Are we sure they are scanning at all ?

The easiest way to detect an open server would be to monitor bandwidth
usage by IP address, and report on the top 10% ect.  Normal users will
have SFA upline traffic, whereas a web server ect will.

They may then target the top users - but unless you *ARE* running
prohibited services for the public you should never be on this list.

My 2c

Jason.



On Fri, 7 Apr 2000, Marty wrote:

> Yeah, but you can be DoS'd with this if someone spoofs a scan from say the
> root dns servers, or your ISP's mail server etc. You can feed IP addresses
> to NMAP for spoofed scans... a quick script and you could end up with a very
> broken ipchains ruleset.
> 
> Optus wants to preserve its backchannel bandwidth. What happens if one has a
> cable modem connection and a permanent dialup (to some other ISP)? ie,
> inbound requests come via the dialup, but the replies go out via the
> cable... not hard to setup with ip-masq and a few pc's, and no open ports
> for Optus to find on the cable connection... asymmetric routes used to break
> things occasionally (vague recollection of being burned by this years ago) -
> any guesses at what might break under a setup like this?
> 
> Are they scanning from certain dedicated machines? Maybe we can just
> blackhole the route for those machines... tho ideally we'd want to send lots
> of RST's instead of nothing.
> 
> Cheers,
> Marty
> 
> >
> >
> > You are after Port Sentry.
> >
> > www.psionic.com
> >
> > Does EXACTLY what you want. Put the offending IP in /etc/hosts.deny and
> > a rule in IPCHAINS on the input chain !
> >
> > I run it, works a treat.
> >
> > Matt Allen
> > YourWeb
> 
> --
> SLUG - Sydney Linux Users Group Mailing List - http://www.slug.org.au
> To unsubscribe send email to [EMAIL PROTECTED] with
> unsubscribe in the text
> 

---
Jason Ball
Electronic Commerce Specialist
Corporate Express Australia Ltd
Phone: +61 2 9335 0374  Fax: +61 2 9335 0753
Email: [EMAIL PROTECTED]

--
SLUG - Sydney Linux Users Group Mailing List - http://www.slug.org.au
To unsubscribe send email to [EMAIL PROTECTED] with
unsubscribe in the text

Reply via email to