Re: ICMP floods

From: Alfred Perlstein (bright@wintelcom.net)
Date: 02/19/01


Date: Mon, 19 Feb 2001 13:20:29 -0800
From: Alfred Perlstein <bright@wintelcom.net>
To: Andy Kim <andy@internetesl.com>


* Andy Kim <andy@internetesl.com> [010219 13:18] wrote:
> Some of the servers have been getting hit several times with ICMP
> floods from our FreeBSD server and we can't figure out why. They
> believe that someone had hacked in and put a trojan on our box.
> Is there any way of finding out what's going on and more importantly,
> how to fix the problem? Any help would be greatly appreciated as
> I am rather new to FreeBSD.

First off, please wrap lines at 70 characters.

As far as "recovering" this machine, your best bet is to do a backup
of all the _data_ (NOT executables) on the mahcine, ie, html, or
whatever, then do a complete reinstall. Otherwise you risk a
backdoor remaining in the system and wasting even more of your time
and reasources.

-- 
-Alfred Perlstein - [bright@wintelcom.net|alfred@freebsd.org]
"I have the heart of a child; I keep it in a jar on my desk."
To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-security" in the body of the message


Relevant Pages

  • Re: ICMP floods
    ... >> floods from our FreeBSD server and we can't figure out why. ... What is being used to detect these ICMP floods? ...
    (FreeBSD-Security)
  • Re: ICMP floods
    ... to port 137 on the FreeBSD DNS server. ... Of course the FreeBSD server was sending back ICMP port unreach, ... >>> floods from our FreeBSD server and we can't figure out why. ...
    (FreeBSD-Security)
  • RE: Firewall rules for local lan
    ... Firewall rules for local lan ... The FreeBSD server is used as an internet gateway with a dial up ... I'd like to be able to access the FreeBSD server from my local LAN ...
    (freebsd-questions)
  • Re: dial up on FreeBSD 4.8
    ... > I'm running FreeBSD 4.8 as a NAT router for my internal network. ... >my FreeBSD server with a modem and start using the internet as if I ...
    (comp.unix.bsd.freebsd.misc)
  • sftp and FreeBSD
    ... I closed down ftp on our FreeBSD server recently and have ... However I also have a FreeBSD ... I am not wanting to log on as root, and have root access via ftp ...
    (comp.unix.bsd.freebsd.misc)

Quantcast