View Single Post
  #2   Report Post  
Bruce L. Bergman
 
Posts: n/a
Default Firewalls and reporting

On 2 May 2004 11:10:12 -0400, wrote:

I believe you were talking about MyNe****chman specificly. I wouldn't bother
with them. As one of those on the "source ISP" end of things, we get notices
from them often and they are useless. They report that someone with foo
address tried to make a connection to baz address on this date. There isn't
enough information in the reports to determine what was happening and why,
so it gets ignored. Requests for more information from MyNe****chman were
also never answered.


So what would you recommend as an effective method of reporting
spammers, scammers & skript kiddies poking at your system ports for
vulnerabilities, that the BOFH ;-) Sysop community will actually
listen to?

I've been doing this from the user end for FAR too long (IBM 360
mark-sense card runs in Junior High, TI 99/4A, PC-XT...) and don't
want to spend too much time tracerouting the idiots and chasing down
foreign WHOIS sites, etc. - but if a neat little program can point me
to the moron's true origins, I'll gladly drop a dime on his ass so you
can terminate the account "with extreme prejudice". ;-)

The Internet is supposed to be self-policing. Give us the tools and
we'll help.

-- Bruce --
--
Bruce L. Bergman, Woodland Hills (Los Angeles) CA - Desktop
Electrician for Westend Electric - CA726700
5737 Kanan Rd. #359, Agoura CA 91301 (818) 889-9545
Spamtrapped address: Remove the python and the invalid, and use a net.