From: William Katsak <wkatsak@gmail.com>
To: cerowrt-devel@lists.bufferbloat.net
Subject: [Cerowrt-devel] Possibly Serious Compromise
Date: Sat, 03 Jan 2015 19:20:53 -0500 [thread overview]
Message-ID: <54A88765.5040809@gmail.com> (raw)
I"m having a possible very serious issue with Cero. I started noticing
slow internet access today and checked the router. I noticed a boatload
of dns resolutions. These push the router load over 1, and eventually
dnsmasq crashes and has to be restarted.
After tracing it for an hour or so and ruling out misbehaving software
on the local net, I enabled logging in dnsmasq and saw that the
resolutions were coming from 127.0.0.1. I kept running netstat -up until
I saw some of the connections, and saw that they were coming from lua.
All of the requests seem to be reverse DNS lookups of all kinds of crazy
IPs.
These requests look like part of some attack/compromise. If I kill
lighthttpd, everything settles down and runs fine. If I turn it back on,
the traffic starts again. I am thinking some kind of vulnerability in
the http server allowing malformed requests from outside? I can't for
the life of me figure out how they are getting in though. I have very
few changes to the firewall config, and only a few port forwards.
I'll send more info as I get it.
Anyone else see anything like this?
-Bill
--
****************************************
William Katsak <wkatsak@gmail.com>
****************************************
next reply other threads:[~2015-01-04 0:20 UTC|newest]
Thread overview: 2+ messages / expand[flat|nested] mbox.gz Atom feed top
2015-01-04 0:20 William Katsak [this message]
2015-01-04 0:39 ` Dave Taht
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
List information: https://lists.bufferbloat.net/postorius/lists/cerowrt-devel.lists.bufferbloat.net/
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=54A88765.5040809@gmail.com \
--to=wkatsak@gmail.com \
--cc=cerowrt-devel@lists.bufferbloat.net \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox