Solved

land attack

Posted on 2006-06-22
3
800 Views
Last Modified: 2008-01-16
i see an impossible ip packet alert being triggered on the cisco ips sensors.  the traffic is from and to one of the domain controllers on udp port 138.  this may be indicative of land attack but it is happening on a couple of servers.  also, the servers are properly patched and nothing malacious was detected on the servers.  the other servers are not DCs.

does anyone know more about this?

thanks,
netgeek
0
Comment
Question by:net-geek
  • 2
3 Comments
 
LVL 38

Accepted Solution

by:
Rich Rumble earned 50 total points
ID: 16963164
There are false positives with most IDS and IPS systems, but this error has occured with Snort IDS sig's in the past
http://www.snort.org/archive-3-1767.html
http://support.microsoft.com/kb/188001

They could be spoofed, if possible, install wireshark (formerly ethereal) on the pc's in question and see if they are actaully sending that data, or span the port of these pc's to a sniffer to see if they are infact comming from that pc.
The LAND attack is a variation on the SYN attack. In the LAND attack, instead of sending
SYN packets with IP addresses that do not exist, the flood of SYN packets all have the same
spoof IP address—that of the targeted computer. The LAND attack can be prevented by filtering
out incoming packets for which source IP addresses appear to be from computers on the internal
network
-rich
0
 

Author Comment

by:net-geek
ID: 17003679
ok, thanks.
0
 
LVL 38

Expert Comment

by:Rich Rumble
ID: 17005173
Were you able to confirm that the traffic was definatly comming from the source that your IDS said it was? Just curious.
-rich
0

Featured Post

Gigs: Get Your Project Delivered by an Expert

Select from freelancers specializing in everything from database administration to programming, who have proven themselves as experts in their field. Hire the best, collaborate easily, pay securely and get projects done right.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

The 21st century solution to antiquated pagers.
Data breaches are on the rise, and companies are preparing by boosting their cybersecurity budgets. According to the Cybersecurity Market Report (http://www.cybersecurityventures.com/cybersecurity-market-report), worldwide spending on cybersecurity …
Nobody understands Phishing better than an anti-spam company. That’s why we are providing Phishing Awareness Training to our customers. According to a report by Verizon, only 3% of targeted users report malicious emails to management. With compan…
The Email Laundry PDF encryption service allows companies to send confidential encrypted  emails to anybody. The PDF document can also contain attachments that are embedded in the encrypted PDF. The password is randomly generated by The Email Laundr…

776 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question