Subj : Getting hammered! To : Digital Man From : Sniper Date : Fri Mar 17 2017 21:37:00 Re: Getting hammered! By: Digital Man to Sniper on Fri Mar 17 2017 04:35 pm > Re: Getting hammered! > By: Sniper to All on Thu Mar 16 2017 10:53 pm > > > So, its been a long time... My BBS has been running on auto-pilot. With > > daily observation, just not participating. ANyway, over the last few > > months, it seems that my IP address, host name, or something has been > > given to the hackers of the world. My system is constantly being > > connected to and they are trying to log in with unknown users. I've > > checked on the system and 2 or 3 nodes are scrolling off the screen as > > someone is attempting to brute force the Guest account. (Doesn't exist, > > but that doesn't seem to stop them). They try to brute force the "root" > > and "admin" as well. The large majority of these are coming from > > oversees. .jp, .ru, .au, etc. So I was attempting to block them by IP, > > but, as soon as I block one, 50 more show up. Now all this is occuring > > on a little 18 meg Uverse setup. Its getting a little out of hand! > > Read this: http://wiki.synchro.net/howto:block-hackers > > digital man > > Synchronet/BBS Terminology Definition #16: > DOVE = Domain/Vertrauen > Norco, CA WX: 80.7øF, 37.0% humidity, 10 mph ESE wind, 0.00 inches > rain/24hrs > Rob, as usual, you have the answer... I pushed it pretty high on the loginattemptdelay and loginattempthrottle. 10000 on each. Yes, they are still hitting, but its really slow... Awesome. So along with my .cn, .ru's in the host.can, this may have done the trick. They were filling up all my nodes and then attempting to force the passwords, and now... nothing... The way it was working, the connection would show up, and shortly after a second connection. The first would disconnect and the second would go start up the login process, and eventually go into the brute force attempt. Now, the first connection comes on, and it won't let the second connect, so the first quits and the second never starts. Awesome! :) Its stills scrolling off the screen pretty fast, but, none are completing. Someone can actually get in my BBS now! THey aren't filling up all the nodes! :) Sniper Killed In Action BBS, telnet://kiabbs.org  --- þ Synchronet þ Killed In Action BBS - kiabbs.org .