Re: DoS "Probing" on one of our hosts

From: Christopher Kunz (chrislist_at_de-punkt.de)
Date: 06/30/03

  • Next message: Christopher Kunz: "Re: DoS "Probing" on one of our hosts"
    Date: Mon, 30 Jun 2003 18:47:50 +0200
    To: incidents@securityfocus.com
    
    

    Edward Balas wrote:
    >
    > Depends on the nature of the attack, from what I have seen this is not
    > uncommen. Ive seen this type agaist IRC servers quite often.

    Yeah, that is pretty usual - you want a server, specifically a node
    server, to lose its link with the other servers to "split" the network
    and be able to splitride your way into becoming op in your target
    channel(s). We don't run IRC services, however.

    > If you have access to the netflow accounting data for the routers, then
    > you can backtrace the traffic to the incomming network. Or if you dont,
    > your ISP may. They probably wont be interesting in helping backtrack
    > this given the short duration.

    I second. They seem to be used to real attacks going over days (to take
    down one of the many shell providers housed in the same data center) and
    don't take action for short spikes. They would, however, have filtered
    the source IPs on their border routers, but that's no good if you either
    don't know the source or have to suspect it is spoofed.

    --ck

    -- 
    php development | hosting |  housing | professional game server hosting
    http://www.de-punkt.de   [ chris@de-punkt.de ]    http://www.stormix.de
    +49 511 1237504 | +49 511 1237505 | laportestr. 2a, 30449 hannover.de
    Filoo auf dem Linuxtag 2003 (F15) - http://www.de-punkt.de/lt2003.php
    ----------------------------------------------------------------------------
    Attend the Black Hat Briefings & Training, July 28 - 31 in Las Vegas, the 
    world's premier technical IT security event! 10 tracks, 15 training sessions, 
    1,800 delegates from 30 nations including all of the top experts, from CSO's to 
    "underground" security specialists.  See for yourself what the buzz is about!  
    Early-bird registration ends July 3.  This event will sell out. www.blackhat.com
    ----------------------------------------------------------------------------
    

  • Next message: Christopher Kunz: "Re: DoS "Probing" on one of our hosts"

    Relevant Pages

    • RE: DoS "Probing" on one of our hosts
      ... that pattern sounds a lot more like someone's hacked a server and set up a warez site. ... There are lots of reasons your IDS isn't raising alarms: the system that was hacked was already an FTP server, ... a pretty good indicator for an attack. ... world's premier technical IT security event! ...
      (Incidents)
    • RE: Views and Correlation in Intrusion Detection
      ... >>server if my IMAP server isn't vulnerable to that attack. ... and the passive ones don't really tell you much about vulnerability ... world's premier technical IT security event! ...
      (Focus-IDS)
    • [NT] Web Browsers Vulnerable to the Extended HTML Form Attack
      ... inject HTML scripts, which makes use of the same method described in the ... The Original HTML form attack: ... server 7 open ...
      (Securiteam)
    • RE: Error 537 and 529 on SBS 2003 SP1
      ... Since the SBS 2003 server enabled security audit in the security policy by ... Regarding Security event 537 ... a core service for Microsoft Exchange. ...
      (microsoft.public.windows.server.sbs)
    • [UNIX] DoS Attack Against FreeRADIUS (Other RADIUS Servers Affected)
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... to create a high-performance and highly configurable GPL'd RADIUS server. ... program with failed requests causing a denial of service attack. ... Access-Request to the RADIUS server, ...
      (Securiteam)