Bitcoin Forum

Bitcoin => Bitcoin Discussion => Topic started by: NghtRppr on June 22, 2011, 10:37:22 PM



Title: someone is syn flooding clients
Post by: NghtRppr on June 22, 2011, 10:37:22 PM
I recently launched the client on my school's network and I got a bunch of syn flood attack warnings.


Title: Re: someone is syn flooding clients
Post by: ius on June 22, 2011, 10:40:20 PM
And you're absolutely sure it isn't due to the multitude of peers trying to connect to you? ;)


Title: Re: someone is syn flooding clients
Post by: NghtRppr on June 22, 2011, 10:44:00 PM
And you're absolutely sure it isn't due to the multitude of peers trying to connect to you? ;)

It's never triggered it before but no I'm not sure.


Title: Re: someone is syn flooding clients
Post by: btc_man on June 22, 2011, 11:19:40 PM
are they to/from an ip you know?


Title: Re: someone is syn flooding clients
Post by: phorensic on June 22, 2011, 11:43:17 PM
I would say it's the p2p nature of the client downloading blocks that is setting off your firewall.  It will use a lot of connections if you let it run for a while.


Title: Re: someone is syn flooding clients
Post by: zer0 on June 23, 2011, 01:10:30 AM
i run bitcoind over Tor seems the best way to prevent floods or somebody finding it


Title: Re: someone is syn flooding clients
Post by: JoelKatz on June 23, 2011, 01:18:28 AM
I recently launched the client on my school's network and I got a bunch of syn flood attack warnings.
If it goes away in a few minutes, it's probably completely normal. The client wants to be well-connected as quickly as possible and this may set off attack warnings on some systems.

If someone has a chance, it would be helpful to run the client on a machine that is monitored for traffic and connection volume. At least count SYNs to the bitcoin port. Ideally, use the IP for nothing else for awhile and log *all* traffic to it to see if you get probes, attack attempts, and the like. Post your summarized statistical results so we can have a baseline for what's normal. If nobody else does this, I'll try to do it myself tomorrow sometime.


Title: Re: someone is syn flooding clients
Post by: bitcoinBull on June 23, 2011, 01:54:44 AM
I recently launched the client on my school's network and I got a bunch of syn flood attack warnings.
If it goes away in a few minutes, it's probably completely normal. The client wants to be well-connected as quickly as possible and this may set off attack warnings on some systems.

If someone has a chance, it would be helpful to run the client on a machine that is monitored for traffic and connection volume. At least count SYNs to the bitcoin port. Ideally, use the IP for nothing else for awhile and log *all* traffic to it to see if you get probes, attack attempts, and the like. Post your summarized statistical results so we can have a baseline for what's normal. If nobody else does this, I'll try to do it myself tomorrow sometime.

Would be quite helpful if somebody(s) set up several honeypots and left them connected to the network, reporting the results periodically.  There are downloadable honeypot configurations that should make this easy enough.