[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
RE: [cobalt-security] surge in port scans?
- Subject: RE: [cobalt-security] surge in port scans?
- From: "Brian Poppenwimer" <popper@xxxxxxxxxxxxxxx>
- Date: Tue, 9 Mar 2004 16:10:13 -0500
- Organization: Nelson & Pope
- List-id: Mailing list for users to address network security on Cobalt products. <cobalt-security.list.cobalt.com>
Yes I have been getting a surge since the weekend, along with a lot of
spoofing attacks on my firewall.
-----Original Message-----
From: cobalt-security-admin@xxxxxxxxxxxxxxx
[mailto:cobalt-security-admin@xxxxxxxxxxxxxxx] On Behalf Of Dan Keller
Sent: Tuesday, March 09, 2004 1:16 AM
To: cobalt-security@xxxxxxxxxxxxxxx
Cc: cobalt@xxxxxxxxxx
Subject: [cobalt-security] surge in port scans?
Is it just me or has anyone else noticed a big
increase in port scans on their RaQ lately?
Until I few days ago, I was getting several each day.
Now I get several each hour.
I have the "log and block" option enabled on my RaQ 550.
How can I tell if it's working? Is there a file I can examine
that lists the blocked IPs? None is named in the iptables
manpage... Thanks for any pointers you can provide.
TIA,
Dan Keller
San Francisco
_______________________________________________
cobalt-security mailing list
cobalt-security@xxxxxxxxxxxxxxx
http://list.cobalt.com/mailman/listinfo/cobalt-security