Linode Forum
Linode Community Forums
 FAQFAQ    SearchSearch    MembersMembers      Register Register 
 LoginLogin [ Anonymous ] 
Post new topic  Reply to topic
Author Message
PostPosted: Sun Jul 22, 2012 12:56 pm 
Offline
Senior Member

Joined: Mon Jan 02, 2012 12:45 pm
Posts: 365
We've been getting hit by 217.34.101.120 for the last 3 hours. I added the IP to the block list in iptables. We've got about 20Kb incoming per second. This attack is on all three of the additional IP's that we got this week (one of which doesn't even have a domain associated to it yet).

I'm new to iptables, so would someone please verify that I've added the offender to be blocked on all ports & adaptors?
Code:
target       prot opt in     out     source               destination         
DROP         all  --  any    any     host217-34-101-120.in-addr.btopenworld.com  anywhere


Besides blocking the IP with iptables, is there anything else I can do to minimize the effect of this attack ... or even stop it completely?

Any guidance would be greatly appreciated.

Thanks,
James


Last edited by Main Street James on Sun Jul 22, 2012 1:49 pm, edited 1 time in total.

Top
   
PostPosted: Sun Jul 22, 2012 1:00 pm 
Offline
Junior Member

Joined: Sun Jun 24, 2012 4:27 pm
Posts: 29
Yes, send an email to abuse@btopenworld.com with your logs.


Top
   
PostPosted: Sun Jul 22, 2012 1:13 pm 
Offline
Senior Member

Joined: Mon Jan 02, 2012 12:45 pm
Posts: 365
bacon wrote:
Yes, send an email to abuse@btopenworld.com with your logs.

Thanks - I've already done that and filled out their web form to report the issue.


Last edited by Main Street James on Sun Jul 22, 2012 1:50 pm, edited 1 time in total.

Top
   
PostPosted: Sun Jul 22, 2012 1:17 pm 
Offline
Senior Member
User avatar

Joined: Sun Dec 27, 2009 11:12 pm
Posts: 1038
Location: Colorado, USA
Technically, since it's from a single IP it's a DoS (denial of service) attack.

DDoS is DISTRIBUTED, and with just one IP it's not that.

_________________
Either provide enough details for people to help, or sit back and listen to the crickets chirp.
Security thru obscurity is a myth - and really really annoying.


Top
   
PostPosted: Sun Jul 22, 2012 1:50 pm 
Offline
Senior Member

Joined: Mon Jan 02, 2012 12:45 pm
Posts: 365
vonskippy wrote:
Technically, since it's from a single IP it's a DoS (denial of service) attack.

DDoS is DISTRIBUTED, and with just one IP it's not that.

Thanks ... I've corrected the subject line.


Top
   
PostPosted: Mon Jul 23, 2012 10:16 am 
Offline
Senior Member
User avatar

Joined: Tue May 26, 2009 3:29 pm
Posts: 1691
Location: Montreal, QC
Linode doesn't charge for incoming bandwidth, so with a 20 kilobit attack, dropping it with iptables will have completely mitigated the attack. You've notified btopenworld, you've done all you should have.


Top
   
Display posts from previous:  Sort by  
Post new topic  Reply to topic


Who is online

Users browsing this forum: No registered users and 3 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum

Search for:
Jump to:  
RSS

Powered by phpBB® Forum Software © phpBB Group