When I want to vent about the morons who spam email systems and bombard forums with their useless junk

State Sponsored hacking?

So yesterday my site got hit by a large number(140) of Chinese IP addresses  all trying to login to my site. Fail2 ban blocked them and sent me lots of emails: Then this morning another pile of Chinese IP addresses ( over 100 ) attempted to login to my email server: Fail2ban blocked those too. […]

More Botnet stats

So I upgraded Fail2ban and so had to restart it. As it stores it’s bans in a database it can restore them at start up. And what a depressingly long list it is for the botnet: 2017-08-05 14:58:20,149[dovecot-disconnect] Ban 1.163.34.115 2017-08-05 14:58:21,110[dovecot-disconnect] Ban 1.175.2.48 2017-08-05 14:58:23,213[dovecot-disconnect] Ban 1.175.27.62 2017-08-05 14:58:24,683[dovecot-disconnect] Ban 1.180.64.86 2017-08-05 14:58:27,764[dovecot-disconnect] Ban […]

Bad IPs

Its the list of usual suspects – China featuring high in the list of machines trying to break into servers (no surprises there) and OVH : 89.248.174.27 60.173.16.74 161.0.153.110 123.214.172.84 218.27.147.130 120.203.25.58 41.110.189.60 62.99.78.120 155.4.33.255 223.241.247.6 218.5.3.45 46.181.62.158 221.3.236.94 114.251.196.28 113.195.181.52 117.245.8.29 184.168.116.130 41.134.156.241 211.103.155.236 216.248.98.187 180.166.246.174 103.238.15.67 58.62.55.130 190.185.133.243 111.16.48.137 222.177.182.10 166.62.88.83 58.242.164.10 122.144.136.211 […]

More shit from the internet

I tightened up the fail2ban rules after looking at my mail logs. The result is impressive but at the same time depressing … so many machines trying to break into my server. Several from GoDaddy…. I guess they’re starting to sit in the same place as OVH when it comes to hosting scum.

I guess enom.com are quite happy being associated with spammers

Yet more spam… same crap.. from the same people on a new domain: Domain Name: PREVOKEE.COM Registry Domain ID: NA Registrar WHOIS Server: whois.enom.com Registrar URL: www.enom.com Updated Date: 2017-03-06T08:18:22.00Z Creation Date: 2017-03-06T16:18:00.00Z Registrar Registration Expiration Date: 2018-03-06T16:18:00.00Z Registrar: ENOM, INC. Registrar IANA ID: 48 Domain Status: clientTransferProhibited https://www.icann.org/epp#clientTransferProhibited Registry Registrant ID: Registrant Name: SOPHIA […]

Another spammer

Same usual shit… Domain is brand new too: Domain Name: METICANTS.COM Registry Domain ID: NA Registrar WHOIS Server: whois.enom.com Registrar URL: www.enom.com Updated Date: 2017-03-05T05:57:17.00Z Creation Date: 2017-03-05T13:57:00.00Z Registrar Registration Expiration Date: 2018-03-05T13:57:00.00Z Registrar: ENOM, INC. Registrar IANA ID: 48 Domain Status: clientTransferProhibited https://www.icann.org/epp#clientTransferProhibited Registry Registrant ID: Registrant Name: SOPHIA RUSSO Registrant Organization: Registrant Street: […]