Re: What can I do about breakin attempts?



On Fri, 24 Feb 2006, in the Usenet newsgroup comp.os.linux.security, in article
<43ffdc86$0$11005$9a6e19ea@xxxxxxxxxxxxxxxxxxxx>, Chris wrote:

Some thug has repeatedly attempted to break in to my server. There's a long
list of repeat login attempts, with alphabetical user names, from one
particular IP address. (The jerk is at 216.155.75.230, if you're curious).

Is your newsreader so broken that you didn't see the thread "Dictionary
attacks on port 22"?

The IP address belongs to Telefonica del Sur S.A in Valdivia, Chile
which is a fair sized city about 40 degrees South (450 miles/720 KM South
of Santiago). LACNIC says there is an rwhois server at rwhois.telsur.cl
on port 4321, but it's not answering a SYN.

What can I do about this?

Why is your server accepting connections from the world? Use your firewall
to restrict access to the limited number of addresses (or address ranges)
where you might actually want to connect. Another tact is to move the
server to a non-standard port. What you are seeing is probably yet another
windoze zombie box. Lots of suggestions in that other thread.

Old guy
.



Relevant Pages

  • What can I do about breakin attempts?
    ... Some thug has repeatedly attempted to break in to my server. ... list of repeat login attempts, with alphabetical user names, from one ...
    (comp.os.linux.security)
  • RE: Some technical errors
    ... If the SMTP server is not running on port 25 TCP it is not a public ... Manager - Computer Assurance Services BDO Chartered Accountants & ...
    (Security-Basics)
  • Re: SRV RRs support in Internet Explorer?
    ... The port number could be implicit (i.e. ... At any point in time, a server could fail ... can't effectively LB or backup because NSs cache the records for the TTL ... I still don't see how SRV records would help backup or LB. ...
    (microsoft.public.win2000.dns)
  • Re: Still cant connect to RWW or OWA remotely
    ... I get 'cannot find server or dns error' on both ... TCP [port number]> to open the ports. ... As for error messages when I fail to access RWW with the laptop, ... network, no connection seems possible. ...
    (microsoft.public.windows.server.sbs)
  • Re: cannot send mail from Windows mail
    ... When a username/password combination doesn't work in Windows Mail, ... I mean I dont use it but as outgoing address for my ISP account. ... youir username and password are correct for your mail server". ... Ask your home ISP if they support SMTP on a port other than 25. ...
    (microsoft.public.windows.vista.mail)