<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>[blog.rayfoo] &#187; blacklist</title>
	<atom:link href="http://blog.rayfoo.info/tag/blacklist/feed" rel="self" type="application/rss+xml" />
	<link>http://blog.rayfoo.info</link>
	<description>Infosec, DFIR, tech geekery, thoughts and whatnot</description>
	<lastBuildDate>Wed, 25 Jan 2012 00:36:47 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>SSH brute force connection attempts #fail</title>
		<link>http://blog.rayfoo.info/2009/10/ssh-brute-force-connection-attempts-fail</link>
		<comments>http://blog.rayfoo.info/2009/10/ssh-brute-force-connection-attempts-fail#comments</comments>
		<pubDate>Tue, 20 Oct 2009 02:18:17 +0000</pubDate>
		<dc:creator>ray</dc:creator>
				<category><![CDATA[Everything]]></category>
		<category><![CDATA[audit trail]]></category>
		<category><![CDATA[blacklist]]></category>
		<category><![CDATA[brute forcing]]></category>
		<category><![CDATA[fail]]></category>
		<category><![CDATA[hardening]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[SSH]]></category>

		<guid isPermaLink="false">http://blog.rayfoo.info/?p=273</guid>
		<description><![CDATA[Collected these over the past few months, reverse chronological order. Seeing different machines attempting to connect hundreds of times a day each is just, wow. Some might say that a SSH blacklist daemon might help, but it only increases the time taken for a brute force attempt, and is of no use against a botnet [...]]]></description>
			<content:encoded><![CDATA[<p>Collected these over the past few months, reverse chronological order.  Seeing different machines attempting to connect <strong>hundreds</strong> of times a day each is just, wow.</p>
<p>Some might say that a SSH blacklist daemon might help, but it only increases the time taken for a brute force attempt, and is of no use against a botnet trying to brute force the ssh login.</p>
<p>There are plenty of things that can be done to lock down the ssh server, and restricting it to only publickey is by far one of the most effective, counting that the resource (the server) you're protecting is pretty important.<br />
<span id="more-273"></span><br />
Plenty of interesting IPs/hosts in this list, take a look if you're really interested, heh. <img src='http://blog.rayfoo.info/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
<p style="color:green;">reverse mapping checking getaddrinfo for <span style="color: #ff0000;">93.184.69.3.vnet.sk [93.184.69.3]</span> failed - POSSIBLE BREAK-IN ATTEMPT! : <span style="color: #ff0000;">237 time(s)</span><br />
reverse mapping checking getaddrinfo for <span style="color: #ff0000;">95-128-245-59.wiseweb.ru [95.128.245.59]</span> failed - POSSIBLE BREAK-IN ATTEMPT! : <span style="color: #ff0000;">567 time(s)</span><br />
reverse mapping checking getaddrinfo for <span style="color: #ff0000;">h-69-3-215-11-static.lsanca54.covad.net [69.3.215.11]</span> failed - POSSIBLE BREAK-IN ATTEMPT! : <span style="color: #ff0000;">543 time(s)</span><br />
reverse mapping checking getaddrinfo for iodc-74-206-96-142.ioconnect.net [74.206.96.142] failed - POSSIBLE BREAK-IN ATTEMPT! : 6 time(s)<br />
reverse mapping checking getaddrinfo for 202-153-191-246-static.unigate.net.tw [202.153.191.246] failed - POSSIBLE BREAK-IN ATTEMPT! : 5 time(s)<br />
reverse mapping checking getaddrinfo for corporat065-167059038.sta.etb.net.co [65.167.59.38] failed - POSSIBLE BREAK-IN ATTEMPT! : 19 time(s)<br />
reverse mapping checking getaddrinfo for ev1s-75-125-43-50.theplanet.com [75.125.43.50] failed - POSSIBLE BREAK-IN ATTEMPT! : 46 time(s)<br />
reverse mapping checking getaddrinfo for hst13.migrateplans.com [72.46.131.181] failed - POSSIBLE BREAK-IN ATTEMPT! : 68 time(s)<br />
reverse mapping checking getaddrinfo for <span style="color: #ff0000;">bzq-179-135-183.static.bezeqint.net [212.179.135.183]</span> failed - POSSIBLE BREAK-IN ATTEMPT! : <span style="color: #ff0000;">298 time(s)</span><br />
reverse mapping checking getaddrinfo for host112163.metrored.net.mx [200.77.249.163] failed - POSSIBLE BREAK-IN ATTEMPT! : 8 time(s)<br />
Address 98.126.208.50 maps to customer.krypt.com, but this does not map back to the address - POSSIBLE BREAK-IN ATTEMPT! : 50 time(s)<br />
reverse mapping checking getaddrinfo for corporat200-7543230.sta.etb.net.co [200.75.43.230] failed - POSSIBLE BREAK-IN ATTEMPT! : 97 time(s)<br />
Address 61.168.44.5 maps to pc5.zz.ha.cn, but this does not map back to the address - POSSIBLE BREAK-IN ATTEMPT! : 50 time(s)<br />
reverse mapping checking getaddrinfo for ip36.70.inetmar.com [92.42.36.70] failed - POSSIBLE BREAK-IN ATTEMPT! : 50 time(s)<br />
Address 218.28.20.135 maps to pc0.zz.ha.cn, but this does not map back to the address - POSSIBLE BREAK-IN ATTEMPT! : 168 time(s)<br />
reverse mapping checking getaddrinfo for <span style="color: #ff0000;">187-5-142-129.bnut3700.e.brasiltelecom.net.br [187.5.142.129]</span> failed - POSSIBLE BREAK-IN ATTEMPT! : <span style="color: #ff0000;">478 time(s)</span><br />
reverse mapping checking getaddrinfo for <span style="color: #ff0000;">cliente-13108.iberbanda.es [82.198.115.50] </span>failed - POSSIBLE BREAK-IN ATTEMPT! : <span style="color: #ff0000;">324 time(s)</span><br />
reverse mapping checking getaddrinfo for <span style="color: #ff6600;">host-203-92-76-19.lga.net.sg [203.92.76.19] </span>failed - POSSIBLE BREAK-IN ATTEMPT! : 5 time(s)<br />
reverse mapping checking getaddrinfo for <span style="color: #ff0000;">229.1.163.220.broad.km.yn.dynamic.163data.com.cn [220.163.1.229]</span> failed - POSSIBLE BREAK-IN ATTEMPT! : <span style="color: #ff0000;">240 time(s)</span><br />
reverse mapping checking getaddrinfo for 56h29.xjtu.edu.cn [202.117.56.29] failed - POSSIBLE BREAK-IN ATTEMPT! : 54 time(s)<br />
reverse mapping checking getaddrinfo for 202.53.76.24.nettlinx.com [202.53.76.24] failed - POSSIBLE BREAK-IN ATTEMPT! : 45 time(s)<br />
Address 218.28.103.202 maps to pc0.zz.ha.cn, but this does not map back to the address - POSSIBLE BREAK-IN ATTEMPT! : 373 time(s)<br />
Address 72.9.228.73 maps to marisil.org, but this does not map back to the address - POSSIBLE BREAK-IN ATTEMPT! : 6 time(s)<br />
Address 72.9.228.73 maps to marisil.org, but this does not map back to the address - POSSIBLE BREAK-IN ATTEMPT! : 6 time(s)<br />
reverse mapping checking getaddrinfo for 74.126.30.110.static.a2webhosting.com [74.126.30.110] failed - POSSIBLE BREAK-IN ATTEMPT! : 15 time(s)<br />
reverse mapping checking getaddrinfo for 74.126.30.110.static.a2webhosting.com [74.126.30.110] failed - POSSIBLE BREAK-IN ATTEMPT! : 15 time(s)</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.rayfoo.info/2009/10/ssh-brute-force-connection-attempts-fail/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Finexis&#8217; new tactic: Social Engineering</title>
		<link>http://blog.rayfoo.info/2009/09/finexis-new-tactic-social-engineering</link>
		<comments>http://blog.rayfoo.info/2009/09/finexis-new-tactic-social-engineering#comments</comments>
		<pubDate>Mon, 07 Sep 2009 08:58:27 +0000</pubDate>
		<dc:creator>ray</dc:creator>
				<category><![CDATA[Everything]]></category>
		<category><![CDATA[blacklist]]></category>
		<category><![CDATA[social engineering]]></category>
		<category><![CDATA[telemarketing]]></category>

		<guid isPermaLink="false">http://blog.rayfoo.info/?p=56</guid>
		<description><![CDATA[Just got a call from Finexis, trying to get/trick me into going down to talk to their financial consultants. They are now trying to do so by saying that there's been some changes to their(implied: your) policies, and want you do go down for a session with them. Problem is, I don't have any policies [...]]]></description>
			<content:encoded><![CDATA[<p>Just got a call from Finexis, trying to get/trick me into going down to talk to their financial consultants.  They are now trying to do so by saying that there's been some changes to their(implied: your) policies, and want you do go down for a session with them.</p>
<p>Problem is, I don't have any policies with them <img src='http://blog.rayfoo.info/wp-includes/images/smilies/icon_biggrin.gif' alt=':D' class='wp-smiley' />   Well, one more number (6341 5315) in my blacklist.</p>
<p>Do be warned.</p>
<p>For the curious, our conversation went like this:</p>
<blockquote><p><span style="color: #ff0000;">Her: Hi, may I speak to Ray?</span><br />
(note that she already has my name, so I continue to talk to her, for now)</p>
<p><span style="color: #00ccff;">Me: Yeah, what's up?</span></p>
<p><span style="color: #ff0000;">Her: I'm calling from Finexis.  There's been a change with some of our policies...</span></p>
<p><span style="color: #00ccff;">Me: Huh?  But do I have any plans with Finexis?</span><br />
(I know I don't)</p>
<p><span style="color: #ff0000;">Her: Errr...no.. But we'd like to invite you down to have a talk with one of our financial consultants on this.</span></p>
<p><span style="color: #00ccff;">Me: (laughs) No thanks <img src='http://blog.rayfoo.info/wp-includes/images/smilies/icon_biggrin.gif' alt=':D' class='wp-smiley' />  *hangs up*</span></p></blockquote>
]]></content:encoded>
			<wfw:commentRss>http://blog.rayfoo.info/2009/09/finexis-new-tactic-social-engineering/feed</wfw:commentRss>
		<slash:comments>6</slash:comments>
		</item>
	</channel>
</rss>

