Sky
Regular Contributor
Greetings. I have been seeing some strange listings in my General SysLog. I added line feeds & emphasis to make it clearer to read. I think what's happening is the actual user name (replaced by _USERNAME_ below) may be compromised. I can't tell from this if the password is also compromised or is under attack. The ip's come back to Russia & rotate. This has been going on since 20-Jan.
If I blacklist the entire apparent attacking network, 92.63.194., in Firewall>URL Filter (leaving off the last octet is supposed to block 1-255) the router refuses access to all clients on the LAN, including hardwire via the switch. The only access is by reset > direct hardwire to the router; client access is only restored by removing that block. I can't see any reason Asus or its partners would be using a network in Russia, so that's confusing.
Also, I saw this entry at WAN>NAT Passthrough: FTP_ALG Port 2021. This appears to be a default in the new FW. Is this normal?
RT-AC87R | FW is 3.0.0.4.382_51939-g3ecf3e2 & signature checks OK.
If I blacklist the entire apparent attacking network, 92.63.194., in Firewall>URL Filter (leaving off the last octet is supposed to block 1-255) the router refuses access to all clients on the LAN, including hardwire via the switch. The only access is by reset > direct hardwire to the router; client access is only restored by removing that block. I can't see any reason Asus or its partners would be using a network in Russia, so that's confusing.
Also, I saw this entry at WAN>NAT Passthrough: FTP_ALG Port 2021. This appears to be a default in the new FW. Is this normal?
RT-AC87R | FW is 3.0.0.4.382_51939-g3ecf3e2 & signature checks OK.
::: Last normal entry:::
Feb 17 03:04:36 hour monitor: ntp sync fail, will retry after 120 sec
<< START ATTACK? >>
Feb 17 08:56:33 pptp[6748]: pppd 2.4.7 started by _USERNAME_, uid 0
Feb 17 08:56:33 pptp[6748]: Connect: pptp0 <--> pptp (92.63.194.91)
Feb 17 08:56:33 pptp[6748]: appear to have received our own echo-reply!
Feb 17 08:56:33 pptp[6748]: No CHAP secret found for authenticating admin
Feb 17 08:56:33 pptp[6748]: Peer admin failed CHAP authentication
Feb 17 08:56:33 pptpd[6747]: CTRL: EOF or bad error reading ctrl packet length.
Feb 17 08:56:33 pptpd[6747]: CTRL: couldn't read packet header (exit)
Feb 17 08:56:33 pptpd[6747]: CTRL: CTRL read failed
Feb 17 08:56:34 pptp[6758]: pppd 2.4.7 started by _USERNAME_, uid 0
Feb 17 08:56:34 pptp[6758]: Couldn't allocate PPP unit 10 as it is already in use
Feb 17 08:56:34 pptp[6758]: Connect: pptp1 <--> pptp (92.63.194.92)
Feb 17 08:56:34 pptp[6758]: appear to have received our own echo-reply!
Feb 17 08:56:34 pptp[6758]: No CHAP secret found for authenticating vpn
Feb 17 08:56:34 pptp[6758]: Peer vpn failed CHAP authentication
Feb 17 08:56:35 pptpd[6757]: CTRL: EOF or bad error reading ctrl packet length.
Feb 17 08:56:35 pptpd[6757]: CTRL: couldn't read packet header (exit)
Feb 17 08:56:35 pptpd[6757]: CTRL: CTRL read failed
Feb 17 08:56:35 pptp[6770]: pppd 2.4.7 started by _USERNAME_, uid 0
Feb 17 08:56:35 pptp[6770]: Couldn't allocate PPP unit 10 as it is already in use
Feb 17 08:56:35 pptp[6770]: Couldn't allocate PPP unit 11 as it is already in use
Feb 17 08:56:35 pptp[6770]: Connect: pptp2 <--> pptp (92.63.194.93)
Feb 17 08:56:36 pptp[6770]: appear to have received our own echo-reply!
Feb 17 08:56:36 pptp[6770]: No CHAP secret found for authenticating test
Feb 17 08:56:36 pptp[6770]: Peer test failed CHAP authentication
Feb 17 08:56:36 pptpd[6769]: CTRL: EOF or bad error reading ctrl packet length.
Feb 17 08:56:36 pptpd[6769]: CTRL: couldn't read packet header (exit)
Feb 17 08:56:36 pptpd[6769]: CTRL: CTRL read failed
Feb 17 08:56:36 pptp[6782]: pppd 2.4.7 started by _USERNAME_, uid 0
Feb 17 08:56:36 pptp[6782]: Couldn't allocate PPP unit 10 as it is already in use
Feb 17 08:56:36 pptp[6782]: Couldn't allocate PPP unit 11 as it is already in use
Feb 17 08:56:36 pptp[6782]: Couldn't allocate PPP unit 12 as it is already in use
Feb 17 08:56:36 pptp[6782]: Connect: pptp3 <--> pptp (92.63.194.94)
Feb 17 08:56:37 pptp[6782]: appear to have received our own echo-reply!
Feb 17 08:56:37 pptp[6782]: No CHAP secret found for authenticating 1
Feb 17 08:56:37 pptp[6782]: Peer 1 failed CHAP authentication
Feb 17 08:56:37 pptpd[6781]: CTRL: EOF or bad error reading ctrl packet length.
Feb 17 08:56:37 pptpd[6781]: CTRL: couldn't read packet header (exit)
Feb 17 08:56:37 pptpd[6781]: CTRL: CTRL read failed
Feb 17 08:56:38 pptp[6794]: pppd 2.4.7 started by _USERNAME_, uid 0
Feb 17 08:56:38 pptp[6794]: Couldn't allocate PPP unit 10 as it is already in use
Feb 17 08:56:38 pptp[6794]: Couldn't allocate PPP unit 11 as it is already in use
Feb 17 08:56:38 pptp[6794]: Couldn't allocate PPP unit 12 as it is already in use
Feb 17 08:56:38 pptp[6794]: Couldn't allocate PPP unit 13 as it is already in use
Feb 17 08:56:38 pptp[6794]: Connect: pptp4 <--> pptp (92.63.194.95)
Feb 17 08:56:38 pptp[6794]: appear to have received our own echo-reply!
Feb 17 08:56:38 pptp[6794]: No CHAP secret found for authenticating 123
Feb 17 08:56:38 pptp[6794]: Peer 123 failed CHAP authentication
Feb 17 08:56:38 pptpd[6793]: CTRL: EOF or bad error reading ctrl packet length.
Feb 17 08:56:38 pptpd[6793]: CTRL: couldn't read packet header (exit)
Feb 17 08:56:38 pptpd[6793]: CTRL: CTRL read failed
Feb 17 08:56:39 pptp[6806]: pppd 2.4.7 started by _USERNAME_, uid 0
Feb 17 08:56:39 pptp[6806]: Couldn't allocate PPP unit 10 as it is already in use
Feb 17 08:56:39 pptp[6806]: Couldn't allocate PPP unit 11 as it is already in use
Feb 17 08:56:39 pptp[6806]: Couldn't allocate PPP unit 12 as it is already in use
Feb 17 08:56:39 pptp[6806]: Couldn't allocate PPP unit 13 as it is already in use
Feb 17 08:56:39 pptp[6806]: Couldn't allocate PPP unit 14 as it is already in use
Feb 17 08:56:39 pptp[6806]: Connect: pptp5 <--> pptp (92.63.194.47)
Feb 17 08:56:39 pptp[6806]: appear to have received our own echo-reply!
Feb 17 08:56:39 pptp[6806]: No CHAP secret found for authenticating 111
Feb 17 08:56:39 pptp[6806]: Peer 111 failed CHAP authentication
Feb 17 08:56:39 pptp[6748]: Connection terminated.
Feb 17 08:56:39 pptp[6748]: Modem hangup
Feb 17 08:56:39 pptpd[6805]: CTRL: EOF or bad error reading ctrl packet length.
Feb 17 08:56:39 pptpd[6805]: CTRL: couldn't read packet header (exit)
Feb 17 08:56:39 pptpd[6805]: CTRL: CTRL read failed
Feb 17 08:56:40 pptp[6823]: pppd 2.4.7 started by _USERNAME_, uid 0
Feb 17 08:56:40 pptp[6823]: Connect: pptp0 <--> pptp (92.63.194.91)
Feb 17 08:56:40 pptp[6823]: appear to have received our own echo-reply!
Feb 17 08:56:40 pptp[6823]: No CHAP secret found for authenticating user
Feb 17 08:56:40 pptp[6823]: Peer user failed CHAP authentication
Feb 17 08:56:40 pptp[6758]: Connection terminated.
Feb 17 08:56:41 pptp[6758]: Modem hangup
Feb 17 08:56:41 pptpd[6822]: CTRL: EOF or bad error reading ctrl packet length.
Feb 17 08:56:41 pptpd[6822]: CTRL: couldn't read packet header (exit)
Feb 17 08:56:41 pptpd[6822]: CTRL: CTRL read failed
Feb 17 08:56:41 pptp[6838]: pppd 2.4.7 started by _USERNAME_, uid 0
Feb 17 08:56:41 pptp[6838]: Couldn't allocate PPP unit 10 as it is already in use
Feb 17 08:56:41 pptp[6838]: Connect: pptp1 <--> pptp (92.63.194.92)
Feb 17 08:56:42 pptp[6838]: appear to have received our own echo-reply!
Feb 17 08:56:42 pptp[6838]: No CHAP secret found for authenticating vpn
Feb 17 08:56:42 pptp[6838]: Peer vpn failed CHAP authentication
Feb 17 08:56:42 pptp[6770]: Connection terminated.
Feb 17 08:56:42 pptpd[6837]: CTRL: EOF or bad error reading ctrl packet length.
Feb 17 08:56:42 pptpd[6837]: CTRL: couldn't read packet header (exit)
Feb 17 08:56:42 pptpd[6837]: CTRL: CTRL read failed
Feb 17 08:56:42 pptp[6770]: Modem hangup
(continued in next post -- character count a bit long)
Feb 17 03:04:36 hour monitor: ntp sync fail, will retry after 120 sec
<< START ATTACK? >>
Feb 17 08:56:33 pptp[6748]: pppd 2.4.7 started by _USERNAME_, uid 0
Feb 17 08:56:33 pptp[6748]: Connect: pptp0 <--> pptp (92.63.194.91)
Feb 17 08:56:33 pptp[6748]: appear to have received our own echo-reply!
Feb 17 08:56:33 pptp[6748]: No CHAP secret found for authenticating admin
Feb 17 08:56:33 pptp[6748]: Peer admin failed CHAP authentication
Feb 17 08:56:33 pptpd[6747]: CTRL: EOF or bad error reading ctrl packet length.
Feb 17 08:56:33 pptpd[6747]: CTRL: couldn't read packet header (exit)
Feb 17 08:56:33 pptpd[6747]: CTRL: CTRL read failed
Feb 17 08:56:34 pptp[6758]: pppd 2.4.7 started by _USERNAME_, uid 0
Feb 17 08:56:34 pptp[6758]: Couldn't allocate PPP unit 10 as it is already in use
Feb 17 08:56:34 pptp[6758]: Connect: pptp1 <--> pptp (92.63.194.92)
Feb 17 08:56:34 pptp[6758]: appear to have received our own echo-reply!
Feb 17 08:56:34 pptp[6758]: No CHAP secret found for authenticating vpn
Feb 17 08:56:34 pptp[6758]: Peer vpn failed CHAP authentication
Feb 17 08:56:35 pptpd[6757]: CTRL: EOF or bad error reading ctrl packet length.
Feb 17 08:56:35 pptpd[6757]: CTRL: couldn't read packet header (exit)
Feb 17 08:56:35 pptpd[6757]: CTRL: CTRL read failed
Feb 17 08:56:35 pptp[6770]: pppd 2.4.7 started by _USERNAME_, uid 0
Feb 17 08:56:35 pptp[6770]: Couldn't allocate PPP unit 10 as it is already in use
Feb 17 08:56:35 pptp[6770]: Couldn't allocate PPP unit 11 as it is already in use
Feb 17 08:56:35 pptp[6770]: Connect: pptp2 <--> pptp (92.63.194.93)
Feb 17 08:56:36 pptp[6770]: appear to have received our own echo-reply!
Feb 17 08:56:36 pptp[6770]: No CHAP secret found for authenticating test
Feb 17 08:56:36 pptp[6770]: Peer test failed CHAP authentication
Feb 17 08:56:36 pptpd[6769]: CTRL: EOF or bad error reading ctrl packet length.
Feb 17 08:56:36 pptpd[6769]: CTRL: couldn't read packet header (exit)
Feb 17 08:56:36 pptpd[6769]: CTRL: CTRL read failed
Feb 17 08:56:36 pptp[6782]: pppd 2.4.7 started by _USERNAME_, uid 0
Feb 17 08:56:36 pptp[6782]: Couldn't allocate PPP unit 10 as it is already in use
Feb 17 08:56:36 pptp[6782]: Couldn't allocate PPP unit 11 as it is already in use
Feb 17 08:56:36 pptp[6782]: Couldn't allocate PPP unit 12 as it is already in use
Feb 17 08:56:36 pptp[6782]: Connect: pptp3 <--> pptp (92.63.194.94)
Feb 17 08:56:37 pptp[6782]: appear to have received our own echo-reply!
Feb 17 08:56:37 pptp[6782]: No CHAP secret found for authenticating 1
Feb 17 08:56:37 pptp[6782]: Peer 1 failed CHAP authentication
Feb 17 08:56:37 pptpd[6781]: CTRL: EOF or bad error reading ctrl packet length.
Feb 17 08:56:37 pptpd[6781]: CTRL: couldn't read packet header (exit)
Feb 17 08:56:37 pptpd[6781]: CTRL: CTRL read failed
Feb 17 08:56:38 pptp[6794]: pppd 2.4.7 started by _USERNAME_, uid 0
Feb 17 08:56:38 pptp[6794]: Couldn't allocate PPP unit 10 as it is already in use
Feb 17 08:56:38 pptp[6794]: Couldn't allocate PPP unit 11 as it is already in use
Feb 17 08:56:38 pptp[6794]: Couldn't allocate PPP unit 12 as it is already in use
Feb 17 08:56:38 pptp[6794]: Couldn't allocate PPP unit 13 as it is already in use
Feb 17 08:56:38 pptp[6794]: Connect: pptp4 <--> pptp (92.63.194.95)
Feb 17 08:56:38 pptp[6794]: appear to have received our own echo-reply!
Feb 17 08:56:38 pptp[6794]: No CHAP secret found for authenticating 123
Feb 17 08:56:38 pptp[6794]: Peer 123 failed CHAP authentication
Feb 17 08:56:38 pptpd[6793]: CTRL: EOF or bad error reading ctrl packet length.
Feb 17 08:56:38 pptpd[6793]: CTRL: couldn't read packet header (exit)
Feb 17 08:56:38 pptpd[6793]: CTRL: CTRL read failed
Feb 17 08:56:39 pptp[6806]: pppd 2.4.7 started by _USERNAME_, uid 0
Feb 17 08:56:39 pptp[6806]: Couldn't allocate PPP unit 10 as it is already in use
Feb 17 08:56:39 pptp[6806]: Couldn't allocate PPP unit 11 as it is already in use
Feb 17 08:56:39 pptp[6806]: Couldn't allocate PPP unit 12 as it is already in use
Feb 17 08:56:39 pptp[6806]: Couldn't allocate PPP unit 13 as it is already in use
Feb 17 08:56:39 pptp[6806]: Couldn't allocate PPP unit 14 as it is already in use
Feb 17 08:56:39 pptp[6806]: Connect: pptp5 <--> pptp (92.63.194.47)
Feb 17 08:56:39 pptp[6806]: appear to have received our own echo-reply!
Feb 17 08:56:39 pptp[6806]: No CHAP secret found for authenticating 111
Feb 17 08:56:39 pptp[6806]: Peer 111 failed CHAP authentication
Feb 17 08:56:39 pptp[6748]: Connection terminated.
Feb 17 08:56:39 pptp[6748]: Modem hangup
Feb 17 08:56:39 pptpd[6805]: CTRL: EOF or bad error reading ctrl packet length.
Feb 17 08:56:39 pptpd[6805]: CTRL: couldn't read packet header (exit)
Feb 17 08:56:39 pptpd[6805]: CTRL: CTRL read failed
Feb 17 08:56:40 pptp[6823]: pppd 2.4.7 started by _USERNAME_, uid 0
Feb 17 08:56:40 pptp[6823]: Connect: pptp0 <--> pptp (92.63.194.91)
Feb 17 08:56:40 pptp[6823]: appear to have received our own echo-reply!
Feb 17 08:56:40 pptp[6823]: No CHAP secret found for authenticating user
Feb 17 08:56:40 pptp[6823]: Peer user failed CHAP authentication
Feb 17 08:56:40 pptp[6758]: Connection terminated.
Feb 17 08:56:41 pptp[6758]: Modem hangup
Feb 17 08:56:41 pptpd[6822]: CTRL: EOF or bad error reading ctrl packet length.
Feb 17 08:56:41 pptpd[6822]: CTRL: couldn't read packet header (exit)
Feb 17 08:56:41 pptpd[6822]: CTRL: CTRL read failed
Feb 17 08:56:41 pptp[6838]: pppd 2.4.7 started by _USERNAME_, uid 0
Feb 17 08:56:41 pptp[6838]: Couldn't allocate PPP unit 10 as it is already in use
Feb 17 08:56:41 pptp[6838]: Connect: pptp1 <--> pptp (92.63.194.92)
Feb 17 08:56:42 pptp[6838]: appear to have received our own echo-reply!
Feb 17 08:56:42 pptp[6838]: No CHAP secret found for authenticating vpn
Feb 17 08:56:42 pptp[6838]: Peer vpn failed CHAP authentication
Feb 17 08:56:42 pptp[6770]: Connection terminated.
Feb 17 08:56:42 pptpd[6837]: CTRL: EOF or bad error reading ctrl packet length.
Feb 17 08:56:42 pptpd[6837]: CTRL: couldn't read packet header (exit)
Feb 17 08:56:42 pptpd[6837]: CTRL: CTRL read failed
Feb 17 08:56:42 pptp[6770]: Modem hangup
(continued in next post -- character count a bit long)
Last edited: