Linux Netfilter discussions
 help / color / mirror / Atom feed
From: "Ed Street" <blacknet@simplyaquatics.com>
To: 'Matthew Hellman' <mhellman@raccoon.com>,
	'Guillaume Devoyon' <guillaume.devoyon@integro-networks.com>,
	netfilter@lists.samba.org
Subject: RE: PREROUTING AND SECURITY
Date: Fri, 28 Jun 2002 10:45:18 -0400	[thread overview]
Message-ID: <000301c21eb2$6c47ec20$0a01a8c0@ed> (raw)
In-Reply-To: <003101c21e9a$be395360$020aa8c0@matttm9svd8lrh>

Hello,

What type of network card are you using, what distribution of linux,
what kernel version and what is the hardware your using. If you want you
can email directly.

A few possibilities I can think is 
a) resource sharing issues
b) eepro 100 nic (but not limited to this card)
c) local network layout/setup
d) low system resources.  

" Since the interrupt handler keeps calling the Rx and Tx-done routines
while there are packets to be processed, a slower machine will have a
higher average "work event" count per interrupt handler pass.  (ie.
faster machines can do the required work before more new work arrives
and thus fall out the bottom of the IRQ handler sooner.)"

From this it would be interesting to see the cpu time during these
events.  If I recall correctly didn't earlier releases of 2.4 kernel
have issues with resource sharing and ide devices?

Hope this helps,

Ed


-----Original Message-----
From: netfilter-admin@lists.samba.org
[mailto:netfilter-admin@lists.samba.org] On Behalf Of Matthew Hellman
Sent: Friday, June 28, 2002 7:56 AM
To: Guillaume Devoyon; netfilter@lists.samba.org
Subject: Re: PREROUTING AND SECURITY

I wouldn't jump to any conclusions about an attack just yet.  If these
two
machines are similarily configured (same network card, etc) , it's very
likely that this is just a hardware or driver problem. Do a search for
that
error on groups.google.com and you'll see what I mean.  Goodluck,

Matt

----- Original Message -----
From: "Guillaume Devoyon" <guillaume.devoyon@integro-networks.com>
To: <netfilter@lists.samba.org>
Sent: Friday, June 28, 2002 3:17 AM
Subject: PREROUTING AND SECURITY


> hello,
>
> on the firewall at my office, i do preroutings tasks in order to
forward
ports.
> In order to do that, i use the following rule :
>
> /sbin/iptables -t nat -A PREROUTING -s $CLIENT_PUBLIC_IP -p tcp -i
$EXTERNAL_INTERFACE\
>  --dport 80 -j DNAT --to $INTERNAL_MACHINE:80
>
> As you can see, I use the "-s" option  to allow only  one person to
use my
forwarding port.
>
> Yesterday, I had an attack on the firewall .
> I had this in my /var/log/messages :
>
>
> Jun 27 14:44:39 cofw01 kernel: FIREWALL_80IN=eth0 OUT=
MAC=00:30:48:51:08:f0:00:20:6f:11:34:7b:08:00 SRC=xxx.xxx.xxx.xxx
DST=192.168.1.2 LEN=48 TOS=0x00 PREC=0x00 TTL=115 ID=47214 DF PROTO=TCP
SPT=3033 DPT=80 WINDOW=8192 RES=0x00 SYN URGP=0
> Jun 27 14:51:49 cofw01 kernel: eth0: card reports no resources.
> Jun 27 14:51:49 cofw01 last message repeated 15 times
> Jun 27 14:51:49 cofw01 kernel: eth0: Too much work at interrupt,
status=0x4050.
> Jun 27 14:51:49 cofw01 kernel: eth0: card reports no resources.
> Jun 27 14:51:49 cofw01 last message repeated 19 times
> Jun 27 14:51:49 cofw01 kernel: eth0: Too much work at interrupt,
status=0x4050.
> Jun 27 14:51:49 cofw01 kernel: eth0: card reports no resources.
> Jun 27 14:51:49 cofw01 kernel: eth0: Too much work at interrupt,
status=0x4050.
> Jun 27 14:51:49 cofw01 kernel: eth0: Too much work at interrupt,
status=0x4050.
> Jun 27 14:51:49 cofw01 kernel: eth0: card reports no resources.
> Jun 27 14:51:49 cofw01 last message repeated 8 times
> Jun 27 14:51:49 cofw01 kernel: eth0: Too much work at interrupt,
status=0x4050
>
> so i saw that xxx.xxx.xxx.xxx had attacked my firewall.
>
> After this i had to reboot my firewall
>
> 1) how is it possible that my firewall switched of my eth0 card ?
>    Is it because I do a log of this translation rule ? (made my system
heavy if there are many connections ?)
>    Is it because for others rules i do an reject instead of an drop ?
>
> Next, I had a look at my apache server behind the firewall, and I
found
the following messages in my /var/log/messages
>
> Jun 27 14:51:24 coupf01 kernel: eth0: card reports no resources.
> Jun 27 14:51:24 coupf01 kernel: eth0: Too much work at interrupt,
status=0x4050.
>
>
> whow !!
> the attack had also touched my server behind the firewall..
> How is it possible ? I put an "-s" option in my prerouting..
> Is it enough or should I put an drop rule for others connections?
(other
than my client : -s $CLIENT_PUBLIC_IP)
>
>
> Guillaume Devoyon
>





      reply	other threads:[~2002-06-28 14:45 UTC|newest]

Thread overview: 3+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2002-06-28  8:17 PREROUTING AND SECURITY Guillaume Devoyon
2002-06-28 11:55 ` Matthew Hellman
2002-06-28 14:45   ` Ed Street [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to='000301c21eb2$6c47ec20$0a01a8c0@ed' \
    --to=blacknet@simplyaquatics.com \
    --cc=guillaume.devoyon@integro-networks.com \
    --cc=mhellman@raccoon.com \
    --cc=netfilter@lists.samba.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox