Likes Likes:  0
Resultaten 1 tot 2 van de 2
Geen
  1. #1
    Abuse-melding, server gebruikt voor DDos ??
    geregistreerd gebruiker
    9 Berichten
    Ingeschreven
    01/01/14

    Locatie
    Nijeveen

    Post Thanks / Like
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    0 Berichten zijn liked



    Thread Starter

    Abuse-melding, server gebruikt voor DDos ??

    Ik kreeg vanmorgen een mailtje binnen met onderstaande inhoud;

    ________________________________________
    Onderwerp:............................ Exploitable chargen service used for an attack: 178.18.134.18
    IP adres:............................. 178.18.134.18
    Verzoekende partij:................... NFOservers.com DDoS notifier
    E-Mailadres:.......................... ddos-response@nfoservers.com
    Datum:................................ 2014-09-28 18:44:00
    ________________________________________

    Melding:

    It appears that a public \"chargen\" service on your network, running on IP address 178.18.134.18, participated in a large-scale attack against a customer of ours, generating large UDP responses to spoofed probes that claimed to be from the attack target.

    chargen is an old testing service that generates large quantities of traffic with only a small request required. It is commonly enabled by default on old printers and other connected appliances, but it has no useful purpose over the open internet.

    Please block UDP port 19 (inbound and outbound) at your network edge, as this should stop these chargen attacks without blocking legitimate traffic. If the endpoint device that generated this traffic is configurable, please further investigate whether it is running a chargen service (and disable it, if so) -- commonly exploited devices include Cisco hardware that has \"udp small servers\" mistakenly enabled, old printers, old UNIX boxes with \"chargen\" running under inetd, and Windows boxes with the \"Simple TCP/IP services\" package installed. Also, it is worth checking if it is a machine that has been compromised, as some malware directly generates port 19 traffic, simulating chargen, and in this way masks its presence.

    If you are an ISP, please also look at your network configuration and make sure that you do not allow spoofed traffic (that pretends to be from external IP addresses) to leave the network. Hosts that allow spoofed traffic make possible this type of attack.

    Example responses from your host during this attack are given below.
    Timestamps (far left) are PDT (UTC-7), and the date is 2014-09-28.

    09:39:26.046085 IP 178.18.134.18.19 > 162.248.88.x.40790: UDP, length 1024
    0x0000: 4500 041c 0000 4000 3511 0df6 b212 8612 E.....@.5.......
    0x0010: a2f8 58be 0013 9f56 0408 ad87 3536 3738 ..X....V....5678
    0x0020: 393a 3b3c 3d3e 3f40 4142 4344 4546 4748 9:;<=>?@ABCDEFGH
    0x0030: 494a 4b4c 4d4e 4f50 5152 5354 5556 5758 IJKLMNOPQRSTUVWX
    0x0040: 595a 5b5c 5d5e 5f60 6162 6364 6566 6768 YZ[\\]^_`abcdefgh
    0x0050: 696a ij
    09:39:26.421859 IP 178.18.134.18.19 > 162.248.88.x.40790: UDP, length 1024
    0x0000: 4500 041c 0000 4000 3511 0df6 b212 8612 E.....@.5.......
    0x0010: a2f8 58be 0013 9f56 0408 d583 2223 2425 ..X....V....\"#$%
    0x0020: 2627 2829 2a2b 2c2d 2e2f 3031 3233 3435 &\'()*+,-./012345
    0x0030: 3637 3839 3a3b 3c3d 3e3f 4041 4243 4445 6789:;<=>?@ABCDE
    0x0040: 4647 4849 4a4b 4c4d 4e4f 5051 5253 5455 FGHIJKLMNOPQRSTU
    0x0050: 5657 VW
    09:39:26.592123 IP 178.18.134.18.19 > 162.248.88.x.40790: UDP, length 1024
    0x0000: 4500 041c 0000 4000 3511 0df6 b212 8612 E.....@.5.......
    0x0010: a2f8 58be 0013 9f56 0408 ea20 4f50 5152 ..X....V....OPQR
    0x0020: 5354 5556 5758 595a 5b5c 5d5e 5f60 6162 STUVWXYZ[\\]^_`ab
    0x0030: 6364 6566 6768 696a 6b6c 6d6e 6f70 7172 cdefghijklmnopqr
    0x0040: 7374 7576 7778 797a 7b7c 7d21 2223 2425 stuvwxyz{|}!\"#$%
    0x0050: 2627 &\'
    09:39:26.762364 IP 178.18.134.18.19 > 162.248.88.x.40790: UDP, length 1024
    0x0000: 4500 041c 0000 4000 3511 0df6 b212 8612 E.....@.5.......
    0x0010: a2f8 58be 0013 9f56 0408 bdc8 7c7d 2122 ..X....V....|}!\"
    0x0020: 2324 2526 2728 292a 2b2c 2d2e 2f30 3132 #$%&\'()*+,-./012
    0x0030: 3334 3536 3738 393a 3b3c 3d3e 3f40 4142 3456789:;<=>?@AB
    0x0040: 4344 4546 4748 494a 4b4c 4d4e 4f50 5152 CDEFGHIJKLMNOPQR
    0x0050: 5354 ST
    09:39:26.935999 IP 178.18.134.18.19 > 162.248.88.x.40790: UDP, length 1024
    0x0000: 4500 041c 0000 4000 3511 0df6 b212 8612 E.....@.5.......
    0x0010: a2f8 58be 0013 9f56 0408 83ba 3c3d 3e3f ..X....V....<=>?
    0x0020: 4041 4243 4445 4647 4849 4a4b 4c4d 4e4f @ABCDEFGHIJKLMNO
    0x0030: 5051 5253 5455 5657 5859 5a5b 5c5d 5e5f PQRSTUVWXYZ[\\]^_
    0x0040: 6061 6263 6465 6667 6869 6a6b 6c6d 6e6f `abcdefghijklmno
    0x0050: 7071 pq
    09:39:27.106387 IP 178.18.134.18.19 > 162.248.88.x.40790: UDP, length 1024
    0x0000: 4500 041c 0000 4000 3511 0df6 b212 8612 E.....@.5.......
    0x0010: a2f8 58be 0013 9f56 0408 1d54 5b5c 5d5e ..X....V...T[\\]^
    0x0020: 5f60 6162 6364 6566 6768 696a 6b6c 6d6e _`abcdefghijklmn
    0x0030: 6f70 7172 7374 7576 7778 797a 7b7c 7d21 opqrstuvwxyz{|}!
    0x0040: 2223 2425 2627 2829 2a2b 2c2d 2e2f 3031 \"#$%&\'()*+,-./01
    0x0050: 3233 23

    (The final octet of our customer\'s IP address is masked in the above output because some automatic parsers become confused when multiple IP addresses are included. The value of that octet is \"190\".)

    -John
    President
    Nuclearfallout, Enterprises, Inc. (NFOservers.com)

    (We\'re sending out so many of these notices, and seeing so many auto-responses, that we can\'t go through this email inbox effectively. If you have follow-up questions, please contact us at noc@nfoe.net.)
    Volgens de host (colocatie) moet ik mijn RAC updaten.
    Gebeurt dit inderdaad middels remote access?
    Is het dan een 'poort' kwestie, heeft 'men' toegang tot mijn server gekregen door mijn ww te over-rulen?

    Ik snap deze dus even duidelijk niet

  2. #2
    Abuse-melding, server gebruikt voor DDos ??
    Programmeur / Hoster
    3.952 Berichten
    Ingeschreven
    20/06/06

    Locatie
    Wijlre

    Post Thanks / Like
    Mentioned
    28 Post(s)
    Tagged
    0 Thread(s)
    647 Berichten zijn liked


    Naam: John Timmer
    Bedrijf: SystemDeveloper.NL
    Functie: Eigenaar
    URL: www.systemdeveloper.nl
    KvK nummer: 14083066
    View johntimmer's profile on LinkedIn

    Installeer eens een firewall. Dit soort poorten hebben totaal geen nut om open te staan voor de buitenwereld.
    SystemDeveloper.NL - 64BitsWebhosting.EU : Softwareontwikkeling & Hosting freaks

Webhostingtalk.nl

Contact

  • Rokin 113-115
  • 1012 KP, Amsterdam
  • Nederland
  • Contact
© Copyright 2001-2026 Webhostingtalk.nl.
Web Statistics