Re: Port 135 Probes Continue

From: Bit Twister (BitTwister_at_localhost.localdomain)
Date: 12/17/03

  • Next message: Durk van Veen: "Re: iptables rule generation software?"
    Date: Wed, 17 Dec 2003 04:53:26 GMT
    
    

    On Tue, 16 Dec 2003 21:47:51 -0700, Felix Tilley wrote:
    > Back in October, I got probed every 6 or 7 minutes on port 135. Now look
    > at this mess. It is less than a minute on average. Things are getting
    > worse, not better.

    See what virus is hot http://www.dshield.org/
    click other in map for others

    Just add a rule to your firewall to not log and drop the packets
    ${IPTABLES} -A INPUT -i ${DHCP_IFACES} -p udp --dport 135 -j ${REJECT_METHOD}


  • Next message: Durk van Veen: "Re: iptables rule generation software?"

    Relevant Pages

    • Re: What can we rely on IDS to monitor?
      ... :connection attempts, packet with an illegal TCP flag combination, email ... :containing a particular virus, DNS buffer overflow, DoS, file access as ... A typical firewall would filter: ... packets for this, and might have to reassemble large numbers of packets ...
      (comp.security.misc)
    • Re: Completely replace software firewall with hardware firewall?
      ... >> But a hardware firewall can't distinguish between packets you've ... >> and packets a virus has requested. ... Unfortunately the sort of people who manage to install viruses and ...
      (comp.security.firewalls)
    • Re: Completely replace software firewall with hardware firewall?
      ... >> But a hardware firewall can't distinguish between packets you've ... >> and packets a virus has requested. ... Unfortunately the sort of people who manage to install viruses and ...
      (alt.computer.security)
    • Re: Port 135 Probes Continue
      ... > at this mess. ... See what virus is hot http://www.dshield.org/ ... Just add a rule to your firewall to not log and drop the packets ...
      (comp.security.unix)
    • Re: Port 135 Probes Continue
      ... > at this mess. ... See what virus is hot http://www.dshield.org/ ... Just add a rule to your firewall to not log and drop the packets ...
      (comp.security.misc)

  • Quantcast