From owner-freebsd-questions@FreeBSD.ORG Thu Feb 19 18:00:47 2009 Return-Path: Delivered-To: freebsd-questions@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id 45C80106566B for ; Thu, 19 Feb 2009 18:00:47 +0000 (UTC) (envelope-from andrewlylegould@gmail.com) Received: from mail-ew0-f21.google.com (mail-ew0-f21.google.com [209.85.219.21]) by mx1.freebsd.org (Postfix) with ESMTP id A90158FC14 for ; Thu, 19 Feb 2009 18:00:46 +0000 (UTC) (envelope-from andrewlylegould@gmail.com) Received: by ewy14 with SMTP id 14so545733ewy.19 for ; Thu, 19 Feb 2009 10:00:45 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=gamma; h=domainkey-signature:mime-version:received:date:message-id:subject :from:to:content-type; bh=OANjAFqi+rVEKolyT7KM4JfGcEOOo/3rREuGTwJww1E=; b=KqwCoo17aAIbEdkG4ESGyM8tAxPOTBpFUFU/9BMHM+jM5NCEeGCPEFprzK0L5QKZDt BynA8Wc80sr6Zj+mxxMHQiv6FAXefFsFnK25KSNH6tKa8uI4rb0JOGXwTZiGN2r+5hUa OgYPkoZF4yjxam7u4LpJF3o1ws93tYSi3J+rE= DomainKey-Signature: a=rsa-sha1; c=nofws; d=gmail.com; s=gamma; h=mime-version:date:message-id:subject:from:to:content-type; b=RonGQWItYbBkimWqtcvjmk3NxYGUXkfeWPLDxZlO2rrg3jidw0RUb0bJPdduIEgdDK LMumIuKUMvyXyp6VEsMNzOG39znBuAMm4sDKL8qA79dkVxZkAPWXq//P7gw3iyAtvJGH dL3eU8u0FnKuFDRDk8HRzG3kMROT+D7nsyUMc= MIME-Version: 1.0 Received: by 10.103.171.6 with SMTP id y6mr817043muo.31.1235066445508; Thu, 19 Feb 2009 10:00:45 -0800 (PST) Date: Thu, 19 Feb 2009 12:00:45 -0600 Message-ID: From: Andrew Gould To: FreeBSD Questions Mailing List Content-Type: text/plain; charset=ISO-8859-1 Content-Transfer-Encoding: 7bit X-Content-Filtered-By: Mailman/MimeDel 2.1.5 Subject: off topic: reporting attempts to access computers X-BeenThere: freebsd-questions@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: User questions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Thu, 19 Feb 2009 18:00:47 -0000 What information should I send to an abuse@* address when reporting a break-in attempt? My logs show a dictionary attack of invalid user names against port 22. I obtained an abuse@* email address using 'whois' and reported the beginning and ending date/times and the originating IP address. Is there any other information I need to send? Is there someone else I should notify? Most of the attacks I receive are from other continents, so I just block the network range found via 'whois'. In this case, the IP address is fairly local, so I'm hesitant to block the entire range. Thanks, Andrew