Ryan Hairyes <rhairyesat_private> wrote asking: >I am having some trouble and would like to know if someone can help me out. >Right now my mailserver (RedHat 7.2) is being used by unwanted guest to >attack adult sites via port 80 (Apache 1.3.20). When I run a netstat -an >on my system I can "see" them connected to my machine. I have snort and >have run that as well and sure enough they are there. It seems as though >they are using my apache to do brute force password cracking on these adult >sites. Thanks in advance. Does your mailserver have a way of locking out machines or domains that abuse your services? Most recent versions of Sendmail do, but I don't know what RedHat is using ( Solaris here ). If you can deny access, try it and it should prevent the offender from abusing you. Another approach is to get a copy of a firewall program, like IPFilter, and lock the offending site out of yours. IPFilter is free. Snort has an "enable-response" option, which must be selected during the compilation step in order to be available, that would allow you to send an RST packet back to the offender every time one arrived from him, but in my experience this just sets off a packet storm that can fill your logs up in no time. Have you been able to trace the ISP this clown is working from? If so, it may -- or may not -- do some good to tell them one of their children isn't playing nice. Not all ISPs are responsible, so it may be a waste of time. Best regards, Neil Dickey, Ph.D. Research Associate/Sysop Geology Department Northern Illinois University DeKalb, Illinois 60115 ---------------------------------------------------------------------------- This list is provided by the SecurityFocus ARIS analyzer service. For more information on this free incident handling, management and tracking system please see: http://aris.securityfocus.com
This archive was generated by hypermail 2b30 : Mon Feb 04 2002 - 10:34:57 PST