Re: HELP Under Attack

From: Jem Berkes (jb_at_users.pc9.org)
Date: 08/24/04

  • Next message: buck: "Why is tcp_syncookies off by default?"
    Date: 24 Aug 2004 14:38:18 GMT
    
    

    > Hello, yes we are a well known company and we currently have 5 servers
    > with a load balancer. The balancer did a good job keeping up with the
    > attack. From what I have read tcp_syncookies takes the load off of
    > apache and transfers it to the kernel. I cannot drop traffic to any
    > country because we deal with all countries around the world.

    If the attacking IP addresses are genuine, then I would strongly recommend
    importing the big list of known compromised/zombie IP addresses from
    ahbl.org, cbl.abuseat.org and using these IPs in your firewall rule to
    block packets.

    But if the IP addresses are forged, syn cookies is your best bet. Of course
    you can't do anything about the bandwidth wasted by the attack, but it
    should keep the connection table in your TCP/IP stack clean.

    -- 
    Jem Berkes
    http://www.sysdesign.ca/
    

  • Next message: buck: "Why is tcp_syncookies off by default?"

    Relevant Pages

    • Re: Help SYN Flood Detection
      ... > I'm not trying to use snort to stop the attack... ... out of it's head (on the load balancer was it not?). ... could handle that kind of network traffic or am I perhaps missing something ... > The servers themselves are not having to hard of a time. ...
      (comp.security.firewalls)
    • Re: HELP Under Attack
      ... a load balancer. ... The balancer did a good job keeping up with the attack. ... >> servers from a Syn attack. ... > has made the common mistake of having something 'static' in the DoS attack ...
      (comp.os.linux.security)
    • Re: HELP Under Attack
      ... I had contacted Comcast on one of the ip's that came ... no clue that their Pc was being used in an attack. ... >> with a load balancer. ... >> country because we deal with all countries around the world. ...
      (comp.os.linux.security)
    • RAW Targets Pak Army Headquarters
      ... country from Afghanistan where tentacles of terrorism are present. ... By setting aside the atrocities of the Taliban militants ... of subversive acts also continue in Pakistan. ... It was the deadliest attack in ...
      (talk.politics.misc)
    • RAW Targets Pak Army Headquarters
      ... country from Afghanistan where tentacles of terrorism are present. ... By setting aside the atrocities of the Taliban militants ... of subversive acts also continue in Pakistan. ... It was the deadliest attack in ...
      (sci.military.naval)