General Discussion
  >> General Broadband Chatter


Register (or login) on our website and you will not see this ad.


  Print Thread
Standard User trolleybus
(fountain of knowledge) Thu 21-Nov-24 10:40:38
Print Post

trace route


[link to this post]
 
Within my router I have blocked trace route. This has highlighted that throughout the day I frequently get a mail alert such as this where the source IP is not the same each time:

2024/11/21 09:04:51 -- [DOS][Block][trace_route][152.70.75.102->00.00.00.00][ICMP][HLen=20, TLen=34, Type=8, Code=0]

I have changed my IP to 00.00.00.00 in the alert message.

What exactly is hoped to be gained by the sender by probing my internet connection?
Standard User Zarjaz
(eat-sleep-adslguide) Thu 21-Nov-24 13:11:31
Print Post

Re: trace route


[re: trolleybus] [link to this post]
 
Access.

In old money, this is like a toe-rag going along trying the doors of parked cars … once you’re in, then just take what’s easy.

54-46 was my number
Standard User trolleybus
(fountain of knowledge) Thu 21-Nov-24 14:05:50
Print Post

Re: trace route


[re: Zarjaz] [link to this post]
 
In reply to a post by Zarjaz:
Access.

In old money, this is like a toe-rag going along trying the doors of parked cars … once you’re in, then just take what’s easy.


Then there is a bloody army of toe-rags out there then! Around 40 separate IPs seeing if I have locked my car today!


Register (or login) on our website and you will not see this ad.

Standard User Zarjaz
(eat-sleep-adslguide) Thu 21-Nov-24 15:15:53
Print Post

Re: trace route


[re: trolleybus] [link to this post]
 
Then there is a bloody army of toe-rags out there then!

Always a reasonable assumption in my book.

54-46 was my number
Standard User jpm
(fountain of knowledge) Thu 21-Nov-24 15:34:10
Print Post

Re: trace route


[re: trolleybus] [link to this post]
 
It's all completely automated and distributed around compromised hosts. You have nothing to gain by receiving an alert whenever your external IP is on the end of a ping or traceroute.
Standard User XGS_Is_On
(experienced) Thu 21-Nov-24 15:43:30
Print Post

Re: trace route


[re: trolleybus] [link to this post]
 
Switch the alert off. This is background noise.

Basic test to see if there's something there which will be followed by a port scan to try and find a vulnerable service running to exploit.
Administrator seb
(founder) Sun 24-Nov-24 04:05:02
Print Post

Re: trace route


[re: XGS_Is_On] [link to this post]
 
In reply to a post by XGS_Is_On:
Switch the alert off. This is background noise.
Basic test to see if there's something there which will be followed by a port scan to try and find a vulnerable service running to exploit.


Pretty much that. You can't realistically do anything to stop it.

Sebastien Lahtinen
[email protected]

The author of the above post is a thinkbroadband staff member. It may not constitute an official statement on behalf of thinkbroadband.
  Print Thread

Jump to