floods through our proxy

From: Jon Zobrist (jzobrist_at_contentwatch.com)
Date: 07/29/03

  • Next message: Frank Knobbe: "RE: Scan of TCP 552-554"
    To: incidents <incidents@securityfocus.com>
    Date: 29 Jul 2003 14:47:45 -0600
    
    
    

    We have an old software proxy that clients surfed through.
    It's discontinued and normally we have 50 clients or less still trying
    to use it. In the last hour it's climbed to over 3000 so I did some
    investigating.
    It seems the same clients over and over are making massive amounts of
    http queries. Since we don't proxy, we just forward to a page that says
    product discontinued, and since that page is on a thttpd server, it
    hasn't affected us.

    However, it seems to be a DoS...I've got 8 IPs that were sending a
    combined 40 requests/second listed in my firewall now.

    Anyone else noticing any bursts in http traffic or known attacks?

    -- 
    Jon Zobrist 
    CISSP
    <jzobrist@contentwatch.com>
    
    



  • Next message: Frank Knobbe: "RE: Scan of TCP 552-554"

    Relevant Pages

    • Re: Vista clients became unresponsive after network move
      ... was mentioned that DHCP wasn't used, ... used, and all clients are static and incorrectly configured, I can ... network connection. ... IPs are static assigned IPs in 192.168.x.x range. ...
      (microsoft.public.windows.server.networking)
    • Re: Vista clients became unresponsive after network move
      ... was mentioned that DHCP wasn't used, ... used, and all clients are static and incorrectly configured, I can ... All other IPs are ... network connection. ...
      (microsoft.public.windows.server.networking)
    • Help! Lost in the forrest ? or NAT issue?
      ... I have a small network (about 10 Clients) that I'm trying to get a net ... I setup a server w/ Win2k3 and standard 192.168.x.x IPs and DHCP the ... I was curoius if any one out there has a similar situation: Win2K3, ...
      (microsoft.public.win2000.networking)
    • Re: delicate DHCP problem with bridged eth devices
      ... > We want all of our packets to run through our Linux server to be able to ... > The clients themselves are wired to three 24-port switches, ... > other three to our switches / clients. ... it's tested to be working but the clients don't get their IPs ...
      (comp.os.linux.networking)
    • Re: Chanigin IPs on DCs
      ... If your dc is hosting dns make sure that all of your clients are updated ... dc (Like authenticating). ... I've come into an organization where their DCs are not part ... of the internal network but have public facing IPs instead. ...
      (microsoft.public.windows.server.active_directory)