Back to Forums








View Full Version : SYN Flood Attack Detect


egghead
April 3rd, 2005, 13:00 PM
my router was reporting this yesterday in the logs.

I do not know what this is.

can someone enlighten me?

is it a result of something getting in or sending out?

Curio
April 3rd, 2005, 16:57 PM
It's someone trying to DOS you by opening lots of connections to you and hoping to bomb your equipment. This doesn't usually work on modern equipment cos the stack is hardened and if your router can detect the attack it means it can also defend against it. The attacker sends the first part of a connection request which makes your receiving port go into a ready state, the connection is never completed but more (many more) are attempted in the same way hoping to run you out of resources. Nowadays these half-open connections are closed after a short timeout and some equipment will ignore the originating IP if a certain threshold of requests is crossed.

You can download syn-flooders all over the place and some kiddy is probably trying one out, he'll get bored when it doesn't work.

cash_site
April 3rd, 2005, 23:37 PM
script-kiddie :D

egghead
April 4th, 2005, 09:11 AM
thanks for the heads up.

No reason why that would happen

hmm......

it stopped a day or so ago so who knows

might be the ip they attacked

mine changes so i must have been infotunate for that time

thanks again