[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[cobalt-users] Constant problem with one IP 'attacking' me.
- Subject: [cobalt-users] Constant problem with one IP 'attacking' me.
- From: "First Hosting" <sales@xxxxxxxxxxxxxxxxxx>
- Date: Thu Jan 24 07:01:04 2002
- List-id: Mailing list for users to share thoughts on Cobalt products. <cobalt-users.list.cobalt.com>
Hi,
For some time now, I have had the following message reported by Logcheck
on an hourly basis. I have contacted my hosts, who own the IP concerned,
but they say the enquiry is not coming from them.
The message that logcheck gives me every hour is:-
Jan 24 13:00:07 cob698 portsentry[1427]: attackalert: UDP scan from
host: 209.207.168.221/209.207.168.221 to UDP port: 820
Jan 24 13:00:07 cob698 portsentry[1427]: attackalert: Host:
209.207.168.221/209.207.168.221 is already blocked Ignoring
Jan 24 13:04:08 cob698 portsentry[1427]: attackalert: UDP scan from
host: 209.207.168.221/209.207.168.221 to UDP port: 820
Jan 24 13:04:08 cob698 portsentry[1427]: attackalert: Host:
209.207.168.221/209.207.168.221 is already blocked Ignoring
Etc...
I have tried and failed to get rid of these messages - can anyone
suggest what I can do to stop the messages from coming through, or
better still to stop the 'attacks' in the first place.
Thanks in advance,
Ian.