_wo_ack][77.190.74.182:50618->77.190.74.182:25126][TCP][HLen=20, TLen=52, Flag=F, Seq=3909450284, Ack=0, Win=65535]
That appears to contain two IP addresses that have *nothing* to do with me; other times I get what appears to be one of my WAN addresses attacking another one in the same IP block.
Neither of these scenarios seem to make any sense.:?
I have my router set up to send me reports on DoS attacks, but I'm having difficulty interpreting the content.
Does anyone have a good resource to point me to?
Example:
[DOS][Block][tcp_flag, scanner=fin_wo_ack][77.190.74.182:50618->77.190.74.182:25126][TCP][HLen=20, TLen=52, Flag=F, Seq=3909450284, Ack=0, Win=65535]
That appears to contain two IP addresses that have *nothing* to do with me; other times I get what appears to be one of my WAN addresses attacking another one in the same IP block.
Neither of these scenarios seem to make any sense.
--
Marc
Cleopatra Consultants Ltd
Please Log in or Create an account to join the conversation.
- ghostworks
- Offline
- Member
Less
More
- Posts: 354
- Thank you received: 0
31 May 2012 12:21 #72392
by ghostworks
Replied by ghostworks on topic Re: Interpreting DoS reports
Same here
[DOS][Block][tcp_flag, scanner=fin_wo_ack][192.168.1.29:59161->65.55.64.250:443][TCP][HLen=20,
[DOS][Block][tcp_flag, scanner=fin_wo_ack][192.168.1.29:59161->65.55.64.250:443][TCP][HLen=20,
Please Log in or Create an account to join the conversation.
Moderators: Chris, Sami
Copyright © 2024 DrayTek