LinuxQuestions.org
Review your favorite Linux distribution.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Networking
User Name
Password
Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.

Notices


Reply
  Search this Thread
Old 12-09-2011, 09:47 AM   #1
deviss
LQ Newbie
 
Registered: Dec 2011
Posts: 3

Rep: Reputation: Disabled
Windows 2k3 UDP flood, help please


Hello

I have a small server hosted on windows 2003 standard ed sp1 and since few days ago someone is flooding us through udp ports.

I have followed these guides

http://blog.larmib.com/2011/stop-out...-2003-or-2008/

and

http://www.serverintellect.com/suppo...c-blockip.aspx

but the upd flood still goes on.

I'm using outpostfirewall to see the packets and the ip that are flooding. svchost.exe is shown as flooded through UDP 123 port


Could anyone help me to sort this out?


Thank you
 
Old 12-09-2011, 12:15 PM   #2
macemoneta
Senior Member
 
Registered: Jan 2005
Location: Manalapan, NJ
Distribution: Fedora x86 and x86_64, Debian PPC and ARM, Android
Posts: 4,593
Blog Entries: 2

Rep: Reputation: 344Reputation: 344Reputation: 344Reputation: 344
How is this Linux related?
 
Old 12-09-2011, 05:42 PM   #3
deviss
LQ Newbie
 
Registered: Dec 2011
Posts: 3

Original Poster
Rep: Reputation: Disabled
i m thinking that someone could give a hand of help since i have seen other windows threads related
 
Old 12-09-2011, 07:25 PM   #4
macemoneta
Senior Member
 
Registered: Jan 2005
Location: Manalapan, NJ
Distribution: Fedora x86 and x86_64, Debian PPC and ARM, Android
Posts: 4,593
Blog Entries: 2

Rep: Reputation: 344Reputation: 344Reputation: 344Reputation: 344
Usually when Windows is discussed, it's in regards to a Linux interaction. For example, a problem running a Windows guest under Linux virtualization, or Windows connecting to a Linux server. There are hundreds of Windows support sites, if you are just having a Windows problem.
 
Old 12-19-2011, 07:57 PM   #5
WizadNoNext
Member
 
Registered: Nov 2009
Posts: 140

Rep: Reputation: 9
I shouldn't, but I would show my good intentions.
Just turn off NTP (Network Time Protocol). It includes any internet time synchronization!
And next time do your homework, before you would post on any forum and learn to read with understanding - it is LINUXquestions and not WINDOWSquestions!
Next time before you would ask about anything what have anything to do with IP ports type in google: tcp udp ports list and go to wikipedia link - it is actually rip off from IANA!
And, if would to use any server OS learn something about networking, IP, TCP, UDP, ports etc. 123 UDP is registered (as every 0-1023) and IANA put NTP on it really long years ago!

P.S. it is not flood! I can see that you didn't try to find what is it and why it appeared in first place! NTP is connectionless (rather obvious - it is UDP) and you simply register with "master" and "slaves" connects with you to synchronize your time, after completing this part you will become one of "slaves" as well - that is reason for high number of packets - you get your time and then you provide it to others. Eas, isn't it?

P.P.S. I read RFC for NTP years ago and simply gave him principles not specification, if he want to know how exactly it works, he can read NTP RFC and even thought I have this RFC on my server, I won't be looking for it - for me extending or refreshing this knowledge is pointless.
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Iptables configuration for UDP Flood AsadMoeen Linux - Server 13 06-04-2014 10:19 AM
How i can protect from udp flood boyan96 Linux - Networking 1 11-16-2011 06:09 PM
Windows UDP Flood? hoodez Linux - Networking 4 08-17-2010 08:17 PM
Flood of UDP 59002 from various IP's gadgetx23 Linux - Security 12 02-13-2010 07:58 AM
udp flood behind router darthaxul Linux - Software 3 08-17-2008 10:25 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Networking

All times are GMT -5. The time now is 12:34 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration