Re: flood attacks

From: Mike Silbersack (silby@silby.com)
Date: 09/27/01


Date: Thu, 27 Sep 2001 09:19:14 -0500 (CDT)
From: Mike Silbersack <silby@silby.com>
To: Ronan Lucio <ronan@melim.com.br>


On Thu, 27 Sep 2001, Ronan Lucio wrote:

> Hi All,
>
> Some times Iīm having troubles with somebody attacking
> my network by RST flood
>
> I have two questions:
>
> 1. My FreeBSD-4.3 only show the message
> Limiting closed port RST response from 1800 to 200 packets per second.
> But, it donīt show the source IP of attack. I already looked at
> /var/log/messages, security and ipfw files and I saw nothing about this.
> Does anybody knows what option should I configure to FreeBSD show
> me such IP?

When it says "Limiting closed port RST response", what this means is that
*your* response is being limited. They could be throwing almost any type
of packet at you. In order to detect what's happening, you could install
a network IDS such as snort, or take captures with tcpdump.

Note that if the attack is spoofed, tracing it backs to its source may be
a lot of effort, and not worth it in this case. Others on this list can
probably tell you more info about how to go about this.

Mike "Silby" Silbersacks

To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-security" in the body of the message



Relevant Pages

  • Tech paper on proposed future generation NIDS
    ... Data is aggregated from the network ... UDP packets, or other incongruity in data and packet types. ... to reduce IDS rule sets and attack proccessing. ... When people in security speak of correlation, ...
    (Focus-IDS)
  • RE: Intrusion Prevention Systems
    ... Network systems functioning as a bridge can prevent the traffic ... recognize the attack and prevent it from affecting the target is absurd. ... His point is that there are many techniques ... variables affecting the application's receipt of and response to the data. ...
    (Focus-IDS)
  • [Full-disclosure] Re: RLA ("Remote LanD Attack")
    ... > " That is correct this affects network perimeter devices, ... > I used the -k switch a few, times although, it seemed to work either ... > the data/payload size seems to cause the attack to be more optimized. ... >>> remotely against the central connectivity device. ...
    (Full-Disclosure)
  • RE: ForeScout ActiveScout (was: Re: Intrusion Prevention)
    ... The technology sounds interesting but I have doubts regarding the ... If I for example scan for port 80, ... How do you deal with real network problems that prevent legitimate ... put the product in alert mode waiting for an attack? ...
    (Focus-IDS)
  • Re: Emergency HT for non HAM?
    ... Even if there is no chance of them being in the attack itself, ... We have 3 1/2 cell phone carriers here, one runs a mixed AMPS CDMA network, ... Ham radio still works. ... and communicate when everything you think is normal stops working. ...
    (rec.radio.amateur.equipment)