Democratic Underground Latest Greatest Lobby Journals Search Options Help Login
Google

What is a SYN port attack?

Printer-friendly format Printer-friendly format
Printer-friendly format Email this thread to a friend
Printer-friendly format Bookmark this thread
This topic is archived.
Home » Discuss » The DU Lounge Donate to DU
 
Room101 Donating Member (1000+ posts) Send PM | Profile | Ignore Tue May-11-04 12:26 AM
Original message
What is a SYN port attack?
I just installed a firewall and it blocked a SYN port attack. I traced it and have the contact information. Is there foul play going on here?
Printer Friendly | Permalink |  | Top
SlavesandBulldozers Donating Member (1000+ posts) Send PM | Profile | Ignore Tue May-11-04 12:33 AM
Response to Original message
1. if you have repeated instances of it
Edited on Tue May-11-04 12:37 AM by soundgarden1
over the course of time its a big deal. 1 or two here and there not really a big deal. Sometimes it simply means your computer is getting pinged from an address it cannot respond to. If it becomes a pattern, there may be a problem. Sometimes firewalls misreport pings as attacks.

You're going to want multiple opinions on this, as Im not the be-all-end-all expert on that shit. It could be that your computer is getting probed for exploitation, pings are a method hackers use to find exploitable computers.
Printer Friendly | Permalink |  | Top
 
jadedcherub Donating Member (367 posts) Send PM | Profile | Ignore Tue May-11-04 12:53 AM
Response to Original message
2. It's a DOS attack,
Edited on Tue May-11-04 12:55 AM by jadedcherub
it usually comes from a spoofed address, which sends a bunch of SYN packets at your 'puter, and when your 'puter SYN-ACK's back, it can't find the host, so it it retries(five times, actually) it uses resources, each SYN attack can be 3 minutes, so the idea is they spam SYN packets at you and your resources get so low your puter can't take on any more connections, and you lose service.

But if it's just one, all a SYN packet is, is a TCP connection request.

I highly doubt your vulnerable behind your firewall.
Printer Friendly | Permalink |  | Top
 
Ricdude Donating Member (218 posts) Send PM | Profile | Ignore Tue May-11-04 12:55 AM
Response to Original message
3. A SYN port attack is...

Someone asked your computer "Are you there?". Your computer responded "Yes? What do you want?" and never heard from them again. Many times.

Probably not someone targetting you specifically, more likely a script kiddie (cyber vandal), who is using the computer that attacked yours (not likely its even their own) to attack random targets of opportunity.

I wouldn't worry about it unless I saw many of them from the same address range.

Aren't you glad you have a firewall? =)


http://docsrv.sco.com:507/en/NetAdminG/nwRs_SYNflood.html

A ``SYN flood'' is a Denial of Service attack that takes advantage of the TCP ``three way handshake'' protocol. A SYN is a type of TCP packet sent to initiate a connection with a listening TCP port. The port responds with a SYN/ACK to the initiating port, and places the SYN packet in a partial connections queue. When a corresponding ACK packet is received on the listening port, the validated SYN packet is removed from the partial connections queue and an entry is placed in the established connection queue awaiting a socket connection.

A SYN flood occurs when one or more listening TCP ports are sent large numbers of SYN packets. Such attacks could take various forms, most of which do not adversely affect the attacked system. However, the most potentially harmful attack sends SYN packets in which the client address refers to a system which does not exist. In this case, SYN packets remain in the TCP partial connection queue for each listening port that is attacked, unable to complete because the SYN/ACK cannot be routed to a bogus address. If the queues are too small and packets awaiting response remain on the queues, the TCP stack refuses to accept any connections until the bogus packets have timed out.
Printer Friendly | Permalink |  | Top
 
jadedcherub Donating Member (367 posts) Send PM | Profile | Ignore Tue May-11-04 12:56 AM
Response to Reply #3
4. :)
Printer Friendly | Permalink |  | Top
 
DU AdBot (1000+ posts) Click to send private message to this author Click to view 
this author's profile Click to add 
this author to your buddy list Click to add 
this author to your Ignore list Wed May 08th 2024, 04:05 PM
Response to Original message
Advertisements [?]
 Top

Home » Discuss » The DU Lounge Donate to DU

Powered by DCForum+ Version 1.1 Copyright 1997-2002 DCScripts.com
Software has been extensively modified by the DU administrators


Important Notices: By participating on this discussion board, visitors agree to abide by the rules outlined on our Rules page. Messages posted on the Democratic Underground Discussion Forums are the opinions of the individuals who post them, and do not necessarily represent the opinions of Democratic Underground, LLC.

Home  |  Discussion Forums  |  Journals |  Store  |  Donate

About DU  |  Contact Us  |  Privacy Policy

Got a message for Democratic Underground? Click here to send us a message.

© 2001 - 2011 Democratic Underground, LLC