Languish.org

General Category => Off the Record => Computer Affairs => Topic started by: viper37 on August 02, 2015, 12:32:54 AM

Title: Syn flood attack coming from network computer: should I be worried?
Post by: viper37 on August 02, 2015, 12:32:54 AM
I've had so much shit last week...

Anyway.  As I was working yesterday night, trying to fix my problems, my office firewall (Eset) detected an attack coming from the other office Windows computer on the network, described as a "Syn flood attack".  Sort of a port scan, from what I gather.

This particular computer has already been scanned with 2 different rescue antivirus (Kaspersky and AVG) wich found nothing.  Previously, since Windows updates would no longer install themselves and a Windows refresh was not working at all, I decided to delete the partition and reinstall Windows 8.1.  Then I installed Eset and Malwarebytes and SuperAntiSpyware and made initial scans, all clean.

I then installed the software I needed, left it on as I was doing something else... and then this warning came.  I immediatly shut down the computer, I did not have time to investigate.

Could this be a false alert or should I be worried there some kind of hidden malware on this computer that is troublesome to find?
Title: Re: Syn flood attack coming from network computer: should I be worried?
Post by: DontSayBanana on August 02, 2015, 07:25:32 AM
Quote from: viper37 on August 02, 2015, 12:32:54 AM
I've had so much shit last week...

Anyway.  As I was working yesterday night, trying to fix my problems, my office firewall (Eset) detected an attack coming from the other office Windows computer on the network, described as a "Syn flood attack".  Sort of a port scan, from what I gather.

This particular computer has already been scanned with 2 different rescue antivirus (Kaspersky and AVG) wich found nothing.  Previously, since Windows updates would no longer install themselves and a Windows refresh was not working at all, I decided to delete the partition and reinstall Windows 8.1.  Then I installed Eset and Malwarebytes and SuperAntiSpyware and made initial scans, all clean.

I then installed the software I needed, left it on as I was doing something else... and then this warning came.  I immediatly shut down the computer, I did not have time to investigate.

Could this be a false alert or should I be worried there some kind of hidden malware on this computer that is troublesome to find?

One of the things I read about SYN floods is that they often use spoofed IP addresses- it doesn't sound like the kind of complex malware that could lodge itself in the master boot record, so the fact that you're still getting a positive from that address even after reinstalling Windows makes me think that might be the case- can you double-check the identity of the attacker at another OSI level, maybe the NIC?
Title: Re: Syn flood attack coming from network computer: should I be worried?
Post by: viper37 on August 02, 2015, 06:50:39 PM
Quotecan you double-check the identity of the attacker at another OSI level, maybe the NIC?


how do I double check the identity of the attacker?  Where and what do I look for?
Title: Re: Syn flood attack coming from network computer: should I be worried?
Post by: DontSayBanana on August 02, 2015, 09:43:41 PM
Quote from: viper37 on August 02, 2015, 06:50:39 PM
Quotecan you double-check the identity of the attacker at another OSI level, maybe the NIC?


how do I double check the identity of the attacker?  Where and what do I look for?

Actually, I'm gonna backtrack a little bit- after thinking about it, my suspicion is an external attacker found some open ports and is routing SYN requests through that machine.  Do you use static IP addresses?
Title: Re: Syn flood attack coming from network computer: should I be worried?
Post by: viper37 on August 02, 2015, 10:06:33 PM
Quote from: DontSayBanana on August 02, 2015, 09:43:41 PM
Quote from: viper37 on August 02, 2015, 06:50:39 PM
Quotecan you double-check the identity of the attacker at another OSI level, maybe the NIC?


how do I double check the identity of the attacker?  Where and what do I look for?

Actually, I'm gonna backtrack a little bit- after thinking about it, my suspicion is an external attacker found some open ports and is routing SYN requests through that machine.  Do you use static IP addresses?
on the network, yes.  Outside (internet), no, dynamic IP from the ISP.
Title: Re: Syn flood attack coming from network computer: should I be worried?
Post by: Darth Wagtaros on August 03, 2015, 04:38:16 PM
Could be a false positive.  You could always turn it on and put Wireshark on.  If your firewall starts up again you can turn on Wireshark.  Or leave it on and filter for SYN traffic.