Jul. 4th, 2015

sweh: (Straight Jacket)
Either the DHS is attacking me, or else they've got compromised computers...

In my logs I see 1147 attempts from 64.69.57.20 to my web server; e.g.
Read more... )
The Nessus proxy check line makes me think this might be a generic scan... but why my machine?

They didn't stop there... I have SSHD running on a non-standard port. If someone attempts to connect too frequently then they get blocked (simple iptables rule). I can see 6 dropped packets from the same SRC=64.69.57.20 to my SSH port.

Didn't stop there, either. DNS attempts?
Read more... )

Looks like also some port scans, 'cos I can see "rsync" (started from xinetd) being woken up (but it rejects them access).

And, from another machine on the same network, SMTP attacks!
Read more... )
(66 attempts against SMTP)

OK, OK, this all looks like an "out of the box" type scan from some misconfigured security tool. But it's funny that it's the DHS!

August 2025

S M T W T F S
     12
3456789
101112 13141516
17181920212223
24252627282930
31      

Style Credit

Expand Cut Tags

No cut tags
Page generated Aug. 31st, 2025 02:39 pm
Powered by Dreamwidth Studios