View Issue Details

IDProjectCategoryView StatusLast Update
0005398Networks[All Projects] Specialpublic2024-09-12 05:17
ReporterDigitalMy 
PrioritynormalSeverityminorReproducibilityhave not tried
Status assignedResolutionopen 
Summary0005398: block DDoS attacks to servers
DescriptionHave got many of
ping icmp from botnet
every day password brute-force
TagsNo tags attached.

Activities

DigitalMy

2024-07-24 14:19

administrator   ~0014311

Last edited: 2024-09-11 14:55

View 3 revisions

Got hanging of router and
crash page cgi-bin/luci/admin/status/realtime/connections
service rpcd restart
some DDOS going on router, suspected DNS ports (load reduced in case disable forwarding)

shows many ICMP UDP TCP traffic

DigitalMy

2024-09-11 15:11

administrator   ~0014373

Last edited: 2024-09-12 05:17

View 4 revisions

Set OpenWRT firewall
/cgi-bin/luci/admin/network/firewall/rules

limit matching ICMP 2 packets per minute does not work

first list "allow" rules, after list "drop" rules (bottom)

added to wan zone in /etc/config/firewall
option 'conntrack' '1'

DigitalMy

2024-09-11 18:35

administrator   ~0014375

find ports to close
netstat -tunpl
have UDP 5678 online
have dnsmasq on IPv6