LinuxQuestions.org
Visit Jeremy's Blog.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 01-10-2005, 10:24 PM   #1
davidtsui
LQ Newbie
 
Registered: Jan 2005
Posts: 2

Rep: Reputation: 0
port 80 attack, help!!!!


our network include a RH9 iptables firewall and RH9 web server.

several days ago, our webpage been hacked and change the default

webpage to a blank page which contain belowing

sentence"SegmentationFault -need a help?segfaultbr@hotmail.com."
After we replace the original homepage , we found that the firewall
server always show messages that it have lots of connection to

webserver's port 80 from different outside ip address. Moreover, our

webserver always appear message: "NET XXX messages suppressed".
it make our server very slow and can't provoid normal service again.
Does any one have been face similar situation before? Any methods
to avoid port 80 attack through iptables? Does the "Snort" can help

to avoid it again?
Thank you very much!!!
 
Old 01-11-2005, 12:30 AM   #2
sgrayban
Member
 
Registered: Nov 2004
Location: Spokane, WA
Distribution: Debian 6.0
Posts: 369

Rep: Reputation: 30
Try throttling your connections to port 80.

Look at shorewall.com and dos_evade for apache.
 
Old 01-11-2005, 01:26 AM   #3
rhoekstra
Member
 
Registered: Aug 2004
Location: The Netherlands
Distribution: RedHat 2, 3, 4, 5, Fedora, SuSE, Gentoo
Posts: 372

Rep: Reputation: 42
Is your box being hacked as in, code replaced, not the same anymore?
Or is there just a lot of traffic to your machine ?

If the first, don't trust your machine anymore, as it could be 'rootkit'ed, you'll have to reinstall.

if the latter, do as sgrayban suggested...

Also, is the port 80 to foreign IPs, outgoing ? or incoming?
 
Old 01-11-2005, 02:17 AM   #4
davidtsui
LQ Newbie
 
Registered: Jan 2005
Posts: 2

Original Poster
Rep: Reputation: 0
i am still not very clear

thanks sgrayban and rhoekstra.

after we been hacked, we already install a new RH9 linux web server , and then copy web data from old server to new web server, then install trend server protect anti-virus software to ensure no virus on web server.

and we install trend server protect anti-virus software
on linux firewall too, and not found any virus.

The question at now is we must let firewall accept port 80 requirement from internet and then redirect it to web server's port80 for broswing webpage. But very large quantity of port 80 connection requirement appear if we enable port 80 on firewall. we can't find any method to solve it now.

i Look at shorewall.com and dos_evade for apache as
sgrayban said. but i can't find any result? Can you give us some suggestion more detail?

Thank you very much.
 
Old 01-11-2005, 11:43 AM   #5
sgrayban
Member
 
Registered: Nov 2004
Location: Spokane, WA
Distribution: Debian 6.0
Posts: 369

Rep: Reputation: 30
shorewall is used as a firewall is much easier to use. It has the ability to throttle connections to any port.

dos_evade module for apache is just as it name suggests. It can be setup to add IP's to iptables incase your getting ddosed.

If you read the docs you will see this. I really recommend you use shorewall.
 
Old 01-11-2005, 12:38 PM   #6
david_ross
Moderator
 
Registered: Mar 2003
Location: Scotland
Distribution: Slackware, RedHat, Debian
Posts: 12,047

Rep: Reputation: 79
Moved: This thread is more suitable in Security and has been moved accordingly to help your thread/question get the exposure it deserves.
 
Old 01-11-2005, 12:43 PM   #7
sgrayban
Member
 
Registered: Nov 2004
Location: Spokane, WA
Distribution: Debian 6.0
Posts: 369

Rep: Reputation: 30
Quote:
Originally posted by david_ross
Moved: This thread is more suitable in Security and has been moved accordingly to help your thread/question get the exposure it deserves.
works for me
 
Old 01-12-2005, 12:48 AM   #8
rhoekstra
Member
 
Registered: Aug 2004
Location: The Netherlands
Distribution: RedHat 2, 3, 4, 5, Fedora, SuSE, Gentoo
Posts: 372

Rep: Reputation: 42
If not moving to shorewall, why not upgrade to RedHat ES/AS (paid) or Fedora Core (free) ? RH9 has past its end of life.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
What attack could this be??? darrel Linux - Security 10 02-26-2005 10:10 PM
What to do during an attack? revenant Linux - Security 9 04-02-2004 12:18 AM
Help I am UNDER ATTACK... needamiracle Linux - Security 28 04-22-2003 12:06 PM
Attack scanner NeTd4mN Linux - Networking 1 09-15-2002 05:56 PM
Any attack? vcheah Linux - Security 1 12-07-2001 01:26 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 10:59 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration