Re: ICMP floods

From: Bryan Bradsby (Bryan.Bradsby@capnet.state.tx.us)
Date: 02/19/01


Date: Mon, 19 Feb 2001 16:26:27 -0600 (CST)
From: Bryan Bradsby <Bryan.Bradsby@capnet.state.tx.us>
To: Thomas Cannon <tcannon@noops.org>

One of our Certified NT techs installed a personal firewall at home that
was reporting an ICMP "DOS flood" from one of our DNS servers. So he sent
an e-mail to my boss saying he was sure the server was hacked including 10
Megabytes of bitmaps to "prove" it.

I checked the logs and saw 9 packets per second from his box from port 137
to port 137 on the FreeBSD DNS server.

Of course the FreeBSD server was sending back ICMP port unreach, just as
it should, for each of these Netbios queries.

It seems to me these personal firewalls are (by default) set too sensitive
and lump together dangerous and innocuous packet types, resulting in the
customer being very surprised to see all those "people hacking my
computer".

The vendor looks "good" because their product reports "attacks", the
customer feels comfortable that "he is now protected", and legitimate
infrastructure operators repeatedly explain to very skeptical consumers
that one ICMP echo return (per day) is not an attack on their computer.

-bryan bradsby

================================

On Mon, 19 Feb 2001, Thomas Cannon wrote:

> > * Andy Kim <andy@internetesl.com> [010219 13:18] wrote:
> > > Some of the servers have been getting hit several times with ICMP
> > > floods from our FreeBSD server and we can't figure out why. They
> > > believe that someone had hacked in and put a trojan on our box.
> > > Is there any way of finding out what's going on and more importantly,
> > > how to fix the problem? Any help would be greatly appreciated as
> > > I am rather new to FreeBSD.
>
> Hi Andy.
>
> What is being used to detect these ICMP floods? What version of FreeBSD do
> you have? Also, do you see anything in the FBSD machine's logs about icmp
> source-quench or bandwidth-limit icmp packets being issued?
>
> It's possible that the machine is broken, yes, but it's also possible that
> the measuring device is broken, or that something is misconfigured, or god
> only knows what.
>
> Cheers,
>
> tcannon
>
>
> Richard Feynman was a hacker; read any of his books.
> -Bruce Schneier
>
>
>
> To Unsubscribe: send mail to majordomo@FreeBSD.org
> with "unsubscribe freebsd-security" in the body of the message
>

To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-security" in the body of the message



Relevant Pages

  • Re: Master Time Server Help
    ... It looks like in this case your server can't resolve jac21797 IP address. ... ICMP: 23ms delay. ... NTP: -0.0094663s offset from JSTDC.johnstownamerica.com ... RefID: JSTDC.johnstownamerica.com ...
    (microsoft.public.windows.server.setup)
  • Re: ICMP floods
    ... >> floods from our FreeBSD server and we can't figure out why. ... What is being used to detect these ICMP floods? ...
    (FreeBSD-Security)
  • Re: DoS attack - advice needed
    ... > on my freebsd 3.3-release server. ... > to prevent such attacks on 3.x freebsd, without blocking all icmp ... If you're interested in making your boxes more resiliant to attack, ...
    (FreeBSD-Security)
  • Re: bestimmte Webseiten nicht mehr erreichbar
    ... Betrachtung): PMTUD Selbst-Sabotage auf Serverseite. ... Die Webserver werden vor poesen ICMP Paketen "geschuetzt", ... macht sich der Idiot, der die Server betreibt, damit IP kaputt. ...
    (de.comp.sys.mac.internet)
  • Re: Problems with DHCP (I believe)
    ... >>>says I have just gotten a new lease. ... >>>DHCP Server ... >>all ICMP will also cause you trouble. ... >>but it cann't communicate with the ISP DHCP server. ...
    (comp.security.firewalls)