OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
From: Andy Farkas (andyf_at_speednet.com.au)
Date: Tue Jan 21 2003 - 10:27:15 CST

  • Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]

    > > > On rare occasions, a FreeBSD system in our network has
    > > > been known to print the example shown in the subject at a furious
    > > > rate for a short time and then things get back to normal.
    > > >
    > > > Is that what the effects of a ping flood look like?
    > >

    Yes, that's exactly what happens when ping-flooded.

    Note that only root can ping-flood.

    > It could be a ping flood, but if its happening after named dies, its more
    > likely your kernel sending back messages to all the hosts asking for DNS
    > requests. i.e. since named is dead, you had 231 DNS requests coming in per
    > second. The kernel, limits its response to the first 200 hosts, sending
    > back a message saying there is nothing listening on that port.

    He is talking about icmp packets - nothing to do with named.

    --
    

    :{ andyfspeednet.com.au

    Andy Farkas System Administrator Speednet Communications http://www.speednet.com.au/

    To Unsubscribe: send mail to majordomoFreeBSD.org with "unsubscribe freebsd-security" in the body of the message