LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 10-10-2004, 08:16 AM   #1
floppywhopper
Member
 
Registered: Aug 2004
Location: Western Australia
Distribution: Mageia , Centos
Posts: 643
Blog Entries: 2

Rep: Reputation: 136Reputation: 136
Angry little blue men ??


OK OK
i thought I'd seen it all
or at least most of it
In my snort logs I get
Cyberkit, Nmap, Ip spoofing,MS SQL worms etc etc you name it

but what the hell is a broadscan smurf scanner

is this something new or what
are little blue guys ( the smurfs ) trying to crack my system
who are these morons and why arent they locked up in a rubber room

floppy

 
Old 10-10-2004, 11:14 AM   #2
christhom
Member
 
Registered: Sep 2004
Distribution: Debian sarge/sid
Posts: 41

Rep: Reputation: 15
Re: little blue men ??

Quote:
Originally posted by floppywhopper
but what the hell is a broadscan smurf scanner
http://www.pentics.net/denial-of-ser...pers/smurf.cgi

The smurf attack is a type of DoS attack, described here. I'd imaging this smurf scanner is scanning for vulnerabilities that allow someone to use the attack.

Quote:

who are these morons and why arent they locked up in a rubber room
They are invariably 15yr olds with far too much time on their hands, playing tit-for-tat against their "friends" on IRC somewhere. In this endeavour, recall neal stephenson: "Arguing with anonymous strangers on the Internet is a sucker's game because they almost always turn out to be - or to be indistinguishable from - self-righteous sixteen-year-olds possessing infinite amounts of free time."
 
Old 10-10-2004, 11:24 AM   #3
Capt_Caveman
Senior Member
 
Registered: Mar 2003
Distribution: Fedora
Posts: 3,658

Rep: Reputation: 69
A Smurf attack is a pretty well known DoS attack. It involves sending a ping to the broadcast address of a network. The catch is that the source address is spoofed to that of the target host, so that all the echo reply traffic from each host on the network that responds to broadcast pings will be sent to the target host instead of the attacker, so the initial packet is amplified by the number of hosts on the network. You should have your systems configured so that they do not respond to pings of the broadcast address or at the very minimum filter this kind of traffic at the border router/firewall. The alert is likely telling you that someone was attempting to identify whether your system/network responds to these kinds of packets and can be used as a smurf "amplifier". This attack is a well documented type of DoS, so you can find detailed info using a google search.

----EDIT---

or just follow the linkage christhom posted.

Last edited by Capt_Caveman; 10-10-2004 at 11:29 AM.
 
Old 10-10-2004, 11:56 PM   #4
floppywhopper
Member
 
Registered: Aug 2004
Location: Western Australia
Distribution: Mageia , Centos
Posts: 643

Original Poster
Blog Entries: 2

Rep: Reputation: 136Reputation: 136
Thanks Capt & Christhom

the Smoothie is set to drop pings, ICMPs, etc etc - its just driving snort crazy
will check out those links
and yes looking at the firewall logs there are a lot of 15 yr olds with way too much time on their hands
thanks again
floppy
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
X and Blue screen? SharkBait Linux - Newbie 5 09-20-2005 06:55 PM
blue screen on xp! j0hn_galt Fedora 2 08-14-2005 07:27 AM
Met the chick from X-Men the other night jaz General 12 05-15-2005 02:42 AM
RTL8139 or 8139too Mod. Red Hat 8.0. Men in White Coats? silverbear Linux - Hardware 2 01-09-2004 10:36 PM
Men are cool (joke) KenCo General 12 10-06-2003 02:17 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 03:54 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration