|
Register | FAQ | The Twelve Commandments | Members List | Calendar | Arcade | Find the Best VPN | Today's Posts | Search |
| LinkBack | Thread Tools | Display Modes |
| |||
1000's of 6346 hits from one IP-help! For a few days last week I was on the Gnutella network for the first time with Limewire 1.6d. Though it's been several days since I disconnected, my firewall logs show tens of thousands of port 6346 hits from a single IP: 131.116.76.178. And there does not seem to be any end in sight. Having used the Gnutella network for well over a year with various servents, I am quite familiar with the lingering effects of 6346 port activity after terminating the use of a servent. I never considered it to be much of a problem. However, this current situation is beyond tolerance and is affecting my ability to monitor my firewall logs for real threats. Can you offer any help? Thank you. ps I've already disconnected the computer from the network for 24 hrs pps I've already sent email to abuse@, registry@ and dns@telia.net ppps I'm posting here as I would think there is a more powerful user base on this thread than others and perhaps the next Limewire (or next generation of servents in general) can disconnect from the Gnutella network without the lingering 6346 port activity Thanks again. |
| |||
Your experience adds to my suspicion that there is some sort of DoS attack taking place in Gnutella these past several months. Since LimeWire offers so little diagnostic info, I haven't been able to prove or disprove anything, but I've definitely noticed a dropoff in network performance. I wouldn't be surprised if the RIAA or the movie industries was secretly paying some hackers to disrupt things. The question is: what can be done to improve the Gnutella protocol/network to resist DoS attacks? |
| |||
I've noticed a drop-off too. I'm using Gnucleus which gives you more info than LimeWire, but I can't really see anything too unusual. What I'm seeing mostly is a drop-off in the number search results VS. searches. Usually this kind of thing happens when a more popular client makes a change (or has a bug) in its handling of things. In such cases I like to hope it's usually accidental and will be fixed. Unfortunately, as the number of different peers increases this kind of problem may become more likely. A ddos attack would have to come in the form of a flood of search, ping, or pong packets (etc.) since completely bad packets are usually just dropped, but while I'm seeing a lot of those, it's not unusually high (at least to my eyes). |
| |
Similar Threads | ||||
Thread | Thread Starter | Forum | Replies | Last Post |
6346!!!! :( | JayJay04 | General Windows Support | 1 | February 16th, 2006 03:57 AM |
Port 6346 hits... | dilbert666 | General Gnutella / Gnutella Network Discussion | 2 | June 27th, 2002 06:49 PM |
6346 Hits | MadAxe | General Gnutella / Gnutella Network Discussion | 7 | October 3rd, 2001 05:36 PM |
1000's of 6346 hits from one IP-help! | dallas7 | General Gnutella / Gnutella Network Discussion | 2 | September 16th, 2001 03:13 PM |
2 instances on 127.0.0.1:6346 | rip | General Discussion | 1 | March 6th, 2001 04:26 PM |