|
|
| Author |
Message |
| fuzz |
This post is not being displayed .
|
 fuzz World Chat Champion

Joined: 24 Mar 2004 Karma :   
|
 Posted: 23:41 - 17 Jul 2006 Post subject: Strange router/WAP problem |
 |
|
This is really bugging me now. My firewall is constantly blocking data packets from my router. I can't figure out where they're coming from. When I checked the logs, it looks like a rogue signal being transmitted, but this is the second time it has happened in a month. I have reset the router, but I'm still getting these packets.
They are 55 bytes in length, are directed to port 0 for some reason, from port 80, and all the checksums are wrong. I have port forwarding set up on port 80 for my web server which is currently offline. Could this be it somehow?
One thing it means though, is that I don't have a trojan on my system trying to download malware, which was my first thought. There are no outgoing requests, just these incoming acknowledgement packets. Any ideas what's going on? Is it just my router playing up? ____________________ https://www.bikepics.com/members/fuzzbcf/
Bikes: '99 NSR125R, '00 SV650S, K1 GSX-R600, '97 CB500, K3 SV1000S, '16 VFR800 |
|
| Back to top |
|
You must be logged in to rate posts |
|
 |
| fuzz |
This post is not being displayed .
|
 fuzz World Chat Champion

Joined: 24 Mar 2004 Karma :   
|
 Posted: 13:03 - 19 Jul 2006 Post subject: |
 |
|
Anyone? No?
I should be able to answer it myself, really....
I've just passed my Network+ exam  ____________________ https://www.bikepics.com/members/fuzzbcf/
Bikes: '99 NSR125R, '00 SV650S, K1 GSX-R600, '97 CB500, K3 SV1000S, '16 VFR800 |
|
| Back to top |
|
You must be logged in to rate posts |
|
 |
| NSR Mick |
This post is not being displayed .
|
 NSR Mick World Chat Champion

Joined: 26 Jun 2005 Karma :   
|
|
| Back to top |
|
You must be logged in to rate posts |
|
 |
| fuzz |
This post is not being displayed .
|
 fuzz World Chat Champion

Joined: 24 Mar 2004 Karma :   
|
 Posted: 22:45 - 19 Jul 2006 Post subject: |
 |
|
Maybe, but why would the packets be addressed to port 0? AFAIK this is a reserved port not used with any application layer protocol.
It must just be the router sending nonsense, but I want to figure out how to stop it, as it's turning in to it's own little DoS attack - even ping can take some time to display information when it's having a benny.  ____________________ https://www.bikepics.com/members/fuzzbcf/
Bikes: '99 NSR125R, '00 SV650S, K1 GSX-R600, '97 CB500, K3 SV1000S, '16 VFR800 |
|
| Back to top |
|
You must be logged in to rate posts |
|
 |
| Dave1216 |
This post is not being displayed .
|
 Dave1216 Two Stroke Sniffer

Joined: 28 Jun 2006 Karma :   
|
 Posted: 13:55 - 23 Jul 2006 Post subject: |
 |
|
What router are you using? have you tried flashing/upgrading the firmware?
How often is this happening? If it is only a couple of times a month it make's it hard to trace.
If it does appear more frequent - remove each factor at a time. Take the webserver out, and test. Then if it does still appear try and 'borrow' another router from somebody and see if the problem still exists.
Your noticing this on a WinXP machine? Not the router itself? If that's the case, take that machine out of the equation - maybe give linux a whirl for a few day's . ____________________ Yamaha YBR-125 |
|
| Back to top |
|
You must be logged in to rate posts |
|
 |
| fuzz |
This post is not being displayed .
|
 fuzz World Chat Champion

Joined: 24 Mar 2004 Karma :   
|
 Posted: 21:13 - 23 Jul 2006 Post subject: |
 |
|
It's a Linksys BEW11S4 v4 with the latest firmware. It is only on occasion that it happens, but I'm sure it's the router as there are no packets sent to the router to initiate communication. ____________________ https://www.bikepics.com/members/fuzzbcf/
Bikes: '99 NSR125R, '00 SV650S, K1 GSX-R600, '97 CB500, K3 SV1000S, '16 VFR800 |
|
| Back to top |
|
You must be logged in to rate posts |
|
 |
| Dave1216 |
This post is not being displayed .
|
 Dave1216 Two Stroke Sniffer

Joined: 28 Jun 2006 Karma :   
|
 Posted: 02:11 - 24 Jul 2006 Post subject: |
 |
|
If you really want to track down the problem i would suggest using a packet logger such as etherpeek. Make sure you set specific log rule's, ie only log port 0 activity. Maybe try ethereal to help you analyse it.
This should help you see info on the packet, such as header and such. If you do decided to do this - i'd be interested to see a copy of the packet! ____________________ Yamaha YBR-125 |
|
| Back to top |
|
You must be logged in to rate posts |
|
 |
Old Thread Alert!
The last post was made 20 years, 73 days ago. Instead of replying here, would creating a new thread be more useful? |
 |
|
|