• Telnet hack attempts

    From Tim Smith@1:103/705 to All on Tue Nov 15 08:58:38 2016
    Hello Syncops!


    Just wondering if many have the same problem I have, I started the BBS using only 4 nodes, because a few years back, most of the time that would be plenty. but now almost ALL DAY EVERY DAY i get BOMBARDED by hack attempts vial telnet specifically Mirai attemps:

    11/15 08:48:31a Node 2 Unknown User 'Root'
    11/15 08:48:32a Node 2 Unknown User 'Shell'
    11/15 08:48:32a Node 2 Unknown User 'Sh'
    11/15 08:48:33a Node 2 Unknown User '/bin/busybox Mirai'

    I can sit and put these ips in the ip filter all day long, it has slowed it a bit, but it stil is crazy. I've renewed my IP address a few times, and it happens worse on some IP's then others, but I would presume WINDSTREAM is just being bombarded by this virus. I read a little about it, don't know much on it, I know it gains access to vunerable systems then sits and waits for commands, I presume for dos attacks, etc.. but I know it's just killing me over here and really don't know a way to cutail it any more. there are nights that my maintenence will not run because the nodes are constantly busy, one after another.

    anyone??? Thanks!
    --

    Tim Smith (KK4QBN)

    ---
    * Synchronet * KK4QBN BBS - (706)422-9538 - kk4qbn.synchro.net, Chatsworth GA USA
    * Origin: Vertrauen - vert.synchro.net (1:103/705)
  • From Accession@1:103/705 to Tim Smith on Tue Nov 15 08:42:04 2016
    Hello Tim,

    On 15 Nov 16 08:58, Tim Smith wrote to All:

    Just wondering if many have the same problem I have, I started the BBS using only 4 nodes, because a few years back, most of the time that
    would be plenty. but now almost ALL DAY EVERY DAY i get BOMBARDED by
    hack attempts vial telnet specifically Mirai attemps:

    11/15 08:48:31a Node 2 Unknown User 'Root'
    11/15 08:48:32a Node 2 Unknown User 'Shell'
    11/15 08:48:32a Node 2 Unknown User 'Sh'
    11/15 08:48:33a Node 2 Unknown User '/bin/busybox Mirai'

    First, make sure these login attempts (ie: Root, Shell, Sh, /bin/busybox Mirai)

    are all in your name.can in your sbbs/text directory. Also, if they're all coming from the same hostname, you can use host.can for the hostname (ie: *.HINET-IP.hinet.net, or something similar).

    I can sit and put these ips in the ip filter all day long, it has
    slowed it a bit, but it stil is crazy. I've renewed my IP address a
    few times, and it happens worse on some IP's then others, but I would presume WINDSTREAM is just being bombarded by this virus. I read a
    little about it, don't know much on it, I know it gains access to vunerable systems then sits and waits for commands, I presume for dos attacks, etc.. but I know it's just killing me over here and really
    don't know a way to cutail it any more. there are nights that
    my maintenence will not run because the nodes are constantly busy, one after another.

    I have asked about this before. It would be nice to be able to automatically add IP address to ip.can if they try to connect more than say a few times in 20

    seconds or something. However this isn't currently possible that I know of.

    Regards,
    Nick

    ... "If at first you don't succeed, destroy all evidence that you tried."
    --- GoldED+/LNX 1.1.5-b20160827
    # Origin: thePharcyde_ distribution system (Wisconsin) (723:1/1)
    * Synchronet * thePharcyde_ telnet://bbs.pharcyde.org (Wisconsin)
    * Origin: Vertrauen - vert.synchro.net (1:103/705)
  • From poison@1:103/705 to Accession on Tue Nov 15 16:39:00 2016
    Accession wrote to Tim Smith <=-

    Hello Tim,

    On 15 Nov 16 08:58, Tim Smith wrote to All:

    Just wondering if many have the same problem I have, I started the BBS using only 4 nodes, because a few years back, most of the time that
    would be plenty. but now almost ALL DAY EVERY DAY i get BOMBARDED by
    hack attempts vial telnet specifically Mirai attemps:

    11/15 08:48:31a Node 2 Unknown User 'Root'
    11/15 08:48:32a Node 2 Unknown User 'Shell'
    11/15 08:48:32a Node 2 Unknown User 'Sh'
    11/15 08:48:33a Node 2 Unknown User '/bin/busybox Mirai'

    First, make sure these login attempts (ie: Root, Shell, Sh,
    /bin/busybox Mirai) are all in your name.can in your sbbs/text
    directory. Also, if they're all coming from the same hostname, you can
    use host.can for the hostname (ie: *.HINET-IP.hinet.net, or something similar).

    I can sit and put these ips in the ip filter all day long, it has
    slowed it a bit, but it stil is crazy. I've renewed my IP address a
    few times, and it happens worse on some IP's then others, but I would presume WINDSTREAM is just being bombarded by this virus. I read a
    little about it, don't know much on it, I know it gains access to vunerable systems then sits and waits for commands, I presume for dos attacks, etc.. but I know it's just killing me over here and really
    don't know a way to cutail it any more. there are nights that
    my maintenence will not run because the nodes are constantly busy, one after another.

    I have asked about this before. It would be nice to be able to automatically add IP address to ip.can if they try to connect more than say a few times in 20 seconds or something. However this isn't
    currently possible that I know of.

    Regards,
    Nick

    ... "If at first you don't succeed, destroy all evidence that you
    tried." --- GoldED+/LNX 1.1.5-b20160827
    * Origin: thePharcyde_ distribution system (Wisconsin) (723:1/1)
    .[0m * .[32mSynchronet.[0m * thePharcyde_ telnet://bbs.pharcyde.org (Wisconsin)

    How about just change the default telnet port from 23 to something obscure and let your users know and maybe post that on your homepage?
    ... MultiMail, the new multi-platform, multi-format offline reader!
    --- MultiMail/Win32 v0.49
    * Synchronet * [bbs.memphistw.org] - [www.memphistw.org]
    * Origin: Vertrauen - vert.synchro.net (1:103/705)
  • From mark lewis@1:3634/12.73 to Tim Smith on Tue Nov 15 22:06:40 2016

    15 Nov 16 08:58, you wrote to All:

    Just wondering if many have the same problem I have, I started the BBS using only 4 nodes, because a few years back, most of the time that
    would be plenty. but now almost ALL DAY EVERY DAY i get BOMBARDED by
    hack attempts vial telnet specifically Mirai attemps:

    FWIW: they are not "hack attempts"... at least not against your board... they are simply dumb bots targetting DVRs, IP cams, and other devices with known default user names and passwords...

    11/15 08:48:31a Node 2 Unknown User 'Root'
    11/15 08:48:32a Node 2 Unknown User 'Shell'
    11/15 08:48:32a Node 2 Unknown User 'Sh'
    11/15 08:48:33a Node 2 Unknown User '/bin/busybox Mirai'

    I can sit and put these ips in the ip filter all day long,

    why? just add those known names to your .can file so they can't get any further...

    it has slowed it a bit, but it stil is crazy. I've renewed my IP
    address a few times, and it happens worse on some IP's then others,
    but I would presume WINDSTREAM is just being bombarded by this virus.

    1. it is not a virus... it is a botnet attempting to spread and gain more bot nodes...

    2. i'm on windstream and they are not alone in this problem...

    I read a little about it, don't know much on it, I know it gains
    access to vunerable systems then sits and waits for commands, I
    presume for dos attacks, etc.. but I know it's just killing me over
    here and really don't know a way to cutail it any more. there are
    nights that my maintenence will not run because the nodes are
    constantly busy, one after another.

    personally speaking, look below at my signature... if what my sig points out is
    not what you want to do, then simply move your telnet port from 23 and/or 2323 to another one and let your users know what the new port is that they should be
    using... this stuff will not end until IOT manufacturers finally understand and
    take to heart that security is not a given and not a bolt-on afterthought...

    FWIW: i do use an IDS/IPS and i specifically have not moved off of 23 or 2323... why? so i can contribute to the list(s) of known IOT devices that are infested... at this point in time, my IDS/IPS is tracking 7000+ infested IOT IPs over the last 30 days...

    FWIW2: there are some systems out there that are fighting back and infesting IOT devices with a MIRAI variant that disables the ability for MIRAI and its variants to get into the vulnerable systems... some would say that this is just
    as illegal as MIRAI operators are doing... this isn't the first time it has been done, though... the nimda worm was also fought in this manner... those systems that are fightling back? yes, they will also appear as MIRAI and variants because that's how they have to get in to be able to stop the others from getting in...

    FWIW3: my IDS/IPS is tracking at least seven MIRAI variants in addition to the original MIRAI bot...

    )\/(ark

    Always Mount a Scratch Monkey
    Do you manage your own servers? If you are not running an IDS/IPS yer doin' it wrong...
    ... It's not an optical illusion. It just looks like one.
    ---
    * Origin: (1:3634/12.73)
  • From mark lewis@1:3634/12.73 to Accession on Tue Nov 15 21:54:24 2016

    15 Nov 16 08:42, you wrote to Tim Smith:

    First, make sure these login attempts (ie: Root, Shell, Sh, /bin/busybox Mirai) are all in your name.can in your sbbs/text directory.

    to be more clear, only the initial user names need to be added... the rest of the stuff after the user name and password are commands... if you block the user names and passwords you don't need to bother with the following commands...

    add the following to the end of your text/name.can

    ===== snip =====
    ;
    ; these are added from MIRAI and variants infestor
    ;
    service
    supervisor
    admin1
    666666
    888888
    ubnt
    tech
    mother
    ===== snip =====



    )\/(ark

    Always Mount a Scratch Monkey
    Do you manage your own servers? If you are not running an IDS/IPS yer doin' it wrong...
    ... Don't go messin' with a country boy! - Hillbilly Jim
    ---
    * Origin: (1:3634/12.73)
  • From Nicholas Boel@1:154/10 to mark lewis on Tue Nov 15 22:41:32 2016
    Hello mark,

    On 15 Nov 16 21:54, mark lewis wrote to Accession:

    First, make sure these login attempts (ie: Root, Shell, Sh,
    /bin/busybox Mirai) are all in your name.can in your sbbs/text
    directory.

    to be more clear, only the initial user names need to be added... the
    rest of the stuff after the user name and password are commands... if
    you block the user names and passwords you don't need to bother with
    the following commands...

    Be more clear on what? I believe he said that those were actual usernames being
    attempted on his system. Was it not?

    Regards,
    Nick

    ... "?? ????. ? ????? ?????? ???????."
    --- GoldED+/LNX 1.1.5-b20160827
    * Origin: thePharcyde_ distribution system (Wisconsin) (1:154/10)
  • From mark lewis@1:3634/12.73 to Nicholas Boel on Wed Nov 16 06:05:46 2016

    15 Nov 16 22:41, you wrote to me:

    First, make sure these login attempts (ie: Root, Shell, Sh,
    /bin/busybox Mirai) are all in your name.can in your sbbs/text
    directory.

    to be more clear, only the initial user names need to be added... the
    rest of the stuff after the user name and password are commands... if
    you block the user names and passwords you don't need to bother with
    the following commands...

    Be more clear on what? I believe he said that those were actual
    usernames being attempted on his system. Was it not?

    yes but the statement was incorrect... those other commands look like usernames
    because the bot is shoving them out without any care at all to any prompts... in fact, it doesn't even look for any prompts before spewing its login attempts... should it be mentioned that they are also terminated by a null character?

    but thinking about it, maybe you are right and those should be added but i don't know how to add the null character or if it is required or may lead to a problem in sync...

    FWIW: below is how frontdoor sees these connections... tcpdump packet captures confirm same, too... the log is slightly modified (to ascii and spacing) but it
    is a live log from my frontdoor system... this one is an attempt to log in as user "service" with password "service"... you can see that both of those strings are terminated with CRLF... but the others? i've hilighted the null character lines to make them easier to see... they do actually send

    username 0x0d 0x0a
    password 0x0d 0x0a
    enable 0x00 0x0d 0x0a
    system 0x00 0x0d 0x0a
    shell 0x00 0x0d 0x0a

    without the spaces i put in for readability...

    ===== FDN11.LOG =====

    ---------- Wed 16 Nov 16, FD 2.33.mL.b2; Task=11
    + 0:39:42 Event 2-J >>> (NoUsers:23h15m, NoReq:>=OneWk)
    0:39:42 Processing NetMail folder
    0:39:44 No messages to send in this event
    + 0:39:45 Event 0-@ >>> (NoUsers:23h15m, NoReq:>=OneWk)
    0:39:45 Processing NetMail folder
    0:39:45 No messages to send in this event
    0:39:45 Rescan requested
    + 0:39:45 Event 2-J >>> (NoUsers:23h15m, NoReq:>=OneWk)
    0:39:45 Processing NetMail folder
    0:39:46 No messages to send in this event
    + 0:39:46 Event 0-@ >>> (NoUsers:23h15m, NoReq:>=OneWk)
    0:39:46 Processing NetMail folder
    0:39:46 No messages to send in this event
    0:39:46 [ModemDebug] Sending <CR><CR>
    0:39:46 [ModemDebug] Sending Init-1
    0:39:46 [ModemDebug] Done (OK)
    = 0:40:16 RING
    = 0:40:21 RING
    0:40:21 [ModemDebug] Sending first answer string
    = 0:40:21 CONNECT 57600/ARQ/TEL FROM 14.164.170.44
    0:40:22 Intro: 0073 (s)
    0:40:22 Intro: 0065 (e)
    0:40:22 Intro: 0072 (r)
    0:40:22 Intro: 0076 (v)
    0:40:22 Intro: 0069 (i)
    0:40:22 Intro: 0063 (c)
    0:40:22 Intro: 0065 (e)
    0:40:22 Intro: 000D
    0:40:22 Intro: 000A
    0:40:23 Intro: 0073 (s)
    0:40:23 Intro: 0065 (e)
    0:40:23 Intro: 0072 (r)
    0:40:23 Intro: 0076 (v)
    0:40:23 Intro: 0069 (i)
    0:40:23 Intro: 0063 (c)
    0:40:23 Intro: 0065 (e)
    0:40:23 Intro: 000D
    0:40:23 Intro: 000A
    0:40:24 Intro: 0065 (e)
    0:40:24 Intro: 006E (n)
    0:40:24 Intro: 0061 (a)
    0:40:24 Intro: 0062 (b)
    0:40:24 Intro: 006C (l)
    0:40:24 Intro: 0065 (e)
    0:40:24 Intro: 0000
    0:40:24 Intro: 000D
    0:40:24 Intro: 000A
    0:40:24 Intro: 0073 (s)
    0:40:24 Intro: 0079 (y)
    0:40:24 Intro: 0073 (s)
    0:40:24 Intro: 0074 (t)
    0:40:24 Intro: 0065 (e)
    0:40:24 Intro: 006D (m)
    0:40:24 Intro: 0000
    0:40:25 Intro: 000D
    0:40:25 Intro: 000A
    0:40:25 Intro: 0073 (s)
    0:40:25 Intro: 0068 (h)
    0:40:25 Intro: 0065 (e)
    0:40:25 Intro: 006C (l)
    0:40:25 Intro: 006C (l)
    0:40:25 Intro: 0000
    0:40:26 Intro: 000D
    0:40:26 Intro: 000A
    0:40:26 Intro: 0073 (s)
    0:40:26 Intro: 0068 (h)
    0:40:26 Intro: 0000
    0:40:27 Intro: 000D
    0:40:27 Intro: 000A
    0:40:27 Intro: 002F (/)
    0:40:27 Intro: 0062 (b)
    0:40:27 Intro: 0069 (i)
    0:40:27 Intro: 006E (n)
    0:40:27 Intro: 002F (/)
    0:40:27 Intro: 0062 (b)
    0:40:27 Intro: 0075 (u)
    0:40:27 Intro: 0073 (s)
    0:40:27 Intro: 0079 (y)
    0:40:27 Intro: 0062 (b)
    0:40:27 Intro: 006F (o)
    0:40:27 Intro: 0078 (x)
    0:40:27 Intro: 0020 ( )
    0:40:27 Intro: 004D (M)
    0:40:27 Intro: 0045 (E)
    0:40:27 Intro: 004D (M)
    0:40:27 Intro: 0045 (E)
    0:40:27 Intro: 0053 (S)
    0:40:27 Intro: 0000
    0:40:27 Intro: 000D
    0:40:27 Intro: 000A

    ===== FDN11.LOG =====

    at this point, FD caught a carrier loss signal from the virtual modem because the IDS/IPS kicked in and issued a (30+day) ip block for 14.164.170.44 on the WAN port... at the same time, the IDS/IPS also issued a ICMP RESET to the virtual modem telling it the connection has been terminated... from now on, until the block period expires, any attempts to connect /from/ 14.164.170.44 are simply DROPped at the firewall... additionally attempts to connect out /to/
    14.164.170.44 are met with ICMP ADMIN PROHIBITED response from the firewall... no traceroute, no ping, no nothing can get out to that ip address...

    you'll also notice that this one sent "MEMES"... it is or looks like a MIRAI variant... there's a new "THTC" that showed up a few days ago to join the others being tracked...

    MIRAI, MEMES, ECCHI, IHCCE, VDOSS, FREEPEIN, THTC are the commands we're seeing
    added to the busybox line...

    )\/(ark

    Always Mount a Scratch Monkey
    Do you manage your own servers? If you are not running an IDS/IPS yer doin' it wrong...
    ... What is the IRS deduction for co-dependants?
    ---
    * Origin: (1:3634/12.73)
  • From Accession@1:103/705 to poison on Tue Nov 15 22:00:54 2016
    Hello poison,

    On 15 Nov 16 16:39, poison wrote to Accession:

    I have asked about this before. It would be nice to be able to
    automatically add IP address to ip.can if they try to connect
    more than say a few times in 20 seconds or something. However
    this isn't currently possible that I know of.

    Regards,
    Nick

    How about just change the default telnet port from 23 to something
    obscure and let your users know and maybe post that on your homepage?

    Maybe because I like to connect to an address without having to specify a port?

    I dunno. Why move it to a non-default port when you don't have to? You can also

    setup iptables/ip6tables at the router and not even let them have access to your telnet server on the standard port after X amount of tries.

    There's lots of ways to skin a cat.

    Regards,
    Nick

    ... "-Y-| -+-+-#-A. -> -+-|-|-U-i -e-+-+-i-|-+ -C-#-#-+-e-#-A."
    --- GoldED+/LNX 1.1.5-b20160827
    # Origin: thePharcyde_ distribution system (Wisconsin) (723:1/1)
    * Synchronet * thePharcyde_ telnet://bbs.pharcyde.org (Wisconsin)
    * Origin: Vertrauen - vert.synchro.net (1:103/705)
  • From Tim Smith@1:103/705 to poison on Wed Nov 16 03:45:56 2016
    Re: Re: Telnet hack attempts
    By: poison to Accession on Tue Nov 15 2016 04:39 pm

    How about just change the default telnet port from 23 to something obscure and let your users know and maybe post that on your homepage?


    I would rather stick to as much (standards) as I could.. I havent been back into bbsing long enough to see "all" of synchronets new feature, but if there would be one that would add ANY ip that tried to log in as /bin/ANYTHING straight to the ip.can.. I might actually be able to rig something to do this myself.. dunno.. wont hurt to try..
    --

    Tim Smith (KK4QBN)

    ---
    * Synchronet * KK4QBN BBS - (706)422-9538 - kk4qbn.synchro.net, Chatsworth GA USA
    * Origin: Vertrauen - vert.synchro.net (1:103/705)
  • From Tim Smith@1:103/705 to Accession on Wed Nov 16 03:49:16 2016
    Re: Re: Telnet hack attempts
    By: Accession to poison on Tue Nov 15 2016 10:00 pm

    Maybe because I like to connect to an address without having to specify a port? I dunno. Why move it to a non-default port when you don't have to? You can also setup iptables/ip6tables at the router and not even let them have access to your telnet server on the standard port after X amount of tries.

    There's lots of ways to skin a cat.

    See this is the stuff I'm looking for, hopefully my router has this ability, thanks for the info.
    --

    Tim Smith (KK4QBN)

    ---
    * Synchronet * KK4QBN BBS - (706)422-9538 - kk4qbn.synchro.net, Chatsworth GA USA
    * Origin: Vertrauen - vert.synchro.net (1:103/705)
  • From poison@1:103/705 to Accession on Wed Nov 16 08:00:12 2016
    Re: Re: Telnet hack attempts
    By: Accession to poison on Tue Nov 15 2016 10:00 pm

    Hello poison,

    On 15 Nov 16 16:39, poison wrote to Accession:

    I have asked about this before. It would be nice to be able to
    automatically add IP address to ip.can if they try to connect
    more than say a few times in 20 seconds or something. However
    this isn't currently possible that I know of.

    Regards,
    Nick

    How about just change the default telnet port from 23 to something obscure and let your users know and maybe post that on your homepage?

    Maybe because I like to connect to an address without having to specify a po I dunno. Why move it to a non-default port when you don't have to? You can a setup iptables/ip6tables at the router and not even let them have access to your telnet server on the standard port after X amount of tries.

    There's lots of ways to skin a cat.

    Regards,
    Nick

    ... "-Y-| -+-+-#-A. -> -+-|-|-U-i -e-+-+-i-|-+ -C-#-#-+-e-#-A."
    Yes there are many solutions.
    /a


    * Patrick Siglin - www.memphistw.org *
    ---
    * Synchronet * [bbs.memphistw.org] - [www.memphistw.org]
    * Origin: Vertrauen - vert.synchro.net (1:103/705)
  • From Tim Smith@1:103/705 to mark lewis on Fri Nov 18 10:33:48 2016
    Re: Telnet hack attempts
    By: mark lewis to Tim Smith on Tue Nov 15 2016 10:06 pm

    1. it is not a virus... it is a botnet attempting to spread and gain more bot nodes...

    Thanks for the verification, I know its just nasty, worse than I have ever seen before.

    personally speaking, look below at my signature... if what my sig points out is not what you want to do, then simply move your telnet port from 23 and/or 2323 to another one and let your users know what the new port is that they should be using... this stuff will not end until IOT manufacturers finally understand and take to heart that security is not a given and not a bolt-on afterthought...

    Yeah, Guess it is something I just will need to deal with, it's at a managable level "right now", But yeah you are correct, all these smart devices are pretty much just fuel to the fire.
    FWIW: i do use an IDS/IPS and i specifically have not moved off of 23 or 2323... why? so i can contribute to the list(s) of known IOT devices that are infested... at this point in time, my IDS/IPS is tracking 7000+ infested IOT IPs over the last 30 days...

    And that is just crazy, I'll more than likely get one of these lists and work into mine, until I get more of a feel of whats going on.
    FWIW3: my IDS/IPS is tracking at least seven MIRAI variants in addition to the original MIRAI bot...

    JUst crazy, I thought I could see variations in them here, thanks for all the insight, I might sit the storm out a little longer, if I cannot get a hold on it might just move ports.. i've never seen such a mess.
    --

    Tim Smith (KK4QBN)

    ---
    * Synchronet * KK4QBN BBS - (706)422-9538 - kk4qbn.synchro.net, Chatsworth GA
    * Origin: Vertrauen - vert.synchro.net (1:103/705)
  • From Tim Smith@1:103/705 to mark lewis on Fri Nov 18 10:42:42 2016
    Re: Telnet hack attempts
    By: mark lewis to Accession on Tue Nov 15 2016 09:54 pm

    service
    supervisor
    admin1
    666666
    888888
    ubnt
    tech
    mother
    ===== snip =====

    add:

    oot
    upport
    upervisor

    for what reason, I dont know, but several systems have tried using these names logging in, dunno if the first letter is just being chopped, or whats happening but its more then 5 different ip addresses that have tried this way.
    --

    Tim Smith (KK4QBN)

    ---
    * Synchronet * KK4QBN BBS - (706)422-9538 - kk4qbn.synchro.net, Chatsworth GA
    * Origin: Vertrauen - vert.synchro.net (1:103/705)
  • From mark lewis@1:3634/12.73 to Tim Smith on Fri Nov 18 22:13:46 2016

    18 Nov 16 10:33, you wrote to me:

    FWIW3: my IDS/IPS is tracking at least seven MIRAI variants in
    addition to the original MIRAI bot...

    JUst crazy, I thought I could see variations in them here, thanks for
    all the insight, I might sit the storm out a little longer, if I
    cannot get a hold on it might just move ports.. i've never seen such a mess. --

    you and others would be best off to just switch ports from 23 and/or 2323 to something else... it won't get better until commercial entities stop bolting security on as an afterthought... it is, in fact, going to get worse... since my last post, i've added another three variants but they may not be related at all since they're basically using the same or an enhanced list of default user names and passwords for IoT devices...

    we won't even talk about the stuff going on on the bluetooth or zephyer networks...

    )\/(ark

    Always Mount a Scratch Monkey
    Do you manage your own servers? If you are not running an IDS/IPS yer doin' it wrong...
    ... The devil can quote statistics to prove his purpose. Sam'l Clemens
    ---
    * Origin: (1:3634/12.73)
  • From mark lewis@1:3634/12.73 to Tim Smith on Fri Nov 18 22:17:32 2016

    18 Nov 16 10:42, you wrote to me:

    service
    supervisor
    admin1
    666666
    888888
    ubnt
    tech
    mother
    ===== snip =====

    add:

    oot
    upport
    upervisor

    ewww...

    for what reason, I dont know, but several systems have tried using
    these names logging in, dunno if the first letter is just being
    chopped, or whats happening but its more then 5 different ip addresses that have tried this way.

    yeah, the first letter is being dropped for some reason... can you provide those IP addresses exhibiting this, please? i know a few folks that would love to take a crack at them and see if they can grab those binaries for analysis to
    see if they can determine if it is a new player or just a skiddie trying their hand at swimming with the big boys...

    )\/(ark

    Always Mount a Scratch Monkey
    Do you manage your own servers? If you are not running an IDS/IPS yer doin' it wrong...
    ... REAL Sysops disconnect the Speaker!
    ---
    * Origin: (1:3634/12.73)
  • From Tim Smith@1:103/705 to mark lewis on Sat Nov 19 07:18:28 2016
    Re: Telnet hack attempts
    By: mark lewis to Tim Smith on Fri Nov 18 2016 10:13 pm

    you and others would be best off to just switch ports from 23 and/or 2323 to something else... it won't get better until commercial entities stop bolting security on as an afterthought... it is, in fact, going to get worse... since my last post, i've added another three variants but they may not be related at all since they're basically using the same or an enhanced list of default user names and passwords for IoT devices...

    we won't even talk about the stuff going on on the bluetooth or zephyer networks...

    Yup, I'm starting to believe that more and more every hour.. this thing is evolving, or something.. but growing exponitially.. Thanks for all the crappy backdoors china..
    --

    Tim Smith (KK4QBN)

    ---
    * Synchronet * KK4QBN BBS - (706)422-9538 - kk4qbn.synchro.net, Chatsworth GA
    * Origin: Vertrauen - vert.synchro.net (1:103/705)
  • From Tim Smith@1:103/705 to mark lewis on Sat Nov 19 07:37:50 2016
    Re: Telnet hack attempts
    By: mark lewis to Tim Smith on Fri Nov 18 2016 10:17 pm

    yeah, the first letter is being dropped for some reason... can you provide those IP addresses exhibiting this, please? i know a few folks that would love to take a crack at them and see if they can grab those binaries for analysis to
    see if they can determine if it is a new player or just a skiddie trying their hand at swimming with the big boys...

    yup, hold up a sec... I've deleted some logfiles, but I'm sure I can still provide a few...

    14.136.5.149 Freepein
    96.230.36.92 Mirai

    Pattern <FIOS> Verizon (multiple ips)

    36.68.36.249 Memes
    123.141.45.9 Mirai
    152.204.30.4 Memes
    59.94.221.21 Mirai
    96.91.59.179 Mirai
    183.46.214.149 ""
    61.5.113.181 ""
    93.57.108.26 ""
    78.90.63.216 Memes
    175.156.228.106 ""
    190.59.21.76 Mirai

    ----> Will Continue in another message, need to switch terminals.
    --

    Tim Smith (KK4QBN)

    ---
    * Synchronet * KK4QBN BBS - (706)422-9538 - kk4qbn.synchro.net, Chatsworth GA
    * Origin: Vertrauen - vert.synchro.net (1:103/705)
  • From Tim Smith@1:103/705 to mark lewis on Sat Nov 19 08:13:34 2016
    Re: Telnet hack attempts
    By: Tim Smith to mark lewis on Sat Nov 19 2016 07:37 am

    Heres your continued LIst.. I'm trying to get Synchronet to add these automajically via the LoginAttemptHackThreshold, etc set the number to 2 and STILL it is not adding the IP or hotname to their respective files, is this not what this is here for?


    14.136.5.149 Freepein
    96.230.36.92 Mirai

    Pattern <FIOS> Verizon (multiple ips)

    36.68.36.249 Memes
    123.141.45.9 Mirai
    152.204.30.4 Memes
    59.94.221.21 Mirai
    96.91.59.179 Mirai
    183.46.214.149 ""
    61.5.113.181 ""
    93.57.108.26 ""
    78.90.63.216 Memes
    175.156.228.106 ""
    190.59.21.76 Mirai

    ----> Will Continue in another message, need to switch terminals.

    Continued ----

    @+ Telnet <no name> [182.186.185.102]
    +! Unknown User 'Oot'
    +! Unknown User 'System'
    +! Unknown User 'Shell'
    +! Unknown User 'Sh'
    +! Unknown User '/bin/busybox Mirai'
    @- 01:32a T: 9 sec

    @ 02:21a Sat Nov 19 2016 Node 2
    @+ Telnet <no name> [95.106.78.40]
    +! Unknown User 'Oot'
    +! Unknown User 'System'
    +! Unknown User 'Shell'
    +! Unknown User 'Sh'
    +! Unknown User '/bin/busybox Memes'
    @- 02:21a T: 8 sec

    @ 02:47a Sat Nov 19 2016 Node 1
    @+ Telnet 112.64.79.82.static.cluj.rdsnet.ro [82.79.64.112]
    +! Unknown User 'Dmin'
    +! Unknown User 'System'
    +! Unknown User 'Shell'
    +! Unknown User 'Sh'
    +! Unknown User '/bin/busybox Memes'
    @- 02:47a T: 8 sec

    @ 03:11a Sat Nov 19 2016 Node 2
    @+ Telnet <no name> [82.200.170.246]
    +! Unknown User 'Uest'
    +! Unknown User 'System'
    +! Unknown User 'Shell'
    +! Unknown User 'Sh'
    +! Unknown User '/bin/busybox Mirai'
    @- 03:11a T: 8 sec

    @ 03:13a Sat Nov 19 2016 Node 2
    @+ Telnet <no name> [118.42.19.50]
    +! Unknown User 'Ervice'
    +! Unknown User 'System'
    +! Unknown User 'Shell'
    +! Unknown User 'Sh'
    +! Unknown User '/bin/busybox Thtc'
    @- 03:13a T: 9 sec

    @ 03:17a Sat Nov 19 2016 Node 3
    @+ Telnet <no name> [37.232.95.22]
    +! Unknown User 'Oot'
    +! Unknown User 'System'
    +! Unknown User 'Shell'
    +! Unknown User 'Sh'
    +! Unknown User '/bin/busybox Mirai'
    @- 03:17a T: 8 sec

    @ 03:55a Sat Nov 19 2016 Node 2
    @+ Telnet res70-57.mediana.net.ua [46.175.70.57]
    +! Unknown User 'Oot'
    +! Unknown User 'System'
    +! Unknown User 'Shell'
    +! Unknown User 'Sh'
    +! Unknown User '/bin/busybox Mirai'
    @- 03:55a T: 8 sec

    @ 04:23a Sat Nov 19 2016 Node 2
    @+ Telnet <no name> [43.239.59.95]
    +! Unknown User 'Oot'
    +! Unknown User 'System'
    +! Unknown User 'Shell'
    +! Unknown User 'Sh'
    +! Unknown User '/bin/busybox Uchilaisasni'
    @- 04:23a T: 12 sec

    @ 04:26a Sat Nov 19 2016 Node 3
    @+ Telnet cable190-249-188-230.epm.net.co [190.249.188.230]
    +! Unknown User 'Oot'
    +! Unknown User 'System'
    +! Unknown User 'Shell'
    +! Unknown User 'Sh'
    +! Unknown User '/bin/busybox Freepein'
    @- 04:26a T: 8 sec

    @ 04:26a Sat Nov 19 2016 Node 2
    @+ Telnet LMontsouris-657-1-166-205.w82-127.abo.wanadoo.fr [82.127.204.205]
    +! Unknown User 'Oot'
    +! Unknown User 'Xc3511'
    @- 04:27a T: 33

    @ 05:01a Sat Nov 19 2016 Node 2
    @+ Telnet <no name> [211.230.192.232]
    +! Unknown User 'Ealtek'
    +! Unknown User 'System'
    +! Unknown User 'Shell'
    +! Unknown User 'Sh'
    +! Unknown User '/bin/busybox Thtc'
    @- 05:01a T: 8 sec

    @ 05:07a Sat Nov 19 2016 Node 2
    @+ Telnet <no name> [109.100.117.113]
    +! Unknown User 'Ech'
    +! Unknown User 'System'
    +! Unknown User 'Shell'
    +! Unknown User 'Sh'
    +! Unknown User '/bin/busybox Mirai'
    @- 05:07a T: 8 sec

    @ 05:32a Sat Nov 19 2016 Node 3
    @+ Telnet <no name> [89.160.124.240]
    +! Unknown User 'Dmin'
    +! Unknown User 'System'
    +! Unknown User 'Shell'
    +! Unknown User 'Sh'
    +! Unknown User '/bin/busybox Mirai'
    @- 05:32a T: 7 sec

    @ 05:37a Sat Nov 19 2016 Node 3
    @+ Telnet 563BCF35.dsl.pool.telekom.hu [86.59.207.53]
    +! Unknown User 'Oot'
    +! Unknown User 'System'
    +! Unknown User 'Shell'
    +! Unknown User 'Sh'
    +! Unknown User '/bin/busybox Mirai'
    @- 05:37a T: 8 sec

    @ 05:39a Sat Nov 19 2016 Node 3
    @+ Telnet ppp-58-11-94-208.revip2.asianet.co.th [58.11.94.208]
    +! Unknown User 'Oot'
    +! Unknown User 'System'
    +! Unknown User 'Shell'
    +! Unknown User 'Sh'
    +! Unknown User '/bin/busybox Mirai'
    @- 05:39a T: 8 sec

    @ 05:59a Sat Nov 19 2016 Node 3
    @+ Telnet bd21221d.virtua.com.br [189.33.34.29]
    +! Unknown User 'Ser'
    +! Unknown User 'System'
    +! Unknown User 'Shell'
    +! Unknown User 'Sh'
    +! Unknown User '/bin/busybox Memes'
    @- 05:59a T: 7 sec

    @ 06:27a Sat Nov 19 2016 Node 4
    @+ Telnet b3dbaec6.virtua.com.br [179.219.174.198]
    +! Unknown User 'Dmin'
    +! Unknown User 'System'
    +! Unknown User 'Shell'
    +! Unknown User 'Sh'
    +! Unknown User '/bin/busybox Freepein'
    @- 06:27a T: 7 sec



    I have plenty more like this that has been amassed over the last 2 days, but I have to get ready to go to work so this is all i can post atm.. lemme know if you need more.
    --

    Tim Smith (KK4QBN)

    ---
    * Synchronet * KK4QBN BBS - (706)422-9538 - kk4qbn.synchro.net, Chatsworth GA
    * Origin: Vertrauen - vert.synchro.net (1:103/705)
  • From Digital Man@1:103/705 to Tim Smith on Sat Nov 19 10:55:54 2016
    Re: Telnet hack attempts
    By: Tim Smith to mark lewis on Sat Nov 19 2016 08:13 am

    Re: Telnet hack attempts
    By: Tim Smith to mark lewis on Sat Nov 19 2016 07:37 am

    Heres your continued LIst.. I'm trying to get Synchronet to add these automajically via the LoginAttemptHackThreshold, etc set the number to 2 and STILL it is not adding the IP or hotname to their respective files, is this not what this is here for?

    No, that is not what that is for. As described here, that .ini setting determines how many consecutive failed login attempts before a log entry is added to your hack.log file: http://wiki.synchro.net/config:sbbs.ini?s[]=loginattempthackthreshold

    The hack.log file does not filter anything, it's just notification mechanism. If you want automatic filtering or banning, you need to use the LoginAttemptBan* values or LoginAttemptFilterThreshold values, as described here: http://wiki.synchro.net/howto:block-hackers

    digital man

    Synchronet "Real Fact" #7:
    The name "Synchronet" was suggested by Steve Deppe (Ille Homine Albe) in 1991. Norco, CA WX: 68.3oF, 23.0% humidity, 0 mph E wind, 0.00 inches rain/24hrs
    --- SBBSecho 3.00-Win32
    * Origin: Vertrauen - vert.synchro.net (1:103/705)
  • From Tim Smith@1:103/705 to Digital Man on Sat Nov 19 17:39:32 2016
    Re: Telnet hack attempts
    By: Digital Man to Tim Smith on Sat Nov 19 2016 10:55 am

    No, that is not what that is for. As described here, that .ini setting determines how many consecutive failed login attempts before a log entry is added to your hack.log file: http://wiki.synchro.net/config:sbbs.ini?s[]=loginattempthackthreshold

    The hack.log file does not filter anything, it's just notification mechanism. If you want automatic filtering or banning, you need to use the LoginAttemptBan* values or LoginAttemptFilterThreshold values, as described here: http://wiki.synchro.net/howto:block-hackers

    I tried the LoginAttemptFilterThreshold, and it is'nt doing anything, I must not be doing it right.. I'll read over the wiki later, thanks for your help.


    digital man
    --

    Tim Smith (KK4QBN)

    ---
    * Synchronet * KK4QBN BBS - (706)422-9538 - kk4qbn.synchro.net, Chatsworth GA
    * Origin: Vertrauen - vert.synchro.net (1:103/705)
  • From Tim Smith@1:103/705 to Digital Man on Sat Nov 19 17:51:04 2016
    Re: Telnet hack attempts
    By: Tim Smith to mark lewis on Sat Nov 19 2016 08:13 am

    Re: Telnet hack attempts
    By: Tim Smith to mark lewis on Sat Nov 19 2016 07:37 am

    Heres your continued LIst.. I'm trying to get Synchronet to add these automajically via the LoginAttemptHackThreshold, etc set the number to 2
    and
    STILL it is not adding the IP or hotname to their respective files, is this not what this is here for?

    No, that is not what that is for. As described here, that .ini setting >determines how many consecutive failed login attempts before a log entry is >added to your hack.log file: >http://wiki.synchro.net/config:sbbs.ini?s[]=loginattempthackthreshold

    The hack.log file does not filter anything, it's just notification mechanism. >If you want automatic filtering or banning, you need to use the >LoginAttemptBan* values or LoginAttemptFilterThreshold values, as described >here: http://wiki.synchro.net/howto:block-hackers


    Yeah, I've even set LoginAttemptFilterThreshold=2 and it still does'nt log the IP or hostame (i checked both) I cannot understand why.

    ---
    * Synchronet * KK4QBN BBS - (706)422-9538 - kk4qbn.synchro.net, Chatsworth GA
    * Origin: Vertrauen - vert.synchro.net (1:103/705)
  • From Digital Man@1:103/705 to Tim Smith on Sat Nov 19 19:50:04 2016
    Re: Telnet hack attempts
    By: Tim Smith to Digital Man on Sat Nov 19 2016 05:51 pm

    Re: Telnet hack attempts
    By: Tim Smith to mark lewis on Sat Nov 19 2016 08:13 am

    Re: Telnet hack attempts
    By: Tim Smith to mark lewis on Sat Nov 19 2016 07:37 am

    Heres your continued LIst.. I'm trying to get Synchronet to add these automajically via the LoginAttemptHackThreshold, etc set the number to 2 and
    STILL it is not adding the IP or hotname to their respective files, is this not what this is here for?

    No, that is not what that is for. As described here, that .ini setting >determines how many consecutive failed login attempts before a log entry is >added to your hack.log file: >http://wiki.synchro.net/config:sbbs.ini?s[]=loginattempthackthreshold

    The hack.log file does not filter anything, it's just notification mechanism. >If you want automatic filtering or banning, you need to use the >LoginAttemptBan* values or LoginAttemptFilterThreshold values, as described >here: http://wiki.synchro.net/howto:block-hackers


    Yeah, I've even set LoginAttemptFilterThreshold=2 and it still does'nt log the IP or hostame (i checked both) I cannot understand why.

    What do you mean it doesn't "log the IP or hostname"? Did you mean to say it doesn't filter the IP or hostname? Hostnames are never filtered automatically (only IP addresses). And IP addresses are only filtered after consecutive unique failed login attempts (the user actually sends a username and password that are incorrect). Is that occurring?

    You can also check your failed login attempt list (e.g. SBBSCTRL->View->Login Attempts...) and see how many unique attempts have been made by which IP addresses.

    digital man

    Synchronet "Real Fact" #58:
    The last version of Synchronet to run on MS-DOS and OS/2 was v2.30c (1999). Norco, CA WX: 63.9oF, 34.0% humidity, 2 mph SSE wind, 0.00 inches rain/24hrs --- SBBSecho 3.00-Win32
    * Origin: Vertrauen - vert.synchro.net (1:103/705)
  • From mark lewis@1:3634/12.73 to Tim Smith on Sat Nov 19 22:48:24 2016

    19 Nov 16 07:18, you wrote to me:

    we won't even talk about the stuff going on on the bluetooth or
    zephyer networks...

    Yup, I'm starting to believe that more and more every hour.. this
    thing is evolving, or something.. but growing exponitially..

    look... i've got a couple of copies of the supposed MIRAI code as released by the supposed original author... i'm sure that there are hundreds of others with
    the same code that are bashing it into something they want for their nefarious purposes... at least one has merged the code with their IRC based bot and i've seen those things trying to get in because i know the name they are using besides MIRAI... i've seen stuff that comes from some italian skiddie because they left italian comments and responses in the code... the other day i saw a new variant hitting my systems with a really long name that turns out to be russian but i've not yet found a translation for it... i'm waiting on some others to find a copy of it in their honeypots and disect it...

    Thanks for all the crappy backdoors china.. --

    it isn't all china, really... it is more stupid/ignorant humans simply not changing the default uaer names and passwords to their own stuff... that's really all it takes to stop MIRAI and its variants... change those damned user names and passwords! never ever ever ever leave the defaults in place... ever ever! ;)

    )\/(ark

    Always Mount a Scratch Monkey
    Do you manage your own servers? If you are not running an IDS/IPS yer doin' it wrong...
    ... We are a monopoly phone company. Resistance is futile.
    ---
    * Origin: (1:3634/12.73)
  • From mark lewis@1:3634/12.73 to Tim Smith on Sat Nov 19 22:54:40 2016

    19 Nov 16 07:37, you wrote to me:

    yeah, the first letter is being dropped for some reason... can you
    provide those IP addresses exhibiting this, please? i know a few
    folks that would love to take a crack at them and see if they can
    grab those binaries for analysis to see if they can determine if it
    is a new player or just a skiddie trying their hand at swimming with
    the big boys...

    yup, hold up a sec... I've deleted some logfiles, but I'm sure I can
    still provide a few...

    14.136.5.149 Freepein
    96.230.36.92 Mirai

    Pattern <FIOS> Verizon (multiple ips)

    36.68.36.249 Memes

    yeah, those are the most common ones... i have all of those IPs blocked, too...
    they are just a small subset, though...

    do you have any idea what the "FREEPEIN" one are referencing?? think of the Lizard Squad and their activities and then look at, well, you might not be able
    to see it but, how they all shrank back and MIRAI activities dropped of the a couple of members of the LS were arrested and taken into questioning... it was a couple of weeks later when MIRAI activity started up again with increased activities at that time...


    )\/(ark

    Always Mount a Scratch Monkey
    Do you manage your own servers? If you are not running an IDS/IPS yer doin' it wrong...
    ... Nothing like a bribe to get things rolling.
    ---
    * Origin: (1:3634/12.73)
  • From Tony Langdon@3:633/410 to mark lewis on Sun Nov 20 22:47:00 2016
    mark lewis wrote to Tim Smith <=-

    it isn't all china, really... it is more stupid/ignorant humans simply
    not changing the default uaer names and passwords to their own stuff... that's really all it takes to stop MIRAI and its variants... change
    those damned user names and passwords! never ever ever ever leave the defaults in place... ever ever! ;)

    Good advice, but we know that the people who need to, don't listen. There's a reason why wifi routers went from being shipped with no encryption and a default password to coming with WPA/WPA2 turned on and a unique password - because the majority of owners don't think to change the defaults.


    ... All the stats in the world don't mean as much as a human feeling.
    --- MultiMail/Win32 v0.49
    * Origin: Freeway BBS - freeway.apana.org.au (3:633/410)
  • From Tim Smith@1:103/705 to Digital Man on Sun Nov 20 06:21:52 2016
    Re: Telnet hack attempts
    By: Digital Man to Tim Smith on Sat Nov 19 2016 07:50 pm

    What do you mean it doesn't "log the IP or hostname"? Did you mean to say it doesn't filter the IP or hostname? Hostnames are never filtered automatically (only IP addresses). And IP addresses are only filtered after consecutive unique failed login attempts (the user actually sends a username and password that are incorrect). Is that occurring?

    Right, it does'nt add the IPs to the IP filter



    You can also check your failed login attempt list (e.g. SBBSCTRL->View->Login Attempts...) and see how many unique attempts have been made by which IP addresses.

    NONE, I mean ZERO of these miria attemps show up in login attempts file, only attempts using ssh (1). I get 400kb logfiles daily full of Mirai login attemps, and even as many IP addresses I've added to the ip can manually, it is still a non stop process.. (not quite as bad as before) BUT I dunno if these attempts are trying to login username/password.. I would presume.. the bot telnets in and sends about 5-6 commands, hangs up, goes to the next node, does it over again, usualy to the tune of..

    Root
    mom
    sh
    System
    Shell
    /bin/busybox Mirai

    even with the threshhold set to two, it does'nt block the ips.

    unless I'm using this wrong also..
    --

    Tim Smith (KK4QBN)

    ---
    * Synchronet * KK4QBN BBS - (706)422-9538 - kk4qbn.synchro.net, Chatsworth GA
    * Origin: Vertrauen - vert.synchro.net (1:103/705)
  • From Tim Smith@1:103/705 to mark lewis on Sun Nov 20 06:26:38 2016
    Re: Telnet hack attempts
    By: mark lewis to Tim Smith on Sat Nov 19 2016 10:48 pm

    it isn't all china, really... it is more stupid/ignorant humans simply not changing the default uaer names and passwords to their own stuff... that's really all it takes to stop MIRAI and its variants... change those damned user names and passwords! never ever ever ever leave the defaults in place... ever ever! ;)


    Whats bad, like with windstream/etc tehy install the routers when they do an in home installation, they should atleast change the passwords.. they left my router at admin/admin.. that freaking simple.. just change the freaking password and put a sticker on the router if needed..
    --

    Tim Smith (KK4QBN)

    ---
    * Synchronet * KK4QBN BBS - (706)422-9538 - kk4qbn.synchro.net, Chatsworth GA
    * Origin: Vertrauen - vert.synchro.net (1:103/705)
  • From Tim Smith@1:103/705 to mark lewis on Sun Nov 20 06:32:02 2016
    Re: Telnet hack attempts
    By: mark lewis to Tim Smith on Sat Nov 19 2016 10:54 pm

    do you have any idea what the "FREEPEIN" one are referencing?? think of the Lizard Squad and their activities and then look at, well, you might not be able to see it but, how they all shrank back and MIRAI activities dropped of the a couple of members of the LS were arrested and taken into questioning... it was a couple of weeks later when MIRAI activity started up again with increased activities at that time...

    Looks like "Freepein" has something to do with "someone" who wrote some code and is is jail and #freepein is floating around social media to raise awareness.. hmm.. dunno...

    https://twitter.com/search?q=%23FreePein
    --

    Tim Smith (KK4QBN)

    ---
    * Synchronet * KK4QBN BBS - (706)422-9538 - kk4qbn.synchro.net, Chatsworth GA
    * Origin: Vertrauen - vert.synchro.net (1:103/705)
  • From Digital Man@1:103/705 to Tim Smith on Sun Nov 20 12:00:26 2016
    Re: Telnet hack attempts
    By: Tim Smith to Digital Man on Sun Nov 20 2016 06:21 am

    Re: Telnet hack attempts
    By: Digital Man to Tim Smith on Sat Nov 19 2016 07:50 pm

    What do you mean it doesn't "log the IP or hostname"? Did you mean to say it doesn't filter the IP or hostname? Hostnames are never filtered automatically (only IP addresses). And IP addresses are only filtered after consecutive unique failed login attempts (the user actually sends a username and password that are incorrect). Is that occurring?

    Right, it does'nt add the IPs to the IP filter



    You can also check your failed login attempt list (e.g. SBBSCTRL->View->Login Attempts...) and see how many unique attempts have been made by which IP addresses.

    NONE, I mean ZERO of these miria attemps show up in login attempts file,

    What file is that? I don't actually have a "login attempts file", other than the normal terminal server (and other log) output. Or are you thinking of the hack.log file?

    only attempts using ssh (1). I get 400kb logfiles daily full of Mirai login attemps, and even as many IP addresses I've added to the ip can manually, it is still a non stop process.. (not quite as bad as before) BUT I dunno if these attempts are trying to login username/password.. I would presume.. the bot telnets in and sends about 5-6 commands, hangs up, goes to the next node, does it over again, usualy to the tune of..

    Root
    mom
    sh
    System
    Shell
    /bin/busybox Mirai

    even with the threshhold set to two, it does'nt block the ips.

    unless I'm using this wrong also..

    Here some examples from my hack.log:
    SUSPECTED SSH LOGIN HACK ATTEMPT for user 'xubuntu' on Thu Nov 17 2016 01:26 pm Using port 44305 at 61-91-124-216.static.asianet.co.th [61.91.124.216]
    Details: xubuntu

    SUSPECTED SSH LOGIN HACK ATTEMPT for user 'root1' on Thu Nov 17 2016 01:26 pm Using port 35755 at 61-91-124-216.static.asianet.co.th [61.91.124.216]
    Details: root1

    Note: these are not *all* the failed login attempts from that IP address. Just the *consecutive* failed logins with unique (non-repeated) credentials that occured *after* that IP address hit my configured LoginAttemptHackThreshold (10).

    Here are some examples of auto-filtering from my ip.can:
    ; SSH - TOO MANY CONSECUTIVE FAILED LOGIN ATTEMPTS by root on Wed Jun 24 2015 08:20 pm
    ; Hostname: 5ED55D42.cm-7-6b.dynamic.ziggo.nl
    94.213.93.66

    ; SSH - TOO MANY CONSECUTIVE FAILED LOGIN ATTEMPTS by root on Sat Jun 27 2015 01:13 am
    ; Hostname: <no name>
    208.165.55.150

    ; SSH - TOO MANY CONSECUTIVE FAILED LOGIN ATTEMPTS by root on Sun Jun 28 2015 04:18 pm
    ; Hostname: <no name>
    46.101.129.70

    ; SSH - TOO MANY CONSECUTIVE FAILED LOGIN ATTEMPTS by voice on Wed Jul 08 2015 02:49 am
    ; Hostname: static-71-245-177-204.pitbpa.fios.verizon.net
    71.245.177.204

    These are kind of old now because I use the new temp-ban feature of v3.17 to handle these anoyances in a less "permanent" manner.

    digital man

    Synchronet/BBS Terminology Definition #29:
    IP = Internet Protocol
    Norco, CA WX: 64.8oF, 61.0% humidity, 8 mph SE wind, 0.00 inches rain/24hrs
    --- SBBSecho 3.00-Win32
    * Origin: Vertrauen - vert.synchro.net (1:103/705)
  • From Tim Smith@1:103/705 to Digital Man on Sun Nov 20 19:49:52 2016
    Re: Telnet hack attempts
    By: Digital Man to Tim Smith on Sun Nov 20 2016 12:00 pm

    What do you mean it doesn't "log the IP or hostname"? Did you mean
    to say it doesn't filter the IP or hostname? Hostnames are never
    filtered automatically (only IP addresses). And IP addresses are
    only filtered after consecutive unique failed login attempts (the
    user actually sends a username and password that are incorrect).
    Is that occurring?
    Right, it does'nt add the IPs to the IP filter
    What file is that? I don't actually have a "login attempts file", other than the normal terminal server (and other log) output. Or are you thinking of the hack.log file?


    No, thinking of the IP filter, or to be exact ../text/ip.can, it was my assumption that by using the threshold command after x amount failed logins it would automaticall put the ip in there.. please bare with me because i'm pretty fresh and rusty here in the BBS scene again.. it will take me a bit to get back up to par. Like the logfile snippet I sent, the botnet sends about 5-6 commands the terminates and goes to another node and does the same, sometimes with different variences on the same one. in the log it will give about 5 "Unkown User" for the same IP on the same instance, that should be enough to get their IP into the ip.can correct? if it is working right. since I have the threshold set to 2 "being strict.".

    Down the road I'll end up either putting the BBS back on linux, or either building a version for windows, but I'm running it on its own XP box just for ease of installing doorgames etc.. but these Mirai requests get so bad sometime its almost as if I'm getting hit by a DOS attack, by manually adding IPs I've gotten it down to where I get only 5-6 a day now that hammer the machine, until I get a chance to get their IPs added.. but truthfully thats what I though LoginAttemptFilterThreshold, etc was for.. the TempBanThreshold is in my sbbs.ini also, So I'm to presume it does'nt work with this version of sbbs. (316c)

    Thanks.
    --

    Tim Smith (KK4QBN)

    ---
    * Synchronet * KK4QBN BBS - (706)422-9538 - kk4qbn.synchro.net, Chatsworth GA
    * Origin: Vertrauen - vert.synchro.net (1:103/705)
  • From Digital Man@1:103/705 to Tim Smith on Sun Nov 20 20:33:22 2016
    Re: Telnet hack attempts
    By: Tim Smith to Digital Man on Sun Nov 20 2016 07:49 pm

    Re: Telnet hack attempts
    By: Digital Man to Tim Smith on Sun Nov 20 2016 12:00 pm

    What do you mean it doesn't "log the IP or hostname"? Did you mean DM>> to say it doesn't filter the IP or hostname? Hostnames are never DM>> filtered automatically (only IP addresses). And IP addresses are DM>> only filtered after consecutive unique failed login attempts (the DM>> user actually sends a username and password that are incorrect). DM>> Is that occurring?
    Right, it does'nt add the IPs to the IP filter
    What file is that? I don't actually have a "login attempts file", other than the normal terminal server (and other log) output. Or are you thinking of the hack.log file?


    No, thinking of the IP filter, or to be exact ../text/ip.can, it was my assumption that by using the threshold command after x amount failed logins it would automaticall put the ip in there.. please bare with me because i'm pretty fresh and rusty here in the BBS scene again.. it will take me a bit to get back up to par. Like the logfile snippet I sent, the botnet sends about 5-6 commands the terminates and goes to another node and does the same, sometimes with different variences on the same one. in the log it will give about 5 "Unkown User" for the same IP on the same instance, that should be enough to get their IP into the ip.can correct? if it is working right. since I have the threshold set to 2 "being strict.".

    Down the road I'll end up either putting the BBS back on linux, or either building a version for windows, but I'm running it on its own XP box just for ease of installing doorgames etc.. but these Mirai requests get so bad sometime its almost as if I'm getting hit by a DOS attack, by manually adding IPs I've gotten it down to where I get only 5-6 a day now that hammer the machine, until I get a chance to get their IPs added.. but truthfully thats what I though LoginAttemptFilterThreshold, etc was for..

    That is what it's for. But I think I know why it's not working for you. The failed login attempt logging/filtering system requires a password as part of the criteria (e.g. to detect duplicate attempts) and if SCFG->Nodes->Node 1->Always Prompt for Password is set to "No", then an invalid username will just be rejected, no password prompted for, and not counted as a "failed login attempt". I can change this behavior for v3.17, but not for v3.16. The fix for you is to just change that option to "Yes" in SCFG.

    the
    TempBanThreshold is in my sbbs.ini also, So I'm to presume it does'nt work with this version of sbbs. (316c)

    That's correct.

    digital man

    Synchronet/BBS Terminology Definition #40:
    R0DENT = Derogatory reference to a young BBS user of the 1990's
    Norco, CA WX: 56.4oF, 92.0% humidity, 0 mph SSE wind, 0.00 inches rain/24hrs --- SBBSecho 3.00-Win32
    * Origin: Vertrauen - vert.synchro.net (1:103/705)
  • From Lord Time@1:103/705 to Digital Man on Sun Nov 20 21:15:54 2016
    Re: Telnet hack attempts
    By: Tim Smith to Digital Man on Sun Nov 20 2016 07:49 pm

    Re: Telnet hack attempts
    By: Digital Man to Tim Smith on Sun Nov 20 2016 12:00 pm

    What do you mean it doesn't "log the IP or hostname"? Did you mean DM>> to say it doesn't filter the IP or hostname? Hostnames are never DM>> filtered automatically (only IP addresses). And IP addresses are DM>> only filtered after consecutive unique failed login attempts (the DM>> user actually sends a username and password that are incorrect). DM>> Is that occurring?
    Right, it does'nt add the IPs to the IP filter
    What file is that? I don't actually have a "login attempts file", other than the normal terminal server (and other log) output. Or are you thinking of the hack.log file?


    No, thinking of the IP filter, or to be exact ../text/ip.can, it was my assumption that by using the threshold command after x amount failed logins it would automaticall put the ip in there.. please bare with me because i'm pretty fresh and rusty here in the BBS scene again.. it will take me a bit to get back up to par. Like the logfile snippet I sent, the botnet sends about 5-6 commands the terminates and goes to another node and does the same, sometimes with different variences on the same one. in the log it will give about 5 "Unkown User" for the same IP on the same instance, that should be enough to get their IP into the ip.can correct? if it is working right. since I have the threshold set to 2 "being strict.".

    Down the road I'll end up either putting the BBS back on linux, or either building a version for windows, but I'm running it on its own XP box just for ease of installing doorgames etc.. but these Mirai requests get so bad sometime its almost as if I'm getting hit by a DOS attack, by manually adding IPs I've gotten it down to where I get only 5-6 a day now that hammer the machine, until I get a chance to get their IPs added.. but truthfully thats what I though LoginAttemptFilterThreshold, etc was for..

    That is what it's for. But I think I know why it's not working for you. The failed login attempt logging/filtering system requires a password as part of the criteria (e.g. to detect duplicate attempts) and if SCFG->Nodes->Node 1->Always Prompt for Password is set to "No", then an invalid username will just be rejected, no password prompted for, and not counted as a "failed login attempt". I can change this behavior for v3.17, but not for v3.16. The fix for you is to just change that option to "Yes" in SCFG.

    I just check my test bbs, it look like that setting is in the off mode by default


    ---

    Rob Starr
    Lord Time SysOp of
    Time Warp of the Future BBS
    Telnet://Time.Darktech.Org:24 or
    Telnet://Time.Synchro.Net:24 (qwk or ftn & e-mail)
    ICQ # 11868133 or # 70398519 Jabber : lordtime2000@gmail.com
    Yahoo : lordtime2000 AIM : LordTime20000 Astra : lord_time
    X-Box : Lord Time 2000 oovoo : lordtime2000
    ---
    * Synchronet * Time Warp of the Future BBS - Home of League 10 IBBS Games
    * Origin: Vertrauen - vert.synchro.net (1:103/705)
  • From Digital Man@1:103/705 to Lord Time on Sun Nov 20 23:07:58 2016
    Re: Re: Telnet hack attempts
    By: Lord Time to Digital Man on Sun Nov 20 2016 09:15 pm

    That is what it's for. But I think I know why it's not working for you. The failed login attempt logging/filtering system requires a password as part of the criteria (e.g. to detect duplicate attempts) and if SCFG->Nodes->Node 1->Always Prompt for Password is set to "No", then an invalid username will just be rejected, no password prompted for, and not counted as a "failed login attempt". I can change this behavior for v3.17, but not for v3.16. The fix for you is to just change that option to "Yes" in SCFG.

    I just check my test bbs, it look like that setting is in the off mode by default

    I guess that explains why that feature seems to never work for anyone but me! :-)

    digital man

    Synchronet/BBS Terminology Definition #11:
    DCD = Data Carrier Detect
    Norco, CA WX: 55.8oF, 94.0% humidity, 0 mph W wind, 0.01 inches rain/24hrs
    --- SBBSecho 3.00-Win32
    * Origin: Vertrauen - vert.synchro.net (1:103/705)
  • From Lord Time@1:103/705 to Digital Man on Sun Nov 20 23:16:16 2016
    That is what it's for. But I think I know why it's not working for you. The failed login attempt logging/filtering system requires a password as part of the criteria (e.g. to detect duplicate attempts) and if SCFG->Nodes->Node 1->Always Prompt for Password is set to "No", then an invalid username will just be rejected, no password prompted for, and not counted as a "failed login attempt". I can change this behavior for v3.17, but not for v3.16. The fix for you is to just change that option to "Yes" in SCFG.

    I just check my test bbs, it look like that setting is in the off mode by default

    I guess that explains why that feature seems to never work for anyone but me! :-)

    maybe


    ---

    Rob Starr
    Lord Time SysOp of
    Time Warp of the Future BBS
    Telnet://Time.Darktech.Org:24 or
    Telnet://Time.Synchro.Net:24 (qwk or ftn & e-mail)
    ICQ # 11868133 or # 70398519 Jabber : lordtime2000@gmail.com
    Yahoo : lordtime2000 AIM : LordTime20000 Astra : lord_time
    X-Box : Lord Time 2000 oovoo : lordtime2000
    ---
    * Synchronet * Time Warp of the Future BBS - Home of League 10 IBBS Games
    * Origin: Vertrauen - vert.synchro.net (1:103/705)
  • From Tim Smith@1:103/705 to Digital Man on Mon Nov 21 06:04:14 2016
    Re: Telnet hack attempts
    By: Digital Man to Tim Smith on Sun Nov 20 2016 08:33 pm

    That is what it's for. But I think I know why it's not working for you. The failed login attempt logging/filtering system requires a password as part of the criteria (e.g. to detect duplicate attempts) and if SCFG->Nodes->Node
    Always Prompt for Password is set to "No", then an invalid username
    will
    just be rejected, no password prompted for, and not counted as a "failed login attempt". I can change this behavior for v3.17, but not for v3.16. The fix for you is to just change that option to "Yes" in SCFG.


    Beautiful, I was thinking about the same, because the attempts never actual are password attempts only username, so its not a full attempt.. thanks DM
    --

    Tim Smith (KK4QBN)

    ---
    * Synchronet * KK4QBN BBS - (706)422-9538 - kk4qbn.synchro.net, Chatsworth GA
    * Origin: Vertrauen - vert.synchro.net (1:103/705)
  • From Accession@1:103/705 to Digital Man on Mon Nov 21 09:26:30 2016
    Hello Digital,

    On 20 Nov 16 23:07, Digital Man wrote to Lord Time:

    I guess that explains why that feature seems to never work for anyone
    but me!
    :-)

    Oddly enough, after upgrading to get this new feature, I see this in my logs after polling for Dovenet messages:

    evnt !Filtering QWK message from Deavmi due to blocked IP: 41.164.54.42

    Hopefully this isn't because now NNTP is banning IPs that are connecting many times to retreive newsgroups and/or switch areas. And actually, after looking up that IP address in ip.can, it shows NNTP banned that address back in July, so who knows. I've removed it so we'll see what happens.

    I just that filtering QWK message in the logs before today.

    Regards,
    Nick

    ... "-Y-| -+-+-#-A. -> -+-|-|-U-i -e-+-+-i-|-+ -C-#-#-+-e-#-A."
    --- GoldED+/LNX 1.1.5-b20160827
    # Origin: thePharcyde_ distribution system (Wisconsin) (723:1/1)
    * Synchronet * thePharcyde_ telnet://bbs.pharcyde.org (Wisconsin)
    * Origin: Vertrauen - vert.synchro.net (1:103/705)
  • From Digital Man@1:103/705 to Tim Smith on Mon Nov 21 13:40:42 2016
    Re: Telnet hack attempts
    By: Tim Smith to Digital Man on Mon Nov 21 2016 06:04 am

    Re: Telnet hack attempts
    By: Digital Man to Tim Smith on Sun Nov 20 2016 08:33 pm

    That is what it's for. But I think I know why it's not working for you. The failed login attempt logging/filtering system requires a password as part of the criteria (e.g. to detect duplicate attempts) and if SCFG->Nodes->Node
    Always Prompt for Password is set to "No", then an invalid username
    will
    just be rejected, no password prompted for, and not counted as a "failed login attempt". I can change this behavior for v3.17, but not for v3.16. The fix for you is to just change that option to "Yes" in SCFG.


    Beautiful, I was thinking about the same, because the attempts never actual are password attempts only username, so its not a full attempt.. thanks DM

    Most likely, if the "hacker" was prompted for a password, they would send one. But because you have the "Alwasy Prompt for Password" option set to "No", and they're trying an invalid user name, they never get prompted for a password.

    Additionally, these scripts/bots may not be able to tell the difference between a Login/name prompt and a password prompt, so they might be sending a password attempt for the second login/attempt in that configuration.

    digital man

    Synchronet/BBS Terminology Definition #15:
    DOS = Disk Operating System (as in PC-DOS and MS-DOS)
    Norco, CA WX: 63.2oF, 68.0% humidity, 12 mph E wind, 0.45 inches rain/24hrs
    --- SBBSecho 3.00-Win32
    * Origin: Vertrauen - vert.synchro.net (1:103/705)
  • From Tim Smith@1:103/705 to Digital Man on Mon Nov 21 11:33:16 2016
    Re: Re: Telnet hack attempts
    By: Digital Man to Lord Time on Sun Nov 20 2016 11:07 pm

    I just check my test bbs, it look like that setting is in the off mode
    by default

    I guess that explains why that feature seems to never work for anyone but me!

    ; Telnet - TOO MANY CONSECUTIVE FAILED LOGIN ATTEMPTS by Support on Mon Nov 21 2016 07:42 am
    ; Hostname: host-133-209.adc.net.ar
    181.174.133.209

    ; Telnet - TOO MANY CONSECUTIVE FAILED LOGIN ATTEMPTS by Admin on Mon Nov 21 20 16 08:35 am
    ; Hostname: <no name>
    200.111.7.52

    ; SSH - TOO MANY CONSECUTIVE FAILED LOGIN ATTEMPTS by ubnt on Mon Nov 21 2016 0 8:54 am
    ; Hostname: <no name>
    61.149.239.68

    ; Telnet - TOO MANY CONSECUTIVE FAILED LOGIN ATTEMPTS by 888888 on Mon Nov 21 2 016 09:34 am
    ; Hostname: 77.87.147.20.sta.pautina.ua
    77.87.147.20

    ; Telnet - TOO MANY CONSECUTIVE FAILED LOGIN ATTEMPTS by Admin on Mon Nov 21 20 16 09:35 am
    ; Hostname: <no name>
    117.212.14.71

    ; Telnet - TOO MANY CONSECUTIVE FAILED LOGIN ATTEMPTS by Root on Mon Nov 21 201 6 09:45 am
    ; Hostname: 177208184224.user.veloxzone.com.br
    177.208.184.224

    ; Telnet - TOO MANY CONSECUTIVE FAILED LOGIN ATTEMPTS by Admin on Mon Nov 21 20 16 10:03 am
    ; Hostname: <no name>
    113.219.113.120

    ; Telnet - TOO MANY CONSECUTIVE FAILED LOGIN ATTEMPTS by Support on Mon Nov 21 2016 10:23 am
    ; Hostname: abts-north-dynamic-121.233.177.122.airtelbroadband.in 122.177.233.121

    ; Telnet - TOO MANY CONSECUTIVE FAILED LOGIN ATTEMPTS by Admin on Mon Nov 21 20 16 10:45 am
    ; Hostname: rrcs-50-75-223-82.nyc.biz.rr.com
    50.75.223.82

    ; Telnet - TOO MANY CONSECUTIVE FAILED LOGIN ATTEMPTS by /bin/busybox Uchilaisa sni on Mon Nov 21 2016 11:14 am
    ; Hostname: c-73-155-33-90.hsd1.tx.comcast.net
    73.155.33.90

    Working beautifully now, telnet servers are finally getting a break.

    Thanks again for all your help Rob.
    --

    Tim Smith (KK4QBN)

    ---
    * Synchronet * KK4QBN BBS - (706)422-9538 - kk4qbn.synchro.net, Chatsworth GA
    * Origin: Vertrauen - vert.synchro.net (1:103/705)
  • From Digital Man@1:103/705 to Tim Smith on Mon Nov 21 14:14:04 2016
    Re: Re: Telnet hack attempts
    By: Tim Smith to Digital Man on Mon Nov 21 2016 11:33 am

    Working beautifully now, telnet servers are finally getting a break.

    Thanks again for all your help Rob.

    Good to know. In the next release of sbbs, that feature will work regardless of the "Always Prompt for Password" setting. Thanks for helping to realize that was the problem!

    digital man

    Synchronet/BBS Terminology Definition #53:
    XJS = External JavaScript
    Norco, CA WX: 63.1oF, 68.0% humidity, 6 mph E wind, 0.45 inches rain/24hrs
    --- SBBSecho 3.00-Win32
    * Origin: Vertrauen - vert.synchro.net (1:103/705)
  • From Tim Smith@1:103/705 to Digital Man on Mon Nov 21 19:21:54 2016
    Re: Telnet hack attempts
    By: Digital Man to Tim Smith on Mon Nov 21 2016 01:40 pm

    Additionally, these scripts/bots may not be able to tell the difference between a Login/name prompt and a password prompt, so they might be sending a password attempt for the second login/attempt in that configuration.

    Thats true, they are just trying to the quickest brute force way to gain access, there appears to be no real structure to it, and it seems very stupid, some of them use the DUMBEST usernames that I could never envision ANYONE use.

    but we're fixed here, thanks for your resiliance.
    --

    Tim Smith (KK4QBN)

    ---
    * Synchronet * KK4QBN BBS - (706)422-9538 - kk4qbn.synchro.net, Chatsworth GA US
    * Origin: Vertrauen - vert.synchro.net (1:103/705)
  • From Tim Smith@1:103/705 to Digital Man on Mon Nov 21 19:28:56 2016
    Re: Re: Telnet hack attempts
    By: Digital Man to Tim Smith on Mon Nov 21 2016 02:14 pm

    By: Tim Smith to Digital Man on Mon Nov 21 2016 11:33 am

    Working beautifully now, telnet servers are finally getting a break.

    Thanks again for all your help Rob.

    Good to know. In the next release of sbbs, that feature will work regardless of the "Always Prompt for Password" setting. Thanks for helping to realize that was the problem!

    Glad to be some sort of help.. lol.. as I say, I'm very rusty.. but this is kina like riding bikes or flying RC airplanes, lay it down for a while, then pick back up and catch on pretty quick. I'm LOVING all the new features, especially since I received my Tech License, My next endevour is to getting the packet BBS side up, I'm going to see if I can host it on a local 440 repeater that gets 0 traffic whatsoever, and its a club repeater.

    of course a lot of precations will be made to keep legal, and I had a little brainstorm, thinking of patching either an IRC channel, or something into a RAT reflector, if thats possible.. I know there's tons of endless possabilities, Just got to get back into that JS and really hammer down, I want to start contributing to Synchronet once again. I was crusing around your board looking at some of the help files (precurser to wiki) I presume that I had uploaded for installing BBS door, and QWK packet networks, but could'nt find them. those were from my Warzone, and Datashack BBS days :)
    --

    Tim Smith (KK4QBN)

    ---
    * Synchronet * KK4QBN BBS - (706)422-9538 - kk4qbn.synchro.net, Chatsworth GA US
    * Origin: Vertrauen - vert.synchro.net (1:103/705)