GoFuckYourself.com - Adult Webmaster Forum

GoFuckYourself.com - Adult Webmaster Forum (https://gfy.com/index.php)
-   Fucking Around & Business Discussion (https://gfy.com/forumdisplay.php?f=26)
-   -   Anybody experiencing FTP attacks on their servers? (https://gfy.com/showthread.php?t=921406)

TheSenator 08-12-2009 04:21 PM

Anybody experiencing FTP attacks on their servers?
 
I am getting some crazy FTP attacks from China.

Some bot from China is trying to find exploits on my sites.

Here is an IP 221.130.193.61

My system admin already figured out the pattern and has a script to detect if my server is being attack.


Shit has slowed down my server.

CaptainWolfy 08-12-2009 04:28 PM

i have experienced that shit just month ago, change every ftp pass you have, and clean that shit if you got infected..

Fletch XXX 08-12-2009 04:28 PM

at least youre on it, good luck.

camgirlshide 08-12-2009 04:33 PM

using just a single ip for the attack? That's surprising. Usually they are better than that.

TurboAngel 08-12-2009 04:53 PM

That sucks.


:Oh crap

TheSenator 08-12-2009 05:00 PM

The attacks are spread out through the day. My system admin is on top of that shit. Whatever bot they are using has unlimited bandwidth to suck and dump shit at 100Mbs...

raymor 08-13-2009 01:59 PM

We see FTP dictionary attacks on most servers where we look for it.
POP3, email, is also a popular target because very often your FTP user/pass
will be approved for POP3, but people leave POP3 unprotected. So the bad
guys brute on POP3, then when they hit one that works try the same user/pass
for FTP, Wordpress, etc. On our servers, EVERY single daemon has brute
force protection - SMTP, IMAP, POP3, FTP... . SSH is keys only, no passwords.
We created a single brute force protection system that can watch any service.
There are just a couple of settings to adapt it fro FTP, POP3, etc.

AdultHardcore 08-13-2009 02:41 PM

Quote:

Originally Posted by TheSenator (Post 16176673)
I am getting some crazy FTP attacks from China.

Some bot from China is trying to find exploits on my sites.

Here is an IP 221.130.193.61

My system admin already figured out the pattern and has a script to detect if my server is being attack.


Shit has slowed down my server.

That sucks!!!

d-null 08-13-2009 02:46 PM

yeah the bastards are a piss off

BestXXXPorn 08-13-2009 02:55 PM

Best solution, disable FTP! It's antiquated :P

fuzebox 08-13-2009 04:16 PM

Quote:

Originally Posted by BestXXXPorn (Post 16180791)
Best solution, disable FTP! It's antiquated :P

:thumbsup

I can't believe more webmasters don't use ssh/scp/sftp/whatever...


All times are GMT -7. The time now is 02:59 AM.

Powered by vBulletin® Version 3.8.8
Copyright ©2000 - 2025, vBulletin Solutions, Inc.
©2000-, AI Media Network Inc123