Results 1 to 3 of 3
Thread: TCP: Treason uncloaked
-
06-06-2005, 02:25 AM #1Temporarily Suspended
- Join Date
- Oct 2003
- Location
- Hanoi
- Posts
- 4,309
TCP: Treason uncloaked
Hello
one of our servers seems under attack. In dmesg, it shows
TCP: Treason uncloaked! Peer 203.113.161.127:1377/80 shrinks window 1801780131:1801784427. Repaired.
TCP: Treason uncloaked! Peer 161.57.231.33:2622/80 shrinks window 2655921439:2655933284. Repaired.
TCP: Treason uncloaked! Peer 203.113.162.154:1275/80 shrinks window 224138556:224141588. Repaired.
TCP: Treason uncloaked! Peer 203.113.162.154:1275/80 shrinks window 224218580:224220348. Repaired.
I have suspended the account under attack, but is there anyway to protect from this kind of attack?
thanks
-
06-06-2005, 12:42 PM #2Junior Guru
- Join Date
- Oct 2003
- Location
- Long Island, New York
- Posts
- 220
This seems possibly indicitive of an attack, however it looks more like a malfunctioning IP stack. I don't see how you could relate this to a particular vhost or user account.. Can you explain more about how you did that?
TWSites.com - Business Web Hosting Solutions & Server Management Since 2003
-
06-06-2005, 07:53 PM #3Web Hosting Master
- Join Date
- Jan 2001
- Posts
- 2,605
That is completely harmless. Ignore it, and turn off the warning message.
Dr. Colin Percival, FreeBSD Security Officer
Online backups for the truly paranoid: http://www.tarsnap.com/