| TIP: Click on subject to list as thread! | ANSI |
| echo: | |
|---|---|
| to: | |
| from: | |
| date: | |
| subject: | Unwanted connections to port 23. |
On 2017 Jun 12 00:54:18, you wrote to All: Ig> I've since recently put my board back on port 23... and I now recall Ig> why I took it off of it. I keep getting all of these connections from Ig> hackers, I take it. they are not hackers... at best they are skiddies but in reality, it is the MIRAI botnets trying to see if your system is a vulnerable IoT (Internet of Things) device like an IP Camera or a DVR or smart TV and similar... anything that has default login credentials hardcoded in it... Ig> Anyone know of a way to filter these bad connections? there is none, really... you have to let them connect and then dump them based on the data they shove at you without waiting for any prompts... yes, that's right... they do not look for and respond to any sort of login prompts... they just start spewing their login stuff followed by the shell commands to fire off busybox... Ig> I've tried Janis' iptables suggestion, but it isn't working. intrusion detection systems are the only things i've seen that come close but the connection and attempted login still has to take place... the *ONLY* other option is to get off of port 23 and the other few that MIRAI specifically targets... that includes the default SSH port as well... )\/(ark Always Mount a Scratch Monkey Do you manage your own servers? If you are not running an IDS/IPS yer doin' it wrong... ... WANTED: Meaningful overnight relationship. ---* Origin: (1:3634/12.73) SEEN-BY: 103/705 116/116 123/141 129/215 135/300 140/1 154/10 20 30 40 700 SEEN-BY: 203/0 221/6 227/51 201 229/310 240/1661 5832 249/303 261/38 280/464 SEEN-BY: 280/5003 292/854 310/31 340/800 423/120 633/267 280 712/848 770/1 SEEN-BY: 2320/100 3634/12 15 24 27 50 @PATH: 3634/12 154/10 280/464 712/848 633/267 |
|
| SOURCE: echomail via fidonet.ozzmosis.com | |
Email questions or comments to sysop@ipingthereforeiam.com
All parts of this website painstakingly hand-crafted in the U.S.A.!
IPTIA BBS/MUD/Terminal/Game Server List, © 2025 IPTIA Consulting™.