Re: iptables Timed Port Block?

From: Kasper Dupont (kasperd@daimi.au.dk)
Date: 02/27/03


From: Kasper Dupont <kasperd@daimi.au.dk>
Date: Thu, 27 Feb 2003 21:10:04 +0100

Tantor wrote:
>
> What I want to be able to do is open port 21 and as soon as a computer scans
> that port I want something that reads its ip and drop all further packets
> from that person for x amount of time. Since nothing is using port 21 if
> something does scan it then I have to assume that its for an attack of
> somekind, so I figure it would be a good idea to just block everything from
> that IP for awhile.

Sounds like a bad idea. You are making yourself vulnurable to DoS attacks.
And notice that unless you install a honeypot or something similar on the
port, you will never know, if the packet is really a part of an attack, or
just a result from a typo, misconfiguration, or other mistake.

-- 
Kasper Dupont -- der bruger for meget tid på usenet.
For sending spam use mailto:aaarep@daimi.au.dk
for(_=52;_;(_%5)||(_/=5),(_%5)&&(_-=2))putchar(_);


Relevant Pages

  • Re: linux newbie: how to stop port scan abuse?
    ... the packets of the scan -- and they happened to choose your IP address as ... No Linux box can be considered anywhere near secure unless all the ... attack. ... particular port. ...
    (comp.os.linux.security)
  • RE: Strange loopback in firefox.
    ... described as heavy attack from outside IP addresses. ... either using the Microsoft_DS port or epmap port to connect). ... For example a connection from port 3014 to 3015 and the next ... to facilitate one-on-one interaction with one of our expert instructors. ...
    (Security-Basics)
  • Re: Attack attempts from 195.86.128.45
    ... I agree with Hamish Stanaway in that you are unlikely to hear ... If the packets being dropped are all just "SYN" ... a SubSeven attack, or just a SYN packet sent to that port. ...
    (Incidents)
  • Re: Port 17889 - new attack?
    ... Port 17889 - new attack? ... would this theory hold true if the servers on different subnets all sent packets at generally the same time? ... Port 17889 - new attack? ...
    (Incidents)
  • FW: Legal? Road Runner proactive scanning.[Scanned]
    ... You consider a port scan to be an attack? ... to facilitate one-on-one interaction with one of our expert instructors. ... Attend a course taught by an expert instructor with years of in-the-field ...
    (Security-Basics)