DOS Attack in Progress - Telkom ISP - have no idea what I am talking about.

TobieV

Member
Joined
Feb 23, 2011
Messages
29
Reaction score
0
Location
Brits - Langberg
My Hello Peter Post :

For three days (now 4) , and after several hours on the phone to the call centre, and speaking to many many different people, I have not succeeded in explaining my problem let alone getting advice or action to fix it.

Any IP address that is assigned by TELKOM (my ISP) to either of my two routers on ADSL lines, are IMMEDIATELY attacked with Denial of Service Attacks from all over the world.

The attacks are causing my routers to hang and require reboot every hour. (and as an aside, Telkom Call Centre suggests that is a lovely solution, no problem, just restart the routers when they hang.)

Can I please speak to someone who knows what this means :

kernel: Intrusion -> IN=ppp_0_8_35_1 OUT= MAC= SRC=212.38.181.116 DST=105.226.10.250 LEN=40 TOS=0x10 PREC=0x00 TTL=246 ID=23235 PROTO=TCP SPT=51655 DPT=5905 WINDOW=1024 RES=0x00 SYN URGP=0

There are hundreds of these .... all from different SRC IP addresses. Even if my IP address changes due to reboot of router, Attacks just continue on new IP Address.

PLEASE HELP ! Who can I talk to to convince Telkom that THEY are under attack, and that the problem is not my Laptop ? (Not that I don't have seventy other computers on the network) And that for me to try connecting with another computer is not the answer.

Obviously I am trying to determine if any of this is originating from within the network, but I can not find anything.

I am packet capturing as we speak.


More Logs : (D-Link)

Dec 22 10:01:00 user alert kernel: Intrusion -> IN=ppp_0_8_35_1 OUT= MAC= SRC=122.225.109.103 DST=(my dynamically assigned IP)
LEN=40 TOS=0x10 PREC=0x00 TTL=96 ID=256 PROTO=TCP SPT=6000 DPT=22 WINDOW=16384 RES=0x00 SYN URGP=0
Dec 22 10:01:20 user alert kernel: Intrusion -> IN=ppp_0_8_35_1 OUT= MAC= SRC=60.173.10.74 DST=(my dynamically assigned IP)
LEN=40 TOS=0x10 PREC=0x00 TTL=107 ID=256 PROTO=TCP SPT=23243 DPT=10022 WINDOW=16384 RES=0x00 SYN URGP=0
Dec 22 10:06:26 user alert kernel: Intrusion -> IN=ppp_0_8_35_1 OUT= MAC= SRC=41.220.77.56 DST=(my dynamically assigned IP)
LEN=52 TOS=0x10 PREC=0x00 TTL=115 ID=9526 PROTO=TCP SPT=60689 DPT=40381 WINDOW=8192 RES=0x00 SYN URGP=0


Other Router : (Netgear)

[DoS Attack: ACK Scan] from source: 179.60.192.97, port 443, Monday, December 22,2014 10:24:22
[DoS Attack: ACK Scan] from source: 77.234.41.63, port 80, Monday, December 22,2014 10:23:43
[DoS Attack: ACK Scan] from source: 179.60.192.17, port 443, Monday, December 22,2014 10:16:36


Any comments on this please ?


I will be loading a different ISP on the routers soon, to see if the attacks stop.

Problem remains , no one at TELKOM even understands my question.
 
Last edited:

Thanks, I saw that one and tenscore others else-where , and despite all assurances that this is 'harmless' and that the router is doing it's job by blocking and reporting packets (and supposedly dropping them), it is not harmless, it changes the default gateway settings and brings the router down.

All firmware updates and every avenue has been researched. I have no answer.

Would my ISP, the National Telecommunications Operator not know how to deal with this ?

Are there representatives from other ISP's on here. What would you advise if I came to you with this problem ?
 
Thanks, I saw that one and tenscore others else-where , and despite all assurances that this is 'harmless' and that the router is doing it's job by blocking and reporting packets (and supposedly dropping them), it is not harmless, it changes the default gateway settings and brings the router down.

All firmware updates and every avenue has been researched. I have no answer.

Would my ISP, the National Telecommunications Operator not know how to deal with this ?

Are there representatives from other ISP's on here. What would you advise if I came to you with this problem ?

There was a 'hack' a while back due to the system user on the D-Link 2750u (Telkom model) set to Telkom123456. Change the password and it should fix the default gateway (and DNS settings) form being changed.
 
There was a 'hack' a while back due to the system user on the D-Link 2750u (Telkom model) set to Telkom123456. Change the password and it should fix the default gateway (and DNS settings) form being changed.

Thank you, I saw that there was in fact a whole hoo-haah about that. Articles on Mybroadband even.

It is a D-Link DSL-2500U - not that 'TELKOM' model, and off course I have done all that.
 
If those two log extracts are sequential, then it looks more like an automated port scan than a DOS attack. The D-Link is showing three probes over a six minute period, the Netgear three probes over eight minutes. DOS would be hundreds per second. My firewall is showing similar rates. I'm not bothered by this level of probing.


Dec 22 11:30:25 anzac %ASA-3-710003: TCP access denied by ACL from 61.174.51.228/6000 to outside:196.215.x.x/22
Dec 22 11:37:15 anzac %ASA-3-313001: Denied ICMP type=3, code=3 from 178.121.135.198 on interface outside
Dec 22 11:37:30 anzac %ASA-3-313001: Denied ICMP type=3, code=3 from 178.121.135.198 on interface outside
Dec 22 11:39:05 anzac %ASA-3-313001: Denied ICMP type=3, code=1 from 61.98.152.116 on interface outside
Dec 22 11:54:08 anzac %ASA-3-313001: Denied ICMP type=3, code=1 from 218.153.243.15 on interface outside
Dec 22 11:58:04 anzac %ASA-3-710003: TCP access denied by ACL from 61.166.189.69/37957 to outside:196.215.x.x/22
Dec 22 11:59:03 anzac %ASA-3-710003: TCP access denied by ACL from 61.174.51.216/6000 to outside:196.215.x.x/22
Dec 22 12:07:24 anzac %ASA-3-313001: Denied ICMP type=3, code=3 from 14.204.245.195 on interface outside
 
Simple port probes to be used for exploits against your router. DoS would be syn/ack spam magnitudes more frequently
 
Noted, and thank you.

You are right, the frequency is not hundreds of probes, scans, attacks.

My problem is that they are getting through some-how, and hanging the router (and it seems that it does that by messing with the gateway), and I'm thinking, this is what the router is reporting. Is that all that is happening ? I think there might be more happening that what the 'entry level' consumer router can report on despite it's log level that is set to 'debug' level.

I can't prove it yet, and am investigating, but I believe some stuff is getting through to my Server 2008 R2 that 'NATS' to the internal network. Firewall switched on, obviously !
Why would any recently dynamically assigned IP address automatically be attacked, the moment it comes online.

Can the routers mac address on the WAN port attract something like this ? i.e. If I used another router and a different ISP will it also be attacked. (bear in mind, there is already another router but with same ISP)

I am about to try this.
 
Get hold of Wireshark on the 2k8 R2 box and run it for a bit, see what pops up from non-local network addresses. Maybe do the same for the entire inside network. By filtering out local-local comms and keeping the machines silent for a while, you should see traffic that breached the firewall showing up.

Consumer-level routers "shouldn't" let things in unless explicitly configured. However if UPNP is enabled on it, then any little bit of software on a machine inside can request ports to be opened. I make sure that crap like that is disabled. Could be that something opened a port dynamically from one of the machines inside.

As to MAC address, that is restricted to the local network hop between you and the DSLAM. It does not progress beyond the first hop after your router and certainly no device anywhere off that local network can get to the router based solely on the MAC address.

The resumption of probes on the new address is probably because the new address is in the same IP subnet as the original. A botnet doing an initial probe would have hundreds of machines random-walking through a network range at the same time and would quite easily hit your new address at the same time. There might also be more than one botnet at play as well. There was a chap at Rhodes University that ran an internet telescope that saw some very complex and almost random patterns in port scans that revealed themselves over a couple of days.

I wonder if the debug level of logging might be causing the firewall to reset itself. Might be worth switching it off for a while and see what happens. Those little ARM processors aren't that powerful. :whistle:

Another ISP with another range might be clean, or it could have its own ranges being scanned by a different entity. I'm on WebAfrica and you saw the SSH probes I am getting.
 
Why would any recently dynamically assigned IP address automatically be attacked, the moment it comes online.

* Select ISP IP Range
* Run port scans against range
* Rinse,repeat
 
Interesting, the 179.60.192.17/97 addresses have also probed my firewall on the 21st of December. Traces back to a CDN called Edge Network Services in Latin America somewhere. Maybe let their abuse email take some flak as well.
 
Have you tried to contact SAIX they are the only people that will know what you are talking about call centers know nothing about their own network they just read from tick sheets .
http://www.saix.net/cgi-bin/saix_contacts.pl

I have not spoken to them directly, but calls were logged with them, I have reference numbers.
Someone called quoting those reference numbers, (don't know if it was them) and said I should try a different laptop if my email does not work. And next cruise was great buffalo.

Will try ...

UPDATE : New EDIMAX router in ....

Logs ...

12/22/2014 13:17:14> netMakeChannDial: err=-3000 rn_p=804baba0
12/22/2014 13:17:26> Last errorlog repeat 50 Times
12/22/2014 13:17:26> SNMP TRAP 2: link down
12/22/2014 13:17:26> MPOA Link Down
12/22/2014 13:17:26> mpoaChannDown: ch<0> null iface
12/22/2014 13:17:26> netMakeChannDial: err=-3001 rn_p=804baba0
12/22/2014 13:17:57> Last errorlog repeat 303 Times
12/22/2014 13:17:57> MPOA Link Up
12/22/2014 13:17:58> netMakeChannDial: err=-3000 rn_p=804baba0
12/22/2014 13:18:5> Last errorlog repeat 29 Times
12/22/2014 13:18:5> ppp_ready: ch:8050b440, iface:80458f1c
12/22/2014 13:18:5> SNMP TRAP 3: link up
12/22/2014 13:18:5> Accept() fail
12/22/2014 13:18:5> Accept() fail
12/22/2014 13:18:5> netMakeChannDial: err=-3000 rn_p=804baba0
12/22/2014 13:25:25> Last errorlog repeat 698 Times
12/22/2014 13:25:25> netMakeChannDial: err=-3000 rn_p=804baba0
12/22/2014 13:25:42> netMakeChannDial: err=-3000 rn_p=804baba0
12/22/2014 13:33:47> Last errorlog repeat 203 Times
12/22/2014 13:34:17> netMakeChannDial: err=-3000 rn_p=804baba0


This is new information.

Looks like bad line ? Or bad line as well ?
 
Interesting, the 179.60.192.17/97 addresses have also probed my firewall on the 21st of December. Traces back to a CDN called Edge Network Services in Latin America somewhere. Maybe let their abuse email take some flak as well.

Eish. I have IP's from all over the world.
I don't know what to say.

I don't have time for this, I have other work to do and deadlines.

Now testing new Router and Wiresharking it all.
 
Those log line certainly seem to indicate a problem in syncing the ADSL connection. That's probably the root-cause of your problems and not the probes. Make sure the DSL settings on the router are correct, VPI=8, VCI=35 and Annex-A and either automatic or ADSL2+ or G.DMT. If that's all valid and the cables are good, get Telkom to run a diagnostic while you have that modem trying to sync. Good luck.
 
UPDATE : TELKOM has responded due to a Hello Peter complaint. Despite having several reference numbers, there was and is no record of any fault reports on my numbers. New calls have been logged by their Social Media Team. I now have two more reference numbers.

Has anyone else seen that their fault reports just disappear off the system ?
 
They usually SMS you saying that fault xxxxxxxx has been attended to and service restored reply NO if still faulty, if they don't get a response to the SMS they clear the fault.

Last few faults I've reported have had a YES option as well with which I've responded if the fault is fixed but I suspect they close the fault if you don't reply within a certain time frame
 
UPDATE : TELKOM has responded due to a Hello Peter complaint. Despite having several reference numbers, there was and is no record of any fault reports on my numbers. New calls have been logged by their Social Media Team. I now have two more reference numbers.

Has anyone else seen that their fault reports just disappear off the system ?
If you were given valid fault ref numbers then there is no means for it to disappear off their system. The ref number will always be there.... but the status may change!
 
Top
Sign up to the MyBroadband newsletter
X