Re: RE: Incident response to being scanned

From: Bob Kelley (b0bk3ll3yjr_at_adelphia.net)
Date: 04/26/03

  • Next message: Godfrey, Tyler: "RE: DShield.org Recommended Block List"
    To: <security@riggstar.com>
    Date: Sat, 26 Apr 2003 5:13:51 -0400
    
    

    Yes. All patched, behind a sound firewall and IIS Lockdown. It's a static site so URLScan works like a champ.
    >
    > From: "Security News" <security@riggstar.com>
    > Date: 2003/04/26 Sat AM 01:53:22 EDT
    > To: "Bob Kelley" <b0bk3ll3yjr@adelphia.net>
    > Subject: RE: Incident response to being scanned
    >
    > Heck yeah, report those folks to their ISPs. Also, is your webserver locked
    > down, and I don't only mean security patches?
    >
    > -----Original Message-----
    > From: Bob Kelley [mailto:b0bk3ll3yjr@adelphia.net]
    > Sent: Friday, April 25, 2003 1:16 AM
    > To: security-basics@securityfocus.com
    > Subject: Incident response to being scanned
    >
    >
    >
    >
    > In reviewing my firewall and web server logs, I see repeated attempts from
    > several ip addresses to scan my network as well as infect my webserver with
    > code red. The source addresses are not always the same. I am confident
    > that I don't have any holes in my firewall and my webserver is up to date.
    > I perform weekly vulnerability scans of my equipment to make sure I am
    > covered. What is considered the best practice for dealing with these
    > incidents? Should I be filing abuse reports with the ISPs of the source
    > IPs? This obviously takes time. I am looking for a business case to
    > justify the time spent responding. Thanks
    >
    > ---------------------------------------------------------------------------
    > Attend Black Hat Briefings & Training Europe, May 12-15 in Amsterdam, the
    > world's premier event for IT and network security experts. The two-day
    > Training features 6 hand-on courses on May 12-13 taught by professionals.
    > The two-day Briefings on May 14-15 features 24 top speakers with no vendor
    > sales pitches. Deadline for the best rates is April 25. Register today to
    > ensure your place. http://www.securityfocus.com/BlackHat-security-basics
    > ----------------------------------------------------------------------------
    >
    >
    >

    ---------------------------------------------------------------------------
    Attend Black Hat Briefings & Training Europe, May 12-15 in Amsterdam, the
    world's premier event for IT and network security experts. The two-day
    Training features 6 hand-on courses on May 12-13 taught by professionals.
    The two-day Briefings on May 14-15 features 24 top speakers with no vendor
    sales pitches. Deadline for the best rates is April 25. Register today to
    ensure your place. http://www.securityfocus.com/BlackHat-security-basics
    ----------------------------------------------------------------------------


  • Next message: Godfrey, Tyler: "RE: DShield.org Recommended Block List"

    Relevant Pages

    • Re: WindowsXP slower after reinstall.
      ... > Did you get on the Internet unprotected by a firewall or antivirus? ... > Also - did you test your hardware before reinstalling - it could be a bad ... > will have to do whatever you did before to get them installed or download ... > You can see the critical patches released for a given ...
      (microsoft.public.windowsxp.basics)
    • Re: WindowsXP slower after reinstall.
      ... > Did you get on the Internet unprotected by a firewall or antivirus? ... > Also - did you test your hardware before reinstalling - it could be a bad ... > will have to do whatever you did before to get them installed or download ... > You can see the critical patches released for a given ...
      (microsoft.public.windowsxp.basics)
    • Re: AdAware, SpyBot S &D, etc. + leave PC connected to Internet
      ... >It will be a while I get the router and do that. ... >> labelling on the box to be sure it has firewall features. ... name, like Disconnect from Internet, and click Finish. ... generally talking only about "critical patches" that affect security. ...
      (comp.security.firewalls)
    • Re: The current architecture is broken
      ... * Use a good firewall to block access to your computer from the Internet ... > download and keep up with all they send, but Microsoft has ... >> Internet to download all those security patches. ...
      (microsoft.public.security.virus)
    • Re: ** READ THIS BEFORE POSTING - answers to frequently asked question
      ... >> Microsoft generally releases security patches on the second Tuesday of more ... >> 4) You're not running a firewall, or your firewall isn't protecting you. ... >> I just heard about a new Microsoft security patch update. ... >> I forgot my Windows logon password and can't log in. ...
      (microsoft.public.scripting.virus.discussion)