FTP login flood attack

FTP login flood attack

Secure Home | Search | About
 Microsoft Applications Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
FTP login flood attack Ralph Hulslander 11-22-2007
Posted by Ralph Hulslander on November 22, 2007, 8:01 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Has anyone else seen and dealt with a reoccuring FTP login flood?

My domain gets hit with a new FTP login flood about every two or three days.

It is allways a different IP but the same boring login attack.

There can be thousands of login attempts.

Essentially this causes a denial of service because IIS allways acknowledges
these

login request (which are allways denied). This uses resources on the server
and slows

things down. The attacks are never successful and are really just a pain but
who

knows what would happen if they succeded.

This never happens on other domains.

How would I deal with this type of attack?

------------------------------------------------------------------

Does anyone know how to get some use out of the Event log?

All of the attempts are recorded in the Event log so I could have a script
looking at the Event log and If three failed attempts at FTP login then turn
of the FTP server for a couple of minutes. This would stop the attack at
least untill the next time.

I am surprised that I have not foundother mention of this kind of attack.

Thanks for any pointers.

Ralph



Similar ThreadsPosted
Flood.F July 28, 2006, 8:43 am
Smart Card Login + Certificate Login to AD -> Lost smart card December 15, 2005, 10:03 pm
Smart Card Login + Certificate Login to AD -> Lost smart card December 15, 2005, 10:41 pm
Help - Hacker attack September 4, 2005, 4:00 pm
ethernet attack April 5, 2006, 12:03 pm
PHP script attack? September 24, 2007, 8:46 am
Help: "Delayed writes" is this an attack? July 29, 2006, 10:39 am
Flash9 DoS attack on IE6SP1 September 27, 2006, 6:44 am
Help: Windows XP cyber attack? July 31, 2007, 3:30 pm
Remote Attack? Modem security January 24, 2006, 9:36 pm

The site map in XML format XML site map

Contact Us | Privacy Policy