[ILUG] logwatch - should I be worried?

Timothy Murphy tim at birdsnest.maths.tcd.ie
Sun Jul 17 12:32:14 IST 2005


Logwatch stopped working properly on my Fedora system
with one update of logwatch.rpm but has now started again
with the next update.

During the week or fortnight I missed
the number of dropped packets has increased dramatically,
from about 200 per day to about 1000.

Most of these are targeted at ports 1026, 1027
which I take to be some kind of ssh or ssl attack.

My question is, Should I be worried?
Is there any chance that this attack will succeed at some point?
And is there anything more that I could or should do?
(I'm running a standard shorewall firewall.)

-- 
Timothy Murphy  
e-mail (<80k only): tim /at/ birdsnest.maths.tcd.ie
tel: +353-86-2336090, +353-1-2842366
s-mail: School of Mathematics, Trinity College, Dublin 2, Ireland



More information about the ILUG mailing list