Hi to all,
First of all I want to say that I am missing a security-dedicated subforum on this forums.
To the point:
I have some FreeBSD servers running 24X7 and I have the port 22 and the openssh daemon running.
It is required by the network infrastructure to use only the port 22 for this purpose and not any other port and for that reason I receive daily ssh probes and dictionary attacks on the logs from attackers.
Of course I have taken all the needed precautions such us very strict openssh configuration and denyhosts configured using custom scripts that blocks the attacker at the firewall level as well.
Now I am planning to write a script to be executed by denyhosts so as to detect attackers's isp from the whois database and send an informational email to their isp's abuse mailing list about the attackers actions.
Do you have any comment on this? Do you find something not legal there in the terms of law?
Thanks
First of all I want to say that I am missing a security-dedicated subforum on this forums.
To the point:
I have some FreeBSD servers running 24X7 and I have the port 22 and the openssh daemon running.
It is required by the network infrastructure to use only the port 22 for this purpose and not any other port and for that reason I receive daily ssh probes and dictionary attacks on the logs from attackers.
Of course I have taken all the needed precautions such us very strict openssh configuration and denyhosts configured using custom scripts that blocks the attacker at the firewall level as well.
Now I am planning to write a script to be executed by denyhosts so as to detect attackers's isp from the whois database and send an informational email to their isp's abuse mailing list about the attackers actions.
Do you have any comment on this? Do you find something not legal there in the terms of law?
Thanks