Interim report from running a simple teergrube script over the weekend
97 requests from 17 different IP addresses during the last few days. Somebody seems to have gotten hold of a bunch of near-adjacent IP addresses so it's actually probably only 15 difrerent sources.
I changed the script to pull stuff from /dev/urandom since it was just too slow otherwise, and anyway, the entropy of the random data is not exactly a concern here.
Over the weekend, one particular loser pulled down 20 meg in two requests over two days. I bet I have a new fan there. (At 83.17.53.162 in case you care.)
Most script kiddies (or worms?) are clever enough to pull down just the first 512 or 768 or 2304 or 8448 bytes (no prizes for guessing the significance of those numbers?) so I guess I should have a plan B for them.
by
era
2006-06-19 01:23
blog
·
erablog
·
security
·
server
·
web
·
20060619-0123