[lug] TCP Wrapers and Going After Bad People

D. Stimits stimits at idcomm.com
Wed Sep 12 12:17:53 MDT 2001


Greg Horne wrote:
> 
> Yo BLUG, yes. . . You CAN help Greg get the bad guys!
> 
> So two people stand out in my logs as always trying to break into my
> systems.  I get e-mails daily from the servers saying . . .Tried NS1, tried
> MMS1, tried Webserver 1, etc. . .
> 
> My question is this:  Have any of you tried to track some of these people
> down?  Any sucess stories to tell?  If so, what were your methods?
> 
> For good measure i'll include the *evil* offenders.
> 
> attempt from APoitiers-103-1-1-165.abo.wanadoo.fr unknown 193.253.254.165
> to in.ftpd at Wed Sep 12 05:30:51 PDT 2001
> 
> attempt from HSE-QuebecCity-ppp3496564.sympatico.ca unknown 65.92.224.5 to
> in.ftpd at Tue Sep 11 18:57:37 PDT 2001

FYI, I've had the sympatico.ca domain firewalled for a while now. I
don't see this particular ip hitting, but I have a lot of stuff from
another sympatico.ca:
64.229.67.34

Firewall it. I wish I knew how to find out what ISP provides for a given
IP.

D. Stimits, stimits at idcomm.com

> 
> Thanks,
> 
> Greg Horne
> 
> _________________________________________________________________
> Get your FREE download of MSN Explorer at http://explorer.msn.com/intl.asp
> 
> _______________________________________________
> Web Page:  http://lug.boulder.co.us
> Mailing List: http://lists.lug.boulder.co.us/mailman/listinfo/lug



More information about the LUG mailing list