Somebody is trying to brute force my FTP server. What should I do?

Leros

Lifer
Jul 11, 2004
21,867
7
81
Somebody is repeatedly trying to login to my FTP server. There are about two attempts every second.

The IP is 200.119.223.247. I did a reverse lookup and its coming from Uruguay.

What should I do?
 

Leros

Lifer
Jul 11, 2004
21,867
7
81
Originally posted by: AgaBoogaBoo
Block the IP? :p


He is on my deny list, but the attempted login is still showing up every half second.

He isn't using any of my bandwidth, but my FTP program is using 80% of my CPU.
 

ValkyrieofHouston

Golden Member
Sep 26, 2005
1,736
0
0
Originally posted by: Leros
Somebody is repeatedly trying to login to my FTP server. There are about two attempts every second.

The IP is 200.119.223.247. I did a reverse lookup and its coming from Uruguay.

What should I do?



There is another site that I visit pretty frequently who was hacked twice just recently. Looked russian or something with a weird name, and then the hackers signature disappeared. That is the first time I have actually seen anything like that. Wow, I knew there were sites to look oup IP locations, did not know you might possibly be able to do a reverse look up. Hmmmm... I learn something new everyday here.
 

Leros

Lifer
Jul 11, 2004
21,867
7
81
I blocked off the IP at the router. Should I do anything about this guy or just ignore the hundreds of packets bouncing off my router?
 

skyking

Lifer
Nov 21, 2001
22,857
6,021
146
Originally posted by: Leros
I blocked off the IP at the router. Should I do anything about this guy or just ignore the hundreds of packets bouncing off my router?

Ignore. You'll get used to the kiddies, and they will go way eventually.
 

BurnItDwn

Lifer
Oct 10, 1999
26,369
1,879
126
As others have said, it's usually best to just block their IP and then ignore.

I sometimes run an nmap on them just to let them know I'm watching them.
Not too long ago a person who was trying to brute force me stuck around on undernet. I just sent him a tell that I had patched my proftpd and that he'd be chrooted with read only access and there's no chance of him causing a buffer underrun. I also told him that he will need a new IP address to try to break into my site. I also let him know that there is no "admin" account, and that root is obviously set to "su only" access (well, aside from physical console anyways). He stopped trying to get into my site.