dslreports logo
Search similar:


uniqs
681
joan151
join:2004-02-16
Albuquerque, NM

joan151

Member

[Help Me] About My Dlink DI-624 Log

Lately i have been getting a log emailed to me from my router. This is ok, what concerns me is the data attached to it.
I really do not understand how to read it, But can someone tell me what is going on. I think someone is trying to jack into my network.
I run Mac filtering with static ip addresses. I have a limit on ip addresses also. Only the wireless and wired connections in my network will get an ip address.
One thing i see in this log is "drop UDP packet from Wan" also "Unauthorized wireless PC try to connected 00-0F-B5-03-E7-25" Mac address not part of my network, "Drop TCP packet from WAN" and finally "Ip address and mac address Spoof". What does all this mean? Is this a virus or some one trying to jack into my network? This is so consistent that it fills up the log with in 2 hrs (20 pages worth of attacks and other nonsense. What should i do?

funchords
Hello
MVM
join:2001-03-11
Yarmouth Port, MA

funchords

MVM

If you are using the Windows XP network Bridge feature, or if you are using some other kind of bridge (like a wireless extender or repeater), then I think if you'll look at those MAC addresses, you'll find that those addresses are involved with those systems.

The one that says "Unauthorized wireless PC try to connected 00-0F-B5-03-E7-25," I've never seen but all of the others you've listed, I've seen associated with those bridge-type devices.
joan151
join:2004-02-16
Albuquerque, NM

joan151

Member

This makes some sort of sense. There are new wireless networks in my neighborhood that i can see. I my self don't have a wireless bridge or extender. If i turn off mac filtering and set my dhcp server to automatic and turn off static ip address and revert it to dynamic, This Unauthorized wireless Pc listed above will actually acquire an ip address and it will list itself on my routers ip address list. It also follows with the name ryan. If i turn on WEP Then this unauthorized pc message will not appear in my log. Even when i change my SSID I still get this Unauthorized pc to log onto my network. I think i will turn on wep and safe guard my network.
What do you suggest?
Is static ip address a measure of safety or is it just a configuration?
Should i use mac filtering and WEP for my wireless equipment?
WIll hiding my SSID do anything for me?
Bwuutje
join:2005-01-10

Bwuutje

Member

MAC-address filtering, SSID hiding, switching off DHCP, WEP are all pretty outdated/useless measures when it comes to security. You can find lots of (sometimes heated) discussions here about this topic. See e.g. here: »The Six Dumbest Ways to Secure a Wireless LAN or here: »To broadcast or not to broadcast?

If you can just use WPA-PSK with a long random key/pass-phrase. And if possible use WPA + AES-encryption or even better WPA2. Then you should be safe.

Bwuutje.

Basher13
join:2004-05-02
Beverly Hills, CA

Basher13

Member

Bwuutje has offerred brilliant advice.

Don't use WEP or anything to protect your router
than WPA-PSK ...someone will just find a way
to break in. It's just a matter of time.

Also, in a similar reasoning, don't bother locking
the front door to your apartment or your house,
or locking the doors to your car. Someone will
eventually use a sledge hammer, a crow bar, or
a locking picking kit to get inside. It's just a matter
of time.

Let them get in, and take what they want ...keep
the refridigerator packed with cold beer, just in
case the intruders are thirsty, as well.