Re: [opensuse] More dictionary attacks





zoran wrote:
Richard,

Try to congigure your router, actually ban intruders IP in router., if
possible depends on manufacture. This wil save you a lot of time and it's
much more relaible.


Kind regards,
Zoran
<snip>

I feel this is probably impractical simply because the IP of the
attacker never repeats so every attack would be from an IP that is not
in the list. What I need is a DYNAMICly created list, which is what I
thought the 'recent' feature of iptables was supposed to do. I still
haven't given up hope that this worm (if that is what it is) is
stoppable using this feature but it appears to come in from a different
IP *and* a different PORT each attack, making it hard to trap until the
attack actually starts. In fact, the port changes *during* the attack.
So far, I have not seen anything I can get my teeth into but the
router seems to be too low a level to detect/trap this beast.

Richard
--
To unsubscribe, e-mail: opensuse+unsubscribe@xxxxxxxxxxxx
For additional commands, e-mail: opensuse+help@xxxxxxxxxxxx



Relevant Pages

  • [Full-disclosure] RE: RLA ("Remote LanD Attack")
    ... if the router of my internet provider has ACL's to deny ... and the LAND attack no longer works. ... hping2 on Comcast Cable connection behind Linksys Router ...
    (Full-Disclosure)
  • [NEWS] Denial of Service Vulnerability in SMC Networks Barricade Wireless Router
    ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... Latest attack techniques. ... Stateful Packet Inspection firewall security, network management, ... the router remains unresponsive to requests on the ...
    (Securiteam)
  • Re: DOS attack logged by Netgear router DG836G
    ... *** During these 10 hrs no PC was powered on, but the router is ... But basically you're screwed over for the duration of the attack. ... inside the ISP helped to get it blocked, or going with an ISP that ... Over to you to run a zillion name/password combos on the telnet port :-) ...
    (uk.telecom.broadband)
  • Re: security issue.
    ... the ISP now has a BCC of this email. ... > pings to and from the server at the router by putting in an ACL on ... >> For the past few days, i had troubles connecting to my KIFCO server ... >> Which consider a PORTSCAN and an ATTACK. ...
    (freebsd-questions)
  • Re: Am i OK? Getting a LOT of alerts from my router about LAND!!!
    ... > Sample Alert from router... ... or perhaps just your Internet Service Provider doing routine network maintenance. ... Save this email for comparison with future alert messages. ... but it sounds alot like an attack I'v read about. ...
    (comp.security.firewalls)