|
#1
|
|||
|
|||
|
I recently enabled the email notification for failed lo in attempts to see what was happening, A lot from the places you might expect, Russia, China etc.
So today we get one from theplanet.com nice......... |
|
#2
|
||||
|
||||
|
Quote:
Regards, George B. |
|
#3
|
|||
|
|||
|
I understand, just the fact that one of them is coming from within.
|
|
#4
|
||||
|
||||
|
When there is a datacenter where there are thousands of servers, there are at least a few servers that are compromised.
__________________
quietFinn - netFinn Finland "Be who you are and say what you feel because those who mind don't matter and those who matter don't mind." - Dr. Seuss |
|
#5
|
|||
|
|||
|
That kind of raised my eyebrows, when I first saw it, too, but I get so many brute force attacks from the usual suspects (China, Russia, Ukraine, Thailand, Vietnam, Moldova, GoDaddy, etc.) that I just consider them all the same, regardless of where they originate.
Even though all HostGator domains are on ThePlanet, not all ThePlanet domains are within HostGator. |
|
#6
|
||||
|
||||
|
Quote:
__________________
- David |
|
#7
|
|||
|
|||
|
That's right, but the attacking IP addresses are often still registered as "ThePlanet.com Internet Services, Inc." though they now belong to SoftLayer.
|
|
#8
|
|||
|
|||
|
If you are getting hit by the same IP over and over, report it to their ISP and send excerpts of the log showing them blocked. Time-stamped logs are crucial when reporting, so the host can lookup the attempt on their end to confirm.
Almost all hosts will act on it and warn/remove the abuser, as it eats up their network resources. A log excerpt will look something like this: [Thu Feb 09 11:08:30 2012] [error] [client ip.address.here] /whatever they were trying to do here. Most of the abusers are hacked sites/servers from either careless/unknowing webmasters. Not usually the host's fault, unless they don't take action against abuse complaints. |
|
#9
|
||||
|
||||
|
Quote:
|
|
#10
|
|||
|
|||
|
Yes, I am quite familiar with the procedure, but it is not the same IP address. There are a number of miscreants probing other servers from The Planet's IP address range.
|
|
#11
|
||||
|
||||
|
This is what they call brute force I think. Trying possible combination until it gets in. One possible option here is to limit login attempts from a sepcifi source IP. Say 5 failed login attempts from a source IP will disable to function until 4h or so.
Question is, is this doable?
__________________
You're never a loser until you quit trying. |
|
#12
|
||||
|
||||
|
Quote:
http://www.configserver.com/cp/csf.html
__________________
quietFinn - netFinn Finland "Be who you are and say what you feel because those who mind don't matter and those who matter don't mind." - Dr. Seuss |
|
#13
|
|||
|
|||
|
Quote:
Every now and then you'll get a sysadmin (rarely SL) that will reply to your abuse report and explain their customer was hacked and mention they had an exploit script running on their box that was attacking other servers. One reply I received over the summer when I was under heavy attack, mentioned the exploit script had my server's IP stored in some database. You probably got unlucky and landed in one of those databases and just by coincidence keep seeing the same providers. |
![]() |
| Bookmarks |
«
Previous Thread
|
Next Thread
»
| Thread Tools | |
|
|
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| phpMyAdmin hack attempts | LittleTiger | Security Issues | 6 | 05-22-2011 03:36 PM |
All times are GMT -5. The time now is 12:18 PM.










