Image
 
linkedin_logo.png rss_logo.jpg
twitter_logo.png youtube_logo.jpg
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 75 guests and 2 members online
EH-Net News Feeds
Latest Additions
 
Advertisement

You are here: Home arrow Forum arrow Ethical Hacking Discussions and Related Certificationsarrow Network Pen Testingarrow DOS logs
EH-Net
February 09, 2012, 08:31:11 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: Advertise on EH-Net!! - Reasonable Rates, Highly Targeted Audience.
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: DOS logs  (Read 3563 times)
0 Members and 1 Guest are viewing this topic.
lovewadhwa
Newbie
*
Offline Offline

Posts: 16


View Profile
« on: June 26, 2008, 07:39:03 AM »

Hi i have been receiving the following on running dmesg on one of my linux servers.Seems to be a sort of DOS attack.I need to reproduce it.But unable to get the tool which can do the same.Can anybody out there help me.

TCP: Treason uncloaked! Peer 195.166.241.58:62516/80 shrinks window 1125437396:1125437397. Repaired.
TCP: Treason uncloaked! Peer 195.166.241.58:62516/80 shrinks window 1125437396:1125437397. Repaired.
TCP: Treason uncloaked! Peer 195.166.241.58:62516/80 shrinks window 1125437396:1125437397. Repaired.
TCP: Treason uncloaked! Peer 210.212.88.48:2339/80 shrinks window 1732317231:1732317232. Repaired.
TCP: Treason uncloaked! Peer 88.202.127.229:51950/80 shrinks window 3906350758:3906350759. Repaired.
TCP: Treason uncloaked! Peer 203.199.30.15:53364/80 shrinks window 3067016690:3067019450. Repaired.
Logged

lovewadhwa
Newbie
*
Offline Offline

Posts: 16


View Profile
« Reply #1 on: July 02, 2008, 11:57:09 PM »

Can anyone help regarding the same.Can see the views hits increasing but nothing as a reply.Plz help.
Logged

dean
Full Member
***
Offline Offline

Posts: 135


View Profile
« Reply #2 on: July 03, 2008, 01:02:20 PM »

lovewadhwa,

The message indicates that the remote host changed the tcp window size without renegotiating the size with your server. Newer kernels will handle this without any problems. The message gets printed when the client shrinks the tcp window size and the server still has data to transmit.

Is your server a webserver? It could be an attack. A common DoS on web servers is to use up all available connections by not completing the 3-way handshake and having that socket remain in a half open state. A network capture of the traffic will confirm this.

Check your server logs and any other facilities you may have for detecting attacks. (Firewall, IDS, etc) They may show additional details.

More than likely it is a broken client somewhere.

You could probably script hping to replicate this type of attack.

dean
Logged

<script>alert('%52%54%46%4D')</script>
lovewadhwa
Newbie
*
Offline Offline

Posts: 16


View Profile
« Reply #3 on: July 08, 2008, 02:42:37 AM »

Hi
Thanx a lot for ur response.Have played with hping tool but couldn't replicate the same.Can u plz provide the arguments to be given to hping to replicate the same.Plz help.

Thanx a ton.
Logged

Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.16 | SMF © 2011, Simple Machines
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.106 seconds with 22 queries.
 

gk_static-ad_feb2012.jpg
Global Knowledge Training: Build Security Skills to Protect and Defend

offsec_130x200-2_jan-feb2012.png
Offensive Security
AWE Live in the Caribbean!
March 5 - 9, 2012

SANS Deals 4 EH-Netters
$150 OFF Any SANS Course in Any Format!
Coupon Code: Refer_EHN
Including SANS Phoenix 2012, SANS 2012
Recent Forum Topics

cbtnuggets_logo_125.jpg
Try CBT Nuggets Free!

Vote For EH-Net

Add to Technorati Favorites
technorati fave

 
         
Advertisement

© 2012 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.