Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos network security services platform







Security Incidents: DoS attack... what to do?

DoS attack... what to do?

From: Nigel Kukard <nkukard_at_lbsd.net>
Date: Tue, 04 Jan 2005 19:41:19 +0000

Hi Guys,

Here is the situation...

I have a dedicated server at ISP X, about 1 week after I signed up for
the service I received a DoS attack against my DNS service... the attack
came from over 10,000 IP addresses and tried to resolve the following
domain names...

leet.nexhost.org
ns1.nexhost.org
ns2.nexhost.org
floop.m33pm33p.info
irc.k1hosting.net
b0tn3t.elite-coders.org

I thought i would be clever and changed root.cache on my named service
to resolve all dns queries to 127.0.0.1, this seems to of worked for
about 1hr. Next I get even more attacks on port 5556 which I don't even
use and basically by default drop everything to that port.

I have sent off abuse reports for over 10,000 IP's, grouping them by ISP
and sending 1 email per ISP.....

What to do? I've got a constant 200Kbps of traffic, and its kinda
bugging me...

Any help would greatly be appreciated. (btw, netsky.V uses port 5556)

Regards
Nigel Kukard
Received on Jan 04 2005

[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]