• Help with Security and BB

    From Daryl Stout@1:103/705 to DAITENGU on Tue Feb 27 12:59:00 2018
    SSH is encrypted, so passwords are not sent in plaintext.

    I had so many hack and logon attempts, it kept tying up the
    nodes...so, I finally just disabled SSH.

    Daryl

    ---
    * OLX 1.53 * I've repeatedly said to you, to not be redundant.
    * Synchronet * The Thunderbolt BBS - wx1der.dyndns.org
    * Origin: Vertrauen - [vert/cvs/bbs].synchro.net (1:103/705)
  • From Mike Powell@1:103/705 to MARK LEWIS on Wed Feb 28 18:36:00 2018
    some users /can't/ do ssh... they're lucky they can telnet at all... i'm aware >of at least one BBS user that (still) uses a 486 with DOS v6 and the old watcom
    comms drivers stuff... almost kinda similar to the old KA9Q stuff...

    Some BBSes cannot offer it, either. For whatever reason, synchronet will compile on my system, but will segfault when executed if SSH/SSL is enabled.

    I've not tried it lately. DM may have figured out what was causing it by
    now.

    ---
    * SLMR 2.1a * Gimme three chili dogs and a malt.
    * Synchronet * CAPCITY2 * CCO BBS * capcity2.synchro.net:26
    * Origin: Vertrauen - [vert/cvs/bbs].synchro.net (1:103/705)
  • From Mike Powell@1:103/705 to ISPYHUMANFLY on Wed Feb 28 18:47:00 2018
    I'm not a fan of non-default ports. I think using non-default ports creates one extra hurdle for users, if you care about attracting them. <shrug>

    I second this.

    I am not, either, but got tired of getting hammered on the default telnet
    port. I have left my other services on the defaults, though.

    A telnet "call" to the default port here does bring up a screen which tells
    any human "callers" which port to find the actual BBS on.

    ---
    * SLMR 2.1a * Mike Powell, Sysop *The PAN-AMERICAN* 502/875-8938 * v34+
    * Synchronet * CAPCITY2 * CCO BBS * capcity2.synchro.net:26
    * Origin: Vertrauen - [vert/cvs/bbs].synchro.net (1:103/705)
  • From Digital Man@1:103/705 to Mike Powell on Wed Feb 28 16:08:29 2018
    Re: Help with Security and BB
    By: Mike Powell to MARK LEWIS on Wed Feb 28 2018 06:36 pm

    some users /can't/ do ssh... they're lucky they can telnet at all... i'm aware >of at least one BBS user that (still) uses a 486 with DOS v6 and the old watcom
    comms drivers stuff... almost kinda similar to the old KA9Q stuff...

    Some BBSes cannot offer it, either. For whatever reason, synchronet will compile on my system, but will segfault when executed if SSH/SSL is enabled.

    I've not tried it lately. DM may have figured out what was causing it by now.

    Yeah, that sounds like something that was introduced with the latest cryptlib update and fixed (by now).

    digital man

    This Is Spinal Tap quote #26:
    David St. Hubbins: They were still booing him when we came on stage.
    Norco, CA WX: 57.8oF, 56.0% humidity, 9 mph ENE wind, 0.00 inches rain/24hrs --- SBBSecho 3.03-Win32
    * Origin: Vertrauen - [vert/cvs/bbs].synchro.net (1:103/705)
  • From ispyhumanfly@1:103/705 to Mike Powell on Thu Mar 1 06:23:53 2018
    Re: Help with Security and BB
    By: Mike Powell to ISPYHUMANFLY on Wed Feb 28 2018 06:47 pm

    I am not, either, but got tired of getting hammered on the default telnet port. I have left my other services on the defaults, though.

    A telnet "call" to the default port here does bring up a screen which tells any human "callers" which port to find the actual BBS on.

    That's not a bad workaround to the problem. Yeah it does appear these days that default telnet ports are getting hit a lot. I've seen a few other solutions that I also like:

    1 - Jack Phlash of Distortion requires an ESC to be hit before login.
    2 - MRO of EOB has a captcha then whitelists the IP.

    I've considered similar solutions to your own, and the above mentioned.

    _ispy++

    ---
    * Synchronet * euphoria - euphoriabbs.org
    * Origin: Vertrauen - [vert/cvs/bbs].synchro.net (1:103/705)
  • From Daryl Stout@1:103/705 to MIKE POWELL on Thu Mar 1 12:32:00 2018
    Mike,

    A telnet "call" to the default port here does bring up a screen which tells MP>any human "callers" which port to find the actual BBS on.

    Not a bad idea...but I zapped the SSH deal, as I was getting slammed
    on it. I had changed to bizarre port numbers, but they still found it,
    and I just got tired of all the nodes getting tied up with them trying
    to hack into the system.

    With Synchronet's login-js deal, plus my ever growing user.can and
    ip.can files, and SBBS's feature of where "if a terminal type is not
    detcted, the inactivity hangup is reduced to 75 seconds", that helps
    get rid of a lot of these bots.

    Daryl

    ---
    * OLX 1.53 * What idiot put CONFOUND.SYS on my computer??!!
    * Synchronet * The Thunderbolt BBS - wx1der.dyndns.org
    * Origin: Vertrauen - [vert/cvs/bbs].synchro.net (1:103/705)
  • From Daryl Stout@1:103/705 to ISPYHUMANFLY on Thu Mar 1 12:33:00 2018
    A telnet "call" to the default port here does bring up a screen which tells any human "callers" which port to find the actual BBS on.

    That's not a bad workaround to the problem. Yeah it does appear these days th I>default telnet ports are getting hit a lot. I've seen a few other solutions I>that I also like:

    1 - Jack Phlash of Distortion requires an ESC to be hit before login.

    I wonder if opening up port 23 to Argus would do that...and still
    allow dial-up callers??

    2 - MRO of EOB has a captcha then whitelists the IP.

    I tried the CAPTCHA deal, but it kept locking up, so I decided not to
    use it.

    Daryl

    ---
    * OLX 1.53 * What if someone's real name is a psuedonym??
    * Synchronet * The Thunderbolt BBS - wx1der.dyndns.org
    * Origin: Vertrauen - [vert/cvs/bbs].synchro.net (1:103/705)
  • From ispyhumanfly@1:103/705 to Daryl Stout on Fri Mar 2 19:43:46 2018
    Re: Help with Security and BB
    By: Daryl Stout to ISPYHUMANFLY on Thu Mar 01 2018 12:33 pm

    2 - MRO of EOB has a captcha then whitelists the IP.

    I tried the CAPTCHA deal, but it kept locking up, so I decided not to
    use it.

    Sounds like the solution you have in place is a good one, too. So no loss.

    _ispy++

    ---
    * Synchronet * euphoria - euphoriabbs.org
    * Origin: Vertrauen - [vert/cvs/bbs].synchro.net (1:103/705)
  • From Simulant@1:103/705 to Daryl Stout on Fri Mar 2 15:56:13 2018
    Re: Help with Security and BB
    By: Daryl Stout to MIKE POWELL on Thu Mar 01 2018 12:32 pm

    With Synchronet's login-js deal, plus my ever growing user.can and
    ip.can files, and SBBS's feature of where "if a terminal type is not detcted, the inactivity hangup is reduced to 75 seconds", that helps
    get rid of a lot of these bots.

    Hey Daryl, that feature sounds good! How do I enable the 75 second if no term detected option, or is this just "on" from installation now in Synchronet?

    ---
    * Synchronet * BBS for Amstrad computer users including CPC, PPC and PCW!
    * Origin: Vertrauen - [vert/cvs/bbs].synchro.net (1:103/705)
  • From Digital Man@1:103/705 to Simulant on Fri Mar 2 14:47:42 2018
    Re: Help with Security and BB
    By: Simulant to Daryl Stout on Fri Mar 02 2018 03:56 pm

    Re: Help with Security and BB
    By: Daryl Stout to MIKE POWELL on Thu Mar 01 2018 12:32 pm

    With Synchronet's login-js deal, plus my ever growing user.can and ip.can files, and SBBS's feature of where "if a terminal type is not detcted, the inactivity hangup is reduced to 75 seconds", that helps
    get rid of a lot of these bots.

    Hey Daryl, that feature sounds good! How do I enable the 75 second if no term detected option, or is this just "on" from installation now in Synchronet?

    Look in exec/login.js for this code:

    if(!console.autoterm) {
    console.inactivity_hangup *= .25;
    log(LOG_NOTICE, "Terminal not detected, reducing inactivity hang-up
    timeout to " + console.inactivity_hangup + " seconds");
    }

    If you have that code, you have it already. If not, update your login.js file from CVS.

    digital man

    This Is Spinal Tap quote #26:
    David St. Hubbins: They were still booing him when we came on stage.
    Norco, CA WX: 57.4oF, 76.0% humidity, 3 mph ESE wind, 0.00 inches rain/24hrs --- SBBSecho 3.03-Win32
    * Origin: Vertrauen - [vert/cvs/bbs].synchro.net (1:103/705)
  • From mark lewis@1:3634/12.73 to Simulant on Fri Mar 2 21:50:12 2018

    On 2018 Mar 02 15:56:12, you wrote to Daryl Stout:

    Hey Daryl, that feature sounds good! How do I enable the 75 second if
    no term detected option, or is this just "on" from installation now in Synchronet?

    it is automatic in the code...

    )\/(ark

    Always Mount a Scratch Monkey
    Do you manage your own servers? If you are not running an IDS/IPS yer doin' it wrong...
    ... CanYouComeHereAndFixMySpaceBarKey?ThankYou!
    ---
    * Origin: (1:3634/12.73)
  • From Mike Powell@1:103/705 to DIGITAL MAN on Fri Mar 2 19:24:00 2018
    Yeah, that sounds like something that was introduced with the latest cryptlib update and fixed (by now).

    Thanks! I will give it a shot the next chance I get and see what happens.

    ---
    * SLMR 2.1a * "When you have a rib-eye steak, you must floss it!"-Homer
    * Synchronet * CAPCITY2 * CCO BBS * capcity2.synchro.net:26
    * Origin: Vertrauen - [vert/cvs/bbs].synchro.net (1:103/705)
  • From Daryl Stout@1:103/705 to ISPYHUMANFLY on Sat Mar 3 01:55:00 2018
    2 - MRO of EOB has a captcha then whitelists the IP.

    I tried the CAPTCHA deal, but it kept locking up, so I decided not to use it.

    Sounds like the solution you have in place is a good one, too. So no loss.

    I would've liked to use the CAPTCHA. I have Argus set as the frontend,
    mainly for dial-up, but it has a TCP/IP daemon. If I enable that, I
    wonder if it'd require folks to press <ESC> to load the BBS. A bot
    wouldn't know what to do, and would eventually disconnect, thinking
    there's no response. But, Synchronet has it now where if a terminal type
    (i.e. ANSI) is not detected, it drops the inactivity timer to 75
    seconds, the drops them. Or the bot enters a name in the "trashcan
    file", and they get disconnected...or placed in the temporary banned IP
    list. When I note that, I modify the IP trashcan file, and make the ban permanent.

    Daryl

    ---
    * OLX 1.53 * You'll have no other Sysop before me (just kidding).
    * Synchronet * The Thunderbolt BBS - wx1der.dyndns.org
    * Origin: Vertrauen - [vert/cvs/bbs].synchro.net (1:103/705)
  • From Daryl Stout@1:103/705 to SIMULANT on Sat Mar 3 01:57:00 2018
    With Synchronet's login-js deal, plus my ever growing user.can and ip.can files, and SBBS's feature of where "if a terminal type is not detcted, the inactivity hangup is reduced to 75 seconds", that helps
    get rid of a lot of these bots.

    Hey Daryl, that feature sounds good! How do I enable the 75 second if no term S>detected option, or is this just "on" from installation now in Synchronet?

    This is with the beta versions of Synchronet 3.17 -- you can download
    the SBBS_DEV.ZIP and SBBS_RUN.ZIP from ftp://vert.synchro.net -- be sure
    to make a backup of your SBBS directories before you shut down the
    Synchronet Control Panel, to extract the files to apply the changes,
    then restart the BBS. See the README files in the archives for more
    details.

    Daryl

    ---
    * OLX 1.53 * You'll win the lottery, & spend the winnings on The Sysop
    * Synchronet * The Thunderbolt BBS - wx1der.dyndns.org
    * Origin: Vertrauen - [vert/cvs/bbs].synchro.net (1:103/705)
  • From Daryl Stout@1:103/705 to DIGITAL MAN on Sat Mar 3 02:08:00 2018
    Rob,

    Look in exec/login.js for this code:

    if(!console.autoterm) {
    console.inactivity_hangup *= .25;
    log(LOG_NOTICE, "Terminal not detected, reducing inactivity hang-up
    timeout to " + console.inactivity_hangup + " seconds");
    }

    Can that value be changed?? Such as to 30 seconds instead of 75??

    Daryl

    ---
    * OLX 1.53 * 100% of people who breathe, die.
    * Synchronet * The Thunderbolt BBS - wx1der.dyndns.org
    * Origin: Vertrauen - [vert/cvs/bbs].synchro.net (1:103/705)
  • From Digital Man@1:103/705 to Daryl Stout on Sun Mar 4 12:55:37 2018
    Re: Help with Security and BB
    By: Daryl Stout to DIGITAL MAN on Sat Mar 03 2018 02:08 am

    Rob,

    Look in exec/login.js for this code:

    if(!console.autoterm) {
    console.inactivity_hangup *= .25;
    log(LOG_NOTICE, "Terminal not detected, reducing inactivity hang-up
    timeout to " + console.inactivity_hangup + " seconds");
    }

    Can that value be changed?? Such as to 30 seconds instead of 75??

    Sure. The inactivity hang value is configurable in SCFG->Nodes->Node 1->Inactivity Disconnection (default 600 seconds). The login.js just reduces that number by 75%. So if you want a 30-second inactivity hang-up for non-ANSI connections, set that value to 120 seconds (25% of 120 is 30).

    digital man

    This Is Spinal Tap quote #29:
    I find lost luggage. I locate mandolin strings in the middle of Austin!
    Norco, CA WX: 59.3oF, 41.0% humidity, 2 mph NNW wind, 0.06 inches rain/24hrs --- SBBSecho 3.03-Win32
    * Origin: Vertrauen - [vert/cvs/bbs].synchro.net (1:103/705)