Solved 9 More DoS STORM Attacks?

Discussion in 'Network Help' started by sodapop554, Jun 6, 2012.


Thread Status:
Not open for further replies.
  1. sodapop554 Elite Member

    Elite
    Message Count:
    701
    Likes Received:
    7
    My System
    Loading...
    I know my current newer computer isn't infected based off the scans I've performed recently. However if that's the case, what could've triggered the 9 false positive DoS STORM Attacks my router logged about 5 hours ago?

    [DoS attack: STORM] attack packets in last 20 sec from ip [192.168.1.2], Tuesday, Jun 05,2012 18:38:46
    [DoS attack: STORM] attack packets in last 20 sec from ip [192.168.1.2], Tuesday, Jun 05,2012 18:38:20
    [DoS attack: STORM] attack packets in last 20 sec from ip [192.168.1.2], Tuesday, Jun 05,2012 18:37:59
    [DoS attack: STORM] attack packets in last 20 sec from ip [192.168.1.2], Tuesday, Jun 05,2012 18:37:31
    [DoS attack: STORM] attack packets in last 20 sec from ip [192.168.1.2], Tuesday, Jun 05,2012 18:37:10
    [DoS attack: STORM] attack packets in last 20 sec from ip [192.168.1.2], Tuesday, Jun 05,2012 18:36:49
    [DoS attack: STORM] attack packets in last 20 sec from ip [192.168.1.2], Tuesday, Jun 05,2012 18:36:20
    [DoS attack: STORM] attack packets in last 20 sec from ip [192.168.1.2], Tuesday, Jun 05,2012 18:35:59
    [DoS attack: STORM] attack packets in last 20 sec from ip [192.168.1.2], Tuesday, Jun 05,2012 18:35:38

    By just guessing I'm assuming it could be Java although I'm not sure. I would appreciate any & all opinions on this or ideas as to how I could debunk what is causing them.

  2. Hengis PCHF Manager

    Manager
    PCHF Staff
    Message Count:
    39,466
    Likes Received:
    5,025
    My System
    Loading...
    These "attacks" are coming from inside your network (local IP 192.168.1.2) - Are you using any Torrent, file sharing, server, software?
  3. sodapop554 Elite Member

    Elite
    Message Count:
    701
    Likes Received:
    7
    My System
    Loading...
    Nope, the only thing I can think of is the game I play that uses Java. Upon logging in there are over 100 different worlds (servers) to play on. Each one of these worlds is pinged so that players can try to chose the one that will perform best for them (world with lowest ping). In addition the game does store some files on my computer. The game cache which includes images as well as graphics & audio settings. Do you think this could be the cause?

    EDIT: Upon searching "DoS" on Wikipedia I found the following after I scrolled down & read a bit.

    "Routers have also been known to create unintentional DoS attacks, as both D-Link and Netgear routers have created NTP vandalism by flooding NTP servers without respecting the restrictions of client types or geographical limitations."

    If not what I stated about the game I play, could what I have in quoted italics instead be the cause?
  4. Google Advertisement

  5. Belahzur Freedom Fighter

    PCHF Staff
    Message Count:
    6,779
    Likes Received:
    883
    My System
    Loading...
    It is probably the games, if your pinging many servers at; once to test for the best connection, then ZA may have picked that up as a DDOS attack because that's essentially what a DOS attack is - pinging a website many times a second.
  6. sodapop554 Elite Member

    Elite
    Message Count:
    701
    Likes Received:
    7
    My System
    Loading...
    It's my router that's logging these attacks, not Zone Alarm. However, you're probably right though since sometimes a world's ping will show up as "N/A". It could be that my router is preventing it from pinging the servers properly. What I'll do is keep checking these logs every hour for the rest of this month. If it continues to only rarely happen when I load the game then that's probably it. I load the game at least twice a day, everyday. So being that it's these events have only shown up twice (total of 12 individual attacks), so far over the past two weeks that in itself I think automatically rules out anything malicious. I'll ask that this thread be kept open though until I'm able to examine a long term pattern of these events to even more prove it's just the game.
  7. sodapop554 Elite Member

    Elite
    Message Count:
    701
    Likes Received:
    7
    My System
    Loading...
    As an update on June the 6th it every time I retrieved the game server pings these attacks reappeared in my routers logs. This lead me to think that the company must have done something to their site that is causing this to happen every time like clockwork, although the number of attacks did vary (from 9 to 3) they did show up every time, yesterday that is. Today (June the 7th) however not one has shown up no matter how many times I've tried reloading the game. Is it safe to assume that whatever the problem was, was on their end & is now fixed since it's no longer causing my router to think these are "attacks"?
  8. Hengis PCHF Manager

    Manager
    PCHF Staff
    Message Count:
    39,466
    Likes Received:
    5,025
    My System
    Loading...
    This is the relevant part of your 1st post:
    ...the IP is on your network.
  9. sodapop554 Elite Member

    Elite
    Message Count:
    701
    Likes Received:
    7
    My System
    Loading...
    I already know that much, that IP belongs to my computer. Or at least that's the IP that represents mine once I'm logged into my router. My dad's laptop is 192.168.1.3 & if I plug in my old computer in place of my new one it's 192.168.1.4. So it seems that the last number goes up one depending on the computer. Are you trying to say that it's on my end though & not the gaming companies?
  10. Hengis PCHF Manager

    Manager
    PCHF Staff
    Message Count:
    39,466
    Likes Received:
    5,025
    My System
    Loading...
    The so-called "DDOS" is coming from your router - it is referencing (only) an address on your internal network. I don't see the issue here..
  11. sodapop554 Elite Member

    Elite
    Message Count:
    701
    Likes Received:
    7
    My System
    Loading...


    Oh, well it wasn't really an issue to start with since it doesn't seem to be effecting my game play. The only thing it does cause is that the server pings took longer to be retrieved. In addition to the simple fact that my router is logging something harmless as an attack. It didn't do it again all day yesterday though so now I'm not sure if it was just the result of my router booting improperly or what. Could it be this bug or glitch is occurring because my routers firmware isn't up-to-date? Should I try updating my routers firmware manually? I've been told doing so can be risky & should only be done if the update contains an important fix. Below is all it says about the update when viewing via logged into my router. Is this an important update or what?

    Current GUI Language Version: 1.0.2.18_2.1.5.1
    New GUI Language Version: 1.0.2.28_2.1.10.1
    Current Firmware Version 1.0.2.18NA
    New Firmware Version 1.0.2.28NA
    Release Notes:
    1. Update to version 1.0.2.28
  12. Crush Administrator & Security Team Leader

    Manager
    PCHF Staff
    Message Count:
    39,930
    Likes Received:
    3,672
    My System
    Loading...
    It's as important as keeping your antivirus up to date :)
  13. sodapop554 Elite Member

    Elite
    Message Count:
    701
    Likes Received:
    7
    My System
    Loading...
    Alright I'll give it a try then, hopefully it wont damage my router. I'll have to backup all my current settings 1st although I'll probably do so by just writing them down.
  14. sodapop554 Elite Member

    Elite
    Message Count:
    701
    Likes Received:
    7
    My System
    Loading...
    While I'm writing down all these settings I do have one question that I need answered. If it's as important as my AV then why was I told numerous times on these forums not to update it because of the risk it could damage my router?
  15. Crush Administrator & Security Team Leader

    Manager
    PCHF Staff
    Message Count:
    39,930
    Likes Received:
    3,672
    My System
    Loading...
    It could damage your router depending on how much configuration you've done, but as a general rule of thumb it should be kept updated.
  16. sodapop554 Elite Member

    Elite
    Message Count:
    701
    Likes Received:
    7
    My System
    Loading...
    Hmm alright well would it help if I restored all default settings before updating? I've already written down all the necessary custom settings that I've been instructed by PCHF in the past so I'll know what to set it back to. Also too based off the release notes it doesn't say this update fixes any crucial bugs, the only problems it does address are issues in how menus are displayed.

    *EDIT: Here are the links that entitle what minor bugs are fixed with this update...

    http://support.netgear.com/app/answers/detail/a_id/19969

    http://support.netgear.com/app/answ...2LzEvdGltZS8xMzM5MTkwNzE1L3NpZC9QalBMS2Etaw==

9 More DoS STORM Attacks?

Thread Status:
Not open for further replies.