A couple months ago, I was getting repeated guest logins every day using "shell" as their location. It was a known bot, but now I've been getting multiple repeated guest logins each day from the same location, but different locations each day or 2. Recently I noticed I was getting 5+ guest logins from Halifax, and yesterday and today I noticed my BBS has had at least 5 guest logins from Turkey, spread over at least 6 hours. I'm not sure if these are genuine users (or the same user) from the same country or if it's another bot. Has anyone else noticed this on their BBS?
A couple months ago, I was getting repeated guest logins every day using "shell" as their location. It was a known bot, but now I've been getting multiple repeated guest logins each day from the same location, but different locations each day or 2. Recently I noticed I was getting 5+ guest logins from Halifax, and yesterday and today I noticed my BBS has had at least 5 guest logins from Turkey, spread over at least 6 hours. I'm not sure if these are genuine users (or the same user) from the same country or if it's another bot. Has anyone else noticed this on their BBS?
A couple months ago, I was getting repeated guest logins every day using "shell" as their location. It was a known bot, but now I've been getting
it is the same set of bots and variants, man... they are not going to go away... i do really wish that ""you guys"" would put a fido mailer in frontt of your BBSes and let it answer the connections because then you would see exactly what is going on and it would buffer it a little from the BBS... then you would see that they are connecting and immediately sending a username and a password without waiting for any prompts... they are trying to load a command shell on what they think is a vulnerable IoT device... they are assuming that the shell is loading and then they are issuing commands... you guys are seeing these shell commands being stuffed
it is the same set of bots and variants, man... they are not going to
go away... i do really wish that ""you guys"" would put a fido mailer
in frontt of your BBSes and let it answer the connections because
then you would see exactly what is going on and it would buffer it a
little from the BBS... then you would see that they are connecting
and immediately sending a username and a password without waiting for
any prompts... they are trying to load a command shell on what they
think is a vulnerable IoT device... they are assuming that the shell
is loading and then they are issuing commands... you guys are seeing
these shell commands being stuffed
IMO, Synchronet already has fairly good protections against this
stuff, so I'm not sure a FIDO mailer is really necessary.
Any bot that is trying to send these usernames and passwords isn't
going to get in because most likely, the username & password
combination they're sending don't exist on the BBS. Synchronet will
just reject their login attempt. They won't be able to run a command shell that way. So I don't think they're really doing any harm.
while this is true, it is not the point of my post(s) on the subject... too many are apparently not understanding why they are seeing certain text in certain fields... by seeing what is actually going on and understanding how the BBS is processing what is being sent, one can easily understand why they might see "shell" in the location field... and then there's the thing about hoping they will go away... that ain't gonna happen... to be honest, i'm surprised it has taken them this long to start being a bother to us BBS operators... there are scans and probes going on all the time on all the common ports...
thing about hoping they will go away... that ain't gonna happen... to be honest, i'm surprised it has taken them this long to start being a bother to us BBS operators... there are scans and probes going on all the time on all the common ports...
A couple months ago, I was getting repeated guest logins every day
using "shell" as their location. It was a known bot, but now I've
been getting multiple repeated guest logins each day from the same
location, but different locations each day or 2. Recently I noticed
I was getting 5+ guest logins from Halifax, and yesterday and today
I noticed my BBS has had at least 5 guest logins from Turkey, spread
over at least 6 hours. I'm not sure if these are genuine users (or
the same user) from the same country or if it's another bot. Has
anyone else noticed this on their BBS?
Not yet for me, I'm getting the confirmed bot hits (even with a password on the guest account, just not as many). but I have'nt seen this yet.
Did they do anything or just hang araound?
Re: Repeated guest logins from the same place
By: mark lewis to Nightfox on Sun Sep 10 2017 09:03 am
thing about hoping they will go away... that ain't gonna happen... to be honest, i'm surprised it has taken them this long to start being a bother to us BBS operators... there are scans and probes going on all the time on all the common ports...
I've seen bots try to get onto my BBS for years, but only recently have I started noticing the bot using "shell" and the many repeated guest logins from the same location. So it's not that it's just now started being a bother, I just haven't seen those patterns until recently. And I actually don't feel like it's much of a bother, since I don't think they're actually doing any harm - I was mainly just curious. The biggest thing they're doing is just filling up my BBS log with their login attempts.
Re: Repeated guest logins from the same place
By: KK4QBN to Nightfox on Fri Sep 08 2017 05:48 pm
A couple months ago, I was getting repeated guest logins every day
using "shell" as their location. It was a known bot, but now I've
been getting multiple repeated guest logins each day from the same
location, but different locations each day or 2. Recently I noticed
I was getting 5+ guest logins from Halifax, and yesterday and today
I noticed my BBS has had at least 5 guest logins from Turkey, spread
over at least 6 hours. I'm not sure if these are genuine users (or
the same user) from the same country or if it's another bot. Has
anyone else noticed this on their BBS?
Not yet for me, I'm getting the confirmed bot hits (even with a password on the guest account, just not as many). but I have'nt seen this yet.
Did they do anything or just hang araound?
It seems one of them ran my ANSI viewer door and left, so it seems they're doing actual things. So they may be real users.
I just committed a change to exec/logon.js. With this change, add "sh" and "shell" to your text/email.can file and any "Guest" that enters either of those strings for their email address will be immediately disconnected. I did the same for the "location" (using text/location.can), but either seems like it would effective at killing these bot connections.
I've noticed on some CVS update like
1.5 >>>>>>>>>> logon.js date
or something to that extend with older code?
I just committed a change to exec/logon.js. With this change, add
"sh" and "shell" to your text/email.can file and any "Guest" that
enters either of those strings for their email address will be
immediately disconnected. I did the same for the "location" (using
text/location.can), but either seems like it would effective at
killing these bot connections.
Beautiful, now I don't have to do away with my Guest account... The
BOTS are stupid..
But I truly believe they are learning from the BBS systems, they are getting further into the menu system, and even wall apps then ever
before.
That looks like a merge conflict. A "cvs status <filename>" will confirm if that is the case or not. You must reserve conflicts manually (by editing the file) or if you don't care about your local changes, you can force an update to overwrite the local file (not merge).
| Sysop: | Winzlo |
|---|---|
| Location: | Minnesota, USA |
| Users: | 11 |
| Nodes: | 16 (0 / 16) |
| Uptime: | 495940:20:57 |
| Calls: | 82 |
| Files: | 1,070 |
| D/L today: |
27 files (11,920K bytes) |
| Messages: | 286,975 |