[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

RE: [cobalt-users] Raq Hacked



> It would be nice to see or hear of Dial-Up and Broadband ISP's
> cancelling accounts that are being used to run probes and hacking 
> attempts. While a lot of attacks are launched from comprimised servers
> a ton are coming from dial-up and cable modem accounts. Between
> portsentry
> and BlackIce on my pc's I'm intercepting an average of TWELVE attacks
> daily.
> 
> Here's  a list of Denied IP's from just one machine.
> 
> ALL : 216.13.170.3
> ALL : 209.221.133.140
> ALL : 24.65.56.80
> ALL : 209.172.64.4
> ALL : 62.158.129.156
> ALL : 62.227.20.173
> ALL : 217.5.83.4
> ALL : 194.52.191.152
> ALL : 64.6.195.146
> ALL : 213.73.153.109
> ALL : 213.51.116.192
> ALL : 211.207.68.98
> ALL : 211.117.9.77
<snipsnip>

Isn't it interesting to resolve some of theses IPs. The last one comes from one 
of the biggest dial-ups of korea. Sorry, Korea, but the IPs from KRNIC kept 
bothering so much that I put the whole Provider on my black list.

Let's see it this way: the more people use portsentry to keep their garden tidy 
the less traffic will be pushed thru bottle necks...

Regards

Hendrik Runte
--
granus.net