| TIP: Click on subject to list as thread! | ANSI |
| echo: | |
|---|---|
| to: | |
| from: | |
| date: | |
| subject: | Telnet at Prism |
03 Oct 16 15:10, you wrote to Janis Kracht:
JK>> If you've been 'locked out' of the telnet server and you need to use
JK>> it, let me know. I'll check your ip wasn't marked as 'bad'. I've
JK>> been trapping large numbers of nodes here who seem to just
JK>> log-on/log-off
BR> I'm getting quite a few myself, probably part of a new Telnet
"attack"
BR> which I am getting from dozens of different IP addresses weekly that
BR> try to
have you seen the links i shared earlier? i dropped them in several
conferences by cross posting a reply to janis...
BR> login with the following sequence:
BR> === Snip ===
BR> Unknown
BR> ENABLE
BR> SYSTEM
BR> SHELL
BR> === Snip ===
actually, it is roughly two or three months old... the first portion (which
you left one out) is a user name... your "unknown" is actually
the password but not that sequence of letters... they are transmitted
normal-like with the CFLF after them... the rest of the string sequences
you posted are each followed by a nul (0x00) character and then the CRLF...
you're missing the last two parts, "sh" and a call to busybox
with a command name which is the main tracking and detection signature...
BR> I am blocking some with multiple hits, but I ignore the rest {chuckle}
the order of the above was different in the beginning... there is always
the user name and password but one or the other may be empty (just a CRLF
sequence)... it started as only three commands followed by the call to
busybox with its command name... then it changed to four commands with
"enable" being first as you show above...
)\/(ark
Always Mount a Scratch Monkey
Do you manage your own servers? If you are not running an IDS/IPS yer doin'
it wrong...
... Correction does much, but encouragement does more.
---
* Origin: (1:3634/12.73)SEEN-BY: 18/200 19/33 34/999 90/1 116/18 120/302 331 123/500 128/187 140/1 SEEN-BY: 218/700 222/2 230/150 240/1120 249/303 250/1 261/38 100 266/404 SEEN-BY: 267/155 280/1027 282/1031 1056 292/907 908 320/119 219 340/400 393/68 SEEN-BY: 393/70 633/267 280 640/384 712/620 848 770/1 801/161 189 2320/100 @PATH: 3634/12 123/500 261/38 712/848 633/267 |
|
| SOURCE: echomail via fidonet.ozzmosis.com | |
Email questions or comments to sysop@ipingthereforeiam.com
All parts of this website painstakingly hand-crafted in the U.S.A.!
IPTIA BBS/MUD/Terminal/Game Server List, © 2025 IPTIA Consulting™.