Author Topic: Strange home router logs.. why is the GH IP address showing up like this?  (Read 1926 times)

0 Members and 1 Guest are viewing this topic.

Offline Psybin

  • of Rallos Zek
  • Thread Starter
  • Posts: 620
  • Location: Merica
So I was playing around with some settings in my router yesterday and started looking through the logs. I'm by no means a networking pro, but I'm not completely inept, so school me. What does this mean?

I would assume a real DOS attack would be a absolute flood of packets, not just a couple. But is strange that the originating IP address is the address for Geekhack.

Side note I don't work Mondays, and when I'm home and doing homework or what not I just keep a tab open to GH on the topic spy. That's why its two Mondays in a row.

[DoS attack: ACK Scan] attack packets in last 20 sec from ip [67.214.104.143], Monday, Jun 09,2014 15:56:05
[DoS attack: RST Scan] attack packets in last 20 sec from ip [65.111.241.205], Monday, Jun 09,2014 11:54:19
[DoS attack: RST Scan] attack packets in last 20 sec from ip [65.111.241.205], Monday, Jun 09,2014 11:53:06
[DoS attack: RST Scan] attack packets in last 20 sec from ip [65.111.241.205], Monday, Jun 09,2014 11:51:53
[DoS attack: RST Scan] attack packets in last 20 sec from ip [65.111.241.205], Monday, Jun 09,2014 11:50:40
[DoS attack: RST Scan] attack packets in last 20 sec from ip [65.111.241.205], Monday, Jun 09,2014 11:49:27
[DoS attack: ACK Scan] attack packets in last 20 sec from ip [65.111.241.205], Monday, Jun 09,2014 11:48:13
[DoS attack: RST Scan] attack packets in last 20 sec from ip [65.111.241.205], Monday, Jun 09,2014 11:47:00
[DoS attack: RST Scan] attack packets in last 20 sec from ip [65.111.241.205], Monday, Jun 09,2014 11:45:47
[DoS attack: RST Scan] attack packets in last 20 sec from ip [65.111.241.205], Monday, Jun 09,2014 11:44:34
[DoS attack: RST Scan] attack packets in last 20 sec from ip [65.111.241.205], Monday, Jun 09,2014 11:43:21
[DoS attack: ACK Scan] attack packets in last 20 sec from ip [65.111.241.205], Monday, Jun 09,2014 11:42:08
[DoS attack: RST Scan] attack packets in last 20 sec from ip [65.111.241.205], Monday, Jun 02,2014 14:11:35
[DoS attack: RST Scan] attack packets in last 20 sec from ip [65.111.241.205], Monday, Jun 02,2014 14:10:22
[DoS attack: RST Scan] attack packets in last 20 sec from ip [65.111.241.205], Monday, Jun 02,2014 14:09:09
[DoS attack: RST Scan] attack packets in last 20 sec from ip [65.111.241.205], Monday, Jun 02,2014 14:07:56
[DoS attack: RST Scan] attack packets in last 20 sec from ip [65.111.241.205], Monday, Jun 02,2014 14:06:43
[DoS attack: ACK Scan] attack packets in last 20 sec from ip [65.111.241.205], Monday, Jun 02,2014 14:05:30
[DoS attack: RST Scan] attack packets in last 20 sec from ip [65.111.241.205], Monday, Jun 02,2014 14:04:16
[DoS attack: RST Scan] attack packets in last 20 sec from ip [65.111.241.205], Monday, Jun 02,2014 14:03:03


Offline digi

  • elite af tbh
  • * Exquisite Elder
  • Posts: 2789
  • keyboard game on fleek
Most likely a false positive on your firewall/soho router log, probably because geekhack.org validates your source IP address.

Offline bueller

  • MX baller
  • * Esteemed Elder
  • Posts: 3769
  • Location: Perth, Australia
  • Church of the Ergo Clear
From what I can tell those two IP's are from different ISP's, take a quick look at the WHOIS records.
It's a good width!  If it's half-width it's too narrow, and full-width is too wide. 

[WTT] bueller's trade thread - CLACKS WANTED

Offline Psybin

  • of Rallos Zek
  • Thread Starter
  • Posts: 620
  • Location: Merica
Ah ok. I figured it was a false positive, was just curious what it was. I don't think I get on many other sites that validate the IP; well not as much as I lurk on GH. I wonder if the gear at work flags anything.

Yea the one IP that's different isn't the geekhack IP, that's something else /shrug
« Last Edit: Wed, 11 June 2014, 14:12:29 by Psybin »

Offline paicrai

  • Actually a Jane Austen novel
  • * Destiny Supporter
  • Posts: 470
  • Location: sun stuff
  • mindblank
2spooks m8
THE FEMINIST ILLUMINATI

I will literally **** you raw paicrai, I hope you're legal by the time I meet you.
👌👀👌👀👌👀👌👀👌👀 good **** go౦ԁ ****👌 thats ✔ some good👌👌**** right👌👌th 👌 ere👌👌👌 right✔there ✔✔if i do ƽaү so my self 💯  i say so 💯  thats what im talking about right there right there (chorus: ʳᶦᵍʰᵗ ᵗʰᵉʳᵉ) mMMMMᎷМ💯 👌👌 👌НO0ОଠOOOOOОଠଠOoooᵒᵒᵒᵒᵒᵒᵒᵒᵒ👌 👌👌 👌 💯 👌 👀 👀 👀 👌👌Good ****

Offline tp4tissue

  • * Destiny Supporter
  • Posts: 13568
  • Location: Official Geekhack Public Defender..
  • OmniExpert of: Rice, Top-Ramen, Ergodox, n Females
pretty sure this was designed to filter out  Ripster... 

excessive IMHO..  he's still here regardless....  we just don't know which current user he's cloaked under...

Offline Psybin

  • of Rallos Zek
  • Thread Starter
  • Posts: 620
  • Location: Merica
link me the cliffnotes about the ripster deal. I've gleaned some of the story from various posts but not much.

Offline mkawa

  •  No Marketplace Access
  • Posts: 6562
  • (ツ)@@@. crankypants
false positive, probably due to the proxy configuration that we use here.

to all the brilliant friends who have left us, and all the students who climb on their shoulders.