tcpdump host 210.19.250.210
Une attaque du même type à repris voilà le tcpdump
07:19:25.436359 IP 175.145.93.105.62137 >
secoursssh.mondomaine.net.http: Flags [S], seq 1084614541, win 8192, options [mss 1452,nop,wscale 8,nop,nop,sackOK], length 0
07:19:25.436432 IP
secoursssh.mondomaine.net.http > 175.145.93.105.62137: Flags [S.], seq 1499561818, ack 1084614542, win 64240, options [mss 1460,nop,nop,sackOK,nop,wscale 7], length 0
07:19:25.695466 IP 175.145.93.105.62137 >
secoursssh.mondomaine.net.http: Flags [.], ack 1, win 256, length 0
07:19:31.510551 IP
secoursssh.mondomaine.net.http > 175.145.93.105.62080: Flags [S.], seq 3564908076, ack 55372286, win 64240, options [mss 1460,nop,nop,sackOK,nop,wscale 7], length 0
07:19:50.807006 IP 175.145.93.105.62198 >
secoursssh.mondomaine.net.http: Flags [S], seq 3615006826, win 8192, options [mss 1452,nop,wscale 8,nop,nop,sackOK], length 0
07:19:50.807076 IP
secoursssh.mondomaine.net.http > 175.145.93.105.62198: Flags [S.], seq 3837827955, ack 3615006827, win 64240, options [mss 1460,nop,nop,sackOK,nop,wscale 7], length 0
07:19:51.091706 IP 175.145.93.105.62198 >
secoursssh.mondomaine.net.http: Flags [.], ack 1, win 256, length 0
07:19:56.854548 IP
secoursssh.mondomaine.net.http > 175.145.93.105.62137: Flags [S.], seq 1499561818, ack 1084614542, win 64240, options [mss 1460,nop,nop,sackOK,nop,wscale 7], length 0
07:20:17.153004 IP 175.145.93.105.62254 >
secoursssh.mondomaine.net.http: Flags [S], seq 1831603278, win 8192, options [mss 1452,nop,wscale 8,nop,nop,sackOK], length 0
07:20:17.153115 IP
secoursssh.mondomaine.net.http > 175.145.93.105.62254: Flags [S.], seq 393988377, ack 1831603279, win 64240, options [mss 1460,nop,nop,sackOK,nop,wscale 7], length 0
07:20:17.410812 IP 175.145.93.105.62254 >
secoursssh.mondomaine.net.http: Flags [.], ack 1, win 256, length 0
07:20:22.198547 IP
secoursssh.mondomaine.net.http > 175.145.93.105.62198: Flags [S.], seq 3837827955, ack 3615006827, win 64240, options [mss 1460,nop,nop,sackOK,nop,wscale 7], length 0
07:20:42.494754 IP 175.145.93.105.62311 >
secoursssh.mondomaine.net.http: Flags [S], seq 2014050386, win 8192, options [mss 1452,nop,wscale 8,nop,nop,sackOK], length 0
07:20:42.494859 IP
secoursssh.mondomaine.net.http > 175.145.93.105.62311: Flags [S.], seq 784348536, ack 2014050387, win 64240, options [mss 1460,nop,nop,sackOK,nop,wscale 7], length 0
07:20:42.743537 IP 175.145.93.105.62311 >
secoursssh.mondomaine.net.http: Flags [.], ack 1, win 256, length 0
07:20:48.566539 IP
secoursssh.mondomaine.net.http > 175.145.93.105.62254: Flags [S.], seq 393988377, ack 1831603279, win 64240, options [mss 1460,nop,nop,sackOK,nop,wscale 7], length 0
07:21:07.846470 IP 175.145.93.105.62371 >
secoursssh.mondomaine.net.http: Flags [S], seq 1008661856, win 8192, options [mss 1452,nop,wscale 8,nop,nop,sackOK], length 0
07:21:07.846553 IP
secoursssh.mondomaine.net.http > 175.145.93.105.62371: Flags [S.], seq 3750841569, ack 1008661857, win 64240, options [mss 1460,nop,nop,sackOK,nop,wscale 7], length 0
07:21:08.102621 IP 175.145.93.105.62371 >
secoursssh.mondomaine.net.http: Flags [.], ack 1, win 256, length 0
peu de ressource sur gogole mais ce serait bien une attaque lente un peu à la slowloris (mauvais souvenir) mais destinée à saturer une pile netfilter.
J'ai trouvé ça :
https://blog.qualys.com/vulnerabilities-threat-research/2012/01/05/slow-readJe vais la laissé tourner un peu et chercher plus de ressources. De mémoire j'ai de la marge sur les conntrack