Здрасьте вам.
у меня в /var/log/messages валяться вот такие сообщения
---------------- cut ---------------------
Jun 25 06:33:53 host2 proftpd[15824]: host29 (ip.205.162.23.19.tctc.com[205.162.23.19]) - FTP session closed.
Jun 25 06:44:55 host2 proftpd[15991]: host29 (ip.205.162.23.19.tctc.com[205.162.23.19]) - FTP session opened.
Jun 25 06:44:55 host2 proftpd[15991]: host29 (ip.205.162.23.19.tctc.com[205.162.23.19]) - FTP session closed.
Jun 25 06:44:58 host2 proftpd[15992]: host29 (ip.205.162.23.19.tctc.com[205.162.23.19]) - FTP session opened.
Jun 25 06:44:58 host2 proftpd[15993]: host29 (ip.205.162.23.19.tctc.com[205.162.23.19]) - FTP session opened.
Jun 25 06:44:58 host2 proftpd[15994]: host29 (ip.205.162.23.19.tctc.com[205.162.23.19]) - FTP session opened.
Jun 25 06:44:58 host2 proftpd[15995]: host29 (ip.205.162.23.19.tctc.com[205.162.23.19]) - FTP session opened.
Jun 25 06:44:59 host2 proftpd[15992]: host29 (ip.205.162.23.19.tctc.com[205.162.23.19]) - FTP session closed.
Jun 25 06:44:59 host2 proftpd[15993]: host29 (ip.205.162.23.19.tctc.com[205.162.23.19]) - FTP session closed.
Jun 25 06:44:59 host2 proftpd[15995]: host29 (ip.205.162.23.19.tctc.com[205.162.23.19]) - FTP session closed.
Jun 25 06:44:59 host2 proftpd[15994]: host29 (ip.205.162.23.19.tctc.com[205.162.23.19]) - FTP session closed.
Jun 25 06:45:07 host2 proftpd[16006]: host29 (ip.205.162.23.19.tctc.com[205.162.23.19]) - FTP session opened.
Jun 25 06:45:08 host2 proftpd[16009]: host29 (ip.205.162.23.19.tctc.com[205.162.23.19]) - FTP session opened.
Jun 25 06:45:09 host2 proftpd[16006]: host29 (ip.205.162.23.19.tctc.com[205.162.23.19]) - FTP session closed.
Jun 25 06:45:14 host2 proftpd[16010]: host29 (ip.205.162.23.19.tctc.com[205.162.23.19]) - FTP session opened.
Jun 25 06:45:16 host2 proftpd[16009]: host29 (ip.205.162.23.19.tctc.com[205.162.23.19]) - FTP session closed.
Jun 25 06:45:16 host2 proftpd[16010]: host29 (ip.205.162.23.19.tctc.com[205.162.23.19]) - FTP session closed.
Jun 25 06:47:21 host2 proftpd[16054]: host29 (ip.205.162.23.19.tctc.com[205.162.23.19]) - FTP session opened.
Jun 25 06:47:21 host2 proftpd[16054]: host29 (ip.205.162.23.19.tctc.com[205.162.23.19]) - FTP session closed.
Jun 25 06:47:53 host2 proftpd[16069]: host29 (ip.205.162.23.19.tctc.com[205.162.23.19]) - FTP session opened.
Jun 25 06:47:53 host2 proftpd[16069]: host29 (ip.205.162.23.19.tctc.com[205.162.23.19]) - FTP session closed.
Jun 25 06:48:24 host2 proftpd[16084]: host29 (ip.205.162.23.19.tctc.com[205.162.23.19]) - FTP session opened.
Jun 25 06:48:25 host2 proftpd[16084]: host29 (ip.205.162.23.19.tctc.com[205.162.23.19]) - FTP session closed.
Jun 25 06:48:39 host2 proftpd[16089]: host29 (ip.205.162.23.19.tctc.com[205.162.23.19]) - FTP session opened.
Jun 25 06:48:40 host2 proftpd[16089]: host29 (ip.205.162.23.19.tctc.com[205.162.23.19]) - FTP session closed.
Jun 25 06:48:54 host2 proftpd[16090]: host29 (ip.205.162.23.19.tctc.com[205.162.23.19]) - FTP session opened.
Jun 25 06:48:55 host2 proftpd[16090]: host29 (ip.205.162.23.19.tctc.com[205.162.23.19]) - FTP session closed.
Jun 25 06:49:13 host2 proftpd[16098]: host29 (ip.205.162.23.19.tctc.com[205.162.23.19]) - FTP session opened.
Jun 25 06:49:13 host2 proftpd[16098]: host29 (ip.205.162.23.19.tctc.com[205.162.23.19]) - FTP session closed.
Jun 25 06:55:46 host2 proftpd[16189]: host29 (ip.205.162.23.19.tctc.com[205.162.23.19]) - FTP session opened.
Jun 25 06:55:49 host2 proftpd[16192]: host29 (ip.205.162.23.19.tctc.com[205.162.23.19]) - FTP session opened.
Jun 25 06:55:49 host2 proftpd[16193]: host29 (ip.205.162.23.19.tctc.com[205.162.23.19]) - FTP session opened.
Jun 25 06:55:50 host2 proftpd[16189]: host29 (ip.205.162.23.19.tctc.com[205.162.23.19]) - FTP session closed.
Jun 25 06:55:51 host2 proftpd[16192]: host29 (ip.205.162.23.19.tctc.com[205.162.23.19]) - FTP session closed.
------------- cut -------------
это явный скан 21 порта, по моему мнению.
как уберечься от такого ? а то у меня даже inetd загибается ?
sourcse ip addresses меняються, т.е. какой то один закрыть файерволом не представляется возможным, может быть как-то в реал тайме можно это отслеживать ?
подскажите, технологию или тулзы
спасибо
василий