Results 1 to 16 of 16

Thread: how to find the IP of someone DOSsing you?

  1. #1
    Senior Member
    Join Date
    Sep 2005
    Posts
    587
    Thanks
    7
    Thanked
    7 times in 7 posts

    how to find the IP of someone DOSsing you?

    Is there a log file or something that shows all the IPs pinging you and stuff?

    This is Win Server 2008

    Thanks

  2. #2
    Registered+
    Join Date
    May 2009
    Posts
    60
    Thanks
    1
    Thanked
    0 times in 0 posts

    Re: how to find the IP of someone DOSsing you?

    Apologies, I know this is not exactly what you asked, but if you do happen to have a Linux machine available that you could put in place of the Windows server, I find that the syslogs are pretty good (I was getting hit pretty hard at one time - particularly with people trying to brute-force my SSH server). If you can set one up the logs are usually in /var/log/messages

    On the Windows side, I guess you've already tried the event viewer? Not sure how much it would log on Server 2008 by default, but it must be possible to set it up to log pretty verbosely

  3. #3
    Senior Member
    Join Date
    Sep 2005
    Posts
    587
    Thanks
    7
    Thanked
    7 times in 7 posts

    Re: how to find the IP of someone DOSsing you?

    thanks, no, I have not looked in the eventlog. I will try to poke around in there tonight.

    About the linux, right now the windows server does not have a router. It is plugged directly into the fiber "modem" thing, and it obtains its static IP addresses manually via the windows' TCP/IP properties for the ethernet card, based on the gateway and information that my ISP provided me.

    I have an unused server, and I was thinking about putting something like IPcop or pFsense on it for a linux router, but that's a bit of a task for me b/c I know jack about linux.

  4. #4
    Gentoo Ricer
    Join Date
    Jan 2005
    Location
    Galway
    Posts
    11,048
    Thanks
    1,016
    Thanked
    944 times in 704 posts
    • aidanjt's system
      • Motherboard:
      • Asus Strix Z370-G
      • CPU:
      • Intel i7-8700K
      • Memory:
      • 2x8GB Corsiar LPX 3000C15
      • Storage:
      • 500GB Samsung 960 EVO
      • Graphics card(s):
      • EVGA GTX 970 SC ACX 2.0
      • PSU:
      • EVGA G3 750W
      • Case:
      • Fractal Design Define C Mini
      • Operating System:
      • Windows 10 Pro
      • Monitor(s):
      • Asus MG279Q
      • Internet:
      • 240mbps Virgin Cable

    Re: how to find the IP of someone DOSsing you?

    pfSense is very easy to use. It has a web interface for daily administration. And the installation process is fairly intutive.
    Quote Originally Posted by Agent View Post
    ...every time Creative bring out a new card range their advertising makes it sound like they have discovered a way to insert a thousand Chuck Norris super dwarfs in your ears...

  5. #5
    Seething Cauldron of Hatred TheAnimus's Avatar
    Join Date
    Aug 2005
    Posts
    17,168
    Thanks
    803
    Thanked
    2,152 times in 1,408 posts

    Re: how to find the IP of someone DOSsing you?

    pfSense is really rather gnarley! Its actually BSD based rather than linux, and is a fork of m0n0wall my favourate hardware firewall for student housing (so easy to set up QoS so that chris's gay 'pictographic research' does not effect your lag for gaming!).

    It is VERY easy to install and get running (so long as the hardware is 'compatable')
    throw new ArgumentException (String, String, Exception)

  6. #6
    Registered+
    Join Date
    Feb 2008
    Posts
    57
    Thanks
    0
    Thanked
    5 times in 5 posts

    Re: how to find the IP of someone DOSsing you?

    Install Wireshark, you can see all the traffic on the wire then.

  7. Received thanks from:

    latrosicarius (06-07-2009)

  8. #7
    The late but legendary peterb - Onward and Upward peterb's Avatar
    Join Date
    Aug 2005
    Location
    Looking down & checking on swearing
    Posts
    19,378
    Thanks
    2,892
    Thanked
    3,403 times in 2,693 posts

    Re: how to find the IP of someone DOSsing you?

    Your router logs may have a history of IP addresses that have connected to your network - have you looked at those? Also have a look at the security event log.
    (\__/)
    (='.'=)
    (")_(")

    Been helped or just 'Like' a post? Use the Thanks button!
    My broadband speed - 750 Meganibbles/minute

  9. #8
    Senior Member
    Join Date
    Sep 2005
    Posts
    587
    Thanks
    7
    Thanked
    7 times in 7 posts

    Re: how to find the IP of someone DOSsing you?

    i looked in the security log but it doesn't show any ip addresses.

    I installed wireshark and i see a bunch of packets being sent to and from my server to various IPs.

    Can someone tell me how to track down the person who is DOS attacking? For instance, is there a way to log the IP of anyone who makes over 100 connections in 5 seconds or something??

    Thank you

  10. #9
    The late but legendary peterb - Onward and Upward peterb's Avatar
    Join Date
    Aug 2005
    Location
    Looking down & checking on swearing
    Posts
    19,378
    Thanks
    2,892
    Thanked
    3,403 times in 2,693 posts

    Re: how to find the IP of someone DOSsing you?

    Could be a DDOS attack from a botnet - very hard to travck down, however that would be a directed attack and unless you have something specific, it is unlikely that you would be the subject of one.

    You can do a whois to find out who the IP address belongs to - normally that will be an ISP, so you can file an abuse report with them. Don't hold your breath for a reply - I only got one twice - one from a US army site, and once in reply to a phishing e mail I received - they took the phishing site down within minutes of my report.

    Many of these attacks originate from China, Russia and former soviet block counties. Rumania seems to be a source for many of the ones I receive - SSH attacks in particular (50,000 on one memorable 24 hour period - but normally between 50 and 2,000 a night)
    (\__/)
    (='.'=)
    (")_(")

    Been helped or just 'Like' a post? Use the Thanks button!
    My broadband speed - 750 Meganibbles/minute

  11. #10
    Senior Member
    Join Date
    Sep 2005
    Posts
    587
    Thanks
    7
    Thanked
    7 times in 7 posts

    Re: how to find the IP of someone DOSsing you?

    Quote Originally Posted by peterb View Post
    it is unlikely that you would be the subject of one.
    I have no doubt they are specifically targeting me. They are rival gaming clans, and I run the most popular game server of this particular type in the world.
    Quote Originally Posted by peterb View Post
    Could be a DDOS attack from a botnet
    I don't think that it would be a "distributed" (DDOS) attack from a botnet; just a regular DOS attack by some scumbag. Two reasons: (1) i just don't think it is likely that a crappy rip-off gaming clan would have the skills and conviction to illegally compromise a large group of computers. (2) I have been DDOSsed before by a real botnet and let me say: it does not just lag you; it fills your entire bandwidth and shuts you down.
    Quote Originally Posted by peterb View Post
    Many of these attacks originate from China, Russia and former soviet block counties. Rumania seems to be a source for many of the ones I receive - SSH attacks in particular (50,000 on one memorable 24 hour period - but normally between 50 and 2,000 a night)
    I have gotten some of those as well, but they are normally not attacks with the intention to deny service, but to brute-force a password to gain access to a server. Now that I changed to using non-standard ports, these foreign attacks have subsided for the most part. They had no particular interest in me, but were just attacking me because I was there.

    My current problem, however is a few people who purposefully direct attacks at me because they see me as "competition" or whatnot.

    I was hoping someone could give me link or quick how-to rundown for getting Wireshark to log any IP addresses that have an abnormally high amount of connections (such as X number in Y seconds). Thanks

  12. #11
    Senior Member watercooled's Avatar
    Join Date
    Jan 2009
    Posts
    11,478
    Thanks
    1,541
    Thanked
    1,029 times in 872 posts

    Re: how to find the IP of someone DOSsing you?

    You should just be able to 'see' the attack in wireshark - look for any packet from the same IP (if you think it's a single machine DoS) which appears a lot. If possible, check the IPs connected to the game server so you can rule them out. Remember, wireshark must run either on the same machine that's being DoS'd or another machine across the network using a HUB, not a switch.
    Hope this helps

    Edit: another option would be to temporarily close the server so there is less to look through in wireshark. Ignore IPs that send only a few packets - a DoS will be a constant flow. But I doubt anyone with the knowledge of how to perform a DoS would bother doing it with a single machine - after all his upload speed is almost certainly lower than your download so wouldn't do much to your server. But, as I've said on another post my friend's brother was DDoS'd by someone on XBL - I found on some news sites/forums on the net that there are paid services that will DDoS someone off XBL if they are winning etc (why they bother doing it and risking 10ys prison I don't know)...
    Last edited by watercooled; 06-07-2009 at 07:08 PM.

  13. #12
    Senior Member
    Join Date
    Sep 2005
    Posts
    587
    Thanks
    7
    Thanked
    7 times in 7 posts

    Re: how to find the IP of someone DOSsing you?

    Right, watercooled. I was just sitting there looking at the IPs, but there are problems with this approach:

    (1) The attacks are not constant. They occur periodically, and I really have better things to do than just sit in remote desktop 24/7 waiting for them.

    (2) This particular server box is a gameserver with probably 200+ people connected to it at any given time, each one is constantly moving around, jumping, shooting, typing, speaking on their microphones, etc etc. All of that data is sent through the server and relayed to all the other clients in the game. There are *so* many connections flying across the screen that my eyes simply cannot interpret it fast enough.

    That's why I was hoping for some help to set up a log that will capture the malicious connections for me. And by malicious, I mean an IP which is making more connections than normal.

  14. #13
    You're god damn right Barry's Avatar
    Join Date
    Jul 2003
    Posts
    1,484
    Thanks
    70
    Thanked
    75 times in 59 posts
    • Barry's system
      • Motherboard:
      • Gigabyte Z270M-D3H
      • CPU:
      • Intel i7 7700
      • Memory:
      • 16GB (2x8GB) Avexir 2400
      • Storage:
      • Samsung 860 256GB SSD, Sandisk Ultra 3D 500GB, LG BR Writer
      • Graphics card(s):
      • Evga GeForce GTX Titan X 12GB
      • PSU:
      • Corsair RM750I
      • Case:
      • Fractal Design Focus G
      • Operating System:
      • Windows 10 Professional
      • Monitor(s):
      • 28" Acer UHD 4K2K
      • Internet:
      • Sky Fibre

    Re: how to find the IP of someone DOSsing you?

    smsniff is also a good app for checking, it will show you the amount of data and type being sent
    Someone left a note on a piece of cake in the fridge that said, "Do not eat!". I ate the cake and left a note saying, "Yuck, who the hell eats paper ?

  15. #14
    The late but legendary peterb - Onward and Upward peterb's Avatar
    Join Date
    Aug 2005
    Location
    Looking down & checking on swearing
    Posts
    19,378
    Thanks
    2,892
    Thanked
    3,403 times in 2,693 posts

    Re: how to find the IP of someone DOSsing you?

    Sorry, didn't know you were running a game server, or likely to be targeted. Some form of log analyser (like awstats - not sure if that would work in your set up though) might help to determine something after the event. Google may be useful for something more suitable.
    (\__/)
    (='.'=)
    (")_(")

    Been helped or just 'Like' a post? Use the Thanks button!
    My broadband speed - 750 Meganibbles/minute

  16. #15
    Senior Member
    Join Date
    May 2009
    Location
    Norfolk
    Posts
    474
    Thanks
    3
    Thanked
    26 times in 26 posts
    • pipTheGeek's system
      • Motherboard:
      • Asus P6T Deluxe
      • CPU:
      • Core i7 920 @ 3.6GHz
      • Memory:
      • 3 * 2Gb Corsair XMS @ DDR3 1800
      • Storage:
      • 300GB 15K SAS + 500Gb
      • Graphics card(s):
      • GTX570
      • PSU:
      • corsair 760i
      • Case:
      • Corsair 550d
      • Operating System:
      • Windows 7
      • Monitor(s):
      • Dell Alienware 23"
      • Internet:
      • VM 50Mb

    Re: how to find the IP of someone DOSsing you?

    If you set a filter of tcp.flags == 2 in wireshark, then it will capture only the syn packets. This is the type of TCP packet that opens a connection. So you will have far less packets to sift though.
    Sadly, if they are sending UDP (the sort of traffic a game server would normally recieve ) then it won't capture it. The only other way I can think of catching it is to leave the capture running for a while, then stop the capture and start analysing it. Do this by looking for the first source address, then filter the trace to decide if they are playing the game or attacking you. If they are playing the game then apply a different filter that will exclude that address and look for the next address, and so on until you have no log left, or find the culprit.

  17. #16
    Senior Member
    Join Date
    Dec 2005
    Location
    ::1
    Posts
    204
    Thanks
    4
    Thanked
    9 times in 8 posts
    • chinny's system
      • Motherboard:
      • Asus P5Q-EM
      • CPU:
      • Intel E6300
      • Memory:
      • 4Gb Corsair XMS2
      • Operating System:
      • Win7 x64

    Re: how to find the IP of someone DOSsing you?

    Another useful one in Wireshark is to leave it capturing and go to Statistics -> endpoints. Take your pick from ipv4/tcp/udp etc and it'll keep the stats updating for you so you can sort on packets etc.

    Have found that very useful before myself.

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Similar Threads

  1. Lian Li V1200 Plus - Please help can't find it anywhere!!!
    By AFK_Matrix in forum Retail Therapy and Bargains
    Replies: 3
    Last Post: 29-05-2006, 12:07 AM
  2. How do I find the cheapest price?
    By Equinor in forum PC Hardware and Components
    Replies: 19
    Last Post: 15-09-2005, 04:00 PM
  3. Help find a poem
    By eldren in forum General Discussion
    Replies: 2
    Last Post: 09-07-2005, 06:20 PM
  4. Find me this video clip
    By Atomic in forum General Discussion
    Replies: 3
    Last Post: 07-06-2005, 04:36 PM
  5. Replies: 13
    Last Post: 02-05-2005, 07:43 PM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •