how to respond to possible attacks

2008-03-08 Thread Robin Becker
Sorry if this is too off topic, but I would like to find out what to do when you suspect a possible dos attack on your system. I know there are many experienced sysadmins here. Although my system (freebsd 6.0/apache 2.0.x) did in fact hold up, what steps should I be taking? The originating ip

Re: how to respond to possible attacks

2008-03-08 Thread Bill Campbell
On Sat, Mar 08, 2008, Robin Becker wrote: Sorry if this is too off topic, but I would like to find out what to do when you suspect a possible dos attack on your system. I know there are many experienced sysadmins here. Although my system (freebsd 6.0/apache 2.0.x) did in fact hold up, what

Re: how to respond to possible attacks

2008-03-08 Thread Mel
On Saturday 08 March 2008 23:34:56 Robin Becker wrote: The originating ip doesn't seem to be reverse mappable. sure it is: whois(1) is your friend. -- Mel Problem with today's modular software: they start with the modules and never get to the software part.

Re: how to respond to possible attacks

2008-03-08 Thread Siraj Shaikh
On 08/03/2008, Robin Becker [EMAIL PROTECTED] wrote: Sorry if this is too off topic, but I would like to find out what to do when you suspect a possible dos attack on your system. I know there are many experienced sysadmins here. Although my system (freebsd 6.0/apache 2.0.x) did in fact hold