Date: Mon, 28 Aug 2000 13:31:06 -0400 From: "Shane Hale" <shale@bricsnet.com> To: <freebsd-security@freebsd.org> Message-ID: <CCEDJBBFHBFABONEPKICOECHCDAA.shale@bricsnet.com>
index | next in thread | raw e-mail
[-- Attachment #1 --] Hello I have a machine that's getting attacked regularly. (Yes i know my clock is wrong... 1886809 seconds fast to be exact) Sep 19 00:17:54 shell /kernel: icmp-response bandwidth limit 3491/200 pps Sep 19 00:17:55 shell /kernel: icmp-response bandwidth limit 3499/200 pps Sep 19 00:17:56 shell /kernel: icmp-response bandwidth limit 3505/200 pps Sep 19 00:17:57 shell /kernel: icmp-response bandwidth limit 3503/200 pps Sep 19 00:17:58 shell /kernel: icmp-response bandwidth limit 3505/200 pps Sep 19 00:17:59 shell /kernel: icmp-response bandwidth limit 3502/200 pps Sep 19 00:18:00 shell /kernel: icmp-response bandwidth limit 3488/200 pps Sep 19 00:18:01 shell /kernel: icmp-response bandwidth limit 3491/200 pps Sep 19 00:18:02 shell /kernel: icmp-response bandwidth limit 3494/200 pps Sep 19 00:18:03 shell /kernel: icmp-response bandwidth limit 3491/200 pps Sep 19 00:18:04 shell /kernel: icmp-response bandwidth limit 3497/200 pps Sep 19 00:18:05 shell /kernel: icmp-response bandwidth limit 3501/200 pps Sep 19 00:18:06 shell /kernel: icmp-response bandwidth limit 3504/200 pps Sep 19 00:18:07 shell /kernel: icmp-response bandwidth limit 3485/200 pps Sep 19 00:18:27 shell /kernel: icmp-response bandwidth limit 1599/200 pps (This went on for about 15 minutes, and caused my network to be slow as molasses and a traceroute from home stopped at the router that routes my C-Class) I have ICMP bandwith limiting on the machine being attacked, but... - how can i trace who's attacking me - what exactly are they trying to do - how does ICMP_BANDWITH Limiting work If there is anyone who can help me, i'd appreciate it. Shane Hale Systems Administration Bricsnet, Inc Suite 601, 2300 Yonge Street, Box 2361 / Toronto, Ontario / M4P 1E4 / Canada Phone: +1(416)489-9000 ext. 304 Fax: +1(416)489-3201 Email: shale@bricsnet.com Web: http://www.bricsnet.com __________________________________________ Bricsnet Inc. Bricsnet.com is the leading e-marketplace for the global building industry [-- Attachment #2 --] x>" IPM.Microsoft Mail.Note 1 ( 0 ! # &
