[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[cobalt-users] Installed Portsentry AND just caught my first scan!!



Hi All.

I installed portsentry last night after reading the excellent install
instructions at

http://www.linuxnewbie.org/nhf/intel/security/portsentry1.html

Well 10 minutes ago i received the following in my logsentry email.


Active System Attack Alerts
=-=-=-=-=-=-=-=-=-=-=-=-=-=
May 23 09:11:02 ns portsentry[5240]: attackalert: Connect from host:
211.236.162.221/211.236.162.221 to TCP port: 111
May 23 09:11:02 ns portsentry[5240]: attackalert: Host 211.236.162.221 has
been blocked via wrappers with string: "ALL: 211.236.162.221"
May 23 09:11:02 ns portsentry[5240]: attackalert: Host 211.236.162.221 has
been blocked via dropped route using command: "/sbin/route add -host
211.236.162.221 reject"

I feel safer already!!

Are there any other great scripts you gurus can recommend for making the
cobalt a safer place.

regards

Mark