Vulture
Sep 4 2005, 10:55 PM
Anyone else notice a large increase in port scans from Korean/China IP addresses? There are over 20 scanning me right now I am wondering if I am about to be in for an attack. We don't host anything big so we have no enemies.
Thanx,
Chuck
pepolez
May 5 2006, 07:30 PM
We get approximately 1400 SSH based hacking attempts on our home connection (which hosts 5 sites) per day. The attempts basically use random usernames/passwords.
The access attempts are likely not actually people in China, but rather people using proxies that reside in China.
We have only ever been DoSed/DDoSed twice (although probably not related). One attack was at about 20mbit, which saturated our 15mbit connection for about 3 days. The other, strangely enough, seemed to be at a mere 5kbit and lasted for about a week (might have just been one of the boxes here stuck in a network based loop, i dunno).
Basically, these attempts are not too much of a concern as far as being attacked by saturation based attacks. As a precaution though, we have blocked all of China and I suggest that if the problem continues for you, that you do the same.