LinuxQuestions.org
Share your knowledge at the LQ Wiki.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 11-03-2002, 01:38 PM   #1
pilot1
Member
 
Registered: Jun 2002
Location: USA
Distribution: Gentoo, Fedora Core
Posts: 408

Rep: Reputation: 30
Am I being DoSd?


First off, i'm sorry if this is the wrong forum, I didn't know where to put it.

My cable line has been going on and off all day, and I assumed it was simply maintenance, until I checked RoadRunner's webpage, which says everything is working fine. Then I got the idea I could be the victim of a DoS attack, and so I configured my Linksys router to show me all the incoming packets. Here is a sample of them, as you can see some are from IPs that simply don't exist, such as 0.24.4.1.

Source IP ---- Destination Port Number
213.255.66.97 ---- 21
213.84.126.95 ----137
200.176.116.226 ----137
80.13.164.113 ----137
203.239.159.234 ----1660
207.69.188.187 ----1089
203.239.159.234 ----1660
207.69.188.187 ----1089
207.69.188.186 ----1075
216.73.82.11 ----1272
207.69.188.185 ----1065
61.1.36.156 ----137
207.69.188.187 ----1060
207.69.188.186 ----1043
24.200.196.67 ----137
35.11.130.97 ----49320
0.24.4.1 ----1035
65.172.162.154 ----1093
65.172.162.153 ----1092

What do you guys think?
And if it is a DoS how would I set up RH 7.2, or my Linksys router to stop it?

Last edited by pilot1; 11-03-2002 at 01:42 PM.
 
Old 11-03-2002, 05:07 PM   #2
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Without a full printout of firewall logs, especially flags and rates, no. Have you read this thread?
 
Old 11-03-2002, 06:19 PM   #3
pilot1
Member
 
Registered: Jun 2002
Location: USA
Distribution: Gentoo, Fedora Core
Posts: 408

Original Poster
Rep: Reputation: 30
No, i'm reading it. Thats all the logs I have, the only firewall I have is my router. I need to set up a better one, but I dunno how to.
 
Old 11-03-2002, 08:29 PM   #4
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Hmm, how about searching Linuxquestions.org for terms like linksys+firewall?
With a +10K userbase I'm sure we can provide some info...
 
Old 11-04-2002, 07:40 AM   #5
pilot1
Member
 
Registered: Jun 2002
Location: USA
Distribution: Gentoo, Fedora Core
Posts: 408

Original Poster
Rep: Reputation: 30
I read the search results, and i'm pretty sure that it was a DoS, and that my router is configured just as well as it can be..
 
Old 11-04-2002, 08:04 AM   #6
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,415
Blog Entries: 55

Rep: Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600Reputation: 3600
Well, I'm ready to learn then.
W/o knowing packet flags or clues from payload size/contents, how did you determine it was a DoS attack?
 
Old 11-04-2002, 04:07 PM   #7
pilot1
Member
 
Registered: Jun 2002
Location: USA
Distribution: Gentoo, Fedora Core
Posts: 408

Original Poster
Rep: Reputation: 30
Well, my AMAZING skills helped... just kidding.
Some jerk on IRC admitted to it, it seems he was mad because I z:lined him when he wouldn't stop the porn scripts.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Being possibly dosd unixpirate Linux - Security 7 11-07-2002 01:39 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 04:26 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration