Go Back   HostGator Peer Support Forums > HostGator Peer Support Forums > Linux VPS Support

Notices

Reply
 
Thread Tools
  #1  
Old 02-02-2012, 08:28 AM
AJA AJA is offline
Hatchling Croc
 
Join Date: Oct 2011
Posts: 7
Angry Log in attempts

I recently enabled the email notification for failed lo in attempts to see what was happening, A lot from the places you might expect, Russia, China etc.

So today we get one from theplanet.com
nice.........
Reply With Quote
  #2  
Old 02-02-2012, 10:44 AM
freeman's Avatar
freeman freeman is offline
Swamp Croc
 
Join Date: Jan 2006
Location: Montreal, QC, Canada
Posts: 308
Default Re: Log in attempts

Quote:
Originally Posted by AJA View Post
I recently enabled the email notification for failed lo in attempts to see what was happening, A lot from the places you might expect, Russia, China etc.

So today we get one from theplanet.com
nice.........
Relax, there is nothing to worry about, that's usually. People are trying....


Regards,
George B.
Reply With Quote
  #3  
Old 02-02-2012, 01:05 PM
AJA AJA is offline
Hatchling Croc
 
Join Date: Oct 2011
Posts: 7
Default Re: Log in attempts

I understand, just the fact that one of them is coming from within.
Reply With Quote
  #4  
Old 02-02-2012, 02:11 PM
quietFinn's Avatar
quietFinn quietFinn is offline
Veteran Croc
 
Join Date: Feb 2005
Posts: 3,558
Default Re: Log in attempts

Quote:
Originally Posted by AJA View Post
I understand, just the fact that one of them is coming from within.
When there is a datacenter where there are thousands of servers, there are at least a few servers that are compromised.
__________________
quietFinn - netFinn Finland
"Be who you are and say what you feel because those who mind don't matter and those who matter don't mind." - Dr. Seuss
Reply With Quote
  #5  
Old 02-07-2012, 10:46 AM
gbh gbh is offline
Hatchling Croc
 
Join Date: Feb 2011
Location: Shenandoah Valley
Posts: 17
Default Re: Log in attempts

Quote:
Originally Posted by AJA View Post
I understand, just the fact that one of them is coming from within.
That kind of raised my eyebrows, when I first saw it, too, but I get so many brute force attacks from the usual suspects (China, Russia, Ukraine, Thailand, Vietnam, Moldova, GoDaddy, etc.) that I just consider them all the same, regardless of where they originate.

Even though all HostGator domains are on ThePlanet, not all ThePlanet domains are within HostGator.
Reply With Quote
  #6  
Old 02-07-2012, 04:51 PM
striddy's Avatar
striddy striddy is offline
Veteran Croc
 
Join Date: Mar 2008
Location: /home/australia/earth
Posts: 4,093
Default Re: Log in attempts

Quote:
Originally Posted by gbh View Post
Even though all HostGator domains are on ThePlanet, not all ThePlanet domains are within HostGator.
Actually it's SoftLayer not The Planet
__________________
- David
Reply With Quote
  #7  
Old 02-09-2012, 06:34 AM
gbh gbh is offline
Hatchling Croc
 
Join Date: Feb 2011
Location: Shenandoah Valley
Posts: 17
Default Re: Log in attempts

Quote:
Originally Posted by striddy View Post
Actually it's SoftLayer not The Planet
That's right, but the attacking IP addresses are often still registered as "ThePlanet.com Internet Services, Inc." though they now belong to SoftLayer.
Reply With Quote
  #8  
Old 02-10-2012, 12:13 AM
aeons aeons is offline
Junior Croc
 
Join Date: Dec 2010
Posts: 104
Default Re: Log in attempts

If you are getting hit by the same IP over and over, report it to their ISP and send excerpts of the log showing them blocked. Time-stamped logs are crucial when reporting, so the host can lookup the attempt on their end to confirm.

Almost all hosts will act on it and warn/remove the abuser, as it eats up their network resources.

A log excerpt will look something like this:
[Thu Feb 09 11:08:30 2012] [error] [client ip.address.here] /whatever they were trying to do here.

Most of the abusers are hacked sites/servers from either careless/unknowing webmasters. Not usually the host's fault, unless they don't take action against abuse complaints.
Reply With Quote
  #9  
Old 02-10-2012, 01:13 AM
mrintech's Avatar
mrintech mrintech is online now
Royal Croc
 
Join Date: Nov 2009
Location: India
Posts: 408
Default Re: Log in attempts

Quote:
Originally Posted by gbh View Post
That kind of raised my eyebrows, when I first saw it, too, but I get so many brute force attacks from the usual suspects (China, Russia, Ukraine, Thailand, Vietnam, Moldova, GoDaddy, etc.) that I just consider them all the same, regardless of where they originate.

Even though all HostGator domains are on ThePlanet, not all ThePlanet domains are within HostGator.
__________________
MrinTech| Coupons | Facebook
Reply With Quote
  #10  
Old 02-14-2012, 08:41 AM
gbh gbh is offline
Hatchling Croc
 
Join Date: Feb 2011
Location: Shenandoah Valley
Posts: 17
Default Re: Log in attempts

Quote:
Originally Posted by aeons View Post
If you are getting hit by the same IP over and over, report it to their ISP...
Yes, I am quite familiar with the procedure, but it is not the same IP address. There are a number of miscreants probing other servers from The Planet's IP address range.
Reply With Quote
  #11  
Old 02-15-2012, 10:46 AM
beiker's Avatar
beiker beiker is offline
Baby Croc
 
Join Date: Feb 2012
Posts: 55
Default Re: Log in attempts

This is what they call brute force I think. Trying possible combination until it gets in. One possible option here is to limit login attempts from a sepcifi source IP. Say 5 failed login attempts from a source IP will disable to function until 4h or so.

Question is, is this doable?
__________________
You're never a loser until you quit trying.
Reply With Quote
  #12  
Old 02-15-2012, 11:51 AM
quietFinn's Avatar
quietFinn quietFinn is offline
Veteran Croc
 
Join Date: Feb 2005
Posts: 3,558
Default Re: Log in attempts

Quote:
Originally Posted by beiker View Post
This is what they call brute force I think. Trying possible combination until it gets in. One possible option here is to limit login attempts from a sepcifi source IP. Say 5 failed login attempts from a source IP will disable to function until 4h or so.

Question is, is this doable?
Sure it is, just install CSF:
http://www.configserver.com/cp/csf.html
__________________
quietFinn - netFinn Finland
"Be who you are and say what you feel because those who mind don't matter and those who matter don't mind." - Dr. Seuss
Reply With Quote
  #13  
Old 02-26-2012, 03:20 AM
aeons aeons is offline
Junior Croc
 
Join Date: Dec 2010
Posts: 104
Default Re: Log in attempts

Quote:
Originally Posted by gbh View Post
Yes, I am quite familiar with the procedure, but it is not the same IP address. There are a number of miscreants probing other servers from The Planet's IP address range.
The attacker likely started probing a set of IPs and landed with a bunch of Softlayer's servers that were run by owners that didn't do the necessities to harden their server and thus hacked.

Every now and then you'll get a sysadmin (rarely SL) that will reply to your abuse report and explain their customer was hacked and mention they had an exploit script running on their box that was attacking other servers.
One reply I received over the summer when I was under heavy attack, mentioned the exploit script had my server's IP stored in some database.

You probably got unlucky and landed in one of those databases and just by coincidence keep seeing the same providers.
Reply With Quote
Reply

Bookmarks

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
phpMyAdmin hack attempts LittleTiger Security Issues 6 05-22-2011 03:36 PM

All times are GMT -5. The time now is 12:18 PM.