DoS "Probing" on one of our hosts

From: Christopher Kunz (chrislist_at_de-punkt.de)
Date: 06/29/03

  • Next message: Dave Laird: "Re: Anyone else seeing a spike in SSHd scans?"
    Date: Sun, 29 Jun 2003 22:41:50 +0200
    To: incidents@securityfocus.com
    
    

    Hey,

    we have been encountering three short DoS attacks during the weekend -
    each one around 1 hour in length and with about 100mbit worth of
    bandwidth. So far, we've yet to determine even the most basic stuff,
    since we don't seem to have any logging. I have two questions regarding
    this:
    1. isn't one hour a pretty short time for a DoS? I've seen attacks on
    other nets lasting for hours, sometimes up to a day...
    2. is there any tool to determine the source IPs of the attack (even if
    they're spoofed, I'd like to see _anything_)? Snort sits on the attacked
    host and happily reports SQL/Slammer and other trivial stuff, but goes
    through one of the attacks without picking any signatures up.

    Regards,

    --ck

    -- 
    php development | hosting |  housing | professional game server hosting
    http://www.de-punkt.de   [ chris@de-punkt.de ]    http://www.stormix.de
    +49 511 1237504 | +49 511 1237505 | laportestr. 2a, 30449 hannover.de
    Filoo auf dem Linuxtag 2003 (F15) - http://www.de-punkt.de/lt2003.php
    ----------------------------------------------------------------------------
    Attend the Black Hat Briefings & Training, July 28 - 31 in Las Vegas, the 
    world's premier technical IT security event! 10 tracks, 15 training sessions, 
    1,800 delegates from 30 nations including all of the top experts, from CSO's to 
    "underground" security specialists.  See for yourself what the buzz is about!  
    Early-bird registration ends July 3.  This event will sell out. www.blackhat.com
    ----------------------------------------------------------------------------
    

  • Next message: Dave Laird: "Re: Anyone else seeing a spike in SSHd scans?"

    Relevant Pages

    • Re: Stealth vs. Blocked
      ... >certain packets as opposed to allowing your system or router to respond to ... >them you will cut down the impact of many DOS attacks. ... How many DOS attacks have you seen on your home computer (or in your ... And, don't you think that with that many packets coming in, ZoneAlarm ...
      (alt.computer.security)
    • Re: [PHP] Google Chrome
      ... Chrome already exploited for DoS attacks? ... its just a browser crash ... so forcing a browser to crash is not 'Denial of Service'? ...
      (php.general)
    • Re: Nortel Contivity 2600
      ... > him with DoS attacks - unless those attacks are due to malformed ... Firewall is not allways the right thing to protect, ... Audit your website security with Acunetix Web Vulnerability Scanner: ...
      (Pen-Test)
    • Re: [PHP] Google Chrome
      ... Chrome already exploited for DoS attacks? ... its just a browser crash ... I think your confused with DDoS ...
      (php.general)
    • Re: DoS "Probing" on one of our hosts
      ... > bandwidth. ... > through one of the attacks without picking any signatures up. ... They probably wont be interesting in helping backtrack ... world's premier technical IT security event! ...
      (Incidents)