I've had scores of FTP bots slamming into the system, with
a quick successive and repetitive connect then disconnect,
which can lock up the nodes. By putting "no name" into the host.can
file, it blocks them, but it cuts off access for legitimate
users wanting to use anonymous FTP.
Aside from them setting up an account, or using the Guest account, is
there anything I can do??
I've had scores of FTP bots slamming into the system, with a quick successive and repetitive connect then disconnect, which can lock up
the nodes.
By putting "no name" into the host.can file, it blocks
them,
but it cuts off access for legitimate users wanting to use
anonymous FTP.
Aside from them setting up an account, or using the Guest account,
is there anything I can do??
By putting "no name" into the host.can file, it blocks them,
It does? How?
Digital Man wrote to Daryl Stout <=-
I've had scores of FTP bots slamming into the system, with a quick successive and repetitive connect then disconnect, which can lock up
the nodes.
How would "FTP bots" lock up the nodes?
Dumas Walker wrote to Digital Man <=-
Digital Man wrote to Daryl Stout <=-
I've had scores of FTP bots slamming into the system, with a quick successive and repetitive connect then disconnect, which can lock up
the nodes.
How would "FTP bots" lock up the nodes?
I have been getting a lot of garbage traffic lately that seems to tie
the whole system up, even when they are only hammering at the ports for one protocol, i.e. hammering telnet makes it more difficult to connect
via other methods because the overall inbound traffic volume is that
high.
Most of my garbage is coming in on telnet, though. Was the usual
suspects until yesterday, when many of the IPs had domestic sources.
All of them were hostname = no name. I had to whois them to figure out where they were coming from.
I've had scores of FTP bots slamming into the system, with a quick
successive and repetitive connect then disconnect, which can lock up the
nodes.
I have been getting a lot of garbage traffic lately that seems to tie
the whole system up, even when they are only hammering at the ports
for one protocol, i.e. hammering telnet makes it more difficult
to connect via other methods because the overall inbound traffic
volume is that high.
Most of my garbage is coming in on telnet, though. Was the usual
suspects until yesterday, when many of the IPs had domestic sources.
All of them were hostname = no name. I had to whois them to figure
Dumas Walker wrote to Digital Man <=-
Digital Man wrote to Daryl Stout <=-
I've had scores of FTP bots slamming into the system, with a quick successive and repetitive connect then disconnect, which can lock
up the nodes.
How would "FTP bots" lock up the nodes?
I have been getting a lot of garbage traffic lately that seems to tie the whole system up, even when they are only hammering at the ports
for one protocol, i.e. hammering telnet makes it more difficult
to connect via other methods because the overall inbound traffic
volume is that high.
Most of my garbage is coming in on telnet, though. Was the usual suspects until yesterday, when many of the IPs had domestic sources.
All of them were hostname = no name. I had to whois them to figure
out where they were coming from.
I'm seeing the same thing here.
I have been getting a lot of garbage traffic lately that seems to tie
the whole system up, even when they are only hammering at the ports
for one protocol, i.e. hammering telnet makes it more difficult
to connect via other methods because the overall inbound traffic
volume is that high.
Most of my garbage is coming in on telnet, though. Was the usual
suspects until yesterday, when many of the IPs had domestic sources.
All of them were hostname = no name. I had to whois them to figure
you are on linux right. use some iptables magic.
As an aside, the amount of SPAM traffic on my personal e-mail account has also shot up ridiculously high since that conflict started. Lots of messages from C0STC0, Steaks 0maha, Prime Amazon... I think you can see the pattern here. ;)
Yes. I am thinking of setting up something with haproxy since I also already use it. It has some "magic" that I know works on http/https traffic. I will have to research some and see what it can do for
other levels of traffic.
That said, I normally don't have too many issues. My issues similar
to what Daryl mentioned didn't seem to start until this week.
Overall bot traffic has been up since the Middle East conflict
heated up. Mostly bots from Iran, and some from Israel. As noted,
that changed just in the past couple of days when I noticed a sharp
increase in domestic bot traffic, and an unusual absence of the
usual suspects... Iran, Russia, North Korea, China, etc.
As an aside, the amount of SPAM traffic on my personal e-mail account
has also shot up ridiculously high since that conflict started. Lots
of messages from C0STC0, Steaks 0maha, Prime Amazon... I think you
can see the pattern here. ;)
| Sysop: | Luis Silva |
|---|---|
| Location: | Lisbon |
| Users: | 768 |
| Nodes: | 10 (0 / 10) |
| Uptime: | 494964:16:58 |
| Calls: | 631 |
| Files: | 46,158 |
| Messages: | 15,107 |