View previous topic :: View next topic |
Author |
Message |
gortiag Tux's lil' helper
![Tux's lil' helper Tux's lil' helper](/images/ranks/rank_rect_1.gif)
![](images/avatars/12647956484482e7d634397.gif)
Joined: 30 Aug 2005 Posts: 92
|
Posted: Sun Jan 15, 2006 8:50 pm Post subject: Constant IP updates & sudden attack spams when up. |
|
|
Hello!
We run a wireless lan, using d-links router DL-624 and I've just recieved complaints about my gentoo box.
My admin told me that my computer renews its IP adress *every* time somebody else connects to the network.
Also, he told me that as soon as I connect to the network, the router (which is also a firewall) gets spammed by attacks from the outside.. (random ip adresses).
He says he has observed the same pattern several times.
I'm quite the newbie when it comes to Linux, and networking in general..
Does anybody know how I can make it stop renewing the IP every time somebody connects to the router, and can I check if the attacks made from outside the router really is my computers fault, and what can I do about in that case?
Thanks! |
|
Back to top |
|
![](templates/gentoo/images/spacer.gif) |
NeddySeagoon Administrator
![Administrator Administrator](/images/ranks/rank-admin.gif)
![](images/avatars/3946266373f47d606a2db3.jpg)
Joined: 05 Jul 2003 Posts: 54851 Location: 56N 3W
|
Posted: Sun Jan 15, 2006 10:39 pm Post subject: |
|
|
gortiag,
Your wirless interface needs to be in managed mode, not ad-hoc mode. You must not be running a DHCP server on your gentoo either.
I'm not sure what 'outside' means for wireless. Everything is outside. Is the attack comming down the wired interface on the firewall?
Get tcpdump and record traffic on your wireless interface. It will be easy to spot the things your admin claims are happening.
See if you can work with your system admn to spot the attacking IPs _________________ Regards,
NeddySeagoon
Computer users fall into two groups:-
those that do backups
those that have never had a hard drive fail. |
|
Back to top |
|
![](templates/gentoo/images/spacer.gif) |
gortiag Tux's lil' helper
![Tux's lil' helper Tux's lil' helper](/images/ranks/rank_rect_1.gif)
![](images/avatars/12647956484482e7d634397.gif)
Joined: 30 Aug 2005 Posts: 92
|
Posted: Mon Jan 16, 2006 12:11 pm Post subject: |
|
|
Thanks for the reply!
My wireless interface is in managed mode, and I'm not running a DHCP server on my box - only the client.
I'm pretty sure that he meant that the attacks were coming from outside
of our network, ie not my computer or anything "behind" the router, but
rather the big, big internet out there.
It looks like this:
--------------Router---------------
---------------- || -----------------
-- Our -------- || ----- The big---
- Network --- || ------Internet -
---------------- || -----------------
Sorry about the drawing, but I like to draw. ![Cool 8)](images/smiles/icon_cool.gif) |
|
Back to top |
|
![](templates/gentoo/images/spacer.gif) |
NeddySeagoon Administrator
![Administrator Administrator](/images/ranks/rank-admin.gif)
![](images/avatars/3946266373f47d606a2db3.jpg)
Joined: 05 Jul 2003 Posts: 54851 Location: 56N 3W
|
Posted: Mon Jan 16, 2006 8:28 pm Post subject: |
|
|
gortiag,
OK, so far so good. Drawing is easier if you use the tages to get a fixed space font.
and use Preview to fix the spaces.
Your next step is to and see whats coming and going on your interface. _________________ Regards,
NeddySeagoon
Computer users fall into two groups:-
those that do backups
those that have never had a hard drive fail. |
|
Back to top |
|
![](templates/gentoo/images/spacer.gif) |
gortiag Tux's lil' helper
![Tux's lil' helper Tux's lil' helper](/images/ranks/rank_rect_1.gif)
![](images/avatars/12647956484482e7d634397.gif)
Joined: 30 Aug 2005 Posts: 92
|
Posted: Tue Jan 17, 2006 5:17 pm Post subject: |
|
|
Thanks for the reply.
I emerged tcpdump, but when I don't run an application (like mozilla or irssi), there is no output, not even with the -vv flag.. (that's a good sign, right?)
So, what's the next step?
EDIT:
So, uh, he sent me over this log, or made the router send me the log or whatever. It spammed my mailbox with four messages... (I've got this really annoying admin)
But I don't get much out of it, and obviously neither did he.
This is *probably* the ip-renewal thingie he mentioned...? I've got *no* clue at all, really.. He could've sent me an essay in ancient greek.. -.-
Rovtomte is our essid asus-p4pe is somebody elses cpu and MPU is mine.
Quote: | Jan/17/2006 18:20:15
SYN Flood Attack Detect Packet Dropped
Jan/17/2006 18:07:00
Wireless PC connected 00-0f-3d-86-bc-5f
Jan/17/2006 18:00:04
SMTP: send mail succeed
Jan/17/2006 18:00:02
SYN Flood Attack Detect Packet Dropped
Jan/17/2006 17:59:50
SMTP: send mail succeed
Jan/17/2006 17:59:49
SYN Flood Attack Detect Packet Dropped
Jan/17/2006 17:59:47
SMTP: send mail succeed
Jan/17/2006 17:59:45
SYN Flood Attack Detect Packet Dropped
Jan/17/2006 17:59:43
SMTP: send mail succeed
Jan/17/2006 17:59:42
SYN Flood Attack Detect Packet Dropped
Jan/17/2006 17:59:41
SMTP: send mail succeed
Jan/17/2006 17:59:39
SYN Flood Attack Detect Packet Dropped
Jan/17/2006 17:49:57
DHCP lease IP 192.168.0.104 to MPU 00-0f-3d-86-bc-5f
Jan/17/2006 17:49:56
Wireless PC connected 00-0f-3d-86-bc-5f
Jan/17/2006 17:18:17
DHCP lease IP 192.168.0.101 to asus-p4pe 00-0f-3d-ac-4e-a5
Jan/17/2006 17:18:16
Wireless PC connected 00-0f-3d-ac-4e-a5
Jan/17/2006 17:03:28
DHCP lease IP 192.168.0.101 to asus-p4pe 00-0f-3d-ac-4e-a5
Jan/17/2006 17:03:27
Wireless PC connected 00-0f-3d-ac-4e-a5
Jan/17/2006 17:03:23
Wireless PC connected 00-0f-3d-ac-4e-a5
Jan/17/2006 14:43:45
DHCP lease IP 192.168.0.101 to asus-p4pe 00-0f-3d-ac-4e-a5
Jan/17/2006 14:43:40
Wireless PC connected 00-0f-3d-ac-4e-a5
Jan/17/2006 08:33:25
DHCP lease IP 192.168.0.101 to asus-p4pe 00-0f-3d-ac-4e-a5
Jan/17/2006 08:33:22
Wireless PC connected 00-0f-3d-ac-4e-a5
Jan/17/2006 08:32:13
System started
Jan/17/2006 08:32:13
AP 2.4GHz mode Ready. Channel : 6 TxRate : best SSID : Rovtomte
Jan/17/2006 08:32:13
Access point: Rovtomte started at channel 6. |
Know what this means or what it is? ![Smile :)](images/smiles/icon_smile.gif) |
|
Back to top |
|
![](templates/gentoo/images/spacer.gif) |
|
|
You cannot post new topics in this forum You cannot reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum You cannot vote in polls in this forum
|
|