• Unleashed BBS

    From Daphantom@1:103/705 to All on Fri Dec 9 16:55:48 2016
    Hello
    It's been a long time since ive ran a bbs so i decided to try and get back into the bbs world back in the 80s and 90s i ran renegade and iniquity now i'm messing around with synchro. My handle is daphantom and my Name is Roy

    if anyone is interested in checking out the bbs the address is unleashed.remotewebaccess.com:85 for the web interface and :23 for telnet

    ---
    * Synchronet * Unleashed - unleashed.remotewebaccess.com
    * Origin: Vertrauen - vert.synchro.net (1:103/705)
  • From mark lewis@1:3634/12.73 to Daphantom on Sat Dec 10 08:24:46 2016

    09 Dec 16 16:55, you wrote to All:

    if anyone is interested in checking out the bbs the address is unleashed.remotewebaccess.com:85 for the web interface and :23 for
    telnet

    you may want to get off of 23 for telnet... stay off of 2323 as well as 5555 and 7547... these are all being probed by MIRAI and its variants looking for IoT devices to infest and add to their controllers' botnets... they're too stupid to recognize a BBS so they keep scanning and probing the BBSes on those ports all the time... operators not aware of this immediately suspect human hackers DOSing them or trying to hack them and this is the furthest thing from reality...

    )\/(ark

    Always Mount a Scratch Monkey
    Do you manage your own servers? If you are not running an IDS/IPS yer doin' it wrong...
    ... We can't have a crisis today, my schedule is already full.
    ---
    * Origin: (1:3634/12.73)
  • From Daphantom@1:103/705 to mark lewis on Mon Dec 12 13:46:20 2016
    Re: Unleashed BBS
    By: mark lewis to Daphantom on Sat Dec 10 2016 08:24 am

    Thanks for letting me know about the ports i was wondering why i always had stange ips tring to log in

    ---
    * Synchronet * Unleashed - unleashed.remotewebaccess.com
    * Origin: Vertrauen - vert.synchro.net (1:103/705)
  • From Nightfox@1:103/705 to mark lewis on Mon Dec 12 16:38:06 2016
    you may want to get off of 23 for telnet... stay off of 2323 as well as 5555 and 7547... these are all being probed by MIRAI and its variants looking for IoT devices to infest and add to their controllers' botnets... they're too stupid to recognize a BBS so they keep scanning and probing the BBSes on those ports all the time... operators not aware of this immediately suspect human hackers DOSing them or trying to hack them and this is the furthest thing from reality...

    I doubt those bots are doing anything really harmful, besides perhaps keeping a node busy for a moment. Sysop tend to report a dramatic drop in users if they change away from the default/standard ports.

    Nightfox

    ---
    * Synchronet * Digital Distortion: digitaldistortionbbs.com
    * Origin: Vertrauen - vert.synchro.net (1:103/705)
  • From mark lewis@1:3634/12.73 to Nightfox on Mon Dec 12 20:56:24 2016

    12 Dec 16 16:38, you wrote to me:

    you may want to get off of 23 for telnet... stay off of 2323 as well as
    5555 and 7547... these are all being probed by MIRAI and its variants
    looking for IoT devices to infest and add to their controllers'
    botnets... they're too stupid to recognize a BBS so they keep scanning
    and probing the BBSes on those ports all the time... operators not
    aware of this immediately suspect human hackers DOSing them or trying
    to hack them and this is the furthest thing from reality...

    I doubt those bots are doing anything really harmful, besides perhaps keeping a node busy for a moment.

    on a BBS, you are right... in the real world, though, they are hijacking IoT devices and taking over routers... MIRAI really opened up a new world and the release of the code has enabled a lot of variants to come along and build on the new method as well as exposing a lot more devices to being hacked...

    )\/(ark

    Always Mount a Scratch Monkey
    Do you manage your own servers? If you are not running an IDS/IPS yer doin' it wrong...
    ... Brunswick stew - Seems strange having a side of meat with meat.
    ---
    * Origin: (1:3634/12.73)
  • From kk4qbn@1:103/705 to Nightfox on Tue Dec 13 19:08:08 2016
    Re: Unleashed BBS
    By: Nightfox to mark lewis on Mon Dec 12 2016 04:38 pm

    I doubt those bots are doing anything really harmful, besides perhaps keeping a node busy for a moment. Sysop tend to report a dramatic drop in users if they change away from the default/standard ports.

    Correct, and the bots get no further than un/pw and with the new IP filtering laws that can be set it keeps the nodes clear, even if the bots are actively hammering the system, I've got mine set to ban an IP for * minutes if a client fails to authenticate 3 times, then after ban, if that client fails 5 times it puts it in the ip filter (at least I believe thats what its doing) all I know is my nodes stay clear most the time now unless it is a real user, every now and then I'll get 3 nodes fire up at once, then they are cleared out quicly when the user fails to authenticate in X amount of seconds.

    --

    Tim Smith (KK4QBN)
    KK4QBN BBS

    ---
    * Synchronet * KK4QBN BBS - (706)422-9538 - kk4qbn.synchro.net, Chatsworth GA US
    * Origin: Vertrauen - vert.synchro.net (1:103/705)
  • From Tony Langdon@3:633/410 to kk4qbn on Wed Dec 14 16:33:00 2016
    kk4qbn wrote to Nightfox <=-

    I doubt those bots are doing anything really harmful, besides perhaps keeping a node busy for a moment. Sysop tend to report a dramatic drop in users if they change away from the default/standard ports.

    Correct, and the bots get no further than un/pw and with the new IP filtering laws that can be set it keeps the nodes clear, even if the

    Yeah, it's just the annoyance factor. I'd prefer to stay on standard ports too. The less users have to change things, the better.

    bots are actively hammering the system, I've got mine set to ban an IP
    for * minutes if a client fails to authenticate 3 times, then after
    ban, if that client fails 5 times it puts it in the ip filter (at least
    I believe thats what its doing) all I know is my nodes stay clear most
    the time now unless it is a real user, every now and then I'll get 3
    nodes fire up at once, then they are cleared out quicly when the user fails to authenticate in X amount of seconds.

    Yet another reason to upgrade to 3.17. :)


    ... Blessed be the pessimist for he hath bought insurance.
    --- MultiMail/Win32 v0.49
    * Origin: Freeway BBS - freeway.apana.org.au (3:633/410)