RE: Best way to filter "Nachi pings"?

From: Francis A. Vidal (francisv-sender-21ebc3_at_irc.dagupan.com)
Date: 10/27/03

  • Next message: Colin Percival: "RE: Best way to filter "Nachi pings"?"
    To: <freebsd-security@freebsd.org>
    Date: Mon, 27 Oct 2003 16:06:44 +0800
    
    

    Wouldn't it break stuff like traceroute?

    -----Original Message-----
    From: Kris Kennaway [mailto:kris@obsecurity.org]
    Sent: Monday, October 27, 2003 4:03 PM
    To: Brett Glass
    Cc: security@freebsd.org
    Subject: Re: Best way to filter "Nachi pings"?

    On Mon, Oct 27, 2003 at 12:31:46AM -0700, Brett Glass wrote:
    > We're being ping-flooded by the Nachi worm, which probes subnets for
    > systems to attack by sending 92-byte ping packets. Unfortunately,
    > IPFW doesn't seem to have the ability to filter packets by length.
    > Assuming that I stick with IPFW, what's the best way to stem the
    > tide?

    Block all ping packets? Most security-conscious admins do this
    anyway.

    Kris
    _______________________________________________
    freebsd-security@freebsd.org mailing list
    http://lists.freebsd.org/mailman/listinfo/freebsd-security
    To unsubscribe, send any mail to "freebsd-security-unsubscribe@freebsd.org"


  • Next message: Colin Percival: "RE: Best way to filter "Nachi pings"?"

    Relevant Pages

    • Re: Can not ping the server
      ... Outbound filters to the adapter to allow Internet Control Message Protocol ... Please follow the steps to enable ICMP router to resolve the issue. ... Cannot Ping External Network Adapter After Configuring RRAS as a VPN Server ... Create a IP packet filter using the pre-defined "ICMP Ping Query" ...
      (microsoft.public.windows.server.sbs)
    • Re: [TIP] BUG kmalloc-4096: Poison overwritten (ath5k_rx_skb_alloc)
      ... in parallel with iperf or ping. ... Unfortunately I had no filter so this was ... (the script is obviously flawed but it did the job) ... is also a pre grepped log of in that directory. ...
      (Linux-Kernel)
    • Re: Openserver 5.0.6 ping floods router
      ... network causes the pings to stop. ... capture those ping packets with your sniffer; ... Turn on process accounting, then monitor it: ...
      (comp.unix.sco.misc)
    • newbie debian network problem : no ping on eth0
      ... I have installed debian 3.1r2 onto a Dell Latitude CPi laptop ... However I can't ping to or from the laptop on my home network. ... the ping packets are being sent via lo rather than eth0. ... My route table looks ok: ...
      (comp.os.linux.networking)
    • Re: =?ISO-8859-1?Q?"Sinkt_mit_steigend?= =?ISO-8859-1?Q?em_IQ_der_religi=F6se?= =?IS
      ... Ping Of Death MC schrieb am Sat, ... Ich bin nicht auf Deinen geistigen Ping ... Natürlich stecke ich Dich zu Deinen andern Dummdödel-Masken Ulrich ... Filter zu tunneln, um wieder auf mich eingehen zu können, obwohl ich ...
      (de.soc.weltanschauung.christentum)