Follow us on Twitter!
Follow us on Facebook!
 

Go Back   Pixtus - Photography Forum, Photographers, Photo Tips > General Information > Open Talk


DoS attacks on the rise?

This is a discussion on DoS attacks on the rise? within the Open Talk forums, part of the General Information category; Over the last week or so, my router has seen far too many DoS (Denial of Service) attacks and port ...

Reply
 
LinkBack Thread Tools Display Modes
  (#1) Old
Light Moderator
 
srwatters's Avatar
 
Posts: 11,926
Join Date: Jan 2005
Location: West Plano, Texas
Real First Name: Scott
Camera: Nikon D3 & Hasselblad H2
Can Others Edit My Photos: No
iTrader Rating: 16

Likes Received LIKES Received: 44
Likes Given LIKES Given: 10
DoS attacks on the rise? - 03-25-2007, 11:43 AM


Over the last week or so, my router has seen far too many DoS (Denial of Service) attacks and port scans. Last night it was so bad that I was getting only 60% of my packets to the next hop over the FIOS, basically unusable. I ended up releasing my PPoE connection and rebooted the router after leaving it off for 5 minutes. I've turned on the DoS log and have only seen two attacks since last night (both simple port scans). This all started after last weekend when I let a visitor connect to my wireless network with their Dell notebook (Windows). I wonder if they had some bot running that tagged my IP address?

Anyone else having this much trouble?

---------------------------
Scott Watters
PoloDigital | Flickr | Pbase
Nikon | Hasselblad | Phase One | Hensel | Apple
Reply With Quote
Sponsored Links

Premium Members do not see Google advertisements. SIGN UP today and help support our community.
  (#2) Old
Camouflaged Moderator
 
Daniel Bates's Avatar
 
Posts: 11,351
Join Date: May 2006
Location: Daegu, Korea
Real First Name: Daniel
Camera: Canon
Can Others Edit My Photos: Yes
iTrader Rating: 9

Likes Received LIKES Received: 31
Likes Given LIKES Given: 35
03-25-2007, 12:29 PM


I'm not sure what's causing it but my Internet has been extraordinarily slow over the last few days (rumours are a packet server went down).

---------------------------
Forum Rules Here | How To: Report rule violations
Reply With Quote
  (#3) Old
Master of the Obvious
 
engstrom's Avatar
 
Posts: 4,596
Join Date: Aug 2005
Location: Plano, TX, Texas
Real First Name: John
Camera: Canon
Can Others Edit My Photos: Yes
iTrader Rating: 1

Likes Received LIKES Received: 1
Likes Given LIKES Given: 0
03-25-2007, 12:53 PM


Scott, I also have FIOS but have not seen even a port scan for the last couple days which is kind of weird. Anyway, you might be onto something with your guest having a bot that tagged your IP.

---------------------------
John Engstrom
Plano, TX

http://www.pbase.com/engstrom

Reply With Quote
  (#4) Old
Master of the Obvious
 
engstrom's Avatar
 
Posts: 4,596
Join Date: Aug 2005
Location: Plano, TX, Texas
Real First Name: John
Camera: Canon
Can Others Edit My Photos: Yes
iTrader Rating: 1

Likes Received LIKES Received: 1
Likes Given LIKES Given: 0
03-25-2007, 01:05 PM


Oh, and as a public service announcement to anyone out there - be sure and test your network with an online safe port scan and make sure that your ports are secure. There's one at http://www.hackerwatch.org/probe/ that I haven't had any problems with but as always YMMV.

---------------------------
John Engstrom
Plano, TX

http://www.pbase.com/engstrom

Reply With Quote
  (#5) Old
Forum Regular
 
mobilezen's Avatar
 
Posts: 691
Join Date: Dec 2006
Location: Dallas,
Real First Name: Alex
Camera: Canon 40D
Can Others Edit My Photos: No
iTrader Rating: 0

Likes Received LIKES Received: 0
Likes Given LIKES Given: 0
Send a message via AIM to mobilezen Send a message via MSN to mobilezen Send a message via Yahoo to mobilezen
03-26-2007, 01:29 AM


DoS attacks are so old school but then again when I see someone trying to tap my router or even my computer(s), I attack back. :)
Reply With Quote
  (#6) Old
Supa Dupa Poster
 
Murph's Avatar
 
Posts: 4,351
Join Date: Apr 2005
Location: San Antonio, Texas
Real First Name: Murph
Camera: Nikon and Yashica TLR
Can Others Edit My Photos: Yes
iTrader Rating: 3

Likes Received LIKES Received: 23
Likes Given LIKES Given: 3
03-26-2007, 07:08 AM


Try this site, I swear by Steve Gibson: https://www.grc.com/x/ne.dll?bh0bkyd2

---------------------------
Texas can exist without the United States, but the United States, cannot, except at great peril, exist without Texas. Sam Houston.
Reply With Quote
  (#7) Old
Forum Master
 
rages4calm's Avatar
 
Posts: 1,007
Join Date: Mar 2005
Location: Vienna, Virginia
Real First Name: Carl
Camera: Canon
Can Others Edit My Photos: Yes
iTrader Rating: 1

Likes Received LIKES Received: 0
Likes Given LIKES Given: 0
Send a message via ICQ to rages4calm Send a message via AIM to rages4calm Send a message via MSN to rages4calm Send a message via Yahoo to rages4calm Send a message via Skype™ to rages4calm
03-27-2007, 12:54 PM


Yea, DDoS attacks all over the US here lately not just routers and war driving but alot of websites as well.

It's actually quite funny in a way.. DDoS was suppose to be the past and taken care of back when they started knocking software such as telnet off the market. Hackers however always find a way around things.

In answer to your attacks you should probably try Masking your ip address or mac address and changing your encryption on your router from WEP to WPA or if you don't have one at all then WEP will still do just as good.


Quote:
Originally Posted by mobilezen
DoS attacks are so old school but then again when I see someone trying to tap my router or even my computer(s), I attack back. :)

I second that lol

---------------------------
http://www.carl-prewitt.com
Reply With Quote
  (#8) Old
You Can't Be Serious!!
 
AndrewCCM's Avatar
 
Posts: 9,327
Join Date: May 2006
Location: Dallas/Fort Worth, Texas
Real First Name: Andrew
Camera: 1D3, 7D, 5D2, LX3
Can Others Edit My Photos: No
iTrader Rating: 8

Likes Received LIKES Received: 0
Likes Given LIKES Given: 0
03-27-2007, 03:01 PM


Quote:
Originally Posted by mobilezen
DoS attacks are so old school but then again when I see someone trying to tap my router or even my computer(s), I attack back. :)
One thing to consider... Many of the attacks are initiated by systems that are not the source (ie, compromised systems that the user doesn't know about). I realize you probably already know this... but attacking back sometimes just exacerbates the issue. But fun I agree... Another useful resource that I use daily in my "real job" - http://isc.sans.org/

I only wish I could get FIOS here. I know there was a time a few years ago where we were doing some penetration testing on our office machines from our home machines and was actually contacted with a threat to disconnect our service from our home ISP. Hehe. We now use Qualys for all of our scheduled penetration testing. Very nice tool. But expensive.

---------------------------
Andrew
Website: Crystal Clear Media
Blog: CCM BLOG
Reply With Quote
  (#9) Old
Forum Master
 
rages4calm's Avatar
 
Posts: 1,007
Join Date: Mar 2005
Location: Vienna, Virginia
Real First Name: Carl
Camera: Canon
Can Others Edit My Photos: Yes
iTrader Rating: 1

Likes Received LIKES Received: 0
Likes Given LIKES Given: 0
Send a message via ICQ to rages4calm Send a message via AIM to rages4calm Send a message via MSN to rages4calm Send a message via Yahoo to rages4calm Send a message via Skype™ to rages4calm
03-27-2007, 04:35 PM


I personally enjoy being attacked rather its a hacker or a cracker or someone just trying to phish out info, because when they are done trying to do whatever, it gives me the right and opportunity to do to them as they tried to do to me.

---------------------------
http://www.carl-prewitt.com
Reply With Quote
  (#10) Old
You Can't Be Serious!!
 
AndrewCCM's Avatar
 
Posts: 9,327
Join Date: May 2006
Location: Dallas/Fort Worth, Texas
Real First Name: Andrew
Camera: 1D3, 7D, 5D2, LX3
Can Others Edit My Photos: No
iTrader Rating: 8

Likes Received LIKES Received: 0
Likes Given LIKES Given: 0
03-27-2007, 09:17 PM


Quote:
Originally Posted by rages4calm
I personally enjoy being attacked rather its a hacker or a cracker or someone just trying to phish out info, because when they are done trying to do whatever, it gives me the right and opportunity to do to them as they tried to do to me.
Legally, it doesn't. But.. I know what you mean...

My day job is a Manager of Information Security/Infrastructure. It's amazing how much crap is going on these days... Funny though.. I spend more time these days dealing with compliance with government regulations than anything.

---------------------------
Andrew
Website: Crystal Clear Media
Blog: CCM BLOG
Reply With Quote
  (#11) Old
Senior Member
 
Tapper's Avatar
 
Posts: 269
Join Date: Dec 2006
Location: Allen,
Real First Name: Brian
Camera: D200
Can Others Edit My Photos: No
iTrader Rating: 2

Likes Received LIKES Received: 0
Likes Given LIKES Given: 0
Send a message via ICQ to Tapper Send a message via AIM to Tapper Send a message via Yahoo to Tapper
03-27-2007, 09:41 PM


In my "real job" I'm a network engineer, and operate a large metropolitan area network, numerous routers, and a ton of switches. I have various measure in place to monitor activity on these nets, including IDS sensors, TAPs, distributed sniffers, etc etc.

Y'all should keep a few things in mind here.

First, real DoS attacks are pretty rare these days, at least in terms of home computers. More often, computers become infested with a worm, and the source of any packet storms are local to you. Real DoS attacks do happen, but these days they tend to be directed at businesses as a means of extortion - i.e. we'll stop holding down your link if you pay us money. The typical agent in these attacks, are botnets composed of hundreds or thousands of home computers infected with worms, and running some variant of a Trinoo agent.

98% of the crap you see spewed at your connection, comes from other computers infested with a worm and trying to assimilate you into a botnet. The process of scanning IP ranges for a vulnerability is nearly always wholly automated, and originating from your Grandmas computer - or someone similar who lacks the requisite computer knowledge to perform simple windows updates, run a virus scanner, or even a firewall of some sort.

Responding (attacking back) to these probes or exploit attempts accomplishes two things.

1. You commit a rather serious felony. Note that word felony. If you download some stupid script kiddie utility off the net, and aim it at some poor ignorant souls compromised computer, you're liable to have someone like me track you down. If that happens, don't look for mercy. You won't get any. These days, running stuff like that is good for a trip to a nice PMITA federal pen.

2. Rather than some supar s3cr4t l33t h4x0r, you'll actually be attacking some poor fool who's only crime was being to lazy to learn how to operate their computer. And that makes you the bad guy.

It's nearly *always* a good idea to run a little Linksys or DLink router between your computers and your DSL/Cable modem. Run NAT, and turn on port blocking. That will prevent nearly 100% of the random nasty stuff from reaching you. You'll still be able to accidentally download activeX controls, or java bombs from websites, but that's why you're running a virus scanner and keeping it, and windows currently updated, right?

---------------------------
At night I dreamed that life was beauty, but I awoke and life was duty. So I bought a camera.
Reply With Quote
  (#12) Old
Senior Member
 
Tapper's Avatar
 
Posts: 269
Join Date: Dec 2006
Location: Allen,
Real First Name: Brian
Camera: D200
Can Others Edit My Photos: No
iTrader Rating: 2

Likes Received LIKES Received: 0
Likes Given LIKES Given: 0
Send a message via ICQ to Tapper Send a message via AIM to Tapper Send a message via Yahoo to Tapper
03-27-2007, 09:51 PM


Quote:
Originally Posted by AndrewCCM
Funny though.. I spend more time these days dealing with compliance with government regulations than anything.
I don't get so much of that yet in my sector, but SOx 404, the new rules of Civil Procedure, and all these new proposed data retention initiatives are really busting my stones. That, and the recently rise in popularity with LEOs - suddenly I have new buddies

---------------------------
At night I dreamed that life was beauty, but I awoke and life was duty. So I bought a camera.
Reply With Quote
  (#13) Old
Light Moderator
 
srwatters's Avatar
 
Posts: 11,926
Join Date: Jan 2005
Location: West Plano, Texas
Real First Name: Scott
Camera: Nikon D3 & Hasselblad H2
Can Others Edit My Photos: No
iTrader Rating: 16

Likes Received LIKES Received: 44
Likes Given LIKES Given: 10
03-27-2007, 10:07 PM


I do have a wireless router with NAT turned on. It was that public IP that was being stormed. I watched the packets bombarding the interface and until I released my public IP and waited long enough to get a different one, it would continue. My guess was most likely correct in that the guest was infected and passed my public IP on to more of the botnet.

With a new public IP on my router, I'm a happy camper (for now).

---------------------------
Scott Watters
PoloDigital | Flickr | Pbase
Nikon | Hasselblad | Phase One | Hensel | Apple
Reply With Quote
  (#14) Old
You Can't Be Serious!!
 
AndrewCCM's Avatar
 
Posts: 9,327
Join Date: May 2006
Location: Dallas/Fort Worth, Texas
Real First Name: Andrew
Camera: 1D3, 7D, 5D2, LX3
Can Others Edit My Photos: No
iTrader Rating: 8

Likes Received LIKES Received: 0
Likes Given LIKES Given: 0
03-27-2007, 10:09 PM


Quote:
Originally Posted by Tapper
I don't get so much of that yet in my sector, but SOx 404, the new rules of Civil Procedure, and all these new proposed data retention initiatives are really busting my stones. That, and the recently rise in popularity with LEOs - suddenly I have new buddies
Yep.. Gotta love it.. My new one is the dang changes in PCI compliance.. The Payment Card Industry is harder than the dang government with their infrastructure rules in 2007.

Blah.. Keeps me employed though.

Good message above btw...

---------------------------
Andrew
Website: Crystal Clear Media
Blog: CCM BLOG
Reply With Quote
  (#15) Old
Senior Member
 
Tapper's Avatar
 
Posts: 269
Join Date: Dec 2006
Location: Allen,
Real First Name: Brian
Camera: D200
Can Others Edit My Photos: No
iTrader Rating: 2

Likes Received LIKES Received: 0
Likes Given LIKES Given: 0
Send a message via ICQ to Tapper Send a message via AIM to Tapper Send a message via Yahoo to Tapper
03-27-2007, 10:23 PM


Quote:
Originally Posted by AndrewCCM
Yep.. Gotta love it.. My new one is the dang changes in PCI compliance.. The Payment Card Industry is harder than the dang government with their infrastructure rules in 2007.
Changes? We did all the testing and so forth in 06 - did they change it?

---------------------------
At night I dreamed that life was beauty, but I awoke and life was duty. So I bought a camera.
Reply With Quote
Reply

Tags
attacks, dos, rise

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



Visit Our Sponsors
 

Google Sponsors

Premium Members do not see Google advertisements. SIGN UP today and help support our community.

Copyright ©2004 - 2011, Abel Longoria - www.Pixtus.com
Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2012, vBulletin Solutions, Inc.