Login Register






The stories and information posted here are artistic works of fiction and falsehood. Only a fool would take anything posted here as fact.
Thread Rating:
  • 0 Vote(s) - 0 Average


Please confirm this is a ddos attack [Logs] filter_list
Author
Message
Please confirm this is a ddos attack [Logs] #1
Someone have attacked my Css server which is running on my dedicated server at home.

I got a picture of the logs, and in my eyes it looks like a ddos.

[Image: pwOW0V1.png]

[Image: 7MFLH30.png]

The port i use for the server is 27015.
[Image: izAuzcHJUuq8G.gif]

Reply

RE: Please confirm this is a ddos attack [Logs] #2
Confirmed from here sir.
RAT Expert - Need help? PM me, Subject "RAT Help"

Reply

RE: Please confirm this is a ddos attack [Logs] #3
In wireshark:
src ip target ip protocol src port>target port

So ... something on 192.168.2.104 is sending all that trafic randomly, this looks similar to
nmap -sS 192.168.1.x but random targets...

So is it DDoS? I don't think so...

[edit] But I am still not sure, could you please share the cap file with us? (in case you still have it)...

Thanks
[Image: wvBFmA5.png]

Reply

RE: Please confirm this is a ddos attack [Logs] #4
(02-10-2014, 01:00 AM)Ligeti Wrote: In wireshark:
src ip target ip protocol src port>target port

So ... something on 192.168.2.104 is sending all that trafic randomly, this looks similar to
nmap -sS 192.168.1.x but random targets...

So is it DDoS? I don't think so...

[edit] But I am still not sure, could you please share the cap file with us? (in case you still have it)...

Thanks

You're right... I dont think he's being ddos'd directly. The source ip and source port of the transmissions are of his server... the destination are all external. they're also all different. its not a targetted attack on someone so i would rule out being used as slave to DDoS.

There is definitely something suspicious. I dont know anything about a CSS server though so I cant say much about it, but perhaps someone has compromised it? or its misconfigured in some way? that many consecutive rst packets seems to be odd though. something is clearly not right

Reply

RE: Please confirm this is a ddos attack [Logs] #5
Thank you Geoff... I would really love to know more about this case, but seems that Nille is busy now to answer our quetions.

I can create the same senario using only hping by the way! But I don't see the point... Did it affect the network's performance significantly? (did I spell that right) lol
[Image: wvBFmA5.png]

Reply

RE: Please confirm this is a ddos attack [Logs] #6
(02-10-2014, 03:21 AM)Ligeti Wrote: Thank you Geoff... I would really love to know more about this case, but seems that Nille is busy now to answer our quetions.

I can create the same senario using only hping by the way! But I don't see the point... Did it affect the network's performance significantly? (did I spell that right) lol

LOL im slightly impressed. I dont think ive ever heard anyone else reference hping before. its a useful little tool i rank up there with netcat and nmap but that type of hacking is generally out of the scope of the "hacker" communities like this lol.

Reply

RE: Please confirm this is a ddos attack [Logs] #7
Sure i can share the file with you guys..

But it's a 1GB :/

https://dl.dropboxusercontent.com/u/2640...dos.pcapng
[Image: izAuzcHJUuq8G.gif]

Reply

RE: Please confirm this is a ddos attack [Logs] #8
@Geoff thanks for the "slight" compliment Smile

@Nille it's OK :Not-Amused: *joking*

Thanks for sharing anyway Smile
[Image: wvBFmA5.png]

Reply







Users browsing this thread: 3 Guest(s)