LinuxQuestions.org
Welcome to the most active Linux Forum on the web.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Networking
User Name
Password
Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.

Notices


Reply
  Search this Thread
Old 09-11-2013, 04:13 PM   #1
csDraco_
Member
 
Registered: Feb 2002
Location: Canada
Distribution: Fedora / CentOS
Posts: 93

Rep: Reputation: 15
Unhappy Network interface spammed


This is more of a sanity check question here ..

Can one limit the received bytes on a public interface (that needs to stay public)?

My "RX bytes" counter is at 2.5GiB and growing after just 2 days, without any legitimate traffic to my site, that is not "officially" online yet, in fact I don't even have a domain name for my server yet; just a public IP.

I managed to put a near stop to my "TX bytes" by adding malicious IPs to my iptables, turning off my httpd service and also dropping all port 80 packets.

But they keep on coming and coming (packets) with no end in sight on nearly all ports and mostly port 80, even though I'm dropping them with iptables from all IPs, and my RX bytes counter is still growing. Though at a slower rate but still about 50MB/hour.
 
Old 09-12-2013, 09:06 AM   #2
business_kid
LQ Guru
 
Registered: Jan 2006
Location: Ireland
Distribution: Slackware, Slarm64 & Android
Posts: 16,252

Rep: Reputation: 2321Reputation: 2321Reputation: 2321Reputation: 2321Reputation: 2321Reputation: 2321Reputation: 2321Reputation: 2321Reputation: 2321Reputation: 2321Reputation: 2321
That is odd. Sanity check failed. I had a box in a dmz (and so accessible) and I got stupid stuff because I had an ssh server on it, but nothing like what you are talking about. I got people running nmap, then a script trying to log in with names picked at random from the Flintstones :-/. I wasn't running iptables at all. But I was in no way secure, so I did things fast. I had put it there for a few days, and forgot to take it off.

If you're logging malicious IPs I would try and get the traffic blocked upstream of you. I'm sure the guys who run honeypots would love your IP!
 
1 members found this post helpful.
Old 09-12-2013, 10:20 AM   #3
csDraco_
Member
 
Registered: Feb 2002
Location: Canada
Distribution: Fedora / CentOS
Posts: 93

Original Poster
Rep: Reputation: 15
Blocking the traffic upstream sure would be nice, its like a zoo out there!

I had those brute force ssh attacks too within 2 days of going online if I remember correctly. Changing the default port to a much higher one fixed that quick.

For now I've added a rule to drop all access besides the IP I use to access my server; and incoming traffic on my public interface has come down to about 4 Mbytes an hour. Its been going down gradually to 4Mb so looks like bot farms are loosing interest.

But I still need to run my httpd on port 80, and unblock it one day .. and spammers know it.

Before I go public again with my port 80, I'll either subscribe to an ip blacklist, or install fail2ban, or both!

Cheers, and thanks for the sanity check business_kid
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
How to prevent auto up an interface at /etc/network/interface file ? Joydeep Bakshi Linux - Networking 8 07-28-2011 02:43 AM
Fedora 13 Network Interface fails to connect after starting network manager crazy eddy Linux - Networking 2 06-15-2010 09:47 AM
How NET_TX_SOFTIRQ select network interface when multiple interface exits Mr.J Linux - Kernel 0 06-02-2009 11:17 AM
In FC6 network interface doesn't come up if 'service network restart' command is run rajat Linux - Networking 2 05-02-2007 11:53 PM
network interface (BCM4401-B0) hangs on hight network load indig0kid Linux - Hardware 0 03-09-2007 09:49 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Networking

All times are GMT -5. The time now is 10:51 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration