Results 1 to 3 of 3
  1. #1
    Join Date
    Jun 2003
    Location
    Ukraine
    Posts
    263

    I block IP in APF but it still trying to telnet me!

    31-th of March I add 195.66.204.51 to deny_hosts.rules APF file and restarted APF.

    But today I recieve logwatch for 1-st April where I get
    Code:
       From 195.66.204.51 - 10 packets
          To MyIP - 10 packets
             Service: telnet (tcp/23) (** TELNET **,eth0,none) - 10 packets
    How it can be ?

  2. #2
    Join Date
    Mar 2003
    Location
    California USA
    Posts
    13,294
    if u read above it will say something like

    --------------------- Kernel Begin ------------------------

    Dropped 630 packets on interface eth0


    as you can see its droped the 10 packets the ip has sent
    Steven Ciaburri | Industry's Best Server Management - Rack911.com
    Software Auditing - 400+ Vulnerabilities Found - Quote @ https://www.RACK911Labs.com
    Fully Managed Dedicated Servers (Las Vegas, New York City, & Amsterdam) (AS62710)
    FreeBSD & Linux Server Management, Security Auditing, Server Optimization, PCI Compliance

  3. #3
    Join Date
    Jun 2003
    Location
    Ukraine
    Posts
    263
    nope, nothing like that.

    there is only 1 occurence of that IP in logwatch email at all.

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •