Re: off topic: reporting attempts to access computers
- From: Andrew Gould <andrewlylegould@xxxxxxxxx>
- Date: Thu, 19 Feb 2009 14:36:26 -0600
On Thu, Feb 19, 2009 at 2:01 PM, GESBBB <gesbbb@xxxxxxxxx> wrote:
From: Andrew Gould andrewlylegould@xxxxxxxxxI
What information should I send to an abuse@* address when reporting a
break-in attempt?
My logs show a dictionary attack of invalid user names against port 22.
obtained an abuse@* email address using 'whois' and reported thebeginning
and ending date/times and the originating IP address.the
Is there any other information I need to send? Is there someone else I
should notify?
Most of the attacks I receive are from other continents, so I just block
network range found via 'whois'. In this case, the IP address is fairly
local, so I'm hesitant to block the entire range.
There are some applications that you might want to install that can help.
Personally, I have found reporting the abuse virtually useless. I use to
just include the entire log with the data that pertained to the user in
question; however, that just proved a waste of time.
If you are using 'passwords' to access your account, you might want to
consider using certificates instead. That is far safer than using a password
that eventually can be cracked.
--
Jerry
Yes, it's probably time to move to certificates. Thanks for the suggestion.
Andrew
_______________________________________________
freebsd-questions@xxxxxxxxxxx mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-questions
To unsubscribe, send any mail to "freebsd-questions-unsubscribe@xxxxxxxxxxx"
- Follow-Ups:
- Re: off topic: reporting attempts to access computers
- From: Steve Bertrand
- Re: off topic: reporting attempts to access computers
- References:
- off topic: reporting attempts to access computers
- From: Andrew Gould
- Re: off topic: reporting attempts to access computers
- From: GESBBB
- off topic: reporting attempts to access computers
- Prev by Date: RE: desktop app/config
- Next by Date: Re: globally limit fetch download?
- Previous by thread: Re: off topic: reporting attempts to access computers
- Next by thread: Re: off topic: reporting attempts to access computers
- Index(es):
Relevant Pages
|