Carrier Hacker new servers be warned

Any and all non-support discussions

Moderators: gerski, enjay, williamconley, Op3r, Staydog, gardo, mflorell, MJCoate, mcargile, Kumba, Michael_N

Carrier Hacker new servers be warned

Postby mattyou1985 » Tue Jul 12, 2016 3:47 pm

Tracing route to 217.28.216.250 over a maximum of 30 hops

1 14ms 12ms 15ms 195.166.128.190
2 12ms 13ms 12ms 212.159.2.128
3 12ms 12ms 12ms 212.159.0.104
4 13ms 12ms 12ms 195.66.224.193
5 62ms 65ms 63ms 87.245.232.181
6 62ms 63ms 62ms 87.245.229.126
7 64ms 64ms 65ms 217.28.216.250


[Jul 12 20:17:23] NOTICE[17152]: manager.c:2440 authenticate: 217.28.216.250 tried to authenticate with nonexistent user 'phpagi'
[Jul 12 20:17:23] NOTICE[17152]: manager.c:2477 authenticate: 217.28.216.250 failed to authenticate as 'phpagi'
[Jul 12 20:17:24] == Connect attempt from '217.28.216.250' unable to authenticate

[Jul 12 20:24:09] NOTICE[17968]: manager.c:2440 authenticate: 217.28.216.250 tried to authenticate with nonexistent user 'admin'
[Jul 12 20:24:09] NOTICE[17968]: manager.c:2477 authenticate: 217.28.216.250 failed to authenticate as 'admin'
[Jul 12 20:24:10] == Connect attempt from '217.28.216.250' unable to authenticate


https://sysadminman.net/blog/2010/block ... l2ban-1392

http://www.eflo.net/VICIDIALforum/viewtopic.php?t=14509

this is still hapning at least i meniged to pull his working ip 217.28.216.250 feall free to repay the faver fello vici admin's
mattyou1985
 
Posts: 111
Joined: Tue Apr 19, 2016 3:30 pm

Re: Carrier Hacker new servers be warned

Postby williamconley » Tue Jul 12, 2016 4:26 pm

If you allows general public access to your Vicidial server, you WILL be attacked. Lock it down.

Dynamic Good Guys firewall for Vicidial:

http://viciwiki.com/index.php/DGG

Note that you don't have to actually install it if you don't want to. The instructions specify how to whitelist lockdown the server before you install. If you stop there, you can manually add "known good IPs" in the yast firewall directly from the command line.

The DGG installation merely provides easy management and easy remote access for authorized users from anywhere.
Vicidial Installation and Repair, plus Hosting and Colocation
Newest Product: Vicidial Agent Only Beep - Beta
http://www.PoundTeam.com # 352-269-0000 # +44(203) 769-2294
williamconley
 
Posts: 20018
Joined: Wed Oct 31, 2007 4:17 pm
Location: Davenport, FL (By Disney!)


Return to General Discussion

Who is online

Users browsing this forum: RBecker and 51 guests