Educause Security Discussion mailing list archives
Re: portmapper DDOS
From: Julian Y Koh <kohster () NORTHWESTERN EDU>
Date: Thu, 2 Jun 2016 13:37:32 +0000
On Thu Jun 02 2016 08:29:55 CDT, Emily Harris <emharris () vassar edu> wrote:
We have received four separate notices about machines on our network launching DDOS attacks via RPC port mapping on UDP port 111. Two of them are under our control and shouldn't be available from the Internet, so we are blocking access via our edge firewall. The other two are regular user machines. I'm thinking of just blocking access to UDP port 111, but I am wondering if anyone else had experience this and if that blocking strategy affecting any other services. From what I read, RPC port mapping should work on TCP if UDP is unavailable. Has anyone done this and experienced any negative consequences? Thanks!
We've been blocking port 111 for years globally without any ill effect. -- Julian Y. Koh Associate Director, Telecommunications and Network Services Northwestern Information Technology 2001 Sheridan Road #G-166 Evanston, IL 60208 +1-847-467-5780 Northwestern IT Web Site: <http://www.it.northwestern.edu/> PGP Public Key:<http://bt.ittns.northwestern.edu/julian/pgppubkey.html>
Current thread:
- portmapper DDOS Emily Harris (Jun 02)
- Re: portmapper DDOS Julian Y Koh (Jun 02)
- Re: portmapper DDOS Alan Amesbury (Jun 02)
- Re: portmapper DDOS Haselhoff, Brent (Jun 02)
- Re: portmapper DDOS Ben Marsden (Jun 02)
- Re: portmapper DDOS Julian Y Koh (Jun 02)
