Have your own Website or Server
Friday, January 9th, 2009Here is How to report Denial of Service attacks
Typical Denial of Service abuse (DoS) involves a very large number of connections or packets being directed to the target computer or website, either from a single source IP address or (Distributed Denial of Service,DDoS) from a number of addresses, possibly a large number and probably in several different networks. Sometimes the effect is to stop the data network working or make it so slow as to interfere with its normal use; sometimes the target is a single machine which also may cease to work or run very slowly. Then other times it is a mere attempt to obtain secured information you have protected. If the target is a single service such as a Web, DNS or e-mail server, it may be swamped by very many otherwise normal and legitimate requests for information.
What to include in your report
In a Denial of Service it can be difficult to obtain complete information. Please include as much as possible of the following:
* source IP address or addresses
* destination IP address (in your network) and port or service;
* date and time when the abuse started and finished (include your timezone and check whether your system clock was accurate at the time);
* brief description of what happened;
* any original log or trace information;
* any other information you think may be helpful.
If it is available, a good sample of log information is all that is needed.
Fortunately we keep very good logs of our site and our clients sites traffic and was able to easily See and PinPoint the IP of the DOS attack we experienced on our personal site here yesterday in an attempt to obtain private information protected on this site.
We were able to include all of the above & a report was filed promptly.
We are waiting for the info to file formal charges.
} The Mrs {