recently our Internet has been up and down like a yoyo.. we have been hacked in the past and recently I have noticed some dodgy things happening on other forums and our home network.
I decided to go to the router and see what the Intrusion Detection Stats were like as well as the .log's
this is what I have found;
Intrusion Detection:
fragment_sweep 27fragment_out-of-order 141398
and Log's;
xxx.xxx.xxx.xxx = our IP Address.
Info 05:29:14 (since last boot) UPnP action 'DeletePortMapping' from ip=192.168.1.xx (Success)
Info 05:29:15 (since last boot) UPnP action 'DeletePortMapping' from ip=192.168.1.xx (Success)
Error 05:29:02 (since last boot) FIREWALL icmp check (1 of 1): Protocol: ICMP Src ip: 46.250.48.74 Dst ip: xxx.xxx.xxx.xxx Type: Destination Unreachable Code: Host Unreacheable
Info 05:28:26 (since last boot) IDS fragment parser : fragment out-of-order (1 of 7) : 82.26.117.143 xxx.xxx.xxx.xxx 1452 UDP 30647->28532 frag 7469:1432@0+
Info 05:24:56 (since last boot) IDS fragment parser : fragment out-of-order (1 of 9) : 82.26.117.143 xxx.xxx.xxx.xxx 1452 UDP 30647->28532 frag 29039:1432@0+
Info 05:20:40 (since last boot) IDS fragment parser : fragment out-of-order (1 of 6) : 82.26.117.143 xxx.xxx.xxx.xxx 1452 UDP 30647->28532 frag 14974:1432@0+
Info 05:19:22 (since last boot) IDS fragment parser : fragment out-of-order (1 of 5) : 82.26.117.143 xxx.xxx.xxx.xxx 1452 UDP 30647->28532 frag 11094:1432@0+
Info 05:15:22 (since last boot) IDS fragment parser : fragment out-of-order (1 of 150) : 82.26.117.143 xxx.xxx.xxx.xxx 1452 UDP 30647->28532 frag 31250:1432@0+
Info 05:14:07 (since last boot) IDS fragment parser : fragment out-of-order (1 of 4326) : 2.93.10.32 xxx.xxx.xxx.xxx 1396 UDP 58261->28532 frag 35924:1376@0+
Error 05:13:42 (since last boot) IDS fragment parser : fragment sweep (1 of 1) : 2.93.10.32 xxx.xxx.xxx.xxx 0054 UDP frag 22854:34@1376
Info 05:13:06 (since last boot) IDS fragment parser : fragment out-of-order (1 of 5721) : 2.93.10.32 xxx.xxx.xxx.xxx 1396 UDP 58261->28532 frag 65083:1376@0+
Error 05:12:41 (since last boot) IDS fragment parser : fragment sweep (1 of 1) : 2.93.10.32 xxx.xxx.xxx.xxx 0054 UDP frag 47033:34@1376
Info 05:12:05 (since last boot) IDS fragment parser : fragment out-of-order (1 of 5544) : 2.93.10.32 xxx.xxx.xxx.xxx 1396 UDP 58261->28532 frag 19596:1376@0+
Error 05:11:40 (since last boot) IDS fragment parser : fragment sweep (1 of 1) : 2.93.10.32 xxx.xxx.xxx.xxx 0054 UDP frag 4379:34@1376
Info 05:11:04 (since last boot) IDS fragment parser : fragment out-of-order (1 of 4914) : 93.80.212.118 xxx.xxx.xxx.xxx 1396 UDP 59470->28532 frag 17521:1376@0+
Error 05:10:39 (since last boot) IDS fragment parser : fragment sweep (1 of 1) : 93.80.212.118 xxx.xxx.xxx.xxx 1396 UDP 59470->28532 frag 60449:1376@0+
Info 05:10:03 (since last boot) IDS fragment parser : fragment out-of-order (1 of 4993) : 2.93.10.32 xxx.xxx.xxx.xxx 1396 UDP 58261->28532 frag 9723:1376@0+
Error 05:09:38 (since last boot) IDS fragment parser : fragment sweep (1 of 1) : 2.93.10.32 xxx.xxx.xxx.xxx 0054 UDP frag 62317:34@1376
Info 05:09:02 (since last boot) IDS fragment parser : fragment out-of-order (1 of 3091) : 2.93.10.32 xxx.xxx.xxx.xxx 1396 UDP 58261->28532 frag 38752:1376@0+
Error 05:08:38 (since last boot) IDS fragment parser : fragment sweep (1 of 1) : 2.93.10.32 xxx.xxx.xxx.xxx 0054 UDP frag 30300:34@1376
Info 05:08:01 (since last boot) IDS fragment parser : fragment out-of-order (1 of 1821) : 2.93.10.32 xxx.xxx.xxx.xxx 1396 UDP 58261->28532 frag 11827:1376@0+
Error 05:07:36 (since last boot) IDS fragment parser : fragment sweep (1 of 1) : 2.93.10.32 xxx.xxx.xxx.xxx 0054 UDP frag 60150:34@1376
Warning 05:07:25 (since last boot) PPP link up (Internet) [xxx.xxx.xxx.xxx]
Info 05:07:25 (since last boot) PPP PAP Authenticate Ack received
Info 05:07:25 (since last boot) PPP PAP Authenticate Request sent
Warning 05:07:14 (since last boot) PPP link down (Internet) [xxx.xxx.xxx.xxx]
Info 05:07:00 (since last boot) IDS fragment parser : fragment out-of-order (1 of 10925) : 2.93.10.32 xxx.xxx.xxx.xxx 1396 UDP 58261->28532 frag 41488:1376@0+
not liking this Telecom Dynamic plan which is falsely advertised. As in Fact we are on a Static IP. Have requested numerous times for a Dynamic IP which TBQH can't be done with Telecom.
any idea's on what to do here would be appreciated.