Click to See Complete Forum and Search --> : What to do with firewall logs???


blingbling!!
08-23-2004, 11:22 AM
Hey Peeps!

So, i've installed Firestarter (gtk IPTables front-end) on the new Slackware 10 install, and all is very hunky-dory! The question that now arises is what to do about all those hits i keep getting in the list. I reckon that most of them are from Zombies, coming in on unknown ports, then going away again. Some of them look pretty cheeky, though, I've had a few 'Back Orifice' attempts, some trying to get in on ftp, others on ssh, and some over a things called 'Kuang2' (i think).
What do you people do about the hits you get in your firewall? Do you ever contact the ISP's in question and alert them as to what's going on? (i can usually look up the hostname of the offending IP numbers) Is there any point in doing that? I share my Internet with my flatmate who uses windows, so presumably he's getting walloped all the time (we swap the cables in the ADSL box and use the conn. one at a time - very lazy!!!).

Any advice/comments appreciated.
--Robin