The Daily Static
  The Daily Static
UF Archives
Register
UF Membership
Ad Free Site
Postcards
Community

Geekfinder
UFie Gear
Advertise on UF

Forum Rules
& FAQ


Username

Password


Create a New Account

 
 

Back to UserFriendly Strip Comments Index

Calling all UFie sysadmins by Kickstart 2003-03-18 17:38:40
Almost 3.5 days of Denial of Service attacks...I'm getting pretty tired and seek advice.

Someone out there appears to be exploiting vulnerability on Win2k and WinNT, especially the recent on in IIS 5.0. They are using this vulnerability to do distributed Denial of Service attacks on my company's biggest client...hcareers.com.

We can't drop the incoming packets from these compromised machines, since there is no point...they incoming packets are filling the pipe anyway, and the server park host shuts the connection to our servers down before the bandwidth charges overwhelm the client financially and the bandwidth use affects their other clients.

Basically, as long as these machines are compromised, we're screwed. We can't stop the attacker in any other way. Because he is using other machines on (mostly) cable and ADSL networks that are not likely to track connections and usage, he is effectively not trace-able.

If you've got any clues as to what we can do to stop this before a lone hacker puts the client out of business (which would likely put me out of a job), I'd appreciate the info.

If you've got nothing else, a word of sympathy would be lovely. :(

Thanks,

Kickstart
PS. I'll be back here in a couple hours to answer posts to this thread.
[ Reply ]
  If the server's been 'compromised' by kahuana2003-03-18 17:45:26
  Ohhh... That sucks. by mswebchik2003-03-18 17:45:35
  Start contacting the other networks anyway, by Arcanum2003-03-18 17:47:20
  Man, that's tough... by IByte2003-03-18 17:51:03
  (((((((((((Kickstart))))))))))))) by GeekPrincess2003-03-18 17:56:45
  My knowledge of DDoS attacks wouldn't by Nea2003-03-18 17:58:36
  Nothing helpful by Lady-Luna2003-03-18 18:00:22
  What type of traffic is it? by vyrus2003-03-18 18:00:57
    Port 80, unfortunately. (n/t) by Kickstart2003-03-18 22:14:01
  Well, is this just aimed at your client, or is it by Adiplomat2003-03-18 18:04:12
    Did he write ZoneAlarm? by LionsPhil2003-03-18 18:22:53
      As far as I know, he didn't by Freakazoid2003-03-18 18:29:15
        Yeah, by LionsPhil2003-03-18 18:31:18
          I've actually had a chance to use spinrite by Freakazoid2003-03-18 18:34:49
            Blimey. by LionsPhil2003-03-18 18:38:02
              I was suprised also... by Freakazoid2003-03-18 18:43:32
  {{{Kickstart}}}} by Arienadean2003-03-18 18:07:22
    If you want linkage to GRC's article, by LionsPhil2006-11-19 12:55:59
  Hmm by Reddy2003-03-18 18:09:55
  Check your U.F. e-mail by desertrat662003-03-18 18:34:53
  Linkage on this sort of problem by desertrat662006-11-19 12:55:59
  Make calls... by imperito2003-03-18 19:01:15
    here I think the law says by Arienadean2003-03-18 19:22:07
  Call your upstream provider by wiseguy5862003-03-18 20:35:51

 

[Todays Cartoon Discussion] [News Index]

Come get yer ARS (Account Registration System) Source Code here!
All images, characters, content and text are copyrighted and trademarks of J.D. Frazer except where other ownership applies. Don't do bad things, we have lawyers.
UserFriendly.Org and its operators are not liable for comments or content posted by its visitors, and will cheerfully assist the lawful authorities in hunting down script-kiddies, spammers and other net scum. And if you're really bad, we'll call your mom. (We're not kidding, we've done it before.)