Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Probing for open proxies with CONNECT » Seeing similar probes
Search Topic:
Uniqs:
70
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Post a:
Post a:
AuthorAll Replies


state
stress magnet
Premium,Mod
join:2002-02-08
Hampton, VA
clubs:

Host:
Webhosting
Sonic.net
UK Broadband
Washington & Balti..
UK Chat
Seeing similar probes

I started seeing something similar a few days ago, but hadn't had a chance to really dig into it - it was more of a nuisance than anything else since 404s were being returned to the requester:


The logs show somewhere in the neighborhood of 40-50 entries per day from this particular IP address, sequentially walking the IPs that were assigned to the machine - each GET request with it's own unique hash.

After adding a rule to iptables I saw it send a dozen or so ping packets to see if the host was up:


And then nothing. So far. With so many script kiddies running what would appear to be "out-of-the-box" scripts against large netblocks, it sometimes makes me wonder if I should follow in the footsteps of CNN and the like and simply discard inbound ICMP requests..

mikenolan7
Premium
join:2005-06-07
Torrance, CA

Think twice before dropping traffic. I'm just a home user, but I have a pretty good-sized network I experiment with here (15 machines +/-). I run zero externally accessible services, but I'm on a cable modem and live in LA. The number of attacks is hard to believe (I average anywhere between one every 3 to 10 seconds). I used to just drop it all, but I found when I rejected everything instead, the number of attacks dropped by about 70%. I run strict rate limits on the rejections so no one can get much benefit from using my address as part of a reverse DDOS, but I haven't seen that even tried, yet (using my address anyway).

The only explanation I can come up with is that the automated attacks move on when they get a rejection, but try a few more times if nothing comes back - possibly hoping that the lack of a rejection indicates other "misconfigurations". RoadRunners arp blasters pretty much tell anyone with a clue what IP's are in use at any time.
Forums » Probing for open proxies with CONNECT


Thursday, 10-Dec 06:41:54 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10 years online! © 1999-2009 dslreports.com.
page compression OFF
Most commented news this week
· [200] Sprint Sued For Distracted Driving Death
· [117] AT&T Launching New 24 Mbps U-Verse Tier
· [82] 3G Network Test Says AT&T Is Tops
· [72] Mediacom Unveils 105 Mbps Pricing
· [67] AT&T Hints At Usage-Based iPhone Data Pricing
· [66] Sprint Poised For A Turnaround?
· [66] WPA Cracker: Test WPA-PSK Networks In 20 Minutes
· [51] The Future Of Wi-Fi Is Bright
· [47] Site Leaks Yahoo, Verizon Fed Data Share Pricing
· [45] Microwaving Your Innards Is Not 'Extreme'
Most people now reading
· Windows 7 boot manager editing questions [Microsoft Help]
· Cross Server Dungeon Experience [World of Warcraft]
· Adobe Flash Player version 10.0.42.34 [Security]
· Connecting to Google Voice Via SIP [VOIP Tech Chat]
· IMG 1.7 (IMG Updates and Discussion) [Verizon FIOS TV]
· [How to] Install Asterisk on an Asus WL-520GU router [VOIP Tech Chat]
· 3.x Feral Druid - Bear Tanking Guide [World of Warcraft]
· The aftermath [World of Warcraft]
· Opening a file download dialog from a JavaScript function. [Webmasters and Developers]
· SB6120 Firmware update [Comcast HSI]