Grokbase
Topics Posts Groups | in
x
[ help ]

Re: SYD flood dropped on Sendmail (centos 4.x)

View PostFlat  Thread  Threaded | < Prev - Next >
Les Mikesell Re: [CentOS] SYD flood dropped on Sendmail (centos 4.x)
| +1 vote
[ Profile | Reply to group ] [ Flat  Thread  Threaded ]
Kai Schaetzl wrote:
> Chris Heiner wrote on Thu, 20 Nov 2008 08:48:50 -0800:
>
>> My firewall seems to block an attack my Centos / Sendmail boxes on port 110.
>
> port 110 is your POP server, probably dovecot.
>
>> These servers require a reboot after each attack.
>
> Because of what?
>
>> My firewall says it's
>> blocked?
>
> I don't see this statement in your logs. How/where does it say this?
>
>> Do I need to patch something on sendmail? Or is my firewall not
>> doing its job (Sonicwall)? This is not the first time this has happened.
>
> SYN floods are not unusual, even if it is not an attack.
> What or if you want to do something depends on your situation.

If you have a popular server you can get what appear to be syn floods
from broken asymmetrical routing or bad firewall settings that permit
what would ordinarily be a normal number of client connection requests
to reach you but keep your response from getting back.  So the clients 
sit and retry, hammering you with syn's.

--
   Les Mikesell
    [email protected: lesmik...@gmail.com]

_______________________________________________
CentOS mailing list
[email protected: C...@centos.org]
http://lists.centos.org/mailman/listinfo/centos

Thread : SYD flood dropped on Sendmail (centos 4.x)
1)
Chris Heiner This is a multi-part message in MIME format. Content-Type: multipart/alternative;...
2)
Kai Schaetzl Chris Heiner wrote on Thu, 20 Nov 2008 08:48:50 -0800: port 110 is your POP server, probably...
3)
Chris Heiner What would you like to know about my situation? I have 6 servers running Centos 4.x and every time...
4)
Kai Schaetzl Chris, you still didn't answer *why* you have to reboot them. What exactly is the symptom that...
5)
Chris Heiner I get complaints about "the servers asking for username and password". I started test@ accounts all...
6)
Filipe Brandenburger Hi Chris, You still did not give enough detail of what happens on the machine when the problem...
7)
Kai Schaetzl Chris Heiner wrote on Thu, 20 Nov 2008 13:43:44 -0800: from your users or what? Of course, they may...
8)
Scott Silva This is an OpenPGP/MIME signed message (RFC 2440 and 3156) --==============38641819=Content-Type:...
9)
Glenn Watch out for this gotcha! The Dovecot version 1.0.x that comes with CentOS 5.x is much better and...
10)
Chris Heiner Good advice! Thanks for helping without the "corrective elitist attitude"!
11)
Kai Schaetzl Scott Silva wrote on Thu, 20 Nov 2008 16:03:04 -0800: The dovecot in CentOS 5 exhibits the same...
12)
Scott Silva This is an OpenPGP/MIME signed message (RFC 2440 and 3156) --==============00134360=Content-Type:...
13)
Scott Silva This is an OpenPGP/MIME signed message (RFC 2440 and 3156) --==============80080849=Content-Type:...
14)
Chris Heiner Good advice! I will upgrade the Dovecot as it sounds like a good idea. I was also considering just...
15)
Chris Heiner 11/20/2008 02:53:04.864 - SYN flood attack dropped - 11/20/2008 03:08:04.864 - SYN flood attack...
16)
Les Mikesell If you have a popular server you can get what appear to be syn floods from broken asymmetrical...
17)
Chris Heiner Les, I have had that issue before with high traffic users and you are correct, but I think this may...
18)
John Hinton If these are to bogus email addresses, you might try letting sendmail itself throttle the attacks....
19)
John Hinton Duh... obviously I can't read. Sorry. John Hinton
spacer
View PostFlat  Thread  Threaded | < Prev - Next >