daveb47 Posted April 8, 2014 Author Posted April 8, 2014 Another 800 plus overnight,still going at about 50 per hour.no sshd (i use non standard high number port)mostly smtp which get ip blocked after first attempt and i get email,i then block 20 ip each side manually.Fuckin nuisance i know that.
inconsistant Posted April 8, 2014 Posted April 8, 2014 Its the school holidays so they're probably just bored. When something like this happened to us I went round and spoke to their parents, who of course knew nothing about it.They assured me that they would take appropriate action and sure enough the next day there was a timid knock on the door, an apology, and that was the last we heard of them.
dieselnutjob Posted April 8, 2014 Posted April 8, 2014 smtp is pain in the arseI use greylisting which helps but I think that eventually I will outsource my mx record to googlemail or something
Partridge Posted April 8, 2014 Posted April 8, 2014 Its paedophile porn rings trying to use servers to store porn i suspect,lot of it about at moment.http://news.sky.com/story/1238455/hackers-put-child-abuse-images-on-computersMy security is pretty good,plus fact that i am always checking so should be fine.Fucking hell. Almost makes me scared to use the internet to be honest. Thank you Dave, for holding the fort so well for us. Banger Kenny 1
oman5 Posted April 8, 2014 Posted April 8, 2014 all I can remember from the early '80s dawn of widespread home computer programming is 10 print "FUCK OFF";20 goto 10 does this help? inconsistant and Minimad5 2
FredTransit Posted April 10, 2014 Posted April 10, 2014 are the attacks linked in any way to the heartbleed bug? http://www.digitaltrends.com/computing/heres-a-list-of-websites-allegedly-affected-by-the-heartbleed-bug/#!DrYRd list of affected sites..... https://github.com/musalbas/heartbleed-masstest/blob/master/top1000.txt
daveb47 Posted April 10, 2014 Author Posted April 10, 2014 are the attacks linked in any way to the heartbleed bug? http://www.digitaltrends.com/computing/heres-a-list-of-websites-allegedly-affected-by-the-heartbleed-bug/#!DrYRd list of affected sites..... https://github.com/musalbas/heartbleed-masstest/blob/master/top1000.txtNo Fred,probably just chancers looking for somewhere to store illegal stuff,usuallt paedo stuff nowadays.Still going btw,over 2000 in last couple of days.
FredTransit Posted April 10, 2014 Posted April 10, 2014 bloody ell wot a pain Dave! I thought my old forum having 60 a day was bad....
daveb47 Posted April 10, 2014 Author Posted April 10, 2014 They are not trying to access the forum,they are trying to take over the server.
daveb47 Posted June 7, 2014 Author Posted June 7, 2014 They are at it again,500 plus and counting today so far.
Spiny Norman Posted June 7, 2014 Posted June 7, 2014 Hardly 'hackers' surely?Won't these just be Russian spammers trying to sell us willy embiggening pills and fake iThings?There's no financial advantage to be gained from infiltrating Autoshite, quite the reverse. hWe should try and sell them Cav's mouldy old BX, that'd sow them.... When I ran a forum there were hundreds of the fuckers. Looking in the spam logs usually revealed pages and pages of random looking email addresses.
daveb47 Posted June 7, 2014 Author Posted June 7, 2014 They are trying to access the server itself,not the forum.Spammers are fairly easy to counter.
loserone Posted June 7, 2014 Posted June 7, 2014 Have you something like fail2ban running? I don't (appear to) have too much trouble with smtp (yet), but it's always a matter of time Oh, just read this part: mostly smtp which get ip blocked after first attempt and i get email,i then block 20 ip each side manually. Are you seeing hits from consecutive IPs, or is this just a precaution?
Spiny Norman Posted June 7, 2014 Posted June 7, 2014 Why would hackers want onto a car forum server? There's no money here, no banking details, credit card numbers etc, there are far better things for them to go after, surely?
daveb47 Posted June 7, 2014 Author Posted June 7, 2014 They could use the email server to send bulk spam emails,or use the space to store/distribute porn etc.Or even somewhere to use for terrorist website maybe.Or just to store distribute pirate films or software.Loads of uses.Its not a car forum server,its a large server that just happens to host a car forum.
Jim Bell Posted June 8, 2014 Posted June 8, 2014 Could I use it to store a broken old car?That'd keep the hackers out. And I'd pay rent.
daveb47 Posted June 8, 2014 Author Posted June 8, 2014 If you can get it there i can probably find space for it on a hard drive.. dugong, DeeJay and Jim Bell 3
Lankytim Posted June 8, 2014 Posted June 8, 2014 Can't you let them upload it then delete it all? That would piss them off.
daveb47 Posted June 8, 2014 Author Posted June 8, 2014 Can't you let them upload it then delete it all? That would piss them off.Unfortunately they would delete everything on there before changing passwords etc.I could sort that out in a very short time but i would then have to rebuild board from latest backup.( i back up everything totally twice a day)But there would be downtime and post losses.Wont happen tho.
spike60 Posted June 8, 2014 Posted June 8, 2014 Sorry to hear you're getting so much chew, I can offer no useful advice though. Keep up the good work!
Lacquer Peel Posted June 8, 2014 Posted June 8, 2014 Bloody foreign hackers, the worst kind of hackers.
Mr_Bo11ox Posted June 8, 2014 Posted June 8, 2014 They come over here undercutting our own hardworking cyber crims and putting undue strain on already scant resources like the Police and Norton anti-virus etc. dugong and Lord Sterling 2
Paul Dupart Posted June 8, 2014 Posted June 8, 2014 UKIP would sort them! Lord Sterling, Cavcraft and Partridge 3
daveb47 Posted September 22, 2014 Author Posted September 22, 2014 Over 1200 attempts at accessing server in past couple of hours,still rising.
Parky Posted September 22, 2014 Posted September 22, 2014 Can you trace the attempts back to one particular place or is it all hidden? Maybe we could identify their location and block up their servers with Tagora pictures or something?
Caffiend Posted September 22, 2014 Posted September 22, 2014 I don't know if such attempts come associated with originating domain names. If they do, then it would be very very very wrong to go to whois.com, extract any email addresses you can find and sign them up to spamsignup.com (< yes that really exists). So don't* do that.
daveb47 Posted September 22, 2014 Author Posted September 22, 2014 All from different ip addressed from multiple countries so no chance of tracing actual ip address Large number of attempts from this IP: 190.187.47.55Origin Country: Peru (PE)Large number of attempts from this IP: 180.215.142.144Origin Country: India (IN)Large number of attempts from this IP: 188.52.27.50Origin Country: Saudi Arabia (SA)Etc so obviously using random proxiesAbout 1 every second at moment
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now