Community discussions

MikroTik App
 
singh
Frequent Visitor
Frequent Visitor
Topic Author
Posts: 72
Joined: Sat Apr 04, 2009 11:57 am

Suspected Spam Issue

Fri Mar 01, 2013 9:06 am

I am using Mikrotik RouterOS v5. It connects to my internet on ethe1 and my hotspot is on ether2. My link is 2mb. The problem is that when I see the tx/rx for ether1(internet), it always stays at 2mbps or 1.9mbps. Mostly the rx for this interface stays just at 2mbps. My hotspot interface shows tx/rx of just about 700kbps to 900kbps.
The worring thing now is that I cant access google as it says that my IP is sending automated requests. Even if I disconnect all users from the hotspot and leave just my laptop, the tx/rx for ether1 does not go down and stays just at 2mbps. My laptop is using Norton internet security and Windows 8 so I m pretty much sure I could not have a virus on my laptop.
Could anyone please help to sort this out as I am clueless
You do not have the required permissions to view the files attached to this post.
 
petrn
Member Candidate
Member Candidate
Posts: 179
Joined: Thu Jul 29, 2010 3:56 am

Re: Suspected Spam Issue

Sat Mar 02, 2013 1:16 am

My laptop is using Norton internet security and Windows 8 so I m pretty much sure I could not have a virus on my laptop.
if you say so ...
Could anyone please help to sort this out as I am clueless
What about to run "Torch" on "ether1" to see what traffic is there.
Petr
 
singh
Frequent Visitor
Frequent Visitor
Topic Author
Posts: 72
Joined: Sat Apr 04, 2009 11:57 am

Re: Suspected Spam Issue

Sat Mar 02, 2013 9:15 am

Ok. Torch brought the following screenshot. On further looking up the top few IPs in the list, I found that 178.33.237.67 is srv.ryushare.com, 88.221.217.10 is deploy.akamaitechnologies.com
If I google these sites, it tells me deploy.akamaitechnologies.com is used to prevent hacking to one's IP and so is used by sites as a dummy. Nothing sensible I can see for the other site.
I have blocked incoming traffic from 178.33.237.67 and my Rx has come down a bit though still high. I am able to open google.com though it brigs a capcha. ( I did not try to open google just before blocking 178.33.237.67 so I am not sure if that sorted me out or it had already started working.)
If anyone can make out these IPs and advise, that would be great.
You do not have the required permissions to view the files attached to this post.
 
singh
Frequent Visitor
Frequent Visitor
Topic Author
Posts: 72
Joined: Sat Apr 04, 2009 11:57 am

Re: Suspected Spam Issue

Wed Mar 06, 2013 11:04 am

The rx has still gone back to 2mbps. I tried to block the top random sites that I think do not make much sense of being there but as you can see on the list the sites are so many. If I block the top few sites others keep doing the same. Any general rules that I can implement.
 
singh
Frequent Visitor
Frequent Visitor
Topic Author
Posts: 72
Joined: Sat Apr 04, 2009 11:57 am

Re: Suspected Spam Issue

Wed Mar 06, 2013 11:19 am

I am getting something in Rx errors 2209 in interface list. Is that of any concern
 
singh
Frequent Visitor
Frequent Visitor
Topic Author
Posts: 72
Joined: Sat Apr 04, 2009 11:57 am

Re: Suspected Spam Issue

Fri Mar 08, 2013 1:42 pm

Issue still remains unsolved. Pease assist. Below is a snapshot of the error.
You do not have the required permissions to view the files attached to this post.
 
singh
Frequent Visitor
Frequent Visitor
Topic Author
Posts: 72
Joined: Sat Apr 04, 2009 11:57 am

Re: Suspected Spam Issue

Mon Mar 11, 2013 9:21 am

Any help anyone..............
 
User avatar
janisk
MikroTik Support
MikroTik Support
Posts: 6283
Joined: Tue Feb 14, 2006 9:46 am
Location: Riga, Latvia

Re: Suspected Spam Issue

Mon Mar 11, 2013 9:59 am

Usually this is not an issue as RX drops usually are packets from protocols that router does not know about, for example, multicast packets that are sent by windows7 hosts.

At what rate this counter increases?
 
singh
Frequent Visitor
Frequent Visitor
Topic Author
Posts: 72
Joined: Sat Apr 04, 2009 11:57 am

Re: Suspected Spam Issue

Mon Mar 11, 2013 1:15 pm

Monitoring for te past 10mins, I can say 1 per minute. Total is now at 139375. The rx still stays at 2mbps
 
CelticComms
Forum Guru
Forum Guru
Posts: 1766
Joined: Wed May 02, 2012 5:48 am

Re: Suspected Spam Issue

Mon Mar 11, 2013 1:29 pm

If the external traffic can't be explained by your own hotspot then it is possible that your router is being used as a proxy and some other observations seem to support that. If you contact me by email I can take a quick look and kill off the connections.
Interlynx | Networking and Information Security Consultants & Trainers | Email: routerlynx@gmail.com
BGP | EIGRP | OSPF | MPLS | Firewall | VPN | IPsec | Multicast | QOS | IPv4/6 | STP | VLAN | PON | AE | M2M | and more!

 
singh
Frequent Visitor
Frequent Visitor
Topic Author
Posts: 72
Joined: Sat Apr 04, 2009 11:57 am

Re: Suspected Spam Issue

Mon Mar 11, 2013 4:28 pm

If the external traffic can't be explained by your own hotspot then it is possible that your router is being used as a proxy and some other observations seem to support that. If you contact me by email I can take a quick look and kill off the connections.
Thanks for sorting me out +1

Who is online

Users browsing this forum: alexvicol and 204 guests