Security Incidents mailing list archives

Re: DoS/DDoS on port 1863(MSN protocol)


From: Martin Mačok <martin.macok () underground cz>
Date: Mon, 27 Sep 2004 12:00:01 +0200

On Thu, Sep 23, 2004 at 01:01:05PM -0300, Diego Sebastián González wrote:

Too much SYNs are being sent from a lot of our Public IP Customers
to 1863 port to MSN Servers.

Are you able to count (or limit) SYNs per IP per second or minute?

I can't think of better general solution to this sort of problem
other than detecting and blocking misbehaving customers (those that
spread DoS, spam, viruses/worms and so on).

Martin Mačok
IT Security Consultant


Current thread: