On Mon, 2 May 2005 07:14:16 -0700 (PDT) Jack [email protected] wrote:
Wow! That's great news! Ok, so the plan looks rto be to add the ipaddresses to iptables and change the port for sshd. Other ports are being probed and attacked, but not as frequently and not nearly as aggressively. I'll modify my blacklist gathering script to automatically add the new addresses to iptables and send me an email listing the new addresses.
I would block all ports from those addresses. If they are attacking you on one port they could very well be attacking you on others. I guess you have to ask yourself the question, "Is there any reason I would need/want E-mail from an IP that is actively attacking me or is otherwise compromised?" If you answer yes, then I think you might need your head examined. ;)
--------------------------------- Frank Wiles [email protected] http://www.wiles.org ---------------------------------