
Mailing List Archive
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: [tlug] Script Kiddy Defence Script
> Yes, I'm planning to do that. Not sure yet which other attacks are
> worth considering... maybe port scans, exploit tests via http...
> well, if someone has ideas, let me know.
I wrote a short perl script to scan a weblog in real-time looking for the
typical IIS exploits. In my case, I was less forgiving, in that I blocked
the IP until the following midnight (just because I didn't want to have to
deal with counting down timeouts and the like -- just run a cronjob to
clear out the SHITLIST chain at midnight every day. It cut down on a lot
of crud in the web logs. I'll send you the script if you're interested.
In the case of port scans, closing the ports seems to keep the kids out.
--
Joe Larabell -- Synopsys VCS Support US: larabell@example.com
http://wwwin.synopsys.com/~larabell/ Japan: larabell@?jp
Home |
Main Index |
Thread Index