Re: Attacks on ssh port

From: Zoran Kolic (kolicz_at_EUnet.yu)
Date: 09/20/04

  • Next message: Dmitry Pryanishnikov: "Re: Random source ports in FreeBSD?"
    Date: Mon, 20 Sep 2004 08:08:48 +0200
    To: freebsd-security@freebsd.org
    
    

    Dear all!
    There is possibility that someone
    makes fake tide of IP addresses,
    just to hide his own. If the list
    is long enough, that IP could be
    even not logged. If the packets
    are "syn", IPs you answer don't
    exist, you have syn flood and death
    of the server. However, only total
    idiot would make such kind of attack.
    Everybody knows he is trying some-
    thing. Suspect "script kid". Little
    joke with your server and you have
    a lot of job to do.
    Just be aware not to open new gate
    for another kind of attack. Human is
    the wickiest part of chain.
    Best regards

                         ZK

    _______________________________________________
    freebsd-security@freebsd.org mailing list
    http://lists.freebsd.org/mailman/listinfo/freebsd-security
    To unsubscribe, send any mail to "freebsd-security-unsubscribe@freebsd.org"


  • Next message: Dmitry Pryanishnikov: "Re: Random source ports in FreeBSD?"

    Relevant Pages

    • [NT] Web Browsers Vulnerable to the Extended HTML Form Attack
      ... inject HTML scripts, which makes use of the same method described in the ... The Original HTML form attack: ... server 7 open ...
      (Securiteam)
    • [UNIX] DoS Attack Against FreeRADIUS (Other RADIUS Servers Affected)
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... to create a high-performance and highly configurable GPL'd RADIUS server. ... program with failed requests causing a denial of service attack. ... Access-Request to the RADIUS server, ...
      (Securiteam)
    • Re: I was hacked
      ... > I have a Windows 2000 server that is current w/ the latest patches from MS. ... > It is running an IIS server that is configured w/ Microsoft's URLScan tool. ... > It is also running Terminal Services w/ 128 bit encryption turned on. ... > the first visible process of the attack. ...
      (alt.computer.security)
    • Re: I was hacked
      ... > I have a Windows 2000 server that is current w/ the latest patches from MS. ... > It is running an IIS server that is configured w/ Microsoft's URLScan tool. ... > It is also running Terminal Services w/ 128 bit encryption turned on. ... > the first visible process of the attack. ...
      (microsoft.public.inetserver.iis.security)
    • Re: I was hacked
      ... I saw no successes in your IIS Log. ... > It is running an IIS server that is configured w/ Microsoft's URLScan ... > It is also running Terminal Services w/ 128 bit encryption turned on. ... > the first visible process of the attack. ...
      (alt.computer.security)