# \[DoS attack: Smurf\] attack packets in last 20 sec from ip

**URL:** <https://community.homey.app/t/dos-attack-smurf-attack-packets-in-last-20-sec-from-ip/16245>\
**Category:** Questions & Help\
**Created:** [July 31, 2019, 9:38am UTC](https://community.homey.app/t/dos-attack-smurf-attack-packets-in-last-20-sec-from-ip/16245 "2019-07-31T09:38:42Z")\
**Posts on this page:** 19\
**Page:** 2

<div class="post-metadata">

**Author:** ![robertklep](https://sea1.discourse-cdn.com/flex025/user_avatar/community.homey.app/robertklep/32/160628_2.png) [@robertklep](https://community.homey.app/u/robertklep)\
**Post date:** [January 15, 2021, 12:26pm UTC](https://community.homey.app/t/dos-attack-smurf-attack-packets-in-last-20-sec-from-ip/16245/21 "2021-01-15T12:26:28Z")

</div>

192.168.23.8 is my Homey. It doesn’t resolve anything:

```auto
$ nslookup homey.app 192.168.23.8
;; connection timed out; no servers could be reached

```

Regarding your followup post: how do you know the traffic is coming from Homey when the packets arrive on your external interface? Do you have a Netgear router? If so, read [this post](https://community.netgear.com/t5/Nighthawk-WiFi-Routers/DoS-attack-ACK-Scan-from-source/td-p/1768924) about those generating a lot of false positives when it comes to DoS attack alerts.

---

<div class="post-metadata">

**Author:** ![amoscami](https://sea1.discourse-cdn.com/flex025/user_avatar/community.homey.app/amoscami/32/14024_2.png) [@amoscami](https://community.homey.app/u/amoscami)\
**Post date:** [January 15, 2021, 12:39pm UTC](https://community.homey.app/t/dos-attack-smurf-attack-packets-in-last-20-sec-from-ip/16245/22 "2021-01-15T12:39:47Z")

</div>

I’m blocking the homey ip, and the traffic disappear

---

<div class="post-metadata">

**Author:** ![robertklep](https://sea1.discourse-cdn.com/flex025/user_avatar/community.homey.app/robertklep/32/160628_2.png) [@robertklep](https://community.homey.app/u/robertklep)\
**Post date:** [January 15, 2021, 12:43pm UTC](https://community.homey.app/t/dos-attack-smurf-attack-packets-in-last-20-sec-from-ip/16245/23 "2021-01-15T12:43:05Z")

</div>

How do you know it’s not regular normal traffic? The DNS amplification issue that you mention is not relevant because your Homey is located in an internal network and no outside attackers can abuse it (unless you have a _very_ badly configured network).

---

<div class="post-metadata">

**Author:** ![Robin\_van\_Kekem](https://sea1.discourse-cdn.com/flex025/user_avatar/community.homey.app/robin_van_kekem/32/8187_2.png) [@Robin\_van\_Kekem](https://community.homey.app/u/Robin_van_Kekem)\
**Post date:** [January 15, 2021, 1:46pm UTC](https://community.homey.app/t/dos-attack-smurf-attack-packets-in-last-20-sec-from-ip/16245/24 "2021-01-15T13:46:24Z")

</div>

> [@amoscami](#):
>
> Nessus

Tried NSlookup while using Wireshark also but I didn’t receive any response… on UDP.  
On TCP however, Homey did respond.  
However I’m not an expert on Wireshark so I can’t tell if the responses are ‘wrong’

---

<div class="post-metadata">

**Author:** ![robertklep](https://sea1.discourse-cdn.com/flex025/user_avatar/community.homey.app/robertklep/32/160628_2.png) [@robertklep](https://community.homey.app/u/robertklep)\
**Post date:** [January 15, 2021, 1:49pm UTC](https://community.homey.app/t/dos-attack-smurf-attack-packets-in-last-20-sec-from-ip/16245/25 "2021-01-15T13:49:13Z")

</div>

> [@Robin\_van\_Kekem](#):
>
> On TCP however, Homey did respond.

There’s something running on TCP port 53, but at least with firmware v4.2, it just closes the connection immediately:

```auto
$ dig +tcp @192.168.23.8 homey.app
;; communications error to 192.168.23.8#53: end of file

```

---

<div class="post-metadata">

**Author:** ![SmartVillaLife](https://sea1.discourse-cdn.com/flex025/user_avatar/community.homey.app/smartvillalife/32/9958_2.png) [@SmartVillaLife](https://community.homey.app/u/SmartVillaLife)\
**Post date:** [January 16, 2021, 8:53pm UTC](https://community.homey.app/t/dos-attack-smurf-attack-packets-in-last-20-sec-from-ip/16245/26 "2021-01-16T20:53:57Z")

</div>

Hey I had similair symptoms myself recently. Out of the blue I had wierd lan issues each time I stream out data(share screen etc) I loose connectivity. I see same error you guys did in netgear logs. I tried turn of netgear app in Homey but with no succces. I turn of homey and problems gone, however my entire house stop working because everything connected to the homey.

You suspect it has something to do with homey passive device scan. Can you turn it off or make The neetgear chill of?

Am using The 5.0 beta though

---

<div class="post-metadata">

**Author:** ![Beege](https://avatars.discourse-cdn.com/v4/letter/b/43a26b/32.png) [@Beege](https://community.homey.app/u/Beege)\
**Post date:** [March 17, 2022, 5:37pm UTC](https://community.homey.app/t/dos-attack-smurf-attack-packets-in-last-20-sec-from-ip/16245/27 "2022-03-17T17:37:20Z")

</div>

Hi, what is the status of these ‘Smurf attacks’ originating from Homey? I have the same thing: warning about possible Smurf attacks from my Homey address at a fixed interval of 15 minutes, from my router:

Mar 17 18:00:41 Firewall attack: Smurf attack -\>IN=br0 OUT= MAC= xxx SRC=192.168.178.xx  
Mar 17 18:15:37 Firewall attack: Smurf attack -\>IN=br0 OUT= MAC= xxx SRC=192.168.178.xx

---

<div class="post-metadata">

**Author:** ![Gruijter](https://sea1.discourse-cdn.com/flex025/user_avatar/community.homey.app/gruijter/32/1973_2.png) [@Gruijter](https://community.homey.app/u/Gruijter)\
**Post date:** [March 17, 2022, 5:54pm UTC](https://community.homey.app/t/dos-attack-smurf-attack-packets-in-last-20-sec-from-ip/16245/28 "2022-03-17T17:54:10Z")

</div>

[https://images.app.goo.gl/JPpQpXd3SuiUKaB47](https://images.app.goo.gl/JPpQpXd3SuiUKaB47)

---

<div class="post-metadata">

**Author:** ![robertklep](https://sea1.discourse-cdn.com/flex025/user_avatar/community.homey.app/robertklep/32/160628_2.png) [@robertklep](https://community.homey.app/u/robertklep)\
**Post date:** [March 17, 2022, 6:17pm UTC](https://community.homey.app/t/dos-attack-smurf-attack-packets-in-last-20-sec-from-ip/16245/29 "2022-03-17T18:17:35Z")

</div>

> [@Beege](#):
>
> Hi, what is the status of these ‘Smurf attacks’ originating from Homey?

Athom doesn’t care: [MAC discovery relies on broadcast pings that not all devices respond to · Issue #148 · athombv/homey-apps-sdk-issues · GitHub](https://github.com/athombv/homey-apps-sdk-issues/issues/148#issuecomment-715815454)

---

<div class="post-metadata">

**Author:** ![Beege](https://avatars.discourse-cdn.com/v4/letter/b/43a26b/32.png) [@Beege](https://community.homey.app/u/Beege)\
**Post date:** [March 17, 2022, 8:00pm UTC](https://community.homey.app/t/dos-attack-smurf-attack-packets-in-last-20-sec-from-ip/16245/30 "2022-03-17T20:00:47Z")

</div>

Ok, thanks for the link @robertklep , guess we can ignore this then.

---

<div class="post-metadata">

**Author:** ![robertklep](https://sea1.discourse-cdn.com/flex025/user_avatar/community.homey.app/robertklep/32/160628_2.png) [@robertklep](https://community.homey.app/u/robertklep)\
**Post date:** [March 18, 2022, 5:51am UTC](https://community.homey.app/t/dos-attack-smurf-attack-packets-in-last-20-sec-from-ip/16245/31 "2022-03-18T05:51:58Z")

</div>

> [@Beege](#):
>
> guess we can ignore this then.

Yes, just like Athom does 😉

---

<div class="post-metadata">

**Author:** ![Super9](https://sea1.discourse-cdn.com/flex025/user_avatar/community.homey.app/super9/32/57144_2.png) [@Super9](https://community.homey.app/u/Super9)\
**Post date:** [January 17, 2023, 6:27pm UTC](https://community.homey.app/t/dos-attack-smurf-attack-packets-in-last-20-sec-from-ip/16245/32 "2023-01-17T18:27:07Z")

</div>

I have also notis this and I could ignore it but the problem is that the router lose connection to all devices during the DoS and that is a hard to ignore problem. I have tried to disable Port Scan and DoS Protection on my netgear router but that does not help.

So how do I solve it?

---

<div class="post-metadata">

**Author:** ![robertklep](https://sea1.discourse-cdn.com/flex025/user_avatar/community.homey.app/robertklep/32/160628_2.png) [@robertklep](https://community.homey.app/u/robertklep)\
**Post date:** [January 17, 2023, 6:30pm UTC](https://community.homey.app/t/dos-attack-smurf-attack-packets-in-last-20-sec-from-ip/16245/33 "2023-01-17T18:30:57Z")

</div>

> [@Super9](#):
>
> So how do I solve it?

If you can’t disable it in your router, you can’t solve it. You can try [submitting a support request](https://support.homey.app/hc/en-us/articles/360015784034-Submitting-a-support-request) but I don’t have high hopes that Athom will do anything about it.

---

<div class="post-metadata">

**Author:** ![CoonHouse](https://sea1.discourse-cdn.com/flex025/user_avatar/community.homey.app/coonhouse/32/2764_2.png) [@CoonHouse](https://community.homey.app/u/CoonHouse)\
**Post date:** [December 19, 2024, 8:21am UTC](https://community.homey.app/t/dos-attack-smurf-attack-packets-in-last-20-sec-from-ip/16245/34 "2024-12-19T08:21:01Z")

</div>

Using an old thread, but I think it’s the same issue.

Since an hour ago I get these messages from my firewall:

> DOS][Block][smurf][homey-ip-\>192.168.11.255][ICMP][HLen=20, TLen=84, Type=8, Code=0]

They keep coming back (still going on) every 2 or 3 minutes.  
I have never seen these before and I don’t believe Homey was updated in the last hours (12.2.1).

Is there a way to stop this? I already rebooted Homey

---

<div class="post-metadata">

**Author:** ![robertklep](https://sea1.discourse-cdn.com/flex025/user_avatar/community.homey.app/robertklep/32/160628_2.png) [@robertklep](https://community.homey.app/u/robertklep)\
**Post date:** [December 19, 2024, 9:27am UTC](https://community.homey.app/t/dos-attack-smurf-attack-packets-in-last-20-sec-from-ip/16245/35 "2024-12-19T09:27:49Z")

</div>

There’s no way to stop this, this is “normal”.

---

<div class="post-metadata">

**Author:** ![CoonHouse](https://sea1.discourse-cdn.com/flex025/user_avatar/community.homey.app/coonhouse/32/2764_2.png) [@CoonHouse](https://community.homey.app/u/CoonHouse)\
**Post date:** [December 19, 2024, 9:31am UTC](https://community.homey.app/t/dos-attack-smurf-attack-packets-in-last-20-sec-from-ip/16245/36 "2024-12-19T09:31:32Z")

</div>

Oké, but why did it start today after running for years.

i whitelisted my Homey in my firewall so it stops sending warning emails, but wondering if it is a security issue.

---

<div class="post-metadata">

**Author:** ![robertklep](https://sea1.discourse-cdn.com/flex025/user_avatar/community.homey.app/robertklep/32/160628_2.png) [@robertklep](https://community.homey.app/u/robertklep)\
**Post date:** [December 19, 2024, 9:40am UTC](https://community.homey.app/t/dos-attack-smurf-attack-packets-in-last-20-sec-from-ip/16245/37 "2024-12-19T09:40:23Z")

</div>

> [@CoonHouse](#):
>
> Oké, but why did it start today after running for years.

It could be indirectly caused by an app you installed, the culprit is Athom’s implementation of “MAC discovery”.

> [@](#):
>
> i whitelisted my Homey in my firewall so it stops sending warning emails, but wondering if it is a security issue.

It’s not a security issue, just an annoyance. I mentioned this behaviour to Athom more than 4 years ago already.

---

<div class="post-metadata">

**Author:** ![CoonHouse](https://sea1.discourse-cdn.com/flex025/user_avatar/community.homey.app/coonhouse/32/2764_2.png) [@CoonHouse](https://community.homey.app/u/CoonHouse)\
**Post date:** [December 19, 2024, 9:45am UTC](https://community.homey.app/t/dos-attack-smurf-attack-packets-in-last-20-sec-from-ip/16245/38 "2024-12-19T09:45:17Z")

</div>

Oke, thanks.

I didn’t change anything in my setup in the last weeks, so no Idea what could have triggered this.  
My knowledge of networking is not that great, I think I remembered the .255 address is for broadcasting?  
But good to know it’s not a security issue.

Thanks

---

<div class="post-metadata">

**Author:** ![robertklep](https://sea1.discourse-cdn.com/flex025/user_avatar/community.homey.app/robertklep/32/160628_2.png) [@robertklep](https://community.homey.app/u/robertklep)\
**Post date:** [December 19, 2024, 10:42am UTC](https://community.homey.app/t/dos-attack-smurf-attack-packets-in-last-20-sec-from-ip/16245/39 "2024-12-19T10:42:27Z")

</div>

> [@CoonHouse](#):
>
> I think I remembered the .255 address is for broadcasting?

Correct, Homey does a ping to the local broadcast address to find devices (with the assumption that all devices respond to that, which they don’t).

[Previous page](https://community.homey.app/t/dos-attack-smurf-attack-packets-in-last-20-sec-from-ip/16245.md?page=1)
