> I'm thinking my valiant little firewall (486, 16Mb > RAM) may not really be suited to tackle these nasty > worms and such, and I should go back to just ignoring > the junk out there. Which brings me to a thought: > This seems to be a way for worm authors to fight back > at packages like LaBrea - just keep filling up the > logs til the system chokes. Perhaps they've already > figured this out!? Or maybe someone is making a > conscious denial of service attack on me because of my > tarpit... > > Any thoughts? Are there ways to cut down on LaBrea's > activity? Clearly it would help a lot if I excluded > port 80, but then there wouldn't be much point would > there?
You can simply stop logging the activity...both LaBrea and IPChains allow you to control what gets logged... Charles Steinkuehler http://lrp.steinkuehler.net http://c0wz.steinkuehler.net (lrp.c0wz.com mirror) _______________________________________________________________ Have big pipes? SourceForge.net is looking for download mirrors. We supply the hardware. You get the recognition. Email Us: [EMAIL PROTECTED] ------------------------------------------------------------------------ leaf-user mailing list: [EMAIL PROTECTED] https://lists.sourceforge.net/lists/listinfo/leaf-user SR FAQ: http://leaf-project.org/pub/doc/docmanager/docid_1891.html
