Re: [Astlinux-users] Dictionary Harvest Attack

2009-04-27 Thread dan
Darrick Hartman wrote: > On Apr 27, 2009, at 5:07 PM, John Novack wrote: > >> May I assume this firewall module is not usable with boards that >> only have a single Ethernet port? >> >> >> John Novack > > Basically, yes 2+ interfaces are required. Lonnie, While not possible with the current A

Re: [Astlinux-users] Dictionary Harvest Attack

2009-04-27 Thread Darrick Hartman (lists)
Lonnie Abelbeck wrote: > On Apr 27, 2009, at 5:07 PM, John Novack wrote: > >> May I assume this firewall module is not usable with boards that >> only have a single Ethernet port? >> >> >> John Novack > > Basically, yes 2+ interfaces are required. Lonnie, While not possible with the current A

Re: [Astlinux-users] Dictionary Harvest Attack

2009-04-27 Thread Philip Prindeville
No, you may not. :-) Hosts also need firewalling. -Philip John Novack wrote: > May I assume this firewall module is not usable with boards that only > have a single Ethernet port? > > > John Novack > > > Philip Prindeville wrote: >> Darrick Hartman (lists) wrote: >> >>> Michael Keuter wrot

Re: [Astlinux-users] Dictionary Harvest Attack

2009-04-27 Thread Lonnie Abelbeck
On Apr 27, 2009, at 5:07 PM, John Novack wrote: > May I assume this firewall module is not usable with boards that > only have a single Ethernet port? > > > John Novack Basically, yes 2+ interfaces are required. The devel's had talked about installing a dummy interface to always allow firew

Re: [Astlinux-users] Dictionary Harvest Attack

2009-04-27 Thread John Novack
May I assume this firewall module is not usable with boards that only have a single Ethernet port? John Novack Philip Prindeville wrote: Darrick Hartman (lists) wrote: Michael Keuter wrote: -Philip A problem in Astlinux is, that before you can add an a

Re: [Astlinux-users] Dictionary Harvest Attack

2009-04-27 Thread Philip Prindeville
Darrick Hartman (lists) wrote: > Michael Keuter wrote: > > -Philip > A problem in Astlinux is, that before you can add an attacker to the blocklist (when you see the attacks in realtime), the "/var/" partition will be full within 2-3 minutes just because of

Re: [Astlinux-users] Dictionary Harvest Attack

2009-04-27 Thread Darrick Hartman (lists)
Michael Keuter wrote: -Philip >>> A problem in Astlinux is, that before you can add an attacker to the >>> blocklist (when you see the attacks in realtime), the "/var/" >>> partition will be full within 2-3 minutes just because of the growing >>> syslog :-(. And from that point in time yo

Re: [Astlinux-users] Dictionary Harvest Attack

2009-04-27 Thread Michael Keuter
>Michael Keuter wrote: >>> Dan Ryson wrote: All, It appears we're getting pounded by a kiddy script that's trying to guess passwords. It's generating ~1,350 password guesses and log entries per minute (see example below). Although I have strong passwords,

Re: [Astlinux-users] Dictionary Harvest Attack

2009-04-27 Thread Darrick Hartman (lists)
Michael Keuter wrote: >> Dan Ryson wrote: >>> All, >>> >>> It appears we're getting pounded by a kiddy script that's trying to >>> guess passwords. It's generating ~1,350 password guesses and log >>> entries per minute (see example below). Although I have strong >>> passwords, I'd like to bl

Re: [Astlinux-users] Dictionary Harvest Attack

2009-04-27 Thread Michael Keuter
>Dan Ryson wrote: >> All, >> >> It appears we're getting pounded by a kiddy script that's trying to >> guess passwords. It's generating ~1,350 password guesses and log >> entries per minute (see example below). Although I have strong >> passwords, I'd like to block this effort by blocking th

Re: [Astlinux-users] Dictionary Harvest Attack

2009-04-27 Thread Dan Ryson
Outstanding. I'll give that a try. Thanks Darrick and Philip. ~ D Philip A. Prindeville wrote: Dan Ryson wrote: All, It appears we're getting pounded by a kiddy script that's trying to guess passwords. It's generating ~1,350 password guesses and log entries per minute (see example bel

Re: [Astlinux-users] Dictionary Harvest Attack

2009-04-27 Thread Philip A. Prindeville
Dan Ryson wrote: > All, > > It appears we're getting pounded by a kiddy script that's trying to > guess passwords. It's generating ~1,350 password guesses and log > entries per minute (see example below). Although I have strong > passwords, I'd like to block this effort by blocking this IP add

Re: [Astlinux-users] Dictionary Harvest Attack

2009-04-27 Thread Darrick Hartman (lists)
Dan, If you're using Arno's fw, you can configure blocked IP addresses very easily. Those blocks will survive an upgrade. That feature should be present in the web interface, but can be done from the command line as well. Darrick Dan Ryson wrote: > All, > > It appears we're getting pounded