GoFuckYourself.com - Adult Webmaster Forum

GoFuckYourself.com - Adult Webmaster Forum (https://gfy.com/index.php)
-   Fucking Around & Business Discussion (https://gfy.com/forumdisplay.php?f=26)
-   -   People still does brute forcing ? (https://gfy.com/showthread.php?t=1054446)

cooldude7 01-22-2012 06:50 AM

People still does brute forcing ?
 
over ssh
i mean , i dont get it., why the fuck ?

most of the times ip gets blacklisted, and pw are very strong these days., and how many attempts they are gonna do ?

there are less than 0.1% chance that they ll get in to box., but why waste so much time and power.

sixsax 01-22-2012 07:02 AM

The success rate grows exponentially as they gain access to more servers that can help gain access to yet another. Once you "own" a large enough network, you start blackmailing big companies, threatening to DDOS their online services. And then... You profit.

cooldude7 01-22-2012 07:20 AM

Quote:

Originally Posted by sixsax (Post 18703766)
The success rate grows exponentially as they gain access to more servers that can help gain access to yet another. Once you "own" a large enough network, you start blackmailing big companies, threatening to DDOS their online services. And then... You profit.

eek so cheap, why not build affiliate sites and make monies :winkwink:

mafia_man 01-22-2012 07:31 AM

Change default port, change default user, block root logins, install fail2ban.

99% problems solved.

Barefootsies 01-22-2012 07:50 AM

The short answer is, "yes". People still do it on a daily basis.

:2 cents:

pornmasta 01-22-2012 12:46 PM

Quote:

Originally Posted by cooldude7 (Post 18703754)
pw are very strong these

why are they strong now and not in the past ?

pornmasta 01-22-2012 12:47 PM

http://pastebin.com/ZGXJuQKW a random link at pastebin: January, 12th 2012

oscer 01-22-2012 12:56 PM

Change your ssh ports to a non standard setting Or use a firewall

Fabien 01-22-2012 01:07 PM

Quote:

Originally Posted by cooldude7 (Post 18703754)
over ssh
i mean , i dont get it., why the fuck ?

most of the times ip gets blacklisted, and pw are very strong these days., and how many attempts they are gonna do ?

there are less than 0.1% chance that they ll get in to box., but why waste so much time and power.

On a new VPS of mine, i get around 5 attempts/da,y that goes over 100 and it's a brand new VPS (5 days old)

cooldude7 01-22-2012 11:40 PM

Quote:

Originally Posted by Fabien (Post 18704284)
On a new VPS of mine, i get around 5 attempts/da,y that goes over 100 and it's a brand new VPS (5 days old)

on my new box 4 days old, gets 6-7 attempts ,with 800+ tries

CYF 01-22-2012 11:45 PM

Quote:

Originally Posted by oscer (Post 18704263)
Change your ssh ports to a non standard setting Or use a firewall

even better, use ssh public keys.

raymor 01-23-2012 05:41 AM

Quote:

Originally Posted by CYF (Post 18705314)
even better, use ssh public keys.


Keys avoid any possibility of success. A firewall avoids wasting resources on attempts.

A lot of people use strong passwords, a vew use passphrases, but way too many webmasters use "admin admin", "qwerty" and other dumb shit. We get webmaster passwords daily of course and I'd say about 10% are really bad. Use LONG passwords, please.

seeandsee 01-23-2012 06:19 AM

they are using bot networks for that, and then they spread, and then they can use it for wahtever reason they want

mafia_man 01-23-2012 07:33 AM

Quote:

Originally Posted by raymor (Post 18705614)
Keys avoid any possibility of success. A firewall avoids wasting resources on attempts.

A lot of people use strong passwords, a vew use passphrases, but way too many webmasters use "admin admin", "qwerty" and other dumb shit. We get webmaster passwords daily of course and I'd say about 10% are really bad. Use LONG passwords, please.

Keys are the best way I just don't trust myself not to lose them.

Barefootsies 01-23-2012 08:19 AM

Quote:

Originally Posted by seeandsee (Post 18705698)
they are using bot networks for that, and then they spread, and then they can use it for wahtever reason they want

More often than not, true dat.


All times are GMT -7. The time now is 01:30 AM.

Powered by vBulletin® Version 3.8.8
Copyright ©2000 - 2025, vBulletin Solutions, Inc.
©2000-, AI Media Network Inc123