> ---- Original Message ----
> From: Will Maier via UW-HEP Help System <help@hep.wisc.edu>
>
> On Mon, Jun 30, 2008 at 07:50:19PM -0500, Steve Rader via UW-HEP Help System wrote:
> > I guess we're okay now, but we should be aware that it seems
> > there's someobody out there who understands AFS and is using loose
> > ACLs to "own" us.
>
> This is ongoing; we're still seeing numerous hosts GETing
> http://www.hep.wisc.edu/dasu/rootFiles/, though they're getting 404s
> now that Steve's removed it. The traffic caused Apache to nearly
> fill the root disk with log events. I rotated and bzip2ed the log
> files, but it might be prudent to block the most egregious IPs.
>
> These two account for 99.5% of the recent bad traffic:
>
> 216.104.34.62
> 206.225.81.178
>
> Shall I add those to /etc/hosts.deny?
Yes, please.
steve
-- |