Re: flood attacks

From: Dave (mudman@R181172.resnet.ucsb.edu)
Date: 09/27/01


Date: Thu, 27 Sep 2001 09:10:55 -0700 (PDT)
From: Dave <mudman@R181172.resnet.ucsb.edu>
To: Ronan Lucio <ronan@melim.com.br>


> Limiting closed port RST response from 1800 to 200 packets per second.

Awhile back, I managed to reproduce this by portscanning myself with a
very fast scanner which doesn't wait for any kind of response from the
server before testing the next port. The 1800 to 200 message thing sounds
quite general, so you could be getting flooded with lots of different
kinds of data. If the messages come in briefly and then stop for awhile
(rather than a continus flow) you could just be getting a fast port scan.

To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-security" in the body of the message



Relevant Pages

  • Re: flood attacks
    ... If they are not hitting random ports and hitting say your web server, ... >> very fast scanner which doesn't wait for any kind of response from the ... If the messages come in briefly and then stop for awhile ... >> you could just be getting a fast port scan. ...
    (FreeBSD-Security)
  • hardware firewall
    ... I have been searching the web for awhile now and have not ... I have a webserver running on Port 80 and the only way that you can ...
    (comp.security.misc)
  • hardware firewall
    ... I have been searching the web for awhile now and have not ... I have a webserver running on Port 80 and the only way that you can ...
    (comp.security.firewalls)
  • Router Port #
    ... can someone refresh my memory to which port to open & forward on the router, ... i haven't set one up for awhile & just blanked on it. ...
    (microsoft.public.sharepoint.teamservices)