SUBSIM Radio Room Forums



SUBSIM: The Web's #1 resource for all submarine & naval simulations since 1997

Go Back   SUBSIM Radio Room Forums > General > General Topics > PC Hardware/Software forum
Forget password? Reset here

Reply
 
Thread Tools Display Modes
Old 06-02-09, 09:33 PM   #1
Monica Lewinsky
Grey Wolf
 
Join Date: Mar 2007
Posts: 845
Downloads: 11
Uploads: 0
Default Anyone good with blocking IP's on a server?

Have my own home server based on Windows Small Business Server 2003 called Windows Home Server.

Geting whacked every 3-4 hours from b.s. client[s] connections in China trying to automatically hack into it looking for old versions of email hosting that I don't even have installed.

Got their IP's blocked with with IIS [Internet Information Services Manger], just tired of seeing the main reports of people accessing my server are hackers. Other than buying a Sonic Wall device got any ideas what to try instead of spending $400 bucks for a hardware solution?
__________________


Sink them all!
Monica Lewinsky is offline   Reply With Quote
Old 06-02-09, 09:48 PM   #2
SUBMAN1
Rear Admiral
 
Join Date: Apr 2005
Posts: 11,866
Downloads: 0
Uploads: 0
Default

Quote:
Originally Posted by Monica Lewinsky View Post
Have my own home server based on Windows Small Business Server 2003 called Windows Home Server.

Geting whacked every 3-4 hours from b.s. client[s] connections in China trying to automatically hack into it looking for old versions of email hosting that I don't even have installed.

Got their IP's blocked with with IIS [Internet Information Services Manger], just tired of seeing the main reports of people accessing my server are hackers. Other than buying a Sonic Wall device got any ideas what to try instead of spending $400 bucks for a hardware solution?
That's normal. Not a big deal. You will never stop it.

Of course, you can always limit what IP ranges people can see your server from, but this will only stop 50% of the China guys. They will just bounce off some local machine to get to you.

The point being is, quit worrying about it.

-S

PS. And make sure you always patch!
__________________
SUBMAN1 is offline   Reply With Quote
Old 06-03-09, 06:19 PM   #3
CaptainHaplo
Silent Hunter
 
CaptainHaplo's Avatar
 
Join Date: Apr 2007
Posts: 4,404
Downloads: 29
Uploads: 0
Default

Lots of options here. The cheapest is if you have a old desktop lying around. Build a linux kernel to have the thing run as a router with a decent IOS, and just set up your access list. If its spare box, the OS won't cost you a dime, so its free. Can't get a better price.

Second option, set up a software firewall. There is a cost for commercial good ones.

Depends on the usage your looking at - it may be best to get a real router with IOS firewall - and if your looking at lots or traffic and critical data - don't skimp and pony up for a true cisco. Their license costs for IOS are excellent - I think my last IOS update was like 6 bucks a router.

Now Subman is right, if your on the net you can use Best Practices, but there is never a guarantee.

However, if you know what the majority are looking for...... set up a honeypot and steer them to that. This way, you can track em, watch em, learn from em even, all the while they never touch the real part of your network.

I love honeypots. I use one pretty much on a consistent basis and have honestly learned ALOT about security because of them.
__________________
Good Hunting!

Captain Haplo
CaptainHaplo is offline   Reply With Quote
Old 06-03-09, 08:55 PM   #4
SUBMAN1
Rear Admiral
 
Join Date: Apr 2005
Posts: 11,866
Downloads: 0
Uploads: 0
Default

In response to Captain Haplo's idea - m0n0wall. Its a professional solution. Enough said.

Won't help you though. I spent years tracking and blocking and they have so many zombie machines, you cannot stop them.

What exactly are they attacking is a better question? If its your website, forget about it. You can't do a thing.

-S
__________________
SUBMAN1 is offline   Reply With Quote
Old 06-24-09, 09:36 PM   #5
Monica Lewinsky
Grey Wolf
 
Join Date: Mar 2007
Posts: 845
Downloads: 11
Uploads: 0
Default

Quote:
Originally Posted by SUBMAN1 View Post
What exactly are they attacking is a better question? If its your website, forget about it. You can't do a thing.
-S
Kinda disappointing to see the fifth place user being a Chinese bot sniffer to my site.

I understand your point[s]. THX guys.
__________________


Sink them all!
Monica Lewinsky is offline   Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT -5. The time now is 05:10 PM.


Powered by vBulletin® Version 3.8.11
Copyright ©2000 - 2024, Jelsoft Enterprises Ltd.
Copyright © 1995- 2024 Subsim®
"Subsim" is a registered trademark, all rights reserved.