• Hacking

    From Bcw142@46:1/138 to All on Sun May 29 11:13:17 2016
    Seem to be under major attack today from hackers or bots or both. Started at 8:31am EDT and still going. Logs make it look like several countries but I figure it's a group and botnet. Took out nweb from Firefox, but it sill works from some other browsers (Pi default works fine). Example:
    May 29 11:34:18 0 Connection from Korea, Republic of
    May 29 11:34:18 0 Connect: 14.44.100.9 (Unknown)
    May 29 11:45:47 0 Connection from Viet Nam
    May 29 11:45:47 0 Connect: 117.5.141.192 (localhost)
    May 29 11:57:29 0 Connection from Romania
    May 29 11:57:29 0 Connect: 5.12.197.98 (5-12-197-98.residential.rdsnet.ro)
    May 29 11:59:25 0 Connection from China
    May 29 11:59:25 0 Connect: 113.238.16.4 (Unknown)
    May 29 11:59:39 0 Connection from Pakistan
    May 29 11:59:39 0 Connect: 182.186.185.18 (Unknown)
    May 29 12:07:51 0 Connection from Taiwan, Province of China
    May 29 12:07:51 0 Connect: 218.161.109.222
    (218-161-109-222.HINET-IP.hinet.net)
    Quite the attack huh? Mystic 1.11 is holding up just fine. I rebooted my
    modem, router, and BBS twice but still under attack so that didn't change anything. Just took out my Mythtv media server- likely have to reset that on the mythtv backend. Well just to let you know what's up on my end, doesn't
    seem to be effecting much on mystic (except big logs). Good work g00r00 ;)

    --- Mystic BBS v1.10 (Linux)
    * Origin: Orbit BBS - Opp, AL USA | orbitbbs.ddns.net (46:1/138)
  • From Al@46:1/161 to Bcw142 on Sun May 29 17:15:51 2016
    On 05/29/16, Bcw142 said the following...

    Seem to be under major attack today from hackers or bots or both.

    I've seen that today too..

    Quite the attack huh? Mystic 1.11 is holding up just fine. I rebooted my modem, router, and BBS twice but still under attack so that didn't change anything. Just took out my Mythtv media server- likely have to reset
    that on the mythtv backend. Well just to let you know what's up on my
    end, doesn't seem to be effecting much on mystic (except big logs). Good work g00r00 ;)

    I just went and had a look at the telnet server in mis. There are two
    different IPs from vitrtua.com.br trying to connect but there connection ettempts are up.. :)

    Ttyl :-),
    Al

    --- Mystic BBS v1.12 A16 (Linux)
    * Origin: The Rusty MailBox - Penticton, BC Canada (46:1/161)
  • From Bcw142@46:1/138 to Al on Tue May 31 10:13:15 2016
    Interesting (that you were being hacked too). I guess that means 'they' had some time to hack. I found that private browsing on most browsers including firefox got through the problems they caused and when they stopped (or slowed way down) things worked normally again by themselves - I didn't need to reset anything. They slowly dropped the number of attempts per minute when they figured out they were banned and then slowed, and slowed and pretty much stopped now (5/31).

    --- Mystic BBS v1.10 (Linux)
    * Origin: Orbit BBS - Opp, AL USA | orbitbbs.ddns.net (46:1/138)
  • From Al@46:1/161 to Bcw142 on Tue May 31 22:21:31 2016
    On 05/31/16, Bcw142 said the following...

    Interesting (that you were being hacked too). I guess that means 'they' had some time to hack. I found that private browsing on most browsers including firefox got through the problems they caused and when they stopped (or slowed way down) things worked normally again by themselves
    - I didn't need to reset anything. They slowly dropped the number of attempts per minute when they figured out they were banned and then slowed, and slowed and pretty much stopped now (5/31).

    Yep, 'they' do it to everybody. Sysops notice it because they have port 23
    (and possibly others) open but these port scanners will attempt to access anything they find open. Most people don't have any of these ports open so it is not a problem generally.

    Mystic handles the situation well though. I just had a look at my telnet
    server in mis and it is quiet now but at times I have two or three bots
    pinging but eventually they get blocked.

    Ttyl :-),
    Al

    --- Mystic BBS v1.12 A16 (Linux)
    * Origin: The Rusty MailBox - Penticton, BC Canada (46:1/161)