Okay so today I noticed this in my router(orbi) logs
[DoS Attack: SYN/ACK Scan] from source: 39.107.196.251, port 80, Thursday, October 24, 2019 21:04:01
[DoS Attack: SYN/ACK Scan] from source: 125.64.5.24, port 80, Thursday, October 24, 2019 21:03:19
[DoS Attack: RST Scan] from source: 121.198.25.74, port 80, Thursday, October 24, 2019 21:02:47
[DoS Attack: SYN/ACK Scan] from source: 121.198.25.74, port 80, Thursday, October 24, 2019 21:02:26
[DoS Attack: SYN/ACK Scan] from source: 119.23.78.110, port 80, Thursday, October 24, 2019 21:01:09
[DoS Attack: RST Scan] from source: 122.114.90.192, port 80, Thursday, October 24, 2019 21:00:23
[DoS Attack: SYN/ACK Scan] from source: 122.114.90.192, port 80, Thursday, October 24, 2019 21:00:02
[DoS Attack: SYN/ACK Scan] from source: 39.134.163.179, port 80, Thursday, October 24, 2019 20:59:36
[DoS Attack: SYN/ACK Scan] from source: 122.226.191.163, port 80, Thursday, October 24, 2019 20:58:56
[admin login] from source 192.168.1.10, Thursday, October 24, 2019 20:58:27
[DoS Attack: SYN/ACK Scan] from source: 110.42.66.207, port 80, Thursday, October 24, 2019 20:57:53
[DoS Attack: SYN/ACK Scan] from source: 58.215.87.161, port 80, Thursday, October 24, 2019 20:57:04
[DoS Attack: SYN/ACK Scan] from source: 198.200.56.203, port 80, Thursday, October 24, 2019 20:55:52
[DoS Attack: SYN/ACK Scan] from source: 103.85.85.59, port 80, Thursday, October 24, 2019 20:55:39
[DoS Attack: SYN/ACK Scan] from source: 103.67.174.120, port 80, Thursday, October 24, 2019 20:55:15
[DoS Attack: SYN/ACK Scan] from source: 123.183.213.241, port 80, Thursday, October 24, 2019 20:54:14
[admin login failure] from source 192.168.1.10, Thursday, October 24, 2019 20:53:32
[admin login] from source 192.168.1.10, Thursday, October 24, 2019 20:52:58
[DHCP IP: 192.168.1.21] to MAC address f0:d1:a9:28:2d:2c, Thursday, October 24, 2019 20:52:31
[DoS Attack: SYN/ACK Scan] from source: 58.218.200.152, port 80, Thursday, October 24, 2019 20:51:32
[DoS Attack: RST Scan] from source: 182.92.213.124, port 80, Thursday, October 24, 2019 20:51:19
[DoS Attack: SYN/ACK Scan] from source: 182.92.213.124, port 80, Thursday, October 24, 2019 20:50:58
I made a thread on the Netgear forums here
https://community.netgear.com/t5/Orbi/Lots-of-dos-attacks-from-China/m-p/1815653#M73698
Comcast it's mot just me but others are noticing this today too, please help stop this.
What do you expect Comcast to do, blacklist entire domains or thousands of IP addresses? That's just not feasible.
You have a personal router, right? Change your IP address at the router to stop the attacks. I'm sure the nice folks at Netgear will tell you how.
You aren't helping Xfinity with snyde answers like that.
@darkangelic wrote:
What do you expect Comcast to do, blacklist entire domains or thousands of IP addresses? That's just not feasible.
You have a personal router, right? Change your IP address at the router to stop the attacks. I'm sure the nice folks at Netgear will tell you how.