Re: DoS "Probing" on one of our hosts

From: Christopher Kunz (chrislist_at_de-punkt.de)
Date: 06/30/03

  • Next message: Harlan Carvey: "RE: DoS "Probing" on one of our hosts"
    Date: Mon, 30 Jun 2003 18:47:31 +0200
    To: incidents@securityfocus.com
    
    

    Chris Calvert wrote:
    > DoS attack duration can vary considerably. I've seen attacks that last
    > over a day or two, it really depends on how persistent the attacker is
    > and how robust the target is. 100 Mbit attacks might bring down a small
    > hosting service, or get shrugged off by a target on a larger pipe.

    Right. Although our service provider seems to have a quite robust
    connection, the bottle neck is of course our rack's uplink.

    > Get a capture of the traffic and do some analysis.
    > help analyzing the traffic. For example, you might be getting hit with
    > huge packets which saturate your Internet connection and/or inbound
    > interface, or you may be getting hit with small packets but at a
    > packet/second rate that your switch, modem, interface, or whatever
    > cannot handle. There may be no signatures to detect, you might simply
    > be the target of a brute force traffic DoS.

    I suspect (after ruling out having a warez distro site on the box) the
    latter. Our uplink provider monitors traffic for us and the spikes are
    there - it's not that our uplink switch just stops working (as it would
    if too many packets per second came in), the traffic really is there. So
    my wild guess was that we were just ping -f'ed, stacheldrahted or
    something like that.

    --ck

    -- 
    php development | hosting |  housing | professional game server hosting
    http://www.de-punkt.de   [ chris@de-punkt.de ]    http://www.stormix.de
    +49 511 1237504 | +49 511 1237505 | laportestr. 2a, 30449 hannover.de
    Filoo auf dem Linuxtag 2003 (F15) - http://www.de-punkt.de/lt2003.php
    ----------------------------------------------------------------------------
    Attend the Black Hat Briefings & Training, July 28 - 31 in Las Vegas, the 
    world's premier technical IT security event! 10 tracks, 15 training sessions, 
    1,800 delegates from 30 nations including all of the top experts, from CSO's to 
    "underground" security specialists.  See for yourself what the buzz is about!  
    Early-bird registration ends July 3.  This event will sell out. www.blackhat.com
    ----------------------------------------------------------------------------
    

  • Next message: Harlan Carvey: "RE: DoS "Probing" on one of our hosts"

    Relevant Pages

    • RE: SYN Attacks - how i cant stop it
      ... # control how network packets are handled after IPFW or IPFILTER ... these MIB. ... # To defend against SYN attacks more commonly known as SYNFLOOD ...
      (freebsd-questions)
    • Re: IPS/IDS behavior with ISIC/UDPSIC/TCPSIC/ICMPSIC traffic
      ... considered as an attack that need to be protected by IPS devices? ... ISIC generates many packets with different IP protocols. ... If you still see 100% CPU problem, you may like to check you log settings. ... with real-world attacks from CORE IMPACT. ...
      (Focus-IDS)
    • Re: Voice encryption (Stream vs CBC mode)
      ... >> And I still don't know of any forgery attacks that are of importance in a ... > matters to your VoIP application, ... Suppose 64 packets per second, ... Compression takes c ms, encryption ...
      (sci.crypt)
    • Re: IDSIPS that can handle one Gig
      ... >> fragmented traffic, an attack can spread itself across multiple packets, ... >> to address such attacks causes a 3rd party loss. ... a bit of a bun fight when you place two vendors side by side ... >> CORE IMPACT. ...
      (Focus-IDS)
    • REVIEW: "Intrusion Signatures and Analysis", Stephen Northcutt et al
      ... "Intrusion Signatures and Analysis", Stephen Northcutt et al, 2001, ... Chapters three and four list a "top ten" of specific attacks, ... Chapter eight outlines packets that indicate ... Book reviews: mnbk.htm ...
      (comp.security.misc)