Also, I'm not a programmer, but I was thinking the initial telnet connect L>challenge (captcha) code idea would be better because it would automatically L>stop "all" automated bots without using an ip.can. You can see it on A2K BBS L>Example below:
----------------------------
Code: 12345
Enter the above code above to proceed:
--------------------------------
Also, I'm not a programmer, but I was thinking the initial telnet
connect challenge (captcha) code idea would be better because it would
automatically stop "all" automated bots without using an ip.can. You
can see it on A2K BBS Example below:
----------------------------
Code: 12345
Enter the above code above to proceed:
--------------------------------
That's what Steve Winn, developer of Virtual Advanced (VADV32)
software, had set up.
Version 3.17 already will temporarily block an IP for a connect that
exceeds the number of MaxCurrentConnects (mine is set at 2). Accounts
like GUEST are EXEMPT from this
test it, it's pretty funny to get bombed by all those lines of text and the DG>system actually drops the connection before all the text is displayed.
That's what Steve Winn, developer of Virtual Advanced (VADV32)
software, had set up.
You know ROB.
This is where ZUUL. the gatekeeper and keymaster would come in handy. pass t K>encyrpted info here or atleast randomized passwords or something.
that would keep the bots from even being able to go into login/logon.js
Daryl Stout wrote to DENN GRAY <=-
@VIA: VERT/TBOLT
@MSGID: <596C1DC8.526.dove-syncops@wx1der.dyndns.org>
@REPLY: <596BD99F.517.dove-syncops@outwestbbs.com>
@TZ: c168
Denn,
test it, it's pretty funny to get bombed by all those lines of text and the
system actually drops the connection before all the text is displayed.
Talk about "disconnect user with line noise". <G>
Daryl
---
= OLX 1.53 = You'll have no other Sysop before me (just kidding).
= Synchronet = The Thunderbolt BBS - wx1der.dyndns.org
test it, it's pretty funny to get bombed by all those lines of text
and the system actually drops the connection before all the text is
displayed.
Talk about "disconnect user with line noise". <G>
This is where ZUUL. the gatekeeper and keymaster would come in handy.
pass t encyrpted info here or atleast randomized passwords or
something.
that would keep the bots from even being able to go into
login/logon.js
Well, it's copyrighted, and mainly for use by VADV32 Sysops
only...it's really no good to anyone else.
But, the concept of a random CAPTCHA code, then to block these idiots
for say, 24 hours, might give them the hint...although the bots would
just assume the BBS is offline, and keep trying.
I was'nt speaking of Captcha, Only Zuul!
Daryl Stout wrote to KK4QBN <=-
@VIA: VERT/TBOLT
@MSGID: <596D664D.545.dove-syncops@wx1der.dyndns.org>
@REPLY: <596D23D3.2471.dove-syncops@kk4qbn.synchro.net>
@TZ: c168
I was'nt speaking of Captcha, Only Zuul!
I know of Captcha and Zulu, but not Zuul.
Daryl
---
* OLX 1.53 * 12 Steps Chocolate Diet: 12 or less steps from chocolate.
* Synchronet * The Thunderbolt BBS - wx1der.dyndns.org
you never watched ghostbusters? Zuul is the demigod
I was'nt speaking of Captcha, Only Zuul!
I know of Captcha and Zulu, but not Zuul.
Re: Guests logging in from "s
By: Daryl Stout to KK4QBN on Mon Jul 17 2017 20:27:00
I was'nt speaking of Captcha, Only Zuul!
I know of Captcha and Zulu, but not Zuul.
Zuul is written into the synchronet code, I believe to see if a specific terminal software was dialing in, hence before the Synchronet ver 3.1X copright pops up, syncronet ask "Are you they keymaster", and the client would answer, "Are you the gatekeeper"
I cant remember exactly what it was for.. maybe Rob will chime in on it :)
I thought I saw some recent posts regarding this on Dove-Net, but now I don't N>see them.. Recently I've noticed a lot of Guest logins on my BBS with the N>location specified as "shell" or "sh". They don't seem to be doing any harm, N>but I'm wondering if there might be any cause for concern? It seems they mig N>be trying to run a command shell ('sh' etc.) to gain access, but that's just N>going into the location prompt during login, so I don't think it's going to d N>anything harmful. I've never seen any bots doing this until recently though. N>My BBS has been getting a lot of these Guest/shell logins lately, from many N>different IP addresses.
Users specifically have to know they can log in as Guest, which makes me wond N>if people are starting to write attack scripts for Synchronet BBSes? I'm als N>using a login matrix with a lightbar menu, so people would have to specifical N>choose the option from the menu to use a guest account.. Unless they don't N>have ANSI, in which my BBS should revert to a more plain text login.
I even got a message from the Guest account recently where someone asked me h N>to create a new user account. This makes me think there may be something mor N>than dumb scripts attacking BBSes now.
it is the Mirai bot, it gains access using the guest username, and sh, shell, K>admin, and other "popular" usernames are also passed and just happen to fill K>the field of "what is your location" question on guest sighn in.
all of these attempts I've seen try to pass 4 or 5 usernames, then just give K>up, I presume when whatever these bots are looking for is not found.
Mirai does'nt know of BBS systems obviously, and hoepfully no one will decide K>that it should.
Thats pretty much what I was thinking too.. I did notice that something (not K>using any Mirai signature) but acting just like it gained access with the gue K>account and posted something on my postit wall that is in my login sequence K>before it went away. strangest thing I have seen, let me try to find the K>message.
| Sysop: | Winzlo |
|---|---|
| Location: | Minnesota, USA |
| Users: | 11 |
| Nodes: | 16 (0 / 16) |
| Uptime: | 495939:07:25 |
| Calls: | 82 |
| Files: | 1,070 |
| D/L today: |
27 files (11,920K bytes) |
| Messages: | 286,966 |