• FTP Virus attemp

    From kk4qbn@1:103/705 to All on Thu Dec 15 10:08:12 2016
    Got an IP HAMMERING my ftp server trying to upload the "photo.scr" virus,

    Here is the IP for anyone who would like it


    61.16.130.150

    So far they have hit EVERY directory trying to upload this trash, ill ban their IP after I get finished watching him.

    also over the last couple days I've noticed someone (or a bot) on my SMTP server trying to login as my username with brute force password attempts, so far two different IPs

    112.84.231.185
    112.83.229.77

    I know these idiots can't do anything, it just makes me sick to know resources are wasted to even allow them any bits of bandwidth..

    --

    Tim Smith (KK4QBN)
    KK4QBN BBS

    ---
    * Synchronet * KK4QBN BBS - (706)422-9538 - kk4qbn.synchro.net, Chatsworth GA US
    * Origin: Vertrauen - vert.synchro.net (1:103/705)
  • From mark lewis@1:3634/12.73 to kk4qbn on Thu Dec 15 12:37:58 2016

    15 Dec 16 10:08, you wrote to All:

    Got an IP HAMMERING my ftp server trying to upload the "photo.scr" virus,

    Here is the IP for anyone who would like it

    61.16.130.150

    So far they have hit EVERY directory trying to upload this trash, ill ban their IP after I get finished watching him.

    you could file an abuse report on it... you'll probably have to provide log evidence... here's the whois record...

    $ whois 61.16.130.150
    % [whois.apnic.net]
    % Whois data copyright terms http://www.apnic.net/db/dbcopyright.html

    % Information related to '61.16.128.0 - 61.16.143.255'

    inetnum: 61.16.128.0 - 61.16.143.255
    netname: TTSLMEIS-IN
    descr: TTSL-ISP DIVISION
    country: IN
    admin-c: TTLC1-AP
    tech-c: TTLC1-AP
    mnt-by: APNIC-HM
    mnt-lower: MAINT-IN-TTSLMEIS
    mnt-routes: MAINT-IN-TTSLMEIS
    mnt-irt: IRT-TTSLMEIS-IN
    status: ALLOCATED PORTABLE
    remarks: -------------------------------------------------------- remarks: To report network abuse, please contact mnt-irt
    remarks: For troubleshooting, please contact tech-c and admin-c
    remarks: Report invalid contact via www.apnic.net/invalidcontact remarks: -------------------------------------------------------- changed: hm-changed@apnic.net 20130416
    source: APNIC

    irt: IRT-TTSLMEIS-IN
    address: TATA TELESERVICES LIMITED
    address: Voltas Premises,
    address: A, E & F Blocks,
    address: Chinchpokli Mumbai
    e-mail: ip.abuse@tatatel.co.in
    abuse-mailbox: ip.abuse@tatatel.co.in
    admin-c: TTLC1-AP
    tech-c: TTLC1-AP
    auth: # Filtered
    mnt-by: MAINT-IN-TTSLMEIS
    changed: ip.abuse@tatatel.co.in 20101109
    source: APNIC

    role: TATA TELESERVICES LTD -- CDMA - network administr
    address: D26/2 TTC INDUSTRIAL AREA MIDC SANPADA
    country: IN
    phone: +91 2267438600
    fax-no: +91 22-67438752
    e-mail: sandeep.malik@tatatel.co.in
    admin-c: SM2088-AP
    tech-c: SM2088-AP
    nic-hdl: TTLC1-AP
    mnt-by: MAINT-TATAINDICOM-IN
    changed: hm-changed@apnic.net 20100831
    source: APNIC

    % Information related to '61.16.130.0/24AS45820'

    route: 61.16.130.0/24
    descr: TTSL
    origin: AS45820
    country: IN
    mnt-lower: MAINT-IN-TTSLMEIS
    mnt-routes: MAINT-IN-TTSLMEIS
    mnt-by: MAINT-IN-TTSLMEIS
    changed: Vivek.puri@tatatel.co.in 20140326
    source: APNIC

    % This query was served by the APNIC Whois Service version 1.69.1-APNICv1r0 (UNDEFINED)



    also over the last couple days I've noticed someone (or a bot) on my
    SMTP server trying to login as my username with brute force password attempts, so far two different IPs

    112.84.231.185
    112.83.229.77

    both out of china... probably got their hands on a data package from one of the
    security breeches... especially if they have your user name and are trying to beat a password out of it... i just wish that sbbs allowed for longer passwords
    than 8 characters... granted, sure, with numbers and letters (not case sensitive) that's "only" 2.82110990746e+12 possible combinations but still... i
    don't know if characters in addition to numbers and letters are allowed... if so, they greatly increase the possible combinations available...

    I know these idiots can't do anything, it just makes me sick to know resources are wasted to even allow them any bits of bandwidth..

    that's what the internet is for, isn't it? ;)

    )\/(ark

    Always Mount a Scratch Monkey
    Do you manage your own servers? If you are not running an IDS/IPS yer doin' it wrong...
    ... Back when I was a mere lad, we carved our own ICs out of wood.
    ---
    * Origin: (1:3634/12.73)
  • From kk4qbn@1:103/705 to mark lewis on Thu Dec 15 14:45:58 2016
    Re: FTP Virus attemp
    By: mark lewis to kk4qbn on Thu Dec 15 2016 12:37 pm

    you could file an abuse report on it... you'll probably have to provide log evidence... here's the whois record...

    Thanks, I'll more than likely do that.

    112.84.231.185
    112.83.229.77
    both out of china... probably got their hands on a data package from one of the security breeches... especially if they have your user name and are trying to beat a password out of it... i just wish that sbbs allowed for longer passwords than 8 characters... granted, sure, with numbers and letters (not case sensitive) that's "only" 2.82110990746e+12 possible combinations but still... i don't know if characters in addition to numbers and letters are allowed... if so, they greatly increase the possible combinations available...

    Yeah, I have never seen such stupid "brute force" attack though, It almost acted as if it was human instead of a computer, within a 15 minute period they only tied about 5 passwords, and they were far from random.. almost as if the person was trying to "guess" what I would think of instead of just trying random combinations..

    I know these idiots can't do anything, it just makes me sick to know
    resources are wasted to even allow them any bits of bandwidth..

    that's what the internet is for, isn't it? ;)

    I guess... lol..

    --

    Tim Smith (KK4QBN)
    KK4QBN BBS

    ---
    * Synchronet * KK4QBN BBS - (706)422-9538 - kk4qbn.synchro.net, Chatsworth GA US
    * Origin: Vertrauen - vert.synchro.net (1:103/705)
  • From Nightfox@1:103/705 to mark lewis on Thu Dec 15 15:23:16 2016
    Re: FTP Virus attemp
    By: mark lewis to kk4qbn on Thu Dec 15 2016 12:37:58

    I know these idiots can't do anything, it just makes me sick to know
    resources are wasted to even allow them any bits of bandwidth..

    that's what the internet is for, isn't it? ;)

    That, and cats and porn, right? ;)

    Nightfox

    ---
    * Synchronet * Digital Distortion: digitaldistortionbbs.com
    * Origin: Vertrauen - vert.synchro.net (1:103/705)
  • From Robert E Starr JR@1:340/400 to kk4qbn on Thu Dec 15 16:26:12 2016
    Got an IP HAMMERING my ftp server trying to upload the "photo.scr" virus,

    was tryed here (a week to a month back), thank god I don't allow guest upload

    Here is the IP for anyone who would like it


    61.16.130.150

    don't remember the ip number

    So far they have hit EVERY directory trying to upload this trash, ill ban their IP after I get finished watching him.

    same here

    also over the last couple days I've noticed someone (or a bot) on my SMTP server trying to login as my username with brute force password attempts, so far two different IPs

    112.84.231.185
    112.83.229.77

    I know these idiots can't do anything, it just makes me sick to know resources are wasted to even allow them any bits of bandwidth..

    yep, I do have a big ip number list, it kind-of hard to get off that list, on my system


    ---

    Rob Starr
    Lord Time SysOp of
    Time Warp of the Future BBS
    Telnet://Time.Darktech.Org:24 or
    Telnet://Time.Synchro.Net:24 (qwk or ftn & e-mail)
    ICQ # 11868133 or # 70398519 Jabber : lordtime2000@gmail.com
    Yahoo : lordtime2000 AIM : LordTime20000 Astra : lord_time
    X-Box : Lord Time 2000 oovoo : lordtime2000
    * Origin: Time Warp of the Future BBS - Home of League 10 (1:340/400)