LinuxQuestions.org
Help answer threads with 0 replies.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 02-09-2006, 09:52 AM   #1
chereth
LQ Newbie
 
Registered: Feb 2006
Posts: 1

Rep: Reputation: 0
Post Linux DOS Attack Possibility


Greetings!

I'm running a RedHat DNS server and believe I've been attacked! When it's plugged in, my network segment utilization jumps to almost 100% and I get tons of protocols that aren't running on the server appearing on the segment (There are protocols that I dind't even know about: CALLBOOK? CSP2? CSP3? ICHAT? TIMBUCKTU? SYBASE-SQLANYWHERE?). Also I can attribute over 50% of this crap to 1 IP address out of China. I'm not a Linux person and I inherited this problem. Can someone help figure out what's going on? I'm thinking that I could drop that IP in an ACL somehow, but I suspect there's some nasty program running on the server or it's being used as some sort of relay...

Thanks
chereth@tcsweb.com
 
Old 02-09-2006, 10:42 AM   #2
XavierP
Moderator
 
Registered: Nov 2002
Location: Kent, England
Distribution: Debian Testing
Posts: 19,192
Blog Entries: 4

Rep: Reputation: 476Reputation: 476Reputation: 476Reputation: 476Reputation: 476
Moved: This thread is more suitable in Linux-Security and has been moved accordingly to help your thread/question get the exposure it deserves.
 
Old 02-09-2006, 12:26 PM   #3
unSpawn
Moderator
 
Registered: May 2001
Posts: 29,417
Blog Entries: 55

Rep: Reputation: 3617Reputation: 3617Reputation: 3617Reputation: 3617Reputation: 3617Reputation: 3617Reputation: 3617Reputation: 3617Reputation: 3617Reputation: 3617Reputation: 3617
I'm not a Linux person and I inherited this problem.
Do you want to become a Linux admin? Are there any Linux admins in the company? Does "inherited" convey you don't feel like you're the problem owner? If so, and if there are no Linux admins around, wouldn't bringing in a temporary Linux admin be a more professional solution?


I'm running a RedHat DNS server
Which release? Was it regularly updated? Was it hardened?
Is it a master or a slave? Does it run other services besides DNS?


and believe I've been attacked!
Log excerpts please.


Also I can attribute over 50% of this crap to 1 IP address out of China.
Then block the IP and check adjacent boxen for same IP/range traffic.


I suspect there's some nasty program running on the server or it's being used as some sort of relay...
What gives you that idea? Can you verify there are no unwanted accounts on the box?
Have you checked the logs? Can you verify the state of the system against RPM's from install CDR's or mirror?
Did you run Chkrootkit or Rkhunter on the box?


*If you want to post logs that are too big, post a D/L location instead.
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
detecting a DOS attack ignus Linux - Security 4 07-29-2004 02:17 PM
Preventing local users from "text flooding" a terminal (DoS attack)... khermans Linux - Security 2 09-24-2003 07:56 AM
cups error log: possible DoS attack busbarn Linux - Security 1 04-30-2003 11:30 AM
Are we under DOS attack? sarmadys Linux - Security 2 02-06-2002 09:41 PM
How to safe from "DOS" Attack johnlee Linux - Security 1 01-06-2002 05:19 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 01:14 PM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration