Re: dos attack solution or not

From: SysAdm (me_at_here.com)
Date: 06/28/04


Date: Mon, 28 Jun 2004 19:22:46 +0000 (UTC)

Duane Arnold <notme@notme.com> wrote in
news:Xns95163E3255B8notmenotmecoml@204.127.204.17:

> "aha" <c> wrote in news:40dfc386$0$124$1b2cd167@news.wanadoo.nl:
>
>> a dos attack happens when 1000's pc sends out 1000's calls for
>> connection request ,why can a firewall
>> not count the number of req from a ip number to the server and grant
>> only one req every 20 sec or so ?
>> this way the server is shielded from the attacker.
>>
>> or is this way to simple,
>> abe
>
> I don't know. To me, just setting a network FW to not respond to pings
> may be a viable solution. Or the ability to set rules on a FW
> appliance to block the IP for a certain amount of time would be viable
> also.
>
> Duane :)
>

ping floods are one of the easiest things to rate-limit for ISPs and
besides, pings are a fairly lame dDos. dDos attacks tend to be based on
service ports these days (either existing or freshly installed).

blocking the source IP for a timelimit is also a potential nightmare as
the source IP in a dDos attack is usually a zombie.

SysAdm



Relevant Pages

  • Re: NLB Cluster - Ping fails or long time to reply from outside local subnet
    ... Using Network Monitor I see the pings being received and replies being sent ... Windows Server 2008 Readiness Team ... administered address is being set correctly on the cluster adapter. ...
    (microsoft.public.windows.server.clustering)
  • RE: using fping to monitor internet connection status
    ... derived from the hosts list ... Fping is in ports ... If one goes down, I don't care, maybe that server is down, so keep ... If variable == number of servers then all pings failed. ...
    (freebsd-questions)
  • Re: NLB Cluster - Ping fails or long time to reply from outside local subnet
    ... Windows Server 2008 Readiness Team ... I have disabled one of the Broadcom NICs, (NIC1 which had an IP from the same subnet). ... I should re-iterate that pings respond perfectly when performed from another host on the same subnet/x.x.16.0 network. ... They are definitely not being teamed and I have tested the locally administered address is being set correctly on the cluster adapter. ...
    (microsoft.public.windows.server.clustering)
  • Re: If you want another way to see if your running a server or host
    ... >running an illegal host or server. ... The only way to see what services are ACTIVELY listening for connections ... >getting so many pings. ...
    (comp.security.firewalls)
  • Re: network setup
    ... firewall on the SBS server blocking the Pings. ... > network setup in my office with a server running Win 2003 SBS. ...
    (microsoft.public.windows.server.setup)