PDA

View Full Version : DoS - Evidence Needed?


PrestonConnors
03-20-01, 03:23 AM
I've been the unlucky victim of several Denial Of Service attacks in the past month. One of my "friends" often gets irate after I win, or sometimes even frag him once, in a QuakeIII game (immature, I know). He totally saturates my bandwith with TCP ECHO replies (Smurf attact) which causes me to lose service for the duration of the attack.

How do I go about stopping this?

I've reported this many times to my ISP (AT&T RR) and his ISP (BellSouth DSL). The times I've called these ISPs all I could get them to tell me are email addresses. I email them and no response. Oh, by the way, the phone techs did not know what a DoS was nor a Smurf attack. I had explain it to them in layman's terms...

I've gathered evidence... TCPdumps showing all the IP addresses that were hitting me, plus his IP address sending me ICMP echo requests (to check to see if I was still "alive" I guess) and conversations of him telling me he is DoSing me.....

What else do I need?

3v1l807
03-20-01, 03:37 AM
Well you could get a firewall.

YARDofSTUF
03-20-01, 04:13 AM
www.cnet.com, (http://www.cnet.com,) searc cnet for zone arlarm, its a free firewall and it has a description, should help u.

PrestonConnors
03-20-01, 04:20 AM
How is a firewall going to help?

He still saturates my downstream bandwith.

3v1l807
03-20-01, 04:24 AM
ICMP Echo request aka ping, you can have the firewall make you basically unpingable and virtually invisible on the internet. You could also ask your ISP for a different IP. How did he get your IP in the first place?

YARDofSTUF
03-20-01, 04:26 AM
hmmmm, i wouldnt play with him anymore lol, i honestly cant tell ya, i come into the cable/dsl to learn, and teh flood attacks/firewall stuff is kinda new/fresh for me, time u called ur service and demanded a manager, get higher ppl involved!

Storm90
03-20-01, 03:33 PM
I would install the firewall. There is no way then he can run a dos denial attack on you. Then report this prouble to your provider. This way you will be able to get his Ip from the logs of your firewall. With out his Ip. You don't have nuch of a chance of stopping him. GoodLuck! ;)

Prey521
03-20-01, 04:24 PM
What kinda lamer ass friend is that? Don't play with that fool no more if he's gonna be such a baby about cheating :rolleyes:

neo86
03-20-01, 06:45 PM
saturate his bandwidth using university computers! he'll learn his lesson :)

Juggernaut
03-20-01, 11:44 PM
go to http://www.zonelabs.com/ and download ZoneAlarm FREE and install it...the firewall will stop the attacks coming in so u won't get flooded anymore.