Help - Search - Members - Calendar
Full Version: Port Scanning from Korea/China
The Planet Forums > Security > DoS & D-DoS Mitigation
Vulture
Anyone else notice a large increase in port scans from Korean/China IP addresses? There are over 20 scanning me right now I am wondering if I am about to be in for an attack. We don't host anything big so we have no enemies.

Thanx,
Chuck
pepolez
We get approximately 1400 SSH based hacking attempts on our home connection (which hosts 5 sites) per day. The attempts basically use random usernames/passwords.

The access attempts are likely not actually people in China, but rather people using proxies that reside in China.

We have only ever been DoSed/DDoSed twice (although probably not related). One attack was at about 20mbit, which saturated our 15mbit connection for about 3 days. The other, strangely enough, seemed to be at a mere 5kbit and lasted for about a week (might have just been one of the boxes here stuck in a network based loop, i dunno).

Basically, these attempts are not too much of a concern as far as being attacked by saturation based attacks. As a precaution though, we have blocked all of China and I suggest that if the problem continues for you, that you do the same.
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.
Invision Power Board © 2001-2009 Invision Power Services, Inc.