LinuxQuestions.org
Visit Jeremy's Blog.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 05-13-2006, 07:27 AM   #1
gabsik
Member
 
Registered: Dec 2005
Location: This planet
Distribution: Debian,Xubuntu
Posts: 567

Rep: Reputation: 30
DOSessssssss !!!!


I keep on getting [DOS] connections on my router keeping on flooding me with mails from ips on my same isp's subnet.maybe worms on windos machines.This DOSes switch my router off "2" times a day.The router has a protection DOS checkbox,but no more than that.It has an another box for content filtering and an "hosts.deny" to stop visiting malicious content website,that i filled with ips 87.7.x.x,85.38.x.x,but maybe it's just for http connection on this sites.I have been using softwares like psad or honeyd,now i'm using labrea but i would like some hints on this ....
I have debian sarge 3.1 2.6 !
 
Old 05-13-2006, 09:10 AM   #2
Brian1
LQ Guru
 
Registered: Jan 2003
Location: Seymour, Indiana
Distribution: Distribution: RHEL 5 with Pieces of this and that. Kernel 2.6.23.1, KDE 3.5.8 and KDE 4.0 beta, Plu
Posts: 5,700

Rep: Reputation: 65
Is this a linux router setup or a store bought router?
If linux router then what are you using to build your iptables?

Brian1
 
Old 05-14-2006, 02:12 PM   #3
gabsik
Member
 
Registered: Dec 2005
Location: This planet
Distribution: Debian,Xubuntu
Posts: 567

Original Poster
Rep: Reputation: 30
It's a Netgear-dg834 with linux 2.4 inside software zebra and an http daemon,i can't connect to it with telnet or ssh only by browser and what you see it's what you get ... look at this logs:
Quote:
May 14 05:21:31 gateway TCP Packet - Source:87.10.99.100,2669 Destination:192.168.0.2,135 - [DOS]
May 14 05:21:31 gateway TCP Packet - Source:87.10.99.100,2669 Destination:192.168.0.2,135 - [DOS]
May 14 05:21:34 gateway TCP Packet - Source:87.10.99.100,2668 Destination:192.168.0.2,445 - [DOS]
May 14 05:21:34 gateway TCP Packet - Source:87.10.99.100,2668 Destination:192.168.0.2,445 - [DOS]
May 14 05:21:38 gateway TCP Packet - Source:87.10.99.100,2667 Destination:192.168.0.2,445 - [DOS]
May 14 05:21:38 gateway TCP Packet - Source:87.10.99.100,2667 Destination:192.168.0.2,445 - [DOS]
May 14 05:21:41 gateway TCP Packet - Source:87.10.99.100,2665 Destination:192.168.0.2,135 - [DOS]
May 14 05:21:41 gateway Send E-mail Success!
May 14 05:21:41 gateway TCP Packet - Source:87.10.99.100,2665 Destination:192.168.0.2,135 - [DOS]
May 14 05:21:41 gateway Send E-mail Success!

Last edited by gabsik; 05-14-2006 at 02:15 PM.
 
Old 05-14-2006, 04:08 PM   #4
Brian1
LQ Guru
 
Registered: Jan 2003
Location: Seymour, Indiana
Distribution: Distribution: RHEL 5 with Pieces of this and that. Kernel 2.6.23.1, KDE 3.5.8 and KDE 4.0 beta, Plu
Posts: 5,700

Rep: Reputation: 65
Never used that hardware so no ideas on what one can do with it.

Brian1
 
Old 05-14-2006, 04:45 PM   #5
gabsik
Member
 
Registered: Dec 2005
Location: This planet
Distribution: Debian,Xubuntu
Posts: 567

Original Poster
Rep: Reputation: 30
Who knows labrea ? any experiences?
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 10:50 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration