Temat: Zabepieczenie routera przez włamaniem

W jaki sposób mogę utrudnić komuś włamanie się na mój router ?
W logach zobaczyłem coś takiego

[  107.620000] ipt_bandwidth: timezone shift of 120 minutes detected, adjusting
[  107.630000]                old minutes west=0, new minutes west=-120
[110518.840000] UDP: bad checksum. From 68.232.187.124:39815 to 192.168.1.253:1900 ulen 99
[1267737.610000] UDP: bad checksum. From 108.61.135.189:19452 to 192.168.1.253:1900 ulen 99
[1592995.300000] UDP: bad checksum. From 110.184.212.84:33398 to 192.168.1.253:27015 ulen 33
[1800145.320000] UDP: bad checksum. From 60.191.23.60:59864 to 192.168.1.253:443 ulen 109
[1800261.510000] UDP: bad checksum. From 60.191.23.60:59864 to 192.168.1.253:636 ulen 109
[1800319.550000] UDP: bad checksum. From 60.191.23.60:59864 to 192.168.1.253:992 ulen 109
[2441147.900000] UDP: bad checksum. From 218.75.40.147:25326 to 192.168.1.253:161 ulen 49
[2441455.070000] UDP: bad checksum. From 218.75.40.147:25326 to 192.168.1.253:1701 ulen 109
[2499330.560000] UDP: bad checksum. From 108.61.135.189:43534 to 192.168.1.253:1900 ulen 99
[2588272.620000] UDP: bad checksum. From 108.61.135.189:38330 to 192.168.1.253:1900 ulen 99
[2644539.890000] UDP: bad checksum. From 108.61.135.189:38330 to 192.168.1.253:1900 ulen 99
[5396508.960000] ipt_bandwidth: timezone shift of 60 minutes detected, adjusting
[5396508.970000]                old minutes west=-120, new minutes west=-60
[5492506.200000] UDP: bad checksum. From 60.191.23.58:50910 to 192.168.1.253:161 ulen 49
[5492813.970000] UDP: bad checksum. From 60.191.23.58:50910 to 192.168.1.253:1701 ulen 109
[5810261.620000] UDP: bad checksum. From 122.224.158.197:7456 to 192.168.1.253:161 ulen 49
[5810571.520000] UDP: bad checksum. From 122.224.158.197:7456 to 192.168.1.253:1701 ulen 109
[6413271.380000] UDP: bad checksum. From 115.236.61.205:50799 to 192.168.1.253:993 ulen 37
[6891415.880000] UDP: bad checksum. From 122.226.116.155:22541 to 192.168.1.253:1900 ulen 102
[6891418.330000] UDP: bad checksum. From 122.226.116.155:57202 to 192.168.1.253:1900 ulen 102
[6891418.360000] UDP: bad checksum. From 122.226.116.155:53650 to 192.168.1.253:1900 ulen 102
[6891418.640000] UDP: bad checksum. From 122.226.116.155:37636 to 192.168.1.253:1900 ulen 102
[6891418.640000] UDP: bad checksum. From 122.226.116.155:37636 to 192.168.1.253:1900 ulen 102
[6891418.640000] UDP: bad checksum. From 122.226.116.155:37636 to 192.168.1.253:1900 ulen 102
[6891418.730000] UDP: bad checksum. From 122.226.116.155:22283 to 192.168.1.253:1900 ulen 102
[6891418.730000] UDP: bad checksum. From 122.226.116.155:22283 to 192.168.1.253:1900 ulen 102
[6891418.870000] UDP: bad checksum. From 122.226.116.155:52699 to 192.168.1.253:1900 ulen 102
[6891422.130000] net_ratelimit: 3 callbacks suppressed
[6891422.130000] UDP: bad checksum. From 122.226.116.155:29660 to 192.168.1.253:1900 ulen 102
[6891422.130000] UDP: bad checksum. From 122.226.116.155:29660 to 192.168.1.253:1900 ulen 102
[6891422.130000] UDP: bad checksum. From 122.226.116.155:29660 to 192.168.1.253:1900 ulen 102
[6891422.130000] UDP: bad checksum. From 122.226.116.155:29660 to 192.168.1.253:1900 ulen 102
[6891422.130000] UDP: bad checksum. From 122.226.116.155:29660 to 192.168.1.253:1900 ulen 102
[6891422.270000] UDP: bad checksum. From 122.226.116.155:60234 to 192.168.1.253:1900 ulen 102
[6891422.270000] UDP: bad checksum. From 122.226.116.155:60234 to 192.168.1.253:1900 ulen 102
[6891422.370000] UDP: bad checksum. From 122.226.116.155:21690 to 192.168.1.253:1900 ulen 102
[6891422.370000] UDP: bad checksum. From 122.226.116.155:21690 to 192.168.1.253:1900 ulen 102
[6891422.780000] UDP: bad checksum. From 122.226.116.155:12495 to 192.168.1.253:1900 ulen 102
[6891427.250000] net_ratelimit: 22 callbacks suppressed
[6891427.250000] UDP: bad checksum. From 122.226.116.155:37674 to 192.168.1.253:1900 ulen 102
[6891427.890000] UDP: bad checksum. From 122.226.116.155:8924 to 192.168.1.253:1900 ulen 102
[6891428.070000] UDP: bad checksum. From 122.226.116.155:58305 to 192.168.1.253:1900 ulen 102
[6891428.380000] UDP: bad checksum. From 122.226.116.155:46779 to 192.168.1.253:1900 ulen 102
[6891428.470000] UDP: bad checksum. From 122.226.116.155:8067 to 192.168.1.253:1900 ulen 102
[6891428.470000] UDP: bad checksum. From 122.226.116.155:8067 to 192.168.1.253:1900 ulen 102
[6891428.470000] UDP: bad checksum. From 122.226.116.155:8067 to 192.168.1.253:1900 ulen 102
[6891428.470000] UDP: bad checksum. From 122.226.116.155:8067 to 192.168.1.253:1900 ulen 102
[6891428.770000] UDP: bad checksum. From 122.226.116.155:20207 to 192.168.1.253:1900 ulen 102
[6891429.210000] UDP: bad checksum. From 122.226.116.155:17926 to 192.168.1.253:1900 ulen 102
[6891433.590000] net_ratelimit: 5 callbacks suppressed
[6891433.590000] UDP: bad checksum. From 122.226.116.155:15325 to 192.168.1.253:1900 ulen 102
[6891433.780000] UDP: bad checksum. From 122.226.116.155:32271 to 192.168.1.253:1900 ulen 102
[6891434.070000] UDP: bad checksum. From 122.226.116.155:38286 to 192.168.1.253:1900 ulen 102
[6891434.070000] UDP: bad checksum. From 122.226.116.155:38286 to 192.168.1.253:1900 ulen 102
[6891434.070000] UDP: bad checksum. From 122.226.116.155:38286 to 192.168.1.253:1900 ulen 102
[6891436.220000] UDP: bad checksum. From 122.226.116.155:32866 to 192.168.1.253:1900 ulen 102
[6891436.220000] UDP: bad checksum. From 122.226.116.155:32866 to 192.168.1.253:1900 ulen 102
[6891436.370000] UDP: bad checksum. From 122.226.116.155:22383 to 192.168.1.253:1900 ulen 102
[6891436.680000] UDP: bad checksum. From 122.226.116.155:39707 to 192.168.1.253:1900 ulen 102
[6891436.790000] UDP: bad checksum. From 122.226.116.155:23355 to 192.168.1.253:1900 ulen 102
[6891440.480000] net_ratelimit: 10 callbacks suppressed
[6891440.480000] UDP: bad checksum. From 122.226.116.155:54346 to 192.168.1.253:1900 ulen 102
[6891440.940000] UDP: bad checksum. From 122.226.116.155:4902 to 192.168.1.253:1900 ulen 102
[6891441.250000] UDP: bad checksum. From 122.226.116.155:53416 to 192.168.1.253:1900 ulen 102
[6891442.480000] UDP: bad checksum. From 122.226.116.155:15248 to 192.168.1.253:1900 ulen 102
[6891442.480000] UDP: bad checksum. From 122.226.116.155:15248 to 192.168.1.253:1900 ulen 102
[6891442.480000] UDP: bad checksum. From 122.226.116.155:15248 to 192.168.1.253:1900 ulen 102
[6891442.700000] UDP: bad checksum. From 122.226.116.155:63429 to 192.168.1.253:1900 ulen 102
[6891443.250000] UDP: bad checksum. From 122.226.116.155:53276 to 192.168.1.253:1900 ulen 102
[6891443.250000] UDP: bad checksum. From 122.226.116.155:53276 to 192.168.1.253:1900 ulen 102
[6891444.080000] UDP: bad checksum. From 122.226.116.155:49876 to 192.168.1.253:1900 ulen 102
[6891446.050000] UDP: bad checksum. From 122.226.116.155:35858 to 192.168.1.253:1900 ulen 102
[6891446.350000] UDP: bad checksum. From 122.226.116.155:22879 to 192.168.1.253:1900 ulen 102
[6891446.350000] UDP: bad checksum. From 122.226.116.155:22879 to 192.168.1.253:1900 ulen 102
[6891446.610000] UDP: bad checksum. From 122.226.116.155:54954 to 192.168.1.253:1900 ulen 102
[6891447.550000] UDP: bad checksum. From 122.226.116.155:41158 to 192.168.1.253:1900 ulen 102
[6891447.810000] UDP: bad checksum. From 122.226.116.155:26249 to 192.168.1.253:1900 ulen 102
[6891450.380000] UDP: bad checksum. From 122.226.116.155:55060 to 192.168.1.253:1900 ulen 102
[6891450.380000] UDP: bad checksum. From 122.226.116.155:55060 to 192.168.1.253:1900 ulen 102
[6891453.510000] UDP: bad checksum. From 122.226.116.155:56498 to 192.168.1.253:1900 ulen 102
[6891453.510000] UDP: bad checksum. From 122.226.116.155:56498 to 192.168.1.253:1900 ulen 102
[6891453.510000] UDP: bad checksum. From 122.226.116.155:56498 to 192.168.1.253:1900 ulen 102
[6891456.130000] UDP: bad checksum. From 122.226.116.155:42297 to 192.168.1.253:1900 ulen 102
[6891456.500000] UDP: bad checksum. From 122.226.116.155:45059 to 192.168.1.253:1900 ulen 102
[6891456.560000] UDP: bad checksum. From 122.226.116.155:44298 to 192.168.1.253:1900 ulen 102
[6891457.680000] UDP: bad checksum. From 122.226.116.155:21705 to 192.168.1.253:1900 ulen 102
[6891460.420000] UDP: bad checksum. From 122.226.116.155:21232 to 192.168.1.253:1900 ulen 102
[6891460.420000] UDP: bad checksum. From 122.226.116.155:21232 to 192.168.1.253:1900 ulen 102
[6891460.420000] UDP: bad checksum. From 122.226.116.155:21232 to 192.168.1.253:1900 ulen 102
[6891461.430000] UDP: bad checksum. From 122.226.116.155:49289 to 192.168.1.253:1900 ulen 102
[6891461.430000] UDP: bad checksum. From 122.226.116.155:49289 to 192.168.1.253:1900 ulen 102
[6891462.320000] UDP: bad checksum. From 122.226.116.155:56726 to 192.168.1.253:1900 ulen 102
[6891462.320000] UDP: bad checksum. From 122.226.116.155:56726 to 192.168.1.253:1900 ulen 102
[6891464.380000] UDP: bad checksum. From 122.226.116.155:7528 to 192.168.1.253:1900 ulen 102
[6891464.800000] UDP: bad checksum. From 122.226.116.155:60774 to 192.168.1.253:1900 ulen 102
[6891464.800000] UDP: bad checksum. From 122.226.116.155:60774 to 192.168.1.253:1900 ulen 102
[6891466.070000] net_ratelimit: 3 callbacks suppressed
[6891466.080000] UDP: bad checksum. From 122.226.116.155:8323 to 192.168.1.253:1900 ulen 102
[6891466.740000] UDP: bad checksum. From 122.226.116.155:57242 to 192.168.1.253:1900 ulen 102
[6891471.690000] UDP: bad checksum. From 122.226.116.155:54833 to 192.168.1.253:1900 ulen 102
[6891472.730000] UDP: bad checksum. From 122.226.116.155:26372 to 192.168.1.253:1900 ulen 102
[6891474.060000] UDP: bad checksum. From 122.226.116.155:23611 to 192.168.1.253:1900 ulen 102
[6891474.060000] UDP: bad checksum. From 122.226.116.155:23611 to 192.168.1.253:1900 ulen 102
[6891474.060000] UDP: bad checksum. From 122.226.116.155:23611 to 192.168.1.253:1900 ulen 102
[6891479.630000] UDP: bad checksum. From 122.226.116.155:36530 to 192.168.1.253:1900 ulen 102
[6891480.850000] UDP: bad checksum. From 122.226.116.155:53338 to 192.168.1.253:1900 ulen 102
[6891482.130000] UDP: bad checksum. From 122.226.116.155:23540 to 192.168.1.253:1900 ulen 102
[6891482.130000] UDP: bad checksum. From 122.226.116.155:23540 to 192.168.1.253:1900 ulen 102
[6891482.130000] UDP: bad checksum. From 122.226.116.155:23540 to 192.168.1.253:1900 ulen 102
[6891482.130000] UDP: bad checksum. From 122.226.116.155:23540 to 192.168.1.253:1900 ulen 102
[6891484.560000] UDP: bad checksum. From 122.226.116.155:35482 to 192.168.1.253:1900 ulen 102
[6891485.580000] UDP: bad checksum. From 122.226.116.155:55893 to 192.168.1.253:1900 ulen 102
[6891485.580000] UDP: bad checksum. From 122.226.116.155:55893 to 192.168.1.253:1900 ulen 102
[6891489.680000] UDP: bad checksum. From 122.226.116.155:53692 to 192.168.1.253:1900 ulen 102
[6891490.590000] UDP: bad checksum. From 122.226.116.155:2101 to 192.168.1.253:1900 ulen 102
[6891490.590000] UDP: bad checksum. From 122.226.116.155:2101 to 192.168.1.253:1900 ulen 102
[6891490.640000] UDP: bad checksum. From 122.226.116.155:47797 to 192.168.1.253:1900 ulen 102
[6891490.640000] UDP: bad checksum. From 122.226.116.155:47797 to 192.168.1.253:1900 ulen 102
[6891490.640000] UDP: bad checksum. From 122.226.116.155:47797 to 192.168.1.253:1900 ulen 102
[6891502.150000] UDP: bad checksum. From 122.226.116.155:16744 to 192.168.1.253:1900 ulen 102
[6891502.150000] UDP: bad checksum. From 122.226.116.155:16744 to 192.168.1.253:1900 ulen 102
[6891502.150000] UDP: bad checksum. From 122.226.116.155:16744 to 192.168.1.253:1900 ulen 102
[6891502.150000] UDP: bad checksum. From 122.226.116.155:16744 to 192.168.1.253:1900 ulen 102
[6891502.150000] UDP: bad checksum. From 122.226.116.155:16744 to 192.168.1.253:1900 ulen 102
[6891504.390000] UDP: bad checksum. From 122.226.116.155:58863 to 192.168.1.253:1900 ulen 102
[6891508.570000] UDP: bad checksum. From 122.226.116.155:56586 to 192.168.1.253:1900 ulen 102
[6891508.570000] UDP: bad checksum. From 122.226.116.155:56586 to 192.168.1.253:1900 ulen 102
[6891510.040000] UDP: bad checksum. From 122.226.116.155:11250 to 192.168.1.253:1900 ulen 102
[6891511.690000] UDP: bad checksum. From 122.226.116.155:58920 to 192.168.1.253:1900 ulen 102
[6891511.690000] UDP: bad checksum. From 122.226.116.155:58920 to 192.168.1.253:1900 ulen 102
[6891511.690000] UDP: bad checksum. From 122.226.116.155:58920 to 192.168.1.253:1900 ulen 102
[6891511.690000] UDP: bad checksum. From 122.226.116.155:58920 to 192.168.1.253:1900 ulen 102
[6891515.060000] UDP: bad checksum. From 122.226.116.155:15811 to 192.168.1.253:1900 ulen 102
[6891515.060000] UDP: bad checksum. From 122.226.116.155:15811 to 192.168.1.253:1900 ulen 102
[6891520.570000] UDP: bad checksum. From 122.226.116.155:30079 to 192.168.1.253:1900 ulen 102
[6891523.360000] UDP: bad checksum. From 122.226.116.155:42129 to 192.168.1.253:1900 ulen 102
[6891524.640000] UDP: bad checksum. From 122.226.116.155:13435 to 192.168.1.253:1900 ulen 102
[6891533.910000] UDP: bad checksum. From 122.226.116.155:33215 to 192.168.1.253:1900 ulen 102
[6891533.910000] UDP: bad checksum. From 122.226.116.155:33215 to 192.168.1.253:1900 ulen 102
[7291531.490000] UDP: bad checksum. From 122.224.158.194:51305 to 192.168.1.253:992 ulen 109
[7291764.780000] UDP: bad checksum. From 122.224.158.194:51305 to 192.168.1.253:23 ulen 109
[7292034.990000] UDP: bad checksum. From 122.224.158.194:51305 to 192.168.1.253:80 ulen 109
[7292074.220000] UDP: bad checksum. From 122.224.158.194:51305 to 192.168.1.253:102 ulen 109
[7292113.430000] UDP: bad checksum. From 122.224.158.194:51305 to 192.168.1.253:110 ulen 109
[7292152.650000] UDP: bad checksum. From 122.224.158.194:51305 to 192.168.1.253:143 ulen 109
[7292191.560000] UDP: bad checksum. From 122.224.158.194:51305 to 192.168.1.253:161 ulen 49
[7292269.990000] UDP: bad checksum. From 122.224.158.194:51305 to 192.168.1.253:179 ulen 109
[7292309.150000] UDP: bad checksum. From 122.224.158.194:51305 to 192.168.1.253:445 ulen 109
[7292348.350000] UDP: bad checksum. From 122.224.158.194:51305 to 192.168.1.253:554 ulen 109
[7292406.050000] UDP: bad checksum. From 122.224.158.194:51305 to 192.168.1.253:808 ulen 109
[7292462.500000] UDP: bad checksum. From 122.224.158.194:51305 to 192.168.1.253:1080 ulen 109
[7292540.200000] UDP: bad checksum. From 122.224.158.194:51305 to 192.168.1.253:1701 ulen 109
[7292579.420000] UDP: bad checksum. From 122.224.158.194:51305 to 192.168.1.253:1723 ulen 109
[7292618.620000] UDP: bad checksum. From 122.224.158.194:51305 to 192.168.1.253:1962 ulen 109
[7292676.280000] UDP: bad checksum. From 122.224.158.194:51305 to 192.168.1.253:3128 ulen 109
[7292715.500000] UDP: bad checksum. From 122.224.158.194:51305 to 192.168.1.253:3389 ulen 109
[7292773.210000] UDP: bad checksum. From 122.224.158.194:51305 to 192.168.1.253:8000 ulen 109
[7292830.900000] UDP: bad checksum. From 122.224.158.194:51305 to 192.168.1.253:8123 ulen 109
[7292907.110000] UDP: bad checksum. From 122.224.158.194:51305 to 192.168.1.253:8080 ulen 109
[7292946.280000] UDP: bad checksum. From 122.224.158.194:51305 to 192.168.1.253:9050 ulen 109
[7292985.450000] UDP: bad checksum. From 122.224.158.194:51305 to 192.168.1.253:1099 ulen 109
root@Gargoyle:~#

Po zerknięciu z jakiego adresu ktoś próbuje mieszać za pomocą tego serwisu
https://www.whatismyip.com/ip-whois-lookup/
okazuje się że to jakiś chińczyk

% [whois.apnic.net]
% Whois data copyright terms    http://www.apnic.net/db/dbcopyright.html

% Information related to '122.226.116.128 - 122.226.116.255'

% Abuse contact for '122.226.116.128 - 122.226.116.255' is 'antispam@dcb.hz.zj.cn'

inetnum:        122.226.116.128 - 122.226.116.255
netname:        JINHUA-TELECOM-LTD
country:        CN
descr:          HangZhou
descr:
admin-c:        FH840-AP
tech-c:         CJ54-AP
mnt-irt:        IRT-CHINANET-ZJ
status:         ASSIGNED NON-PORTABLE
mnt-by:         MAINT-CN-CHINANET-ZJ-JH
last-modified:  2015-11-16T00:10:03Z
source:         APNIC

irt:            IRT-CHINANET-ZJ
address:        Hangzhou, 288 fucun Road, China
e-mail:         lfliu@pubinfo.com.cn
abuse-mailbox:  antispam@dcb.hz.zj.cn
admin-c:        CZ61-AP
tech-c:         CZ61-AP
auth:            Filtered
mnt-by:         MAINT-CHINANET-ZJ
last-modified:  2017-10-23T02:48:11Z
source:         APNIC

role:           CHINANET-ZJ Jinhua
address:        No.155 Xishi street,Jinhua,Zhejiang.321000
country:        CN
phone:          +86-579-2300779
fax-no:         +86-579-2330035
e-mail:         anti_spam@mail.jhptt.zj.cn
remarks:        send spam reports to anti_spam@mail.jhptt.zj.cn
remarks:        and abuse reports to anti_spam@mail.jhptt.zj.cn
remarks:        Please include detailed information and times in UTC
admin-c:        CH55-AP
tech-c:         CH55-AP
nic-hdl:        CJ54-AP
mnt-by:         MAINT-CHINANET-ZJ
last-modified:  2011-12-06T00:11:26Z
source:         APNIC

person:         Feng Huang
nic-hdl:        FH840-AP
e-mail:         nti_spam@mail.jhptt.zj.cna
address:        Jinhua,Zhejiang.Postcode:321000
phone:          +86-13750988858
country:        CN
mnt-by:         MAINT-CN-CHINANET-ZJ-JH
last-modified:  2015-08-16T10:08:01Z
source:         APNIC

% This query was served by the APNIC Whois Service version 1.88.15-46 (WHOIS-UK3)

2

Odp: Zabepieczenie routera przez włamaniem

Akurat bad checksum oznacza uszkodzone pakiety sieciowe, a że adres jest chiński - to zobacz do czego 192.168.1.253 się odwołuje - video, kamery, jakach chmura itd.

Masz niepotrzebny router, uszkodzony czy nie - chętnie przygarnę go.

3

Odp: Zabepieczenie routera przez włamaniem

192.168.1.253 to akurat mój router z n2n'em (supernode) i pod portem 51305 i innymi wysokimi teoretycznie nie powinien z nikim rozmawiać.

4

Odp: Zabepieczenie routera przez włamaniem

zainstaluj beardropper i dodaj reguly po 'UDP: bad checksum. From'
https://github.com/robzr/bearDropper

5

Odp: Zabepieczenie routera przez włamaniem

Jak nie masz nic wystawionego bez hasła itd. to nikt się nie włamie. Też widzę czasem próby podłączenia np. pod VPN ale zawsze są nieudane.

6 (edytowany przez viper_lasser 2018-11-20 21:06:40)

Odp: Zabepieczenie routera przez włamaniem

Hasło oczywiście jest ale widać że próbuje coś zrobić jakiś zewnętrzny automat / skrypt do łamania bo na routerze jest uruchomiony tylko ssh, n2n supernode i nic więcej. Połączenie internetowe jest z netiaspot'u.

7

Odp: Zabepieczenie routera przez włamaniem

Zrób sobie na firewallu regułę blokującą zbyt nachalne IP. Np jak tu: https://forum.archive.openwrt.org/viewt … p?id=27103

OpenWrt: WAX206/NWA50AX/EA6350v3 || W szufladzie: WNDR4300/TL-WDR4300/SR3200

8

Odp: Zabepieczenie routera przez włamaniem

Projekt banip: https://forum.openwrt.org/t/banip-new-p … k/16985/33

Masz niepotrzebny router, uszkodzony czy nie - chętnie przygarnę go.