RE: DoS

From: Andrew Hatfield (andrew@hatfields.com.au)
Date: 01/07/02


Date: Tue, 8 Jan 2002 08:26:32 +1000
From: "Andrew Hatfield" <andrew@hatfields.com.au>
To: "Aleksey Domorad" <aleksey@lioha.com>, <focus-linux@lists.securityfocus.com>


> [**] DDOS shaft synflood [**]
> 01/07-08:21:35.632619 0:2:17:62:12:A5 -> 0:10:4B:C5:F:D
> type:0x800 len:0x3C
> 194.77.208.1:1580 -> XXX.XXX.XXX.XXX:111 TCP TTL:16 TOS:0x0 ID:58100
> IpLen:20 DgmLen:40
> ******S* Seq: 0x28374839 Ack: 0x2294E541 Win: 0xFFFF TcpLen: 20
>
> =+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+=+
> =+=+=+=+=+=+
>
> I'd like to know if there is anykind of software that can
> besides detecting
> DoS attack also report via any tool to Administrator and or
> ISP Abuse Email

you can use Demarc (http://www.demarc.org/) which is an excellent
interface to snort.

you could use syn flood protection via iptables and log it to
/var/log/synflood and have a cron job that checks the log file, parses
it, does funky stuff and then mails you results.

you could also look at logcheck from psionic

  --
  Andrew Hatfield
  Head - Internet Security Division

  Hatfield & Associates Pty. Ltd.
  Phone : +61 7 3849 7155
  Fax : +61 7 3849 6277
  Email : info@hatfields.com.au
  Web : http://www.hatfields.com.au/



Relevant Pages

  • Re: DoS
    ... > I'd like to know if there is anykind of software that can besides detecting ... > DoS attack also report via any tool to Administrator and or ISP Abuse Email ...
    (Focus-Linux)
  • Re: DoS
    ... > I'd like to know if there is anykind of software that can besides detecting ... > DoS attack also report via any tool to Administrator and or ISP Abuse Email ...
    (Focus-Linux)
  • Re: Is it possible to use the value of the PROGRAM ID within the source code?
    ... >> probably to print in a log file or report header. ... The starter program could pass the program name as parameter 1, ... I looked at the debugger. ...
    (comp.lang.cobol)
  • Re: report showing who logged in/out of nt 4 server
    ... permission to the log file (in the logon script solution, ... able to write to the log file, ... report any time, and you can use Excel to analyze the report. ...
    (comp.os.ms-windows.nt.admin.security)
  • I am not receiving server performance or usage reports
    ... SBS Backup Logs - This log file was not found. ... Click Change Server ... Status Report Settings on the Monitoring and Reporting ... There are no updates for this log file. ...
    (microsoft.public.windows.server.sbs)