From owner-freebsd-questions@FreeBSD.ORG Sat Mar 8 22:35:01 2008 Return-Path: Delivered-To: freebsd-questions@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id F2C0010656C7 for ; Sat, 8 Mar 2008 22:35:00 +0000 (UTC) (envelope-from robin@reportlab.com) Received: from fhw-relay07.plus.net (fhw-relay07.plus.net [212.159.14.215]) by mx1.freebsd.org (Postfix) with ESMTP id 2D0598FC19 for ; Sat, 8 Mar 2008 22:35:00 +0000 (UTC) (envelope-from robin@reportlab.com) Received: from [87.114.66.91] (helo=[192.168.0.3]) by fhw-relay07.plus.net with esmtp (Exim) id 1JY7d4-0002fv-68 for freebsd-questions@freebsd.org; Sat, 08 Mar 2008 22:34:58 +0000 Message-ID: <47D31490.1040804@jessikat.plus.net> Date: Sat, 08 Mar 2008 22:34:56 +0000 From: Robin Becker User-Agent: Thunderbird 2.0.0.12 (Windows/20080213) MIME-Version: 1.0 To: freebsd-questions@freebsd.org Content-Type: text/plain; charset=ISO-8859-1; format=flowed Content-Transfer-Encoding: 7bit X-Plusnet-Relay: b933f3ddd3914d0aa155decd9f8d4f85 Subject: how to respond to possible attacks X-BeenThere: freebsd-questions@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: User questions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Sat, 08 Mar 2008 22:35:01 -0000 Sorry if this is too off topic, but I would like to find out what to do when you suspect a possible dos attack on your system. I know there are many experienced sysadmins here. Although my system (freebsd 6.0/apache 2.0.x) did in fact hold up, what steps should I be taking? The originating ip doesn't seem to be reverse mappable. -- Robin Becker