Security Incidents mailing list archives

Re: Help please


From: Neil Dickey <neil () geol niu edu>
Date: Mon, 4 Feb 2002 11:51:19 -0600 (CST)


Ryan Hairyes <rhairyes () lee k12 nc us> wrote asking:

I am having some trouble and would like to know if someone can help me out.
Right now my mailserver (RedHat 7.2) is being used by unwanted guest to 
attack adult sites via port 80 (Apache 1.3.20).  When I run a netstat -an
on my system I can "see" them connected to my machine.  I have snort and 
have run that as well and sure  enough they are there.  It seems as though
they are using my apache to do brute force password cracking on these adult
sites.  Thanks in advance.

Does your mailserver have a way of locking out machines or domains that
abuse your services?  Most recent versions of Sendmail do, but I don't
know what RedHat is using ( Solaris here ).  If you can deny access, try
it and it should prevent the offender from abusing you.  Another approach
is to get a copy of a firewall program, like IPFilter, and lock the
offending site out of yours.  IPFilter is free.

Snort has an "enable-response" option, which must be selected during the
compilation step in order to be available, that would allow you to send
an RST packet back to the offender every time one arrived from him, but
in my experience this just sets off a packet storm that can fill your logs
up in no time.

Have you been able to trace the ISP this clown is working from?  If so, it
may -- or may not -- do some good to tell them one of their children isn't
playing nice.  Not all ISPs are responsible, so it may be a waste of time.

Best regards,

Neil Dickey, Ph.D.
Research Associate/Sysop
Geology Department
Northern Illinois University
DeKalb, Illinois
60115



----------------------------------------------------------------------------
This list is provided by the SecurityFocus ARIS analyzer service.
For more information on this free incident handling, management 
and tracking system please see: http://aris.securityfocus.com


Current thread: