From owner-freebsd-questions Wed Feb 27 15: 5:27 2002 Delivered-To: freebsd-questions@freebsd.org Received: from mail.the-i-pa.com (mail.the-i-pa.com [151.201.71.132]) by hub.freebsd.org (Postfix) with SMTP id 8EEBE37B400 for ; Wed, 27 Feb 2002 15:05:20 -0800 (PST) Received: (qmail 71675 invoked from network); 27 Feb 2002 23:12:32 -0000 Received: from unknown (HELO proxy.pt.com) (151.201.71.209) by mail.the-i-pa.com with SMTP; 27 Feb 2002 23:12:32 -0000 Content-Type: text/plain; charset="iso-8859-1" From: Bill Moran Organization: Potential Technology To: Jim Freeze Subject: Re: Is this a breakin (attempt)? Date: Wed, 27 Feb 2002 18:03:53 -0500 X-Mailer: KMail [version 1.2] Cc: questions@freebsd.org References: <20020227081821.A12905@freeze.org> <02022708505801.00825@proxy.pt.com> <20020227091544.A15249@freeze.org> In-Reply-To: <20020227091544.A15249@freeze.org> MIME-Version: 1.0 Message-Id: <02022718035303.00825@proxy.pt.com> Content-Transfer-Encoding: 8bit Sender: owner-freebsd-questions@FreeBSD.ORG Precedence: bulk List-ID: List-Archive: (Web Archive) List-Help: (List Instructions) List-Subscribe: List-Unsubscribe: X-Loop: FreeBSD.ORG On Wednesday 27 February 2002 09:15, Jim Freeze wrote: > > On another angle, I get this kind of thing all the time. In December, I > > had Samba running unprotected on this machine for about a month (due to > > carelessness on > > What do you mean unprotected. You have my attention here. No ipfw rules preventing access to samba from the internet, and the Samba config did not have any interfaces bound, so it was accepting connections on all interfaces. Lucky for me, I had Samba in "user" mode (which required a password to log in) and the Samba logs showed attempted connections that timed out waiting for a password. Thus, the people attempting to access weren't being too terribly clever. They probably just gave up when they were asked for a password. I've now solved this problem by telling Samba only to bind to the internal interface on this machine, so it doesn't even listen to requests that may come in from the Internet. -- Bill Moran Potential Technology technical services http://www.potentialtech.com To Unsubscribe: send mail to majordomo@FreeBSD.org with "unsubscribe freebsd-questions" in the body of the message