detecting a DDOS attack

From: Bill Tangren (bjt_at_aa.usno.navy.mil)
Date: 10/31/03

  • Next message: Alexey Fadyushin: "Re: cron job for webalizer"
    To: redhat-list@redhat.com
    Date: Fri, 31 Oct 2003 09:38:35 -0500
    
    

    Hello all,

    Our network had been VERY slow in the last two weeks. We have a T3 line,
    but sftp transfer rates are down around 10kB/sec now. I suspect some
    type of attack on our firewalls, though I've never heard of an attack
    being sustained for so long.

    Could someone tell me what to look for? My logs ( I run several servers
    behind the firewall, but I don't administer the firewall itself) don't
    show anything unusual that I can find. I have been examining web server
    logs, and mail logs, and I scrutinize the output from LogWatch.

    Where else should I look?

    TIA,

    Bill Tangren

    -- 
    redhat-list mailing list
    unsubscribe mailto:redhat-list-request@redhat.com?subject=unsubscribe
    https://www.redhat.com/mailman/listinfo/redhat-list
    

  • Next message: Alexey Fadyushin: "Re: cron job for webalizer"

    Relevant Pages

    • Re: Strange WAN Activity
      ... > firewall logs for a possible TCP FIN scan that keeps ... > company's intranet server IP and its port 80 across our ... > My firewall is a Sonicwall Pro 200 and I'm running W2K ... It's difficult to be sure without inspecting the web server for signs of ...
      (microsoft.public.win2000.security)
    • RE: Need help to choose a security policy
      ... Firewall: ... < architecture (for example, you might have only one type of web server, ... pay attention to this attack. ... < Last but no least, if your IDS allows you to create custom rules, ...
      (Focus-IDS)
    • Re: Personal Firewall Recommendations
      ... I had a little problem with my Web server that Hackers used to attack ... Then I decided to install a firewall and Intrusion detection ...
      (Security-Basics)
    • RE: Need help to choose a security policy
      ... Firewall: ... They are normally some robust devices. ... It's a evidence for me that I shouldn't pay attention to this attack. ... < your corporate web server start ftp connections to workstations in your ...
      (Focus-IDS)
    • Re: hundreds of DoS attacks?
      ... > We haven't actually had any problems with our web server, ... > a real attack, the firewall is indeed stopping it. ... I often see SYN packets logged in my PIX logs for ...
      (comp.security.firewalls)