grpprod |
05-02-2007 05:57 PM |
Network Attack seems to ignore my iptables rules
Hi all,
one of my mail servers is currently under attack. I have set up a pretty decent iptables set (syn floods etc), but it seems that it cannot handle this particular one (although it looks like a SYN flood to me). In particular, as shown in the log, it manages to 'catch' it but for some reason it is unresponsive to its services (POP,IMAP,SMTP). I was wondering if someone could help me to deal with this situation. I hope I should be able to do something more than wait for it to finish.
Code:
May 3 01:46:00 srv kernel: Dropped by default:IN=eth0 OUT= MAC=00:0c:29:f4:ad:a0:00:0b:be:4d:e8:00:08:00 SRC=213.180.210.35 DST=1.2.3.4 LEN=44 TOS=0x00 PREC=0x00 TTL=28 ID=64164 PROTO=TCP SPT=55774 DPT=56124 WINDOW=4096 RES=0x00 SYN URGP=0
May 3 01:46:02 srv kernel: Dropped by default:IN=eth0 OUT= MAC=00:0c:29:f4:ad:a0:00:0b:be:4d:e8:00:08:00 SRC=213.180.210.35 DST=1.2.3.4 LEN=44 TOS=0x00 PREC=0x00 TTL=25 ID=31025 PROTO=TCP SPT=55772 DPT=55118 WINDOW=2048 RES=0x00 SYN URGP=0
May 3 01:46:02 srv kernel: Dropped by default:IN=eth0 OUT= MAC=00:0c:29:f4:ad:a0:00:0b:be:4d:e8:00:08:00 SRC=213.180.210.35 DST=1.2.3.4 LEN=44 TOS=0x00 PREC=0x00 TTL=23 ID=22646 PROTO=TCP SPT=55774 DPT=25786 WINDOW=4096 RES=0x00 SYN URGP=0
May 3 01:46:03 srv kernel: Dropped by default:IN=eth0 OUT= MAC=00:0c:29:f4:ad:a0:00:0b:be:4d:e8:00:08:00 SRC=213.180.210.35 DST=1.2.3.4 LEN=44 TOS=0x00 PREC=0x00 TTL=39 ID=33630 PROTO=TCP SPT=55771 DPT=4154 WINDOW=4096 RES=0x00 SYN URGP=0
May 3 01:46:05 srv kernel: Dropped by default:IN=eth0 OUT= MAC=00:0c:29:f4:ad:a0:00:0b:be:4d:e8:00:08:00 SRC=213.180.210.35 DST=1.2.3.4 LEN=44 TOS=0x00 PREC=0x00 TTL=23 ID=13090 PROTO=TCP SPT=55771 DPT=48393 WINDOW=3072 RES=0x00 SYN URGP=0
May 3 01:46:06 srv kernel: Dropped by default:IN=eth0 OUT= MAC=00:0c:29:f4:ad:a0:00:0b:be:4d:e8:00:08:00 SRC=213.180.210.35 DST=1.2.3.4 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=60313 PROTO=TCP SPT=55774 DPT=17878 WINDOW=3072 RES=0x00 SYN URGP=0
May 3 01:46:08 srv kernel: Dropped by default:IN=eth0 OUT= MAC=00:0c:29:f4:ad:a0:00:0b:be:4d:e8:00:08:00 SRC=213.180.210.35 DST=1.2.3.4 LEN=44 TOS=0x00 PREC=0x00 TTL=36 ID=3242 PROTO=TCP SPT=55772 DPT=23571 WINDOW=1024 RES=0x00 SYN URGP=0
May 3 01:46:08 srv kernel: Dropped by default:IN=eth0 OUT= MAC=00:0c:29:f4:ad:a0:00:0b:be:4d:e8:00:08:00 SRC=213.180.210.35 DST=1.2.3.4 LEN=44 TOS=0x00 PREC=0x00 TTL=27 ID=23312 PROTO=TCP SPT=55774 DPT=35985 WINDOW=4096 RES=0x00 SYN URGP=0
May 3 01:46:10 srv kernel: Dropped by default:IN=eth0 OUT= MAC=00:0c:29:f4:ad:a0:00:0b:be:4d:e8:00:08:00 SRC=213.180.210.35 DST=1.2.3.4 LEN=44 TOS=0x00 PREC=0x00 TTL=26 ID=32949 PROTO=TCP SPT=55772 DPT=33707 WINDOW=3072 RES=0x00 SYN URGP=0
May 3 01:46:11 srv kernel: Dropped by default:IN=eth0 OUT= MAC=00:0c:29:f4:ad:a0:00:0b:be:4d:e8:00:08:00 SRC=213.180.210.35 DST=1.2.3.4 LEN=44 TOS=0x00 PREC=0x00 TTL=29 ID=48152 PROTO=TCP SPT=55770 DPT=1737 WINDOW=1024 RES=0x00 SYN URGP=0
May 3 01:46:11 srv kernel: Dropped by default:IN=eth0 OUT= MAC=00:0c:29:f4:ad:a0:00:0b:be:4d:e8:00:08:00 SRC=213.180.210.35 DST=1.2.3.4 LEN=44 TOS=0x00 PREC=0x00 TTL=34 ID=4883 PROTO=TCP SPT=55772 DPT=65379 WINDOW=2048 RES=0x00 SYN URGP=0
May 3 01:46:12 srv kernel: Dropped by default:IN=eth0 OUT= MAC=00:0c:29:f4:ad:a0:00:0b:be:4d:e8:00:08:00 SRC=213.180.210.35 DST=1.2.3.4 LEN=44 TOS=0x00 PREC=0x00 TTL=35 ID=29322 PROTO=TCP SPT=55774 DPT=59015 WINDOW=4096 RES=0x00 SYN URGP=0
May 3 01:46:13 srv kernel: Dropped by default:IN=eth0 OUT= MAC=00:0c:29:f4:ad:a0:00:0b:be:4d:e8:00:08:00 SRC=213.180.210.35 DST=1.2.3.4 LEN=44 TOS=0x00 PREC=0x00 TTL=32 ID=10730 PROTO=TCP SPT=55771 DPT=10950 WINDOW=4096 RES=0x00 SYN URGP=0
May 3 01:46:14 srv kernel: Dropped by default:IN=eth0 OUT= MAC=00:0c:29:f4:ad:a0:00:0b:be:4d:e8:00:08:00 SRC=213.180.210.35 DST=1.2.3.4 LEN=44 TOS=0x00 PREC=0x00 TTL=19 ID=33847 PROTO=TCP SPT=55773 DPT=7563 WINDOW=3072 RES=0x00 SYN URGP=0
|