What he said, but I'll add that you should install Tripwire.

On Tue, Jul 29, 2003 at 04:58:59PM -0400, William Stearns is rumored to have said:
> 
> Good afternoon, Chris,
> 
> On Tue, 29 Jul 2003, Chris Santerre wrote:
> 
> > It seems that since the SA Rule Emporium has been up, I've been the target
> > of many a port scans from our friends in Korea and China. :) 
> > 
> > Guess the spammers may not be too happy with me. 
> 
>       Lock down the machine as best you can, keep it updated with 
> patches for your OS, and don't stress the rest too much.  I'd be glad to 
> give you a hand if you'd like it with locking it down or getting patches 
> in place.
> 
> > It may not have been originated in Korea. Source port was 4280, which I
> > believe is a Remote port. Could be an rootes machine. No biggy, just
> > interesting they started the other day. 
> 
>       Tough to say.  You could be seeing lots of spoofed packets mixed 
> in with the few real port scans.
> 
> > Anyone else ever get this after contributing? Devs?
> 
>       My spam intake jumped from 120/day before to 180/day right around 
> the time I published the spamassassin introduction article.  Hmmm.
>       Thanks for the pointer to the blacklist, by the way.  I appreciate
> it.  (If and when you send out an update, my last name is spelled
> "Stearns", but it's hardly a problem.  :-)
>       Cheers,
>       - Bill
> 

-- 
"Copy from one, it's plagiarism; copy from two, it's research." 
- Wilson Mizner (1876-1933) 


-------------------------------------------------------
This SF.Net email sponsored by: Free pre-built ASP.NET sites including
Data Reports, E-commerce, Portals, and Forums are available now.
Download today and enter to win an XBOX or Visual Studio .NET.
http://aspnet.click-url.com/go/psa00100003ave/direct;at.aspnet_072303_01/01
_______________________________________________
Spamassassin-talk mailing list
[EMAIL PROTECTED]
https://lists.sourceforge.net/lists/listinfo/spamassassin-talk

Reply via email to