[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

SV: [cobalt-users] PortSentry works !



-----Ursprungligt meddelande-----
Fran: cobalt-users-admin@xxxxxxxxxxxxxxx
[mailto:cobalt-users-admin@xxxxxxxxxxxxxxx]For
johnm@xxxxxxxxxxxxxxxxxxxx
Skickat: den 15 mars 2001 09:55
Till: cobalt-users@xxxxxxxxxxxxxxx
Amne: [cobalt-users] PortSentry works !


Hi there,

Just thought I'd tell anyone that doesn't have PortSentry (or something 
similar) installed, about my latest report.

I had read a lot about PortSentry and was thinking about installing it 
when I saw an offer on this list from John Cordeiro to have it installed 
for (I think) $15.  Not being an expert in Linux, despite having been in 
IT for 25 years I took up the offer and had both PortSentry and LocCheck 
installed for $30.  Boy, am I glad I did.

I generally get 3 or 4 'scans' per day - on the normal ports 111 etc with 
a report size of about 3,500 - 4,000 bytes.   However last night one of my 
hourly reports was over 1.2Mb in size - someone had scanned almost every 
port on the system, fortunately they had been clocked after the first port 
but there's an awful lot of lines in the report.

I've reported this attack to British Telecom (they 'own' the dial-up line 
used to scan the server) and am going to take the eveidence to the Police 
to-day to report an offence under the Computer Misuse Act (the first time 
since both te server ad the attacked are based in the UK).  Lets hope that 
it scares the sh*t out of someone.

Cheers

John

_______________________________________________
cobalt-users mailing list
cobalt-users@xxxxxxxxxxxxxxx
To Subscribe or Unsubscribe, please go to:
http://list.cobalt.com/mailman/listinfo/cobalt-users