LinuxQuestions.org
Visit Jeremy's Blog.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Server
User Name
Password
Linux - Server This forum is for the discussion of Linux Software used in a server related context.

Notices


Reply
  Search this Thread
Old 08-26-2016, 09:10 AM   #1
DrSchizo
LQ Newbie
 
Registered: Aug 2016
Posts: 1

Rep: Reputation: Disabled
Question Secure a server used for a SYN attack


Hi everybody,

My server has been used against my will for a SYN flood attack.

Code:
Attack detail : 20Kpps/6Mbps
dateTime                          srcIp:srcPort      dstIp:dstPort     protocol    flags    bytes       reason
2016.08.22 02:34:46 CEST   *.*.*.*:1615      *.*.*.*:28        TCP          SYN     40           ATTACK:TCP_SYN
I would like to restart it but I'm afraid that it will start again. Is there a quick fix to prevent this to happen? It doesn't need to be a loing term solution, since I'm planning to transfer all my website to another server and to close it down afterward. I just want it to be functional for the following week.

My server runs Debian, Apache, PHP and MySQL.

Unfortunately, I don't know how the request have been sent. Can I forbid my server to send external request, knowing that none of my website needs to do such a thing?

Thank you in advance for reading and maybe for answering!
 
Old 08-26-2016, 09:50 AM   #2
Emerson
LQ Sage
 
Registered: Nov 2004
Location: Saint Amant, Acadiana
Distribution: Gentoo ~amd64
Posts: 7,661

Rep: Reputation: Disabled
Compromised server stays offline. Investigate why it happened so you can secure your server better in the future.
 
1 members found this post helpful.
Old 08-26-2016, 01:14 PM   #3
lazydog
Senior Member
 
Registered: Dec 2003
Location: The Key Stone State
Distribution: CentOS Sabayon and now Gentoo
Posts: 1,249
Blog Entries: 3

Rep: Reputation: 194Reputation: 194
Since this server is compromised you cannot trust anything on including the Data. Hopefully you have full backups and can wipe and reinstall. But before placing it on the Internet again you have to really know and understand how the system got compromised to begin with.
 
1 members found this post helpful.
Old 08-29-2016, 07:02 AM   #4
24x7servermanagement
Member
 
Registered: Jul 2016
Location: India
Distribution: CentOS, Redhat, Ubuntu and Debian
Posts: 57

Rep: Reputation: Disabled
Agreed with Lazydog, you cannot trust the data. So really find out from which hosting account the attack is going on. It could be one of the account or all of them. So better to scan the accounts for malware. check the recent files changes, review all server logs. One by one if you find the account is clean, move it to new server.
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
SYN attack or not? How to block? mkools Linux - Security 7 09-23-2012 03:26 PM
i want protect my server from syn attack Dr.TrYaG Linux - Server 8 06-23-2011 12:04 PM
How can I secure my server from DoS attack ? neel.gurjar Linux - Server 9 06-25-2009 07:34 AM
SYN Attack z_haseeb Linux - Security 7 06-30-2008 06:04 PM
What are all these SYN-FLOODs? Am I under attack? Vanyel Linux - Security 11 10-10-2007 04:35 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Server

All times are GMT -5. The time now is 10:24 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration