Recently I've noticed a lot of Guest logins on my BBS
with the location specified as "shell" or "sh". They don't seem to be doing any harm, but I'm wondering if there might be any cause for concern? It seems they might be trying to run a command shell ('sh' etc.) to gain access, but that's just going into the location prompt during login, so I
Additionally, if anyone logs in as Guest and used 'sh' or 'shell', I wonder if I could have my logon script disable their system somehow
(to stop them from attacking other systems) or at least do something annoying, like outputting a bunch of random ASCII characters or something.. Good idea or bad idea?
Perhaps just adding their IP to ip.can would be far enough..
bad idea... you cannot easily feed stuff back through their code that's running
and hacking back on their system is most likely against the law in your area...
I've updated my logon script so that if anyone loggs in as Guest and using 'sh' or 'shell' as their real name/location, their IP > address will be added to ip.can.
I've updated my logon script so that if anyone loggs in as Guest and
using 'sh' or 'shell' as their real name/location, their IP > address
will be added to ip.can.
Can we get a copy of this script?
see it on A2K BBS. Example below:
----------------------------
Code: 12345
Enter the above code above to proceed:
--------------------------------
I always wanted to try to send an ansi bomb or something.. depending on what device it is.. like rokus can be remotely controlled via telnet anyway.. or at least send the ownwer of the IOT device a message telling them their device has been compromised..
you can stop most of them by putting a simple "Press ENTER" prmpt before yo ask for login info..
the bot will automaticially send UN/PW at the PRESS ENTER prompt.. so only password gets sent to username.. so even if they are using GUEST.. they still cannot get in.
They don't worry me a bit.. just a bit of a nuisance..
that gave me an idea that I just implemented on the outwest BBS,
When these annoying bots keep trying to log onto my system and get blocked now they get greeted with 1,000 lines of a random text bomb, I went to a site called random.org and had it create my 1,000 lines of random text, then I cut and pasted that into my badip.can file, I then put my ip in the ip.can file to test it, it's pretty funny to get bombed by all those lines of text and the system actually drops the connection before all the text is displayed.
I thought I saw some recent posts regarding this on Dove-Net, but now I don't see them.. Recently I've noticed a lot of Guest logins on my BBS with the location specified as "shell" or "sh". They don't seem to be doing any harm, but I'm wondering if there might be any cause for concern? It seems they might be trying to run a command shell ('sh' etc.) to gain access, but that's just going into the location prompt during login, so I don't think it's going to do anything harmful. I've never seen any bots doing this until recently though. My BBS has been getting a lot of these Guest/shell logins lately, from many different IP addresses.
Users specifically have to know they can log in as Guest, which makes
me wonder if people are starting to write attack scripts for
Synchronet BBSes?
it is the Mirai bot, it gains access using the guest username, and sh, shell, admin, and other "popular" usernames are also passed and just happen to fill the field of "what is your location" question on guest sighn in.
all of these attempts I've seen try to pass 4 or 5 usernames, then
just give up, I presume when whatever these bots are looking for is
not found.
Mirai does'nt know of BBS systems obviously, and hoepfully no one will decide that it should.
Mirai does'nt know of BBS systems obviously, and hoepfully no one
will decide that it should.
it won't do them any good if it did... there's too much variation between systems for them to be able to do anything worthwhile ;)
I thought I saw some recent posts regarding this on Dove-Net, but now I don't see them.. Recently I've noticed a lot of Guest logins on my BBS with the location specified as "shell" or "sh". They don't seem to be doing any harm, but I'm wondering if there might be any cause for concern? It seems they might be trying to run a command shell ('sh' etc.) to gain access, but that's just going into the location prompt during login, so I don't think it's going to do anything harmful. I've never seen any bots doing this until recently though. My BBS has been getting a lot of these Guest/shell logins lately, from many different IP addresses.
Users specifically have to know they can log in as Guest, which makes me wonder if people are starting to write attack scripts for Synchronet BBSes?
I'm also using a login matrix with a lightbar menu, so people would have to specifically choose the option from the menu to use a guest account..
Unless they don't have ANSI, in which my BBS should revert to a more plain text login.
it is the Mirai bot, it gains access using the guest username, and sh, shell, admin, and other "popular" usernames are also passed and just happen to fill the field of "what is your location" question on guest sighn in.
all of these attempts I've seen try to pass 4 or 5 usernames, then just give up, I presume when whatever these bots are looking for is not found.
Mirai does'nt know of BBS systems obviously, and hoepfully no one will decide that it should.
Doubt it. "Guest" is not that unusual of a user name. Perhaps it's just one of the guesses in their userid/password database.
It's likely that the scripts don't support ANSI. :-)
| Sysop: | Winzlo |
|---|---|
| Location: | Minnesota, USA |
| Users: | 11 |
| Nodes: | 16 (0 / 16) |
| Uptime: | 495939:01:17 |
| Calls: | 82 |
| Files: | 1,070 |
| D/L today: |
27 files (11,920K bytes) |
| Messages: | 286,964 |