Jump to content

Huge SYN Flood when running utorrent


MaxP2P

Recommended Posts

Posted

Most of the times when I try to download with utorrent, everything besides utorrent itselfs stops working, and I mean everything. Firefox/Opera/IE won't connect, my Gmail Notifier gives an error, DynDNS Updater gives an error.

So basicly everything that uses/needs an internet connection goes down.

But utorrent is still running, though with a rather slow speed (10-34kb/s) and giving a yellow error icon at the buttom.

My router reports SYN flood non stop.

Here's a little portion of the log (note the world _little_):

11/14/2006 20:02:03 **SYN Flood** 81.64.168.31, 2309->> 192.168.2.100, 54637 (from PPPoE Inbound)

11/14/2006 20:02:02 **SYN Flood** 86.203.53.165, 4639->> 192.168.2.100, 48930 (from PPPoE Inbound)

11/14/2006 20:02:02 **SYN Flood** 192.168.2.100, 3619->> 83.252.76.8, 36390 (from PPPoE Outbound)

11/14/2006 20:02:02 **SYN Flood** 192.168.2.100, 3618->> 81.216.152.69, 14747 (from PPPoE Outbound)

11/14/2006 20:01:59 **SYN Flood** 192.168.2.100, 3619->> 83.252.76.8, 36390 (from PPPoE Outbound)

11/14/2006 20:01:59 **SYN Flood** 192.168.2.100, 3618->> 81.216.152.69, 14747 (from PPPoE Outbound)

11/14/2006 20:01:56 **SYN Flood** 86.203.53.165, 4639->> 192.168.2.100, 48930 (from PPPoE Inbound)

11/14/2006 20:01:54 **SYN Flood** 192.168.2.100, 3611->> 82.163.110.50, 6881 (from PPPoE Outbound)

11/14/2006 20:01:54 **SYN Flood** 192.168.2.100, 3610->> 201.65.81.157, 7050 (from PPPoE Outbound)

11/14/2006 20:01:53 **SYN Flood** 86.203.53.165, 4639->> 192.168.2.100, 48930 (from PPPoE Inbound)

11/14/2006 20:01:51 **SYN Flood** 192.168.2.100, 3611->> 82.163.110.50, 6881 (from PPPoE Outbound)

11/14/2006 20:01:51 **SYN Flood** 192.168.2.100, 3610->> 201.65.81.157, 7050 (from PPPoE Outbound)

11/14/2006 20:01:46 **SYN Flood** 192.168.2.100, 3606->> 218.186.78.19, 13377 (from PPPoE Outbound)

11/14/2006 20:01:46 **SYN Flood** 192.168.2.100, 3605->> 84.9.179.53, 44392 (from PPPoE Outbound)

11/14/2006 20:01:43 **SYN Flood** 192.168.2.100, 3606->> 218.186.78.19, 13377 (from PPPoE Outbound)

11/14/2006 20:01:43 **SYN Flood** 192.168.2.100, 3605->> 84.9.179.53, 44392 (from PPPoE Outbound)

11/14/2006 20:01:41 **SYN Flood** 82.21.28.72, 2470->> 192.168.2.100, 54637 (from PPPoE Inbound)

11/14/2006 20:01:39 **SYN Flood** 84.217.77.153, 2027->> 192.168.2.100, 48930 (from PPPoE Inbound)

11/14/2006 20:01:39 **SYN Flood** 86.60.86.101, 34725->> 192.168.2.100, 54637 (from PPPoE Inbound)

11/14/2006 20:01:38 **SYN Flood** 82.21.28.72, 2470->> 192.168.2.100, 54637 (from PPPoE Inbound)

11/14/2006 20:01:38 **SYN Flood** 192.168.2.100, 3597->> 82.156.57.220, 23841 (from PPPoE Outbound)

11/14/2006 20:01:38 **SYN Flood** 192.168.2.100, 3596->> 62.163.131.149, 34826 (from PPPoE Outbound)

11/14/2006 20:01:36 **SYN Flood** 86.60.86.101, 34725->> 192.168.2.100, 54637 (from PPPoE Inbound)

11/14/2006 20:01:35 **SYN Flood** 192.168.2.100, 3597->> 82.156.57.220, 23841 (from PPPoE Outbound)

11/14/2006 20:01:35 **SYN Flood** 192.168.2.100, 3596->> 62.163.131.149, 34826 (from PPPoE Outbound)

11/14/2006 20:01:33 **SYN Flood** 84.217.77.153, 2027->> 192.168.2.100, 48930 (from PPPoE Inbound)

11/14/2006 20:01:30 **SYN Flood** 84.217.77.153, 2027->> 192.168.2.100, 48930 (from PPPoE Inbound)

11/14/2006 20:01:30 **SYN Flood** 192.168.2.100, 3590->> 88.110.212.184, 11332 (from PPPoE Outbound)

11/14/2006 20:01:30 **SYN Flood** 192.168.2.100, 3589->> 86.101.217.187, 51515 (from PPPoE Outbound)

11/14/2006 20:01:27 **SYN Flood** 192.168.2.100, 3590->> 88.110.212.184, 11332 (from PPPoE Outbound)

11/14/2006 20:01:27 **SYN Flood** 192.168.2.100, 3589->> 86.101.217.187, 51515 (from PPPoE Outbound)

11/14/2006 20:01:24 **SYN Flood** 86.131.188.139, 3546->> 192.168.2.100, 54637 (from PPPoE Inbound)

11/14/2006 20:01:22 **SYN Flood** 192.168.2.100, 3588->> 82.241.158.35, 57168 (from PPPoE Outbound)

11/14/2006 20:01:22 **SYN Flood** 192.168.2.100, 3587->> 62.235.128.17, 2011 (from PPPoE Outbound)

11/14/2006 20:01:21 **SYN Flood** 86.131.188.139, 3546->> 192.168.2.100, 54637 (from PPPoE Inbound)

11/14/2006 20:01:19 **SYN Flood** 192.168.2.100, 3588->> 82.241.158.35, 57168 (from PPPoE Outbound)

11/14/2006 20:01:19 **SYN Flood** 192.168.2.100, 3587->> 62.235.128.17, 2011 (from PPPoE Outbound)

11/14/2006 20:01:14 **SYN Flood** 192.168.2.100, 3583->> 201.212.125.17, 7339 (from PPPoE Outbound)

11/14/2006 20:01:14 **SYN Flood** 192.168.2.100, 3582->> 84.123.108.155, 38818 (from PPPoE Outbound)

11/14/2006 20:01:11 **SYN Flood** 192.168.2.100, 3583->> 201.212.125.17, 7339 (from PPPoE Outbound)

11/14/2006 20:01:11 **SYN Flood** 192.168.2.100, 3582->> 84.123.108.155, 38818 (from PPPoE Outbound)

11/14/2006 20:01:09 **SYN Flood** 192.168.2.100, 3567->> 24.248.103.83, 32459 (from PPPoE Outbound)

11/14/2006 20:01:07 **SYN Flood** 201.239.179.205, 59963->> 192.168.2.100, 54637 (from PPPoE Inbound)

11/14/2006 20:01:03 **SYN Flood** 192.168.2.100, 3567->> 24.248.103.83, 32459 (from PPPoE Outbound)

11/14/2006 20:01:03 **SYN Flood** 201.239.179.205, 59963->> 192.168.2.100, 54637 (from PPPoE Inbound)

11/14/2006 20:01:03 **SYN Flood** 192.168.2.100, 3569->> 82.241.19.46, 15657 (from PPPoE Outbound)

11/14/2006 19:56:47 **UDP Flood Stop**

11/14/2006 19:56:40 **SYN Flood** 192.168.2.100, 3401->> 64.233.183.147, 80 (from PPPoE Outbound)

11/14/2006 19:44:57 **SYN Flood** 192.168.2.100, 1196->> 62.16.129.112, 12498 (from PPPoE Outbound)

11/14/2006 19:44:57 **SYN Flood** 192.168.2.100, 1195->> 87.200.176.221, 49153 (from PPPoE Outbound)

11/14/2006 19:44:56 **SYN Flood** 192.168.2.100, 1192->> 91.84.9.157, 37435 (from PPPoE Outbound)

11/14/2006 19:44:56 **SYN Flood** 192.168.2.100, 1191->> 83.81.154.95, 54270 (from PPPoE Outbound)

11/14/2006 19:44:56 **SYN Flood** 192.168.2.100, 1190->> 84.113.3.236, 25903 (from PPPoE Outbound)

11/14/2006 19:44:56 **SYN Flood** 192.168.2.100, 1187->> 203.153.203.53, 18879 (from PPPoE Outbound)

11/14/2006 19:44:56 **SYN Flood** 192.168.2.100, 1175->> 85.102.48.147, 6881 (from PPPoE Outbound)

11/14/2006 19:44:56 **SYN Flood** 192.168.2.100, 1174->> 81.179.182.166, 41909 (from PPPoE Outbound)

11/14/2006 19:44:55 **SYN Flood** 192.168.2.100, 1169->> 200.69.166.225, 45174 (from PPPoE Outbound)

11/14/2006 19:44:55 **SYN Flood** 192.168.2.100, 1166->> 82.35.233.49, 6881 (from PPPoE Outbound)

11/14/2006 19:44:55 **SYN Flood** 192.168.2.100, 1163->> 142.167.113.155, 32869 (from PPPoE Outbound)

11/14/2006 19:44:55 **SYN Flood** 192.168.2.100, 1161->> 213.101.237.55, 32459 (from PPPoE Outbound)

11/14/2006 19:44:54 **SYN Flood** 192.168.2.100, 1194->> 86.8.110.25, 63603 (from PPPoE Outbound)

11/14/2006 19:44:54 **SYN Flood** 192.168.2.100, 1193->> 213.60.234.58, 16728 (from PPPoE Outbound)

11/14/2006 19:44:54 **SYN Flood** 192.168.2.100, 1172->> 80.7.61.84, 43575 (from PPPoE Outbound)

11/14/2006 19:44:53 **SYN Flood** 192.168.2.100, 1190->> 84.113.3.236, 25903 (from PPPoE Outbound)

Any ideas of what I can do?

I have a SMC2804WBRP-G router, and the uTorrent port is forwarded correctly.

My TCP half-open ports are at 50 on both windows and utorrent advanced. I have a 6MB/500KB connection, my global max. nr. of connections is at 250. Per torrent is at 67. And nr. of upload slots per torrent is at 9.

Both UPnP and DHT is OFF.

  • 3 years later...
  • 2 months later...
Posted

Hi,

Same issue on my router of this 3d

This are my firewall settings on the router Digicom mod:8E4437

Intrusion Detection Feature:

SPI and Anti-DoS firewall protection selected

RIP defect no

Discard Ping To WAN Interface no

Stateful Packet Inspection:

Packet Fragmentation selected

TCP Connection selected "

UDP Session selected

FTP Service selected

H.323 Service selected

TFTP Service selected

Someone can me help ?

Thanks !!!

Luciana

Posted

Try turning of the firewall, so deselect the packet inspection.

For me that was not successful, so i lowered the amount of connections used by utorrent. That didn't work either, so I downgraded my router firmware and use utorrent 1.6.1 right now.

Weird or not, on my laptop I use utorrent 2.0.3 and I don't get any problems when downloading with my laptop. I simply can't put my finger on it.

Posted

1st and 2nd links in my signature.

You probably need to disable all UDP packets generated by uTorrent.

This means disable UPnP, NAT-PMP, DHT (both kinds), Local Peer Discovery, Bandwidth Management (uTP), Resolve IPs (right-click in torrent window-tab), and maybe even Teredo/IPv6 (though you have to do that last one in windows, not uTorrent!)

Posted
Try turning of the firewall, so deselect the packet inspection.

For me that was not successful, so i lowered the amount of connections used by utorrent. That didn't work either, so I downgraded my router firmware and use utorrent 1.6.1 right now.

Weird or not, on my laptop I use utorrent 2.0.3 and I don't get any problems when downloading with my laptop. I simply can't put my finger on it.

Thanks very much !!!!!!!!!

With 2.0.3 run easy & fine without changes !!!

Regards

Posted
2.0.3 is not supported due to vulnerability to the dll exploit.

2.0.4 is the current supported version.

Ok....

After this post:

1st and 2nd links in my signature.

You probably need to disable all UDP packets generated by uTorrent.

This means disable UPnP, NAT-PMP, DHT (both kinds), Local Peer Discovery, Bandwidth Management (uTP), Resolve IPs (right-click in torrent window-tab), and maybe even Teredo/IPv6 (though you have to do that last one in windows, not uTorrent!)

this are my test on 2.0.4 build 22450:

1. disable all options suggest from Switeck

2. add one options at time to check who generate SYN Flood

Found!! Are DHT (both kinds) : must be disable.

Speed ok

Thanks for the support !

Archived

This topic is now archived and is closed to further replies.

×
×
  • Create New...