Welcome to Tech Support Forum home to more then 136,000 problems solved. Issues have included: Spyware, Malware, Virus Issues, Windows, Microsoft, Linux, Networking, Security, Hardware, and Gaming Getting your problem solved is as easy as:
1. Registering for a free account
2. Asking your question
3. Receiving an answer

Registered members:
* Get free support
* Communicate privately with other members (PM).
* Removal of this message
* See fewer ads.
* And much more..

 



Want to know how to post a question? click here Having problems with spyware and pop-ups? First Steps
Go Back   Tech Support Forum > Networking Forum > Modems/Cable/DSL/Satellite
User Name
Password
Site Map Register Donate Rules Blogs Mark Forums Read


Modems/Cable/DSL/Satellite Fixing your connection devices; Cisco, Intel, Zoom, Linksys

Reply
 
LinkBack Thread Tools
Old 02-03-2008, 02:51 AM   #1 (permalink)
Moderator Hardware Team
 
Done_Fishin's Avatar
 
Join Date: Oct 2006
Location: Brit living in Greece
Posts: 7,472
OS: WinME, WinXP Pro SP3, Win7 Beta, Ubuntu 9.04 & Netbook Remix & CD2USB, Mepis 6.5, Fedora 10

My System

Attack detected / Firewall triggered

I was checking out my router log today .. and found this

Quote:

Current Log Entries


0000-00-00 00:00:01 E |System |Current Mode: Bridge-Router

0000-00-00 00:00:01 E |CWMP |CWMP agent cannot reach the ACS named http://111.111.111.111:1111/ACS-INTF. Short retry initiated

0000-00-00 00:00:01 E |DSL |Boost DSP

0000-00-00 00:00:01 E |DSL |DataPump Version - 07.00.02.00

0000-00-00 00:00:02 E |DSL |State: WAITING

0000-00-00 00:00:04 E |Ethernet |Link 1 Up - 100Base-TX Full Duplex

0000-00-00 00:00:14 E |DSL |State: INITIALIZING

0000-00-00 00:00:26 E |DSL |HYBRID 1

0000-00-00 00:00:26 E |DSL |Link up 1 US 511 DS 4092 (INTL:ADSL2+)

0000-00-00 00:00:49 E |PPP |LCP neg PAP

0000-00-00 00:00:49 E |PPP |LCP up

0000-00-00 00:00:50 E |PPP |IPCP nak option: 3

0000-00-00 00:00:50 E |PPP |IPCP nak option: 129

0000-00-00 00:00:50 E |PPP |IPCP nak option: 131

0000-00-00 00:00:50 E |PPP |IPCP up ip: 91.140.17.190, gw: 62.169.255.23

0000-00-00 00:00:50 E |PPP |IPCP dns: 62.169.194.17, 62.169.194.18

0000-00-00 00:00:56 E |Attack Detected |TCP packet with only FIN flag set - 81.183.114.73:63706 -> 91.140.17.190:31246 len=40 id=15594

0000-00-00 00:00:56 E |DHCP Server |Address 192.168.254.2 given out to 00:14:85:31:2c:be

0000-00-00 00:00:56 E |DHCP Server |1 Address(es) leased

0000-00-00 00:01:36 E |Firewall |D:19:0 ICMP(11) 62.169.255.23:2816 -> 192.168.254.2:42673 len=56 id=5849 DF=0 MF=0 byte-off=0

0000-00-00 00:01:37 E |Firewall |D:19:0 ICMP(11) 62.169.192.69:2816 -> 192.168.254.2:42673 len=56 id=0 DF=0 MF=0 byte-off=0

0000-00-00 00:01:39 E |Firewall |D:19:0 ICMP(11) 151.5.128.229:2816 -> 192.168.254.2:42673 len=56 id=0 DF=0 MF=0 byte-off=0

0000-00-00 00:01:40 E |Firewall |D:19:0 ICMP(11) 151.6.33.225:2816 -> 192.168.254.2:42673 len=56 id=0 DF=0 MF=0 byte-off=0

0000-00-00 00:01:41 E |Firewall |D:19:0 ICMP(11) 151.6.6.109:2816 -> 192.168.254.2:42673 len=56 id=0 DF=0 MF=0 byte-off=0

0000-00-00 00:01:43 E |Firewall |D:19:0 ICMP(11) 151.6.2.82:2816 -> 192.168.254.2:42673 len=56 id=0 DF=0 MF=0 byte-off=0

0000-00-00 00:01:44 E |Firewall |D:19:0 ICMP(11) 213.200.68.77:2816 -> 192.168.254.2:42673 len=56 id=0 DF=0 MF=0 byte-off=0

0000-00-00 00:01:45 E |Firewall |D:19:0 ICMP(11) 213.200.80.93:2816 -> 192.168.254.2:42673 len=56 id=0 DF=0 MF=0 byte-off=0

0000-00-00 00:01:47 E |Firewall |D:19:0 ICMP(11) 213.200.84.250:2816 -> 192.168.254.2:42673 len=56 id=0 DF=0 MF=0 byte-off=0

0000-00-00 00:01:49 E |Firewall |D:19:0 ICMP(11) 62.169.255.23:2816 -> 192.168.254.2:42673 len=56 id=5981 DF=0 MF=0 byte-off=0

0000-00-00 00:01:51 E |Firewall |D:19:0 ICMP(11) 62.169.192.69:2816 -> 192.168.254.2:42673 len=56 id=0 DF=0 MF=0 byte-off=0

0000-00-00 00:01:52 E |Firewall |D:19:0 ICMP(11) 151.5.128.229:2816 -> 192.168.254.2:42673 len=56 id=0 DF=0 MF=0 byte-off=0

0000-00-00 00:01:54 E |Firewall |D:19:0 ICMP(11) 151.6.33.225:2816 -> 192.168.254.2:42673 len=56 id=0 DF=0 MF=0 byte-off=0

0000-00-00 00:01:55 E |Firewall |D:19:0 ICMP(11) 151.6.6.109:2816 -> 192.168.254.2:42673 len=56 id=0 DF=0 MF=0 byte-off=0

0000-00-00 00:01:57 E |Firewall |D:19:0 ICMP(11) 213.200.68.77:2816 -> 192.168.254.2:42673 len=56 id=0 DF=0 MF=0 byte-off=0

0000-00-00 00:01:59 E |Firewall |D:19:0 ICMP(11) 213.200.80.93:2816 -> 192.168.254.2:42673 len=56 id=0 DF=0 MF=0 byte-off=0

0000-00-00 00:02:00 E |Firewall |D:19:0 ICMP(11) 213.200.84.250:2816 -> 192.168.254.2:42673 len=56 id=0 DF=0 MF=0 byte-off=0

0000-00-00 00:02:09 E |Attack Detected |TCP packet with only FIN flag set - 81.183.114.73:63706 -> 91.140.17.190:31246 len=40 id=15644

0000-00-00 00:02:20 E |CWMP |CWMP is attempting to connect to the ACS named http://111.111.111.111:1111/ACS-INTF. Retry in 5 seconds

0000-00-00 00:54:12 E |CWMP |CWMP is attempting to connect to the ACS named http://111.111.111.111:1111/ACS-INTF. Retry in 2560 seconds


0000-00-00 01:10:03 E |Firewall |D:19:0 TCP 15.216.76.109:80 -> 192.168.254.1:3916 len=52 id=14470 DF=0 MF=0 byte-off=0

0000-00-00 11:11:45 E |DHCP Server |Address 192.168.254.3 given out to 00:10:dc:66:d4:7a

0000-00-00 11:11:45 E |DHCP Server |2 Address(es) leased

0000-00-00 11:11:47 E |DHCP Server |Address 192.168.254.3 given out to 00:10:dc:66:d4:7a

0000-00-00 11:11:47 E |DHCP Server |2 Address(es) leased

0000-00-00 11:53:24 E |Firewall |D:19:0 TCP 38.99.76.177:80 -> 192.168.254.3:1409 len=40 id=10414 DF=1 MF=0 byte-off=0

0000-00-00 11:53:25 E |Firewall |D:19:0 TCP 38.99.76.177:80 -> 192.168.254.3:1409 len=40 id=10415 DF=1 MF=0 byte-off=0

0000-00-00 11:53:26 E |Firewall |D:19:0 TCP 38.99.76.177:80 -> 192.168.254.3:1409 len=40 id=10416 DF=1 MF=0 byte-off=0

0000-00-00 11:53:28 E |Firewall |D:19:0 TCP 38.99.76.177:80 -> 192.168.254.3:1409 len=40 id=10417 DF=1 MF=0 byte-off=0

0000-00-00 11:53:32 E |Firewall |D:19:0 TCP 38.99.76.177:80 -> 192.168.254.3:1409 len=40 id=10418 DF=1 MF=0 byte-off=0

0000-00-00 11:53:39 E |Firewall |D:19:0 TCP 38.99.76.177:80 -> 192.168.254.3:1409 len=40 id=10419 DF=1 MF=0 byte-off=0



Can anyone shed light on what this is

0000-00-00 00:54:12 E |CWMP |CWMP is attempting to connect to the ACS named http://111.111.111.111:1111/ACS-INTF.

Also this attack .. is it connected to the Firewall alarms from the two different sites?
0000-00-00 00:00:56 E |Attack Detected |TCP packet with only FIN flag set - 81.183.114.73:63706 -> 91.140.17.190:31246 len=40 id=15594

IS there any way to know if anything got through ???
IS there anything that I should be doing to tighten down my security ??

All advice gratefully recieved ..
__________________
.


.
I'm not old!!
I'm age impaired

..
D_F


I DON'T PLAY GAMES

How to mark your thread as solved



HDD DIAG UTILS

TSF's Photographer's Corner
Done_Fishin is online now  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Reply With Quote
Important Information
Join the #1 Tech Support Forum Today - It's Totally Free!

TechSupportForum.com is a leading support website for your computer needs. We offer free, friendly and personalized computer support. Why pay to have your computer fixed when you can do it for free.

Join TechSupportforum.com Today - Click Here

Old 02-03-2008, 10:17 AM   #2 (permalink)
Manager, Networking Forums
 
johnwill's Avatar
 
Join Date: Sep 2002
Location: S.E. Pennsylvania, US
Posts: 41,654
OS: Windows 7, XP-Pro, Vista, Linux


Blog Entries: 1
Re: Attack detected / Firewall triggered

If it got through, it wouldn't be in the log.

This kind of stuff shows up all the time in the logs.
__________________
If TSF has helped you, Tell us about it! or Donate to help keep the site up!

Microsoft MVP - Windows Desktop Experience
johnwill is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Reply With Quote
Old 02-03-2008, 12:14 PM   #3 (permalink)
Moderator Hardware Team
 
Done_Fishin's Avatar
 
Join Date: Oct 2006
Location: Brit living in Greece
Posts: 7,472
OS: WinME, WinXP Pro SP3, Win7 Beta, Ubuntu 9.04 & Netbook Remix & CD2USB, Mepis 6.5, Fedora 10

My System

Re: Attack detected / Firewall triggered

any idea what http://111.111.111.111:1111/ACS-INTF means .. trued to google it but came up with nothing .. doesn't look like a proper address unless its in the 127 range or maybe it's IPv6
__________________
.


.
I'm not old!!
I'm age impaired

..
D_F


I DON'T PLAY GAMES

How to mark your thread as solved



HDD DIAG UTILS

TSF's Photographer's Corner
Done_Fishin is online now  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Reply With Quote
Old 02-04-2008, 08:52 AM   #4 (permalink)
Manager, Networking Forums
 
johnwill's Avatar
 
Join Date: Sep 2002
Location: S.E. Pennsylvania, US
Posts: 41,654
OS: Windows 7, XP-Pro, Vista, Linux


Blog Entries: 1
Re: Attack detected / Firewall triggered

I have no idea, looks like a cryptic web address, since it's sitting behind an http://
__________________
If TSF has helped you, Tell us about it! or Donate to help keep the site up!

Microsoft MVP - Windows Desktop Experience
johnwill is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Reply With Quote
Old 05-15-2009, 02:03 AM   #5 (permalink)
Registered User
 
Join Date: May 2009
Posts: 1
OS: OS/2 Warp 4.51


Re: Attack detected / Firewall triggered

Quote:
Originally Posted by Done_Fishin View Post
I was checking out my router log today .. and found this

Can anyone shed light on what this is

0000-00-00 00:54:12 E |CWMP |CWMP is attempting to connect to the ACS named http://111.111.111.111:1111/ACS-INTF.

Also this attack .. is it connected to the Firewall alarms from the two different sites?
0000-00-00 00:00:56 E |Attack Detected |TCP packet with only FIN flag set - 81.183.114.73:63706 -> 91.140.17.190:31246 len=40 id=15594

IS there any way to know if anything got through ???
IS there anything that I should be doing to tighten down my security ??

All advice gratefully recieved ..
That is a normal log entry for CWMP aka TR-069 (short for Technical Report 069) aka "CPE WAN Management Protocol" (CPE -- Customer Premise Equipment) and it looks like you may have changed the real IP to all 1's, correct? If not then the ISP setup their Firmware strangely or someone else modified the ACS IP trying to stop it connecting. Either way it is ok.

You can read much more about CWMP at these links below. It is not an attack, and it is harmless as it your Modem checking in with your ISP trying to connect to a private firmware delivery/basic configuration server owned by the ISP to make sure you have their latest bug fixed/latest feature release Firmware along with the basic connection type info for the DSL's VC (Virtual Circuit) settings. That's basically it in a nut shell. It is becoming the de factor standard for ISPs and other service providers (Cell phones, Wi-Fi devices, Set Top Boxes, and much more) to keep their customers equipment updated and secured.

http://www.carricksolutions.com/TR-069/

http://en.wikipedia.org/wiki/TR-069
Quote:
TR-069 (short for Technical Report 069) is a DSL Forum (which was later renamed as Broadband Forum) technical specification entitled CPE WAN Management Protocol (CWMP). It defines an application layer protocol for remote management of end-user devices.
http://www.broadband-forum.org/techn...oad/TR-069.pdf

http://www.broadband-forum.org/techn...Amendment2.pdf

You can disable the CWMP agent/process if you like. Details are in the linked article below:

Disabling the CWMP agent from CLI
http://shadow.sentry.org/~trev/adsl4...mp_config.html

As to security, your log just shows packets it didn't like and dropped. Likely it was a late response to a Browser or DNS, or Email request and the NAPT Table entry had expired so the Router was not expecting a response since that port was closed recently by NAT/NAPT table timeout.

Test your Routers security responses by using these two test sites below. Set your Firewall to Off in the Modem/Router, yes Off as that only allows pings on the Routers WAN Interface and does not reduce your true security level (trust me the scan sill confirm this and also I've been using and setting up these Speedstreams since late 1999, beta tested firmware for a while when Efficient still owned them before Siemens bought them out and I own 8+ different Models including Business Class versions which I can swap out quickly for testing and configuration issues). Pings are not a real security risk even though one site (GRC.com) wants you to think that they are, but as long as your results show all Green Blocks after running the "All Service Ports Test" that is a solid determination on the status of your Routers first 1056 ports (Green aka Stealth means no response, not even a this port is closed response, just no acknowledgment ). Red Blocks are items to be concerned with as those represent a port or ports that when checked, have replied "port number x here and I am open ready to accept connections."

Regards,

Doctor Olds
Doctor Olds is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Reply With Quote
Old 05-15-2009, 11:40 AM   #6 (permalink)
Moderator Hardware Team
 
Done_Fishin's Avatar
 
Join Date: Oct 2006
Location: Brit living in Greece
Posts: 7,472
OS: WinME, WinXP Pro SP3, Win7 Beta, Ubuntu 9.04 & Netbook Remix & CD2USB, Mepis 6.5, Fedora 10

My System

Re: Attack detected / Firewall triggered

Many, many thanks for your knowledgeable help which has confirmed my suspicions about some of the points I had raised. I had forgotten all about this topic which I started over a year ago .. but I still use the same router and the update in information is more than welcome.

The all ones address is exactly as I see it, nothing changed or hidden .. It just seems that it's trying to connect but either not allowed or the host not found, which seemed strange .. why bother ? Why not cut it out ? unless perhaps it's just there to keep the line up & running, There is a term for it which I forget now .. but I think it was a problem going back into win95/98 days when the line would suddenly stop responding until a patch was introduced

Thanks for those links , I will be investigating very shortly .
__________________
.


.
I'm not old!!
I'm age impaired

..
D_F


I DON'T PLAY GAMES

How to mark your thread as solved



HDD DIAG UTILS

TSF's Photographer's Corner
Done_Fishin is online now  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Reply With Quote
Reply


Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off




All times are GMT -7. The time now is 06:06 AM.



Copyright 2001 - 2009, Tech Support Forum
Home Tips Plus | Outdoor Basecamp | Automotive Support Forum

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85