mmburtch
Sleep deprived and cranky
So, I suddenly lost activity on my LAN. When I checked the router attached devices, I noticed that most of the devices were missing. I checked the logs, and this is what I found:
[DOS attack FIN scan] Attack packets in last 20 seconds from 69.7.226.79
Domain Name Domain Name : 69.7.226.79
OrgName: DBS INTERNATIONAL
OrgID: DBSINT
Address: 3949 Schelden Circle
City: Bethlehem
StateProv: PA
PostalCode: 18017
Country: US
ReferralServer: rwhois://rwhois1.dbsintl.net:4321
NetRange: 69.7.224.0 - 69.7.239.255
CIDR: 69.7.224.0/20
NetName: DBSINTL-104-36-0
NetHandle: NET-69-7-224-0-1
Parent: NET-69-0-0-0-0
NetType: Direct Allocation
NameServer: NS1A.DBSINTL.NET
NameServer: NS2A.DBSINTL.NET
NameServer: NS2B.DBSINTL.NET
Comment:
RegDate: 2002-11-27
Updated: 2007-01-26
RTechHandle: WB233-ARIN
RTechName: BACHENBERG, Wayne
RTechPhone: +1-610-691-8811
RTechEmail:
OrgAbuseHandle: TKE4-ARIN
OrgAbuseName: Keiser, Terry
OrgAbusePhone: +1-610-691-8811
OrgAbuseEmail:
OrgNOCHandle: NOC191-ARIN
OrgNOCName: Network Operations Center
OrgNOCPhone: +1-610-691-8811
OrgNOCEmail:
OrgTechHandle: WB233-ARIN
OrgTechName: BACHENBERG, Wayne
OrgTechPhone: +1-610-691-8811
OrgTechEmail:
What the hell? Any ideas on how to stop this?
[DOS attack FIN scan] Attack packets in last 20 seconds from 69.7.226.79
Domain Name Domain Name : 69.7.226.79
OrgName: DBS INTERNATIONAL
OrgID: DBSINT
Address: 3949 Schelden Circle
City: Bethlehem
StateProv: PA
PostalCode: 18017
Country: US
ReferralServer: rwhois://rwhois1.dbsintl.net:4321
NetRange: 69.7.224.0 - 69.7.239.255
CIDR: 69.7.224.0/20
NetName: DBSINTL-104-36-0
NetHandle: NET-69-7-224-0-1
Parent: NET-69-0-0-0-0
NetType: Direct Allocation
NameServer: NS1A.DBSINTL.NET
NameServer: NS2A.DBSINTL.NET
NameServer: NS2B.DBSINTL.NET
Comment:
RegDate: 2002-11-27
Updated: 2007-01-26
RTechHandle: WB233-ARIN
RTechName: BACHENBERG, Wayne
RTechPhone: +1-610-691-8811
RTechEmail:
OrgAbuseHandle: TKE4-ARIN
OrgAbuseName: Keiser, Terry
OrgAbusePhone: +1-610-691-8811
OrgAbuseEmail:
OrgNOCHandle: NOC191-ARIN
OrgNOCName: Network Operations Center
OrgNOCPhone: +1-610-691-8811
OrgNOCEmail:
OrgTechHandle: WB233-ARIN
OrgTechName: BACHENBERG, Wayne
OrgTechPhone: +1-610-691-8811
OrgTechEmail:
What the hell? Any ideas on how to stop this?