Re: Help please

From: Neil Dickey (neilat_private)
Date: Mon Feb 04 2002 - 09:51:19 PST

  • Next message: Oliver Petruzel: "gibberish defacement?"

    Ryan Hairyes <rhairyesat_private> wrote asking:
    
    >I am having some trouble and would like to know if someone can help me out.
    >Right now my mailserver (RedHat 7.2) is being used by unwanted guest to 
    >attack adult sites via port 80 (Apache 1.3.20).  When I run a netstat -an
    >on my system I can "see" them connected to my machine.  I have snort and 
    >have run that as well and sure  enough they are there.  It seems as though
    >they are using my apache to do brute force password cracking on these adult
    >sites.  Thanks in advance.
    
    Does your mailserver have a way of locking out machines or domains that
    abuse your services?  Most recent versions of Sendmail do, but I don't
    know what RedHat is using ( Solaris here ).  If you can deny access, try
    it and it should prevent the offender from abusing you.  Another approach
    is to get a copy of a firewall program, like IPFilter, and lock the
    offending site out of yours.  IPFilter is free.
    
    Snort has an "enable-response" option, which must be selected during the
    compilation step in order to be available, that would allow you to send
    an RST packet back to the offender every time one arrived from him, but
    in my experience this just sets off a packet storm that can fill your logs
    up in no time.
    
    Have you been able to trace the ISP this clown is working from?  If so, it
    may -- or may not -- do some good to tell them one of their children isn't
    playing nice.  Not all ISPs are responsible, so it may be a waste of time.
    
    Best regards,
    
    Neil Dickey, Ph.D.
    Research Associate/Sysop
    Geology Department
    Northern Illinois University
    DeKalb, Illinois
    60115
    
    
    
    ----------------------------------------------------------------------------
    This list is provided by the SecurityFocus ARIS analyzer service.
    For more information on this free incident handling, management 
    and tracking system please see: http://aris.securityfocus.com
    



    This archive was generated by hypermail 2b30 : Mon Feb 04 2002 - 10:34:57 PST