What he said, but I'll add that you should install Tripwire.
On Tue, Jul 29, 2003 at 04:58:59PM -0400, William Stearns is rumored to have said: > > Good afternoon, Chris, > > On Tue, 29 Jul 2003, Chris Santerre wrote: > > > It seems that since the SA Rule Emporium has been up, I've been the target > > of many a port scans from our friends in Korea and China. :) > > > > Guess the spammers may not be too happy with me. > > Lock down the machine as best you can, keep it updated with > patches for your OS, and don't stress the rest too much. I'd be glad to > give you a hand if you'd like it with locking it down or getting patches > in place. > > > It may not have been originated in Korea. Source port was 4280, which I > > believe is a Remote port. Could be an rootes machine. No biggy, just > > interesting they started the other day. > > Tough to say. You could be seeing lots of spoofed packets mixed > in with the few real port scans. > > > Anyone else ever get this after contributing? Devs? > > My spam intake jumped from 120/day before to 180/day right around > the time I published the spamassassin introduction article. Hmmm. > Thanks for the pointer to the blacklist, by the way. I appreciate > it. (If and when you send out an update, my last name is spelled > "Stearns", but it's hardly a problem. :-) > Cheers, > - Bill > -- "Copy from one, it's plagiarism; copy from two, it's research." - Wilson Mizner (1876-1933) ------------------------------------------------------- This SF.Net email sponsored by: Free pre-built ASP.NET sites including Data Reports, E-commerce, Portals, and Forums are available now. Download today and enter to win an XBOX or Visual Studio .NET. http://aspnet.click-url.com/go/psa00100003ave/direct;at.aspnet_072303_01/01 _______________________________________________ Spamassassin-talk mailing list [EMAIL PROTECTED] https://lists.sourceforge.net/lists/listinfo/spamassassin-talk