Networking Forums

Networking Forums > Computer Networking > Windows Networking > Are we sending DDOS?

Reply
Thread Tools Display Modes

Are we sending DDOS?

 
 
James
Guest
Posts: n/a

 
      05-23-2007, 04:48 PM
We got an email from our ISP saying we are sending out a Ddos attack.
How would one go about tracing this?
All our outbound connections are going through an ISA 2000 server.

Any suggestions for a newb?


 
Reply With Quote
 
 
 
 
S. Pidgorny
Guest
Posts: n/a

 
      05-24-2007, 10:07 AM
Monitor external interface of ISA Server for a while to find out what's
outgoing. Use a NIDS (like Snort, which you can run on ISA) to alert on
potential probes from within your network.

Implement restrictive firewall rules and analyse Web requests originating
from your clients. pay special attention to those issued when the user
wasn't there

Ask the ISP for additional information - that is, how they detected the
DDoS, and suggestions as for rectification of the situation. Offer full
cooperation in exchange for them doing some of the above tasks for you.

--
Svyatoslav Pidgorny, MS MVP - Security, MCSE
-= F1 is the key =-

* http://sl.mvps.org * http://msmvps.com/blogs/sp *

"James" <(E-Mail Removed)> wrote in message
news:(E-Mail Removed)...
> We got an email from our ISP saying we are sending out a Ddos attack.
> How would one go about tracing this?
> All our outbound connections are going through an ISA 2000 server.
>
> Any suggestions for a newb?
>
>



 
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Potential email DDoS vuln on Netgear Rangemax routers.. testing_h@yahoo.com Network Routers 0 06-08-2008 10:51 AM
sending an arp... matthuwiler@gmail.com Linux Networking 0 06-29-2007 05:29 PM
MAC address and Wifi DDoS aljuhani Wireless Internet 4 04-11-2007 07:54 PM
Lycos launches DDOS screen saver to attack spamvertised sites Phil Thompson Broadband 0 11-29-2004 04:13 PM
Netgear Router DDOS Problem Klaatu Linux Networking 0 09-01-2003 11:49 PM



1 2 3 4 5 6 7 8 9 10 11