Re: FTP server Service denial attack



On Thu, 18 May 2006 07:09:02 -0700, Jey
<Jey@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote:

Anonymous access is not allowed, smoeone is trying to login as Admin and
diffrent user name. I did check the logs , it only happens for certain time
then stops for a whilr and start again. My IIS server is behind the
corporate firewall .

What else I can do ? Enabling Windows firewall on my server will do any good
?, still i need to allow FTP ( port 21 ) on this server.

You need a firewall that can analyze traffic and block these, or an
IDS.

Jeff




"Jeff Cochran" wrote:

On Wed, 17 May 2006 13:40:02 -0700, Jey
<Jey@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote:

I am running IIS6 FTP on Wondows 2003 box, my serveris under service denial
attack . It come form different IP address all the time. It appears the
attack is from hijacked computers as the IP is allways
different.


How do stop this ?

With a decent IDS or firewall. But then, how do you know it's an
attack and not everyone trying to access your system? Have you looked
at the logs? If you allowed anonymous upload, it's likely you're
serving WaReZ now and generating a ton of requests.

Jeff


.



Relevant Pages

  • detecting a DDOS attack
    ... type of attack on our firewalls, though I've never heard of an attack ... behind the firewall, but I don't administer the firewall itself) don't ... I have been examining web server ... logs, and mail logs, and I scrutinize the output from LogWatch. ...
    (RedHat)
  • Re: Extremely odd thing with Giganews DMCA?
    ... | for Mercury mail and 9001 and 9030 for the Tor node in the Netgear router. ... I had not installed a software firewall yet. ... | Possible I could have left myself open for an attack through those ports. ... | automatically close connections on a persistent attack which the logs show it ...
    (alt.computer.security)
  • Re: Network Traffic Problem
    ... The logs pretty ... > much show that it isn't mail traffic, and our gateway router blocks all the ... > stats are showing the attack as well, so it's definitely from the outside). ... If you don't have a firewall, then you need to get one. ...
    (microsoft.public.win2000.networking)
  • Re: Attacks and Logs
    ... by finely scannings the firewall's logs ... If the log is just a record of "net traffic", finding a missed attack is ... firewall knows what it's doing. ...
    (comp.security.firewalls)
  • Re: Strange WAN Activity
    ... > firewall logs for a possible TCP FIN scan that keeps ... > company's intranet server IP and its port 80 across our ... > My firewall is a Sonicwall Pro 200 and I'm running W2K ... It's difficult to be sure without inspecting the web server for signs of ...
    (microsoft.public.win2000.security)

Quantcast