On Mon, 2 May 2005 07:14:16 -0700 (PDT) Jack quiet_celt@yahoo.com wrote:
Wow! That's great news! Ok, so the plan looks rto be to add the ipaddresses to iptables and change the port for sshd. Other ports are being probed and attacked, but not as frequently and not nearly as aggressively. I'll modify my blacklist gathering script to automatically add the new addresses to iptables and send me an email listing the new addresses.
I would block all ports from those addresses. If they are attacking you on one port they could very well be attacking you on others. I guess you have to ask yourself the question, "Is there any reason I would need/want E-mail from an IP that is actively attacking me or is otherwise compromised?" If you answer yes, then I think you might need your head examined. ;)
--------------------------------- Frank Wiles frank@wiles.org http://www.wiles.org ---------------------------------