[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[cobalt-users] Proactive action against hack attempts
- Subject: [cobalt-users] Proactive action against hack attempts
- From: "Craig Napier" <craignapier@xxxxxxxxxxx>
- Date: Thu Jan 11 11:07:01 2001
- List-id: Mailing list for users to share thoughts on Cobalt products. <cobalt-users.list.cobalt.com>
I have been watching my log reports for the last week now, and have noticed
that 99% of the attack attempts on my system are from abroad. Are IPs
segregate by country or anything?
I guess somewhat - I got so tired of seeing daily (hourly) probes from North
Korea that I've pretty much blocked the whole damn country <north and south
since I have no clients from Korea>... For me, Korea was one of the worse
abusers... Far more than any other location... I spent a good 1-3 hours
looking up IP blocks that I gathered from repeated attacks and just
black-holed 'em all in hosts.deny... Seems to have helped as the scans from
Korea have almost stopped completly.
I'd personally install portsentry <if you haven't already> at the *very*
least... I'm working on IP chains for one of my boxes at the moment.. <bit
of a trick> but at least install portsentry to monitor/block TCP
probes/scans..
Cheers!
Craig Napier
_________________________________________________________________
Get your FREE download of MSN Explorer at http://explorer.msn.com