Search /
Docfinder:
Advanced search  |  Help  |  Site map
RESEARCH CENTERS
SITE RESOURCES
Click for Layer 8! No, really, click NOW!
Networking for Small Business
TODAY'S NEWS
Microsoft details Windows 8 for ARM devices
Web app lets enterprise set security, sharing for Google Apps users
Cloudscaling to offer OpenStack private cloud platform
Valentine's Day Patch Tuesday: Microsoft to issue 9 patches, 4 critical
Mobile World Congress sneak peek: Quad-core smartphones, Ice Cream Sandwich & more
Microsoft details 'Windows on ARM' program
March debut of 'iPad 3' a sure bet, says analyst
Resume Makeover: How an Information Security Professional Can Target CSO Jobs
FBI unbolts Steve Jobs 1991 investigation file
Cisco boosted profit, sales in Q2 while cutting costs
Macs take on the enterprise
Four crazy tech ideas from Google's Solve for X project
Obama 2012 campaign playlist revealed courtesy of Spotify
Oracle buying Taleo for US$1.9 billion in direct hit at SAP
/

Denial-of-service attacks


Do I need to worry about the recent Internet distributed denial-of-service (DDOS) attacks being used in my organization's intranet?

The recent denial-of-service attacks are thought to be based on three software packages - TFN, Trin00 and Stacheldraht, which use "zombie modules" installed on servers to launch attacks against a single site.

For your intranet, you should be worried about two things - protecting your net from DDOS attacks, and protecting your servers from being used against other sites. Protecting your net requires intrusion-detection capabilities and active traffic control. Protecting your servers requires sound system security and active monitoring. While the majority of these attack tools run on Solaris and Linux systems, some run under other Unix operating systems and Windows platforms.

Review the CERT advisory at www.cert.org/advisories/CA-2000-01.html to understand how to deal with the threat. Information is also available at www.fbi.gov/nipc/welcome.htm, http://staff.washington.edu/dittrich/misc/stacheldraht.analysis, and http://xforce.iss.net/alerts/advise40.php3. You can find software for scanning servers for TFN, Trin00 and Stacheldraht at www.fbi.gov/nipc/trinoo.htm. A Perl script called "gag" that detects Stacheldraht attacks is available at the washington.edu link mentioned above. Also, Sun has patches for holes exploited by hackers installing zombies at www.sunsolve.com.

RELATED LINKS

As a network architect at Change at Work in Houston, Blass understands the strain of developing and managing networks. Send your problems to dr.internet@changeatwork.com

Ask Dr. Internet archive
Past columns.


NWFusion offers more than 40 FREE technology-specific email newsletters in key network technology areas such as NSM, VPNs, Convergence, Security and more.
Click here to sign up!
New Event - WANs: Optimizing Your Network Now.
Hear from the experts about the innovations that are already starting to shake up the WAN world. Free Network World Technology Tour and Expo in Dallas, San Francisco, Washington DC, and New York.
Attend FREE
Your FREE Network World subscription will also include breaking news and information on wireless, storage, infrastructure, carriers and SPs, enterprise applications, videoconferencing, plus product reviews, technology insiders, management surveys and technology updates - GET IT NOW.