LinuxQuestions.org
Download your favorite Linux distribution at LQ ISO.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Networking
User Name
Password
Linux - Networking This forum is for any issue related to networks or networking.
Routing, network cards, OSI, etc. Anything is fair game.

Notices


Reply
  Search this Thread
Old 05-18-2018, 12:41 AM   #1
geppy
LQ Newbie
 
Registered: Dec 2017
Posts: 15

Rep: Reputation: Disabled
website, man-in-the-middle


Guys, I am having a problem when I go to a website, man-in-the-middle sends tons of ACK packets and I block some replies to these packets.
The more replies I block (currently 75%) the more attacker sends.

Obvious correct solution would be to look whats in these ACKs but they are encrypted.

What kind of firewall can defend agains this specific attack or maybe this attack has a name?

Maybe this attack exploits some issues in kernel sockets?

EDIT: If I don't block anything then chromium GUI freezes(i can't right click) and eventually chromium closes on its onw. It used to be that web pages or gui flash with black rectangles. Now better.

Last edited by geppy; 05-21-2018 at 01:56 AM.
 
Old 05-21-2018, 03:53 PM   #2
nini09
Senior Member
 
Registered: Apr 2009
Posts: 1,850

Rep: Reputation: 161Reputation: 161
It might be not a attack and could be that some setting is wrong.
 
Old 06-16-2018, 03:56 PM   #3
geppy
LQ Newbie
 
Registered: Dec 2017
Posts: 15

Original Poster
Rep: Reputation: Disabled
The setup is called default setup.

The fixes are under way. So far it debian+wayland+apparmor (no network in debian).
I have sand-boxed systemd (and its systemd-* friends), gdm3, and all their children, and whatever is left.
Took me around one months, full 7 days per week and 10hours per day,
If systemd or systemd-login (no more left from this crap pile) can run without access to /sys or /run or /proc/*/comm - its a good setup.

I am sill having only 150KByte download speed on large files out of my 1MBit. Thinking what need to be done. I have not even apllied fuzzy iptables extension yet. I also have pfsense+suricata on my router which may choke up.

Thanks for no help. But this is what you are payed for?
 
Old 06-17-2018, 02:14 AM   #4
ondoho
LQ Addict
 
Registered: Dec 2013
Posts: 19,872
Blog Entries: 12

Rep: Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053Reputation: 6053
for other people who find this thread:
OP has not provided any hard info on the actual situation; it is all his/her/other interpretation.
an attack is what they think is happening.
i'm not saying it is not so, but we would need hard info to assess the situation.

Quote:
Originally Posted by geppy View Post
Thanks for no help. But this is what you are payed for?
i think you misunderstand.
we all are just lusers here, like you.
nobody's getting paid anything (with the exception of jeremy maybe).
 
Old 06-17-2018, 05:55 PM   #5
Habitual
LQ Veteran
 
Registered: Jan 2011
Location: Abingdon, VA
Distribution: Catalina
Posts: 9,374
Blog Entries: 37

Rep: Reputation: Disabled
Quote:
Originally Posted by geppy View Post
Guys, I am having a problem when I go to a website
What "site"?
Scan it?
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
man-in-the-middle-attack chiendarret Linux - Security 4 12-25-2009 07:12 AM
ssh man-in-the-middle naomi Linux - Security 2 05-19-2005 02:04 PM
man in the middle attack atul_mehrotra Programming 12 09-22-2004 11:48 AM
man in the middle attack atul_mehrotra Linux - Security 4 09-22-2004 09:02 AM
Man in the middle attack juanb Linux - Security 17 03-29-2004 01:03 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Networking

All times are GMT -5. The time now is 06:32 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration