Determining IP of 27001 Error
Posted in 2008
\
Tracing client IP address with xtrace <http://www-01.ibm.com/support/docview.wss?rs=630&context=SSGU8G&context=SSZ2HS&context=SSP6X2&context=SSVHPS&context=SSHPYE&q1=xtrace+ip&uid=swg21162482&loc=en_US&cs=utf-8&lang=en> Particularly , I don't think this is a good method to detect the IP, because isn't easy to keep in execution and can affect the performance of your database. My suggestion is use iptables on Linux to log incoming connections. So far I know , there no other way to do this... same in IDS 11.50.... ________________________________ De: "red_valsen@yahoo.com" <red_valsen@yahoo.com> Para: informix-list@iiug.org Enviadas: Terça-feira, 16 de Dezembro de 2008 19:31:02 Assunto: Determining IP of 27001 Error >From time to time a security utility is placed somewhere on our network that periodically hammers my informixserver port, not quite completing its handshake and filling the message log to absurd size with errors like this: 09:10:32 listener-thread: err = -27001: oserr = 0: errstr = : Read error occurred during connection attempt. Is there any way to capture the IP address from which this annoyance originates as non-root user informix? I'd then be able to forward the the info to our network nazis for detection, apprehension and execution. Using IDS 10.00.FC6 on RedHat Enterprise Linux 4. _______________________________________________ Informix-list mailing list Informix-list@iiug.org http://www.iiug.org/mailman/listinfo/informix-list Veja quais são os assuntos do momento no Yahoo! +Buscados http://br.maisbuscados.yahoo.com
There are a couple of different ways to capture IP information. You could use a network analyzer like wireshark. I think that IBM needs to do more things to make the logging of the connection information easier and efficient. In cases where the engine is used solely for Web apps and there should be minimal connections from apps directly, then you should be able to turn off the logging. Otherwise you should be able to keep it on. I agree that there is a cost for this feature. However in terms of securing your database, for those who need it, the cost is cheap when you consider the alternatives. This implies that you need to consider the additional overhead in right sizing your box. Of course I'm making the assumption that IBM is also considering the importance of tracking these connections as part of their overall security concerns. But hey! What do I know? I'm not in charge of the engine or set Jonathan's priorities. :-) -G PS Since Mark T. and Serge both read c.d.i, I'd say that this would be important to both DB2 and Oracle. On Dec 17, 5:07 am, Cesar Inacio Martins <cesar_inacio_mart...@yahoo.com.br> wrote: > Tracing client IP address with xtrace > > <http://www-01.ibm.com/support/docview.wss?rs=630&context=SSGU8G&conte...> > > Particularly , I don't think this is a good method to detect the IP, because isn't easy to keep in execution and can affect the performance of your database. > > My suggestion is use iptables on Linux to log incoming connections. > > So far I know , there no other way to do this... same in IDS 11.50.... > > ________________________________ > De: "red_val...@yahoo.com" <red_val...@yahoo.com> > Para: informix-l...@iiug.org > Enviadas: Terça-feira, 16 de Dezembro de 2008 19:31:02 > Assunto: Determining IP of 27001 Error > > >From time to time a security utility is placed somewhere on our > > network that periodically hammers my informixserver port, not quite > completing its handshake and filling the message log to absurd size > with errors like this: > > 09:10:32 listener-thread: err = -27001: oserr = 0: errstr = : > Read error occurred during connection attempt. > > Is there any way to capture the IP address from which this annoyance > originates as non-root user informix? I'd then be able to forward the > the info to our network nazis for detection, apprehension and > execution. > > Using IDS 10.00.FC6 on RedHat Enterprise Linux 4. > _______________________________________________ > Informix-list mailing list > Informix-l...@iiug.orghttp://www.iiug.org/mailman/listinfo/informix-list > > Veja quais são os assuntos do momento no Yahoo! +Buscadoshttp://br.maisbuscados.yahoo.com
> > PS Since Mark T. and Serge both read c.d.i, I'd say that this would be > important to both DB2 and Oracle. > Well - Oracle already tracks connected client IP addresses on the database side, via the SYS_CONTEXT session variables. I sort of presume IDS and DB2 do something similar, as it's not that hard to do. Very useful for security, also very useful for end-to-end performance tracing etc. In this case however, we are looking for the IP address of clients that don't complete a session connection ? So it's sort of like a DOS attack ? Can you limit the range of IP addresses that the listener listens to ? Doesn't identify the culprit but at least mitigates the problem