I regularly see and capture information about attempts to gain access to
my system. This month, I've seen a repeated attempt by someone to gain
access by establishing a Telnet session. So far, our software has
successfully rebuffed every access attempt. Because of the pattern, it
appears to me that someone is specifically targeting our IBM i server.
Every attempt consists of 27 attempts to establish a Telnet session, none
of which are successful. Then, the process repeats itself several hours
later. The IP addresses are from all over the place from RIPE in The
Netherlands to APNIC in Brisbane, Australia and from Time Warner, Comcast
and more.
I thought I'd notice law enforcement to see if something can be done
before damage happens and it turns out that there is NOTHING that can be
done. This is clearly malicious in intent but since no crime has been
committed, nobody can do anything about it. I checked with the local
police and the state police and I get the same response from both. I
suppose I could call the FBI, but I suspect they will sing the same song.
So, my question is, is there anything that you can do when you see this
kind of activity? Is there any agency that would respond?
The state police offered to take my system and audit it for me, but that
is just not an option.
Is this the state of protection from cybercrime?
Rich Loeber - @richloeber
Kisco Information Systems
[1]
http://www.kisco.com
References
Visible links
1.
http://www.kisco.com/
As an Amazon Associate we earn from qualifying purchases.