cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

FIbre Support

Get expert support with your Fibre connection.

Warning Intrusion / cyber attack

GuyOnMars
Popular Poster
Private Message
Message 17 of 17

hi

all of a sudden i started having issues with my connection last night and when I look I had a lot of Intrusion security alerts, that keep coming up every 10 mins(ish) .(see below for first lot),

 

also on the log was things like a IP spoofing 192.168.1.1 alerts and some other attack warning.  I will copy whole log when I get home.

 

 

Manufacturer:Huawei Technologies Co., Ltd.
Product Style:HG633
Serial Number:
Hardware Version:H.1.01
Software Version:v2.00t
2023-03-29 01:46:01 Security Warning Intrusion -> src=157.245.156.209 DST=78.145.245.247 LEN=44 TOS=0x00 PREC=0x00 TTL=241 ID=54321 PROTO=TCP SPT=45130 DPT=1950 WIN
2023-03-29 01:39:43 Security Warning DROP FTP Request
2023-03-29 01:39:18 Security Warning ACCEPT SAMBA Request
2023-03-29 01:36:10 Security Warning Intrusion -> src=176.111.174.91 DST=78.145.245.247 LEN=40 TOS=0x00 PREC=0x00 TTL=244 ID=47635 PROTO=TCP SPT=42777 DPT=2880 WIND
2023-03-29 01:31:13 Security Warning DROP TCP SAMBA Request
2023-03-29 01:26:02 Security Warning Intrusion -> src=78.128.113.78 DST=78.145.245.247 LEN=40 TOS=0x00 PREC=0x00 TTL=245 ID=29616 PROTO=TCP SPT=50872 DPT=2859 WINDO
2023-03-29 01:17:55 Security Warning DROP UDP SAMBA Request
2023-03-29 01:16:04 Security Warning Intrusion -> src=162.142.125.84 DST=78.145.245.247 LEN=44 TOS=0x00 PREC=0x00 TTL=41 ID=43972 PROTO=TCP SPT=42360 DPT=10399 WIND

 

 

 

i had same router for 8 years . the last time on the log I the last alert was in Jan., in the end, I end up turning off the internet after battling for hours and trying to work out what was going on.

 

 

0 Likes
16 REPLIES 16

Message 1 of 17

@GuyOnMars good guys on the support team. 

I don't work here and all my opinions are my own.
0 Likes

Message 2 of 17
0 Likes

Message 3 of 17

That's amazing, we received it this morning! thanks chris

0 Likes

Message 4 of 17

tryed this , still same ip 😕

0 Likes

Message 5 of 17

i Unplugged it over night. il have a look at the log when I get home 

0 Likes

Message 6 of 17

Morning,

 

Please let us know how you get on.

 

Thanks

 

0 Likes

Divsec
Community Star
Private Message TalkTalk
Message 7 of 17

Hi @GuyOnMars unplug the router, have your dinner, and try reconnecting 

I don't work here and all my opinions are my own.

Message 8 of 17

To be honest that looks like nothing more than your router firewall doing its job. You can try forcing an IP address change by turning off the router for around 30 minutes. 

0 Likes

GuyOnMars
Popular Poster
Private Message
Message 9 of 17

 

They literally haven't stop since i left for work. -.-

 

Is it worth trying get my ip address changed 

 

Manufacturer:Huawei Technologies Co., Ltd.

Product Style:HG633

Serial Number:C4REQ15825013746

Hardware Version:H.1.01

Software Version:v2.00t

2023-03-29 18:52:33 Security Warning Intrusion -> src=198.199.118.8 DST=78.147.238.191 LEN=40 TOS=0x00 PREC=0x00 TTL=246 ID=54321 PROTO=TCP SPT=55874 DPT=2078 WINDO

2023-03-29 18:42:27 Security Warning Intrusion -> src=47.96.137.227 DST=78.147.238.191 LEN=40 TOS=0x00 PREC=0x00 TTL=238 ID=5648 PROTO=TCP SPT=48377 DPT=2376 WINDOW

2023-03-29 18:32:45 Security Warning Intrusion -> src=194.36.189.194 DST=78.147.238.191 LEN=40 TOS=0x00 PREC=0x00 TTL=248 ID=1393 PROTO=TCP SPT=51039 DPT=52985 WIND

2023-03-29 18:24:52 Security Warning DROP FTP Request

2023-03-29 18:22:32 Security Warning Intrusion -> src=94.102.61.27 DST=78.147.238.191 LEN=40 TOS=0x00 PREC=0x00 TTL=249 ID=54321 PROTO=TCP SPT=47653 DPT=1042 WINDOW

2023-03-29 18:19:05 Security Warning Detect UDP port scan attack, scan packet from 192.168.1.4.

 

2023-03-29 18:12:20 Security Warning Intrusion -> src=212.70.149.42 DST=78.147.238.191 LEN=40 TOS=0x00 PREC=0x00 TTL=245 ID=44542 PROTO=TCP SPT=46902 DPT=23481 WIND

2023-03-29 18:02:39 Security Warning Intrusion -> src=89.248.165.100 DST=78.147.238.191 LEN=40 TOS=0x00 PREC=0x00 TTL=249 ID=25877 PROTO=TCP SPT=55041 DPT=3329 WIND

2023-03-29 17:52:20 Security Warning Intrusion -> src=89.248.165.100 DST=78.147.238.191 LEN=40 TOS=0x00 PREC=0x00 TTL=249 ID=20413 PROTO=TCP SPT=55041 DPT=2204 WIND

2023-03-29 17:42:22 Security Warning Intrusion -> src=89.248.163.64 DST=78.147.238.191 LEN=40 TOS=0x00 PREC=0x00 TTL=249 ID=43955 PROTO=TCP SPT=55111 DPT=10152 WIND

2023-03-29 17:32:33 Security Warning Intrusion -> src=89.248.165.100 DST=78.147.238.191 LEN=40 TOS=0x00 PREC=0x00 TTL=249 ID=62673 PROTO=TCP SPT=55041 DPT=33392 WIN

2023-03-29 17:22:44 Security Warning Intrusion -> src=192.241.228.8 DST=78.147.238.191 LEN=40 TOS=0x00 PREC=0x00 TTL=246 ID=54321 PROTO=TCP SPT=50949 DPT=512 WINDOW

2023-03-29 17:12:32 Security Warning Intrusion -> src=89.248.165.45 DST=78.147.238.191 LEN=40 TOS=0x00 PREC=0x00 TTL=249 ID=64255 PROTO=TCP SPT=55141 DPT=608 WINDOW

2023-03-29 17:02:30 Security Warning Intrusion -> src=89.248.165.45 DST=78.147.238.191 LEN=40 TOS=0x00 PREC=0x00 TTL=249 ID=43809 PROTO=TCP SPT=55141 DPT=6080 WINDO

2023-03-29 16:52:25 Security Warning Intrusion -> src=212.70.149.46 DST=78.147.238.191 LEN=40 TOS=0x00 PREC=0x00 TTL=245 ID=54321 PROTO=TCP SPT=46033 DPT=8443 WINDO

2023-03-29 16:42:23 Security Warning Intrusion -> src=80.82.77.139 DST=78.147.238.191 LEN=44 TOS=0x00 PREC=0x00 TTL=122 ID=46031 PROTO=TCP SPT=20041 DPT=22 WINDOW=6

2023-03-29 16:32:19 Security Warning Intrusion -> src=89.248.165.46 DST=78.147.238.191 LEN=40 TOS=0x00 PREC=0x00 TTL=249 ID=41766 PROTO=TCP SPT=43260 DPT=13870 WIND

2023-03-29 16:22:23 Security Warning Intrusion -> src=89.248.165.100 DST=78.147.238.191 LEN=40 TOS=0x00 PREC=0x00 TTL=249 ID=36708 PROTO=TCP SPT=55041 DPT=12402 WIN

2023-03-29 16:22:09 Security Warning DROP TCP SAMBA Request

2023-03-29 16:12:19 Security Warning Intrusion -> src=89.248.163.64 DST=78.147.238.191 LEN=40 TOS=0x00 PREC=0x00 TTL=249 ID=12294 PROTO=TCP SPT=55111 DPT=50912 WIND

2023-03-29 16:02:22 Security Warning Intrusion -> src=84.243.57.21 DST=78.147.238.191 LEN=40 TOS=0x00 PREC=0x00 TTL=49 ID=57203 PROTO=TCP SPT=58658 DPT=22 WINDOW=57

2023-03-29 15:52:20 Security Warning Intrusion -> src=89.248.163.64 DST=78.147.238.191 LEN=40 TOS=0x00 PREC=0x00 TTL=249 ID=30262 PROTO=TCP SPT=55111 DPT=11152 WIND

2023-03-29 15:42:21 Security Warning Intrusion -> src=66.29.136.194 DST=78.147.238.191 LEN=40 TOS=0x00 PREC=0x00 TTL=240 ID=10974 PROTO=TCP SPT=40831 DPT=1568 WINDO

2023-03-29 15:32:33 Security Warning Intrusion -> src=89.248.165.242 DST=78.147.238.191 LEN=40 TOS=0x00 PREC=0x00 TTL=249 ID=42876 PROTO=TCP SPT=55076 DPT=20861 WIN

2023-03-29 15:22:27 Security Warning Intrusion -> src=183.136.225.9 DST=78.147.238.191 LEN=44 TOS=0x00 PREC=0x00 TTL=113 ID=0 PROTO=TCP SPT=46860 DPT=6668 WINDOW=29

2023-03-29 15:12:22 Security Warning Intrusion -> src=209.188.21.246 DST=78.147.238.191 LEN=40 TOS=0x00 PREC=0x00 TTL=240 ID=51018 PROTO=TCP SPT=58745 DPT=2681 WIND

2023-03-29 15:02:37 Security Warning Intrusion -> src=66.29.136.194 DST=78.147.238.191 LEN=40 TOS=0x00 PREC=0x00 TTL=240 ID=17735 PROTO=TCP SPT=58341 DPT=1563 WINDO

2023-03-29 14:52:25 Security Warning Intrusion -> src=89.248.163.64 DST=78.147.238.191 LEN=40 TOS=0x00 PREC=0x00 TTL=249 ID=21721 PROTO=TCP SPT=55111 DPT=33910 WIND

2023-03-29 14:42:26 Security Warning Intrusion -> src=89.248.165.45 DST=78.147.238.191 LEN=40 TOS=0x00 PREC=0x00 TTL=249 ID=1445 PROTO=TCP SPT=55141 DPT=1338 WINDOW

2023-03-29 14:32:21 Security Warning Intrusion -> src=5.8.18.8 DST=78.147.238.191 LEN=40 TOS=0x00 PREC=0x00 TTL=249 ID=7384 PROTO=TCP SPT=56639 DPT=37186 WINDOW=102

2023-03-29 14:22:28 Security Warning Intrusion -> src=176.111.174.80 DST=78.147.238.191 LEN=40 TOS=0x00 PREC=0x00 TTL=243 ID=51483 PROTO=TCP SPT=42497 DPT=1048 WIND

2023-03-29 14:12:21 Security Warning Intrusion -> src=89.248.165.242 DST=78.147.238.191 LEN=40 TOS=0x00 PREC=0x00 TTL=249 ID=22234 PROTO=TCP SPT=55076 DPT=58518 WIN

2023-03-29 14:02:30 Security Warning Intrusion -> src=162.142.125.143 DST=78.147.238.191 LEN=44 TOS=0x00 PREC=0x00 TTL=41 ID=50335 PROTO=TCP SPT=5789 DPT=58603 WIND

2023-03-29 13:52:20 Security Warning Intrusion -> src=85.209.134.231 DST=78.147.238.191 LEN=40 TOS=0x00 PREC=0x00 TTL=249 ID=54321 PROTO=TCP SPT=48373 DPT=5555 WIND

2023-03-29 13:42:21 Security Warning Intrusion -> src=94.102.61.38 DST=78.147.238.191 LEN=40 TOS=0x00 PREC=0x00 TTL=249 ID=54321 PROTO=TCP SPT=53824 DPT=3070 WINDOW

2023-03-29 13:32:21 Security Warning Intrusion -> src=80.82.77.144 DST=78.147.238.191 LEN=40 TOS=0x00 PREC=0x00 TTL=249 ID=54321 PROTO=TCP SPT=50378 DPT=1201 WINDOW

2023-03-29 13:22:22 Security Warning Intrusion -> src=134.209.103.181 DST=78.147.238.191 LEN=40 TOS=0x00 PREC=0x00 TTL=241 ID=1000 PROTO=TCP SPT=43421 DPT=54308 WIN

2023-03-29 13:12:20 Security Warning Intrusion -> src=207.154.210.100 DST=78.147.238.191 LEN=40 TOS=0x00 PREC=0x00 TTL=246 ID=31722 PROTO=TCP SPT=51847 DPT=402 WIND

2023-03-29 13:02:19 Security Warning Intrusion -> src=66.29.136.194 DST=78.147.238.191 LEN=40 TOS=0x00 PREC=0x00 TTL=240 ID=41188 PROTO=TCP SPT=50962 DPT=1548 WINDO

2023-03-29 12:52:27 Security Warning Intrusion -> src=66.29.136.194 DST=78.147.238.191 LEN=40 TOS=0x00 PREC=0x00 TTL=240 ID=61085 PROTO=TCP SPT=50464 DPT=1547 WINDO

2023-03-29 12:42:25 Security Warning Intrusion -> src=89.248.165.253 DST=78.147.238.191 LEN=40 TOS=0x00 PREC=0x00 TTL=249 ID=56831 PROTO=TCP SPT=55186 DPT=11047 WIN

2023-03-29 12:32:24 Security Warning Intrusion -> src=89.248.165.46 DST=78.147.238.191 LEN=40 TOS=0x00 PREC=0x00 TTL=249 ID=63081 PROTO=TCP SPT=43260 DPT=8600 WINDO

2023-03-29 12:22:20 Security Warning Intrusion -> src=104.219.251.142 DST=78.147.238.191 LEN=40 TOS=0x00 PREC=0x00 TTL=240 ID=10324 PROTO=TCP SPT=48767 DPT=753 WIND

2023-03-29 12:12:19 Security Warning Intrusion -> src=149.18.73.15 DST=78.147.238.191 LEN=40 TOS=0x00 PREC=0x00 TTL=250 ID=24532 PROTO=TCP SPT=47203 DPT=5080 WINDOW

2023-03-29 12:02:20 Security Warning Intrusion -> src=167.248.133.150 DST=78.147.238.191 LEN=44 TOS=0x00 PREC=0x00 TTL=42 ID=4614 PROTO=TCP SPT=24657 DPT=8842 WINDO

2023-03-29 11:52:21 Security Warning Intrusion -> src=43.130.11.228 DST=78.147.238.191 LEN=52 TOS=0x00 PREC=0x00 TTL=50 ID=58921 DFPROTO=TCP SPT=59945 DPT=5280 WIND

2023-03-29 11:42:22 Security Warning Intrusion -> src=185.81.68.102 DST=78.147.238.191 LEN=40 TOS=0x00 PREC=0x00 TTL=245 ID=37433 PROTO=TCP SPT=43013 DPT=3637 WINDO

2023-03-29 11:32:22 Security Warning Intrusion -> src=64.62.197.9 DST=78.147.238.191 LEN=40 TOS=0x00 PREC=0x00 TTL=243 ID=54321 PROTO=TCP SPT=57088 DPT=8081 WINDOW=

2023-03-29 11:32:12 Security Warning DROP UDP SAMBA Request

2023-03-29 11:22:19 Security Warning Intrusion -> src=89.248.165.46 DST=78.147.238.191 LEN=40 TOS=0x00 PREC=0x00 TTL=249 ID=62395 PROTO=TCP SPT=43260 DPT=11056 WIND

2023-03-29 11:12:37 Security Warning Intrusion -> src=89.248.165.46 DST=78.147.238.191 LEN=40 TOS=0x00 PREC=0x00 TTL=249 ID=42419 PROTO=TCP SPT=43260 DPT=10727 WIND

2023-03-29 11:02:21 Security Warning Intrusion -> src=89.248.165.45 DST=78.147.238.191 LEN=40 TOS=0x00 PREC=0x00 TTL=249 ID=51411 PROTO=TCP SPT=55141 DPT=21466 WIND

2023-03-29 10:52:20 Security Warning Intrusion -> src=31.220.1.83 DST=78.147.238.191 LEN=40 TOS=0x00 PREC=0x00 TTL=249 ID=54321 PROTO=TCP SPT=58376 DPT=23 WINDOW=65

2023-03-29 10:42:24 Security Warning Intrusion -> src=219.159.67.4 DST=78.147.238.191 LEN=44 TOS=0x00 PREC=0x00 TTL=235 ID=17866 PROTO=TCP SPT=58914 DPT=110 WINDOW=

2023-03-29 10:34:12 Security Warning Detect UDP port scan attack, scan packet from 146.88.240.4.

 

2023-03-29 10:32:23 Security Warning Intrusion -> src=89.248.165.46 DST=78.147.238.191 LEN=40 TOS=0x00 PREC=0x00 TTL=249 ID=20428 PROTO=TCP SPT=43260 DPT=9584 WINDO

2023-03-29 10:22:24 Security Warning Intrusion -> src=94.102.61.41 DST=78.147.238.191 LEN=44 TOS=0x00 PREC=0x00 TTL=249 ID=54321 PROTO=TCP SPT=44064 DPT=5454 WINDOW

2023-03-29 10:12:33 Security Warning Intrusion -> src=209.188.21.246 DST=78.147.238.191 LEN=40 TOS=0x00 PREC=0x00 TTL=240 ID=60723 PROTO=TCP SPT=59651 DPT=2671 WIND

2023-03-29 10:02:30 Security Warning Intrusion -> src=92.63.197.149 DST=78.147.238.191 LEN=40 TOS=0x00 PREC=0x00 TTL=249 ID=61788 PROTO=TCP SPT=51675 DPT=33387 WIND

2023-03-29 09:58:19 Security Warning DROP FTP Request

2023-03-29 09:52:22 Security Warning Intrusion -> src=94.102.61.42 DST=78.147.238.191 LEN=44 TOS=0x00 PREC=0x00 TTL=249 ID=54321 PROTO=TCP SPT=55299 DPT=8406 WINDOW

2023-03-29 09:42:20 Security Warning Intrusion -> src=5.8.18.8 DST=78.147.238.191 LEN=40 TOS=0x00 PREC=0x00 TTL=249 ID=9258 PROTO=TCP SPT=57851 DPT=36644 WINDOW=102

2023-03-29 09:32:29 Security Warning Intrusion -> src=89.248.165.46 DST=78.147.238.191 LEN=40 TOS=0x00 PREC=0x00 TTL=249 ID=24531 PROTO=TCP SPT=43260 DPT=6354 WINDO

2023-03-29 09:22:24 Security Warning Intrusion -> src=176.111.174.83 DST=78.147.238.191 LEN=40 TOS=0x00 PREC=0x00 TTL=243 ID=38488 PROTO=TCP SPT=42550 DPT=2474 WIND

2023-03-29 09:12:35 Security Warning Intrusion -> src=79.124.59.82 DST=78.147.238.191 LEN=40 TOS=0x00 PREC=0x00 TTL=245 ID=38183 PROTO=TCP SPT=41507 DPT=8445 WINDOW

2023-03-29 09:02:31 Security Warning Intrusion -> src=162.142.125.233 DST=78.147.238.191 LEN=44 TOS=0x00 PREC=0x00 TTL=41 ID=44422 PROTO=TCP SPT=41594 DPT=8168 WIND

2023-03-29 08:52:21 Security Warning Intrusion -> src=80.82.77.144 DST=78.147.238.191 LEN=40 TOS=0x00 PREC=0x00 TTL=249 ID=54321 PROTO=TCP SPT=55912 DPT=502 WINDOW=

2023-03-29 08:42:35 Security Warning Intrusion -> src=170.106.173.40 DST=78.147.238.191 LEN=52 TOS=0x00 PREC=0x00 TTL=51 ID=48471 DFPROTO=TCP SPT=49495 DPT=7090 WIN

0 Likes

Message 10 of 17

Brill! thank you so much for your help. fingers cross this stop them or least slow them down

0 Likes

Message 11 of 17

OK thanks. I've ordered the router, it should be with you within a couple of days 🙂


Thanks

Chris

0 Likes

Message 12 of 17

just done this 🙂 Thanks !

Message 13 of 17

Could you just add the account holders name to the private notes section of your community profile and I'll arrange to send the router

 

Thanks

Chris

Message 14 of 17

Yes please!   i'm bit concerned how much they was messing around with my current one last night.  i been with TT for 8 years probably about time i get a new router.

0 Likes

Chris-TalkTalk
Support Team
Staff
Private Message
Message 15 of 17

Hi GuyOnMars,

 

I can send another router to test with, would you like us to arrange this?

Chris

Divsec
Community Star
Private Message TalkTalk
Message 16 of 17

Hi @GuyOnMars no idea of a solution but your post is escalated to someone who can! I'd send you a new router with likely better firewall.

Expect to hear soon. 

I don't work here and all my opinions are my own.