linux-admin.vger.kernel.org archive mirror
 help / color / mirror / Atom feed
* Server under DDOS attack HELP
@ 2004-08-14 12:10 Kev
  2004-08-14 12:20 ` James Turnbull
  0 siblings, 1 reply; 5+ messages in thread
From: Kev @ 2004-08-14 12:10 UTC (permalink / raw)
  To: linux-admin, linux-config

hi,

for the 5th time today my server is under a DDOS attack :( how can i
stop this ??? what i block all ICMP communication ?????

plz help.....



------- 
Web Hosting at a cheap price, starting at $1 per month with your own domain, .COM, .NET, .LK, .ORG etc..
PHP, CGI, Perl, MySQL, Cpanel 9, POP3, POP3s, SMTP, IMAP, FTP,
http://www.orbitsl.net


^ permalink raw reply	[flat|nested] 5+ messages in thread

* Re: Server under DDOS attack HELP
  2004-08-14 12:10 Server under DDOS attack HELP Kev
@ 2004-08-14 12:20 ` James Turnbull
  2004-08-14 12:30   ` Re[2]: " Kev
  0 siblings, 1 reply; 5+ messages in thread
From: James Turnbull @ 2004-08-14 12:20 UTC (permalink / raw)
  To: Kev; +Cc: linux-admin, linux-config

[-- Attachment #1: Type: text/plain, Size: 434 bytes --]

Kev wrote:

>hi,
>
>for the 5th time today my server is under a DDOS attack :( how can i
>stop this ??? what i block all ICMP communication ?????
>
>plz help.....
>
>  
>
Kev

What sort of attack is this?  What are you seeing in your firewall logs?

To restrict all incoming new and established state ICMP traffic you can 
do something like:

iptables -A INPUT -p icmp -m state --state NEW,ESTABLISHED,RELATED -j DROP

Regards

James

[-- Attachment #2: S/MIME Cryptographic Signature --]
[-- Type: application/x-pkcs7-signature, Size: 2801 bytes --]

^ permalink raw reply	[flat|nested] 5+ messages in thread

* Re[2]: Server under DDOS attack HELP
  2004-08-14 12:20 ` James Turnbull
@ 2004-08-14 12:30   ` Kev
  2004-08-14 12:34     ` James Turnbull
  0 siblings, 1 reply; 5+ messages in thread
From: Kev @ 2004-08-14 12:30 UTC (permalink / raw)
  To: linux-admin, linux-config


>
>What sort of attack is this?  What are you seeing in your firewall logs?
>
>To restrict all incoming new and established state ICMP traffic you can 
>do something like:
>
>iptables -A INPUT -p icmp -m state --state NEW,ESTABLISHED,RELATED -j DROP
>

i cant even SSH to see whats going on..... its with my ISP they told me
its under a DDOS attack and some one trying to loin in via SSH....

if i block all icmp would that help ?


------- 
Web Hosting at a cheap price, starting at $1 per month with your own domain, .COM, .NET, .LK, .ORG etc..
PHP, CGI, Perl, MySQL, Cpanel 9, POP3, POP3s, SMTP, IMAP, FTP,
http://www.orbitsl.net


^ permalink raw reply	[flat|nested] 5+ messages in thread

* Re: Server under DDOS attack HELP
  2004-08-14 12:30   ` Re[2]: " Kev
@ 2004-08-14 12:34     ` James Turnbull
  2004-08-14 12:45       ` Re[2]: " Kev
  0 siblings, 1 reply; 5+ messages in thread
From: James Turnbull @ 2004-08-14 12:34 UTC (permalink / raw)
  To: Kev; +Cc: linux-admin, linux-config

[-- Attachment #1: Type: text/plain, Size: 428 bytes --]

Kev wrote:

>i cant even SSH to see whats going on..... its with my ISP they told me
>its under a DDOS attack and some one trying to loin in via SSH....
>
>if i block all icmp would that help ?
>
>
>  
>
If it's your ISP they should be working on fixing the problem too but 
maybe it might help.  Depends on the nature of the DDOS attack.  You 
need more information from your ISP before you can make any calls.

Regards

James

[-- Attachment #2: S/MIME Cryptographic Signature --]
[-- Type: application/x-pkcs7-signature, Size: 2801 bytes --]

^ permalink raw reply	[flat|nested] 5+ messages in thread

* Re[2]: Server under DDOS attack HELP
  2004-08-14 12:34     ` James Turnbull
@ 2004-08-14 12:45       ` Kev
  0 siblings, 0 replies; 5+ messages in thread
From: Kev @ 2004-08-14 12:45 UTC (permalink / raw)
  To: linux-admin, linux-config


>>
>If it's your ISP they should be working on fixing the problem too but 
>maybe it might help.  Depends on the nature of the DDOS attack.  You 
>need more information from your ISP before you can make any calls.

yeah Jemes, i just ask them to tell me really whats going on with a full
description,

thanks for you help

------- 
Web Hosting at a cheap price, starting at $1 per month with your own domain, .COM, .NET, .LK, .ORG etc..
PHP, CGI, Perl, MySQL, Cpanel 9, POP3, POP3s, SMTP, IMAP, FTP,
http://www.orbitsl.net


^ permalink raw reply	[flat|nested] 5+ messages in thread

end of thread, other threads:[~2004-08-14 12:45 UTC | newest]

Thread overview: 5+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2004-08-14 12:10 Server under DDOS attack HELP Kev
2004-08-14 12:20 ` James Turnbull
2004-08-14 12:30   ` Re[2]: " Kev
2004-08-14 12:34     ` James Turnbull
2004-08-14 12:45       ` Re[2]: " Kev

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).