Security Incidents mailing list archives

Re: Handling Scans.


From: deviate <dv8 () HOME NL>
Date: Tue, 13 Feb 2001 19:51:06 +0100

I am on a dutch cable network, and get scanned so many times I just don't
care anymore.
If your security is so bad that a simple portscan can reveal all kinds of
holes, you have other problems to worry about.

Like one poster mentioned, scanning IS legal, ISP's WON'T generally do
anything about it, and often the adress is spoofed. My box security is
tight, my running services very minimal (SSH, SFTP) and my patches
up-to-date.

So why worry about some lamer who found a scanner on the net and has no
clue what to do with the result he gets?
If it a particular IP adress is scanning me for days in a row, I make a
'deny' rule just for them, but that is as far as I go.

regards,
Deviate

--
- No Sig is a Good Sig -


Current thread: