Nytro Posted September 2, 2013 Report Posted September 2, 2013 Se pare ca au revenit baietii veseli. Nu prea inteleg de ce atacul DDOS vine dupa ora 00:00, oare pe ce fus orar or fi? In SUA e ora 18:20, in China e 06:00 dimineata. Nu am idee.Ce e interesant e ca vin de pe IP-uri de prin toata lumea. Din lipsa de somn am facut reverse DNS pe o parte dintre ele si rezultatul arata cam asa:68-191-191-90.static.fdul.wi.charter.com host141-86-static.98-5-b.business.telecomitalia.it h-109-228-132-146.na.cust.bahnhof.sehosted-by.securefastserver.comarx68-8.araxinfo.com177-069-215-197.static.ctbctelecom.com.brhost-201-218-17-202.telconet.netip-200-53-103-250-mty.marcatel.net.mxWimax-Cali-190-0-16-58.orbitel.net.co80-84-117-233.pool.symbios.ru adsl-90-151-59-151.nojabrsk.ru82-160-137-162.tktelekom.plyak-3062.union-tel.ruh88-150-189-101.host.redstation.co.uk manserv162.static.host.gvt.net.brshinevskiy.hrf.suexpogospel.amplitudenet.com.br FAST-INTERNET-103-246-1-49.solnet.net.id pppoe-dynamic-pool-130.u2net.ru234-50-251-80.pride-net.ruip-91-232-85-10.xlnet.czframan.dfc.unifi.itlvps91-250-113-166.dedicated.hosteurope.destatic.217.12.113.67.tmg.mdautoplan17-8.autoplan.com.brmail.martinbesta.czip-176-192-15-229.bb.netbynet.rukvartal.brov.orghsreina.shadosoft-tm.comkm-unallocated.gtu.net.uawww3386uj.sakura.ne.jp196.216.74.10.swiftkenya.comclients-pools.vt.cooolbox.bgyak-3062.union-tel.rulisg-sh.ELANinet.comtokiodance.metronv.ru95-24-122-21.broadband.corbina.ruec2-54-242-80-90.compute-1.amazonaws.com ec2-54-251-204-189.ap-southeast-1.compute.amazonaws.com ec2-54-232-227-85.sa-east-1.compute.amazonaws.com mailgw.astellas.comj34440.servers.jiffybox.netdu-220-98.sv-en.runewhost.rapidvps.netserver.geek-spot.comPSA.MINAS.netsi.com.br190-82-89-156.static.tie.clip-net-196-43-98-2.africaonline.co.zw netgenius.co.ukstatic.vdc.vndsp-fax.dsp-c.co.rsIP.net124-238.psi.net.pa80-48-126-12.smsiarkowiec.pl 190-94-201-245.ifxnw.com.ve102.200.23.177.fhpinternet.com.brdial-78-141-120-184.orange.skstatic.11.85.40.188.clients.your-server.de hosted-by.securefastserver.comm125.magenta.fastwebserver.dehsreina.shadosoft-tm.comedge.tumblespeed.netckb1.rutil.netNu pare nimic neobisnuit insa am fost surprins sa vad multe servere cumparate: securefastserver.com, fastwebserver.de, your-server.de, cateva de compute.amazonaws.com, dedicated.hosteurope.de... Oare au fost toate prinse pe "./scanu" nostru romanesc, sau cineva a investit in asa ceva?Hm, oricum, oricine ar fi in spatele atacurilor nu e o persoana tocmai inteligenta. S-au folosit peste 570 de IP-uri unice, cu asa ceva era oarecum usor sa pici un server, insa nici nu era nevoie sa le dau DROP pentru ca atacul nu facea nici macar load pe server.Aceasta e lista cu IP-urile:101.109.251.210101.255.71.18103.11.159.195103.16.68.4103.16.79.195103.246.1.186103.246.1.49106.3.102.215108.61.36.88108.61.89.152109.101.9.48109.122.48.165109.185.116.199109.194.65.175109.207.61.14109.227.124.27109.228.132.146109.236.220.98109.69.72.109116.10.143.18116.226.47.78116.228.55.184116.231.193.132116.236.216.116116.66.197.2281.179.128.21.179.144.981.179.147.2119.110.67.200119.110.75.246119.187.148.81119.2.3.222119.235.50.202119.2.49.227119.252.160.99119.254.90.18119.6.73.138119.9.33.171119.93.7.211119.97.146.148121.11.167.246121.12.167.19712.199.141.164123.242.172.4123.30.75.115123.63.33.217130.255.88.65133.242.141.160133.242.144.168136.0.16.210137.116.122.218137.135.104.254137.135.81.169137.175.29.34139.0.16.202141.85.252.13614.192.159.205142.0.128.24142.0.138.34144.76.63.53150.140.141.195150.217.103.160151.232.41.149157.7.137.101162.211.224.30163.125.156.85163.142.73.1131.63.18.22163.5.69.4166.111.132.167170.224.168.197172.162.165.70173.208.252.196173.252.252.218173.45.83.235174.142.184.205175.111.90.35175.136.192.5175.139.213.206175.140.114.207175.25.243.22175.25.243.26176.108.108.111176.192.15.229176.194.189.56176.56.12.48177.107.97.245177.129.214.44177.192.184.45177.207.243.165177.21.253.18177.22.121.34177.23.200.102177.43.210.162177.69.195.4177.69.215.197177.73.3.44178.135.61.179178.149.45.225178.208.255.123178.212.124.111178.217.9.18178.248.43.155179.222.17.43181.112.217.211181.114.225.50181.14.202.100181.225.59.134184.107.243.2184.154.85.245184.82.214.35185.8.107.4185.8.2.18186.0.202.164186.101.41.40186.101.78.110186.103.130.90186.103.143.211186.194.47.46186.209.106.20186.215.255.210186.24.34.178186.249.79.246186.3.6.113186.3.71.155186.47.122.60186.65.96.118186.88.107.73186.88.55.166186.89.109.233186.89.64.6186.91.196.62186.92.114.13186.92.134.50186.92.5.192186.93.127.50186.93.155.113186.93.209.208186.93.248.237186.94.184.195186.95.122.150186.95.238.103186.95.42.166186.95.79.192187.102.127.97187.111.15.221187.11.123.14187.120.208.211187.120.27.22187.120.34.82187.12.189.221187.125.147.178187.157.32.65187.41.65.244187.45.103.200187.51.57.213187.52.2.162187.62.217.81188.128.99.94188.129.214.244188.136.134.231188.190.164.10188.40.85.11188.95.32.186189.106.23.196189.114.75.21189.125.133.50189.1.8.206189.203.225.194189.254.236.185189.2.80.2189.2.90.228189.3.25.146189.41.177.68189.44.113.186189.78.155.168189.85.22.98190.0.16.58190.0.17.202190.0.33.18190.0.45.98190.0.60.238190.111.122.74190.121.135.178190.121.20.61190.14.255.234190.146.132.205190.151.122.38190.152.80.2190.153.33.253190.162.205.240190.167.196.218190.181.243.84190.189.93.245190.199.108.140190.199.220.156190.199.43.52190.200.176.155190.202.250.233190.203.151.104190.203.215.12190.203.76.31190.204.168.238190.204.246.62190.204.2.83190.204.98.120190.207.188.251190.207.215.99190.24.10.122190.253.60.30190.37.101.243190.38.189.52190.39.22.51190.39.91.75190.72.205.104190.72.32.134190.74.187.146190.74.237.37190.77.220.213190.77.3.110190.77.46.194190.78.241.4190.78.251.148190.79.156.43190.82.89.156190.85.53.43190.94.201.245190.94.206.213190.94.210.150190.94.249.130190.95.225.163190.96.64.234192.187.116.226192.64.11.124193.110.216.144193.165.216.52194.141.252.102194.19.245.45194.48.60.26195.128.157.240195.135.251.171195.140.190.146195.191.13.2195.222.36.86195.225.144.38195.24.210.130195.24.220.134195.245.118.5196.216.74.10196.219.24.34196.43.98.2197.136.42.5197.161.39.66197.210.252.44197.211.32.170197.220.193.49197.255.213.146198.102.28.100198.2.196.162198.2.198.33198.23.128.49198.24.181.95198.27.83.105198.49.70.103198.50.241.160198.50.245.105198.50.96.107198.52.247.103198.56.208.37198.56.238.54199.15.233.142199.201.121.139199.250.198.238199.255.28.102200.123.130.129200.148.94.78200.192.255.146200.195.141.178200.199.139.50200.222.4.90200.252.14.166200.46.124.238200.52.172.66200.53.103.250200.54.92.187200.60.11.25200.69.218.221200.7.33.250200.84.106.156200.84.135.195200.84.15.123200.84.61.11200.88.158.250200.93.56.28201.12.116.18201.140.102.173201.208.103.26201.208.97.145201.209.96.176201.210.202.206201.211.0.51201.211.115.254201.211.129.193201.211.3.136201.218.17.202201.234.133.57201.234.74.5201.242.58.89201.243.159.113201.248.113.4201.249.9.139201.33.29.86201.49.209.146201.62.48.153201.62.48.202201.64.254.228203.112.195.238203.153.214.22203.161.24.74203.172.161.211203.19.4.250203.24.76.186203.86.16.230204.93.54.15205.202.253.55206.251.61.230206.251.61.236206.251.61.252207.238.97.13208.73.22.156208.83.61.90208.97.65.4211.138.129.251211.140.207.100211.142.236.132211.157.114.133211.167.64.112212.126.122.160212.138.92.10212.165.128.105212.200.23.18212.249.11.115212.50.224.55212.7.192.139212.8.206.170212.91.169.132213.141.236.133213.164.18.147213.181.73.145213.197.129.70213.203.182.116213.211.36.100213.233.92.78216.152.144.7216.244.65.146216.244.80.50216.250.7.197217.12.113.67217.169.209.2217.169.214.144217.169.215.175217.219.190.209217.23.192.43217.24.251.46217.66.20.2452.181.177.72.183.155.22.184.6.10219.133.127.49219.133.133.209219.135.191.141219.136.231.6219.137.229.146219.149.45.42219.159.105.180219.159.198.77219.159.198.8219.159.198.81219.159.199.6219.239.227.81219.72.225.251219.83.100.195220.113.1.73220.132.19.136220.247.174.17424.172.34.11431.135.196.22931.14.231.16831.170.179.3531.3.231.23131.47.37.4231.6.71.19831.7.144.6637.200.98.21837.229.97.2141.129.244.7541.130.195.10641.164.23.16241.202.77.19541.203.95.23441.206.30.17841.215.245.7741.215.33.6641.215.77.25041.222.196.3741.230.30.2441.41.138.22641.63.163.1741.73.234.24341.75.111.16241.78.26.15441.79.218.11341.89.130.642.120.18.11842.61.213.9946.102.74.1446.181.135.21546.18.35.22646.21.242.13046.214.137.846.248.38.20546.28.70.15346.28.70.8746.60.48.1795.102.156.255.10.85.345.10.85.355.10.85.365.10.85.375.135.182.1055.152.209.1055.187.32.185.35.245.19154.216.232.17954.228.190.15354.232.227.8554.242.80.9054.247.119.12854.251.204.18959.151.37.859.172.208.1865.9.21.20659.46.67.1085.98.86.14162.162.6.1162.201.207.1462.228.76.25462.240.30.19363.141.233.14864.120.160.17964.181.43.7964.251.14.4164.71.156.21664.79.89.6666.102.141.18666.35.68.14566.35.68.14667.55.2.1568.191.191.9068.71.76.24269.50.64.15372.14.175.22674.118.91.23874.208.123.22574.221.209.22874.252.102.24074.62.137.19074.84.137.24474.95.209.3075.147.16.24477.123.76.15777.52.183.25477.65.19.3578.130.201.11078.141.120.18478.182.202.22378.29.9.10478.47.149.6479.106.109.20679.110.119.12679.110.127.23079.111.12.19979.127.120.6679.174.69.4679.175.187.280.241.44.9880.251.50.23480.48.126.1280.78.232.2680.82.51.3880.84.117.23380.87.82.19480.98.13.17181.17.28.16982.114.95.23882.160.137.16282.207.68.14283.146.70.24683.235.177.20784.124.12.284.124.159.1584.129.234.21084.22.32.22284.241.37.19984.40.111.20684.42.3.385.113.38.22785.114.135.12585.135.52.3085.142.225.17885.234.22.12685.9.74.11186.105.82.8986.120.212.19587.120.152.17387.236.210.4587.236.211.7187.255.68.887.56.228.18088.150.181.13088.150.189.10188.212.48.6488.255.147.8388.85.108.1689.110.41.16589.165.161.13389.179.102.12689.179.244.10289.190.195.17089.222.181.22589.37.196.6589.77.33.12690.151.59.15191.121.8.4791.214.84.11091.221.246.6291.227.23.13891.230.54.6091.232.85.1091.233.188.15491.237.249.6191.239.15.11591.241.21.1091.250.113.16691.75.86.9791.98.155.12091.98.156.14892.39.54.16192.82.190.4092.84.232.20992.84.44.5993.113.82.25493.190.18.14693.43.1.6694.100.0.17994.142.27.494.154.24.194.189.135.8994.198.38.24694.228.204.1095.141.236.25395.154.199.10095.154.199.20095.159.105.295.181.33.2295.24.122.2195.28.54.20195.65.58.6195.82.92.3998.190.245.179Daca v-ati logat dupa ora 00:00, e posibil sa nu mai aveti acces. Imi dati un PM cu adresa voastra IP si se rezolva.As avea o rugaminte pentru cei cu bruteforcerele de ssh: incercati cateva IP-uri din lista si vedeti daca au IP-uri clasice: qwerty sau mai stiu ce parola de dictionar. E posibil sa fie gasite astfel.Have fun. Quote
wildchild Posted September 2, 2013 Report Posted September 2, 2013 Haters gonna hate! Guess what? We're still here! Quote
BkDService Posted September 2, 2013 Report Posted September 2, 2013 Le bag eu acum pe toate la scan, daca se logheaza pe vreunu te anunt si vad si persoana care si-a facut de cap pe root Quote
Brenin Posted September 2, 2013 Report Posted September 2, 2013 Ip-urile pornesc de la 1.* la 255.* asta inseamna ca omul a luat tot netu cu doar 1 user/pass, nu o sa fie greu sa se afle care. Quote
TheOne Posted September 2, 2013 Report Posted September 2, 2013 PMA sau PLESK. Sunt singurile care prind multe. Iti zic din propria experienta, am rupt si eu scannerele alea tot pentru DDoS. Mai pe scurt: INVIDIA!Le bag eu acum pe toate la scan, daca se logheaza pe vreunu te anunt si vad si persoana care si-a facut de cap pe root Ai sa gasesti sigur un perl bot. Cauta bine in /tmp , /var/tmp.. Acolo se ruleaza in general perl bot-ul. Quote
unstoppp Posted September 2, 2013 Report Posted September 2, 2013 Adevarat invidia!, asta ce poate face ii transforma in penibili:)) oricum este tot roman cu siguranta, unu care a primit ,ban,care n-a primit un ajutor din partea cuiva , o promovare:)) Anyway mai trebuie sa inveti prietene cu DDos urile Quote
Nytro Posted September 3, 2013 Author Report Posted September 3, 2013 (edited) Da, ai dreptate. Folosesc portul 8291.Username admin cica ar fi, sa vad ce parola au.Hai coaie, dai DDOS de pe niste routere? Tool pentru conectarea la acele IP-uri: http://download2.mikrotik.com/winbox.exe Edited September 3, 2013 by Nytro Quote
dustfeather Posted September 3, 2013 Report Posted September 3, 2013 ... is it just me, sau chiar nu e nici un server .ro in lista aia ? Intrebarea e, de ce ? Quote
Eric Posted September 3, 2013 Report Posted September 3, 2013 next level : scanam busybox-uri si dam ddos din ele !PS: Nytro, ti-am furat nicku pe mirc ! Quote
TheOne Posted September 3, 2013 Report Posted September 3, 2013 ... is it just me, sau chiar nu e nici un server .ro in lista aia ? Intrebarea e, de ce ?Se prind greu root-urile de romania Trebuie sa stii ceva clase bune. Quote
Dubfx Posted September 3, 2013 Report Posted September 3, 2013 (edited) Se prind greu root-urile de romania Trebuie sa stii ceva clase bune.Foarte greu la routere ... admin:admin admin:default admin:12345678//Le2: pentru roate copiezi de aici lista cu cele mai folosite prenume/nume List? de prenume române?ti - Wikipedia si generezi passfile-ul asa:for i in `cat listanume.txt | tr '[A-Z]' '[a-z]'`;do echo $i:$i;for u in 1 12 123 2010 2011 2012 2013 2014; do echo $i:$i$u;done;done//Le3: Clase IP RO: https://www.countryipblocks.net/country_selection.php , bifat romania / CIDR si gata.Sa ne zici si noua ulterior cat de greu se prind roatele de ro Edited September 3, 2013 by Dubfx Quote
Coice1977 Posted September 3, 2013 Report Posted September 3, 2013 Lazlo Juniori va flodeaza , eu mam lasat de meserie ! Quote
TheOne Posted September 3, 2013 Report Posted September 3, 2013 Foarte greu la routere ... admin:admin admin:default admin:12345678//Le2: pentru roate copiezi de aici lista cu cele mai folosite prenume/nume List? de prenume române?ti - Wikipedia si generezi passfile-ul asa:for i in `cat listanume.txt | tr '[A-Z]' '[a-z]'`;do echo $i:$i;for u in 1 12 123 2010 2011 2012 2013 2014; do echo $i:$i$u;done;done//Le3: Clase IP RO: https://www.countryipblocks.net/country_selection.php , bifat romania / CIDR si gata.Sa ne zici si noua ulterior cat de greu se prind roatele de ro La ssh22 se prinde extrem de greu, pentru ca romanu nu prea pune parole gen : qwerty sau plm . Cele mai multe root-uri de romania am prins cu scannerul de exim. Si PMA-ul prinde, versiunele noi. Quote
Stfean_Iordache Posted September 3, 2013 Report Posted September 3, 2013 lozls trebuie sa ii inveti pe astia ce e ala un flud bun Quote
Nytro Posted September 7, 2013 Author Report Posted September 7, 2013 Paranoici mai sunteti. Nu ne-a atacat nimeni, am lucrat eu la server. Quote