ftp tcp reset floods



anyone familiar with something going around that is doing tcp resets on
ftp ports against akamai servers (err, 15% of the internet akamai)?

I have something jumping from one windows pc to another using them to
burst hundreds of thousands of small (less than 50 bytes) ftp packets
against various akamai
servers. I have sniffed the traffic, and it consists of small packets
with the tcp reset flag set to 1 coming from a non-privileged port on
the pc (e.g. 1046) and going against port 21 on the remote machine.
This is followed by an ack response from the remote machine (which is
listed as a duplicate ack) back to port 1046. Rinse and repeat a few
hundred thousand times.

This traffic brings the cpu utilization on our router quickly up to
100% at which point it starts to dump services. I am not sure if this
is an attempt to participate in a DDoS against the remote machines, or
if it is an attempt to tank my router.

Windows pcs have updated anti-virus (CA), are NOW running windows
firewall,
and are fully patched to today (although they may have been compromised
at any time in the past, who knows). Several have had on-line f-secure
and symantec scans in safe-mode that show nothing. Once I turn on
Windows Firewall (it was turned off to allow some administration via CA
Antivirus admin console and for Enterprise ghost functions to work),
that seems to stop the traffic, but I still must have a a nasty bug
waiting to pounce.

Any help would be appreciated.

.



Relevant Pages

  • Re: keeping ports open
    ... If a port is open, it means that 1) a software or service is running on your ... and 2) you're not using a firewall or your firewall isn't ... Use firewall software and hardware and antivirus software that is ... Follow the instructions for hardening Windows and IIS at ...
    (microsoft.public.security)
  • [Full-Disclosure] ron1n phone home, episode 4
    ... Hacking from Windows 3.x, 95 and NT ... Use secret Windows 95 DOS commands to track down and port surf computers ... Download hacker tools such as port scanners and password crackers designed ... Now you have the option of eight TCP/IP utilities to play with: telnet, ...
    (Full-Disclosure)
  • Re: How to Maintain an IIS Server?
    ... > server running on a Windows 2000 server. ... before a firewall and antivirus have been installed]. ... open ports; however, this will not identify which program is using the port. ...
    (microsoft.public.inetserver.iis.security)
  • RE: xp pro sharing printer
    ... How to troubleshoot network printing problems in Windows XP ... SMB-connected print server ... Incompatible print driver ... and then redirect the port to the network server. ...
    (microsoft.public.windowsxp.security_admin)
  • Re: Is secedit.exe left by a hacker?
    ... >> tested on port 445. ... >> I have a Linksys router that I use as a firewall to my ... >investigate the files on your computer - antivirus with ... >windows and everything else. ...
    (microsoft.public.win2000.security)