I just encountered a most inventive DOS attack on an HP-9000 and two linux servers.
Basically it went like this:
There were samba authentication attempts, which all failed, but generated little log files.
ipaddress.log in the directory on /var where samba stores its logs.
Honestly, I wasn't aware that samba kept logs like this, but I never bothered to look before.
There were hundreds of thousands of attempts, each creating log files. Several of the attempts managed to create rather huge log files.
So /var filled up and the systems stop accepting mail, which is how it came to my attention.
Actions taken thus far:
1) Blocked Port 137,138,139(netbios) and 901(swat) on the firewall, public Internet NIC card.
2)Analyzed the log files.
Questions:
1) Has anyone seen this before?
2) What additional security measures do I need to take? I have no need to provide samba services outside my private network.
3) General suggestions.
SEP
Steven E Protter
Owner of ISN Corporation
http://isnamerica.com
http://hpuxconsulting.com
Sponsor: http://hpux.ws
Twitter: http://twitter.com/hpuxlinux
Founder http://newdatacloud.com