|
From: Craig W. <cra...@az...> - 2005-12-05 02:02:38
|
On Sun, 2005-12-04 at 10:31 -0600, da...@so... wrote: > Hi, > > Just got this as we finally have the mail back up. THanks for the > update and the heads up. We've been chasing what I thought was a > DOS here but now I see we've been more likely exploited. Is there > any information out as to getting rid of what ails our machines now? > We have huge (for this little shop) UDP traffic consisting of named > process requests that is just killing the message log with denied > requests. ---- change your firewall rules to simply drop them and not log them. There are some packets such as netbios that aren't worth logging and you could add port 53 to that category. Craig |