Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Re: pings |
|---|---|
| Date: | Wed, 29 Dec 2004 08:17:41 -0600 |
In 1 day I have seen 288 different instances of blocked packets in my firewall on that same day I have seen 46 items in my IDS. Mostly the MSQL worm propagation. If I keep this thought that I get on average the same amount of "attacks" on a daily basis and use 100 days to keep the math simple I see that I have had 28800 firewall hits and 4600 IDS hits. Now, I have a DHCP network on a local ISP and I do not have a domain name registered.
Since 18th Feb. 2004, up until now, I've had 188000+ alerts. As it stands, 69% of these are ICMP packets. In the past, when I first installed snort on the firewall, most were TCP connects. Now the majority is ICMPs.
This gives you about 596 "attacks" a day. I have a friend that runs a
personal network and website that gets attacks likes this as well I
think his number is MUCH higher than this.
consider the following:
- if you have a registered domain name your "attacks" are going
to rise.
- If you have a static IP address your "attacks" are going to
be increased even more.
- If you are on a hostile network /cable modem/ or in Internet
in general you are going to see more attacks.
Question is the network of concern the one that you sent this message
from? (DO NOT ANSWER THAT). :) A Jewellery site in Hong Kong. Are you
going to have E-commerce available? IF so it sounds like the stakes are
rising for having packet hits. was the IP address in question always
yours or did somebody have it prior?
Bottom like is your network sluggish because of this?
Does your up-line provider use ping to see if your network is alive?
Was somebody else setup on this IP that had a ping check to see if the
system was alive?
You are in the hundreds a day group for the ping... Do you see anything
else more serious in your logs?
Where are the packets originating from?
--
Leif
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| Previous by Date: | Re: Simple Firewall, Edel SM |
|---|---|
| Next by Date: | RE: Simple Firewall, Philip Wagenaar |
| Previous by Thread: | Re: pings, cc |
| Next by Thread: | Re: pings, Rodrigo Ramos |
| Indexes: | [Date] [Thread] [Top] [All Lists] |