Democratic Underground Latest Greatest Lobby Journals Search Options Help Login
Google

I need to know what is a "syn port" attack and why would some IP

Printer-friendly format Printer-friendly format
Printer-friendly format Email this thread to a friend
Printer-friendly format Bookmark this thread
This topic is archived.
Home » Discuss » The DU Lounge Donate to DU
 
acmavm Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Nov-04-03 03:06 PM
Original message
I need to know what is a "syn port" attack and why would some IP
administrator in Bombay, India keep attacking my computer. Can anyone tell me what is going on?
Printer Friendly | Permalink |  | Top
amish_enforcer Donating Member (157 posts) Send PM | Profile | Ignore Tue Nov-04-03 03:08 PM
Response to Original message
1. Usually DOS attack
as in Denial of Service, but can have other uses
Printer Friendly | Permalink |  | Top
 
amish_enforcer Donating Member (157 posts) Send PM | Profile | Ignore Tue Nov-04-03 03:08 PM
Response to Original message
2. Is this a server or desktop box? n/t
Printer Friendly | Permalink |  | Top
 
Ellen Forradalom Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Nov-04-03 03:09 PM
Response to Original message
3. Do you mean SYN flooding?
It is a denial-of-service attack in which attacking computer initiates thousands of connections without finishing the 'handshake', thereby sending the victim computer into a tizzy.

SYN refers to the 'synchronize' bit of a packet of data, which initiates a connection between two computers.
Printer Friendly | Permalink |  | Top
 
htuttle Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Nov-04-03 03:13 PM
Response to Original message
4. 'SYN' is a flag that TCP packets carry when they try to connect
IIRC, the first packet in a connection carries a 'SYN' flag.

'SYN floods' are commonly used to determine what ports are open on your machine.

Do you have a firewall on your machine? Somebody is knocking at your door(s)...

NOTE: this doesn't mean you've been singled out -- lots of hackers just scan all the IPs in a range to find out what's there.

Printer Friendly | Permalink |  | Top
 
amish_enforcer Donating Member (157 posts) Send PM | Profile | Ignore Tue Nov-04-03 03:14 PM
Response to Reply #4
5. you remember correctly
SYN then ACK (acknowledge)

but I'm a simple Amish man who knows not of these things ;)
Printer Friendly | Permalink |  | Top
 
htuttle Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Nov-04-03 03:15 PM
Response to Reply #5
6. Never met an Amish hacker before...
...first time for everything...:)

Printer Friendly | Permalink |  | Top
 
amish_enforcer Donating Member (157 posts) Send PM | Profile | Ignore Tue Nov-04-03 03:26 PM
Response to Reply #6
10. yes, our equiptment is not that "mainstream"
Printer Friendly | Permalink |  | Top
 
Ellen Forradalom Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Nov-04-03 03:18 PM
Response to Reply #5
7. The TCP handshake goes like this
First packet (from initiator): SYN bit set
Reply packet(response): SYN and ACK bits set
Third packet (from initiator): ACK bit set

then TCP connection is open

Printer Friendly | Permalink |  | Top
 
Ellen Forradalom Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Nov-04-03 03:19 PM
Response to Original message
8. Aretha sang about that didn't she?
R-E-S-P-E-C-T
Find out what it means to me
R-E-S-P-E-C-T
Open up a TCP
Socket to me
Socket to me
Socket to me
Socket to me
Just a little bit....
Printer Friendly | Permalink |  | Top
 
judge_smales Donating Member (752 posts) Send PM | Profile | Ignore Tue Nov-04-03 03:38 PM
Response to Reply #8
13. Oh God....

And I thought I worked w/ geeks!

R-E-S-P-E-C-T
Find out what it means to me
R-E-S-P-E-C-T
Open up a TCP
Socket to me
Socket to me
Socket to me
Socket to me
Just a little bit....
Printer Friendly | Permalink |  | Top
 
Wonk Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Nov-04-03 03:20 PM
Response to Original message
9. For a detailed technical explanation click here
Printer Friendly | Permalink |  | Top
 
acmavm Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Nov-04-03 03:28 PM
Response to Original message
11. I have a desk top computer and for three days this guy has been
messing with it. I have McAffee on my computer and I can backtrack to who is doing this. I can even get the phone number. Here's some of the info:
ip-admin@giasbmol.vsnl.net.in
IP Adminsitrator, 10th Floor, 2MG Road, Fort Mumhai, India
Phone: +91-22-2623620
Guys name (supposedly) is GP Singh

Every time he does this it just screws up my browser.
Printer Friendly | Permalink |  | Top
 
amish_enforcer Donating Member (157 posts) Send PM | Profile | Ignore Tue Nov-04-03 03:30 PM
Response to Reply #11
12. maybe he doesn't even know its going on (?)
fire him an email maybe from a anon web mail acct
Printer Friendly | Permalink |  | Top
 
DU AdBot (1000+ posts) Click to send private message to this author Click to view 
this author's profile Click to add 
this author to your buddy list Click to add 
this author to your Ignore list Fri Apr 19th 2024, 04:46 PM
Response to Original message
Advertisements [?]
 Top

Home » Discuss » The DU Lounge Donate to DU

Powered by DCForum+ Version 1.1 Copyright 1997-2002 DCScripts.com
Software has been extensively modified by the DU administrators


Important Notices: By participating on this discussion board, visitors agree to abide by the rules outlined on our Rules page. Messages posted on the Democratic Underground Discussion Forums are the opinions of the individuals who post them, and do not necessarily represent the opinions of Democratic Underground, LLC.

Home  |  Discussion Forums  |  Journals |  Store  |  Donate

About DU  |  Contact Us  |  Privacy Policy

Got a message for Democratic Underground? Click here to send us a message.

© 2001 - 2011 Democratic Underground, LLC