DrayTek UK Users' Community Forum

Help, Advice and Solutions from DrayTek Users

Interpreting DoS reports

  • marcw
  • Topic Author
  • Offline
  • Junior Member
  • Junior Member
More
31 Oct 2011 17:28 #69870 by marcw
Interpreting DoS reports was created by marcw
Hi guys.

I have my router set up to send me reports on DoS attacks, but I'm having difficulty interpreting the content.

Does anyone have a good resource to point me to?

Example:

[DOS][Block][tcp_flag, scanner=fin_wo_ack][77.190.74.182:50618->77.190.74.182:25126][TCP][HLen=20, TLen=52, Flag=F, Seq=3909450284, Ack=0, Win=65535]

That appears to contain two IP addresses that have *nothing* to do with me; other times I get what appears to be one of my WAN addresses attacking another one in the same IP block.
Neither of these scenarios seem to make any sense. :?

--
Marc

Cleopatra Consultants Ltd

Please Log in or Create an account to join the conversation.

More
31 May 2012 12:21 #72392 by ghostworks
Replied by ghostworks on topic Re: Interpreting DoS reports
Same here

[DOS][Block][tcp_flag, scanner=fin_wo_ack][192.168.1.29:59161->65.55.64.250:443][TCP][HLen=20,

Please Log in or Create an account to join the conversation.

Moderators: Sami