Dos Attack on SSH Tunnel
I have a small anonymizer service on the web , I have a squid server listening on 127.0.0.1 port 3128. and a ssh server which users connect to it and use it as a tunnel to connect to squid server. very simple setup.
recently I have encountered a problem I have no idea how to solve it. one or some of my users are infected by a worm , and they start to send lots of request for big zip or wmv files through ssh tunnel to my squid server. and it causes my incoming traffic to go very high. in fact it is a ddos attack. but I can not know which user or IP is attacking , because they come from ssh tunnel and in squid log all of requests come from IP 127.0.0.1 like this :
1176020701.378 12063 127.0.0.1 TCP_MISS/200 109973 GET h**p://a1327.r.akareal.net/ondemand/7/1327/2110/973023381/voice.download.akamai.com/2110/wm/voa/nenaf/pers/video/PERSIAN_LATEEDITION1830v0407.wmv? - DIRECT/126.96.36.199 application/octet-stream
do you have any idea how to debug this problem ?