TIP: Click on subject to list as thread! ANSI
echo: bbbs.english
to: JEFF SMITH
from: JANIS KRACHT
date: 2016-05-11 02:58:00
subject: Telnet Login Attacks?

>>> Any tips or suggestions as to a way to limit/avoids telnet login
>>> attacks on BBBS?

>>> Lately I have been getting numerious telnet login attempts by
>>> IP's that reversely resolve to Asian countries. The same IP will
>>> try to login to all available nodes. No actual login is
>>> attempted. Each open node will sit open at the login name
>>> prompt.I have been adding up to 5 IP's at a time to the INET.BBB
>>> file. Which then blocks those IP's. But there are plenty of other
>>> IP's. :-)

>> Yeah, I think that this is a problem for every one of us that runs a
>> BBS.  It got to the poing where I have inbound telnet and binkp
>> connections running on only a certain group of nodes and web services
>> running on another group of nodes.


> I posted the above message shortly after I setup BBBS and noticed a rash
> of "root" and "sysop" login attempts. As well as DOS (Denial of Service)
> attempts by trying to login to all available nodes from the same IP. I
> quickly configured BBBS to reject logins using invvalid user info. As well
> as blocking DOS Ip's for a time. At one point I had some 5000 IP's that
> were being blocked. That type of activity has dimished considerably over
> the last year.


I took care of the problem with iptables.  It's late now, I'll post what I did
tomorrow.  It's easy, you'll see, and it works really well because you specify
the ports you want to 'protect'.

Take care,
Janis

--- BBBS/Li6 v4.10 Dada-2
* Origin: Prism bbs (1:261/38)

SOURCE: echomail via QWK@docsplace.org

Email questions or comments to sysop@ipingthereforeiam.com
All parts of this website painstakingly hand-crafted in the U.S.A.!
IPTIA BBS/MUD/Terminal/Game Server List, © 2025 IPTIA Consulting™.