Results 1 to 8 of 8

Thread: Something odd in my security log.

  1. #1
    Senior Member AledJ's Avatar
    Join Date
    May 2008
    Posts
    1,899
    Thanks
    168
    Thanked
    25 times in 21 posts

    Something odd in my security log.

    In the security log for my router I have seen this:

    **TCP FIN Scan** 000.000.0.0, 54375->> 00.00.000.000, 80 (from WAN Outbound)

    I have replaced the ip address with 0 (My ip address would be the first lot of numbers! At the time on the log i was watching the f1 racing from earlier in the day.

    Also i assume that the more devices on the wireless network the more the signal strength and speed can go down?
    Last edited by AledJ; 25-08-2009 at 12:32 AM.

  2. #2
    Senior Member AledJ's Avatar
    Join Date
    May 2008
    Posts
    1,899
    Thanks
    168
    Thanked
    25 times in 21 posts

    Re: Something odd in my security log.

    This all happened on the 08/19/2009 23:01:29 and there are 10 entries . But since then there has been no log again of this.

    Getting worried that its something bad :|


    Looked at the ip address its only mine! But my pc was turned off at 22.33 that night. Double checked the router clock and its correct. I have no idea whats going on!
    Last edited by AledJ; 25-08-2009 at 02:11 AM.

  3. #3
    Jay
    Jay is offline
    Gentlemen.. we're history Jay's Avatar
    Join Date
    Aug 2006
    Location
    Jita
    Posts
    8,365
    Thanks
    304
    Thanked
    568 times in 409 posts

    Re: Something odd in my security log.

    maybe a spoof IP address.
    □ΞVΞ□

  4. #4
    Senior Member AledJ's Avatar
    Join Date
    May 2008
    Posts
    1,899
    Thanks
    168
    Thanked
    25 times in 21 posts

    Re: Something odd in my security log.

    Also found this :

    08/19/2009 21:36:40 DHCP Client: [WAN]Receive Ack from 00.000.000.01,Lease time=424979
    08/19/2009 21:36:40 DHCP Client: [WAN]Send Request, Request IP=00.00.000.000
    08/19/2009 21:36:40 DHCP Client: [WAN]Receive Offer from 00.000.000.00
    08/19/2009 21:36:40 DHCP Client: [WAN]Send Discover
    08/19/2009 21:36:38 DHCP Client: [WAN]Send Release

    and:

    08/22/2009 08:30:13 DHCP Client: [WAN]Receive Ack from 00.000.000.00,Lease time=604800
    08/22/2009 08:30:13 DHCP Client: [WAN]Send Request, Request IP=00.00.000.000

    (have changed the ip address to 0 but none look like the one my router uses)

    Not seen that before and don't recognize it. In th log the other ip address are all the same apart from the last number.
    Last edited by AledJ; 25-08-2009 at 11:06 AM.

  5. #5
    Senior Member AledJ's Avatar
    Join Date
    May 2008
    Posts
    1,899
    Thanks
    168
    Thanked
    25 times in 21 posts

    Re: Something odd in my security log.

    Just noticed that the log in the first post happened on the day I contacted belkin via the on line chat thing (but that was mid afternoon). Had problems with only my connection upstairs sometime dropping out. But that was fixed by removing the wireless mouse. Its still puzzling that the first log in my post happened when my pc was off.

  6. #6
    The late but legendary peterb - Onward and Upward peterb's Avatar
    Join Date
    Aug 2005
    Location
    Looking down & checking on swearing
    Posts
    19,378
    Thanks
    2,892
    Thanked
    3,403 times in 2,693 posts

    Re: Something odd in my security log.

    Are the IP addresses you balnked out you public IP addresses? The last one looks like a DHCP request, if you are on dynamic IP allocation.

    As for the other, it's hard to tell - again are those addresses public?

    However IP addresses are scanned routinely by people looking to exploit security weaknesses. I have some ports open (particularly 22 for SSH inbound) and they are regularly attacked - one night there were over 50,000 (unsuccessful ) attempts. Just part of being on the net! An automated IP and port scan is quite easy to set up. If you are behind NAT and don't have any inbound ports open, I wouldn't worry about it.

    There is a statistic that says it takes about 4 minutes for an unpatched windows computer connected directly to the internet (without NAT or any firewall) to become infected with malware.
    (\__/)
    (='.'=)
    (")_(")

    Been helped or just 'Like' a post? Use the Thanks button!
    My broadband speed - 750 Meganibbles/minute

  7. #7
    Senior Member AledJ's Avatar
    Join Date
    May 2008
    Posts
    1,899
    Thanks
    168
    Thanked
    25 times in 21 posts

    Re: Something odd in my security log.

    **TCP FIN Scan** 000.000.0.0, 54375->> 00.00.000.000, 80 (from WAN Outbound)

    The first ip address is mine. As from the others blanked out none are from the router. But what does this all mean:

    08/19/2009 21:36:40 DHCP Client: [WAN]Receive Ack from 00.000.000.01,Lease time=424979
    08/19/2009 21:36:40 DHCP Client: [WAN]Send Request, Request IP=00.00.000.000
    08/19/2009 21:36:40 DHCP Client: [WAN]Receive Offer from 00.000.000.00
    08/19/2009 21:36:40 DHCP Client: [WAN]Send Discover
    08/19/2009 21:36:38 DHCP Client: [WAN]Send Release

    Checked my speed and its normal.

  8. #8
    The late but legendary peterb - Onward and Upward peterb's Avatar
    Join Date
    Aug 2005
    Location
    Looking down & checking on swearing
    Posts
    19,378
    Thanks
    2,892
    Thanked
    3,403 times in 2,693 posts

    Re: Something odd in my security log.

    It looks as if your ISP dynamically allocates you a public IP address - this is the handshake sequence that gets (or renews) the 'lease' on that IP address. The lease time is usually in seconds, and is the time period that the allocated IP address is available to you. At the end of that period, the lease will be renewed if you are still connected, otherwise it will lapse and be available for another user. When you reconnect, you will be allocated a new IP address. by your ISP's DHCP server.

    http://www.tcpipguide.com/free/t_DHC...locationRe.htm

    For more info.
    (\__/)
    (='.'=)
    (")_(")

    Been helped or just 'Like' a post? Use the Thanks button!
    My broadband speed - 750 Meganibbles/minute

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Similar Threads

  1. Replies: 6
    Last Post: 08-11-2007, 05:22 PM
  2. Should I have more wireless security?
    By Parm in forum Networking and Broadband
    Replies: 15
    Last Post: 03-09-2007, 08:14 PM
  3. PC Security firms under threat from Microsoft
    By Steve in forum HEXUS News
    Replies: 10
    Last Post: 07-12-2005, 05:57 PM
  4. Mac + Firefox fans, verses security
    By TheAnimus in forum General Discussion
    Replies: 3
    Last Post: 20-09-2005, 10:22 PM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •