Page 3 of 4 FirstFirst 1234 LastLast
Results 21 to 30 of 40

Thread: Routing Help!

  1. #21
    Join Date
    Jan 2005
    Posts
    3,151
    Rep Power
    0

    Default

    that will only stop spoofed packets from leaving your network. It wouldnt stop
    the spoofed packets from DDOSing you to pieces.

  2. #22
    Join Date
    Oct 2004
    Posts
    4,814
    Rep Power
    24

    Default

    Quote Originally Posted by pogi_2nr
    that will only stop spoofed packets from leaving your network. It wouldnt stop
    the spoofed packets from DDOSing you to pieces.
    yeah I know. It was just a reference I came across. If implemented on a network it would prevent ppl from being annoying to others.

    Jamrock, I still dont understand how a packet with destination 10.0.0.255 would be routed on the net to your machine. I didnt come across anything to suggest this.

  3. #23
    Join Date
    Jan 2005
    Posts
    3,151
    Rep Power
    0

    Default

    The paranoia is reaching to Jamrock there

    Clearly somebody hacked his isp and is routing those packets to him .

  4. #24
    Join Date
    Aug 2002
    Posts
    3,959
    Rep Power
    25

    Default

    Jamrock, I still dont understand how a packet with destination 10.0.0.255 would be routed on the net to your machine. I didnt come across anything to suggest this.
    It is my understanding that addresses can be spoofed. One of the basic rules in a firewall script is to check for i.p. addresses orginating outside the machine that claim to be coming from the machine itself.

    I cannot tell you how it is being done. I can only say that my firewall's logs say that these addresses are being blocked.

    Hey Gillion. What is your take on this?

    The paranoia is reaching to Jamrock there
    Perhaps... Perhaps not... When was the last time you reviewed your firewall's logs?

    Anyhow! I think I'll take that advice, I'll hold off the clients and watch the firewall logs for sometime.
    Have you seen anything interesting in your logs?

  5. #25
    Join Date
    Oct 2004
    Posts
    4,814
    Rep Power
    24

    Default

    Quote Originally Posted by jamrock
    Have you seen anything interesting in your logs?
    nope, nothing interesting! not even an anonymous ping. Its only been going for a week though, think im going to observe for another week.

  6. #26
    Join Date
    Aug 2002
    Posts
    3,959
    Rep Power
    25

    Default

    Double check your firewall rules. Make sure your firewall is logging packets and not just dropping them.

  7. #27
    Join Date
    Oct 2004
    Posts
    4,814
    Rep Power
    24

    Default

    OK.. I think its configured to log everything. To be sure I'll hit it with stuff from work and check it later.

  8. #28
    Join Date
    Oct 2004
    Posts
    4,814
    Rep Power
    24

    Default

    Did some probes on the firewall from work. Tried to abuse it as much as I could, I saw most of the abuse in the logs. I havn't tried any penetration attacks was too bored to bother.

    EDIT:

    I forgot, I will be using nessus to do some more detailed probing later. Maybe I should install those sever apps while trying this, or maybe I should try a before and after test. With the before being without the samba and all. In any case u'll know my finds.
    Last edited by leoandru; Jan 5, 2006 at 12:17 AM.

  9. #29
    Join Date
    Jan 2005
    Posts
    3,151
    Rep Power
    0

    Default

    Will this box be up 24/7?

    we should link up via gre

  10. #30
    Join Date
    Oct 2004
    Posts
    4,814
    Rep Power
    24

    Default

    Quote Originally Posted by pogi_2nr
    Will this box be up 24/7?

    we should link up via gre
    yeah its on 24/7 its the network router.. (that reminds me that I need to get a silent fan for it).
    gre ? Heard about it before but never used it (some tunneling protocol right?).

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •