Security Incidents mailing list archives

Re: Ok, we've been scanned.. ..now what!


From: Bill Pennington <billp () ROCKETCASH COM>
Date: Tue, 8 Aug 2000 10:56:13 -0700

First off take a deep breath and count slowly backwards from 10. :-)

The only thing I would recommend is report the offending IP address,
with log files, to the appropriate people. If it is an AOL address then
abuse () aol com might be a good place to start.

fighting fire with fire is, frankly, a dumb thing to do and will most
likely get you in trouble. Scanning is not illegal in the U.S.,
performing DOS attacks is. I think you can see where I am going.
Automated blocking of source IPs can lead you down a dangerous path.
Unless you watch is closely it can lead to a DOS attack from people
spoofing source addresses.

Just my $0.02.

"Steven M. Klass" wrote:

Hey all,

        Well this weekend was a particularly active weekend for the scanners..  It
appears that I have been scanned several hundred times by the same
moron.  What is the proper procedure for telling these idiots to know it
off.  I mean I know that it is coming from the aol spectrum from a
traceroute, so what's next?  Do any of you have scripts to deal with
this.  I was thinking about possibly implementing a dynamic ipchains
protocol that sees a scan and after n times blocks that idiot for a week or
so, on all ports.  Does anyone have such a beast that would like to share
that with me?  I also thought about more devious things, like nmaping the
moron and flooding his available ports..  Fight fire with fire..  Any ideas?
Steven M. Klass
Physical Design Engineering Manager

Andigilog Inc.
7404 W. Detroit Street, Suite 100
Chandler, AZ 85226
Ph: 602-940-6200 ext. 18
Fax: 602-940-4255

sklass () andigilog com
http://www.andigilog.com/

--


Bill Pennington
Senior IT Manager
Rocketcash
billp () rocketcash com
http://www.rocketcash.com


Current thread: