Jump to content

Recommended Posts

Posted

Hi everyone my windows 2000 sp4 just been SYN Flood Attacked and it cannot go Online, once it go online the attack will happen again, i've already do serveral reg fix to remove this syn flood but cannot make it, my server got the most updated HF.

anyone face this problem b4 ?? pls guide me . Thx in advance

post-21704-1118064869_thumb.jpg


Posted

What registry values did you tweak?

Under HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services, have you added Microsoft's recommended settings?

Value Name Value (REG_DWORD)

SynAttackProtect 2

TcpMaxPortsExhausted 1

TcpMaxHalfOpen 500

TcpMaxHalfOpenRetried 400

TcpMaxConnectResponseRetransmissions 2

TcpMaxDataRetransmissions 2

EnablePMTUDiscovery 0

KeepAliveTime 300000 (5 minutes)

NoNameReleaseOnDemand 1

Posted

Thx for your reply

yes i have tweaked as microsoft recomemed

anyway i have found a solution to resolve the problem now my server is running smoothly

Posted

it is a service hiding under system32 and it only will triggle once u go online if u are not ONLINE <---- join public , it's like normal if u stay in private.

identify the particural service and delete it. (unpack32.exe).

So u need to apply the microsoft recemmemed tweak as fdv posted ( there is some more ) i can found it so i think there won't be a problem for u all

Hope this help

Best Regards to u all

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
  • Recently Browsing   0 members

    • No registered users viewing this page.
×
×
  • Create New...