Linode Forum
Linode Community Forums
 FAQFAQ    SearchSearch    MembersMembers      Register Register 
 LoginLogin [ Anonymous ] 
Post new topic  Reply to topic
Author Message
 Post subject: Need advice.
PostPosted: Sat Oct 09, 2004 1:38 am 
Offline
Senior Newbie

Joined: Tue Jul 20, 2004 5:07 am
Posts: 14
What can I do about this:

Someone else owns a domain which has a botnet (IRC) being pointed at it. The guy has changed the DNS entry of this domain to point to my IP, so the botnet is focused on my Linode.

Is there anything I can do about this?

I can't shut down the IRCd, because it's part of a network and there's people using it.

P.S. It's not putting any strain on the servers at all, so please don't like... null route my IP... :-P


Top
   
 Post subject:
PostPosted: Sat Oct 09, 2004 6:02 am 
Offline
Senior Member
User avatar

Joined: Fri Oct 24, 2003 3:51 pm
Posts: 965
Location: Netherlands
Have you tried contacting the organisation hosting the offending DNS servers and complaining? No sensible provider wants their infrastructure sucked into a bot war and they may be prepared to suspend the guy's account for abuse.

If his provider won't help, you could tarpit the bot IPs. The upside of a tarpit is that you minimise the amount of traffic that the attack generates for your Linode and reduce resource utilisation. The down side is that you can end up crashing or seriously overloading the attacking machines, which may provoke a more serious attack, which in turn will cause caker to null route your IP. If the attack is not causing serious problems then just ride it out.

If you decide to go with a tarpit, you need to get round the problem that the netfilter patch-o-matic for the tarpit target has been rejected for inclusion in the regular NF source tree (at the Netfilter Developers Conference last month), so it won't be available on Linodes any time soon. (This is an educated guess - I'm assuming that caker won't want to put half baked patch-o-matic stuff in his production kernels.) One possible solution is to use the dbtarpit component of SpamCannibal, with its configuration files modified to suit IRC instead of mail. It looks as if this only requires CONFIG_IP_NF_CONNTRACK and CONFIG_IP_NF_QUEUE, which are both in the Linode kernels.

_________________
/ Peter


Top
   
Display posts from previous:  Sort by  
Post new topic  Reply to topic


Who is online

Users browsing this forum: No registered users and 7 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum

Search for:
Jump to:  
RSS

Powered by phpBB® Forum Software © phpBB Group