Syn Packets
I think we're under attack. No, not by clones this time. We believe that some individual has been doing a continual syn scan against our server. What does this mean? Well, it means that the rest of the world is getting locked out. Sounds kinda selfish, rude, vile, and punishable by death to me. What did they rule with that Patriot Act thing again? That we could rip out these people's toenails? Hold on. Let me check.
Need a new domain name? See why GoDaddy is the #1 domain registrar worldwide. Now with your domain registration, you'll get hosting, a free blog, complete email system, and much more! Plus, as a listener of The Chris Pirillo Show, enter code CHRIS1 when you check out, and save an additional 10% on any order. Get your piece of the internet at GoDaddy!









6 Comments
Anonymous
January 6th, 2002
at 10:10am
netstat -s |grep “listenqueue overflows”
Too many connections in the state “SYN_RECEIVED” could indicate that the system is being attacked.
Anonymous
January 6th, 2002
at 10:28am
I'll give that a shot the next time we go down for the count. Thanks, Jason!
Anonymous
January 6th, 2002
at 10:33am
Chris, as you move up the food chain and become more widely known you're going to experience more and more of these things. Now would be a good time to start looking into firewalling and protecting yourself and your sites from these knds of things.
The price of fame? :)
Anonymous
January 6th, 2002
at 10:35am
Fame is frustrating. :) Again, an attack is still speculation at this point. It could very well be an internal bottleneck, in which case we'll have to find a few mirrors to defray the load.
Anonymous
January 6th, 2002
at 10:43am
You should have your sysadmin (if u can find him) do a few minor things. You can runa cronjob every few minutes and cat that netstat output to a file so you can backtrace it and see what's happening right before the crashes. That coupled with the Apache watcher I sent before should keep you at least up and running. If you can target a specific IP or block of IP's you should be able to deny them access with TCP wrappers which you should be using already. If not get that installed ASAP. You should get a security expert to do an audit of your system and plug any holes you got happenin. Hell, Kevin Poulson and Kevin Mitnick are in the studios for the Screensavers every other week. I'm sure they can give you some good advice ;-)
Anonymous
January 6th, 2002
at 11:18am
I hate it when that happens, I mean when I get locked out from valuable pieces of wisdom when I need them most. Ripping out their toenails is too nice.