|
The problem is than with a HTTP Security
server ressource to block NimDa even if you specify DROP in the
rule Securities Servers never DROP
connection they ALWAYS REJECT them. For NimDA if you drop attack
from
a source it will hit you about 1
probe/minute if you reject attack from a source it will attack you
10 to 20 times/sec because it seems it
doesn't care about drop/reject when the attack gets a reject or
timeout (out) it send the next
one.
The interesting thing is than i had a
ressource to DROP (Read REJECT in the log...) CodeRED II attack,
i used a filter of *{NNNNN;XXXXX}* because
other filters i tried like default.ida caused unrelated
traffic to be rejected to. This ressource
did not reject Nimda virus but because the Nimda connections
where examined by the security server in
the following rule, not using security ressources, where i
dropped connection for HTTP service
except those to our HTTP server (Not running any form of MS HTTP
server
because there are all real piece of shit!)
those where Rejected and no Dropped because of a side effect
of the HTTP Ressource to katch CodeRed. I
had to disable that Code Red ressource
As long as Nimda attack are dropped i get's
less than 1KB/Sec traffic from it when i reject them
i get at least steady 50KB/Sec traffic from
it.
I will open a trouble ticket with
Checkpoint Support on the fact than if a connection is
inspected by a Secury Server it can't be
DROPPED just REJECTED even if the DROP is in
rule without ressource after the rule with
the ressource.
Yves Belle-Isle
|
Title: RE: [FW1] New worm on the road?
- RE: [FW1] New worm on the road? Paul Seifer
- Re: [FW1] New worm on the road? Yves Belle-Isle
- Re: [FW1] New worm on the road? hsanders
- RE: [FW1] New worm on the road? Roelandts, Guy
- Re: [FW1] New worm on the road? Patrick Coomans
- RE: [FW1] New worm on the road? Allison, Mark
- RE: [FW1] New worm on the road? Chris Sorel
- Re: [FW1] New worm on the road? Joe Pampel
- RE: [FW1] New worm on the road? METE EMINAGAOGLU (IT)
- Re: [FW1] New worm on the road? Paul Cardon
- Re: [FW1] New worm on the road? Yves Belle-Isle
- Re: [FW1] New worm on the road? Thomas M Swint
- RE: [FW1] New worm on the road? Steven Schuster
- Re: [FW1] New worm on the road? Kim ARAGON
- RE: [FW1] New worm on the road? Patrick Coomans
- RE: [FW1] New worm on the road? METE EMINAGAOGLU (IT)
- RE: [FW1] New worm on the road? METE EMINAGAOGLU (IT)
- Re: [FW1] New worm on the road? Patrick Coomans
- RE: [FW1] New worm on the road? enash
- RE: [FW1] New worm on the road? Shane Castle
