Securifi Community Forum

Securifi Products => Almond+ => Topic started by: francehopper on November 26, 2014, 01:54:57 pm

Title: Almond+ Suspected of DDOS Attack
Post by: francehopper on November 26, 2014, 01:54:57 pm
So I woke up this morning to this email from our central IT department at my university (edited for their spelling mistakes):
"Your device is exposing a recursive DNS resolver and an SSDP service to the internet which is being leveraged in a DDOS attack."

They've already isolated its network jack since the email came in an hour ago. I'm away for the holiday but will have to deal with this on Sunday now. Any suggestions? Personally, I'm inclined to say they're bullshitting to get revenge for complaining about the internet outage we had yesterday and calling them out for never logging a downtime incident for it.
Title: Re: Almond+ Suspected of DDOS Attack
Post by: jjoepaulines on November 26, 2014, 07:33:12 pm
As i remember , You turn-off  your firewall right ? ....

REF : http://forum.securifi.com/index.php/topic,1501.msg7380.html#msg7380
Title: Re: Almond+ Suspected of DDOS Attack
Post by: francehopper on November 26, 2014, 07:35:29 pm
With the constant brute force attempts and port scans that were coming in as a result, it's been back on for a while now.
Title: Re: Almond+ Suspected of DDOS Attack
Post by: jjoepaulines on November 26, 2014, 09:46:28 pm
You got these alert because of port 53 which belongs to Dnsmasq been exposed to wan side ..

Please share you config file of your ALmond plus via PM @joe.john@securifi.com to analyse your problem.
Title: Re: Almond+ Suspected of DDOS Attack
Post by: francehopper on November 26, 2014, 09:52:46 pm
You got these alert because of port 53 which belongs to Dnsmasq been exposed to wan side ..

Please share you config file of your ALmond plus via PM @joe.john@securifi.com to analyse your problem.


I'll have to send it Sunday when I'm back from my holiday break.
Title: Re: Almond+ Suspected of DDOS Attack
Post by: chevyman142000 on November 28, 2014, 11:06:26 am
I have gotten a similar email from my ISP about a month or so ago for the same reasons. I resolved by not allowing the router to respond on the WAN interface. Only downside to this is I cannot get to the web interface from outside of my home network.
Title: Re: Almond+ Suspected of DDOS Attack
Post by: francehopper on November 28, 2014, 11:49:26 am
I have gotten a similar email from my ISP about a month or so ago for the same reasons. I resolved by not allowing the router to respond on the WAN interface. Only downside to this is I cannot get to the web interface from outside of my home network.

I'll have to look in to that.

EDIT: @Joe: I've sent you an email with my settings.