Full Disclosure mailing list archives

Re: Brute force attack - need your advice


From: <dudevanwinkle () hush ai>
Date: Mon, 11 Feb 2008 17:17:08 -0500

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

THIS IS NO TIME FOR YOU'RE SILLY JOKES

On Mon, 11 Feb 2008 16:32:12 -0500 Paul Schmehl
<pauls () utdallas edu> wrote:
--On Tuesday, February 12, 2008 02:16:02 +0530 Abilash Praveen
<contactme () abilashpraveen com> wrote:


Hello experts,

I had been talking to our web hosts the other day and they seem
to have a lot
of unusual brute force attack on the servers recently. I'm
guessing that it
could be because of my emails to the list? I mean, do you advice
on using a
personal email for this type of list? Or should I use something
like
@gmail.com? I know they can't easily break in to our servers,
but am I just
giving them a chance?


The chances of your little corner of the web being singled out for
attack are
pretty low.  Besides, the level of pure crap flying around on the
internet
makes it nearly impossible to distinguish a directed attack from
the usual
garbage.  So, you do your best to properly configure and secure
everything,
keep good logs and sit back and watch the crap fly.

--
Paul Schmehl (pauls () utdallas edu)
Senior Information Security Analyst
The University of Texas at Dallas
http://www.utdallas.edu/ir/security/

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/
-----BEGIN PGP SIGNATURE-----
Note: This signature can be verified at https://www.hushtools.com/verify
Charset: UTF8
Version: Hush 2.5

wpwEAQECAAYFAkewyQIACgkQ+cOIFG8Ql/4OuQP9EagLTXFp69+sIA+rSiAVLK9Vt3rG
X3Bl+4/Ev6rbsszr6xw9hCfxX8C83ezUJSJtv2+iB4cBs4g2mjmR/55xEenE3LbqTQMK
tzMF+NkTNiCQNSKW3NGDl3elmB3VFBVyGCflvDPKX6x2CujF5IQ1kBultrnKOIluyP/6
0oH5wR8=
=ufp2
-----END PGP SIGNATURE-----

--
Click for information on obtaining a VA loan.
http://tagline.hushmail.com/fc/Ioyw6h4d9Cvgc7YPPsxUFlHRG4Zv2wsnezmFCVO8EPxvr2BKFhnE8I/

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/


Current thread: