Skip site navigation (1)Skip section navigation (2)
Date:      Fri, 28 Sep 2001 03:09:36 +0100
From:      "Mark Hughes" <mark@dvdnews.co.uk>
To:        <freebsd-questions@FreeBSD.ORG>
Subject:   Nimda....suggestions for minimising impact?
Message-ID:  <076a01c147c2$b2cc8560$0200a8c0@mark2>

next in thread | raw e-mail | index | archive | help
Okay.....I've just checked the httpd error log on my freeBSD box which is
acting as my firewall/gateway for a small home network through an ADSL
connection and out into the big wide world.

I'm getting over two thousand scans a day now for Nimda, which I would say
is "fairly annoying", to say the least. It pales the 50 or so a day that I
was getting before for code-red-a-likes into insignificance - you can see
the date the virus was released due to a massive increase in the number of
errors, which seems to be doubling every three or four days aswell...

So, what I want to know is, what do people recommend for minimising the
impact of this? Ideally I'd want to drop the packets just as soon as
possible, I don't think I want to get into apache::codered and the like - I
just want to minimise the impact and possibly log each IP address that
causes an attack once, rather than appending miles and miles of errors to
the error log.

So, what do people recommend? I'm running IPFW, ppp -nat is doing my
connection sharing, apache is my webserver....am I best just letting it get
on with it or is there some way I can filter out this crap before it gets
in, as it were?

I'd rather not disable apache, but it's not vital that it remains
externally accessible - would disabling it help at all? Is there anything I
can make apache say back to the infected computer that would say "no, get
lost" as it were, and make it give up?

Obviously, these will be things that will be useful for anyone with an
internet connected freebsd box I'd guess, due to the nature of the beast.

Thanks in advance,
Mark
--
Mark Hughes - DVD & Film Content Manager, Technical Officer
Digital Spy Ltd
http://www.digitalspy.co.uk/
Your number one source for digital media and entertainment news!



To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-questions" in the body of the message




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?076a01c147c2$b2cc8560$0200a8c0>