[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

RE: Hosts.all/Hosts.deny vs. a firewall?]



On 27-Aug-2000 Gary Jones wrote:
> I'm sorry, make that three attempts. The fuckwits can FOAD - all such 
> attempts are logged and sent to the appropriate abuse / postmaster 
> addresses.

I have been on a DSL connection for a few weeks, and my IP address will change
about once a week.  Since the most recent IP address change, I have been
seeing in my logs attempted connections to ports 137, 138, and 139 but I am
not concerned because I am guessing that someone was running a server there
before I got the IP address.  Once I start seeing attempts from one host/net
to connect to multiple ports, I get concerned and I e-mail their abuse address.

I run portsentry and logcheck together and it works well for me.

--
Andrew



Reply to: