Phone UDP flooding my TP-link router

MuHcOw

New member
Dec 30, 2017
2
0
0
Hi all, I hope you can help me with this one.
A good while back my TP-link router (TL-ER604W) started to drop WiFi, LAN and WAN connection (not simultaneously).
Some times all WiFi connected clients couldn't connect to the network, but cabled devices could ping each other. No devices could access the internet.
A router reboot was the only solution to regain connection.

In the router logs I noticed that a number of UDP flood attacks had taken place from inside the network (local IP).
>> 2017-12-30 08:24:36 <4> : Detected stationary source udp flood attack, dropped 6107 packets, attack source: 10.0.0.13 <<
Every time the registered IP belonged to my (non-rooted) OnePlus 2 phone.

I have now installed an app that shows me which apps are accessing the network and which protocol they are using.
Every time I reboot the phone a NEW app is accessing the router gateway 10.0.0.1 using port 67. No other apps are accessing the gateway using UDP on port 67 (except youtube, when used).
And it doesn't stop - It's connected all the time.

Screenshot_20171230-152617.jpgScreenshot_20171230-152225.jpgScreenshot_20171230-145829.jpgScreenshot_20171230-200250.jpg

I think it's VERY weird that there's a NEW app accessing 10.0.0.1:67 every time I reboot. And it's also kind of weird that it keeps the connection open all the time.

I have tried installing different kinds of anti virus app and have them scan the phone. None of them found anything.

Another thing that have happened a few times is (according to the router logs) a "large scale" ping attack on the WAN side.
The ping attacks always happened within a few hours of the UDP flood attacks.
I don't know if the two are connected and I don't know if anybody has gained access to my network.

What can I do? Is everything okay? I'm at a loss...

Kind regards
 
Last edited:
Is this a Galaxy S8 by chance? I am having a similar issue where an S8 is causing what loos kike a Large Ping flood to my gateway while it's on WiFi. We also have an Galaxy 8 Note doing the same think but at a slightly slower pace.

I have a TL-ER6020 router involved but they are not so different.
 
Last edited:
Sorry, but no - It's a Oneplus 2 phone.
The ping attacks that I receive comes from the WAN side - The UDP flood attacks comes from the LAN side.
Ping attacks happens within a few hours of an UDP flood attack.


Kind regards
 
Hi all, I hope you can help me with this one.
A good while back my TP-link router (TL-ER604W) started to drop WiFi, LAN and WAN connection (not simultaneously).
Some times all WiFi connected clients couldn't connect to the network, but cabled devices could ping each other. No devices could access the internet.
A router reboot was the only solution to regain connection.

In the router logs I noticed that a number of UDP flood attacks had taken place from inside the network (local IP).
>> 2017-12-30 08:24:36 <4> : Detected stationary source udp flood attack, dropped 6107 packets, attack source: 10.0.0.13 <<
Every time the registered IP belonged to my (non-rooted) OnePlus 2 phone.

I have now installed an app that shows me which apps are accessing the network and which protocol they are using.
Every time I reboot the phone a NEW app is accessing the router gateway 10.0.0.1 using port 67. No other apps are accessing the gateway using UDP on port 67 (except youtube, when used).
And it doesn't stop - It's connected all the time.

I think it's VERY weird that there's a NEW app accessing 10.0.0.1:67 every time I reboot. And it's also kind of weird that it keeps the connection open all the time.

I have tried installing different kinds of anti virus app and have them scan the phone. None of them found anything.

Another thing that have happened a few times is (according to the router logs) a "large scale" ping attack on the WAN side.
The ping attacks always happened within a few hours of the UDP flood attacks.
I don't know if the two are connected and I don't know if anybody has gained access to my network.

What can I do? Is everything okay? I'm at a loss...

Kind regards
Hi!

I know it is a 6 year old post, but I have the same problem.
I also use TP-Link router and it blocked my stock android phone for DoS attack.
Maybe except it is not a UDP flood but a TCP sync attack. 🤔

Have you found it out? What app did you use for network use tracking?

Thanks!

1720093619735.png