Re: Strange attack question - seems udp

From: Christoph Gruber (list_at_guru.at)
Date: 10/21/05

  • Next message: jouser_at_gmail.com: "Re: SSH bruteforce on its way..."
    Date: Fri, 21 Oct 2005 13:31:03 +0200
    To: <incidents@securityfocus.com>
    
    

    On 18.10.2005 13:21 Uhr "Mihai Tanasescu" wrote as <mihai@duras.ro>:

    > Hello,
    >
    > Thanks for explainning the reason for udp ports not appearing in the
    > tcpdump output.
    > Well the Cisco 3750 is the gateway for my clients and not the
    > destination host (so I can't figure why it starts choking)
    >
    > The source IP addresses belong to my clients (those with 86.104 ).
    >
    > And it usually happens like this:
    > 3/4 ip addresses that belong to my clients contact the same 4-5 ip
    > addresses like the one below (70.84.247.164) and start doing 98% only
    > upload udp traffic.
    >
    > Is it possibly for a service to do so much upload compared to download ?

    May be this is not the right question. You'd should rather question "what
    the hell is talking to 70.84.247.164?"

    And 98% upstream udp ist strange in the second step.

    -- 
    "Theoretisch ist es praktisch, aber praktisch ist es unpraktisch" Bernhard
    P.
    

  • Next message: jouser_at_gmail.com: "Re: SSH bruteforce on its way..."

    Relevant Pages

    • Re: Example: VMS to Web Browser "push" technology
      ... to all clients that subscribe to a particular IP address. ... Was there some special reason to use UDP? ... There is no benefit in maintaining a persitent connection between client ... and server because who's to say that you'll want to visit that same server ...
      (comp.os.vms)
    • Re: Events between machines
      ... The problem with UDP is that it is generally not reliable. ... would also work if no single event would ever reach the clients. ... Windows Server 2003) which allows you to send a message to multiple ... > regarding how the clients (which are listening for these udp packets) ...
      (microsoft.public.dotnet.framework.remoting)
    • Re: network game example
      ... > i have a basic question about network games. ... > The clients send their controls/move commands to the server. ... > I got the hint to use UDP for a network game. ... * Send frame data UDP, ignore dropped frames & move on. ...
      (comp.games.development.programming.misc)
    • Re: Max NFSD processes
      ... >>I have several heavily used NFS servers, ... I meant a sysctl for the MAXNFSDCNT setting in nfsd.c. ... I have found that nfs over udp ... Most of my clients are using udp. ...
      (freebsd-questions)
    • Re: Max NFSD processes
      ... >>I have several heavily used NFS servers, ... I meant a sysctl for the MAXNFSDCNT setting in nfsd.c. ... I have found that nfs over udp ... Most of my clients are using udp. ...
      (freebsd-net)