Ask Your Question

Revision history [back]

click to hide/show revision 1
initial version

Unable To Capture Ping Of Death Atack Packets

My Zyxel 3301 Router is reporting that the Ring Chime Pro v2 on the 5Ghz segment of my LAN is sending Ping Of Death packets. These reported attacks occur 6 hours apart and run at 1 second intervals for a total of 22 packets then stop.

Some of the 22 packets in each block are targeted to my router at 192.168.1.1, others are targeted to external ip addresses including 34.240.249.71 and 154.54.39.118

I have set Wireshark on my Ethernet connected MAC to record traffic to and from the Chime Pro using the filter {host 192.168.1.57} without the brackets with the object of analysing the packets to see what's going on, but Wireshark only seems to capture ARPs to the router which occur 1 every 30 seconds. It never sees or captures the Pings Of Death the router is reporting.

If I ping the Chime Pro using Terminal on my MAC the pings are correctly returned but again Wireshark does not see them. I've tried adding {&& icmp} to the filter but still nothing.

Clearly I'm doing something wrong but I can't work out what.

This is what the router is reporting....

kernel: PING OF DEATH ATTACK:IN=br0 OUT=ppp1 MAC=50:e0:39:19:cc:10:2a:42:01:03:d3:c0:08:00 SRC=192.168.1.57 DST=154.54.39.118 LEN=4460 TOS=0x00 PREC=0x00 TTL=63 ID=22673 PROTO=ICMP TYPE=8 CODE=0 ID=13759 SEQ=3 MARK=0xb0020000

Can someone help with this please?

Thanks in advance and Best Regards.