D&C GLug - Home Page

[ Date Index ] [ Thread Index ] [ <= Previous by date / thread ] [ Next by date / thread => ]

[LUG] reaction to botnet attack?

 

I'm assuming this is an attack from a botnet.

Router log
Sat, 2006-11-25 05:15:44 - UDP Packet - Source:221.231.130.87,2232
Destination:91.84.28.93,1434 - [Any(ALL) rule not match]
Sat, 2006-11-25 05:27:14 - UDP Packet - Source:102.1.1.73,1025
Destination:91.84.28.93,137 - [Any(ALL) rule not match]
Sat, 2006-11-25 05:42:22 - UDP Packet - Source:61.246.53.183,1028
Destination:91.84.28.93,137 - [Any(ALL) rule not match]
Sat, 2006-11-25 05:45:09 - UDP Packet - Source:212.49.206.22,1322
Destination:91.84.28.93,1434 - [Any(ALL) rule not match]
Sat, 2006-11-25 05:52:07 - TCP Packet - Source:58.121.75.35,1685
Destination:91.84.28.93,2100 - [Any(ALL) rule not match]
Sat, 2006-11-25 06:28:51 - UDP Packet - Source:218.75.82.210,4619
Destination:91.84.28.93,1434 - [Any(ALL) rule not match]
Sat, 2006-11-25 07:18:51 - UDP Packet - Source:203.160.254.139,2734
Destination:91.84.28.93,1434 - [Any(ALL) rule not match]
Sat, 2006-11-25 07:35:33 - UDP Packet - Source:82.242.129.43,1098
Destination:91.84.28.93,137 - [Any(ALL) rule not match]
Sat, 2006-11-25 10:00:18 - UDP Packet - Source:218.75.24.230,4206
Destination:91.84.28.93,1434 - [Any(ALL) rule not match]

What might one do about that, preferably something automatable, and
intended to cause inconvenience to the attacker.

-- 
A

-- 
The Mailing List for the Devon & Cornwall LUG
http://mailman.dclug.org.uk/listinfo/list
FAQ: http://www.dcglug.org.uk/linux_adm/list-faq.html