Looks like no one’s replied in a while. To start the conversation again, simply ask a new question.

Router showing random outgoing DOS activity since Mavericks update?

Hello, Looking to see if anyone is encountering a similar issue since the Mavericks update.


My iMac is connected to the Internet using a Draktek router, everything has previously been working fine.


The router has a facility where it can send an email when it detects VPN connections and Denial Of Service attacks.


Since the Mavericks update, I'm getting loads of random emails with the following, which seems to suggest that the iMac is attempting to connect to a range of sequential ports at an IP address that seems to belong to Apple.


The 192.168.0.24 is my internal IP of the iMac which happens to be the wireless rather than the Ethernet IP.


I know I could switch the email function off on the router, however I’m curious as to what process is sequentially going through ports.


I have only copied a small section below, today there was 26 emails of the same but with sequencing ports.


Pre Mavericks you I got a few emails a month where it was a genuine DOS issue on the internet side IP.


Any thoughts anyone?

Thanks




2013/10/26 00:44:29 -- [DOS][Block][tcp_flag, scanner=fin_wo_ack][192.168.0.24:52028->17.172.208.43:443][TCP][HLen=20, TLen=52, Flag=F, Seq=2591126476, Ack=0, Win=65535]

2013/10/26 00:53:31 -- [DOS][Block][tcp_flag, scanner=fin_wo_ack][192.168.0.24:52063->17.172.208.43:443][TCP][HLen=20, TLen=52, Flag=F, Seq=4115121682, Ack=0, Win=65535]

2013/10/26 00:53:31 -- [DOS][Block][tcp_flag, scanner=fin_wo_ack][192.168.0.24:52064->17.172.208.43:443][TCP][HLen=20, TLen=52, Flag=F, Seq=12381466, Ack=0, Win=65535]

2013/10/26 00:53:31 -- [DOS][Block][tcp_flag, scanner=fin_wo_ack][192.168.0.24:52065->17.172.208.43:443][TCP][HLen=20, TLen=52, Flag=F, Seq=3046506818, Ack=0, Win=65535]

2013/10/26 00:53:31 -- [DOS][Block][tcp_flag, scanner=fin_wo_ack][192.168.0.24:52066->17.172.208.43:443][TCP][HLen=20, TLen=52, Flag=F, Seq=3479243549, Ack=0, Win=65535]

iMac, OS X Mavericks (10.9)

Posted on Oct 26, 2013 12:52 AM

Reply
1 reply

Feb 13, 2014 12:23 AM in response to applekentuser

I wonder if it is NOT Mavericks related, but another Apple update,


I never upgraded to 10.9. I am still on 10.6.8


I also have a Draytek router, Vigor 2800g


Also getting many daily similar alerts from the router , also emanating fro Apple devices: iPhone and iPad.


Wonder if it is something across the board that Apple has changed.


See my post and log


https://discussions.apple.com/thread/5891329?answerId=24836429022#24836429022



Mine seems to be outgoing on port 53 which is DNS.

Router showing random outgoing DOS activity since Mavericks update?

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple ID.