»
 

Go Back   ResellerRatings Store Ratings > ResellerRatings Forums > Tech Support

Reply
 
LinkBack Thread Tools Display Modes
Old 01-10-2002, 08:25 PM   #1 (permalink)
Registered User
 
newbie~wan's Avatar
 
Join Date: Oct 2001
Location: Columbus, OH
Posts: 1,340
newbie~wan is on a distinguished road
I've been DoS attacked....from inside my LAN!!

I was watching survivor. I come back and try to load a web page. Nothing happens. I look in my systray and see the Sygate icon flashing. I open it up. This is what it says:

Security Type: Denial of Service
Severity : Major
Direction: Outgoing
Protocol: ICMP
Remote Host: 192.168.1.102
Local IP: 192.168.1.101
Application involved:

Denial of Service "IP Fragmentation Overlap" attack detected.
Description:
An IP Fragmentation Overlap attack exploits IP's packet reassembly feature by creating packet fragments with overlapping offset fields, making it impossible for your system to reassemble the packets properly.

Anyone know what to make of this? Whatever it was, it apparently stopped.

newbie~wan is offline   Reply With Quote
Old 01-10-2002, 08:31 PM   #2 (permalink)
Registered User
 
Join Date: Oct 2001
Location: TOO close to Wash DC
Posts: 7,956
vass0922 is on a distinguished road
Who is Remote Host: 192.168.1.102 ??

Whos' on that IP?

Is it your router by chance?
If so it could of indeed come from outside, but since it was routed through it appears to be from inside.

If its from a PC, maybe there is a zombie installed.
Check for viruses!!!
Make sure there is a firewall on that PC as well!!

If that IP does not exist on your LAN hmmm no clue
vass0922 is offline   Reply With Quote
Old 01-10-2002, 08:34 PM   #3 (permalink)
Registered User
 
DVNT1's Avatar
 
Join Date: Oct 2001
Location: Ohio
Posts: 5,577
DVNT1 is on a distinguished road
Could be someone using tools like TFN, TFN2K, or Trinoo. It may be a SMURF attack in which the source IPs are spoofed.


What is your LAN enviroment? Like number of PCs, just yours or other peoples, using a NAT router, etc...
DVNT1 is offline   Reply With Quote
Old 01-10-2002, 08:43 PM   #4 (permalink)
Registered User
 
Join Date: Oct 2001
Location: TOO close to Wash DC
Posts: 7,956
vass0922 is on a distinguished road
oh yeah spoofing... duh lol

Could be a bad case of backdoor trojans too

vass0922 is offline   Reply With Quote
Old 01-10-2002, 08:51 PM   #5 (permalink)
Registered User
 
FreakyOCR's Avatar
 
Join Date: Oct 2001
Location: Langley, BC, Canada
Posts: 3,422
FreakyOCR is on a distinguished road
Send a message via ICQ to FreakyOCR Send a message via AIM to FreakyOCR Send a message via Yahoo to FreakyOCR
Hey do you have a router?? I get that when Sandra(I think) tries a network benchmarkk..
__________________
- Freaky
FreakyOCR is offline   Reply With Quote
Old 01-11-2002, 06:13 AM   #6 (permalink)
Registered User
 
newbie~wan's Avatar
 
Join Date: Oct 2001
Location: Columbus, OH
Posts: 1,340
newbie~wan is on a distinguished road
192.168.1.102 is in my LAN. All my computers sit behind a router w/ NAT. That box currently doesnt have a firewall on it, but mine does (192.168.1.101).

I think Freaky nailed it. I performed a Sandra total analysis. The time that Sygate reports the attack would have been about the same time I ran Sandra. However, a warning did pop up shortly after I began the test asking if I wanted to allow Sandra access to the network, so I told it yes. I then left the box and didnt come back for an hour.

I suppose its possible that sandra asked for access again and I wasnt there to Ok it this time. I'll run it again when I get home tonight and see if I get the same message.
newbie~wan is offline   Reply With Quote
Reply




Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Most Active Discussions

Recent Discussions

All times are GMT -6. The time now is 01:00 PM.