Hi, my firewall is detecting a "netbus attack" from an external source. Anyway I can basically refuse connections? Nothing's gotten through yet, but it's a pain to see someone doing it and I'd like to smack them around a bit. Any ideas? Wes
Hi, my firewall is detecting a "netbus attack" from an external source. Anyway I can basically refuse connections? Nothing's gotten through yet, but it's a pain to see someone doing it and I'd like to smack them around a bit. Any ideas?
It sounds like you already are refusing connections (or just dropping the packets). If it looks like it's casual portscanning I'd just ignore it. If it's coming from the same source constantly over a period of time, send a nasty email to their provider's abuse@ address. =) -b
And if its from a 130.215 address, please tell WPI Netops. We like to stop that kinda thing. :-) Phil On Wed, 17 Apr 2002, Brian J. Conway wrote:
Hi, my firewall is detecting a "netbus attack" from an external source. Anyway I can basically refuse connections? Nothing's gotten through yet, but it's a pain to see someone doing it and I'd like to smack them around a bit. Any ideas?
It sounds like you already are refusing connections (or just dropping the packets). If it looks like it's casual portscanning I'd just ignore it. If it's coming from the same source constantly over a period of time, send a nasty email to their provider's abuse@ address. =)
-b
_______________________________________________ Wlug mailing list Wlug@mail.wlug.org http://mail.wlug.org/mailman/listinfo/wlug
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=- Phil Deneault "We work in the dark, We do what we can, deneault@wpi.edu We give what we have. Our doubt is our passion, WPI NetOps and our passion is our task. The rest is the OpenVMS Guy maddness of art." - Henry James -=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
Ahh, yes, that's a good one. Wes On ed, 2002-04-17 at 12:56, Brian J. Conway wrote:
Hi, my firewall is detecting a "netbus attack" from an external source. Anyway I can basically refuse connections? Nothing's gotten through yet, but it's a pain to see someone doing it and I'd like to smack them around a bit. Any ideas?
It sounds like you already are refusing connections (or just dropping the packets). If it looks like it's casual portscanning I'd just ignore it. If it's coming from the same source constantly over a period of time, send a nasty email to their provider's abuse@ address. =)
-b
_______________________________________________ Wlug mailing list Wlug@mail.wlug.org http://mail.wlug.org/mailman/listinfo/wlug
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 iptable -A INPUT -s IPOFATTACK -j DROP On 17 Apr 2002, Wesley Allen wrote:
Hi, my firewall is detecting a "netbus attack" from an external source. Anyway I can basically refuse connections? Nothing's gotten through yet, but it's a pain to see someone doing it and I'd like to smack them around a bit. Any ideas?
Wes
_______________________________________________ Wlug mailing list Wlug@mail.wlug.org http://mail.wlug.org/mailman/listinfo/wlug
- ---------------------------------------------- | Chuck Haines | AOL: CyberGrex | | GDC Webmaster | ICQ: 3707881 | | WPILA Lab Manager | Yahoo: CyberGrex_27 | | http://gdc.wpi.edu | MSN: CyberGrex | - ---------------------------------------------- "Geek by nature, Linux by choice." -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.0.6 (OSF1) Comment: For info see http://www.gnupg.org iD8DBQE8vdFq7HPTHjUkyKwRAuq9AJ9GtulXC4x2rCIftAMfpcSrNX0vnACcCxZA O8jItcQM8R0BHfEZE9yhYWg= =N7JM -----END PGP SIGNATURE-----
dont let netops confuse you, its coming from them :/ -mike ----- Original Message ----- From: "Wesley Allen" <wallen@charter.net> To: <wlug@mail.wlug.org> Sent: Wednesday, April 17, 2002 12:51 Subject: [Wlug] netbus attack...
Hi, my firewall is detecting a "netbus attack" from an external source. Anyway I can basically refuse connections? Nothing's gotten through yet, but it's a pain to see someone doing it and I'd like to smack them around a bit. Any ideas?
Wes
_______________________________________________ Wlug mailing list Wlug@mail.wlug.org http://mail.wlug.org/mailman/listinfo/wlug
LOL, Netops has much better methods for annoying its users then using Netbus. :-) Wouldn't you agree Mike? :-) Phil On Wed, 17 Apr 2002, Michael Frysinger wrote:
dont let netops confuse you, its coming from them :/ -mike
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=- Phil Deneault "We work in the dark, We do what we can, deneault@wpi.edu We give what we have. Our doubt is our passion, WPI NetOps and our passion is our task. The rest is the OpenVMS Guy maddness of art." - Henry James -=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-
participants (5)
-
Brian J. Conway
-
Chuck Haines
-
Michael Frysinger
-
Phillip G Deneault
-
Wesley Allen