Pls help: Stonebeat can't boot due to local "attack" ?

From: ST Wong (st-wong_at_alumni.cuhk.net)
Date: 09/13/04

  • Next message: MC: "Re: Zyxel ZyWall 10 router MADNESS"
    Date: 12 Sep 2004 23:11:38 -0700
    
    

    Hi all,

    We've around 20 machines protected by firewall in DMZ. There are 2
    firewall machines with HA configuration (Checkpoint firewall-1 FP3
    (Feature Pack 3), Stonebeat FullCluster version 3.0 SP 3-6 on
    Solaris). Recently we're under attack that made the firewall fail to
    start. Some findings follow:
    - the firewall machines hangs up and failed to reboot. The boot
    process hanged when starting Stonebeat.
    - the firewall machines could be reboot if the internal network cable
    is not connected.
    - no suspected traffic found in firewall log before the event
    occurred.
    - no information logged in IDS due to some system problems.
    - not much incoming traffic when the problem was detected.
    - most of the systems within DMZ are running properly, except 2, with
    large traffic rate.

    The firewall machines could be restarted after disconnecting the 2
    systems with large traffic volume. It's strange as these 2 systems
    are of small capacity when compared with the 2 firewal systems when
    there is no trace of hacking activities can be found on these 2
    systems. Meanwhile one of these systems seemed to hang up.

    I've no idea about what kind of attack we suffered from, due to
    limited information. Did anyone meet similar issue before?

    Sorry for the newbie question.
    Thanks a lot.
    Regards,
    /ST


  • Next message: MC: "Re: Zyxel ZyWall 10 router MADNESS"

    Relevant Pages

    • RE: External Network / Firewall Setup.
      ... ILLEGITIMATE traffic, and, depending on the type of firewall, they may ... inbound HTTP to a web server), then you either need to spend the big ... should prevent attack from getting into the internal network. ... > the mailserver in the DMZ - how much of a security issue is this? ...
      (Security-Basics)
    • RE: IDS question [was: Re: Firewall and DMZ topology]
      ... > along the lines of having the IDS in the DMZ. ... > past the outside firewall to the DMZ hosts would be ... IDS to recognise attack signatures and you get advance ...
      (Security-Basics)
    • RE: [Full-Disclosure] Sidewinder G2
      ... Secure Computing Sidewinder G2 Firewall Stops New High-Profile Sendmail ... Technology Prevents Sendmail Attack Warned About in CERT Advisory ...
      (Full-Disclosure)
    • RE: Thinking about Security rules...
      ... > Subject: Re: Thinking about Security rules... ... >>rules for the IDS. ... by which you attack. ... firewalls in series isn't nearly as nice as a stateful firewall coupled ...
      (Vuln-Dev)
    • Re: Can I protect myself against network attacks?
      ... > I guess that was one purpose of the attack. ... > had happened if you just used the SP2 firewall which does not warn you ... back, I've seen the firewall crash before my eyes, without warning. ... network attacks, or trojans. ...
      (comp.security.firewalls)