The actual server

Throw a log on the fire and watch the sparks fly............
Off-topic discussions.
HINT: Avoid religion, party politics (inflammatory comments) and dubious sexual innuendo.
Post Reply
User avatar
dasilvarsa
300 Posts
300 Posts
Posts: 349
Joined: 2012-07-30T06:18:49+02:00
13
Location: Light Side
Age: 67

Re: The actual server

#2606

Post by dasilvarsa »

I tried to upload a jpg and I think that it crashed the server.
Can U please Check Darryl.

This pic Joe?
You do not have the required permissions to view the files attached to this post.
Nuvi 3490LMT + Garmin Forerunner 35

“The main reason Santa is so jolly is because he knows where all the bad girls live.”
― George Carlin
User avatar
fugglefeet
500 Posts
500 Posts
Posts: 521
Joined: 2012-07-29T09:24:56+02:00
13
Location: Florida, Roodepoort
Been thanked: 4 times
Age: 56

The actual server's popularity

#2618

Post by fugglefeet »

Hi all,

The forum has come under close scrutiny again from the outside world by means of another method:-

http://www.shodanhq.com/

What this does is pretty self-explanatory, but here is a quick rundown. This is the hacker's Google to every conceivable device that is connected to the internet at any given time. Below is a screenshot of one of the servers that has tried to access the forum.
Shodan.png
And here is an example of the attack attempt being launched from a Shodan server on the forum:-
Shodan Block.png
And this is only one of many such attacks on an hourly basis.

Darryl
You do not have the required permissions to view the files attached to this post.
I was a parent with my first child. I'm now a referee now that I have two children.

Navigation devices: Gut feel and unreliable Nokia 1

Solaris newbie, FreeBSD junkie, Linux user, Windows 10 job and Windows 10 home hacker.
User avatar
fugglefeet
500 Posts
500 Posts
Posts: 521
Joined: 2012-07-29T09:24:56+02:00
13
Location: Florida, Roodepoort
Been thanked: 4 times
Age: 56

The firewall

#2653

Post by fugglefeet »

Hi all,

I have managed to compile a report of the attacks that the firewall has endured in the past 2 days from unscrupulous internet travelers to our forum. Attached is a pdf document listing each attack on the forum firewall (about 4 A4 pages long listing 114 events). The list shows the attacking IP address and the port it originated from, the destination IP address (in most cases the forum IP) and the ports that have come under attack, along with a description of the type of attack launched against the firewall.

Hope this information proves insightful.

Darryl
You do not have the required permissions to view the files attached to this post.
I was a parent with my first child. I'm now a referee now that I have two children.

Navigation devices: Gut feel and unreliable Nokia 1

Solaris newbie, FreeBSD junkie, Linux user, Windows 10 job and Windows 10 home hacker.
User avatar
Phillip Coetser
500 Posts
500 Posts
Posts: 578
Joined: 2012-08-01T07:48:25+02:00
13
Location: Edenvale Gauteng
Has thanked: 23 times
Been thanked: 19 times
Age: 77

Re: The actual server

#2654

Post by Phillip Coetser »

Hi Darryl, Phillip, hope you're well. Thanks for helping me getting back on the forum, had a rough time with my I.P. address being seen as a "hacker".
Personal Navigation Devices: - Garmin Drive Smart 65, Nüvi3597 LMT
Logic will take you from A to B...but.....
Imagination will take you everywhere
.
User avatar
fugglefeet
500 Posts
500 Posts
Posts: 521
Joined: 2012-07-29T09:24:56+02:00
13
Location: Florida, Roodepoort
Been thanked: 4 times
Age: 56

The forum's top three blacklisted

#2660

Post by fugglefeet »

Hi all,

Here is the forum's top three blacklisted IP addresses:-

218.77.79.34 (with 33 attempts)
218.77.79.34.pdf
93.174.93.51 (with 13 attempts)
93.174.93.51.pdf
71.6.167.142 (with 10 attempts)
71.6.167.142.pdf
Hope this is insightful

Darryl
You do not have the required permissions to view the files attached to this post.
I was a parent with my first child. I'm now a referee now that I have two children.

Navigation devices: Gut feel and unreliable Nokia 1

Solaris newbie, FreeBSD junkie, Linux user, Windows 10 job and Windows 10 home hacker.
User avatar
fugglefeet
500 Posts
500 Posts
Posts: 521
Joined: 2012-07-29T09:24:56+02:00
13
Location: Florida, Roodepoort
Been thanked: 4 times
Age: 56

Re: The actual server

#2680

Post by fugglefeet »

Hi all,

Here is a picture of the hosts blocked by Snort up until around 05:00 this morning:-
Snort Block List.png
Darryl
You do not have the required permissions to view the files attached to this post.
I was a parent with my first child. I'm now a referee now that I have two children.

Navigation devices: Gut feel and unreliable Nokia 1

Solaris newbie, FreeBSD junkie, Linux user, Windows 10 job and Windows 10 home hacker.
User avatar
admin
Site Admin
Site Admin
Posts: 31
Joined: 2012-07-29T08:54:11+02:00
13
Has thanked: 1 time

Re: The actual server

#2690

Post by admin »

The most persistent hacker that has been busy trying to hack the forum.
Hacker.png
User avatar
F.Viljoen
500 Posts
500 Posts
Posts: 541
Joined: 2012-07-29T10:44:25+02:00
13
Location: Welkom, South Africa.
Has thanked: 3 times
Been thanked: 7 times
Age: 67

Re: The actual server

#2691

Post by F.Viljoen »

Can't you report it at that ISP/Organization?
Frans
Personal Navigation Devices: - Nuvi's 200S, 2495LMT, 3490LT, 3790LT, Swambo.
Hell, there are no rules here - we're trying to accomplish something. Thomas A. Edison
User avatar
admin
Site Admin
Site Admin
Posts: 31
Joined: 2012-07-29T08:54:11+02:00
13
Has thanked: 1 time

Re: The actual server

#2692

Post by admin »

F.Viljoen wrote:Can't you report it at that ISP/Organization?
I'm collecting a log of events for a period of time, for evidence prior to my submitting it to the ISP for scrutiny.
User avatar
fugglefeet
500 Posts
500 Posts
Posts: 521
Joined: 2012-07-29T09:24:56+02:00
13
Location: Florida, Roodepoort
Been thanked: 4 times
Age: 56

Re: The actual server

#2693

Post by fugglefeet »

I have in the meantime, sent a 5 page log of just the attacks from this IP address alone, to the ISP concerned to see if I am to get a response.
document.pdf
If it's any consolation, the biggest origin of hack attacks originate from China. The ZB Block application that is used to protect the forum from spammers by default blocks complete IP address ranges originating from China. Something to consider when wanting to setup a server of any sorts that is connected to the internet.

P.S. Don't hold your breath waiting for the ISP to reply with intent to take action against the culprit

EDIT:- To date (6 May 2014) I have not received a reply to an email I had sent to the ISP, listing the numerous times that the customer using the IP address, had attacked the forum's firewall.
You do not have the required permissions to view the files attached to this post.
I was a parent with my first child. I'm now a referee now that I have two children.

Navigation devices: Gut feel and unreliable Nokia 1

Solaris newbie, FreeBSD junkie, Linux user, Windows 10 job and Windows 10 home hacker.
Post Reply

Return to “Around the campfire...”