Follow us on Twitter!
Follow us on Facebook!
 

Go Back   Pixtus - Photography Forum, Photographers, Photo Tips > General Information > Open Talk


DoS attacks on the rise?

This is a discussion on DoS attacks on the rise? within the Open Talk forums, part of the General Information category; Originally Posted by Tapper Changes? We did all the testing and so forth in 06 - did they change it? ...

Reply
 
LinkBack Thread Tools Display Modes
  (#16) Old
You Can't Be Serious!!
 
AndrewCCM's Avatar
 
Posts: 9,327
Join Date: May 2006
Location: Dallas/Fort Worth, Texas
Real First Name: Andrew
Camera: 1D3, 7D, 5D2, LX3
Can Others Edit My Photos: No
iTrader Rating: 8

Likes Received LIKES Received: 0
Likes Given LIKES Given: 0
03-27-2007, 09:28 PM


Quote:
Originally Posted by Tapper
Changes? We did all the testing and so forth in 06 - did they change it?
Yep.. much more stringent requirements based on how much web/e-commerce CC processing you do. Everything from 3rd party penetration certification to firewall rulebase review.. Speaking of UGH.. I have to go in to the office right now to collect evidence in a potential internal CC fraud investigation. Gonna try and do it via VPN first.. but I have this sneaky suspicion that I will be leaving in a few..

---------------------------
Andrew
Website: Crystal Clear Media
Blog: CCM BLOG
Reply With Quote
Sponsored Links

Premium Members do not see Google advertisements. SIGN UP today and help support our community.
  (#17) Old
You Can't Be Serious!!
 
AndrewCCM's Avatar
 
Posts: 9,327
Join Date: May 2006
Location: Dallas/Fort Worth, Texas
Real First Name: Andrew
Camera: 1D3, 7D, 5D2, LX3
Can Others Edit My Photos: No
iTrader Rating: 8

Likes Received LIKES Received: 0
Likes Given LIKES Given: 0
03-27-2007, 09:31 PM


BTW:

https://www.pcisecuritystandards.org...i_dss_v1-1.pdf

I "think" this is the newest revision due in 2007. It did come out in 2006 though.

Here is a bit more on the changes. I haven't started working on it "yet".. But it's coming.

http://www.computerworld.com/action/...icleId=9003229

---------------------------
Andrew
Website: Crystal Clear Media
Blog: CCM BLOG
Reply With Quote
  (#18) Old
Luminous Cat Herder
 
Ahh!'s Avatar
 
Posts: 4,857
Join Date: Jan 2007
Location: Frisco, Texas
Real First Name: Peter
Camera: Nikon
Can Others Edit My Photos: Yes
iTrader Rating: 2

Likes Received LIKES Received: 29
Likes Given LIKES Given: 23
I keep burning up routers - 03-27-2007, 09:35 PM


So, when my network a few weeks ago started slowing to a crawl I replaced my netgear with a belkin (a handy thing to spare). Problem over. 5 minutes. But i haven't had the time to diagnose the netgear to figure out if it was the culprit or a DoS local storm. But I, too, had heard of recent localized storms in residential dsl-land.

I keep that spare for traveling when they have no wireless and I have 2 or more laptops in my team. Cuts down on the telecom bill at the hotel...and allows us to stuff 35 people in a conference room equiped with the usual 1 or 2 ports during the day.

---------------------------
Putting the Ahh! in Photography.
A 35 to my eye and a 45 by my side.
What say you?
Reply With Quote
  (#19) Old
Senior Member
 
Tapper's Avatar
 
Posts: 269
Join Date: Dec 2006
Location: Allen,
Real First Name: Brian
Camera: D200
Can Others Edit My Photos: No
iTrader Rating: 2

Likes Received LIKES Received: 0
Likes Given LIKES Given: 0
Send a message via ICQ to Tapper Send a message via AIM to Tapper Send a message via Yahoo to Tapper
03-27-2007, 09:38 PM


Quote:
Originally Posted by AndrewCCM
Yep.. much more stringent requirements based on how much web/e-commerce CC processing you do. Everything from 3rd party penetration certification to firewall rulebase review.. Speaking of UGH.. I have to go in to the office right now to collect evidence in a potential internal CC fraud investigation. Gonna try and do it via VPN first.. but I have this sneaky suspicion that I will be leaving in a few..
We switched up our stuff, and mainly do CC stuff on an offsite server now, which reduces the nosiness :)

Feel ya on the Vpn thing. Been there, so many times...

---------------------------
At night I dreamed that life was beauty, but I awoke and life was duty. So I bought a camera.
Reply With Quote
  (#20) Old
Supa Dupa Poster
 
engstrom's Avatar
 
Posts: 4,596
Join Date: Aug 2005
Location: Plano, TX, Texas
Real First Name: John
Camera: Canon
Can Others Edit My Photos: Yes
iTrader Rating: 1

Likes Received LIKES Received: 1
Likes Given LIKES Given: 0
03-27-2007, 10:43 PM


Quote:
Originally Posted by rages4calm
In answer to your attacks you should probably try Masking your ip address or mac address and changing your encryption on your router from WEP to WPA or if you don't have one at all then WEP will still do just as good.
I couldn't disagree more about using WEP. It may actually do more harm than good by providing a false sense of security. A hacker with an easily available tool and 10 minutes can crack WEP - it will be slightly longer for larger WEP keys but still very doable. WPA is the only way to go - and even then you should realize a determined hacker can probably get in - it will just take a while.

http://www.youtube.com/watch?v=6y4k2EM0zr4

---------------------------
John Engstrom
Plano, TX

http://www.pbase.com/engstrom

Reply With Quote
  (#21) Old
Uber Poster
 
Jeff_Green's Avatar
 
Posts: 3,325
Join Date: Feb 2006
Location: Mansfield, Texas
Real First Name: Jeff
Camera: Nikon D300/D70
Can Others Edit My Photos: Yes
iTrader Rating: 4

Likes Received LIKES Received: 50
Likes Given LIKES Given: 31
03-27-2007, 11:12 PM


NERDS!!!

---------------------------
"If you find a job you love, you'll never have to work a day in your life."
Reply With Quote
  (#22) Old
Light Moderator
 
srwatters's Avatar
 
Posts: 11,942
Join Date: Jan 2005
Location: West Plano, Texas
Real First Name: Scott
Camera: Nikon D3 & Hasselblad H2
Can Others Edit My Photos: No
iTrader Rating: 16

Likes Received LIKES Received: 47
Likes Given LIKES Given: 10
03-27-2007, 11:15 PM


WPA2 with a long key string.

---------------------------
Scott Watters
PoloDigital | Flickr | Pbase
Nikon | Hasselblad | Phase One | Hensel | Apple
Reply With Quote
  (#23) Old
Forum Master
 
rages4calm's Avatar
 
Posts: 1,007
Join Date: Mar 2005
Location: Vienna, Virginia
Real First Name: Carl
Camera: Canon
Can Others Edit My Photos: Yes
iTrader Rating: 1

Likes Received LIKES Received: 0
Likes Given LIKES Given: 0
Send a message via ICQ to rages4calm Send a message via AIM to rages4calm Send a message via MSN to rages4calm Send a message via Yahoo to rages4calm Send a message via Skype™ to rages4calm
03-28-2007, 08:32 AM


Quote:
Originally Posted by engstrom
I couldn't disagree more about using WEP. It may actually do more harm than good by providing a false sense of security. A hacker with an easily available tool and 10 minutes can crack WEP - it will be slightly longer for larger WEP keys but still very doable. WPA is the only way to go - and even then you should realize a determined hacker can probably get in - it will just take a while.

http://www.youtube.com/watch?v=6y4k2EM0zr4

Yep, way to easy to get around these days and I know there is a great number of war drivers around here with there little net stumblers, cain and abel etc..

Quote:
Originally Posted by Tapper
Responding (attacking back) to these probes or exploit attempts accomplishes two things.

1. You commit a rather serious felony. Note that word felony. If you download some stupid script kiddie utility off the net, and aim it at some poor ignorant souls compromised computer, you're liable to have someone like me track you down. If that happens, don't look for mercy. You won't get any. These days, running stuff like that is good for a trip to a nice PMITA federal pen.

2. Rather than some supar s3cr4t l33t h4x0r, you'll actually be attacking some poor fool who's only crime was being to lazy to learn how to operate their computer. And that makes you the bad guy.
That is true for the most part, but I also learned throughout alot of the seminars my job has sent me to, that as long as you have little messages on your server that are clearly seen when someone makes an attempt to jump in with there attack that states upon failure to make there attack they are agreeing to whatever is on that document.

Now that isn't exactly legal but it does help, and I would not exactly nor do I know anyone who would make an attack back that would be considered a felony. Technically speaking most hacking is considered legal as long as they are just exploring, (except when it comes to government and education)

I agree though and I still find it fun either way if anything its a learning experience.
BTW ya'll run spyder servers?

---------------------------
http://www.carl-prewitt.com
Reply With Quote
  (#24) Old
Senior Member
 
Tapper's Avatar
 
Posts: 269
Join Date: Dec 2006
Location: Allen,
Real First Name: Brian
Camera: D200
Can Others Edit My Photos: No
iTrader Rating: 2

Likes Received LIKES Received: 0
Likes Given LIKES Given: 0
Send a message via ICQ to Tapper Send a message via AIM to Tapper Send a message via Yahoo to Tapper
03-28-2007, 09:56 AM


Quote:
Originally Posted by rages4calm
That is true for the most part, but I also learned throughout alot of the seminars my job has sent me to, that as long as you have little messages on your server that are clearly seen when someone makes an attempt to jump in with there attack that states upon failure to make there attack they are agreeing to whatever is on that document.

Now that isn't exactly legal but it does help, and I would not exactly nor do I know anyone who would make an attack back that would be considered a felony. Technically speaking most hacking is considered legal as long as they are just exploring, (except when it comes to government and education)

I agree though and I still find it fun either way if anything its a learning experience.
BTW ya'll run spyder servers?
Not exactly sure what you are saying here, but if I understand correctly you're saying that posting a "If you hit me I get to hit you back" notice on a website somewhere on your machine, you are exempted from the law. I would advise you to consider some different seminars.

But summarizing - several courts have held that persons accessing (portscans are considered a form of remote access without permission) a remote network/machine are
guilty of violating several different federal statutes. And no, I don't think "well, he started it" is going to be much help if you get charged. Typically, the ISP - as the owner of the link you traversed - is going to be the party that the State listens to. And they didn't agree to anything, did they?

Bottom line, it's just a really really bad time to be messing around this way on the networks. Secure your own machine, and don't be cute with other people's machines, and you'll save yourself a lot of grief.

---------------------------
At night I dreamed that life was beauty, but I awoke and life was duty. So I bought a camera.
Reply With Quote
  (#25) Old
Forum Master
 
rages4calm's Avatar
 
Posts: 1,007
Join Date: Mar 2005
Location: Vienna, Virginia
Real First Name: Carl
Camera: Canon
Can Others Edit My Photos: Yes
iTrader Rating: 1

Likes Received LIKES Received: 0
Likes Given LIKES Given: 0
Send a message via ICQ to rages4calm Send a message via AIM to rages4calm Send a message via MSN to rages4calm Send a message via Yahoo to rages4calm Send a message via Skype™ to rages4calm
03-28-2007, 10:56 AM


Quote:
Originally Posted by Tapper
Not exactly sure what you are saying here, but if I understand correctly you're saying that posting a "If you hit me I get to hit you back" notice on a website somewhere on your machine, you are exempted from the law. I would advise you to consider some different seminars.
Selective reading eh :) ? I never said it was legal. If anything its a way to scare the person who is attempting an attack. As far as the law goes, your right its divided in several areas, it may not be illegal in some states but that doesn't mean the ISP allows it.
What I stated is no different then what microsoft telnet server messages use to give, it was never legal but it gave a good scare to people.

---------------------------
http://www.carl-prewitt.com
Reply With Quote
  (#26) Old
You Can't Be Serious!!
 
AndrewCCM's Avatar
 
Posts: 9,327
Join Date: May 2006
Location: Dallas/Fort Worth, Texas
Real First Name: Andrew
Camera: 1D3, 7D, 5D2, LX3
Can Others Edit My Photos: No
iTrader Rating: 8

Likes Received LIKES Received: 0
Likes Given LIKES Given: 0
03-28-2007, 02:34 PM


Quote:
Originally Posted by Jeff_Green
NERDS!!!
Hey! I resemble that remark!

---------------------------
Andrew
Website: Crystal Clear Media
Blog: CCM BLOG
Reply With Quote
  (#27) Old
Uber Poster
 
babybluetx23's Avatar
 
Posts: 3,091
Join Date: Dec 2005
Location: Arlington, Texas
Real First Name: Cynthia
Camera: Canon 5D
Can Others Edit My Photos: Yes
iTrader Rating: 0

Likes Received LIKES Received: 0
Likes Given LIKES Given: 0
03-28-2007, 02:47 PM


Hey Scott when I WAS working for verizon we would see that ALOT!!! we would see it on a Daily basis at LEAST three times a day! I dont know where they are coming from or why? I havent seen anything like that at my house, but I dont live in FIOS territory =( We have comcast....roadrunner...time warner....whatever they are calling themselves now a days.

---------------------------
Cynthia Cox
Arlington, Tx
http://www.innovativeillusionsphoto.com/
OMP member #: 173034

Canon EOS 5D : Bogen 3051 tripod : Bogen Monopod : Bogen 3030 head unit : Canon Speedlight 580EX : Canon EF 28-200 F3.5 : Canon 70-200 f2.8L : Canon 24-70mm F2.8L and other Canon Gear

The camera doesn't make a bit of difference. All of them can record what you are seeing. But, you have to SEE." - Ernst Haas
Reply With Quote
Reply

Tags
attacks, dos, rise

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



Visit Our Sponsors
 

Google Sponsors

Premium Members do not see Google advertisements. SIGN UP today and help support our community.

Copyright ©2004 - 2011, Abel Longoria - www.Pixtus.com
Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2012, vBulletin Solutions, Inc.