Go Back   The UNIX and Linux Forums > Special Forums > Security
google site



Security Discuss UNIX and Linux computer and network security, cybersecurity, cyberattacks, IT security, CISSP, OWASP and more.

Reply
English Japanese Spanish French German Portuguese Italian Powered by Powered by Google
 
Thread Tools Search this Thread Display Modes
  #8  
Old 01-15-2010
sysgate's Avatar
sysgate sysgate is offline Forum Advisor  
Unix based
 

Join Date: Nov 2006
Location: Bulgaria
Posts: 1,368
Thanks: 0
Thanked 1 Time in 1 Post
It depends. Back in the days when I was dealing with hundreds of spammers and attackers as a security officer I have even seen people ending up in the jail. But again, it will depend on the ISP / Enterprise, the local laws - California may be different than, let's say, Arizona, though they are neighbors, and especially the way you report the attacks / spam messages. Both Spamcop.net and Spamhaus.org do a pretty good job in providing cooperation to network / abuse admins through automated mail systems. There's a risk, however - some or all of the IP addresses may be indeed legitimate, but the attack itself deploys forged addresses injected directly into TCP packets.
Nevertheless, all spam messages fall under the CAN SPAM ACT 2003.
As for the SSHD attacks, you may consider those general advises, deploy sshdfilter or implement SSHBL.
HTH.
Sponsored Links
  #9  
Old 01-19-2010
Registered User
 

Join Date: Mar 2009
Posts: 50
Thanks: 0
Thanked 0 Times in 0 Posts
Quote:
Originally Posted by sysgate View Post
It depends. Back in the days when I was dealing with hundreds of spammers and attackers as a security officer I have even seen people ending up in the jail. But again, it will depend on the ISP / Enterprise, the local laws - California may be different than, let's say, Arizona, though they are neighbors, and especially the way you report the attacks / spam messages. Both Spamcop.net and Spamhaus.org do a pretty good job in providing cooperation to network / abuse admins through automated mail systems. There's a risk, however - some or all of the IP addresses may be indeed legitimate, but the attack itself deploys forged addresses injected directly into TCP packets.
Nevertheless, all spam messages fall under the CAN SPAM ACT 2003.
As for the SSHD attacks, you may consider those general advises, deploy sshdfilter or implement SSHBL.
HTH.
Thank you!
  #10  
Old 04-30-2010
Registered User
 

Join Date: Apr 2010
Posts: 4
Thanks: 0
Thanked 0 Times in 0 Posts
In my experience it is very rare that anything consequential can be done about such attacks. This is because:

a) Usually executed behind offshore proxies
b) lack of political will

(unfortunately)
  #11  
Old 05-14-2010
Registered User
 

Join Date: May 2010
Posts: 7
Thanks: 1
Thanked 0 Times in 0 Posts
Well, If you see attacks originating from any machine, I'd block them.
Sponsored Links
Reply

Bookmarks

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


More UNIX and Linux Forum Topics You Might Find Helpful
Thread Thread Starter Forum Replies Last Post
After The Twitter Attack Linux Bot Cartoons for Geeks 0 08-09-2009 05:15 PM
Replay Attack Ashvin Gaur Security 3 05-27-2008 07:22 AM
anonymous ftp attack? dennisheazle Security 2 04-07-2008 08:11 PM
Bruteforce attack on my pc rdns UNIX for Dummies Questions & Answers 6 10-16-2007 02:37 PM



All times are GMT -4. The time now is 07:57 AM.