examining a log

The router log does, it seems, record some activity, but not all, even though all ports are now closed in the primary firewall.

The router log continues to show the MAC addresses of the devices that attach to it (chiefly my phone and laptops), it also records non-specific port activity, like this:

[DoS attack: FIN Scan] attack packets in last 20 sec from ip [77.247.179.176], Thursday, Feb 20,2014 05:33:54
[DoS attack: FIN Scan] attack packets in last 20 sec from ip [77.247.179.176], Thursday, Feb 20,2014 05:31:10
[DoS attack: FIN Scan] attack packets in last 20 sec from ip [77.247.179.176], Thursday, Feb 20,2014 05:29:46
[DoS attack: FIN Scan] attack packets in last 20 sec from ip [77.247.179.176], Thursday, Feb 20,2014 05:27:13
[DoS attack: FIN Scan] attack packets in last 20 sec from ip [77.247.179.176], Thursday, Feb 20,2014 05:25:42
[DoS attack: FIN Scan] attack packets in last 20 sec from ip [77.247.179.176], Thursday, Feb 20,2014 05:24:15
[DoS attack: FIN Scan] attack packets in last 20 sec from ip [77.247.179.176], Thursday, Feb 20,2014 05:22:21
[DoS attack: FIN Scan] attack packets in last 20 sec from ip [77.247.179.176], Thursday, Feb 20,2014 05:21:59
[DoS attack: FIN Scan] attack packets in last 20 sec from ip [77.247.179.176], Thursday, Feb 20,2014 05:20:23
[DoS attack: FIN Scan] attack packets in last 20 sec from ip [77.247.179.176], Thursday, Feb 20,2014 05:17:53
[DoS attack: FIN Scan] attack packets in last 20 sec from ip [77.247.179.176], Thursday, Feb 20,2014 05:16:09
[DoS attack: FIN Scan] attack packets in last 20 sec from ip [77.247.179.176], Thursday, Feb 20,2014 05:14:54
[DoS attack: FIN Scan] attack packets in last 20 sec from ip [77.247.179.176], Wednesday, Feb 19,2014 17:57:00

Someone in the Netherlands seems to be trying to bring my system down, but with no ports open, all that’s happening is my router is recording the external activity (and promptly ignoring it).

Interesting.

Bookmark the permalink.

Leave a Reply

Your email address will not be published. Required fields are marked *