|
|||||||||||
|
Re: DoS "Probing" on one of our hosts
From: Chris Calvert <chris(at)idaemon.ca>
Date: Mon Jun 30 2003 - 09:32:01 EDT Hi Chris Get a capture of the traffic and do some analysis. If you are being hammered with a connectionless protocol such as UDP or ICMP then there is no way for you, the destination of the traffic, to determine the source if it has been spoofed, however you might be able to get useful data from a capture regardless. Try tools such as Ethereal,for a bit of help analyzing the traffic. For example, you might be getting hit with huge packets which saturate your Internet connection and/or inbound interface, or you may be getting hit with small packets but at a packet/second rate that your switch, modem, interface, or whatever cannot handle. There may be no signatures to detect, you might simply be the target of a brute force traffic DoS. Regards, Chris
On Sun, 2003-06-29 at 14:41, Christopher Kunz wrote:
-- Chris CalvertReceived on Mon Jun 30 11:15:27 2003 This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:02:10 EDT |
||||||||||
|
|||||||||||