Re: Localhost packets on WAN

From: Kirby Angell (kangell_at_alertra.com)
Date: 09/30/04

  • Next message: David Gillett: "RE: Localhost packets on WAN"
    Date: Thu, 30 Sep 2004 16:10:12 -0500
    
    

    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA1

    In our case the WAN IP in question is for our backup connection and is
    not published anywhere. If this were a planned DDoS against us
    specifically I would expect they would use the IP published by for our
    web server.

    Still might be an actual attack, but probably not a DDoS precursor.

    spainsecurity-s.navarro wrote:
    | This kind of traffic can be also the beginning of an attack to your
    network.
    | I've been seing this behavior in the past months in some networks I've
    been
    | monitoring (of my customers).
    | Most of the times these spoofed addresses were the beginning of DDoS
    attacks to
    | hosting providers or just large networks.
    | Your perimeter (firewall, router, whatever) should block these
    packets, but in
    | the case of a DDoS atack you are lost, unless you have great bandwidth
    or you
    | are monitoring carefuly to provide info to your ISP, in order to block
    this
    | traffic before reaching your firewall. ISP also should not allow
    traffic from a
    | loopback address.
    | Hope this can help.

    - --
    Thank you,

    Kirby Angell
    Get notified anytime your website goes down!
    http://www.alertra.com
    key: 9004F4C0
    fingerprint: DD7E E88D 7F50 2A1E 229D 836A DB5B A751 9004 F4C0
    -----BEGIN PGP SIGNATURE-----
    Version: GnuPG v1.2.4 (GNU/Linux)

    iD8DBQFBXHY021unUZAE9MARAq0RAJ9W8AU9ghj89sVxIUHZs3Eqfc0BKQCbBOgi
    N9LLr5XZhzJQ4JUrZLP4NT0=
    =Ew8m
    -----END PGP SIGNATURE-----


  • Next message: David Gillett: "RE: Localhost packets on WAN"

    Relevant Pages

    • Re: IPspoofing
      ... The short answer is that, especially if the threat is DDoS, you can't. ... to disguise the true source of the attack. ... > Este mensaje puede contener información confidencial y/o privilegiada. ... Internet communications are not secure and therefore the Barclays ...
      (Security-Basics)
    • RE: any recommendable anti-ddos solution?
      ... With DDOS you cannot simply block a host, DDOS is originating from lots of ... different subnets on different geographic locations, so blocking a host ... attack, for example if I know you have an IPS system that denies traffic ... and the switch that goes to everything else inside the network. ...
      (Security-Basics)
    • RE: Client DDoS requests, ideas?
      ... The DDOS protection company you are thinking about is www.prolexic.com ... take into consideration that a real DDOS attack will not only take down the ... Asunto: Re: Client DDoS requests, ...
      (Pen-Test)
    • RE: IPS - Cisco vs. McAfee vs. Tippingpoint
      ... A few years ago I worked on a project with a large ISP regarding DDoS ... serious DDoS attack from the customer end. ... Betreff: Re: IPS - Cisco vs. McAfee vs. Tippingpoint ...
      (Focus-IDS)
    • Re: Denial of Service: Commercial Defense products
      ... Some of these fields will have to be at least bounded inside certain intervals - otherwise the attack will not be really effective or will not reach its victim. ... there is no 100% bullet proof solution against DDoS attacks. ... TCP sequence number. ... TCP checksum. ...
      (Focus-IDS)