Hi everyone,

Someone has been running (what appear to be) dictionary attacks against my server using (what appear to be) spoofed IP addresses. They haven't gotten through, and they won't with dictionary attacks (all user accounts have very good passwords), but this kind of thing is annoying.

I doubt there is anything I can do about this, but I thought I'd ask the group and see if any of you have ideas about what to do about this kind of thing.

In general, what do you guys do when your logs show someone attacking your server?

Move SSH, telnet etc.. to a non-default port or better yet lock them down to a certain subnet range where you usually login from. These kinds of attacks are common on Windows machines too- and the solution is to block the NetBIOS ports from non-Intranet addresses.