General Discussion

Reply

Level 6

Level 6
zinep
Posts: 1,493
Registered: ‎23-12-2008
Message 1 of 62 (390 Views)

Revenge of the botnet administrator?

[ Edited ]

Those of you with public servers know that intrusion attempts are a daily occurance. I can get hundreds of futile ssh login attempts each day on one server alone. "They" typically try the usual "root", "oracle", "mysql", "sql", "admin", etc logins.

 

Thoughout the years, I've had the philosophy that one shouldn't block any addresses, because letting them attempt attacks keeps one on one's toes.

 

However, recently I wanted to use regex(3) for something, and I decided to write a fail2ban:ish tool (but with a twist), so I started blocking addresses which appeared in authlog under the wrong circumstances.

 

I was slightly bemused to find that as I started blocking addresses, certain .. four-letter words started appearing in authlog, and grepping for such entries in the archived logs revealed no such entries. :smileyhappy:

 

...and just for the record, I think it was just a coincidence -- but the timing did make me laugh.

 

Anyone else seen these four-letter words used during intrusion attempts?

Please use plain text.

Re: Revenge of the botnet administrator?

All the time.
Please use plain text.
PatC_PSN
Posts: 14,069
Registered: ‎29-11-2008
Message 3 of 62 (354 Views)

Re: Revenge of the botnet administrator?

Thank God it isn't just me.

 

Please use plain text.

Re: Revenge of the botnet administrator?

even when I close my eyes.

Please use plain text.

Level 3

Level 3
dannyjt
Posts: 13,359
Registered: ‎04-07-2005
Message 5 of 62 (296 Views)

Re: Revenge of the botnet administrator?

Can you please explain what some of these things are.
TonightWeRide2.jpg
Please use plain text.

Re: Revenge of the botnet administrator?

:smileyvery-happy: I havent seen any profanity in our logs ! we used to get thousands of attacks every week very annoying . it helped when we disabled password auth did you try that ?

 

a few years ago on another job our admin one morning sent out a mail which said "lol ! Were getting attacked by some loser who couldnt begin to guess how lucky hes been with the user names so far !". around lunch came a new mail from him "i think something is wrong" and late in the afternoon came a panic mail were he said our network may have been compromised ! it was funny seeing him going from ridicule to suspicion to panic . :smileyvery-happy:

Please use plain text.
PatC_PSN
Posts: 14,069
Registered: ‎29-11-2008
Message 7 of 62 (252 Views)

Re: Revenge of the botnet administrator?


Globoux wrote:

 

a few years ago on another job our admin one morning sent out a mail which said "lol ! Were getting attacked by some loser who couldnt begin to guess how lucky hes been with the user names so far !". around lunch came a new mail from him "i think something is wrong" and late in the afternoon came a panic mail were he said our network may have been compromised ! it was funny seeing him going from ridicule to suspicion to panic . :smileyvery-happy:



It certainly does sound a riot in the world of IT system administration.

 

Please use plain text.

Re: Revenge of the botnet administrator?

Aren't people in IT required to at least be able to spell and use grammar correctly?

I know chimney sweeps who can write better.
Please use plain text.
PatC_PSN
Posts: 14,069
Registered: ‎29-11-2008
Message 9 of 62 (238 Views)

Re: Revenge of the botnet administrator?


Warren_Jeeves wrote:
Aren't people in IT required to at least be able to spell and use grammar correctly?

I know chimney sweeps who can write better.


I believe it's optional for most jobs these days, including English teacher.

 

Please use plain text.

Level 6

Level 6
zinep
Posts: 1,493
Registered: ‎23-12-2008
Message 10 of 62 (228 Views)

Re: Revenge of the botnet administrator?


dannyjt wrote:
Can you please explain what some of these things are.

 

I could if I knew what is unclear to you. Could you be more specific?

 

In essence, I'm going to need to use regular expressions in the programming language C not long from now, so I was looking for a small project just to get started with them (I've used plenty of regular expressions before, just not in C). There's a tool called fail2ban which automatically configures the firewall to blocks IP addresses of hosts which fail to do remote logins via ssh (Secure SHell). I wrote a tool which works sort-of like fail2ban using the regex library.

 

Previously when logins failed, I simply let them keep trying, but now they get blocked after three failed attempts. And that's when they started using four-letter words as user names.

 

It got me wondering if botnet administrators actually monitor failures. If one has a botnet, it's pretty trivial to detect if someone starts banning login bots, and it would be trivial to instruct other bots to start logging in using more .. creative user names.

Please use plain text.
This widget could not be displayed.
Announcements
Hello Anonymous!
Welcome to the Official PlayStation Forum

For the latest news and updates on what is happening in the PlayStation community, head over to our Announcements & Events forum. To post a message, you will need to Sign In to the Forums using your PLAYSTATION®Network Sign In ID and password. If you do not yet have a PSN account, just click here to register.





Store Highlights
Click any of the images below to be magically whisked to the SEN Store!



Looking for your local PlayStation Community?


Recent News