hacking contest

hacking exploits security forum
hacking
compliance articles
upgrade backup exec
information security consultant

Full Version: SYN DoS defense
fear
pinged and syn flooded to death..my pc is about shot and i need a solid defense if there is any please let me know. and to set my impression right..i'll say i only know half the basics and in the process of learning...thanks
GSecur
I hope you have a firewall set up. First thing is to set it to ignore ping requests. Good Idea in general because it will decrease the number of random ports scans.


Here are some ragistery tweaks. I take no reponsibility if they destroy your box.

hkey_local_machine \system \currentcontrolset \services \tcpip \parameters \synattackprotect=1 REG_DWORD

hkey_local_machine \system \currentcontrolset \services \tcpip \parameters \tcpmaxconnectresponseretransmissions=2 REG_DWORD

hkey_local_machine \system \currentcontrolset \services \tcpip \parameters \tcpmaxdataretransmissions=3 REG_DWORD

hkey_local_machine \system \currentcontrolset \services \tcpip \parameters \enablepmtudiscovery=0 REG_DWORD

Microsoft has a decent article whiich is where I got the reg hacks.
http://www.microsoft.com/technet/treeview/...ac/dosatack.asp

Are these attacks on a personal machine or company webserver?
MpR
I always found the best way to avoid DDOS is not to piss ppl off, I dunno always worked for me
krackatoa
Your connection can only handle so much traffic, even if you're dropping it. Sometimes there is no defense at the endpoint and steps need to be taken in the core routers of your ISP.

MpR uses the approach that I do, don't piss people off.
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.

 
Invision Power Board © 2001-2005 Invision Power Services, Inc.