Help about UDP Attacks

omri75

New member
Help about UDP Attacks

Hello, Im the admin of israeli.as IRC Network. the system is Working this way: 1.Windows NT 5.0 Updated and secured Runing on Intel Celeron 533Mhz 128MB RAM 2.P166 Packerd Bell LINUX Machine, Caldera. the NT is the Gateway of the network. the nt protected with ZoneAlarm firewall. all things are tesetd and all fine. some one with Linux Machine from EDu flooding us by UDP Attacks, and making the system Havy, means: the CPU is working in 100% and it is hot. very hot memory is 50% Free of 128MB ram the linux has no problems at all. its fully secured and inetd process are closed for best secureing. all packges are updated,and we are connectd with 3 nics [eth cards] 10/100 now whan he flooding the system beging to be slow very slow. now i orderd new server AMD 500Mhz 256MB RAM Nvdia GeforCE 2 64MB Ram card. 20GB HD and thing blah does its will be strong for server? and does it will be almost not effacetd from the UDP ports attack? all ports of UDP are closed but yet he is scaning port and port and trying to attack it here is log FWIN,2001/10/08,18:58:20 +2:00 GMT,211.220.194.252:1026,192.117.101.174:2535,UDP FWIN,2001/10/08,18:58:21 +2:00 GMT,211.220.194.252:1026,192.117.101.174:1645,UDP FWIN,2001/10/08,18:58:21 +2:00 GMT,211.220.194.252:1026,192.117.101.174:445,UDP FWIN,2001/10/08,18:58:25 +2:00 GMT,211.220.194.252:1026,192.117.101.174:13,UDP FWIN,2001/10/08,18:58:26 +2:00 GMT,211.220.194.252:1026,192.117.101.174:3001,UDP FWIN,2001/10/08,18:58:27 +2:00 GMT,211.220.194.252:1026,192.117.101.174:7,UDP FWIN,2001/10/08,18:58:30 +2:00 GMT,211.220.194.252:1026,192.117.101.174:137,UDP FWIN,2001/10/08,18:58:31 +2:00 GMT,211.220.194.252:1026,192.117.101.174:1025,UDP FWIN,2001/10/08,18:58:32 +2:00 GMT,211.220.194.252:1026,192.117.101.174:1646,UDP FWIN,2001/10/08,18:58:33 +2:00 GMT,211.220.194.252:1026,192.117.101.174:3372,UDP FWIN,2001/10/08,18:58:34 +2:00 GMT,211.220.194.252:1026,192.117.101.174:515,UDP FWIN,2001/10/08,18:58:38 +2:00 GMT,211.220.194.252:1026,192.117.101.174:17,UDP FWIN,2001/10/08,18:58:38 +2:00 GMT,211.220.194.252:1026,192.117.101.174:13,UDP FWIN,2001/10/08,18:58:39 +2:00 GMT,211.220.194.252:1026,192.117.101.174:7,UDP FWIN,2001/10/08,18:58:40 +2:00 GMT,211.220.194.252:1026,192.117.101.174:2535,UDP FWIN,2001/10/08,18:58:41 +2:00 GMT,211.220.194.252:1026,192.117.101.174:3372,UDP FWIN,2001/10/08,18:58:41 +2:00 GMT,211.220.194.252:1026,192.117.101.174:1645,UDP FWIN,2001/10/08,18:58:43 +2:00 GMT,211.220.194.252:1026,192.117.101.174:137,UDP FWIN,2001/10/08,18:58:46 +2:00 GMT,211.220.194.252:1026,192.117.101.174:3001,UDP FWIN,2001/10/08,18:58:49 +2:00 GMT,211.220.194.252:1026,192.117.101.174:515,UDP FWIN,2001/10/08,18:58:50 +2:00 GMT,211.220.194.252:1026,192.117.101.174:138,UDP FWIN,2001/10/08,18:58:53 +2:00 GMT,211.220.194.252:1026,192.117.101.174:1813,UDP FWIN,2001/10/08,18:58:57 +2:00 GMT,211.220.194.252:1026,192.117.101.174:9,UDP FWIN,2001/10/08,18:59:01 +2:00 GMT,211.220.194.252:1026,192.117.101.174:135,UDP FWIN,2001/10/08,18:59:01 +2:00 GMT,211.220.194.252:1026,192.117.101.174:1723,UDP FWIN,2001/10/08,18:59:02 +2:00 GMT,211.220.194.252:1026,192.117.101.174:445,UDP FWIN,2001/10/08,18:59:04 +2:00 GMT,211.220.194.252:1026,192.117.101.174:3002,UDP FWIN,2001/10/08,18:59:04 +2:00 GMT,211.220.194.252:1026,192.117.101.174:1025,UDP FWIN,2001/10/08,18:59:04 +2:00 GMT,211.220.194.252:1026,192.117.101.174:13,UDP FWIN,2001/10/08,18:59:04 +2:00 GMT,211.220.194.252:1026,192.117.101.174:1646,UDP FWIN,2001/10/08,18:59:07 +2:00 GMT,211.220.194.252:1026,192.117.101.174:1812,UDP FWIN,2001/10/08,18:59:10 +2:00 GMT,211.220.194.252:1026,192.117.101.174:2535,UDP FWIN,2001/10/08,18:59:14 +2:00 GMT,211.220.194.252:1026,192.117.101.174:515,UDP FWIN,2001/10/08,18:59:16 +2:00 GMT,211.220.194.252:1026,192.117.101.174:3001,UDP FWIN,2001/10/08,18:59:18 +2:00 GMT,211.220.194.252:1026,192.117.101.174:137,UDP FWIN,2001/10/08,18:59:18 +2:00 GMT,211.220.194.252:1026,192.117.101.174:1645,UDP FWIN,2001/10/08,18:59:21 +2:00 GMT,211.220.194.252:1026,192.117.101.174:3372,UDP FWIN,2001/10/08,18:59:22 +2:00 GMT,211.220.194.252:1026,192.117.101.174:1813,UDP FWIN,2001/10/08,18:59:24 +2:00 GMT,211.220.194.252:1026,192.117.101.174:3002,UDP FWIN,2001/10/08,18:59:25 +2:00 GMT,211.220.194.252:1026,192.117.101.174:1723,UDP FWIN,2001/10/08,18:59:31 +2:00 GMT,211.220.194.252:1026,192.117.101.174:20433,UDP FWIN,2001/10/08,19:05:57 +2:00 GMT,211.220.194.252:1026,192.117.101.174:911,UDP FWIN,2001/10/08,19:05:57 +2:00 GMT,211.220.194.252:1026,192.117.101.174:88,UDP FWIN,2001/10/08,19:05:57 +2:00 GMT,211.220.194.252:1026,192.117.101.174:21910,UDP FWIN,2001/10/08,19:05:57 +2:00 GMT,211.220.194.252:1026,192.117.101.174:50594,UDP FWIN,2001/10/08,19:05:57 +2:00 GMT,211.220.194.252:1026,192.117.101.174:59749,UDP Thanks you Israeli.as [email protected]
 

philips

New member
hmm...

hi... hmmm...basically ur suffering from a rather known problem caused by ppl trying to flood you on purpose... nothing new under the sun and lots of materials can be found in the internet.. solution/suggestions to your problems SHOULD NOT BE DONE in this forum...since whoever is bothering you..might as well be reading this..
I will say 2 things... 1. u can write me an e-mail to [email protected] and I will try to help 2. Buying a new/stronger computer is no the answer..... It will make things better but there are lots of other things to be done...such as programs/hardware etc.. 2 more things moreover... 1. DONT USE ZONEALRAM pro or any other HOME FIREWALL systems for your purpose.. it is not build for handling such loads and the result is very clear...
2. if u have 2 linux machines which work perfectly.... why the hell use the NT as gateway.. a linux machine will do this much better... There is alot more to be said and done..... good luck
 

Anti Virus

New member
לא הבנתי מילה אחת ממה שכתוב בשתי ..

ההודעות האלה אתם מוכנים לתרגם לי??????
 

philips

New member
המממ...

אין כל תועלת בתרגום.. אם לא הבנת...סימן שאיך לך רקע בתחום של תקשורת נתונים ורשתות... וחוץ מזה...התשובה הייתה ספציפית מיועדת לכותב השאלה... לגבייך.... אתה יכול להתחיל ללמוד את התחום ואם תצטרך עזרה/שאלות אשמח לענות....
 

T-C-L

New member
read this

if all the attacks are from the same ip why not blocking incoming UDP from that ip? i dont think Zone alarm can block a specific ip but even tiny personal firewall can if u have to stick with a home firewall then use it its better
 
למעלה