Subj : Hackers and port scanners To : Neko From : KK4QBN Date : Fri Mar 10 2017 12:30:00 Re: Hackers and port scanners By: Neko to Digital Man on Fri Mar 10 2017 01:37 pm Ne> [0mI mean there's a bot (Chinese IP address) constantly trying to connect Ne> to my BBS - it lasts about an hour. Log shows that there's an IP trying to Ne> connect and then I can see a warning "SSH Read Failure". After a minute Ne> the same IP tries to connect from another port and the same warning shows Ne> in the log. It doesn't matter if I turn on Windows Firewall, router Ne> firewall on the highest security settings, both or none of them. There are Ne> only exceptions for Synchronet and Windows Server services that need an Ne> exception. Since you made exceptions for SBBS in your firewall, it will ALWAYS allow connections to any port SBBS operates, If you put the IP in the ip.can you will still see the inital connection, but SBBS will block anything further than that. if seeing the connections bug you, you can always move your telnet, ssh, web and other services to non standard ports, but that may hinder you from getting real connections from actual people. even though I have put the IPS in my IP.can they still *TRY* to connect to the BBS on a fairly regular basis, but they never get as far as the inital connect phase before they are turned away. Now that DM has implemented the new can features I've never had issues with the nodes being full, etc. I agree, it gets on my nerves seeing all these bot connections, but there is nothing they can do, SYnchronet will not allow them to harm the system. my IP.CAN is now close to 1mb and growing every day. but the BBS is still running. no issues. -- Tim Smith (KK4QBN) KK4QBN BBS  --- þ Synchronet þ KK4QBN + (706)-422-9538 + kk4qbn.synchro.net + 24/7/365 .