Jump to content

SYN Flood Attacks windows 2000


Recommended Posts

Hi everyone my windows 2000 sp4 just been SYN Flood Attacked and it cannot go Online, once it go online the attack will happen again, i've already do serveral reg fix to remove this syn flood but cannot make it, my server got the most updated HF.

anyone face this problem b4 ?? pls guide me . Thx in advance

post-21704-1118064869_thumb.jpg

Link to comment
Share on other sites


What registry values did you tweak?

Under HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services, have you added Microsoft's recommended settings?

Value Name Value (REG_DWORD)

SynAttackProtect 2

TcpMaxPortsExhausted 1

TcpMaxHalfOpen 500

TcpMaxHalfOpenRetried 400

TcpMaxConnectResponseRetransmissions 2

TcpMaxDataRetransmissions 2

EnablePMTUDiscovery 0

KeepAliveTime 300000 (5 minutes)

NoNameReleaseOnDemand 1

Link to comment
Share on other sites

it is a service hiding under system32 and it only will triggle once u go online if u are not ONLINE <---- join public , it's like normal if u stay in private.

identify the particural service and delete it. (unpack32.exe).

So u need to apply the microsoft recemmemed tweak as fdv posted ( there is some more ) i can found it so i think there won't be a problem for u all

Hope this help

Best Regards to u all

Link to comment
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
  • Recently Browsing   0 members

    • No registered users viewing this page.
×
×
  • Create New...