PDA

View Full Version : syn-flood attacks and my DSL


jtk
11-26-2006, 11:20 AM
So recently I've had my DSL connection drop while I'm in the middle of surfing. A few times a warning has popped up saying my LAN connection has limited connectivity. I'm pretty sure that what's happening is my router (Buffalo g54) is crashing or freezing, because when this happens I cannot login to the router management client. Generally restarting my computer restores the connection. In my router logs are entries like this:

2006/11/24 11:21:33 ATTACK Delete packet cache entry ( Last=2006/11/16 04:23:02 : [ syn-flood ] 75.33.231.27 count=37 )
2006/11/24 11:21:33 ATTACK Delete packet cache entry ( Last=1969/12/31 18:00:00 : [ syn-flood ] 189.145.197.189 count=1 )
2006/11/24 11:21:33 ATTACK Delete packet cache entry ( Last=1969/12/31 18:00:00 : [ syn-flood ] 189.145.212.33 count=1 )
2006/11/24 11:21:33 ATTACK Delete packet cache entry ( Last=1969/12/31 18:00:00 : [ syn-flood ] 75.30.132.215 count=1 )
2006/11/24 11:21:33 ATTACK Delete packet cache entry ( Last=1969/12/31 18:00:00 : [ syn-flood ] 189.146.79.79 count=1 )
2006/11/24 11:21:33 ATTACK Delete packet cache entry ( Last=2006/11/16 23:05:04 : [ port-scan ] 66.45.2.103 count=20 )

and they always coincide with when my connection drops, so it's gotta be this right?

Anyway, what I'm wondering is if another router might be able to handle this better? It's really annoying to have this happen right in the middle of paying bills or something like that...

JEDIYoda
11-27-2006, 02:57 AM
I have the Linksys BEFSX41 router for that very reason!!
I was constantly getting knockd offline on a few of the gaming sites so I bought this router on the recommendation of a friend and I have never looked back!!

Also its possible to go into your registry and harden the stacks.......depending on what OS you are using!!

Good Luck!!

MrWicked1968
11-27-2006, 08:00 AM
does that buffalo router even have a built in firewall? Windows XP's firewall is better at stealthing ports than apparently it is. a port scan should never be successful.

jtk
12-02-2006, 05:00 PM
Thanks guys.

It does have a firewall, but port 113 responds as "closed" (vs. no response at all). I've tried forwarding that port but it never sticks. Also for some reason it was set to respond to pings.

I've got another router here, I'll see if that's any better, and if not, I'll look into that Linksys.

procreate
12-02-2006, 07:15 PM
the trick is to get it NOT to respond to those attacks... most routers now have built in synflood attack.

jtk
12-05-2006, 08:42 PM
I hope you mean built in syn flood attack defense? :)

It hasn't happened in a while, but if it does I think I'll get a new router. Any recommendations? It's been quite awhile since I shopped...

JEDIYoda
12-10-2006, 05:57 PM
the trick is to get it NOT to respond to those attacks... most routers now have built in synflood attack.

Actually it really doesn`t matter if the router responds or not.
They are still capable of taking you off line eventually good router or not!!

procreate
12-13-2006, 11:39 AM
well the BEFSX41... i wouldnt really call it a GOOD router, i should know... i have one. it recently pissed me off to no end. i bought it because it was cheap and had VPN [which isnt stable enough to use either]. they cant even manage to write stable firmware. it loses DHCP. its capable of constant crashing with moderate loads. i was hoping cisco would make things better with that company but im losing hope in that, guess they really just want you to fork out the money for a REAL router with their tradeup program they hit you with as soon as you buy a Linksys.... not to mention linksys tech support is HORRIBLE, i cant even understand them on the phone. their chat is understandable but they are bigger idiots than i am and end up solving the problem [temporarily until it crashes again] that their lead techs cant even manage to figure out.

and it kind of does matter if it responds... at least that is ONE step of prevention.

jtk
12-28-2006, 05:24 PM
Well, it seems to have calmed down. Either that or my one ethernet cable was bad. I haven't been knocked offline since a couple days after my last post up there. I did turn off the ping response (which apparently defaults back to on every time I lose power or hard restart the router) but other than that no changes.