So our FTP server was attacked yesterday...

NathanBWF

Golden Member
May 29, 2003
1,810
0
0
At about 4:15pm yesterday our FTP server came under attack. The IP seemed to originate from the Czech Republic. We had them blocked and things under control in about 5 minutes. This is a first for me, and am just wondering if there is anyone that I could report this to? I doubt the local Police here could do anything about it.

Anyone else work as an IT Security specialist who could point me in the right direction? Is there anything that I can and should do?
 

jlazzaro

Golden Member
May 6, 2004
1,743
0
0
what do you define as an "attack"? there are always bots scouring the internet looking for unpatched devices...nothing you can do about it outside of blocking them.

the best offense is a good defense. keep your systems / software up to date and take care of any known vulnerabilities.
 

n0cmonkey

Elite Member
Jun 10, 2001
42,936
1
0
Send an email to the abuse@ email for their ISP/connection.

Other than that, stop using FTP.
 

NathanBWF

Golden Member
May 29, 2003
1,810
0
0
Originally posted by: jlazzaro
what do you define as an "attack"? there are always bots scouring the internet looking for unpatched devices...nothing you can do about it outside of blocking them.

the best offense is a good defense. keep your systems / software up to date and take care of any known vulnerabilities.

Basically they opened up about 260 simultaneous connections to our FTP server which caused it to 'hang up'. The server is up to date on all of its patches.
 

NathanBWF

Golden Member
May 29, 2003
1,810
0
0
Originally posted by: n0cmonkey
Send an email to the abuse@ email for their ISP/connection.

Other than that, stop using FTP.

Heh...unfortunately is used quite a bit by our employees all across North America so it has to stay up...
 

Tarrant64

Diamond Member
Sep 20, 2004
3,203
0
76
We use FTP where I work as well. Nothing wrong with using it.

It looks like you took the right steps in getting it under control quickly. Hey, if you never had to worry about security you wouldn't have a job, right? Not much else you can do.
 

wlee

Senior member
Oct 10, 1999
585
0
71
You could also have your router ban all IP's from outside of North America.
 

Nothinman

Elite Member
Sep 14, 2001
30,672
0
0
Basically they opened up about 260 simultaneous connections to our FTP server which caused it to 'hang up'. The server is up to date on all of its patches.

Sounds like your FTP server needs fixed then, it should allow only as few simultaneous connections as necessary.

We use FTP where I work as well. Nothing wrong with using it.

Unless it's a public service there is something wrong with FTP that's not wrapped in SSH or a VPN.
 

NathanBWF

Golden Member
May 29, 2003
1,810
0
0
Originally posted by: Nothinman
Basically they opened up about 260 simultaneous connections to our FTP server which caused it to 'hang up'. The server is up to date on all of its patches.

Sounds like your FTP server needs fixed then, it should allow only as few simultaneous connections as necessary.

We use FTP where I work as well. Nothing wrong with using it.

Unless it's a public service there is something wrong with FTP that's not wrapped in SSH or a VPN.

Very true. I checked and it was set to allow up to 10,000 connections or something stupid like that.

Unfortunately customers do also access parts of the FTP site so we do need to keep it public.
 

n0cmonkey

Elite Member
Jun 10, 2001
42,936
1
0
Read only FTP isn't horrible...

I guess.

Did they attack it from one single IP or from multiple?
 

manowar821

Diamond Member
Mar 1, 2007
6,063
0
0
lol @ internet attacks.

They make everyday networking more interesting.

I was going to say you should turn down the number of allowed connections, but they've already gotten to that point.
 

montypythizzle

Diamond Member
Nov 12, 2006
3,699
0
71
something under the patriot act can let us prosecute them or something like that...
intranets is serious business
 

Nothinman

Elite Member
Sep 14, 2001
30,672
0
0
They have computers in the Czech Republic??!!

Yea, and if people would take their heads out of the US sand and look around once in a while they'd realize that the rest of the world isn't quite as backward and destitute as we think.
 

Sunner

Elite Member
Oct 9, 1999
11,641
0
76
In my experience, trying to get anything done with regards to abuse reporting to most of the "internet third world" is more or less futile.
I've sent a bunch of those mails for a variety of reasons, generally there's either no response at all(this is most common) or some automated response that doesn't really say anything, and nothing more after that.
 

KB24

Member
Jan 31, 2007
59
0
0
even if you block all the IP's they could still mask the ip and get in through there. RIgh t?
 

Nothinman

Elite Member
Sep 14, 2001
30,672
0
0
even if you block all the IP's they could still mask the ip and get in through there. RIgh t?

They can't spoof their IP if they want to get any return traffic so it severly limits what they can do. Also, if their ISP's routers are configured semi-correctly they'll only route traffic from their own networks so that would limit the attacker's available source IP ranges. The real problem would be proxies, just about all proxies handle FTP traffic by default so all they need is to find an open proxy to go through and the traffic would appear to come from the proxy instead of them.
 

Fallen Kell

Diamond Member
Oct 9, 1999
6,064
438
126
They don't need to spoof their IP's. Any serious organization will have access to a bot net which is distributed across the entire globe, and could easily just command portions of that network to connect up to your system if others are being blocked.

As for who to report, well, the Secret Service I believe handles problems like this, however, in your case since nothing was stolen or damaged (other then services being down for a period of time), it will be minimally important to them. However, it may still be a good idea to report this as the data may help in other on-going investigations which have been attacked by the same organization (if they hit you, they have probably hit others). And from that standpoint, any bit of data may be helpful.
 
sale-70-410-exam    | Exam-200-125-pdf    | we-sale-70-410-exam    | hot-sale-70-410-exam    | Latest-exam-700-603-Dumps    | Dumps-98-363-exams-date    | Certs-200-125-date    | Dumps-300-075-exams-date    | hot-sale-book-C8010-726-book    | Hot-Sale-200-310-Exam    | Exam-Description-200-310-dumps?    | hot-sale-book-200-125-book    | Latest-Updated-300-209-Exam    | Dumps-210-260-exams-date    | Download-200-125-Exam-PDF    | Exam-Description-300-101-dumps    | Certs-300-101-date    | Hot-Sale-300-075-Exam    | Latest-exam-200-125-Dumps    | Exam-Description-200-125-dumps    | Latest-Updated-300-075-Exam    | hot-sale-book-210-260-book    | Dumps-200-901-exams-date    | Certs-200-901-date    | Latest-exam-1Z0-062-Dumps    | Hot-Sale-1Z0-062-Exam    | Certs-CSSLP-date    | 100%-Pass-70-383-Exams    | Latest-JN0-360-real-exam-questions    | 100%-Pass-4A0-100-Real-Exam-Questions    | Dumps-300-135-exams-date    | Passed-200-105-Tech-Exams    | Latest-Updated-200-310-Exam    | Download-300-070-Exam-PDF    | Hot-Sale-JN0-360-Exam    | 100%-Pass-JN0-360-Exams    | 100%-Pass-JN0-360-Real-Exam-Questions    | Dumps-JN0-360-exams-date    | Exam-Description-1Z0-876-dumps    | Latest-exam-1Z0-876-Dumps    | Dumps-HPE0-Y53-exams-date    | 2017-Latest-HPE0-Y53-Exam    | 100%-Pass-HPE0-Y53-Real-Exam-Questions    | Pass-4A0-100-Exam    | Latest-4A0-100-Questions    | Dumps-98-365-exams-date    | 2017-Latest-98-365-Exam    | 100%-Pass-VCS-254-Exams    | 2017-Latest-VCS-273-Exam    | Dumps-200-355-exams-date    | 2017-Latest-300-320-Exam    | Pass-300-101-Exam    | 100%-Pass-300-115-Exams    |
http://www.portvapes.co.uk/    | http://www.portvapes.co.uk/    |