SV650.org - SV650 & Gladius 650 Forum



Idle Banter For non SV and non bike related chat (and the odd bit of humour - but if any post isn't suitable it'll get deleted real quick).
There's also a "U" rating so please respect this. Newbies can also say "hello" here too.

Reply
 
Thread Tools
Old 26-04-06, 07:56 AM   #11
Ceri JC
Guest
 
Posts: n/a
Default

Interesting. Coeincidentally, I'm writing a paper on IP ID header TCP scans at the moment (these are an obscure sort of port scan and you're unlikely to be being attacked by them).

I wouldn't bother complaining about it. Happens all the time anyway, it's just that at least you've got software that tells you it's happening. Most of the hacking comes from countries which we have no sway/control over anyway, so it's not like anything would be done to the person even if they were caught.
  Reply With Quote
Old 26-04-06, 08:21 AM   #12
timwilky
Member
Mega Poster
 
timwilky's Avatar
 
Join Date: Mar 2004
Location: Not in Yorkshire. (Thank God)
Posts: 4,116
Default

Ok, I am a linux type so this is linux specific

I have written a little listener programmer that listens on two deliberately open ports, I use 23 & 25 as on all but my mail server I do not use smtp and never ever use telnet.

If I detect connection to both of these I know there is a port scan going on and add the source to my iptables drop list that I share amongst all my servers.

Even though I am behind a hardware firewall. I run iptables on all my servers just to prevent an attack should an internet exposed server become compromised. You windoze lot ?I would strongly advise you to run software firewalls on your systems as well as your hardware firewalls.

I suppose I could hack my trap software to alert in a windoze environment. Does anyone know if the windoze xp firewall has a CLI or API interface that 3rd party systems can hook into?

My reason for doing this trap is simple. I have servers that must accept connections from the internet, but I don't want to accept connections from sources that are known to me as being dodgy.

I also use an extention of my trap software to parse http log files and where I find delibererate attack attempts, such as buffer overflow url requests I also drop these sources.
__________________
Not Grumpy, opinionated.
timwilky is offline   Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Port and... Stingo Idle Banter 5 03-05-08 10:47 PM
Conti Road Attack to Sport Attack glade Tyres 5 03-05-08 02:38 PM
Port Charlotte Richie The Good The Bad and The Ugly Pub and Cafe guide 0 07-10-07 08:52 PM
CT scan this afternoon - hug needed MiniMatt Idle Banter 23 14-09-07 01:34 PM
CCC s/s twin port can pepe SV Talk, Tuning & Tweaking 17 04-05-06 10:14 AM


All times are GMT. The time now is 01:35 PM.


Powered by vBulletin® - Copyright ©2000 - 2025, Jelsoft Enterprises Ltd.