CNCzone.com-The Largest Machinist Community on the net!



Home Page Mark Forums Read Today's Posts My Replies Classifieds Reviews Photo Gallery Web Links Share Files Advertise With Us Ad List
Go Back   CNCzone.com-The Largest Machinist Community on the net! > Events, Product Announcements and More > CNCzone Club House


CNCzone Club House Discuss everything in between CNC. THIS IS NOT A TRASH BIN.


This forum is sponsored by:

Reply
 
LinkBack Thread Tools Search this Thread Display Modes
  #1   Ban this user!
Old 03-30-2005, 10:45 AM
Swede's Avatar  
Join Date: Dec 2003
Location: United States
Posts: 383
Swede is on a distinguished road
Angry Help! My web site is attacked by hackers!

Anyone out there an armchair hacker who can help me? My innocent and innocuous hobby web site, 5bears.com, has been under attack and I am threatened with suspension by my hosting service.

The attack is called a "Dictionary Attack". Apparently, the server gets thousands of emails to the domain by an automated system that uses a dictionary to create massive bandwidth. It seems to be all email-based.

If I eliminate any mail service (or have lunarpages block the ports), do you guys think this will help? I am so frustrated. Why can't these punks target blogs or political sites? :frown:
Tweet this Post!Share on Facebook
Reply With Quote

  #2  
Old 03-30-2005, 11:51 AM
CNCadmin's Avatar
Site Owner
 
Join Date: Mar 2003
Location: United States
Posts: 6,338
CNCadmin has disabled reputation
Buy me a Beer?

Read this - http://www.cs.virginia.edu/~csadmin/...rute_force.htm

Does your host provider not have a firewall?
__________________
Thank You,
Paul G
Site Owner-Webmaster-
Administrator
www.rfqwork.com
www.cnczone.com
www.welderzone.com

Last edited by CNCadmin; 03-30-2005 at 11:56 AM.
Tweet this Post!Share on Facebook
Reply With Quote

  #3   Ban this user!
Old 03-30-2005, 11:57 AM
 
Join Date: May 2003
Location: USA
Posts: 550
fyffe555 is on a distinguished road

Swede,

I might be able to help.

You're target for a system that goes through a list of domain names searching for valid or responsive email addresses. The attack will stop once the specified volume of mail is sent, usually a few hours. This attack is somewhat different to the brute force attack that targets http passwords and not email addresses.

A dictionary attack on an email server, as opposed to web password access consists of spammers generating apparently random addresses (xxxx@5bears.com) using a predifined list of words or commonly used email address names (a ‘dictionary’) for a particular domain (5bears.com) and sending email to them.

Those that bounce back as invalid are purged; those that don’t bounce - ie message accepted by the mail server as a good address will be assumed to be active and added to a list of ‘good’ addresses and subsequently used as a target for spam, sold to spammers, or if the server is open relay used to bounce spam.

A variation sends an smtp specific validation request so theres no email but requires a known and published email server to do so. Not commonly used for this attack as its easy to locate the source and action can easily be taken.

This is a common attack, easily identifiable and the process and resolutions are well known. In other words your provider should identify the attack and know what to do about it without threatening you or your service - assuming they host your email server and you're not running your own pop/smtp server locally.

the attacks are emails sent to the email server defined in the mx record for your domain, hosted by your provider. The system(s) sending them are probably forging the headers to show various sender and return addresses *BUT* the sending IP cannot be so easily spoofed. Your provider can (should) easily put a filter on to block email from the sending IP address without affecting your other mail. This is a specific block of a sending IP address, usually before it enters the smpt server. The IP addresses to be blocked are derived from a simple view of headers from some of the messages received and/or bounced. An alternative is to put a reverse DNS test on each incoming mail which checks the sener/return domain against the sending IP. Finally your providor should be able to limit the number of emails received from any IP in a given period - so stopping the thing slowing down the server.

Even if your providor doesn't do any of this then the problem should soon go away as the list is exhausted. look to see if any unusual mails have been received in this period and this could be an indication that the addresses have been farmed..

hth

Andrew

Last edited by fyffe555; 03-30-2005 at 12:01 PM. Reason: can't type....
Tweet this Post!Share on Facebook
Reply With Quote

  #4   Ban this user!
Old 03-30-2005, 01:34 PM
RotarySMP's Avatar  
Join Date: Mar 2004
Location: Vienna, Austria
Posts: 1,048
RotarySMP is on a distinguished road

Swede, Someone is probably trying to tell you that they are desparately waiting for your next update
__________________
Regards,
Mark
www.wrathall.com
Tweet this Post!Share on Facebook
Reply With Quote

  #5   Ban this user!
Old 03-31-2005, 09:49 AM
Swede's Avatar  
Join Date: Dec 2003
Location: United States
Posts: 383
Swede is on a distinguished road

Everyone, especially Andrew, thanks for your replies. My web hosting service (Lunarpages) has generally been very helpful and responsive, but this is the third dictionary attack in the last 2 months, and it seems that there is something malicious going on. I'll post again when I find a resolution.
Tweet this Post!Share on Facebook
Reply With Quote

Sponsored Links
  #6   Ban this user!
Old 03-31-2005, 10:38 AM
KrispyLlama's Avatar  
Join Date: Feb 2005
Location: USA
Age: 28
Posts: 16
KrispyLlama is on a distinguished road
Talking Spamers

This problem does suck but to help prevent this never type your email address online, use a java code or unicode version. This way when the bots that scan for address looks at yours it sees it as random nonsence. Just do a google search for unicode email and you should find the tool online to convert you address to unicode. This has worked for me.
Tweet this Post!Share on Facebook
Reply With Quote

  #7  
Old 03-31-2005, 11:58 AM
WoodSnarfer's Avatar
Gold Member
 
Join Date: Nov 2004
Location: United States
Posts: 78
WoodSnarfer is on a distinguished road

On my account (affordablehost), there is a setting that says "what do you want me to do with mail that is sent to xxx.domain-name.com, if a valid email account does not exist?" The choices are to either reject the mail, or send it to a 'catcher' email id. I had it use the 'catcher' for awhile, but the spam was intolerable -- so I set it to 'reject'. Never had a problem since.

-Chris
Tweet this Post!Share on Facebook
Reply With Quote

  #8   Ban this user!
Old 04-14-2005, 09:50 AM
Swede's Avatar  
Join Date: Dec 2003
Location: United States
Posts: 383
Swede is on a distinguished road

Update - the dictionary attack worked something like this... Some clod would set up a system to email, in rapid sequence, nonsense like

aardvark@swedesdomain.com
abacus@swedesdomain.com
....
zygote@swedesdomain.com

The rapid flow of B.S. spiked the CPU and bandwidth. I actually volunteered to shut down my POP mail server for as long as it took for the attacks to cease. My host said they'd do this. The attack terminated, yet my email still works, so I'm not sure exactly what happened.

I'll cross my fingers and hope.
Tweet this Post!Share on Facebook
Reply With Quote

  #9   Ban this user!
Old 04-08-2007, 05:57 PM
 
Join Date: May 2006
Location: USA
Age: 55
Posts: 3
hackware is on a distinguished road
dos (denial of service) attacks...

if you still have problems with your isp and/or dos attacks...

i'll host your site (free)...

i owned/built/operated an isp company for 8 years, with 17 web stores,

a couple of which were "yahoo site of the day", and was never cracked...

(oh they tried)...

anyway, i'm not on a large bandwidth connection,

but will host you if it will help...
__________________
...william.o.yates...hackware.at.tru2life.net...www.tru2life.net...
Tweet this Post!Share on Facebook
Reply With Quote

Reply




Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is On
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
Need help finding CNC tutorial on the web!! NewCents DIY-CNC Router Table Machines 3 04-10-2009 04:08 PM
New laser cutting web site owhite Laser Engraving & Cutting Machines 4 06-28-2005 10:33 AM
Used cars web site? svenakela CNCzone Club House 2 01-15-2005 12:50 AM
site stats world wide! lsfoils CNCzone Club House 2 04-10-2004 12:33 AM
Web site rcrabb CNCzone Club House 2 09-27-2003 10:39 AM




All times are GMT -5. The time now is 10:03 PM.





Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2012, vBulletin Solutions, Inc.
Content Relevant URLs by vBSEO
Template-Modifications by TMS

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139 140 141 142 143 144 145 146 147 148 149 150 151 152 153 154 155 156 157 158 159 160 161 162 163 164 165 166 167 168 169 170 171 172 173 174 175 176 177 178 179 180 181 182 183 184 185 186 187 188 189 190 191 192 193 194 195 196 197 198 199 200 201 202 203 204 205 206 207 208 209 210 211 212 213 214 215 216 217 218 219 220 221 222 223 224 225 226 227 228 229 230 231 232 233 234 235 236 237 238 239 240 241 242 243 244 245 246 247 248 249 250 251 252 253 254 255 256 257 258 259 260 261 262 263 264 265 266 267 268 269 270 271 272 273 274 275 276 277 278 279 280 281 282 283 284 285 286 287 288 289 290 291 292 293 294 295 296 297 298 299 300 301 302 303 304 305 306 307 308 309 310 311 312 313 314 315 316 317 318 319 320 321 322 323 324 325 326 327 328 329 330 331 332 333 334 335 336 337 338 339 340 341 342 343 344 345 346 347 348 349 350 351 352 353