i got a bunch of messages from my router this morning about a syn flood attack. the messages look like this:
Code:
Jul/24/2004 21:15:22
SYN Flood Attack Detect Packet Dropped
Jul/24/2004 21:15:22
SMTP: send mail succeed
Jul/24/2004 21:15:16
SYN Flood Attack Detect Packet Dropped
Jul/24/2004 21:15:15
SMTP: send mail succeed
Jul/24/2004 21:15:12
SYN Flood Attack Detect Packet Dropped
Jul/24/2004 21:15:12
SMTP: send mail succeed
Jul/24/2004 21:15:09
etc., about 4x that amount per message, in 12 separate messages.
so what happened? my webserver is running fine and there are no signs of cracking that i can see (log checks, chkrootkit, disk space/memory are fine, etc.) was it a successful DoS attack that i just didn't notice because i didn't happen to be trying to access the website during the attack?
from what i understand doing some research this morning, it's almost impossible to defend against a syn flood attack. i guess it was either random, or maybe some windows j3rk0ff on a forum where i was advocating linux deciding they were going to "teach me a lesson." should i cycle my modem and/or router and change the IP? the packet dropped seems like it was detected and averted, but i'm unclear about what the "send mail succeed" part means.
thx