|
-
November 12th, 2002, 03:04 PM
#1
-
November 12th, 2002, 03:16 PM
#2
It could possibly be DRDoS.Usually,a DRDoS won't send a huge flood of packets your way,because the point of it is to flood the target with a large number of legit computers to make the attack almost totally unable to be traced.Do a whois on the IP.Then give the person a call,because if it is DRDoS,the IP most likely won't be spoofed it will lead you to a legitamate user.Ask them to check their firewall to see if they're having a similar problem.This method of attack can involve a huge amount of computers,and the only way to really trace it is for all of the victims to get together and figure out whos IP is whos and then you can find the IP of the attacker(which in all likelyhood is going to be spoofed),and you will have to figure out where the proxy server(s) are,and get the true IP.
Or it could just be noise.It happens from time to time,and there's no real way to totally get rid of it,but just to be sure I'd investigate if I were you.
[shadow] I don\'t believe in anarchy.If you\'re not smart enough to beat the system it\'s your problem. [/shadow]
-
November 12th, 2002, 03:35 PM
#3
gghornet: In a DRDos a SYN or similar packet is sent to the "middle man" with the address of the actual victim spoofed as the source. The ensuing reply, (SYN/ACK or whatever), is then sent to the victim's IP as delineated by the spoofed source. Thus it can't be DRDos.... The target is not legitimate - the packets are being dropped but the internet routers, (and by my firewall for that matter). The target would have to be a legitimate, routable IP address somewhere out there - these purport to come from private, non-routable address blocks. If some moron is trying to DRDos one of his internal addresses by using me et al he needs to read a good TCP/IP primer...... 
PS: Love your tagline.......
Don\'t SYN us.... We\'ll SYN you.....
\"A nation that draws too broad a difference between its scholars and its warriors will have its thinking done by cowards, and its fighting done by fools.\" - Thucydides
-
November 12th, 2002, 03:55 PM
#4
LOL.Good point.Well,I don't have a freakin clue then.I'm not the most security saavy out of the bunch by any means.All I can do is try.
[shadow] I don\'t believe in anarchy.If you\'re not smart enough to beat the system it\'s your problem. [/shadow]
-
November 12th, 2002, 04:05 PM
#5
No prob.... You were bang on for the type of packet I would be seeing - just that routing issue got in the way....
As an aside - I have also considered that it might be someone testing a scanner/tool they are writing for themselves and could care less which address they hit. But this has been going on way too long for someone to just be playing with the interface and bashing away at me as their "test" address. By now I would have expected them to have moved on to more sophisticated testing and would want some response from their new toy - something they won't be getting with these IP addresses.
Don\'t SYN us.... We\'ll SYN you.....
\"A nation that draws too broad a difference between its scholars and its warriors will have its thinking done by cowards, and its fighting done by fools.\" - Thucydides
-
November 12th, 2002, 05:15 PM
#6
It is possible some type of firewall test scan. Used espeically if you have your firewall set to email an account when it has to reject packets of some type. heres the idea....
your firewall emails an external account... say [email protected]... every time it has to reject packets (or you have an ids that does this behind the firewall every time it gets certain sequences).
Ok, so attacker dood gets access to the [email protected] account. Now when he sends packets to your firewall, he can see if they get rejected by checking [email protected]. If there is no message, he has found a way to bypass your firewall/ids. And the bad thing is, you never know where he came from because it was always 10. number that attacked you. And he now knows how to get into your system without triggering any alarms, so he can use a normal IP.
I'm not saying this is what is happening, but it is a possibility.
\"Ignorance is bliss....
but only for your enemy\"
-- souleman
-
November 12th, 2002, 05:33 PM
#7
Souleman: Good thinking - I like the way your mind works.....
Unfortunately, my firewall emails no-one and my IDS systems email me in circumstances that do not fit this pattern.
While that was a great possibility it doesn't fit my situation - but I am about to start thinking about some other things that I might not have thought of which kinda scares me 'cos if this is genuine activity it means that this isn't a simple skiddy and that means I have the attention of someone I probably don't want the attention of.....
Don\'t SYN us.... We\'ll SYN you.....
\"A nation that draws too broad a difference between its scholars and its warriors will have its thinking done by cowards, and its fighting done by fools.\" - Thucydides
-
November 12th, 2002, 05:55 PM
#8
Junior Member
Its Probly Just someone nosing around.. to see what your system is all about.. problably looking for holes.. as long as your firewall is catching most of it, just keep on your toes, and as mentioned, do some backround info checking, and give the guy a call, that usually freaks them out enough to stop it....
-
November 12th, 2002, 06:06 PM
#9
Not meaning to be rude or sarcastic..... But I can't resist.... It's my nature....
Which one of the thousands of 10.1.1.1 addresses there are in the world do you suggest I call.... Then of course there's the 192.168.X.X and the 172.X.X.X addresses too....
These events are from _private_ subnets, they point to no-one that's why I am so confused about their high incidence - I can understand a few from misconfigured machines but this activity is pretty constant - day in, day out, 24 hours a day at random times and for random durations - or at least I can't see a pattern.
I wouldn't care if it was a traceable address - there could be any number of reasons for the activity - what's peeking my curiosity is the origin of so much traffic that patently will go nowhere and do no-one any good - as far as I can see......
Don\'t SYN us.... We\'ll SYN you.....
\"A nation that draws too broad a difference between its scholars and its warriors will have its thinking done by cowards, and its fighting done by fools.\" - Thucydides
-
November 12th, 2002, 06:12 PM
#10
Junior Member
Sorry I guess I am not as Godly Proficient as yourself... Have Fun
Posting Permissions
- You may not post new threads
- You may not post replies
- You may not post attachments
- You may not edit your posts
-
Forum Rules
|
|