|
I've seen logon attacks thru FTPSERVE before and, as I remember,
looking at the FTPSERVE console showed the activity. I've seen 3
different attempts in the last couple of weeks and the FTPSERVE console
doesn't show a thing. Jim Adam Thornton wrote: On Jul 8, 2009, at 11:15 AM, David Boyes wrote:Simple answer: put a Linux guest in front of the VM TCP stack with the old address as the external address, renumber the VM stack to a RFC1918 address on an internal guest lan, and enable IP Masquerade in iptables. That gets you all sorts of useful info, and lets you shut them down cold. Add one of the IDS toolkits, and you can clobber the twerps network wide. -- Jim Bohnsack Cornell University (972) 596-6377 home/office (972) 342-5823 cell [email protected] |
- PERFSVM question Jim Bohnsack
- Re: PERFSVM question Rich Smrcina
- Re: PERFSVM question David Boyes
- Re: PERFSVM question Adam Thornton
- Re: PERFSVM question Adam Thornton
- Re: PERFSVM question Chip Davis
- Re: PERFSVM question Jim Bohnsack
- Re: PERFSVM question Adam Thornton
- Re: PERFSVM question Jim Bohnsack
- Re: PERFSVM question David Boyes
- Re: PERFSVM question Jim Bohnsack
