PDA

View Full Version : Ping flooding


Thelemac
08-05-01, 01:34 AM
What's the point? I've been getting flooded for about an hour now, and I only noticed cause I was getting activity that wasn't going through to my LAN...

No slowdowns at all. Weird.

dugans
08-06-01, 12:40 AM
I noticed the same thing: I've gotten about 250 this evening!

I chatted with my ISP (at&t) and they think it's code red.

I went through my log and http'd to 100 ips 'cause I'm ****ed off about it! I got 13 web hits- 1 secure webserver, 1 stupid one, 1 email list site, and the rest were simple pages, or probably default installs that aren't in use- "under construction" or defaultt IIS page.

It looks to me like it is code red mostly, but the email list site and the secure site BOTH make me wonder!

Thelemac
08-06-01, 12:45 AM
Hmm...hadn't thought to try that...probably because they're mainly from one computer, and they're all for either port 80 (web) or 113 (no clue)...

Like I said:
wierd.

pii100
08-07-01, 11:28 PM
word is that the floods are originating from iis servers crompromised with the code red worm it is searching for other iis servers to infect i think or maybe its trying to crash the internet (hahahah) i am laughing for now at least

Thelemac
08-08-01, 12:58 AM
Yeah, that is the impression that I got from other assorted posts around here. Seems to have stopped, though. Not that I could tell, anyway. :)

pii100
08-08-01, 01:42 AM
sounds like another phase may start in a little while

Kryten
08-08-01, 10:22 PM
From all I have heard these are the symptoms of code red, sorry to be the bearer of bad news but I guess you already suspected as much.

Allan Nielsen
08-10-01, 06:26 PM
Nothing beats floodpinging a win95 computer from a linux computer over a LAN. 2 seconds and it will BSOD for sure! Win98 lasts at least twice as long... :) Win2k is another issue tho... :(

M@€$†®Ö™
08-10-01, 06:29 PM
Originally posted by Thelemac
Hmm...hadn't thought to try that...probably because they're mainly from one computer, and they're all for either port 80 (web) or 113 (no clue)...

Like I said:
wierd.

Network Address Translation Application Protocol Information
Protocol: tcp
Port: AUTH (113)
Application: Identd Protocol

Maestro

M@€$†®Ö™
08-10-01, 06:32 PM
I have been getting alot of Fragmented IGMP packets lately. I wonder how long it will take for people running IIS 4.0 and IIS 5.0 to patch there servers ?


Maestro

Thelemac
08-10-01, 11:21 PM
Originally posted by Allan Nielsen
Nothing beats floodpinging a win95 computer from a linux computer over a LAN. 2 seconds and it will BSOD for sure! Win98 lasts at least twice as long... :) Win2k is another issue tho... :(

Oddly enough, I have yet to crash a Windows computer by flood pinging...even with some gigantic packets (max size). Has always been on a hub though. I'll have to try it with my switch when I get Linux set up again (next few weeks) :)

Flanagun
08-12-01, 12:01 AM
if ya got win 98 first edition one minute of flooding will cause a reboot no bsod nor error msg just a reboot its weird. But i doubt ne one here is running win98 first edition though.

Thelemac
08-12-01, 02:00 AM
Actually, I am. I got my first computer just after it was released. (Well, a few months, anyway)

I'm pretty sure I tried that one. I'll have to try again, like I said.