• Another system using DIGDIST?

    From Nightfox@1:103/705 to All on Sat Mar 10 20:15:59 2018
    In my FTP Server window on my BBS, I noticed a system logged in apparently using the name 'digdist', but since I have no user on my system with that name, it wasn't recognized. DIGDIST is my BBS's QWK ID though.. So I'm wondering if another sysop is trying to use my QWK ID?

    This is what I saw in my FTP Server window:
    3/10 08:08:45p 1600 CTRL thread terminated (0 clients and 1 threads remain, 209 served)
    3/10 08:09:20p 1224 CTRL connection accepted from: 64.233.133.18 port 41593 3/10 08:09:20p 1224 Hostname: cordersvh.ritternet.com
    3/10 08:09:20p 1224 !UNKNOWN USER: 'digdist'
    3/10 08:09:25p 1224 Socket closed by peer on receive (line 1170)


    I tried to load cordersvh.ritternet.com in my web browser, and also tried telnetting to it (as well as telnetting to the IP), but it wouldn't connect. So hopefully this isn't a real BBS system.. Still makes me wonder what's going on..

    Nightfox

    ---
    * Synchronet * Digital Distortion: digitaldistortionbbs.com
    * Origin: Vertrauen - [vert/cvs/bbs].synchro.net (1:103/705)
  • From echicken@1:103/705 to Nightfox on Sun Mar 11 00:58:05 2018
    Re: Another system using DIGDIST?
    By: Nightfox to All on Sat Mar 10 2018 20:15:59

    using the name 'digdist', but since I have no user on my system with that name, it wasn't recognized. DIGDIST is my BBS's QWK ID though.. So I'm

    Perhaps it was reaching you as 'digdist.synchro.net' and just trying that username since it's the same as the subdomain.

    ---
    echicken
    electronic chicken bbs - bbs.electronicchicken.com - 416-273-7230
    * Synchronet * electronic chicken bbs - bbs.electronicchicken.com
    * Origin: Vertrauen - [vert/cvs/bbs].synchro.net (1:103/705)
  • From Digital Man@1:103/705 to Nightfox on Sun Mar 11 01:14:29 2018
    Re: Another system using DIGDIST?
    By: Nightfox to All on Sat Mar 10 2018 08:15 pm

    In my FTP Server window on my BBS, I noticed a system logged in apparently using the name 'digdist', but since I have no user on my system with that name, it wasn't recognized. DIGDIST is my BBS's QWK ID though.. So I'm wondering if another sysop is trying to use my QWK ID?

    This is what I saw in my FTP Server window:
    3/10 08:08:45p 1600 CTRL thread terminated (0 clients and 1 threads remain, 209 served)
    3/10 08:09:20p 1224 CTRL connection accepted from: 64.233.133.18 port 41593 3/10 08:09:20p 1224 Hostname: cordersvh.ritternet.com
    3/10 08:09:20p 1224 !UNKNOWN USER: 'digdist'
    3/10 08:09:25p 1224 Socket closed by peer on receive (line 1170)


    I tried to load cordersvh.ritternet.com in my web browser, and also tried telnetting to it (as well as telnetting to the IP), but it wouldn't connect. So hopefully this isn't a real BBS system.. Still makes me wonder what's going on..

    Likely just a bot. It found digdist.* (.synchro.net?) and just tried to brute force a login at that IP.

    digital man

    This Is Spinal Tap quote #14:
    The Boston gig has been cancelled. [Don't] worry, it's not a big college town. Norco, CA WX: 55.0oF, 98.0% humidity, 1 mph SE wind, 0.55 inches rain/24hrs
    --- SBBSecho 3.03-Win32
    * Origin: Vertrauen - [vert/cvs/bbs].synchro.net (1:103/705)
  • From Jay Allshire@1:120/302 to Nightfox on Sun Mar 11 11:35:59 2018
    Re: Another system using DIGDIST?
    By: Nightfox to All on Sat Mar 10 2018 08:15 pm

    I tried to load cordersvh.ritternet.com in my web browser, and also tried telnetting to it (as well as telnetting to the IP), but it wouldn't connect. So hopefully this isn't a real BBS system.. Still makes me wonder what's going on..


    You could always put that address in your host.can and that would stop it. Sounds like it is not a valid system.


    Mojo
    --- SBBSecho 3.03-Win32
    * Origin: Mojo's World BBS - mojo.synchro.net (1:120/302)
  • From KK4QBN@1:103/705 to Nightfox on Sun Mar 11 20:33:36 2018
    Re: Another system using DIGDIST?
    By: Nightfox to All on Sat Mar 10 2018 20:15:59

    This is what I saw in my FTP Server window:
    3/10 08:08:45p 1600 CTRL thread terminated (0 clients and 1 threads remain, 209 served)
    3/10 08:09:20p 1224 CTRL connection accepted from: 64.233.133.18 port 41593 3/10 08:09:20p 1224 Hostname: cordersvh.ritternet.com
    3/10 08:09:20p 1224 !UNKNOWN USER: 'digdist'
    3/10 08:09:25p 1224 Socket closed by peer on receive (line 1170)


    It's probably a BOT trying to to force a password from your FTP server, I'd ban that IP Address, or at least investigate and do a little "reverse hacking" to find if it is a real person or some sort of IOT device.

    --

    Tim Smith (KK4QBN)
    KK4QBN BBS

    ---
    * Synchronet * KK4QBN BBS - kk4qbn.com - kk4qbn.synchro.net - Chatsworth GA USA
    * Origin: Vertrauen - [vert/cvs/bbs].synchro.net (1:103/705)