• Random people acessing

    From Oshogun@VERT/STARKILL to All on Monday, April 25, 2016 21:16:51
    BTW, is it normal for a lot of (what I assume to be) bots from random places (lots of IPs from russia, for example) to telnet into my BBS system and try to login as root? Some of them even throw random UNIX commands at the login prompt, so I assume they are trying to get acess into unprotected unix shells (who the hell uses telnet on a unix shell anyway).

    It seems to be harmless since none of those commands will actually work on a BBS but, it is annoying.

    ---
    þ Synchronet þ STARKILLER BBS- A brazillian bbs.
  • From Nightfox@VERT/DIGDIST to Oshogun on Monday, April 25, 2016 15:52:29
    BTW, is it normal for a lot of (what I assume to be) bots from random places (lots of IPs from russia, for example) to telnet into my BBS system and try to login as root? Some of them even throw random UNIX commands at the login prompt, so I assume they are trying to get acess into unprotected unix shells (who the hell uses telnet on a unix shell anyway).

    It seems to be harmless since none of those commands will actually work on a BBS but, it is annoying.

    It's fairly common, yes. They are probably bots/scripts trying to do something malicious. I agree they are probably harmless since those commands won't work on a BBS, but if you want to block one of them, you can add the IP address to your ip.can file. I've heard of some scripts for Synchronet that will automatically add an IP address to your ip.can if it detects repeated logins, etc., but I don't remember offhand which scripts will do that for you.

    Nightfox

    ---
    þ Synchronet þ Digital Distortion: digitaldistortionbbs.com
  • From Mro@VERT/BBSESINF to Nightfox on Monday, April 25, 2016 20:55:19
    Re: Random people acessing
    By: Nightfox to Oshogun on Mon Apr 25 2016 03:52 pm

    add the IP address to your ip.can file. I've heard of some scripts for Synchronet that will automatically add an IP address to your ip.can if it detects repeated logins, etc., but I don't remember offhand which scripts will do that for you.



    and the jasman has a script that blocks 'em all
    ---
    þ Synchronet þ ::: BBSES.info - free BBS services :::
  • From Oshogun@VERT/STARKILL to Nightfox on Tuesday, April 26, 2016 00:20:45
    Re: Random people acessing
    By: Nightfox to Oshogun on Mon Apr 25 2016 15:52:29

    It's fairly common, yes. They are probably bots/scripts trying to do something malicious. I agree they are probably harmless since those commands won't work on a BBS, but if you want to block one of them, you can add the IP address to your ip.can file. I've heard of some scripts for Synchronet that will automatically add an IP address to your ip.can if it detects repeated logins, etc., but I don't remember offhand which scripts will do that for you.

    Yeah, I suspected as much. Well, I guess this shouldn't be a problem. It's kinda hilarious to see the bots trying to login as "cd /tmp || cd /var/run||" on a BBS.


    ----------------------------------------------------------------
    "I see the hands of man arise, with hungry mind, and open eyes"

    ---
    þ Synchronet þ STARKILLER BBS- A brazillian bbs.
  • From Ktulu@VERT/ROI to Oshogun on Tuesday, April 26, 2016 20:00:46
    Re: Random people acessing
    By: Oshogun to Nightfox on Tue Apr 26 2016 12:20 am

    I've got the same thing going on here, After looking into it a bit further some of these 'scripts' are attempting to login to do a Brute force on a DVR player, by logging in as "xc5311" (*shrug*)

    The only time it pisses me off is when they tie up ALL nodes of the BBS.

    -Ktulu



    Yeah, I suspected as much. Well, I guess this shouldn't be a problem. It's kinda hilarious to see the bots trying to login as "cd /tmp || cd /var/run||" on a BBS.

    ---
    þ Synchronet þ Realm of Insanity - Racine, WI telnet://roi.synchro.net
  • From Poindexter Fortran@VERT/REALITY to Ktulu on Wednesday, April 27, 2016 07:01:46
    Re: Random people acessing
    By: Ktulu to Oshogun on Tue Apr 26 2016 08:00 pm

    I've got the same thing going on here, After looking into it a bit further some of these 'scripts' are attempting to login to do a Brute force on a DVR player, by logging in as "xc5311" (*shrug*)

    I saw that too, thought it was an EMSI handshake gone awry.

    ---
    þ Synchronet þ realitycheckBBS -- http://realitycheckBBS.org
  • From Denn Gray@VERT/OUTWEST to Ktulu on Wednesday, April 27, 2016 08:26:54
    Re: Random people acessing
    By: Ktulu to Oshogun on Tue Apr 26 2016 08:00 pm

    I've got the same thing going on here, After looking into it a bit further s of these 'scripts' are attempting to login to do a Brute force on a DVR play by logging in as "xc5311" (*shrug*)

    The only time it pisses me off is when they tie up ALL nodes of the BBS.

    It is halarious, Since I closed all ports except the ones I use on my BBS PC the number of bot related hits have gone down considerably.
    Before I closed ports I watched several times as all 10 nodes were being hit all at the same time, since closing ports down I see 1 node once in awhile being sniffed by a sniff bot.

    ---
    þ Synchronet þ The Outwest BBS - outwestbbs.com - DOORS - Files -Dove-Net
  • From Oshogun@VERT/STARKILL to Ktulu on Wednesday, April 27, 2016 11:50:05
    Re: Random people acessing
    By: Ktulu to Oshogun on Tue Apr 26 2016 20:00:46

    Re: Random people acessing
    By: Oshogun to Nightfox on Tue Apr 26 2016 12:20 am

    I've got the same thing going on here, After looking into it a bit further some of these 'scripts' are attempting to login to do a Brute force on a DVR player, by logging in as "xc5311" (*shrug*)

    The only time it pisses me off is when they tie up ALL nodes of the BBS.

    -Ktulu



    Yeah, I suspected as much. Well, I guess this shouldn't be a problem. It's kinda hilarious to see the bots trying to login as "cd /tmp || cd /var/run||" on a BBS.


    Yeah I just got the xc3511 too D:

    Well I use 10 nodes here and they usually just take up one at a time. Lucky me I guess.



    -------------------------------------------------------------------------
    I see the hands of men arise, with hungry mind and open eyes

    ---
    þ Synchronet þ STARKILLER BBS- A brazillian bbs.
  • From Jeff Friend@VERT/MORDOR to Denn Gray on Thursday, April 28, 2016 07:52:41
    Re: Random people acessing
    By: Denn Gray to Ktulu on Wed Apr 27 2016 08:26 am

    It is halarious, Since I closed all ports except the ones I use on my BBS PC the number of bot related hits have gone down considerably.
    Before I closed ports I watched several times as all 10 nodes were being hi all at the same time, since closing ports down I see 1 node once in awhile being sniffed by a sniff bot.

    I have noticed this too. They always seem to try to log in as "root". Of course, they never get in. But in 2 or 3 days, over 2000 attempts to login like that.. I just ignore them.

    Jeff in Brisbane.

    ---
    þ Synchronet þ Mordor - casper.homeip.net
  • From Oshogun@VERT/STARKILL to Denn Gray on Wednesday, April 27, 2016 21:00:48
    Re: Random people acessing
    By: Denn Gray to Ktulu on Wed Apr 27 2016 08:26:54

    It is halarious, Since I closed all ports except the ones I use on my BBS PC the number of bot related hits have gone down considerably.
    Before I closed ports I watched several times as all 10 nodes were being hit all at the same time, since closing ports down I see 1 node once in awhile being sniffed by a sniff bot.

    Oh yes, all the ports here are closed except the ones I use in the bbs and some game servers. Leaving unecessary ports open in your router is usually not a brilliant idea.

    ---
    þ Synchronet þ STARKILLER BBS- A brazillian bbs.
  • From Ktulu@VERT/ROI to Oshogun on Wednesday, April 27, 2016 19:23:43
    Re: Random people acessing
    By: Oshogun to Ktulu on Wed Apr 27 2016 11:50 am

    Yeah I just got the xc3511 too D:

    Googled:
    How to reset a DVR to factory settings, and I found this:

    To reset password use telnet access with login "root" and password "xc3511". Then go to "/mnt/mtd/Config/" (cd /mnt/mtd/Config/) directory and delete all files "Account" (use "rm -f Account*" command). After reboot DVR will accept empty password for admin.

    I still think it's funny. Damn amateurs. LOL!

    -Ktulu

    ---
    þ Synchronet þ Realm of Insanity - Racine, WI telnet://roi.synchro.net
  • From Oshogun@VERT/STARKILL to Ktulu on Thursday, April 28, 2016 08:44:08
    Re: Random people acessing
    By: Ktulu to Oshogun on Wed Apr 27 2016 19:23:43

    Re: Random people acessing
    By: Oshogun to Ktulu on Wed Apr 27 2016 11:50 am

    Yeah I just got the xc3511 too D:

    Googled:
    How to reset a DVR to factory settings, and I found this:

    To reset password use telnet access with login "root" and password "xc3511". Then go to "/mnt/mtd/Config/" (cd /mnt/mtd/Config/) directory and delete all files "Account" (use "rm -f Account*" command). After reboot DVR will accept empty password for admin.

    I still think it's funny. Damn amateurs. LOL!

    -Ktulu


    Now I just feel like making a "root/xc3511" account with no privileges on the bbs just to see what they do when they get access :')

    ---
    þ Synchronet þ STARKILLER BBS- A brazillian bbs.
  • From Ktulu@VERT/ROI to Oshogun on Friday, April 29, 2016 10:04:24
    Re: Random people acessing
    By: Oshogun to Ktulu on Thu Apr 28 2016 08:44 am

    Now I just feel like making a "root/xc3511" account with no privileges on the bbs just to see what they do when they get access :')

    I know! I thought about doing the same thing.
    Or maybe when they login with the account send about a 2GB text listing of movies to their screen then hangup.

    -Ktulu

    ---
    þ Synchronet þ Realm of Insanity - Racine, WI telnet://roi.synchro.net
  • From tracker1@VERT/TRNTEST to Jeff Friend on Saturday, April 30, 2016 17:37:17
    I have noticed this too. They always seem to try to log in as "root". Of
    course, they never get in. But in 2 or 3 days, over 2000 attempts to login like that.. I just ignore them.

    I keep thinking, one could run a script at the top of their login script to "You have 10 seconds to press Esc twice." where it just disconnects after 10 seconds without two escape key presses.. similar to the old dialers, but this time to disconnect the bots before they even get to a login prompt.

    --
    Michael J. Ryan
    tracker1(at)gmail.com
    +o Roughneck BBS

    ---
    þ Synchronet þ RoughneckBBS - http://www.roughneckbbs.com/
  • From Nightfox@VERT/DIGDIST to tracker1 on Saturday, April 30, 2016 21:33:45
    Re: Re: Random people acessing
    By: tracker1 to Jeff Friend on Sat Apr 30 2016 17:37:17

    I keep thinking, one could run a script at the top of their login script to "You have 10 seconds to press Esc twice." where it just disconnects after 10 seconds without two escape key presses.. similar to the old dialers, but this time to disconnect the bots before they even get to a login prompt.

    Seems like that could add an unnecessary hassle, since most of these bots probably won't be able to do anything anyway (you probably don't have a user named 'root', and the commands they try to use won't do anything).
    Several years ago, I added a login matrix to my BBS, and I figure that should also keep most of the bots out since these bots don't know how to use a login matrix. I suppose that only works with telnet though; bots could still try to log in via SSH.

    Nightfox

    ---
    þ Synchronet þ Digital Distortion: digitaldistortionbbs.com
  • From Jeff Friend@VERT/MORDOR to tracker1 on Sunday, May 01, 2016 14:55:04
    Re: Re: Random people acessing
    By: tracker1 to Jeff Friend on Sat Apr 30 2016 05:37 pm

    I keep thinking, one could run a script at the top of their login script to "You have 10 seconds to press Esc twice." where it just disconnects after 10 seconds without two escape key presses.. similar to the old dialers, but thi time to disconnect the bots before they even get to a login prompt.

    I remember seeing that on alot of bbs's years ago too> Would be an idea..

    Jeff

    ---
    þ Synchronet þ Mordor - casper.homeip.net
  • From Mro@VERT/BBSESINF to tracker1 on Sunday, May 01, 2016 10:25:16
    Re: Re: Random people acessing
    By: tracker1 to Jeff Friend on Sat Apr 30 2016 05:37 pm

    I have noticed this too. They always seem to try to log in as "root". Of
    course, they never get in. But in 2 or 3 days, over 2000 attempts to login like that.. I just ignore them.

    I keep thinking, one could run a script at the top of their login script to "You have 10 seconds to press Esc twice." where it just disconnects after
    10 seconds without two escape key presses.. similar to the old dialers, but this time to disconnect the bots before they even get to a login prompt.


    i have a capcha script that blocks everybody and then removes them and whitelists their ip once they solve it. it blocks a lot but there's an unlimited amount of attackers.
    ---
    þ Synchronet þ ::: BBSES.info - free BBS services :::
  • From Patch@VERT/R2LOTW to Nightfox on Sunday, May 01, 2016 16:05:59
    Re: Re: Random people acessing
    By: Nightfox to tracker1 on Sat Apr 30 2016 09:33 pm

    Seems like that could add an unnecessary hassle, since most of these bots probably won't be able to do anything anyway (you probably don't have a user named 'root', and the commands they try to use won't do anything). Several years ago, I added a login matrix to my BBS, and I figure that should also keep most of the bots out since these bots don't know how to use a login matrix. I suppose that only works with telnet though; bots could still try to log in via SSH.

    Curious on this though, is there any method either witnin SBBS or with another software package that can block an IP address from even getting through?

    I thought PeerBlock had a function like that, but didn't see it when I looked the last time.

    -Patch


    ---------------------------------------------------------------------------
    = Return To The Lair of the Wolverine = Telet:r2lotw.synchro.net=

    ---
    þ Synchronet þ R2LOTW - Reliving The Past - r2lotw.synchro.net - 24/7 - Games, Files, Messages.
  • From Spacesst@VERT/SPACESST to Mro on Sunday, May 01, 2016 15:50:48
    Re: Re: Random people acessing
    By: Mro to tracker1 on Sun May 01 2016 10:25:16

    i have a capcha script that blocks everybody and then removes them and whitelists their ip once they solve it. it blocks a lot but there's an unlimited amount of attackers.
    unlimited amount of attackers.

    Why not a Script with 3 connections in 5 min , and block the ip for 30 min
    or indefinitly , also a Block DNS server to detect bad ip

    ... Chuck Norris can have his cake and eat it too.

    ---
    þ Synchronet þ SpaceSST BBS Usenet Gateway
  • From Mro@VERT/BBSESINF to Patch on Sunday, May 01, 2016 19:31:49
    Re: Re: Random people acessing
    By: Patch to Nightfox on Sun May 01 2016 04:05 pm


    I thought PeerBlock had a function like that, but didn't see it when I looked the last time.


    peerblock does that, if you add the ip address to a custom list.
    ---
    þ Synchronet þ ::: BBSES.info - free BBS services :::
  • From Mro@VERT/BBSESINF to Spacesst on Sunday, May 01, 2016 19:33:22
    Re: Re: Random people acessing
    By: Spacesst to Mro on Sun May 01 2016 03:50 pm

    Why not a Script with 3 connections in 5 min , and block the ip for 30 min
    or indefinitly , also a Block DNS server to detect bad ip



    because if they are a blocked straightaway if they are not a bbs user.
    i dont have to add all the "if they do this and that" stuff.

    i only had a few morons type the wrong capcha and answer yes twice when i asked them if they were sure.
    ---
    þ Synchronet þ ::: BBSES.info - free BBS services :::
  • From Nightfox@VERT/DIGDIST to Patch on Sunday, May 01, 2016 17:55:00
    Re: Re: Random people acessing
    By: Patch to Nightfox on Sun May 01 2016 16:05:59

    Curious on this though, is there any method either witnin SBBS or with another software package that can block an IP address from even getting through?

    Yeah, you can add an IP address to the file ip.can to have Synchronet block the IP address from getting through. If you use the Windows version of Synchronet, one way to edit your ip.can is from sbbsctrl, go to BBS > Filters > IP address filter.

    Another thing you could do is if your router supports iptables, you could add
    a line to your router's iptables configuration to block the IP address. Then your router would block it so the request wouldn't have to go to your Synchronet BBS.

    Nightfox

    ---
    þ Synchronet þ Digital Distortion: digitaldistortionbbs.com
  • From Oshogun@VERT/STARKILL to Ktulu on Sunday, May 01, 2016 10:47:03
    Re: Random people acessing
    By: Ktulu to Oshogun on Fri Apr 29 2016 10:04:24

    Or maybe when they login with the account send about a 2GB text listing of movies to their screen then hangup.

    This. This is beautiful. I like it.

    ---
    þ Synchronet þ STARKILLER BBS- A brazillian bbs.
  • From Patch@VERT/R2LOTW to Mro on Monday, May 02, 2016 07:30:41
    Re: Re: Random people acessing
    By: Mro to Patch on Sun May 01 2016 07:31 pm

    peerblock does that, if you add the ip address to a custom list.

    I thought it had a way, thanks for reminding me now. =)

    -Patch


    ---------------------------------------------------------------------------
    = Return To The Lair of the Wolverine = Telet:r2lotw.synchro.net =
    = Discord Global BBS Community = http://discord.gg/0yCxVosom5t6QNk5 =

    ---
    þ Synchronet þ R2LOTW - Reliving The Past - r2lotw.synchro.net - 24/7 - Games, Files, Messages.
  • From Patch@VERT/R2LOTW to Nightfox on Monday, May 02, 2016 07:34:44
    Re: Re: Random people acessing
    By: Nightfox to Patch on Sun May 01 2016 05:55 pm

    Yeah, you can add an IP address to the file ip.can to have Synchronet block the IP address from getting through. If you use the Windows version of Synchronet, one way to edit your ip.can is from sbbsctrl, go to BBS > Filters > IP address filter.

    VERY good to know, thank you!

    I had to modify my Guest log in so that they could get limited things, but I still see someone trying to hack into the board using unix commands and shell as the username.

    While humorous, I'd rather be proactive with that kind-of thing.


    Another thing you could do is if your router supports iptables, you could add a line to your router's iptables configuration to block the IP address. Then your router would block it so the request wouldn't have to go to your Synchronet BBS.

    Ahhh ... forgot about doing it that way.

    So many ways ... =) Thanks again Nightfox!

    -Patch


    ---------------------------------------------------------------------------
    = Return To The Lair of the Wolverine = Telet:r2lotw.synchro.net =
    = Discord Global BBS Community = http://discord.gg/0yCxVosom5t6QNk5 =

    ---
    þ Synchronet þ R2LOTW - Reliving The Past - r2lotw.synchro.net - 24/7 - Games, Files, Messages.
  • From Denn Gray@VERT/OUTWEST to Patch on Monday, May 02, 2016 08:10:03
    Re: Re: Random people acessing
    By: Patch to Nightfox on Sun May 01 2016 04:05 pm

    Curious on this though, is there any method either witnin SBBS or with another software package that can block an IP address from even getting through?

    Mystic has an autoblocker 4 attempts in 20 seconds blocks ip.

    ---
    þ Synchronet þ The Outwest BBS - outwestbbs.com - DOORS - Files -Dove-Net
  • From Patch@VERT/R2LOTW to Denn Gray on Monday, May 02, 2016 11:51:10
    Re: Re: Random people acessing
    By: Denn Gray to Patch on Mon May 02 2016 08:10 am

    Mystic has an autoblocker 4 attempts in 20 seconds blocks ip.

    Very nice.

    I use an application called PeerBlock which connects to known anti-spam servers, downloads lists and implements that on the network.

    One thing that you can do is create a list yourself to be included. After looking at the FTP logs I blocked out a section of IP addresses that seemed to be trying to connect using the 'root' username.

    If you want to go that route please let me know, I'm willing to help get it set up for you and show you how to use it.

    -Patch


    ---------------------------------------------------------------------------
    = Return To The Lair of the Wolverine = Telet:r2lotw.synchro.net =
    = Discord Global BBS Community = http://discord.gg/0yCxVosom5t6QNk5 =

    ---
    þ Synchronet þ R2LOTW - Reliving The Past - r2lotw.synchro.net - 24/7 - Games, Files, Messages.
  • From Mro@VERT/BBSESINF to Denn Gray on Monday, May 02, 2016 17:37:36
    Re: Re: Random people acessing
    By: Denn Gray to Patch on Mon May 02 2016 08:10 am

    Re: Re: Random people acessing
    By: Patch to Nightfox on Sun May 01 2016 04:05 pm

    Curious on this though, is there any method either witnin SBBS or with another software package that can block an IP address from even getting through?

    Mystic has an autoblocker 4 attempts in 20 seconds blocks ip.



    are they still using those blocklists meant for email spam as a general block list?

    i always thought that was stupid. most residential ips are added to those lists.
    ---
    þ Synchronet þ ::: BBSES.info - free BBS services :::
  • From Xucaen@VERT/TIMEPORT to Oshogun on Monday, May 02, 2016 21:06:25
    BTW, is it normal for a lot of (what I assume to be) bots from random places >(lots of IPs from russia, for example) to telnet into my BBS system and try to >login as root? Some of them even throw random UNIX commands at the login >prompt, so I assume they are trying to get acess into unprotected unix shells >(who the hell uses telnet on a unix shell anyway).

    It seems to be harmless since none of those commands will actually work on a >BBS but, it is annoying.


    That happened to me to day after I started running my BBS. I used noip.com and somehow it was made visible to spammers trying to hack in. After changing my url and using Synchronet's IP forward service, that hasn't happened.

    ---
    þ Synchronet þ The Time Portal - timeport.synchro.net:2112 - Home of Labyrinth.
  • From Denn Gray@VERT/OUTWEST to Patch on Tuesday, May 03, 2016 08:01:52
    Re: Re: Random people acessing
    By: Patch to Denn Gray on Mon May 02 2016 11:51 am

    I use an application called PeerBlock which connects to known anti-spam servers, downloads lists and implements that on the network.

    I really don't have to much of a problem since I block all ports except the ones needed by synchronet, you can also block country ips such as China and Russia.

    ---
    þ Synchronet þ The Outwest BBS - outwestbbs.com - DOORS - Files -Dove-Net
  • From Denn Gray@VERT/OUTWEST to Mro on Tuesday, May 03, 2016 08:09:16
    Re: Re: Random people acessing
    By: Mro to Denn Gray on Mon May 02 2016 05:37 pm

    are they still using those blocklists meant for email spam as a general block list?

    I don't know, I ran Mystic for a couple of months but switched back to Synchronet, I just remember the autoblocker feature on Mystic.

    ---
    þ Synchronet þ The Outwest BBS - outwestbbs.com - DOORS - Files -Dove-Net
  • From Patch@VERT/R2LOTW to Denn Gray on Tuesday, May 03, 2016 13:39:05
    Re: Re: Random people acessing
    By: Denn Gray to Patch on Tue May 03 2016 08:01 am

    I really don't have to much of a problem since I block all ports except the ones needed by synchronet, you can also block country ips such as China and Russia.

    Another good suggestion. =)

    -Patch


    ---------------------------------------------------------------------------
    = Return To The Lair of the Wolverine = Telet:r2lotw.synchro.net =
    = Discord Global BBS Community = http://discord.gg/0yCxVosom5t6QNk5 =

    ---
    þ Synchronet þ R2LOTW - Reliving The Past - r2lotw.synchro.net - 24/7 - Games, Files, Messages.
  • From Goose@VERT/ROTHBBSN to Patch on Tuesday, May 03, 2016 23:39:44
    Re: Re: Random people acessing
    By: Patch to Denn Gray on Tue May 03 2016 13:39:05

    Hi Guys,

    why dont use the program PEERBLOCK ?
    Under Windows, you can block blacklisted IPs/Bots from your computer who is running the BBS.

    PeerBlock is open source. i use it on my bbs as well.

    Greetings
    Mike

    ---
    þ Synchronet þ Roth BBS Net - rothbbs.ddns.net
  • From Patch@VERT/R2LOTW to Goose on Tuesday, May 03, 2016 17:15:32
    Re: Re: Random people acessing
    By: Goose to Patch on Tue May 03 2016 11:39 pm

    why dont use the program PEERBLOCK ?

    Yep, I am =)

    I forgot that you could import your own lists to block set IP addresses. It seems to have worked well as I don't have the person trying to hack the telnet port using ROOT as the username. At least not from that IP address...

    -Patch


    ---------------------------------------------------------------------------
    = Return To The Lair of the Wolverine = Telet:r2lotw.synchro.net =
    = Discord Global BBS Community = http://discord.gg/0yCxVosom5t6QNk5 =

    ---
    þ Synchronet þ R2LOTW - Reliving The Past - r2lotw.synchro.net - 24/7 - Games, Files, Messages.
  • From Mro@VERT/BBSESINF to Denn Gray on Tuesday, May 03, 2016 19:50:00
    Re: Re: Random people acessing
    By: Denn Gray to Patch on Tue May 03 2016 08:01 am


    I use an application called PeerBlock which connects to known anti-spam servers, downloads lists and implements that on the network.

    I really don't have to much of a problem since I block all ports except the ones needed by synchronet, you can also block country ips such as China and Russia.


    yeah but it takes the stress away from the bbs when there are attackers hitting the bbs ports.
    ---
    þ Synchronet þ ::: BBSES.info - free BBS services :::
  • From Jeff Friend@VERT/MORDOR to Goose on Wednesday, May 04, 2016 16:30:22
    Re: Re: Random people acessing
    By: Goose to Patch on Tue May 03 2016 11:39 pm

    why dont use the program PEERBLOCK ?
    Under Windows, you can block blacklisted IPs/Bots from your computer who is running the BBS.

    PeerBlock is open source. i use it on my bbs as well.

    I just looked up Peerblock and all it would do is let me see the forums. Found a download link and it just took me back to the forums again.

    Is there a download link somewhere else?

    Jeff

    ---
    þ Synchronet þ Mordor - casper.homeip.net
  • From Goose@VERT/ROTHBBSN to Jeff Friend on Wednesday, May 04, 2016 11:56:28
    Re: Re: Random people acessing
    By: Jeff Friend to Goose on Wed May 04 2016 16:30:22

    Hi Jeff,

    here i got a download link for you.
    http://filehippo.com/de/download_peerblock/

    Greetings
    Mike

    ---
    þ Synchronet þ Roth BBS Net - rothbbs.ddns.net
  • From Patch@VERT/R2LOTW to Jeff Friend on Wednesday, May 04, 2016 08:05:08
    Re: Re: Random people acessing
    By: Jeff Friend to Goose on Wed May 04 2016 04:30 pm

    I just looked up Peerblock and all it would do is let me see the forums. Found a download link and it just took me back to the forums again.

    Is there a download link somewhere else?

    Yes, I was able to download it from my favorite freeware download site:

    www.freewarefiles.com/PeerBlock_program_53440.html

    -Patch



    ---------------------------------------------------------------------------
    = Return To The Lair of the Wolverine = Telet:r2lotw.synchro.net =
    = Discord Global BBS Community = http://discord.gg/0yCxVosom5t6QNk5 =

    ---
    þ Synchronet þ R2LOTW - Reliving The Past - r2lotw.synchro.net - 24/7 - Games, Files, Messages.
  • From Jeff Friend@VERT/MORDOR to Goose on Thursday, May 05, 2016 06:21:54
    Re: Re: Random people acessing
    By: Goose to Jeff Friend on Wed May 04 2016 11:56 am

    Re: Re: Random people acessing
    By: Jeff Friend to Goose on Wed May 04 2016 16:30:22

    Hi Jeff,

    here i got a download link for you. http://filehippo.com/de/download_peerblock/

    Greetings
    Mike

    Thanks Mike, I eventually found it at download.com or what ever it is called.

    Jeff

    ---
    þ Synchronet þ Mordor - casper.homeip.net
  • From Jeff Friend@VERT/MORDOR to Patch on Thursday, May 05, 2016 06:23:07
    Re: Re: Random people acessing
    By: Patch to Jeff Friend on Wed May 04 2016 08:05 am

    Yes, I was able to download it from my favorite freeware download site:

    www.freewarefiles.com/PeerBlock_program_53440.html
    Thanks for that. I found it last night at download.com as well.

    ---
    þ Synchronet þ Mordor - casper.homeip.net
  • From Mro@VERT/BBSESINF to Jeff Friend on Wednesday, May 04, 2016 15:49:12
    Re: Re: Random people acessing
    By: Jeff Friend to Goose on Wed May 04 2016 04:30 pm

    PeerBlock is open source. i use it on my bbs as well.

    I just looked up Peerblock and all it would do is let me see the forums. Found a download link and it just took me back to the forums again.

    Is there a download link somewhere else?



    maybe you have to be logged in. i see what you mean.

    if you want i have an old version.
    ---
    þ Synchronet þ ::: BBSES.info - free BBS services :::
  • From Oshogun@VERT/STARKILL to Xucaen on Tuesday, May 03, 2016 18:58:02
    Re: Random people acessing
    By: Xucaen to Oshogun on Mon May 02 2016 21:06:25

    That happened to me to day after I started running my BBS. I used noip.com and somehow it was made visible to spammers trying to hack in. After changing my url and using Synchronet's IP forward service, that hasn't happened.

    Yeah, I'll have to stick to No-IP because I use it for other services as well (since my bbs is just my plaything anyway). Soon I'm going to completely remove telnet from my BBS and make it a SSH only thing. Although I don't really see much point on using ssh when you are not using RSA keys as well.

    (I do work with computer security and... The kind of technology used on BBS does feed my paranoia)

    The only reason I still support telnet on my BBS is because of the webclient, but I'm going to replace it with a web-based ssh terminal and everything will be happy. At least I hope so.

    ---
    þ Synchronet þ STARKILLER BBS- A brazillian bbs.
  • From Goose@VERT/ROTHBBSN to Jeff Friend on Thursday, May 05, 2016 10:15:27
    Re: Re: Random people acessing
    By: Goose to Jeff Friend on Wed May 04 2016 11:56 am

    Re: Re: Random people acessing
    By: Jeff Friend to Goose on Wed May 04 2016 16:30:22

    Hi Jeff,

    here i got a download link for you. http://filehippo.com/de/download_peerblock/

    Greetings
    Mike

    Thanks Mike, I eventually found it at download.com or what ever it is called.

    Jeff

    No problem :) Hope it works for you :)

    Mike

    ---
    þ Synchronet þ Roth BBS Net - rothbbs.ddns.net
  • From Jeff Friend@VERT/MORDOR to Mro on Thursday, May 05, 2016 16:42:13
    Re: Re: Random people acessing
    By: Mro to Jeff Friend on Wed May 04 2016 03:49 pm

    Is there a download link somewhere else?



    maybe you have to be logged in. i see what you mean.
    Interesting, I created an account, logged in, had the account approved and got the same results.

    Oh well, I have it now from elswhere, so all good.

    Jeff

    ---
    þ Synchronet þ Mordor - casper.homeip.net
  • From Mro@VERT/BBSESINF to Jeff Friend on Thursday, May 05, 2016 17:14:15
    Re: Re: Random people acessing
    By: Jeff Friend to Mro on Thu May 05 2016 04:42 pm

    Interesting, I created an account, logged in, had the account approved and got the same results.

    Oh well, I have it now from elswhere, so all good.


    that's too bad, that must be recent.
    be careful, some of those free download sites have a wrapper that is adware or whatnot.
    ---
    þ Synchronet þ ::: BBSES.info - free BBS services :::
  • From Jeff Friend@VERT/MORDOR to Mro on Friday, May 06, 2016 15:52:27
    Re: Re: Random people acessing
    By: Mro to Jeff Friend on Thu May 05 2016 05:14 pm

    that's too bad, that must be recent.
    be careful, some of those free download sites have a wrapper that is adware whatnot.
    Yes, they either put in some form of adware or they say "free download", but then to actually download, they demand you setup an account, which gives them your email address. But wiat, there's more, they then ask to verify you are a real person by giving them your credit card details.

    So, your "free download" becomes an account you do not need or want, AND your credit card on some possibly NOT SO SECURE server.

    BUT, there are always better sites to download from that do not require these requirements.

    Jeff

    ---
    þ Synchronet þ Mordor - casper.homeip.net
  • From Poindexter Fortran@VERT/REALITY to Patch on Saturday, May 07, 2016 07:06:21
    Re: Re: Random people acessing
    By: Patch to Nightfox on Sun May 01 2016 04:05 pm

    Curious on this though, is there any method either witnin SBBS or with another software package that can block an IP address from even getting through?

    I thought PeerBlock had a function like that, but didn't see it when I looked the last time.

    It does -- right click on an IP address in the list and you can select to temporarily block an IP or block it permanently.

    ---
    þ Synchronet þ realitycheckBBS -- http://realitycheckBBS.org
  • From Sampsa@VERT/B4BBS to Mro on Monday, May 09, 2016 04:23:00
    Mro wrote to Nightfox <=-

    add the IP address to your ip.can file. I've heard of some scripts for Synchronet that will automatically add an IP address to your ip.can if it detects repeated logins, etc., but I don't remember offhand which scripts will do that for you.



    and the jasman has a script that blocks 'em all

    Hey Mr jasman, any chance of a copy of said script? Is it Windows or Linux based (or Javascript for Synchro?)..?

    I've even got some spare Bitcoin I could contribute lol..

    Sampsa


    ... MultiMail, the new multi-platform, multi-format offline reader!
    --- MultiMail/Darwin v0.49
    þ Synchronet þ B4BBS = London, England - b4bbs.sampsa.com:2323 (telnet) or 2222 (ssh)
  • From Mro@VERT/BBSESINF to Sampsa on Sunday, May 08, 2016 23:17:54
    Re: Re: Random people acessing
    By: Sampsa to Mro on Mon May 09 2016 04:23 am


    Hey Mr jasman, any chance of a copy of said script? Is it Windows or Linux based (or Javascript for Synchro?)..?

    I've even got some spare Bitcoin I could contribute lol..


    it's really ugly and i made it myself in 2 mins.

    here's what it does:

    + checks the ip with whitelist.can passes user through if they are whitelisted

    + writes the ip to a blacklist.can right away
    + shows challenge code
    + asks them if they are sure twice.
    + hangs up if they fail.
    + if they PASS, the ip address is removed from blacklist.can and the ip
    is added to whitelist.can

    you can do this with about 6 lines of baja code or 400 in javascript probably :D
    ---
    þ Synchronet þ ::: BBSES.info - free BBS services :::
  • From Sampsa@VERT/B4BBS to Mro on Monday, May 09, 2016 17:40:00
    Mro wrote to Sampsa <=-

    it's really ugly and i made it myself in 2 mins.

    here's what it does:

    + checks the ip with whitelist.can passes user through if they are whitelisted

    + writes the ip to a blacklist.can right away
    + shows challenge code
    + asks them if they are sure twice.
    + hangs up if they fail.
    + if they PASS, the ip address is removed from blacklist.can and the ip
    is added to whitelist.can

    Ah ok, mind sharing the source? I'm sure I can wrap my head around Baja..

    sampsa


    ... MultiMail, the new multi-platform, multi-format offline reader!
    --- MultiMail/Darwin v0.49
    þ Synchronet þ B4BBS = London, England - b4bbs.sampsa.com:2323 (telnet) or 2222 (ssh)
  • From Mro@VERT/BBSESINF to Sampsa on Monday, May 09, 2016 17:18:00
    Re: Re: Random people acessing
    By: Sampsa to Mro on Mon May 09 2016 05:40 pm


    Ah ok, mind sharing the source? I'm sure I can wrap my head around Baja..

    sampsa


    it's really an ugly hack that i made temporarily until i made something in js, but i decided i wasnt in the mood to make releases for people so i didnt rewrite it.

    i'd rather not release my ugly hack because i've done it in the past and told people it was just an ugly hack that i made for myself...but i still had some haters make comments about my stuff.

    did i mention it's an ugly hack
    ---
    þ Synchronet þ ::: BBSES.info - free BBS services :::
  • From Daryl Stout@VERT/TBOLT to NIGHTFOX on Tuesday, May 17, 2016 12:55:00
    It's fairly common, yes. They are probably bots/scripts trying to do somethi N>malicious. I agree they are probably harmless since those commands won't wor N>on a BBS, but if you want to block one of them, you can add the IP address to N>your ip.can file. I've heard of some scripts for Synchronet that will N>automatically add an IP address to your ip.can if it detects repeated logins, N>etc., but I don't remember offhand which scripts will do that for you.

    One of the Synchronet Sysops, Mojo, also uses Peerblock on his system,
    and that helps weed out a lot of these "root logons". Once the weather
    calms down here (been a very stormy spring), I'll get a config file from
    him, and implement it over here.

    Daryl

    ---
    þ OLX 1.53 þ Do not use elevator in case of fire. Water works better.
    þ Synchronet þ The Thunderbolt BBS - Little Rock, AR - wx1der.dyndns.org
  • From Mro@VERT/BBSESINF to Daryl Stout on Wednesday, May 18, 2016 15:04:39
    Re: Random people acessing
    By: Daryl Stout to NIGHTFOX on Tue May 17 2016 12:55 pm

    and that helps weed out a lot of these "root logons". Once the weather
    calms down here (been a very stormy spring), I'll get a config file from him, and implement it over here.


    syntax is name:###.###.###-###.###.###.###
    ---
    þ Synchronet þ ::: BBSES.info - free BBS services :::
  • From tracker1@VERT/TRNTEST to Nightfox on Saturday, May 21, 2016 15:12:06
    Seems like that could add an unnecessary hassle, since most of these bots probably won't be able to do anything anyway (you probably don't have a user named 'root', and the commands they try to use won't do anything).
    Several years ago, I added a login matrix to my BBS, and I figure that should also keep most of the bots out since these bots don't know how to use a login matrix. I suppose that only works with telnet though; bots could still try to log in via SSH.

    The main point was to drop the connection in < 10 seconds, instead of the typical timeout... the bots sometimes have 3+ connections open.

    --
    Michael J. Ryan
    tracker1(at)gmail.com
    +o Roughneck BBS

    ---
    þ Synchronet þ RoughneckBBS - http://www.roughneckbbs.com/