RE: DoS "Probing" on one of our hosts

From: Stone, Alexander (astone_at_mail.mcw.edu)
Date: 06/30/03


To: "'incidents@securityfocus.com'" <incidents@securityfocus.com>
Date: Mon, 30 Jun 2003 12:59:02 -0500

You know, from the looks of the traffic patterns you posted, there really
seams no way but to lean towards a DoS. During the peak inbound, there was
very little outgoing traffic at all. How can you have a warez FTP running
under those circumstances? But in order to determine the type of DoS,
you'll need a packet dump. I just hope there is another spike...

#-----Original Message-----
#From: Christopher Kunz [mailto:chrislist@de-punkt.de]
#Sent: Monday, June 30, 2003 11:48 AM
#To: incidents@securityfocus.com
#Subject: Re: DoS "Probing" on one of our hosts
#
#
#Chris Calvert wrote:
#> DoS attack duration can vary considerably. I've seen
#attacks that last
#> over a day or two, it really depends on how persistent the
#attacker is
#> and how robust the target is. 100 Mbit attacks might bring
#down a small
#> hosting service, or get shrugged off by a target on a larger pipe.
#
#Right. Although our service provider seems to have a quite robust
#connection, the bottle neck is of course our rack's uplink.
#
#> Get a capture of the traffic and do some analysis.
#> help analyzing the traffic. For example, you might be
#getting hit with
#> huge packets which saturate your Internet connection and/or inbound
#> interface, or you may be getting hit with small packets but at a
#> packet/second rate that your switch, modem, interface, or whatever
#> cannot handle. There may be no signatures to detect, you
#might simply
#> be the target of a brute force traffic DoS.
#
#I suspect (after ruling out having a warez distro site on the box) the
#latter. Our uplink provider monitors traffic for us and the spikes are
#there - it's not that our uplink switch just stops working (as it would
#if too many packets per second came in), the traffic really is
#there. So
#my wild guess was that we were just ping -f'ed, stacheldrahted or
#something like that.

#
#--ck
#
#--
#php development | hosting | housing | professional game server hosting
#http://www.de-punkt.de [ chris@de-punkt.de ] http://www.stormix.de
#+49 511 1237504 | +49 511 1237505 | laportestr. 2a, 30449 hannover.de
#Filoo auf dem Linuxtag 2003 (F15) - http://www.de-punkt.de/lt2003.php
#
#
#
#
#---------------------------------------------------------------
#-------------
#Attend the Black Hat Briefings & Training, July 28 - 31 in Las
#Vegas, the
#world's premier technical IT security event! 10 tracks, 15
#training sessions,
#1,800 delegates from 30 nations including all of the top
#experts, from CSO's to
#"underground" security specialists. See for yourself what the
#buzz is about!
#Early-bird registration ends July 3. This event will sell
#out. www.blackhat.com
#---------------------------------------------------------------
#-------------
#

----------------------------------------------------------------------------
Attend the Black Hat Briefings & Training, July 28 - 31 in Las Vegas, the
world's premier technical IT security event! 10 tracks, 15 training sessions,
1,800 delegates from 30 nations including all of the top experts, from CSO's to
"underground" security specialists. See for yourself what the buzz is about!
Early-bird registration ends July 3. This event will sell out. www.blackhat.com
----------------------------------------------------------------------------



Relevant Pages

  • RE: Limited vs full blown testing
    ... >I'm trying to understand the significance of DDOS testing and importance. ... >vector of attack that we live with, a risk level we hope to avoid. ... Ron - I think the difference here is DoS vs. DDoS. ... throwing packets at a target to fill all available bandwidth and I can't see ...
    (Pen-Test)
  • Re: Limiting closed port RST response from 381 to 200 p
    ... Snort is monitor the packets when find DoS detected and it send ... to syslog so the guardian find snort's alert on syslog and it will ... That's how i recieved lot DoS pretty often. ... > Limiting icmp unreach response from 5263 to 200 packets per second ...
    (FreeBSD-Security)
  • Re: blocking ips with iptables accessing invalid URL
    ... iptables -N APACHE_CHECK ... This will prevent you from small DoS attempts from the same IP within 1 ... I like this kind of solution but I think this rules doesnt work. ... I have added the rule to log when the packets are dropped and it logs every ...
    (RedHat)
  • Re: Small TCP packets == very large overhead == DoS?
    ... >> anticipate packets injected into the network by the sender. ... >> receiver could aggressively generate ACKs before data is actually ... >> tinygram DoS attack. ... Daytona attacks are independent of any real or ...
    (Bugtraq)
  • Re: [Lit.] Buffer overruns
    ... might become a DoS attack when re-written in a safe language. ... Some safe languages go even farther, and come with libraries that reduce ... would allow code substitution attacks in plain C and would allow DoS ... programmer is devoting much of their mental capacity to reasoning about ...
    (sci.crypt)