The new forums will be named Coin Return (based on the most recent vote)! You can check on the status and timeline of the transition to the new forums here.
The Guiding Principles and New Rules document is now in effect.

Firewall Log: DoS Attack Blocked...from NASA?

SoCo_and_LimeSoCo_and_Lime Registered User regular
edited September 2009 in Help / Advice Forum
Just checked my firewall log on my router, showing a bunch of blocked DoS attacks. After running an IP lookup on several of the entries, mostly just random shit, one came back to something interesting:

NASA?

I've probably been to this site, or something off of it, VIA Stumble at some point.

I have a very vague understanding of this shit but could use some actual insight/advice/etc. Does any of this seem strange or mean anything?

[x] Bolt Bus
[x] Radisson Hotel Boston
[x] Pre-Pax Dinner
[x] BYOC and 3 Day Pass

SoCo_and_Lime on

Posts

  • TechBoyTechBoy Registered User regular
    edited September 2009
    It's really easy to spoof IP headers and in the case of DoS attacks it's pretty much standard practice to make the attacks look like they're coming from all sort of random places.

    It's either completely random that NASA's ip was one of the sources, or whomever is DoSing you decided to spoof with real, legitimate websites.

    TechBoy on
    tf2_sig.png
  • SoCo_and_LimeSoCo_and_Lime Registered User regular
    edited September 2009
    TechBoy wrote: »
    It's really easy to spoof IP headers and in the case of DoS attacks it's pretty much standard practice to make the attacks look like they're coming from all sort of random places.

    It's either completely random that NASA's ip was one of the sources, or whomever is DoSing you decided to spoof with real, legitimate websites.

    Yeah that's about what I figured

    SoCo_and_Lime on
    [x] Bolt Bus
    [x] Radisson Hotel Boston
    [x] Pre-Pax Dinner
    [x] BYOC and 3 Day Pass

  • DirtyDirtyVagrantDirtyDirtyVagrant Registered User regular
    edited September 2009
    I'm not really up on my network security yet. Can you get a mac address?

    DirtyDirtyVagrant on
  • MKRMKR Registered User regular
    edited September 2009
    I'm not really up on my network security yet. Can you get a mac address?

    MAC addresses are pretty much node to ISP (or within the same local network) and don't go out over the interwebs.

    And it's also possible that NASA either has a compromised system or someone was doing a very poorly thought out experiment. You might want to e-mail them and ask.

    MKR on
  • embrikembrik Registered User regular
    edited September 2009
    MKR wrote: »
    I'm not really up on my network security yet. Can you get a mac address?

    MAC addresses are pretty much node to ISP (or within the same local network) and don't go out over the interwebs.

    And it's also possible that NASA either has a compromised system or someone was doing a very poorly thought out experiment. You might want to e-mail them and ask.

    Yeah, MAC addresses are not routeable. They're layer 2 addressing, used on the same network segment.

    embrik on
    "Damn you and your Daily Doubles, you brigand!"

    I don't believe it - I'm on my THIRD PS3, and my FIRST XBOX360. What the heck?
  • MKRMKR Registered User regular
    edited September 2009
    I forgot pretty much all of the OSI model when I finished school. Perhaps I should rectify that.

    MKR on
  • underdonkunderdonk __BANNED USERS regular
    edited September 2009
    MKR wrote: »
    I forgot pretty much all of the OSI model when I finished school. Perhaps I should rectify that.

    http://en.wikipedia.org/wiki/OSI_model

    Probably spoofed, but it would be considered polite and appropriate to report it to them.

    underdonk on
    Back in the day, bucko, we just had an A and a B button... and we liked it.
  • midgetspymidgetspy Registered User regular
    edited September 2009
    It's entirely possible that a NASA box is rooted and operating as a bot for somebody - NASA isn't some special computer fortress or anything (especially their public computers like that web server). I've seen many bots running off NASA shells on IRC over the years, so I'd definitely email them and let them know exactly what you received and when from that IP.

    midgetspy on
  • underdonkunderdonk __BANNED USERS regular
    edited September 2009
    midgetspy wrote: »
    It's entirely possible that a NASA box is rooted and operating as a bot for somebody - NASA isn't some special computer fortress or anything (especially their public computers like that web server). I've seen many bots running off NASA shells on IRC over the years, so I'd definitely email them and let them know exactly what you received and when from that IP.

    This is true.

    We actually saw traffic from them (and the Army) during the early hours of the Nimda outbreak.

    underdonk on
    Back in the day, bucko, we just had an A and a B button... and we liked it.
  • DogDog Registered User, Administrator, Vanilla Staff admin
    edited September 2009
    They're on to you.

    You need to move the specimen to a more secure location.

    Unknown User on
  • ZampanovZampanov You May Not Go Home Until Tonight Has Been MagicalRegistered User regular
    edited September 2009
    robothero wrote: »
    They're on to you.

    You need to move the specimen to a more secure location.

    Dude. Dude.

    Ixnay on the ecimenspay.

    Zampanov on
    r4zgei8pcfod.gif
    PSN/XBL: Zampanov -- Steam: Zampanov
Sign In or Register to comment.