|
|||||||||||
|
RE: DoS "Probing" on one of our hosts
From: Cook, Christopher S. <Christopher.Cook(at)honeywell-tsi.com>
Date: Mon Jun 30 2003 - 12:12:26 EDT See if you can put a sniffer on the outbound connection (Sniffer is my commercial favorite) to find the endpoints. There are lots of reasons your IDS isn't raising alarms: the system that was hacked was already an FTP server, or if your IDS isn't monitoring common protocols from servers, or the IDS system doesn't see the traffic going to the hacked system, et al.
Chris Cook
These are my opinions, not those of Honeywell.
Harlan Carvey wrote:
Uhm, I'm quite positive that 97.8 mBit coming in through our uplink are a pretty good indicator for an attack. And by "probing" I meant that maybe the attacker only tried to determine our maximum bandwidth for a larger-scale attack, since the DoSes stopped fairly soon without any outer influence. --ck -- php development | hosting | housing | professional game server hosting http://www.de-punkt.de [ chris(at)de-punkt.de ] http://www.stormix.de +49 511 1237504 | +49 511 1237505 | laportestr. 2a, 30449 hannover.de Filoo auf dem Linuxtag 2003 (F15) - http://www.de-punkt.de/lt2003.php ---------------------------------------------------------------------------- Attend the Black Hat Briefings & Training, July 28 - 31 in Las Vegas, the world's premier technical IT security event! 10 tracks, 15 training sessions, 1,800 delegates from 30 nations including all of the top experts, from CSO's to "underground" security specialists. See for yourself what the buzz is about! Early-bird registration ends July 3. This event will sell out. www.blackhat.com ---------------------------------------------------------------------------- ---------------------------------------------------------------------------- Attend the Black Hat Briefings & Training, July 28 - 31 in Las Vegas, the world's premier technical IT security event! 10 tracks, 15 training sessions, 1,800 delegates from 30 nations including all of the top experts, from CSO's to "underground" security specialists. See for yourself what the buzz is about! Early-bird registration ends July 3. This event will sell out. www.blackhat.com ----------------------------------------------------------------------------Received on Mon Jun 30 12:35:30 2003 This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:02:10 EDT |
||||||||||
|
|||||||||||