Re: Ftp attack
[email protected] Tue, 28 Jun 2005 10:15:12 -0500
| Newsgroups | gmane.network.ftp.wuftpd.user |
|---|---|
| Message-ID | <OFB9F59EB4.30B65C12-ON8625702E.0052E362-8625702E.0053C2D7@natinst.com> |
This may or may not be a DoS attack. One of the more unfortunate and
poorly understood things about FTP is that many clients use what they often
call "download acceleration". What this means is that one client opens up
a bunch of simultaneous connections to download a file piecemeal.
For example, someone looking to download a 1 MB file might open 10
connections - the first getting bytes 1-100k, the second getting bytes
100,001 - 200k, etc., and then assembling them on the client side. FTP
supports this, which from some points of view is cool, but from the server
administrator point of view it's a problem.
There's no standard for this, so clients use whatever "brilliant" formula
their developer came up with. So, for example, some download accelerators
say "open as many connections as it takes to get me the file in 1 MB
chunks". Our FTP site has lots of files sized in the hundreds of GB, and
so a client like this will abruptly open, say, 200 connections. As wuftpd
can't limit number of client connections per IP you're effectively
defenseless; you can set the max public connections but then though they
don't crash your server they do DoS other users.
On another note, these download accelerators show up in your logs as
separate downloads with sizes smaller than the entire filesize (that's how
you can ID them). But note that the i/c flag is NOT set reliably by them -
in theory, they'd set it right, and you could tell a download accelerator
session by it having a batch of i's and one final c. For a variety of
reasons this is never the case. Do not trust it.
All the log analysis tools out there that do FTP do NOT handle this
correctly either, and so if you are relying on any of those for FTP stats
you are getting inflated numbers (as one download accelerator would look
like 10+ downloads of a single file). We had to write a custom FTP log
preprocessor that would try to identify accelerator sessions and boil them
down into one line for later processing.
Welcome to the wide world of FTP...
Ernest
"Gopinath Rao"
<[email protected]
om> To
Sent by: <[email protected]>
owner-wuftpd-ques cc
[email protected]
Subject
Ftp attack
06/28/2005 09:55
AM
Hi All,
we are running a wu-ftpd 2.6.2 version. we see DOS attack . log file
indicated. is it possible to protect ftpd from these attacks.
Thanks
Gopi
ftp ftp 208.136.broadban Fri Jun 24 09:34 - 09:34 (00:00)
ftp ftp 208.136.broadban Fri Jun 24 09:34 - 09:34 (00:00)
ftp ftp 208.136.broadban Fri Jun 24 09:34 - 09:34 (00:00)
ftp ftp 208.136.broadban Fri Jun 24 09:34 - 09:34 (00:00)
ftp ftp 208.136.broadban Fri Jun 24 09:34 - 09:34 (00:00)
ftp ftp 208.136.broadban Fri Jun 24 09:34 - 09:34 (00:00)
ftp ftp 208.136.broadban Fri Jun 24 09:34 - 09:34 (00:00)
ftp ftp 208.136.broadban Fri Jun 24 09:34 - 09:34 (00:00)
ftp ftp 208.136.broadban Fri Jun 24 09:34 - 09:34 (00:00)
ftp ftp 208.136.broadban Fri Jun 24 09:34 - 09:34 (00:00)
ftp ftp 208.136.broadban Fri Jun 24 09:34 - 09:34 (00:00)
ftp ftp 208.136.broadban Fri Jun 24 09:33 - 09:33 (00:00)
ftp ftp 208.136.broadban Fri Jun 24 09:33 - 09:33 (00:00)
ftp ftp 208.136.broadban Fri Jun 24 09:33 - 09:33 (00:00)
ftp ftp 208.136.broadban Fri Jun 24 09:33 - 09:33 (00:00)
ftp ftp 208.136.broadban Fri Jun 24 09:33 - 09:33 (00:00)
ftp ftp 208.136.broadban Fri Jun 24 09:33 - 09:33 (00:00)
ftp ftp 208.136.broadban Fri Jun 24 09:33 - 09:33 (00:00)
ftp ftp 208.136.broadban Fri Jun 24 09:33 - 09:33 (00:00)