From owner-freebsd-questions@FreeBSD.ORG Tue Jan 11 22:06:08 2005 Return-Path: Delivered-To: freebsd-questions@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id ED91716A4CE for ; Tue, 11 Jan 2005 22:06:08 +0000 (GMT) Received: from rproxy.gmail.com (rproxy.gmail.com [64.233.170.203]) by mx1.FreeBSD.org (Postfix) with ESMTP id 909EB43D1D for ; Tue, 11 Jan 2005 22:06:08 +0000 (GMT) (envelope-from artware@gmail.com) Received: by rproxy.gmail.com with SMTP id z35so339324rne for ; Tue, 11 Jan 2005 14:06:08 -0800 (PST) DomainKey-Signature: a=rsa-sha1; q=dns; c=nofws; s=beta; d=gmail.com; h=received:message-id:date:from:reply-to:to:subject:in-reply-to:mime-version:content-type:content-transfer-encoding:references; b=Pjo/gEgO7vU5T/xFjYauXTY7M4TgA+lXMCoumnd/0jriMXmOTpnN43K7g2EXbpbwZfZL7rJj8rFpq3BmwN4qSQbbLFgUxeDksBJzR0BXNmBrfVL7+UeTveBmLJGJRV5ubqpro3xA85vzi+ZfOHtChh15X97uCQyOClPJZH2kg38= Received: by 10.38.101.56 with SMTP id y56mr139420rnb; Tue, 11 Jan 2005 14:06:07 -0800 (PST) Received: by 10.38.65.13 with HTTP; Tue, 11 Jan 2005 14:06:07 -0800 (PST) Message-ID: Date: Tue, 11 Jan 2005 16:06:07 -0600 From: artware To: freebsd-questions@freebsd.org In-Reply-To: Mime-Version: 1.0 Content-Type: text/plain; charset=US-ASCII Content-Transfer-Encoding: 7bit References: <7b3c7f0b0501101142223c3e36@mail.gmail.com> Subject: Re: Blacklisting IPs X-BeenThere: freebsd-questions@freebsd.org X-Mailman-Version: 2.1.1 Precedence: list Reply-To: artware List-Id: User questions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Tue, 11 Jan 2005 22:06:09 -0000 These types of attacks don't seem directed -- it's more like fishing for unprotected systems. FWIW, changing the ssh port dropped the illegal user attempts to 0 instantly... - ben On Mon, 10 Jan 2005 23:29:10 -0800, Ted Mittelstaedt wrote: > If I'm going to attack you I'm going to use nessus to scan all > ports on your machine.