HELP!! DOS Attack Scans! I'm Worried!

Hi all,

So I have noticed some unusual ping spikes while placing league of legends. I have also gotten a few unrecognised devices such as "James's aplewatch" on my nether router. That name is incorrect, apple has two 'P''s and also the apple watch does not have a wifi chip, just bt.


I have also had a "Jamess macbook air" But my MBA was not even turned on, it was shut off completely.

I changed the password and only allowed my mac address and everything was fine.

I now have the following on my netgear router logs (there are over 300 lines, ill just paste a few.

The reason I'm posting on apple forums is because 1, I trust apple and it's community, 2. I know they will be helpful 3. I have a time capsule and 2 expresses and wonder if that will effect them, and 4 I also looked up one of the ip's on the internet and found that it belonged to apple!!!!
Why is apple scanning my router doing dos attack scans to it?

Please please help someone. I'm very worried.

DoS attack: ACK Scan] from source: 122.252.42.217:443 Friday, March 18,2016 12:17:32

[DoS attack: ACK Scan] from source: 122.252.42.217:443 Friday, March 18,2016 12:17:00

[DHCP IP: (192.168.0.6)] to MAC address 70:56:81:B0:80:FB Friday, March 18,2016 12:16:49

[DoS attack: ACK Scan] from source: 17.133.231.9:993 Friday, March 18,2016 12:15:44

[DoS attack: ACK Scan] from source: 17.133.231.9:993 Friday, March 18,2016 12:15:10

[DoS attack: ACK Scan] from source: 17.133.231.9:993 Friday, March 18,2016 12:14:36

[DoS attack: ACK Scan] from source: 17.133.231.9:993 Friday, March 18,2016 12:11:18

[DoS attack: ACK Scan] from source: 17.133.231.9:993 Friday, March 18,2016 12:10:41

[DoS attack: ACK Scan] from source: 17.133.231.9:993 Friday, March 18,2016 12:10:19

[WLAN access denied]from MAC: 04:E5:36:6F:5E:9D Friday, March 18,2016 12:02:28

[WLAN access denied]from MAC: 04:E5:36:6F:5E:9D Friday, March 18,2016 12:02:11

[DoS attack: ACK Scan] from source: 122.252.42.217:443 Friday, March 18,2016 12:18:51

2013 Time Capsule (2 TB)-OTHER, Other OS

Posted on Mar 18, 2016 5:36 AM

Reply
7 replies

Mar 19, 2016 12:17 AM in response to 10newsrox

Do you use Torrents?? Even game server on your computer could be joined by people from all over the world.

If so you can expect to see what appears to be DoS attacks when you shut it down.


Otherwise it is just part of living in a connected world. DoS attack cannot be fixed by you.. it is incoming attack against your public IP.


Power off your router for 15min and see if you get a different IP when it comes back up.. if not talk to your ISP about the problem. They can block it..


A real DoS attack will only really happen if you are getting rapid attempts to access your system.. and in the end the only purpose is to deny service.. Not actual hacking.


You are not really being DoS attacked.. this is just standard firewall stuff.


[DoS attack: ACK Scan] from source: 17.133.231.9:993 Friday, March 18,2016 12:15:44

[DoS attack: ACK Scan] from source: 17.133.231.9:993 Friday, March 18,2016 12:15:10

[DoS attack: ACK Scan] from source: 17.133.231.9:993 Friday, March 18,2016 12:14:36

[DoS attack: ACK Scan] from source: 17.133.231.9:993 Friday, March 18,2016 12:11:18

[DoS attack: ACK Scan] from source: 17.133.231.9:993 Friday, March 18,2016 12:10:41

[DoS attack: ACK Scan] from source: 17.133.231.9:993 Friday, March 18,2016 12:10:19

6 attempts over 5min.. is trivial. (Note it can be genuine from something you have turned off.. so much stuff is cloud connected now. The router firewall is noting it but wrongly assigning it to DoS attack).

This might be why Apple do not turn on the firewall log.. or even use a SPI firewall in their router. It just causes paranoia in users.


Every router connected to the internet will have this kind of report. Much worse generally in fact. I would expect up to 10 knocks on the door a minute.. (my cable supplier in those days was unconcerned about bots in their network).


You are really not under threat if you see the firewall in the Netgear giving you messages.. it is blocking any of those attempts.. the real threat is the ones that get through the firewall and those are not on the list.


Did you have a compromised computer or device on the network at any time? If you did there can be a lot of incoming connections to it.. and they can persist for a long time when the kiddie scripters know you exist.


Why is apple scanning my router doing dos attack scans to it?

None of the addresses are real.. they are spoofed by the people who mount these attacks.


Your router will stop the vast majority of break in attempts. Your computer firewall will stop some more but that is more important to block the dial home type of stuff already in there.


Welcome to the internet.

Mar 19, 2016 12:17 AM in response to LaPastenague

Hi,

Thanks a lot for the detailed reply. It helped a lot.

I don't do torrenting or have a server.

I don't do p2p either.

I do play league of legends, but the ip's are from china, india, and random places that are doing the attack ack scans on my router. They happen about every 20 seconds.

I have never had this happen before

I can post all of the ack scans, its not just 5 of them and their not just from apple.


Thanks :

Mar 19, 2016 2:15 AM in response to 10newsrox

One ping every 20sec is not an attack.. it is standard internet people knocking on your door to find if anyone is home.


Netgear do have some models with poor firmware.. So I would check.. especially some of the voip models could be vunerable.

This is from another thread so I do not claim anything about it.. other than you should look up the reference yourself..

Hi everyone,

Just a quick heads up. I couldn't find this in the forums.

Back in February 2015, an exploit was published affecting many different Netgear router models whereby any local user could determine the router's management password and other information.

Even today Netgear has not released an updated firmware to fix this vulnerability for my router (WNDR3700v2).

Lists of routers verified as affected include:
NetGear WNDR3700v4 – V1.0.0.4SH
NetGear WNDR3700v4 – V1.0.1.52
NetGear WNR2200 – V1.0.1.88
NetGear WNR2500 – V1.0.0.24
NetGear WNDR3700v2 – V1.0.1.14 (Tested by Paula Thomas)
NetGear WNDR3700v1 – V1.0.16.98 (Tested by Michał Bartoszkiewicz)
NetGear WNDR3700v1 – V1.0.7.98 (Tested by Michał Bartoszkiewicz)
NetGear WNDR4300 – V1.0.1.60 (Tested by Ronny Lindner)
NetGear R6300v2 – V1.0.3.8 (Tested by Robert Müller)
NetGear WNDR3300 – V1.0.45 (Tested by Robert Müller)*
NetGear WNDR3800 – V1.0.0.48 (Tested by an Anonymous contributor)
NetGear WNR1000v2 – V1.0.1.1 (Tested by Jimi Sebree)
NetGear WNR1000v2 – V1.1.2.58 (Tested by Chris Boulton)
NetGear WNR2200 – V1.0.1.76 (Tested by Marcin Praczko)
NetGear WNR2000v3 – v1.1.2.6 (Tested by Shelby Spencer)
NetGear WNR2000v3 – V1.1.2.10 (Tested by Roland Schiebel)
NetGear R7500 – V1.0.0.82 (Tested by Team Event Tech)

More info is available at https://github.com/darkarnium/secpub/tree/master/NetGear/SOAPWNDR

If you're running a vulnerable firmware, and Netgear isn't updating your firmware, it seems like the only option to become secure is to revert to a third party firmware (eg, DD-WRT).

Obviously Netgear does not take security seriously.

when I look up the reference the vulnerability is only if you have wan management turned on. This is unlikely to be the case for you or most people.


Or you have people who are not trusted users in your local network.

This thread has been closed by the system or the community team. You may vote for any posts you find helpful, or search the Community for additional answers.

HELP!! DOS Attack Scans! I'm Worried!

Welcome to Apple Support Community
A forum where Apple customers help each other with their products. Get started with your Apple Account.