LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 05-23-2006, 10:27 AM   #1
vicious_pucca
LQ Newbie
 
Registered: Aug 2005
Posts: 10

Rep: Reputation: 0
unblockable ip/port by apf?


someone's been flooding my server with UDP.. and i tried to ban IP and/or port with APF, but no available... any clue how to ban it?

problem is, it doesn't show up on netstat.

but it DOES show up on IPTraf/Ethereal.

it's UDP (46 byte) spam from 213.92.42.41:32913 to myserver:9898
another being UDP from 213.30.153.62(forgot the port)...

I DO use BFD + APF. and I've added those IPs into deny_hosts.rules and port 9898 into common drop ports, but no available.

I've tried to block it from iptables, didn't work. tried to use firestarter.. backfired and blocked myself.XD
 
Old 05-23-2006, 11:19 AM   #2
pljvaldez
LQ Guru
 
Registered: Dec 2005
Location: Somewhere on the String
Distribution: Debian Wheezy (x86)
Posts: 6,094

Rep: Reputation: 281Reputation: 281Reputation: 281
Is there any chance that the flood is originating from your server? I had a problem once where a machine on my network (winblows of course) was the origination. Since I was only dropping packets originating from outside the firewall, it didn't deny the flood. So I denied that port/IP outgoing from my network until I could track down the machine and isolate it.

Not familiar with firestarter, I always use fwbuilder to make my own custom firewalls. It's pretty robust and allows me to make some pretty complex rules fairly easily.
 
Old 05-23-2006, 11:22 AM   #3
vicious_pucca
LQ Newbie
 
Registered: Aug 2005
Posts: 10

Original Poster
Rep: Reputation: 0
looking at the IPs, i doubt it? my server is 64.92.xx.xx
 
Old 05-23-2006, 11:49 AM   #4
unixfool
Member
 
Registered: May 2005
Location: Northern VA
Distribution: Slackware, Ubuntu, FreeBSD, OpenBSD, OS X
Posts: 782
Blog Entries: 8

Rep: Reputation: 158Reputation: 158
There are a few things to note:

If you're sniffing with Ethereal from inside your network and the traffic is originating within your network, you're going to see it, even if you've a firewall rule in place to block the traffic.

Sometimes when using sniffers, its easy to misinterpret the traffic's direction, depending on the events happening. With snort, its usually easy to misinterpret web traffic because the tool alarms on system response. I've no idea about Ethereal, though, but I'm betting this traffic is coming from within your network...OR, its coming from outside your network but you haven't blocked the traffic properly...OR, you have blocked the inbound traffic correctly but the exploit is possibly taking advantage or a firewall vulnerability or is somehome circumventing your border firewall.

Can you post your Ethereal capture, if you're willing?

Last edited by unixfool; 05-23-2006 at 11:51 AM.
 
Old 05-23-2006, 12:22 PM   #5
vicious_pucca
LQ Newbie
 
Registered: Aug 2005
Posts: 10

Original Poster
Rep: Reputation: 0
attack has been stopped.

when attack was on-going, leaving ethereal on for, let's say, 3 sec, would create 15MB file.. lol. =d

and "destination" was my server. so i would say either "its coming from outside your network but you haven't blocked the traffic properly...OR, you have blocked the inbound traffic correctly but the exploit is possibly taking advantage or a firewall vulnerability or is somehome circumventing your border firewall." but possibly latter, since it is bypassing iptables/apf's IP ban.

*edited*
hmm, the person started attack again. i would get you ethereal capture, but i can't connect to the server due to high bandwidth usage.. but ya, port 9898 again.

*edited 2*
appearantly it IS hard to drop... he's claiming that he took tibia.com/muonline.com with same/similar method

Last edited by vicious_pucca; 05-23-2006 at 02:45 PM.
 
Old 05-27-2006, 06:04 AM   #6
vicious_pucca
LQ Newbie
 
Registered: Aug 2005
Posts: 10

Original Poster
Rep: Reputation: 0
http://andzropatch.deltaanime.net/Screenshot.png

he attacked again, so I got a screenshot of ethereal.
 
Old 05-31-2006, 08:37 AM   #7
linuxmanju
Member
 
Registered: Sep 2003
Location: India
Distribution: Debian
Posts: 50

Rep: Reputation: 15
YOU DID THAT MISTAKE AGAIN. Revealing your IPs through screenshot.
Damn.. Try to block that IP from the router or anything that is connected to your firewall, Or better still convince your ISP to block everything coming from that IP.

regards
Manjunath
 
Old 06-01-2006, 09:30 PM   #8
vicious_pucca
LQ Newbie
 
Registered: Aug 2005
Posts: 10

Original Poster
Rep: Reputation: 0
who said it was my current IP? =p

tried to block all udp. no success.
tried to block IP. no success(as it is forged, most likely)
tried to secure as much as possible. no success.
tried to contact the host. they denied the request. >_>
=d
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
APF how to use FILTERED latino Linux - Security 1 09-05-2005 01:22 AM
apf questions UnforgotteN Linux - Newbie 3 05-29-2005 05:09 PM
apf blocking ftp port 20 freebies Linux - Networking 1 05-08-2005 01:34 PM
apf and nfs engnet Linux - Security 1 12-04-2003 12:30 PM
APF Firewall BlackRain Linux - Security 2 06-12-2003 08:40 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 12:27 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration