My router is being DOS attacked

terrificFrogg

Active Member
Joined
Jun 13, 2019
Messages
33
Reaction score
3
It started around 4pm. At first it was a DNS hijack. My AV was able to pick it up and block connections to this bad actor. I'll try to link images. Screenshot 2022-02-16 233313.png. I hope this image appears.

I ran a full system scan on my laptop and did a factory reset on my router. I reconfigured my router to connect to my adsl connection and then minutes later my router was attacked with dos. There was so much that I couldn't access my router's settings. So I had to factory reset my router again and then before setting up internet, I tried to block the IP and set up some DOS securities on my router to try and prevent or at least slow it down. It seemed to work because at first, my router's system log had more than 20 entries of dos attacks and something about management account failed or something along those lines. However as of writing this, my system log reported 2 attacks. Screenshot 2022-02-16 232615.png.
But I am still worried. I believe my router has been compromised in some way because port 21, 53, 80 and 443 are open (according to online port checking tools) however in my router settings, I am not forwarding any ports. So it could be that my system log is has been tempered with to not report certain activities.

EDIT:
It happened again.
sdfgsdfgsdf.png sdsdfsfwe.png

I will contact customer support tomorrow during their business hours
 
Last edited:
I contacted customer support via their WhatsApp channel. I just reported everything and she said she'll escalate the issue to relevant department. I haven't been contacted since then.

On my side, yeah my router is reporting attacks. They vary from UDP, SYN to ICMP flood attacks. The latest one at 13:25 today was a SYN flood attack.
 
Not to sound rude, but in my view I think its clear you dont know what you're looking at or talking about...

First, the screenshot you sent seems to be some kind of software on your router or PC (Dare I say Trendmicro software) that kinda looks over DNS queries and connections the router/PC is making for "security".. It has some or other database that is updated every hour/day/whatever and it has signatures for "bad" stuff.


What is happening in the first screenshot is, in my opinion, and OUTBOUND connection from something inside your network. The URLs that might be opening in a popup or something else have been flagged for trying to convince people to install bad software, etc, and added to that DB I mentioned earlier.
Then, when you try to load it up, the router/AV drops the connection for your own safely.

I've gotten these before on some dodgy sites I visit for.. downloads. But if you're getting too many of them, likely some computer on your network has something dodgy going on in it.
Or, some site on some page you use has bad ads or, something.
If your DNS server was changed like you mention, that could do it.
But it is still a DNS connection being made from inside your network, outwards. That could happen if your DNS is sending you somewhere weird, sure.

Onto the next screenshots, that looks like your DLink you mention.
The first line, first image, says you are getting a "UDP" flood. Notice anything funky about the IP address there? Thats Afrihost's DNS server.
Either the router is dumb and doesnt know what its doing, or, something inside your networking is smacking out tons of DNS traffic that is being replied to, but your router thinks the reply traffic is an attack.

I HIGHLY doubt that one of Afrihost's core DNS routers is sending you random UDP floods.

Next, a "TCP Scan" attack is pretty normal. Internet scans happen ALL the time. Do a traffic dump on any internet address on any public IP in the world and I promise you people will drive by checking port 22, 80, 25, etc looking for open port to check what-ya-got. Its the internet.
Feel free to lookup each IP address and complain to that network provider about somone from their network rage, but unless its a big reputible provider who cares, I promise not much will happen.


The manage account fail lines look like your router is open to the internet. Somewhere you'll find an "manage remotely" setting, or something like that. Make sure its off, of your routers web page is open to anyone to take a crack at.
If this was like this by default, its very likely what might have changed DNS servers in your router and caused weird stuff to happen, but its not that big of a deal ultimately.
Turn off the ability to manage your router remotely after a factory reset, and you'll be good to go.
 
Last edited:
It started around 4pm. At first it was a DNS hijack. My AV was able to pick it up and block connections to this bad actor. I'll try to link images. View attachment 1245572. I hope this image appears.

I ran a full system scan on my laptop and did a factory reset on my router. I reconfigured my router to connect to my adsl connection and then minutes later my router was attacked with dos. There was so much that I couldn't access my router's settings. So I had to factory reset my router again and then before setting up internet, I tried to block the IP and set up some DOS securities on my router to try and prevent or at least slow it down. It seemed to work because at first, my router's system log had more than 20 entries of dos attacks and something about management account failed or something along those lines. However as of writing this, my system log reported 2 attacks. View attachment 1245574.
But I am still worried. I believe my router has been compromised in some way because port 21, 53, 80 and 443 are open (according to online port checking tools) however in my router settings, I am not forwarding any ports. So it could be that my system log is has been tempered with to not report certain activities.

EDIT:
It happened again.
View attachment 1245586 View attachment 1245588

I will contact customer support tomorrow during their business hours

Hi,

Can you advise what router you are using?

Port scans on ISP's IP ranges are not uncommon as these are public IP's routable over the internet. There are millions of infected computers on the internet doing constant port scans on IP's trying to find any vulnerabilities to attack and exploit.

I can ask Noc to change your IP however that won't be a complete fix to the issue.

The issue is that your router management portal is visible to the internet when it should not. If you do this for remote management then unfortunately this issue will continue to happen. Setting proper firewall rules to reject and blacklist IP's trying to login with the incorrect details is the best way to curb this abuse.

Please can you drop me a pm with your email address for me to assist.
 
Not to sound rude, but in my view I think its clear you dont know what you're looking at or talking about...

First, the screenshot you sent seems to be some kind of software on your router (Dare I say Trendmicro software) that kinda looks over DNS queries and connections the router is making for "security".. It has some or other database that is updated every hour/day/whatever and it has signatures for "bad" stuff.


What is happening in the first screenshot is, in my opinion, and OUTBOUND connection from something inside your network. The URLs that might be opening in a popup or something else have been flagged for trying to convince people to install bad software, etc, and added to that DB I mentioned earlier.
Then, when you try to load it up, the router drops the connection for your own safely.

I've gotten these before on some dodgy sites I visit for.. downloads. But if you're getting too many of them, likely some computer on your network has something dodgy going on in it.
Or, some site on some page you use has bad ads or, something

Onto the next screenshots, that looks like your DLink you mention.
The first line, first image, says you are getting a "UDP" flood. Notice anything funky about the IP address there? Thats Afrihost's DNS server.
Either the router is dumb and doesnt know what its doing, or, something inside your networking is smacking out tons of DNS traffic that is being replied to, but your router thinks the reply traffic is an attack.

I HIGHLY doubt that one of Afrihost's core DNS routers is sending you random UDP floods.

Next, a "TCP Scan" attack is pretty normal. Internet scans happen ALL the time. Do a traffic dump on any internet address on any public IP in the world and I promise you people will drive by checking port 22, 80, 25, etc looking for open port to check what-ya-got. Its the internet.
Feel free to lookup each IP address and complain to that network provider about somone from their network rage, but unless its a big reputible provider who cares, I promise not much will happen.


The manage account fail lines look like your router is open to the internet. Somewhere you'll find an "manage remotely" setting, or something like that. Make sure its off, of your routers web page is open to anyone to take a crack at.
Thanks for the reply. That's some great insight. I really appreciate that. I will try to see if there's anything on my side that might be generating these reports. My AV is Avast. I scanned my entire network and it said my DNS was hijacked. I believe it was because when I tried opening websites I normally visit, Firefox warned me there was some issue verifying the security of that website. That security warning appeared on my laptop as well as my phone. That lead me assume my router was compromised.
When i accessed those same websites using mobile data, everything was fine.
 
Hi,

Can you advise what router you are using?

Port scans on ISP's IP ranges are not uncommon as these are public IP's routable over the internet. There are millions of infected computers on the internet doing constant port scans on IP's trying to find any vulnerabilities to attack and exploit.

I can ask Noc to change your IP however that won't be a complete fix to the issue.

The issue is that your router management portal is visible to the internet when it should not. If you do this for remote management then unfortunately this issue will continue to happen. Setting proper firewall rules to reject and blacklist IP's trying to login with the incorrect details is the best way to curb this abuse.

Please can you drop me a pm with your email address for me to assist.
Thanks for the reply.

My router is a Dlink dsl-224

I'll send a pm now
 
It started around 4pm. At first it was a DNS hijack. My AV was able to pick it up and block connections to this bad actor. I'll try to link images. View attachment 1245572. I hope this image appears.

I ran a full system scan on my laptop and did a factory reset on my router. I reconfigured my router to connect to my adsl connection and then minutes later my router was attacked with dos. There was so much that I couldn't access my router's settings. So I had to factory reset my router again and then before setting up internet, I tried to block the IP and set up some DOS securities on my router to try and prevent or at least slow it down. It seemed to work because at first, my router's system log had more than 20 entries of dos attacks and something about management account failed or something along those lines. However as of writing this, my system log reported 2 attacks. View attachment 1245574.
But I am still worried. I believe my router has been compromised in some way because port 21, 53, 80 and 443 are open (according to online port checking tools) however in my router settings, I am not forwarding any ports. So it could be that my system log is has been tempered with to not report certain activities.

EDIT:
It happened again.
View attachment 1245586 View attachment 1245588

I will contact customer support tomorrow during their business hours
@EvoX local hacking and iphone expert.
 
Looks like you have 2 issues.

The first screenshot is outbound traffic, so you probably have mitm malware on your PC.

The incoming traffic issues, this looks like your router is open to the internet so all the traffic is normal. No point in logging tickets with anyone. There is probably some setting that exposes your router management IP to the internet .

Are you sure 21, 53, 80 and 443 are open inbound to your router? If so then this is very worrying. 80/443 are for management.
21 is ftp and 53 is dns. Neither of these should even be running on your router.
 
Firstly, it's perfectly normal for a home router to be hit all the time from bad actors trying to scan for open ports. My home router gets scanned almost every minute of every day, but it's no biggie. A true DOS attack would be hundreds of connections every second.

Secondly, ports 21, 53, 80 and 443 are actual service ports used by every router to provide services to your local network. You don't have to have port forwarding active to have these ports open, because these ports are open on the actual router itself. If an online port scan shows that these ports are open then your firewall is clearly disabled or not working properly.

I would suggest you get a better router.
 
Looks like you have 2 issues.

The first screenshot is outbound traffic, so you probably have mitm malware on your PC.

The incoming traffic issues, this looks like your router is open to the internet so all the traffic is normal. No point in logging tickets with anyone. There is probably some setting that exposes your router management IP to the internet .
Thanks for replying.

Any idea how to try and find the mitm? I've done a scan with my AV but nothing came up. The last scan results was that my dns was poisoned
 
Is the router updated to the latest firmware?
i don't think it is. i haven't ran an update since getting it. On its settings, there isn't a "Check for updates" option. It just says "Obtain an updated firmware image file from your ISP."
 
Firstly, it's perfectly normal for a home router to be hit all the time from bad actors trying to scan for open ports. My home router gets scanned almost every minute of every day, but it's no biggie. A true DOS attack would be hundreds of connections every second.

Secondly, ports 21, 53, 80 and 443 are actual service ports used by every router to provide services to your local network. You don't have to have port forwarding active to have these ports open, because these ports are open on the actual router itself. If an online port scan shows that these ports are open then your firewall is clearly disabled or not working properly.

I would suggest you get a better router.
ah man thanks. that calms me down a bit. I will follow your advice. Are there any routers you would recommend? I'm on ADSL.
 
/pats mikrotik router
It has blocklists for chinese and russian IP's, so I have no worries.
And no ports are open to the outside, only the management port's open for me to manage it from the inside.
On the outside you'll see nothing open.
That's why I dislike generic routers, you have no fine grained firewall control, if the producer made an oopsie and left port 443 to the router open, then you will get allsorts trying to compromise your router.
 
ah man thanks. that calms me down a bit. I will follow your advice. Are there any routers you would recommend? I'm on ADSL.

On ADSL your IP is very dynamic. Each session will be a new IP.

If this keeps happening you have Malware on one or more of your devices connected to your network that is causing the issue.

Please download a free antivirus tool like malwatebytes, spybot or bitdefender to scan your pc to search for the malware.
 
Top
Sign up to the MyBroadband newsletter
X