iDRY Vacuum Kilns

Sponsors:

Getting hammered by bots. Working on it

Started by Jeff, December 08, 2017, 10:42:40 AM

Previous topic - Next topic

0 Members and 1 Guest are viewing this topic.

Jeff

The Forestry Forum is suffering from a DOS attack this morning. I am working on it trying to fend them off. I apologize for the intermittent  connectivity.
Just call me the midget doctor.
Forestry Forum Founder and Chief Cook and Bottle Washer.

Commercial circle sawmill sawyer in a past life for 25yrs.
Ezekiel 22:30

Jeff

I HATE BOTS SPAMMERS SCAMMERS AND WHOEVER CAUSES ALL THESE PROBLEMS!

Okay, that made me feel better. :)
Just call me the midget doctor.
Forestry Forum Founder and Chief Cook and Bottle Washer.

Commercial circle sawmill sawyer in a past life for 25yrs.
Ezekiel 22:30

chet

Much better connectivity up here in Yooper land now.   8)
I am a true TREE HUGGER, if I didnt I would fall out!  chet the RETIRED arborist

Kbeitz

To bad you can't just send them back from where they come from...
Collector and builder of many things.
Love machine shop work
and Wood work shop work
And now a saw mill work

Jeff

I'm pretty sure they are from Hell, so that ain't a bad plan.
Just call me the midget doctor.
Forestry Forum Founder and Chief Cook and Bottle Washer.

Commercial circle sawmill sawyer in a past life for 25yrs.
Ezekiel 22:30

Don P

Tureakistan  :D
Yup its all messed up out where the electrons wear out  :D
I was blamin the snow, looks like our first real one of the year.

Got a scam phone call the other day from "windows technical support". I invited him to come on over, bring a bucket and rags and clean my windows. I kept telling him the password was Windex but he didn't seem to understand  ??? Judging from the sound of traffic outside his mud hut I'm not really sure he knows what a window is, of any kind.

Grizzly

Boss, you need to go get a mug of some good herbal tea, maybe set up a aromatherapy thing, and do some goat yoga, and all that stress is just supposed to melt away. Soothing and peaceful is what I hear.....   well ok. It was a great thought though!!   :D :D :D
2011 - Logmaster LM-2 / Chinese wheel loader
Jonsered saws - 2149 - 111S - 90?
2000 Miners 3-31 Board Edger

21incher

I wonder if the hack the forum Christmas contest is seen as a challenge to the hackers. :-\
Thanks for all your hard work behind the scenes  keeping us safe. thumbs-up thumbs-up
Hudson HFE-21 on a custom trailer, Deere 4100, Kubota BX 2360, Echo CS590 & CS310, home built wood splitter, home built log arch, a logrite cant hook and a bread machine. And a Kubota Sidekick with a Defective Subaru motor.

Jim_Rogers

Quote from: 21incher on December 08, 2017, 12:38:07 PM
I wonder if the hack the forum Christmas contest is seen as a challenge to the hackers. :-\
Thanks for all your hard work behind the scenes  keeping us safe. thumbs-up thumbs-up

x2
Whatever you do, have fun doing it!
Woodmizer 1994 LT30HDG24 with 6' Bed Extension

Jeff

 :D no. They are not after the website, they are after the server. They have no idea about the contest. They are not looking at anything on pages.  That's actually kinda like a thief trying to steal a car because there might be a pack of gum locked in the trunk. :)
Just call me the midget doctor.
Forestry Forum Founder and Chief Cook and Bottle Washer.

Commercial circle sawmill sawyer in a past life for 25yrs.
Ezekiel 22:30

Roxie

Quote from: Chet on December 08, 2017, 11:08:05 AM
Much better connectivity up here in Yooper land now.   8)

If he that smelt it dealt it, let's blame Chet.   :D
Say when

Ljohnsaw

Sure would be nice if the ISP's would do their job :-X (block malicious activity) or if we could collectively just reverse DOS them! ;) :D
John Sawicky

Just North-East of Sacramento...

SkyTrak 9038, Ford 545D FEL, Davis Little Monster backhoe, Case 16+4 Trencher, Home Built 42" capacity/36" cut Bandmill up to 54' long - using it all to build a timber frame cabin.

Jeff

It's not that easy.  The bad guys are continuously coming at you from compromised systems. You block one I.P., they come at you from another. It might even be your home computer is the malicious host and you might never know it other than you think it might be running slow at times.
Just call me the midget doctor.
Forestry Forum Founder and Chief Cook and Bottle Washer.

Commercial circle sawmill sawyer in a past life for 25yrs.
Ezekiel 22:30

POSTON WIDEHEAD

This week in Mecklenburg County where Charlotte N.C. is located, Iraq or Iran bots sent a worm email.
Somebody opened it.
Now the whole county server is being held hostage for $23,000 in ransom....that is 2 - bit coins.
The time ran out and the county didn't pay. Now the ransom is up to $75,000 I think.
The county is trying to bring back the files from a backup system and it may takes months.

No taxes can be paid because no one knows what is owed at this time.  :D

The older I get I wish my body could Re-Gen.

Ljohnsaw

Quote from: Jeff on December 08, 2017, 03:10:02 PM
It's not that easy.  The bad guys are continuously coming at you from compromised systems. You block one I.P., they come at you from another. It might even be your home computer is the malicious host and you might never know it other than you think it might be running slow at times.
YEARS ago, I went up to Portland, Oregon to attend a special class.  We were being trained on a fancy full-size PC with some unique hardware.  There were about 30 or 40 of us in the hotel ballroom at the conference.  It was required that we all log into a particular site to get some credentials so we could configure the computers.  The hotel's router/firewall saw that there was a sudden "target" being "attacked" by our machines and we were blocked from reaching it.  It took the hotel staff about an hour o figure out what was going on. :D
John Sawicky

Just North-East of Sacramento...

SkyTrak 9038, Ford 545D FEL, Davis Little Monster backhoe, Case 16+4 Trencher, Home Built 42" capacity/36" cut Bandmill up to 54' long - using it all to build a timber frame cabin.

thecfarm

I was blaming all this on my Dinosaur Computer
Model 6020-20hp Manual Thomas bandsaw,TC40A 4wd 40 hp New Holland tractor, 450 Norse Winch, Heatmor 400 OWB,YCC 1978-79

Peter Drouin

Is there a way to send them a virus back to them?
I mean the  smiley_devil back at them. smiley_smash
A&P saw Mill LLC.
45' of Wood Mizer, cutting since 1987.
License NH softwood grader.

WDH

Peter,

They would not know pecan even if the met one in the road.   smiley_devil   :D :D. 
Woodmizer LT40HDD35, John Deere 2155, Kubota M5-111, Kubota L2501, Nyle L53 Dehumidification Kiln, and a passion for all things with leafs, twigs, and bark.  hamsleyhardwood.com

Peter Drouin

There must be a way to disable them when they try to get in. Maybe leave a hole, door, easy to hack. And when they go in, there pc fills with junk. One less, next, :D
I don't know, just thinking,
A&P saw Mill LLC.
45' of Wood Mizer, cutting since 1987.
License NH softwood grader.

paul case

I had nuttin to do with it being filled with junk.

Keep yer chin up boss, You are doing good!

https://www.youtube.com/watch?v=AW1Hj4eSlIA

PC
life is too short to be too serious. (some idiot)
2013 LT40SHE25 and Riehl edger,  WM 94 LT40 hd E15. Cut my sawing ''teeth'' on an EZ Boardwalk
sawing oak.hickory,ERC,walnut and almost anything else that shows up.
Don't get phylosophical with me. you will loose me for sure.
pc

Ianab

Quote from: Peter Drouin on December 08, 2017, 09:39:27 PM
There must be a way to disable them when they try to get in. Maybe leave a hole, door, easy to hack. And when they go in, there pc fills with junk. One less, next, :D
I don't know, just thinking,

It's called a "honeypot".

If you want to know what the bad guys are up to, you leave out a vulnerable machine in plain sight, and monitor it. It's not actually a real machine, just a virtual system, that has it's actual access locked down tight, and isolated from the rest of the system. But you can watch who attacks it, from where, and what they try and do with it.  Knowing that, it's easier to check and harden the defenses on your real systems.

One guy did get one over the Indian scammers. Strung him along on the phone, and managed to send him a copy of a "Crypto-locker", telling him it was a screen shot of his system. And he opened it.    :D
Weekend warrior, Peterson JP test pilot, Dolmar 7900 and Stihl MS310 saws and  the usual collection of power tools :)

Peter Drouin

A&P saw Mill LLC.
45' of Wood Mizer, cutting since 1987.
License NH softwood grader.

MbfVA

Ponder this one while you're on the topic of cyber-jerks.

It's against the law in most places to conceal your ID in public, as with a mask.

Why then do our diligent & productive lawgivers, federal - state - local, resist (under pressure from the Verizons and others who make money from it) prohibiting ANYONE from concealing their ID when they CALL US or send us email??

It happens every d**g day.  Riddle me that.

:snowball: :snowball:

My homegrown solution to email spam is simple.  Tax everyone who sends email one cent for each one.  Everybody gets a 500 or so monthly exemption, or something like that.  Details later, think on concept lines for now.

Think about it.  Spammers would be out of business almost at once.  The ISPs who have to collect the tax would clamp down IMMEDIATELY.

Wow, I feel better after the above pontification.  Do you?
:new_year:
www.ordinary.com (really)

Jeff

They would not only be spammers then, they would be tax evading spammers, and the tax, would be inflicted upon the people whom had their systems exploited to send the spam.  On the server we had before this one, many years ago, a red hat system, we had a slowdown. We discovered a security hole that had allowed a spammer to set up shop using our server sending hundreds of thousands of spam from our system. It was shut down as soon as it was discovered.  I can just imagine being deemed responsible and having to pay a tax on those spam emails.

Spammers are
Hackers  and they do not use legitimate means to send email.

A message to whom it may concern I can see through the veil of promotion. Stop it.
Just call me the midget doctor.
Forestry Forum Founder and Chief Cook and Bottle Washer.

Commercial circle sawmill sawyer in a past life for 25yrs.
Ezekiel 22:30

Southside

I don't know how you do it Jeff.  To me it was a lot easier when I was handed an M-60 and told "those are the bad guys".
Franklin buncher and skidder
JD Processor
Woodmizer LT Super 70 and LT35 sawmill, KD250 kiln, BMS 250 sharpener and setter
Riehl Edger
Woodmaster 725 and 4000 planner and moulder
Enough cows to ensure there is no spare time.
White Oak Meadows

MbfVA

Granted you and the FF are dealing with a different problem from simple time wasting spam, which is a problem for everyone on the net, but my point is that it is easy to stop the time wasters.  Not an expert nor trying to sound like one but I think you will find that even the jerks who attack your system and others have to have help somewhere along the way from someone/some entity in the legit world who makes money by looking the other way.  It's that way in lot of things that go on that irritate us.

I spent 4 years active in the political world as an elected local supervisor, which included in particular an eyeopening meeting as part of a lobbying group for the National Association of Counties with a senior now retired US Senator in DC.  It was an important but very mundane issue, but it brought me face to face with the reality of "yes, you are right but it is not going to happen because of powerful interests out of our control".  Don't laugh, but it involved "trash".

Politics including, yes, the business world (a VERY political place), is on the inside a lot like the duck whose major struggles and activity are unseen and frankly, not understood by many/most.

Some of it is "necessary" but some of it would make you mad enough to take up arms and not for killing deer 🦌.

ps--never doubt the "power of taxation", check the story of Al Capone's downfall.
www.ordinary.com (really)

Ianab

Problem is, spam is a global issue, with much of it originating in countries that lack any effective government. Basically any law that the US passes won't apply to some Russian bouncing his spam of a network of compromised machines in China. US already has laws against spamming, and if you use your own servers (in the US) to do it, you get arrested. So the spammers look to compromise other peoples machines, and use those to relay spam (as Jeff gave an example of). If someone traces the spam "source", things point back to the FF server, and Jeff. After that the trail either goes cold, or leads to some foreign country. Meanwhile the FF server gets "blacklisted" as a spam source, and even legit emails will be blocked by other servers.

The underlying issue with email and spam is that the original system had very little security or authentication built in. Servers receive and forward emails without actually verifying that they came from the source they claim. So you can put a from "support@ebay.com" or "customer_services@xyzbank.com". The SMTP protocol doesn't check that against any security certificate, it just passes the message on to the destination server.

Then a spam filter has to actually look at the message header (and contents) and try and guess if it's a legit message, or spam. Filter too aggressively, and legit email gets lost. Too lenient and too much spam gets through.

So putting a tax on emails would first be a nightmare to administer, there is no central accounting of emails, and as a spam deterrent, it would be useless anyway, as the spam isn't coming from legit sources.
Weekend warrior, Peterson JP test pilot, Dolmar 7900 and Stihl MS310 saws and  the usual collection of power tools :)

Andries

Quote from: Ianab on December 08, 2017, 11:28:19 PM
. . .  and managed to send him a copy of a "Crypto-locker", telling him it was a screen shot of his system. And he opened it.    :D
So, Ianab may have a source for code called a crypto-locker.
Jeff - how are you at lobb-ing out some 'hurt-lockers'?
LT40G25
Ford 545D loader
Stihl chainsaws

Ianab

QuoteSo, Ianab may have a source for code called a crypto-locker.

He just fished it out of his spam email folder, renamed the "Fedex_docket12345.pdf.exe" to "Screenshot.pdf.exe" and sent it to the scammer. After leading him on for 1/2 an hour trying to get the Teamviewer software to work. 

"Nah it's not working, can I send you a screenshot of what's going on?"

Scammer still thought he had a live one hooked, supplied a gmail address, and opened the file.

It's a sport for some of the techy guys to mess with these scammers.

Heck even my neighbour, who fixes farm milk chillers, is wise to them. "Yeah, I've got Windows open, but it's getting a bit cold in here now..."
Weekend warrior, Peterson JP test pilot, Dolmar 7900 and Stihl MS310 saws and  the usual collection of power tools :)

Thank You Sponsors!