Get expert support with your Fibre connection.
on 29-03-2023 11:41 AM
hi
all of a sudden i started having issues with my connection last night and when I look I had a lot of Intrusion security alerts, that keep coming up every 10 mins(ish) .(see below for first lot),
also on the log was things like a IP spoofing 192.168.1.1 alerts and some other attack warning. I will copy whole log when I get home.
Manufacturer:Huawei Technologies Co., Ltd. Product Style:HG633 Serial Number: Hardware Version:H.1.01 Software Version:v2.00t 2023-03-29 01:46:01 Security Warning Intrusion -> src=157.245.156.209 DST=78.145.245.247 LEN=44 TOS=0x00 PREC=0x00 TTL=241 ID=54321 PROTO=TCP SPT=45130 DPT=1950 WIN 2023-03-29 01:39:43 Security Warning DROP FTP Request 2023-03-29 01:39:18 Security Warning ACCEPT SAMBA Request 2023-03-29 01:36:10 Security Warning Intrusion -> src=176.111.174.91 DST=78.145.245.247 LEN=40 TOS=0x00 PREC=0x00 TTL=244 ID=47635 PROTO=TCP SPT=42777 DPT=2880 WIND 2023-03-29 01:31:13 Security Warning DROP TCP SAMBA Request 2023-03-29 01:26:02 Security Warning Intrusion -> src=78.128.113.78 DST=78.145.245.247 LEN=40 TOS=0x00 PREC=0x00 TTL=245 ID=29616 PROTO=TCP SPT=50872 DPT=2859 WINDO 2023-03-29 01:17:55 Security Warning DROP UDP SAMBA Request 2023-03-29 01:16:04 Security Warning Intrusion -> src=162.142.125.84 DST=78.145.245.247 LEN=44 TOS=0x00 PREC=0x00 TTL=41 ID=43972 PROTO=TCP SPT=42360 DPT=10399 WIND
i had same router for 8 years . the last time on the log I the last alert was in Jan., in the end, I end up turning off the internet after battling for hours and trying to work out what was going on.
on 30-03-2023 11:25 AM
@GuyOnMars good guys on the support team.
on 30-03-2023 10:01 AM
No problem 🙂
Chris, Community Team
Our latest Blog l Share your Ideas l Service Status l Help with your Service l Community Stars l Set your preferences
on 30-03-2023 09:59 AM
That's amazing, we received it this morning! thanks chris
on 30-03-2023 09:58 AM
tryed this , still same ip 😕
on 30-03-2023 09:58 AM
i Unplugged it over night. il have a look at the log when I get home
on 30-03-2023 06:44 AM
Morning,
Please let us know how you get on.
Thanks
on 29-03-2023 07:12 PM
Hi @GuyOnMars unplug the router, have your dinner, and try reconnecting
on 29-03-2023 07:12 PM
To be honest that looks like nothing more than your router firewall doing its job. You can try forcing an IP address change by turning off the router for around 30 minutes.
on 29-03-2023 07:06 PM
They literally haven't stop since i left for work. -.-
Is it worth trying get my ip address changed
Manufacturer:Huawei Technologies Co., Ltd.
Product Style:HG633
Serial Number:C4REQ15825013746
Hardware Version:H.1.01
Software Version:v2.00t
2023-03-29 18:52:33 Security Warning Intrusion -> src=198.199.118.8 DST=78.147.238.191 LEN=40 TOS=0x00 PREC=0x00 TTL=246 ID=54321 PROTO=TCP SPT=55874 DPT=2078 WINDO
2023-03-29 18:42:27 Security Warning Intrusion -> src=47.96.137.227 DST=78.147.238.191 LEN=40 TOS=0x00 PREC=0x00 TTL=238 ID=5648 PROTO=TCP SPT=48377 DPT=2376 WINDOW
2023-03-29 18:32:45 Security Warning Intrusion -> src=194.36.189.194 DST=78.147.238.191 LEN=40 TOS=0x00 PREC=0x00 TTL=248 ID=1393 PROTO=TCP SPT=51039 DPT=52985 WIND
2023-03-29 18:24:52 Security Warning DROP FTP Request
2023-03-29 18:22:32 Security Warning Intrusion -> src=94.102.61.27 DST=78.147.238.191 LEN=40 TOS=0x00 PREC=0x00 TTL=249 ID=54321 PROTO=TCP SPT=47653 DPT=1042 WINDOW
2023-03-29 18:19:05 Security Warning Detect UDP port scan attack, scan packet from 192.168.1.4.
2023-03-29 18:12:20 Security Warning Intrusion -> src=212.70.149.42 DST=78.147.238.191 LEN=40 TOS=0x00 PREC=0x00 TTL=245 ID=44542 PROTO=TCP SPT=46902 DPT=23481 WIND
2023-03-29 18:02:39 Security Warning Intrusion -> src=89.248.165.100 DST=78.147.238.191 LEN=40 TOS=0x00 PREC=0x00 TTL=249 ID=25877 PROTO=TCP SPT=55041 DPT=3329 WIND
2023-03-29 17:52:20 Security Warning Intrusion -> src=89.248.165.100 DST=78.147.238.191 LEN=40 TOS=0x00 PREC=0x00 TTL=249 ID=20413 PROTO=TCP SPT=55041 DPT=2204 WIND
2023-03-29 17:42:22 Security Warning Intrusion -> src=89.248.163.64 DST=78.147.238.191 LEN=40 TOS=0x00 PREC=0x00 TTL=249 ID=43955 PROTO=TCP SPT=55111 DPT=10152 WIND
2023-03-29 17:32:33 Security Warning Intrusion -> src=89.248.165.100 DST=78.147.238.191 LEN=40 TOS=0x00 PREC=0x00 TTL=249 ID=62673 PROTO=TCP SPT=55041 DPT=33392 WIN
2023-03-29 17:22:44 Security Warning Intrusion -> src=192.241.228.8 DST=78.147.238.191 LEN=40 TOS=0x00 PREC=0x00 TTL=246 ID=54321 PROTO=TCP SPT=50949 DPT=512 WINDOW
2023-03-29 17:12:32 Security Warning Intrusion -> src=89.248.165.45 DST=78.147.238.191 LEN=40 TOS=0x00 PREC=0x00 TTL=249 ID=64255 PROTO=TCP SPT=55141 DPT=608 WINDOW
2023-03-29 17:02:30 Security Warning Intrusion -> src=89.248.165.45 DST=78.147.238.191 LEN=40 TOS=0x00 PREC=0x00 TTL=249 ID=43809 PROTO=TCP SPT=55141 DPT=6080 WINDO
2023-03-29 16:52:25 Security Warning Intrusion -> src=212.70.149.46 DST=78.147.238.191 LEN=40 TOS=0x00 PREC=0x00 TTL=245 ID=54321 PROTO=TCP SPT=46033 DPT=8443 WINDO
2023-03-29 16:42:23 Security Warning Intrusion -> src=80.82.77.139 DST=78.147.238.191 LEN=44 TOS=0x00 PREC=0x00 TTL=122 ID=46031 PROTO=TCP SPT=20041 DPT=22 WINDOW=6
2023-03-29 16:32:19 Security Warning Intrusion -> src=89.248.165.46 DST=78.147.238.191 LEN=40 TOS=0x00 PREC=0x00 TTL=249 ID=41766 PROTO=TCP SPT=43260 DPT=13870 WIND
2023-03-29 16:22:23 Security Warning Intrusion -> src=89.248.165.100 DST=78.147.238.191 LEN=40 TOS=0x00 PREC=0x00 TTL=249 ID=36708 PROTO=TCP SPT=55041 DPT=12402 WIN
2023-03-29 16:22:09 Security Warning DROP TCP SAMBA Request
2023-03-29 16:12:19 Security Warning Intrusion -> src=89.248.163.64 DST=78.147.238.191 LEN=40 TOS=0x00 PREC=0x00 TTL=249 ID=12294 PROTO=TCP SPT=55111 DPT=50912 WIND
2023-03-29 16:02:22 Security Warning Intrusion -> src=84.243.57.21 DST=78.147.238.191 LEN=40 TOS=0x00 PREC=0x00 TTL=49 ID=57203 PROTO=TCP SPT=58658 DPT=22 WINDOW=57
2023-03-29 15:52:20 Security Warning Intrusion -> src=89.248.163.64 DST=78.147.238.191 LEN=40 TOS=0x00 PREC=0x00 TTL=249 ID=30262 PROTO=TCP SPT=55111 DPT=11152 WIND
2023-03-29 15:42:21 Security Warning Intrusion -> src=66.29.136.194 DST=78.147.238.191 LEN=40 TOS=0x00 PREC=0x00 TTL=240 ID=10974 PROTO=TCP SPT=40831 DPT=1568 WINDO
2023-03-29 15:32:33 Security Warning Intrusion -> src=89.248.165.242 DST=78.147.238.191 LEN=40 TOS=0x00 PREC=0x00 TTL=249 ID=42876 PROTO=TCP SPT=55076 DPT=20861 WIN
2023-03-29 15:22:27 Security Warning Intrusion -> src=183.136.225.9 DST=78.147.238.191 LEN=44 TOS=0x00 PREC=0x00 TTL=113 ID=0 PROTO=TCP SPT=46860 DPT=6668 WINDOW=29
2023-03-29 15:12:22 Security Warning Intrusion -> src=209.188.21.246 DST=78.147.238.191 LEN=40 TOS=0x00 PREC=0x00 TTL=240 ID=51018 PROTO=TCP SPT=58745 DPT=2681 WIND
2023-03-29 15:02:37 Security Warning Intrusion -> src=66.29.136.194 DST=78.147.238.191 LEN=40 TOS=0x00 PREC=0x00 TTL=240 ID=17735 PROTO=TCP SPT=58341 DPT=1563 WINDO
2023-03-29 14:52:25 Security Warning Intrusion -> src=89.248.163.64 DST=78.147.238.191 LEN=40 TOS=0x00 PREC=0x00 TTL=249 ID=21721 PROTO=TCP SPT=55111 DPT=33910 WIND
2023-03-29 14:42:26 Security Warning Intrusion -> src=89.248.165.45 DST=78.147.238.191 LEN=40 TOS=0x00 PREC=0x00 TTL=249 ID=1445 PROTO=TCP SPT=55141 DPT=1338 WINDOW
2023-03-29 14:32:21 Security Warning Intrusion -> src=5.8.18.8 DST=78.147.238.191 LEN=40 TOS=0x00 PREC=0x00 TTL=249 ID=7384 PROTO=TCP SPT=56639 DPT=37186 WINDOW=102
2023-03-29 14:22:28 Security Warning Intrusion -> src=176.111.174.80 DST=78.147.238.191 LEN=40 TOS=0x00 PREC=0x00 TTL=243 ID=51483 PROTO=TCP SPT=42497 DPT=1048 WIND
2023-03-29 14:12:21 Security Warning Intrusion -> src=89.248.165.242 DST=78.147.238.191 LEN=40 TOS=0x00 PREC=0x00 TTL=249 ID=22234 PROTO=TCP SPT=55076 DPT=58518 WIN
2023-03-29 14:02:30 Security Warning Intrusion -> src=162.142.125.143 DST=78.147.238.191 LEN=44 TOS=0x00 PREC=0x00 TTL=41 ID=50335 PROTO=TCP SPT=5789 DPT=58603 WIND
2023-03-29 13:52:20 Security Warning Intrusion -> src=85.209.134.231 DST=78.147.238.191 LEN=40 TOS=0x00 PREC=0x00 TTL=249 ID=54321 PROTO=TCP SPT=48373 DPT=5555 WIND
2023-03-29 13:42:21 Security Warning Intrusion -> src=94.102.61.38 DST=78.147.238.191 LEN=40 TOS=0x00 PREC=0x00 TTL=249 ID=54321 PROTO=TCP SPT=53824 DPT=3070 WINDOW
2023-03-29 13:32:21 Security Warning Intrusion -> src=80.82.77.144 DST=78.147.238.191 LEN=40 TOS=0x00 PREC=0x00 TTL=249 ID=54321 PROTO=TCP SPT=50378 DPT=1201 WINDOW
2023-03-29 13:22:22 Security Warning Intrusion -> src=134.209.103.181 DST=78.147.238.191 LEN=40 TOS=0x00 PREC=0x00 TTL=241 ID=1000 PROTO=TCP SPT=43421 DPT=54308 WIN
2023-03-29 13:12:20 Security Warning Intrusion -> src=207.154.210.100 DST=78.147.238.191 LEN=40 TOS=0x00 PREC=0x00 TTL=246 ID=31722 PROTO=TCP SPT=51847 DPT=402 WIND
2023-03-29 13:02:19 Security Warning Intrusion -> src=66.29.136.194 DST=78.147.238.191 LEN=40 TOS=0x00 PREC=0x00 TTL=240 ID=41188 PROTO=TCP SPT=50962 DPT=1548 WINDO
2023-03-29 12:52:27 Security Warning Intrusion -> src=66.29.136.194 DST=78.147.238.191 LEN=40 TOS=0x00 PREC=0x00 TTL=240 ID=61085 PROTO=TCP SPT=50464 DPT=1547 WINDO
2023-03-29 12:42:25 Security Warning Intrusion -> src=89.248.165.253 DST=78.147.238.191 LEN=40 TOS=0x00 PREC=0x00 TTL=249 ID=56831 PROTO=TCP SPT=55186 DPT=11047 WIN
2023-03-29 12:32:24 Security Warning Intrusion -> src=89.248.165.46 DST=78.147.238.191 LEN=40 TOS=0x00 PREC=0x00 TTL=249 ID=63081 PROTO=TCP SPT=43260 DPT=8600 WINDO
2023-03-29 12:22:20 Security Warning Intrusion -> src=104.219.251.142 DST=78.147.238.191 LEN=40 TOS=0x00 PREC=0x00 TTL=240 ID=10324 PROTO=TCP SPT=48767 DPT=753 WIND
2023-03-29 12:12:19 Security Warning Intrusion -> src=149.18.73.15 DST=78.147.238.191 LEN=40 TOS=0x00 PREC=0x00 TTL=250 ID=24532 PROTO=TCP SPT=47203 DPT=5080 WINDOW
2023-03-29 12:02:20 Security Warning Intrusion -> src=167.248.133.150 DST=78.147.238.191 LEN=44 TOS=0x00 PREC=0x00 TTL=42 ID=4614 PROTO=TCP SPT=24657 DPT=8842 WINDO
2023-03-29 11:52:21 Security Warning Intrusion -> src=43.130.11.228 DST=78.147.238.191 LEN=52 TOS=0x00 PREC=0x00 TTL=50 ID=58921 DFPROTO=TCP SPT=59945 DPT=5280 WIND
2023-03-29 11:42:22 Security Warning Intrusion -> src=185.81.68.102 DST=78.147.238.191 LEN=40 TOS=0x00 PREC=0x00 TTL=245 ID=37433 PROTO=TCP SPT=43013 DPT=3637 WINDO
2023-03-29 11:32:22 Security Warning Intrusion -> src=64.62.197.9 DST=78.147.238.191 LEN=40 TOS=0x00 PREC=0x00 TTL=243 ID=54321 PROTO=TCP SPT=57088 DPT=8081 WINDOW=
2023-03-29 11:32:12 Security Warning DROP UDP SAMBA Request
2023-03-29 11:22:19 Security Warning Intrusion -> src=89.248.165.46 DST=78.147.238.191 LEN=40 TOS=0x00 PREC=0x00 TTL=249 ID=62395 PROTO=TCP SPT=43260 DPT=11056 WIND
2023-03-29 11:12:37 Security Warning Intrusion -> src=89.248.165.46 DST=78.147.238.191 LEN=40 TOS=0x00 PREC=0x00 TTL=249 ID=42419 PROTO=TCP SPT=43260 DPT=10727 WIND
2023-03-29 11:02:21 Security Warning Intrusion -> src=89.248.165.45 DST=78.147.238.191 LEN=40 TOS=0x00 PREC=0x00 TTL=249 ID=51411 PROTO=TCP SPT=55141 DPT=21466 WIND
2023-03-29 10:52:20 Security Warning Intrusion -> src=31.220.1.83 DST=78.147.238.191 LEN=40 TOS=0x00 PREC=0x00 TTL=249 ID=54321 PROTO=TCP SPT=58376 DPT=23 WINDOW=65
2023-03-29 10:42:24 Security Warning Intrusion -> src=219.159.67.4 DST=78.147.238.191 LEN=44 TOS=0x00 PREC=0x00 TTL=235 ID=17866 PROTO=TCP SPT=58914 DPT=110 WINDOW=
2023-03-29 10:34:12 Security Warning Detect UDP port scan attack, scan packet from 146.88.240.4.
2023-03-29 10:32:23 Security Warning Intrusion -> src=89.248.165.46 DST=78.147.238.191 LEN=40 TOS=0x00 PREC=0x00 TTL=249 ID=20428 PROTO=TCP SPT=43260 DPT=9584 WINDO
2023-03-29 10:22:24 Security Warning Intrusion -> src=94.102.61.41 DST=78.147.238.191 LEN=44 TOS=0x00 PREC=0x00 TTL=249 ID=54321 PROTO=TCP SPT=44064 DPT=5454 WINDOW
2023-03-29 10:12:33 Security Warning Intrusion -> src=209.188.21.246 DST=78.147.238.191 LEN=40 TOS=0x00 PREC=0x00 TTL=240 ID=60723 PROTO=TCP SPT=59651 DPT=2671 WIND
2023-03-29 10:02:30 Security Warning Intrusion -> src=92.63.197.149 DST=78.147.238.191 LEN=40 TOS=0x00 PREC=0x00 TTL=249 ID=61788 PROTO=TCP SPT=51675 DPT=33387 WIND
2023-03-29 09:58:19 Security Warning DROP FTP Request
2023-03-29 09:52:22 Security Warning Intrusion -> src=94.102.61.42 DST=78.147.238.191 LEN=44 TOS=0x00 PREC=0x00 TTL=249 ID=54321 PROTO=TCP SPT=55299 DPT=8406 WINDOW
2023-03-29 09:42:20 Security Warning Intrusion -> src=5.8.18.8 DST=78.147.238.191 LEN=40 TOS=0x00 PREC=0x00 TTL=249 ID=9258 PROTO=TCP SPT=57851 DPT=36644 WINDOW=102
2023-03-29 09:32:29 Security Warning Intrusion -> src=89.248.165.46 DST=78.147.238.191 LEN=40 TOS=0x00 PREC=0x00 TTL=249 ID=24531 PROTO=TCP SPT=43260 DPT=6354 WINDO
2023-03-29 09:22:24 Security Warning Intrusion -> src=176.111.174.83 DST=78.147.238.191 LEN=40 TOS=0x00 PREC=0x00 TTL=243 ID=38488 PROTO=TCP SPT=42550 DPT=2474 WIND
2023-03-29 09:12:35 Security Warning Intrusion -> src=79.124.59.82 DST=78.147.238.191 LEN=40 TOS=0x00 PREC=0x00 TTL=245 ID=38183 PROTO=TCP SPT=41507 DPT=8445 WINDOW
2023-03-29 09:02:31 Security Warning Intrusion -> src=162.142.125.233 DST=78.147.238.191 LEN=44 TOS=0x00 PREC=0x00 TTL=41 ID=44422 PROTO=TCP SPT=41594 DPT=8168 WIND
2023-03-29 08:52:21 Security Warning Intrusion -> src=80.82.77.144 DST=78.147.238.191 LEN=40 TOS=0x00 PREC=0x00 TTL=249 ID=54321 PROTO=TCP SPT=55912 DPT=502 WINDOW=
2023-03-29 08:42:35 Security Warning Intrusion -> src=170.106.173.40 DST=78.147.238.191 LEN=52 TOS=0x00 PREC=0x00 TTL=51 ID=48471 DFPROTO=TCP SPT=49495 DPT=7090 WIN
on 29-03-2023 03:47 PM
Brill! thank you so much for your help. fingers cross this stop them or least slow them down
on 29-03-2023 02:53 PM
OK thanks. I've ordered the router, it should be with you within a couple of days 🙂
Thanks
Chris
Chris, Community Team
Our latest Blog l Share your Ideas l Service Status l Help with your Service l Community Stars l Set your preferences
on 29-03-2023 02:31 PM
just done this 🙂 Thanks !
on 29-03-2023 01:45 PM
Could you just add the account holders name to the private notes section of your community profile and I'll arrange to send the router
Thanks
Chris
Chris, Community Team
Our latest Blog l Share your Ideas l Service Status l Help with your Service l Community Stars l Set your preferences
on 29-03-2023 01:41 PM
Yes please! i'm bit concerned how much they was messing around with my current one last night. i been with TT for 8 years probably about time i get a new router.
on 29-03-2023 12:40 PM
Hi GuyOnMars,
I can send another router to test with, would you like us to arrange this?
Chris
Chris, Community Team
Our latest Blog l Share your Ideas l Service Status l Help with your Service l Community Stars l Set your preferences
on 29-03-2023 12:12 PM
Hi @GuyOnMars no idea of a solution but your post is escalated to someone who can! I'd send you a new router with likely better firewall.
Expect to hear soon.