Re: UDP flood

LuKreme <kremels-/[email protected]> Thu, 6 Feb 2014 08:34:58 -0700
Newsgroups gmane.comp.macosx.admin
Message-ID <[email protected]>
On 05 Feb 2014, at 05:38 , David Herren-Lage <[email protected]> wrote:
> On Feb 4, 2014, at 11:01 PM, LuKreme <kremels-/[email protected]> wrote:

>> Chances are good that you are being used as a reflector/multiplier for a=
 UDP DDOS if the amount of traffic is really a large number, but that=92s j=
ust a guess.

> Any suggestions on how to determine that? And if it's so, how the heck to=
 I fix it?

It can be hard to find the source of UDP issues.

Start turning things off that you are running. The first suspect is DNS, bu=
t since you aren=92t running that, check things like ntp. Do a port scan on=
 your own machine and see what=92s open. Drop into the Terminal and look at=
 the output of ps auxww | more carefully. Check /tmp and /var/tmp. See if t=
here=92s a spurious /var/temp with stuff in it.

Do you run a webserver? Maybe something like awstats, phpBB, webmin, or wor=
dpress? Is everything updated?

Also, what is =93a lot=94 of UDP packets? Are you sure what you think is a =
lot is really a lot? What does the activity monitor on your system show for=
 network traffic?

-- =

If you think that Mick Jagger will still be doing the whole rock star
thing at age fifty, well, then, you are sorely, sorely mistaken.