Score:0

Someone could help me to understand what is happening im my home network?

ma flag

I've installed snort 2.9 in my Ubuntu 22.04. Since last month I discovered some strange traffic when starting a scan. I don't understand too much about pen testing or secure browsing, but this seems suspicious to me.

enter image description here

>>>>Example of PCAP HERE<<<<

ru flag
What you're seeing is that Snort has detected malformed UPnP packet requests to a router, and that the request for UPnP discovery was observed. The device 192.168.100.254 is making those requests. Snort may be detecting *passive* traffic and it may not be malicious traffic. If you are scanning however, and then Snort is seeing this, then this is Normal Traffic. However, Snort is not a *scanner* it's an active IDS/IPS system./
Tekomo Nakama avatar
ma flag
192.168.100.254 IP is the ROUTER Address, even im not sending anything to internet this is happening.
ru flag
In your router settings do you have UPnP (Universal Plug and Play) enabled? If so, I would disable it in the router, which should help stop the UPnP requests/processing. Your system might also be trying to do UPnP scans to see if UPnP is enabled in the system
Tekomo Nakama avatar
ma flag
what if my network provider didnt allowed me to have login password? any suggestion to face this issue?
ru flag
UPnP is also a function of multiple other things.. However, it's unclear still (show me a PCAP from Wireshark, not Snort!) whether the IP being shown is the origin point or the *detection* point. UPnP is a noisy protocol but is usually disabled in most modern networks (even residential routers shut it off by default...)
Tekomo Nakama avatar
ma flag
there we go, i`ve edited the post and attached a link from MEGA. The capturing last about 7 min, some things we can observe is the origin IPs. 192.168.100.104 is a smartTV... 192.168.100.198 &...184 are smartphones, ...254 we can call a router, or switch, and my static adress is .....119.
Score:0
ru flag

Your network is fine, and there is no 'malicious traffic' on your network.

Thanks to your packet capture, which I opened in a sandbox, all the multicast traffic that Snort is seeing is from different sources.

  • Multicast DNS aka MDNS. MDNS resolves hostnames to IP addresses in a network by using Multicast to send DNS to everything on the network attempting to find a response for the IP address <--> Hostname request matching.

  • SSDP - Simple Service Discovery Protocol - is used to discover UPnP and other open port protocols for simple service discovery. THIS is generating the UPnP packet noise. Assuming that 192.168.100.254 is your router, it's actively searching for any UPnP devices on your network so it can do its thing. This needs shut off at the router of your network which is beyond the scope of this question and Ask Ubuntu.

There's also ARP packets (how systems ID which MAC addresses exist on the network segment for a requested IP), and IPv6 router advertisements. Both are normal.

So while there isn't any real threat from UPnP service discovery to your computer, and you probably can consider these Snort alerts "non-issues", you should probably shut UPnP off on your router if you can. If that is not possible because you don't control your network's router, then you may want to start fine-tuining Snort alerts to actually malicious traffic categories you want to block on, not low-level informational and non-problematic traffic.

Tekomo Nakama avatar
ma flag
thanks man, i gonna reset my router cause i dont know the password. The SSDP Protocols made me doubt about integrity of my local network
I sit in a Tesla and translated this thread with Ai:

mangohost

Post an answer

Most people don’t grasp that asking a lot of questions unlocks learning and improves interpersonal bonding. In Alison’s studies, for example, though people could accurately recall how many questions had been asked in their conversations, they didn’t intuit the link between questions and liking. Across four studies, in which participants were engaged in conversations themselves or read transcripts of others’ conversations, people tended not to realize that question asking would influence—or had influenced—the level of amity between the conversationalists.