Skip site navigation (1)Skip section navigation (2)
Date:      Mon, 28 Aug 2000 13:31:06 -0400
From:      "Shane Hale" <shale@bricsnet.com>
To:        <freebsd-security@freebsd.org>
Message-ID:  <CCEDJBBFHBFABONEPKICOECHCDAA.shale@bricsnet.com>

index | next in thread | raw e-mail

[-- Attachment #1 --]

Hello

I have a machine that's getting attacked regularly.

(Yes i know my clock is wrong... 1886809 seconds fast to be exact)

Sep 19 00:17:54 shell /kernel: icmp-response bandwidth limit 3491/200 pps
Sep 19 00:17:55 shell /kernel: icmp-response bandwidth limit 3499/200 pps
Sep 19 00:17:56 shell /kernel: icmp-response bandwidth limit 3505/200 pps
Sep 19 00:17:57 shell /kernel: icmp-response bandwidth limit 3503/200 pps
Sep 19 00:17:58 shell /kernel: icmp-response bandwidth limit 3505/200 pps
Sep 19 00:17:59 shell /kernel: icmp-response bandwidth limit 3502/200 pps
Sep 19 00:18:00 shell /kernel: icmp-response bandwidth limit 3488/200 pps
Sep 19 00:18:01 shell /kernel: icmp-response bandwidth limit 3491/200 pps
Sep 19 00:18:02 shell /kernel: icmp-response bandwidth limit 3494/200 pps
Sep 19 00:18:03 shell /kernel: icmp-response bandwidth limit 3491/200 pps
Sep 19 00:18:04 shell /kernel: icmp-response bandwidth limit 3497/200 pps
Sep 19 00:18:05 shell /kernel: icmp-response bandwidth limit 3501/200 pps
Sep 19 00:18:06 shell /kernel: icmp-response bandwidth limit 3504/200 pps
Sep 19 00:18:07 shell /kernel: icmp-response bandwidth limit 3485/200 pps
Sep 19 00:18:27 shell /kernel: icmp-response bandwidth limit 1599/200 pps

(This went on for about 15 minutes, and caused my network to be slow as
molasses and a traceroute from home stopped at the router that routes my
C-Class)

I have ICMP bandwith limiting on the machine being attacked, but...

- how can i trace who's attacking me
- what exactly are they trying to do
- how does ICMP_BANDWITH Limiting work

If there is anyone who can help me, i'd appreciate it.


Shane Hale
Systems Administration
Bricsnet, Inc
Suite 601, 2300 Yonge Street, Box 2361 / Toronto, Ontario / M4P 1E4 / Canada
Phone: +1(416)489-9000 ext. 304 Fax: +1(416)489-3201
Email: shale@bricsnet.com Web: http://www.bricsnet.com

__________________________________________
Bricsnet Inc.
Bricsnet.com is the leading e-marketplace for the global building industry


[-- Attachment #2 --]
x>"IPM.Microsoft Mail.Note1

(0!#&)6qrX,E?}wSMTP:SHALE@BRICSNET.COM@A
; "CJp/LH€	nj	LZFuŤ
rcpg1252`n033Och
set0 PoPu}
ȴ ;	o0
vwkd4`cP

Hel	dc1 I Ave a hKtt' gu0tg@k%	 `gu`rl$y.(Yi knomy co	 w` .! 188680<9    faBs@to bext)`p!@!00:17:54!h /:cmp-`sp  "pdRd` lpi@30491/Pppw#$5%&/'=9;(?$Y6*+';50v5-/$Y7.0132$Y83417$ho!8:;2;$V8:A=>'K!`@A0BC'OEB2GHI4JA3LMIOB%RS7TA)W:TA.\o:OA3a_D;A2e?fOS1=-T 	@ "@`lo,   au  0tw p"s	"`"`  ptroR`prq"hQtSbv4r C-Cs2#[UICMPlSoAv"лpbo!-tqt uT}v~u#P`u ty">d}ԂyR_BANDWITH LzFqx+fuq py ~~#jQ$@pi'sh`c0tT0vUP1H@"pemdpAt dBcsqplIn<uT06Gp23hY St	Boxb60/ T!o=pO0
M4Yy1EV`CpatdadPu0k+@1(416)E9-9$P#|TPVQFax3
>Ekj@@bߎ1!"q.t(Webkh@p://w.b_ϞE̎u& ve-r0Q~orvg	g  |S_q0Ua F. FR}n; F= F> F? Fg FT9.0h Fi F F; "CJp/LH; "CJp/LH8+*VPSTPRX.DLLNITA7nC:\WINDOWS\Local Settings\Application Data\Microsoft\Outlook\Personal Folders(1).pst
472<CCEDJBBFHBFABONEPKICOECHCDAA.shale@bricsnet.com>!rieHELLOIHAVEAMACHINETHATSGETTINGATTACKEDREGULARLY(YESIKNOWMYCLOCKISWRONG1886809SECONDSFASTTOBEEXACT)SE7
home | help

Want to link to this message? Use this
URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?CCEDJBBFHBFABONEPKICOECHCDAA.shale>