Just a friendly reminder that the only KCLUG posting policy that everyone
agrees on is that all posts should have the quoted section of the message you
are replying to trimmed down to only that part which is relevant.
--- "Matthew T. Eskes" wrote:
> Jack wrote:
>
> >My internet server is being actively attacked.
> >I now have a list of 130 addresses attempting to
> >break into my server. Sometimes very aggressivley.
> >I have many of these address blocked, but I am
> >concerned
> >with performance degrading of my server if I block
> all
> >of these addresses and continue to add more on a
> >regular basis. Anyone have any suggestions? There's
> >really nothing on the server worth attacking, but
> it
> >is my mail server.
> >
> >
> >
> I would get that box offline *now*, backup all the
> info and reinstall.
>
Taking the box offline would take down my mail server.
I use this yahoo account for kclug, but I get all my
regular mail through accounts on my mail server. I
didn't say the box has been compromised, I just want
advice on blocking these attacks as much as possible.
But I don't want to bring my box to a crawl to do it.
Thanks,
Brian D.
__________________________________________________
Do You Yahoo!?
Tired of spam? Yahoo! Mail has the best spam protection around
http://mail.yahoo.com
--- Jack <quiet_celt(a)yahoo.com> wrote:
> My internet server is being actively attacked.
> I now have a list of 130 addresses attempting to
> break into my server. Sometimes very aggressivley.
> ...
I forgot to mention, that somehow these attackers are
using two real accounts on the machine. Perhaps one or
more of the attackers was thev previous attacker. Or
possibly, they got the user id from my mail server. I
had a configuration that I forgot to shut off that
would respond to requests for user mail accounts.
That's been turned off. I may consider deleting those
accounts and creating new ones.
Thanks,
Brian D.
__________________________________________________
Do You Yahoo!?
Tired of spam? Yahoo! Mail has the best spam protection around
http://mail.yahoo.com
My internet server is being actively attacked.
I now have a list of 130 addresses attempting to
break into my server. Sometimes very aggressivley.
I have many of these address blocked, but I am
concerned
with performance degrading of my server if I block all
of these addresses and continue to add more on a
regular basis. Anyone have any suggestions? There's
really nothing on the server worth attacking, but it
is my mail server.
Thanks,
Brian D.
__________________________________________________
Do You Yahoo!?
Tired of spam? Yahoo! Mail has the best spam protection around
http://mail.yahoo.com
--- "D. Hageman" <dhageman(a)dracken.com> wrote:
>
> You could easily use any of the following to achieve
> your goal:
>
> NFS
> Samba
> OpenAFS
>
> Each has its pros and cons.
That was kind of my point in asking.
Although I really hadn't given NFS serious thought.
Last I remember NFS was a rootkit waiting to happen.
I'm looking for something that is somewhat
transparent,
easy to manage, doesn't need babysitting, has the *nix
approach to security. I'm not looking for a CVS. That
is another beast entirely. I'm looking for something
where, after cheking out the code I can store it on a
machine dedicated to apache/<db of choice> so my
desktop system doesn't need them running, and modify
the code from my desktop and test the changes as I go.
Then when I'm happy with it check it back into CVS.
In the process my desktop never runs the code, never
saves the code (except in cache memory) and never runs
the CVS depository.
Thanks for the input people,
Brian D.
__________________________________________________
Do You Yahoo!?
Tired of spam? Yahoo! Mail has the best spam protection around
http://mail.yahoo.com
Couldn't you specifically deny all outside access to the box from the
big bad internet? I'd do that via Iptables on your firewall. You are
using a Linux firewall, aren't you?
>-----Original Message-----
>From: kclug-bounces(a)kclug.org [mailto:[email protected]]
>On Behalf Of Jack
>Sent: Friday, April 29, 2005 1:54 PM
>To: Kclug
>Subject: Re: local development server and mapping drives
>
>
>--- "D. Hageman" <dhageman(a)dracken.com> wrote:
>>
>> You could easily use any of the following to achieve
>> your goal:
>>
>> NFS
>> Samba
>> OpenAFS
>>
>> Each has its pros and cons.
>That was kind of my point in asking.
>Although I really hadn't given NFS serious thought.
>Last I remember NFS was a rootkit waiting to happen.
>
>I'm looking for something that is somewhat
>transparent,
>easy to manage, doesn't need babysitting, has the *nix
>approach to security. I'm not looking for a CVS. That
>is another beast entirely. I'm looking for something
>where, after cheking out the code I can store it on a
>machine dedicated to apache/<db of choice> so my
>desktop system doesn't need them running, and modify
>the code from my desktop and test the changes as I go.
>Then when I'm happy with it check it back into CVS.
>In the process my desktop never runs the code, never
>saves the code (except in cache memory) and never runs
>the CVS depository.
>
>Thanks for the input people,
>Brian D.
>
>
>__________________________________________________
>Do You Yahoo!?
>Tired of spam? Yahoo! Mail has the best spam protection around
>http://mail.yahoo.com
>_______________________________________________
>Kclug mailing list
>Kclug(a)kclug.org
>http://kclug.org/mailman/listinfo/kclug
>
I'm looking to add a headless server, in some out of
the way location to make a webserver (intranet)/ db
server. I want to use it for development of websites
and database apps on, from my desktop. But, I want the
ease of use of being able to read and write files
without doing ftp, etc. I'd like to be able to point
Quanta/Konquerer at it and have it look like a local
filesystem. Is this a Samba project? Or is there
another way to accomplish this, while still protecting
the system from remote attacks should someone breach
the firewall, or having the server inadvertantly
expose itself beyond the firewall?
Thanks,
Brian D.
__________________________________________________
Do You Yahoo!?
Tired of spam? Yahoo! Mail has the best spam protection around
http://mail.yahoo.com
Greettings Luggites!
Got a question for those who are using Mozilla mail or
also looking for suggestions. I've had Mozilla Mail
running for a several weeks now, as I now use the PC
for full time work. I've noticed that it disconnects
from my secure IMAP gateway regularly. Which would be
fine, except it doesn't reconnect, and I see no
options to switch from continuous to timed checking.
I've alos noticed that when it disconnects the only
way to then check the mail that has arrived is to
shutdown Mozilla or purge the cache. Also there is no
place I can see to have it put an icon on the task bar
so it will flash when mail arrives. So I've switched
over to using kmail. Anyone else notice this quirky
berhavior with Mozilla or recommend a good mail client
robust enough to use in a work environment?
I'm running KDE and would prefer not to load both KDE
and Gnome libraries as I'm already loading the system
down with dual KDE screen (to placate my lovely wife's
need for her own desktop, that she can use without
having to "hassle with all that crap, everytime she
wants to use it").
Thanks,
Brian Jack
__________________________________________________
Do You Yahoo!?
Tired of spam? Yahoo! Mail has the best spam protection around
http://mail.yahoo.com
--- "Kelsay, Brian - Kansas City, MO"
<brian.kelsay(a)kcc.usda.gov> wrote:
> >-----Original Message-----
> >From: kclug-bounces(a)kclug.org
> [mailto:[email protected]]
> >On Behalf Of Jack
> >
> >I unfortunately will have to see it, just for the
> >completeness thing. Not like TLoR trilogy, which
> was
> >really very good and the extended versions are even
> >better. It would have been nice to have done the
> >Hobbit also.
> >
> >I'm still waiting for the rest of the Dune series
> to
> >come out.
> >
> >Which brings up the topic, was there a novel for
> Star
> >Wars story before the movie? Or was it just a
> script?
> >I assume Stevie choose to start in the middle for a
> >reason (like the beginning part was boring).
> >
> >Brian D.
>
> Stevie? You mean George?
Doh! Yeah.
>
> What is next in the Dune series after Children of
> Dune?
Dune, Dune Messiah (they skipped this one),
Children of Dune, God Emperor of Dune (Leto's story),
and two more that cover a much much later time period.
Brian D.
__________________________________________________
Do You Yahoo!?
Tired of spam? Yahoo! Mail has the best spam protection around
http://mail.yahoo.com
Best bet is:
1) back up any data,
2) format and reinstall,
3) apply all patches,
4) reconfigure and reinstall any necessary 3rd party
stuff.
That is bound to be the safest and fastest method of
fixing it.
Alternatively,
1) back up any data,
2) backoff any recent changes.
3) This may work, but probably won't.
4) This is of course the fastest way of attempting to
fix, refer to rule #3.
--- Zscoundrel wrote:
> My darling bride just updates her 'doze 98 box and
> TOTALLY fubared it.
> It locks up 3 times a day instead of the usual twice
> a week and she is
> not able to connect to a secure website she uses to
> VPN into the work
> LAN.
>
> Any ideas on what needs to be done to fix it. It
> has been several years
> since I lowered myself to tinker with a 'doze box
> that I sort of forget
> the drill.
>
> Walter
>
> * * * * *
>
> This week Bill Gates announced that he would like to
> see the limits
> removed on H1-B visas.
>
> Isn't it good enough that he can afford to BUY India
> without having to
> bring it here for storage???
No, he's just trying to put the rest of the US IT
industry out of work, in order to kill off all
software competition in the US. Resistance is futile. ;')
__________________________________________________
Do You Yahoo!?
Tired of spam? Yahoo! Mail has the best spam protection around
http://mail.yahoo.com