<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Something ugly is going on. DOS attack. in Operating System - HP-UX</title>
    <link>https://community.hpe.com/t5/operating-system-hp-ux/something-ugly-is-going-on-dos-attack/m-p/4875760#M399673</link>
    <description>Yes Fred.&lt;BR /&gt;&lt;BR /&gt;I don't know where the get is coming from or how its triggered.&lt;BR /&gt;&lt;BR /&gt;the tcpdump data should not be happening because the ip address is blocked.&lt;BR /&gt;&lt;BR /&gt;I would say not voluntary to that questions.&lt;BR /&gt;&lt;BR /&gt;I checked out some of the sites. blazerunner.com is a spyware laden cheap search engine. They don't have the url referenced in the log. Interestingly enough in the DNS realm, the name will not resolve by my browser is able to connect to the site no problem.&lt;BR /&gt;&lt;BR /&gt;SEP</description>
    <pubDate>Thu, 16 Dec 2004 12:21:43 GMT</pubDate>
    <dc:creator>Steven E. Protter</dc:creator>
    <dc:date>2004-12-16T12:21:43Z</dc:date>
    <item>
      <title>Something ugly is going on. DOS attack.</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/something-ugly-is-going-on-dos-attack/m-p/4875750#M399663</link>
      <description>Left my job after a quick fiber card swap on an rp5450. When I left all was well with my web servers.&lt;BR /&gt;&lt;BR /&gt;I get to my private office and its whack city. The web server is unresponsive. A ton of httpd processes are out there with PPID 1 and can't be killed.&lt;BR /&gt;&lt;BR /&gt;Pretty much looks like the kernel (Linux, not relavent) is whacked.&lt;BR /&gt;&lt;BR /&gt;I'm forced to boot. To some degree its going on with apache 2.0.x on all servers, hp9000 and linux.&lt;BR /&gt;&lt;BR /&gt;I see a lot of strange entries in the httpd access_log log.&lt;BR /&gt;&lt;BR /&gt;220.160.43.32 - - [15/Dec/2004:23:30:12 -0600] "GET &lt;A href="http://www.blazerunner.com/ppc/search.php?keywords=Nutrition+supplement&amp;amp;username=robertWyatt" target="_blank"&gt;http://www.blazerunner.com/ppc/search.php?keywords=Nutrition+supplement&amp;amp;username=robertWyatt&lt;/A&gt; HTTP/1.0" 404 5926&lt;BR /&gt;222.135.120.122 - - [15/Dec/2004:23:30:13 -0600] "GET &lt;A href="http://bee-search.com/search.php?AID=25&amp;amp;q=blackjack" target="_blank"&gt;http://bee-search.com/search.php?AID=25&amp;amp;q=blackjack&lt;/A&gt; HTTP/1.0" 404 5871&lt;BR /&gt;60.208.230.145 - - [15/Dec/2004:23:30:14 -0600] "GET &lt;A href="http://hpcgi1.nifty.com/trino/ProxyJ/prxjdg.cgi" target="_blank"&gt;http://hpcgi1.nifty.com/trino/ProxyJ/prxjdg.cgi&lt;/A&gt; HTTP/1.0" 404 5893&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;I see the following in a tcpdump with the -f option for foreign addresses.&lt;BR /&gt;&lt;BR /&gt;ip addresses are altered.&lt;BR /&gt;&lt;BR /&gt;170 is httpd&lt;BR /&gt;168 is httpd&lt;BR /&gt;167 is supposedly mail.&lt;BR /&gt;&lt;BR /&gt;23:22:22.923839 61.42.141.170.http &amp;gt; 220.160.43.32.3702: . 3848796859:3848798291(1432) ack 2301109696 win 6432 (DF)&lt;BR /&gt;23:22:22.976771 222.51.105.105.2420 &amp;gt; 61.42.141.168.http: S 2580438232:2580438232(0) win 16384 &lt;MSS 1414=""&gt; (DF) [tos 0x20]&lt;BR /&gt;23:22:22.976813 61.42.141.168.http &amp;gt; 222.51.105.105.2420: S 4050721642:4050721642(0) ack 2580438233 win 5840 &lt;MSS 1460=""&gt; (DF)&lt;BR /&gt;23:22:23.042141 220.160.43.32.1405 &amp;gt; 61.42.141.167.http: F 1:1(0) ack 1432 win 65535 (DF) [tos 0x20]&lt;BR /&gt;23:22:23.042175 61.42.141.167.http &amp;gt; 220.160.43.32.1405: . 1432:2864(1432) ack 1 win 6432 (DF)&lt;BR /&gt;23:22:23.042182 61.42.141.167.http &amp;gt; 220.160.43.32.1405: . ack 2 win 6432 (DF)&lt;BR /&gt;23:22:23.042187 61.42.141.167.http &amp;gt; 220.160.43.32.1405: . 2864:4296(1432) ack 2 win 6432 (DF)&lt;BR /&gt;23:22:23.303848 61.42.141.168.http &amp;gt; 220.160.43.32.1480: . 0:1432(1432) ack 1 win 6432 (DF)&lt;BR /&gt;23:22:23.454348 220.160.43.32.1215 &amp;gt; 61.42.141.168.http: R 2382819377:2382819377(0) win 0 (DF) [tos 0x20]&lt;BR /&gt;&lt;BR /&gt;Here is the interesting part.&lt;BR /&gt;&lt;BR /&gt;The IP addresses are blocked on the firewall. I've checked the configuration a few times and my response programs updated it properly. Yet the activity continues.&lt;BR /&gt;&lt;BR /&gt;Questions:&lt;BR /&gt;does 220.160.43.32.1215&lt;BR /&gt;in tcpdump mean the traffic came in on 220.160.43.32 port 1215.&lt;BR /&gt;&lt;BR /&gt;I hope not, becasue that port is blocked on the firewall and I have verified that from the outside.&lt;BR /&gt;&lt;BR /&gt;I'm kind of wondering whats going on and how to deal with it. Hardening the firewall configuration seems to have slowed but not stopped the problem. The configuration was pretty solid before.&lt;BR /&gt;&lt;BR /&gt;SEP&lt;/MSS&gt;&lt;/MSS&gt;</description>
      <pubDate>Thu, 16 Dec 2004 00:39:57 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/something-ugly-is-going-on-dos-attack/m-p/4875750#M399663</guid>
      <dc:creator>Steven E. Protter</dc:creator>
      <dc:date>2004-12-16T00:39:57Z</dc:date>
    </item>
    <item>
      <title>Re: Something ugly is going on. DOS attack.</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/something-ugly-is-going-on-dos-attack/m-p/4875751#M399664</link>
      <description>Yes SEP. 220.160.43.32.1215 means 220.160.43.32 port 1215. If you activate name resolution on its output and port is defined in /set/services, you'll see it's a hostname.port format.&lt;BR /&gt;&lt;BR /&gt;What is meant in this line&lt;BR /&gt;23:22:23.454348 220.160.43.32.1215 &amp;gt; 61.42.141.168.http: R 2382819377:2382819377(0) win 0 (DF) [tos 0x20]&lt;BR /&gt;if that 220.160.43.32 send a request to 61.42.141.168. But this is quite normal. If I understand, 61.42.141.168 is your public address. And 220.160.43.32 is the client. It accesses your server on port "http" (probably 80) and its local port is 1215. But that doesn't mean your 1215 port is oppened.&lt;BR /&gt;&lt;BR /&gt;Regards,&lt;BR /&gt;&lt;BR /&gt;Fred&lt;BR /&gt;</description>
      <pubDate>Thu, 16 Dec 2004 08:12:08 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/something-ugly-is-going-on-dos-attack/m-p/4875751#M399664</guid>
      <dc:creator>Fred Ruffet</dc:creator>
      <dc:date>2004-12-16T08:12:08Z</dc:date>
    </item>
    <item>
      <title>Re: Something ugly is going on. DOS attack.</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/something-ugly-is-going-on-dos-attack/m-p/4875752#M399665</link>
      <description>I did not understand the all details, but how about putting additional entry in /var/adm/inetd.sec and deny all services to that ip address?? &lt;BR /&gt;I did nslookup for all those ips, and did not get anything.&lt;BR /&gt;&lt;BR /&gt;Anil</description>
      <pubDate>Thu, 16 Dec 2004 09:04:04 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/something-ugly-is-going-on-dos-attack/m-p/4875752#M399665</guid>
      <dc:creator>RAC_1</dc:creator>
      <dc:date>2004-12-16T09:04:04Z</dc:date>
    </item>
    <item>
      <title>Re: Something ugly is going on. DOS attack.</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/something-ugly-is-going-on-dos-attack/m-p/4875753#M399666</link>
      <description>Are you using a hardware or software firewall?  And if hardware, how many network devices are between the firewall and the systems in question?&lt;BR /&gt;&lt;BR /&gt;In your apache conf files you should also verify that the "MaxSpareServers" setting is as low as resonably possible.  The out-of-the box setting is like 15 or 20; perhaps change it to be equal to the "MinSpareServers" value and then make sure that is set as low as practically possible.  This won't prevent a DDOS attack, but at least it doesn't give hackers as much to work with.&lt;BR /&gt;&lt;BR /&gt;mark</description>
      <pubDate>Thu, 16 Dec 2004 09:51:05 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/something-ugly-is-going-on-dos-attack/m-p/4875753#M399666</guid>
      <dc:creator>Mark Greene_1</dc:creator>
      <dc:date>2004-12-16T09:51:05Z</dc:date>
    </item>
    <item>
      <title>Re: Something ugly is going on. DOS attack.</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/something-ugly-is-going-on-dos-attack/m-p/4875754#M399667</link>
      <description>itrc went unpostable last night when I tried to add further details.&lt;BR /&gt;&lt;BR /&gt;I use ipfilter on the hp-ux apache server and iptables on the Linux one.  61.42.141.167 address is a public address but i picked it at random. Some of the inbound traffic is cominng in with my ip address hardcoded inside and I'm not in the mood to provide any assistance to these persons.&lt;BR /&gt;&lt;BR /&gt;More details coming as time permits.&lt;BR /&gt;&lt;BR /&gt;SEP</description>
      <pubDate>Thu, 16 Dec 2004 11:09:29 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/something-ugly-is-going-on-dos-attack/m-p/4875754#M399667</guid>
      <dc:creator>Steven E. Protter</dc:creator>
      <dc:date>2004-12-16T11:09:29Z</dc:date>
    </item>
    <item>
      <title>Re: Something ugly is going on. DOS attack.</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/something-ugly-is-going-on-dos-attack/m-p/4875755#M399668</link>
      <description>Hi SEP,&lt;BR /&gt;&lt;BR /&gt;I've no experience in this kind of situations but when you wrote "after a quick fiber card swap on an rp5450" I remembered one basic principle I apply everytime I have a new problem: &lt;BR /&gt;&lt;BR /&gt;Until when it was fine and what did I changed since that time??&lt;BR /&gt;&lt;BR /&gt;Hope this will help you because I've no other ideas about your issue since I'm not an expert in security...&lt;BR /&gt;&lt;BR /&gt;Kindest Regards,&lt;BR /&gt;&lt;BR /&gt;Eric Antunes</description>
      <pubDate>Thu, 16 Dec 2004 11:09:37 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/something-ugly-is-going-on-dos-attack/m-p/4875755#M399668</guid>
      <dc:creator>Eric Antunes</dc:creator>
      <dc:date>2004-12-16T11:09:37Z</dc:date>
    </item>
    <item>
      <title>Re: Something ugly is going on. DOS attack.</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/something-ugly-is-going-on-dos-attack/m-p/4875756#M399669</link>
      <description>The problem does not effect the card swap. THe card swap was in a box that is thankfully not a public web server. That was sort of a "it was a sunny day on the way to work" type comment. Sorry to distract.&lt;BR /&gt;&lt;BR /&gt;&lt;A href="http://somesite.com/sproxy.php?ip=" target="_blank"&gt;http://somesite.com/sproxy.php?ip=&lt;/A&gt; 61.42.141.168&amp;amp;port=80&lt;BR /&gt;&lt;BR /&gt;I tried that myself in a browser. It did not go to my webserver and displayed some useless information about what ip addresss I'm at where I am currently sitting.&lt;BR /&gt;&lt;BR /&gt;Does anyonw know why or how such stuff could be getting into my apache logs? I see a lot junk as it is, but this is impacting my servers reliability.&lt;BR /&gt;&lt;BR /&gt;SEP</description>
      <pubDate>Thu, 16 Dec 2004 11:27:54 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/something-ugly-is-going-on-dos-attack/m-p/4875756#M399669</guid>
      <dc:creator>Steven E. Protter</dc:creator>
      <dc:date>2004-12-16T11:27:54Z</dc:date>
    </item>
    <item>
      <title>Re: Something ugly is going on. DOS attack.</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/something-ugly-is-going-on-dos-attack/m-p/4875757#M399670</link>
      <description>I need a light : isn't 61.42.141.168 your IP ? What you mean is that you see traffic log from an unknown host to an unknown host ?&lt;BR /&gt;&lt;BR /&gt;Regards,&lt;BR /&gt;&lt;BR /&gt;Fred&lt;BR /&gt;</description>
      <pubDate>Thu, 16 Dec 2004 11:54:07 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/something-ugly-is-going-on-dos-attack/m-p/4875757#M399670</guid>
      <dc:creator>Fred Ruffet</dc:creator>
      <dc:date>2004-12-16T11:54:07Z</dc:date>
    </item>
    <item>
      <title>Re: Something ugly is going on. DOS attack.</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/something-ugly-is-going-on-dos-attack/m-p/4875758#M399671</link>
      <description>Hi Fred,&lt;BR /&gt;&lt;BR /&gt;Its my ip.&lt;BR /&gt;&lt;BR /&gt;I have changed all the records i post to confuse future hackers. &lt;BR /&gt;&lt;BR /&gt;SEP</description>
      <pubDate>Thu, 16 Dec 2004 12:06:59 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/something-ugly-is-going-on-dos-attack/m-p/4875758#M399671</guid>
      <dc:creator>Steven E. Protter</dc:creator>
      <dc:date>2004-12-16T12:06:59Z</dc:date>
    </item>
    <item>
      <title>Re: Something ugly is going on. DOS attack.</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/something-ugly-is-going-on-dos-attack/m-p/4875759#M399672</link>
      <description>So your real problem is that you see GET lines in access.log that does not correspond to your machines ? (tcpdump output seems normal to me). If this is the case, it may have been produced by a buggy DNS, resolving your IP for the wanting domain. Voluntary or not ? Hacker or not ? This is another problem.&lt;BR /&gt;&lt;BR /&gt;Regards,&lt;BR /&gt;&lt;BR /&gt;Fred&lt;BR /&gt;</description>
      <pubDate>Thu, 16 Dec 2004 12:13:37 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/something-ugly-is-going-on-dos-attack/m-p/4875759#M399672</guid>
      <dc:creator>Fred Ruffet</dc:creator>
      <dc:date>2004-12-16T12:13:37Z</dc:date>
    </item>
    <item>
      <title>Re: Something ugly is going on. DOS attack.</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/something-ugly-is-going-on-dos-attack/m-p/4875760#M399673</link>
      <description>Yes Fred.&lt;BR /&gt;&lt;BR /&gt;I don't know where the get is coming from or how its triggered.&lt;BR /&gt;&lt;BR /&gt;the tcpdump data should not be happening because the ip address is blocked.&lt;BR /&gt;&lt;BR /&gt;I would say not voluntary to that questions.&lt;BR /&gt;&lt;BR /&gt;I checked out some of the sites. blazerunner.com is a spyware laden cheap search engine. They don't have the url referenced in the log. Interestingly enough in the DNS realm, the name will not resolve by my browser is able to connect to the site no problem.&lt;BR /&gt;&lt;BR /&gt;SEP</description>
      <pubDate>Thu, 16 Dec 2004 12:21:43 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/something-ugly-is-going-on-dos-attack/m-p/4875760#M399673</guid>
      <dc:creator>Steven E. Protter</dc:creator>
      <dc:date>2004-12-16T12:21:43Z</dc:date>
    </item>
    <item>
      <title>Re: Something ugly is going on. DOS attack.</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/something-ugly-is-going-on-dos-attack/m-p/4875761#M399674</link>
      <description>SEP,&lt;BR /&gt;&lt;BR /&gt;It will : you're not using the same DNS as the client does.&lt;BR /&gt;&lt;BR /&gt;If the http client wants to access this site (blazerunner.com) and the DNS he refers to gives him your IP for this site, he will try to connect, issue the GET statement and you will have those logs. If you want to do the same, you can't, as long as you use a good DNS, refering your site as your correct IP (It's probably your DNS).&lt;BR /&gt;&lt;BR /&gt;Fact is you should find DNS this IP uses. And that is probably a real challenge :-(&lt;BR /&gt;&lt;BR /&gt;Regards,&lt;BR /&gt;&lt;BR /&gt;Fred&lt;BR /&gt;</description>
      <pubDate>Thu, 16 Dec 2004 12:27:50 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/something-ugly-is-going-on-dos-attack/m-p/4875761#M399674</guid>
      <dc:creator>Fred Ruffet</dc:creator>
      <dc:date>2004-12-16T12:27:50Z</dc:date>
    </item>
    <item>
      <title>Re: Something ugly is going on. DOS attack.</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/something-ugly-is-going-on-dos-attack/m-p/4875762#M399675</link>
      <description>I have DNS resolution now on the site in question. I'm setting up my firewall to block all traffic inbound or outbound to that website.&lt;BR /&gt;&lt;BR /&gt;The junk should show up in the log, but no more information will travel to that website.&lt;BR /&gt;&lt;BR /&gt;This is but one of a dozen sites attempting the same type of abuse. So far all it seems to do is open up lots of extra httpd processes, which I control by restarting the httpd server.&lt;BR /&gt;&lt;BR /&gt;Still there is a whole somewhere that needs to be plugged.&lt;BR /&gt;&lt;BR /&gt;I may need to somehow limit where I accept DNS requests from. This is tricky because public websites must resolve their names.&lt;BR /&gt;&lt;BR /&gt;SEP</description>
      <pubDate>Thu, 16 Dec 2004 12:38:36 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/something-ugly-is-going-on-dos-attack/m-p/4875762#M399675</guid>
      <dc:creator>Steven E. Protter</dc:creator>
      <dc:date>2004-12-16T12:38:36Z</dc:date>
    </item>
    <item>
      <title>Re: Something ugly is going on. DOS attack.</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/something-ugly-is-going-on-dos-attack/m-p/4875763#M399676</link>
      <description>Discovered something very interesting.&lt;BR /&gt;&lt;BR /&gt;The firewall was not configured properly.&lt;BR /&gt;&lt;BR /&gt;A tiny little mistake while doing an system upgrade left the firewall database blocking ip addresses input from the internal network instead of the external network.&lt;BR /&gt;&lt;BR /&gt;eth0 needed to be changed to eth1&lt;BR /&gt;lan0 needed to be lan1&lt;BR /&gt;&lt;BR /&gt;So that explains why measures against the input were failing. They were not blocking on the correct NIC.&lt;BR /&gt;&lt;BR /&gt;Will update and possbily close later.&lt;BR /&gt;&lt;BR /&gt;SEP</description>
      <pubDate>Thu, 16 Dec 2004 18:23:13 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/something-ugly-is-going-on-dos-attack/m-p/4875763#M399676</guid>
      <dc:creator>Steven E. Protter</dc:creator>
      <dc:date>2004-12-16T18:23:13Z</dc:date>
    </item>
    <item>
      <title>Re: Something ugly is going on. DOS attack.</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/something-ugly-is-going-on-dos-attack/m-p/4875764#M399677</link>
      <description>As you see, there is always something we did wrong the last time we changed something... :)&lt;BR /&gt;&lt;BR /&gt;Eric Antunes&lt;BR /&gt;</description>
      <pubDate>Fri, 17 Dec 2004 04:01:52 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/something-ugly-is-going-on-dos-attack/m-p/4875764#M399677</guid>
      <dc:creator>Eric Antunes</dc:creator>
      <dc:date>2004-12-17T04:01:52Z</dc:date>
    </item>
    <item>
      <title>Re: Something ugly is going on. DOS attack.</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/something-ugly-is-going-on-dos-attack/m-p/4875765#M399678</link>
      <description>Once again had to develop a custom firewall solution to deal with the problem.&lt;BR /&gt;&lt;BR /&gt;Detected the activity was coming in on port 80.&lt;BR /&gt;&lt;BR /&gt;Blocked output on the attempted outbound ports.&lt;BR /&gt;&lt;BR /&gt;Wrote a program to detect and add blocking entries to ipfilter and iptables to firewall configuration files.&lt;BR /&gt;&lt;BR /&gt;SEP</description>
      <pubDate>Tue, 28 Dec 2004 13:15:21 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/something-ugly-is-going-on-dos-attack/m-p/4875765#M399678</guid>
      <dc:creator>Steven E. Protter</dc:creator>
      <dc:date>2004-12-28T13:15:21Z</dc:date>
    </item>
    <item>
      <title>Re: Something ugly is going on. DOS attack.</title>
      <link>https://community.hpe.com/t5/operating-system-hp-ux/something-ugly-is-going-on-dos-attack/m-p/4875766#M399679</link>
      <description>Thread closed.</description>
      <pubDate>Tue, 28 Dec 2004 13:38:42 GMT</pubDate>
      <guid>https://community.hpe.com/t5/operating-system-hp-ux/something-ugly-is-going-on-dos-attack/m-p/4875766#M399679</guid>
      <dc:creator>Steven E. Protter</dc:creator>
      <dc:date>2004-12-28T13:38:42Z</dc:date>
    </item>
  </channel>
</rss>

