LinuxQuestions.org

LinuxQuestions.org (/questions/)
-   Linux - Security (https://www.linuxquestions.org/questions/linux-security-4/)
-   -   DOSessssssss !!!! (https://www.linuxquestions.org/questions/linux-security-4/dosessssssss-444389/)

gabsik 05-13-2006 07:27 AM

DOSessssssss !!!!
 
I keep on getting [DOS] connections on my router keeping on flooding me with mails from ips on my same isp's subnet.maybe worms on windos machines.This DOSes switch my router off "2" times a day.The router has a protection DOS checkbox,but no more than that.It has an another box for content filtering and an "hosts.deny" to stop visiting malicious content website,that i filled with ips 87.7.x.x,85.38.x.x,but maybe it's just for http connection on this sites.I have been using softwares like psad or honeyd,now i'm using labrea but i would like some hints on this ....
I have debian sarge 3.1 2.6 !

Brian1 05-13-2006 09:10 AM

Is this a linux router setup or a store bought router?
If linux router then what are you using to build your iptables?

Brian1

gabsik 05-14-2006 02:12 PM

It's a Netgear-dg834 with linux 2.4 inside software zebra and an http daemon,i can't connect to it with telnet or ssh only by browser and what you see it's what you get ... look at this logs:
Quote:

May 14 05:21:31 gateway TCP Packet - Source:87.10.99.100,2669 Destination:192.168.0.2,135 - [DOS]
May 14 05:21:31 gateway TCP Packet - Source:87.10.99.100,2669 Destination:192.168.0.2,135 - [DOS]
May 14 05:21:34 gateway TCP Packet - Source:87.10.99.100,2668 Destination:192.168.0.2,445 - [DOS]
May 14 05:21:34 gateway TCP Packet - Source:87.10.99.100,2668 Destination:192.168.0.2,445 - [DOS]
May 14 05:21:38 gateway TCP Packet - Source:87.10.99.100,2667 Destination:192.168.0.2,445 - [DOS]
May 14 05:21:38 gateway TCP Packet - Source:87.10.99.100,2667 Destination:192.168.0.2,445 - [DOS]
May 14 05:21:41 gateway TCP Packet - Source:87.10.99.100,2665 Destination:192.168.0.2,135 - [DOS]
May 14 05:21:41 gateway Send E-mail Success!
May 14 05:21:41 gateway TCP Packet - Source:87.10.99.100,2665 Destination:192.168.0.2,135 - [DOS]
May 14 05:21:41 gateway Send E-mail Success!

Brian1 05-14-2006 04:08 PM

Never used that hardware so no ideas on what one can do with it.

Brian1

gabsik 05-14-2006 04:45 PM

Who knows labrea ? any experiences?


All times are GMT -5. The time now is 09:56 AM.