Gentoo Forums
Gentoo Forums
Gentoo Forums
Quick Search: in
Constant IP updates & sudden attack spams when up.
View unanswered posts
View posts from last 24 hours

 
Reply to topic    Gentoo Forums Forum Index Networking & Security
View previous topic :: View next topic  
Author Message
gortiag
Tux's lil' helper
Tux's lil' helper


Joined: 30 Aug 2005
Posts: 92

PostPosted: Sun Jan 15, 2006 8:50 pm    Post subject: Constant IP updates & sudden attack spams when up. Reply with quote

Hello!

We run a wireless lan, using d-links router DL-624 and I've just recieved complaints about my gentoo box.

My admin told me that my computer renews its IP adress *every* time somebody else connects to the network.

Also, he told me that as soon as I connect to the network, the router (which is also a firewall) gets spammed by attacks from the outside.. (random ip adresses).
He says he has observed the same pattern several times.

I'm quite the newbie when it comes to Linux, and networking in general..

Does anybody know how I can make it stop renewing the IP every time somebody connects to the router, and can I check if the attacks made from outside the router really is my computers fault, and what can I do about in that case?

Thanks!
Back to top
View user's profile Send private message
NeddySeagoon
Administrator
Administrator


Joined: 05 Jul 2003
Posts: 54851
Location: 56N 3W

PostPosted: Sun Jan 15, 2006 10:39 pm    Post subject: Reply with quote

gortiag,

Your wirless interface needs to be in managed mode, not ad-hoc mode. You must not be running a DHCP server on your gentoo either.

I'm not sure what 'outside' means for wireless. Everything is outside. Is the attack comming down the wired interface on the firewall?

Get tcpdump and record traffic on your wireless interface. It will be easy to spot the things your admin claims are happening.
See if you can work with your system admn to spot the attacking IPs
_________________
Regards,

NeddySeagoon

Computer users fall into two groups:-
those that do backups
those that have never had a hard drive fail.
Back to top
View user's profile Send private message
gortiag
Tux's lil' helper
Tux's lil' helper


Joined: 30 Aug 2005
Posts: 92

PostPosted: Mon Jan 16, 2006 12:11 pm    Post subject: Reply with quote

Thanks for the reply!

My wireless interface is in managed mode, and I'm not running a DHCP server on my box - only the client.

I'm pretty sure that he meant that the attacks were coming from outside
of our network, ie not my computer or anything "behind" the router, but
rather the big, big internet out there.

It looks like this:

--------------Router---------------
---------------- || -----------------
-- Our -------- || ----- The big---
- Network --- || ------Internet -
---------------- || -----------------

Sorry about the drawing, but I like to draw. 8)
Back to top
View user's profile Send private message
NeddySeagoon
Administrator
Administrator


Joined: 05 Jul 2003
Posts: 54851
Location: 56N 3W

PostPosted: Mon Jan 16, 2006 8:28 pm    Post subject: Reply with quote

gortiag,

OK, so far so good. Drawing is easier if you use the
Code:
[code] [/code]
tages to get a fixed space font.
and use Preview to fix the spaces.

Your next step is to
Code:
emerge tcpdump
and see whats coming and going on your interface.
_________________
Regards,

NeddySeagoon

Computer users fall into two groups:-
those that do backups
those that have never had a hard drive fail.
Back to top
View user's profile Send private message
gortiag
Tux's lil' helper
Tux's lil' helper


Joined: 30 Aug 2005
Posts: 92

PostPosted: Tue Jan 17, 2006 5:17 pm    Post subject: Reply with quote

Thanks for the reply.

I emerged tcpdump, but when I don't run an application (like mozilla or irssi), there is no output, not even with the -vv flag.. (that's a good sign, right?)

So, what's the next step? :)

EDIT:

So, uh, he sent me over this log, or made the router send me the log or whatever. It spammed my mailbox with four messages... (I've got this really annoying admin)
But I don't get much out of it, and obviously neither did he.

This is *probably* the ip-renewal thingie he mentioned...? I've got *no* clue at all, really.. He could've sent me an essay in ancient greek.. -.-

Rovtomte is our essid asus-p4pe is somebody elses cpu and MPU is mine.

Quote:
Jan/17/2006 18:20:15
SYN Flood Attack Detect Packet Dropped
Jan/17/2006 18:07:00
Wireless PC connected 00-0f-3d-86-bc-5f
Jan/17/2006 18:00:04
SMTP: send mail succeed
Jan/17/2006 18:00:02
SYN Flood Attack Detect Packet Dropped
Jan/17/2006 17:59:50
SMTP: send mail succeed
Jan/17/2006 17:59:49
SYN Flood Attack Detect Packet Dropped
Jan/17/2006 17:59:47
SMTP: send mail succeed
Jan/17/2006 17:59:45
SYN Flood Attack Detect Packet Dropped
Jan/17/2006 17:59:43
SMTP: send mail succeed
Jan/17/2006 17:59:42
SYN Flood Attack Detect Packet Dropped
Jan/17/2006 17:59:41
SMTP: send mail succeed
Jan/17/2006 17:59:39
SYN Flood Attack Detect Packet Dropped
Jan/17/2006 17:49:57
DHCP lease IP 192.168.0.104 to MPU 00-0f-3d-86-bc-5f
Jan/17/2006 17:49:56
Wireless PC connected 00-0f-3d-86-bc-5f
Jan/17/2006 17:18:17
DHCP lease IP 192.168.0.101 to asus-p4pe 00-0f-3d-ac-4e-a5
Jan/17/2006 17:18:16
Wireless PC connected 00-0f-3d-ac-4e-a5
Jan/17/2006 17:03:28
DHCP lease IP 192.168.0.101 to asus-p4pe 00-0f-3d-ac-4e-a5
Jan/17/2006 17:03:27
Wireless PC connected 00-0f-3d-ac-4e-a5
Jan/17/2006 17:03:23
Wireless PC connected 00-0f-3d-ac-4e-a5
Jan/17/2006 14:43:45
DHCP lease IP 192.168.0.101 to asus-p4pe 00-0f-3d-ac-4e-a5
Jan/17/2006 14:43:40
Wireless PC connected 00-0f-3d-ac-4e-a5
Jan/17/2006 08:33:25
DHCP lease IP 192.168.0.101 to asus-p4pe 00-0f-3d-ac-4e-a5
Jan/17/2006 08:33:22
Wireless PC connected 00-0f-3d-ac-4e-a5
Jan/17/2006 08:32:13
System started
Jan/17/2006 08:32:13
AP 2.4GHz mode Ready. Channel : 6 TxRate : best SSID : Rovtomte
Jan/17/2006 08:32:13
Access point: Rovtomte started at channel 6.


Know what this means or what it is? :)
Back to top
View user's profile Send private message
Display posts from previous:   
Reply to topic    Gentoo Forums Forum Index Networking & Security All times are GMT
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum