Date: Wed, 25 Apr 2001 08:58:14 -0400 From: Nathan Vidican <webmaster@wmptl.com> To: Mark Drayton <mark.drayton@4thwave.co.uk> Cc: questions@freebsd.org Subject: Re: Continously getting error 'rpc.statd: invalid hostname to sm_stat: ...' could it be a DOS attack? (solution) Message-ID: <3AE6C9E6.EE943B7@wmptl.com> References: <200104231831.OAA47437@mail2.wmptl.com> <01042310270701.01587@galaxy.anchoragerescue.org> <20010423225359.A14549@tethys.valhalla.net>
next in thread | previous in thread | raw e-mail | index | archive | help
Mark Drayton wrote: > > Beech Rintoul (akbeech@anchoragerescue.org) wrote: > > On Monday 23 April 2001 10:31, Nathan Vidican wrote: > > > We have been, (for several weeks now), been getting the error > > > message (logged to both the console, and /var/log/messages) as > > > follows: > > [snip linux rpc.statd overflow log message] > > > It' a hack attempt with an old Linux kiddie script. Never affected > > FreeBSD, and no longer works on Linux. I wouldn't worry about it, we > > get that three or four times a day. > > You should firewall off access to your NFS daemons and get > some kind of intrusion detection system (such as snort) to log the > source address of these attacks. NFS daemons should not be accessible > from the internet. > > -- > > Mark Drayton > > To Unsubscribe: send mail to majordomo@FreeBSD.org > with "unsubscribe freebsd-questions" in the body of the message Just a note for those who are lurking or following this thread, I did both. I reconfig'd the kernel to add support for ipfirewall, and made a quick firewall script to disallow all traffic except for email, web, dns, squid, and ftp, as well as to log all other denied tcp traffic. No problems since then (thus far). Also think the other issue wherein the server kept crapping out had to do with the quality of the NIC; since we replaced it with an intel (fxp) card we've had no problems. Anyhow, that's what our solution turned out to be. -Later To Unsubscribe: send mail to majordomo@FreeBSD.org with "unsubscribe freebsd-questions" in the body of the message
Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?3AE6C9E6.EE943B7>