Mitigating garbage requests & other connexion attempts
Sylvain Saboua <[email protected]>
| Newsgroups | gmane.os.openbsd.misc |
|---|---|
| Message-ID | <[email protected]> |
I remember when I first purchased my domain name and linked it to my fixed IP address, without having even published it anywhere yet, my /var/www/logs/access.log was full of attackers' weird requests. The same thing happens in /var/log/authlog even with a nonstandard port for SSH forwarding. I suppose it would also be there in /var/log/maillog would I have set an email server up, and in other places. I know Peter Hansteen has worked on the latter case: https://nxdomain.no/~peter/effective_spam_and_malware_countermeasures.html But I am left bare facing the excessive malicious activity on my httpd(8) and sshd(8) services. So here's my question : is there a preferred / good practice way on OpenBSD to deflect attacker activity ? I'm not too worried about my system being penetrated, although one is never too careful, but I am regarding the workload this puts on my server and connexion. Cheers -- Sylvain Saboua looking for a PDP-11