<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>[blog.rayfoo] &#187; fail</title>
	<atom:link href="http://blog.rayfoo.info/tag/fail/feed" rel="self" type="application/rss+xml" />
	<link>http://blog.rayfoo.info</link>
	<description>Infosec, DFIR, tech geekery, thoughts and whatnot</description>
	<lastBuildDate>Wed, 25 Jan 2012 00:36:47 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Spam comment FAIL</title>
		<link>http://blog.rayfoo.info/2010/10/spam-comment-fail</link>
		<comments>http://blog.rayfoo.info/2010/10/spam-comment-fail#comments</comments>
		<pubDate>Sun, 31 Oct 2010 14:30:19 +0000</pubDate>
		<dc:creator>ray</dc:creator>
				<category><![CDATA[Everything]]></category>
		<category><![CDATA[comment]]></category>
		<category><![CDATA[epic]]></category>
		<category><![CDATA[fail]]></category>
		<category><![CDATA[spam]]></category>

		<guid isPermaLink="false">http://blog.rayfoo.info/?p=747</guid>
		<description><![CDATA[Found this gem in my wordpress spam comment queue. What blog platform are you using?  I've been looking for a new one, and this seems much cleaner than wordpress. I really wanted to approve this spam comment just so that I can respond to it]]></description>
			<content:encoded><![CDATA[<p>Found this gem in my wordpress spam comment queue.</p>
<blockquote><p>What blog platform are you using?  I've been looking for a new one, and this seems much cleaner than wordpress.</p></blockquote>
<p>I really wanted to approve this spam comment just so that I can respond to it <img src='http://blog.rayfoo.info/wp-includes/images/smilies/icon_razz.gif' alt=':P' class='wp-smiley' /> </p>
<p><a href="http://blog.rayfoo.info/wp-content/uploads/2010/10/spam-comment-fail.png"><img class="aligncenter size-full wp-image-748" title="spam-comment-fail" src="http://blog.rayfoo.info/wp-content/uploads/2010/10/spam-comment-fail.png" alt="" width="600" height="269" /></a></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.rayfoo.info/2010/10/spam-comment-fail/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>SSH brute force connection attempts #fail</title>
		<link>http://blog.rayfoo.info/2009/10/ssh-brute-force-connection-attempts-fail</link>
		<comments>http://blog.rayfoo.info/2009/10/ssh-brute-force-connection-attempts-fail#comments</comments>
		<pubDate>Tue, 20 Oct 2009 02:18:17 +0000</pubDate>
		<dc:creator>ray</dc:creator>
				<category><![CDATA[Everything]]></category>
		<category><![CDATA[audit trail]]></category>
		<category><![CDATA[blacklist]]></category>
		<category><![CDATA[brute forcing]]></category>
		<category><![CDATA[fail]]></category>
		<category><![CDATA[hardening]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[SSH]]></category>

		<guid isPermaLink="false">http://blog.rayfoo.info/?p=273</guid>
		<description><![CDATA[Collected these over the past few months, reverse chronological order. Seeing different machines attempting to connect hundreds of times a day each is just, wow. Some might say that a SSH blacklist daemon might help, but it only increases the time taken for a brute force attempt, and is of no use against a botnet [...]]]></description>
			<content:encoded><![CDATA[<p>Collected these over the past few months, reverse chronological order.  Seeing different machines attempting to connect <strong>hundreds</strong> of times a day each is just, wow.</p>
<p>Some might say that a SSH blacklist daemon might help, but it only increases the time taken for a brute force attempt, and is of no use against a botnet trying to brute force the ssh login.</p>
<p>There are plenty of things that can be done to lock down the ssh server, and restricting it to only publickey is by far one of the most effective, counting that the resource (the server) you're protecting is pretty important.<br />
<span id="more-273"></span><br />
Plenty of interesting IPs/hosts in this list, take a look if you're really interested, heh. <img src='http://blog.rayfoo.info/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' /> </p>
<p style="color:green;">reverse mapping checking getaddrinfo for <span style="color: #ff0000;">93.184.69.3.vnet.sk [93.184.69.3]</span> failed - POSSIBLE BREAK-IN ATTEMPT! : <span style="color: #ff0000;">237 time(s)</span><br />
reverse mapping checking getaddrinfo for <span style="color: #ff0000;">95-128-245-59.wiseweb.ru [95.128.245.59]</span> failed - POSSIBLE BREAK-IN ATTEMPT! : <span style="color: #ff0000;">567 time(s)</span><br />
reverse mapping checking getaddrinfo for <span style="color: #ff0000;">h-69-3-215-11-static.lsanca54.covad.net [69.3.215.11]</span> failed - POSSIBLE BREAK-IN ATTEMPT! : <span style="color: #ff0000;">543 time(s)</span><br />
reverse mapping checking getaddrinfo for iodc-74-206-96-142.ioconnect.net [74.206.96.142] failed - POSSIBLE BREAK-IN ATTEMPT! : 6 time(s)<br />
reverse mapping checking getaddrinfo for 202-153-191-246-static.unigate.net.tw [202.153.191.246] failed - POSSIBLE BREAK-IN ATTEMPT! : 5 time(s)<br />
reverse mapping checking getaddrinfo for corporat065-167059038.sta.etb.net.co [65.167.59.38] failed - POSSIBLE BREAK-IN ATTEMPT! : 19 time(s)<br />
reverse mapping checking getaddrinfo for ev1s-75-125-43-50.theplanet.com [75.125.43.50] failed - POSSIBLE BREAK-IN ATTEMPT! : 46 time(s)<br />
reverse mapping checking getaddrinfo for hst13.migrateplans.com [72.46.131.181] failed - POSSIBLE BREAK-IN ATTEMPT! : 68 time(s)<br />
reverse mapping checking getaddrinfo for <span style="color: #ff0000;">bzq-179-135-183.static.bezeqint.net [212.179.135.183]</span> failed - POSSIBLE BREAK-IN ATTEMPT! : <span style="color: #ff0000;">298 time(s)</span><br />
reverse mapping checking getaddrinfo for host112163.metrored.net.mx [200.77.249.163] failed - POSSIBLE BREAK-IN ATTEMPT! : 8 time(s)<br />
Address 98.126.208.50 maps to customer.krypt.com, but this does not map back to the address - POSSIBLE BREAK-IN ATTEMPT! : 50 time(s)<br />
reverse mapping checking getaddrinfo for corporat200-7543230.sta.etb.net.co [200.75.43.230] failed - POSSIBLE BREAK-IN ATTEMPT! : 97 time(s)<br />
Address 61.168.44.5 maps to pc5.zz.ha.cn, but this does not map back to the address - POSSIBLE BREAK-IN ATTEMPT! : 50 time(s)<br />
reverse mapping checking getaddrinfo for ip36.70.inetmar.com [92.42.36.70] failed - POSSIBLE BREAK-IN ATTEMPT! : 50 time(s)<br />
Address 218.28.20.135 maps to pc0.zz.ha.cn, but this does not map back to the address - POSSIBLE BREAK-IN ATTEMPT! : 168 time(s)<br />
reverse mapping checking getaddrinfo for <span style="color: #ff0000;">187-5-142-129.bnut3700.e.brasiltelecom.net.br [187.5.142.129]</span> failed - POSSIBLE BREAK-IN ATTEMPT! : <span style="color: #ff0000;">478 time(s)</span><br />
reverse mapping checking getaddrinfo for <span style="color: #ff0000;">cliente-13108.iberbanda.es [82.198.115.50] </span>failed - POSSIBLE BREAK-IN ATTEMPT! : <span style="color: #ff0000;">324 time(s)</span><br />
reverse mapping checking getaddrinfo for <span style="color: #ff6600;">host-203-92-76-19.lga.net.sg [203.92.76.19] </span>failed - POSSIBLE BREAK-IN ATTEMPT! : 5 time(s)<br />
reverse mapping checking getaddrinfo for <span style="color: #ff0000;">229.1.163.220.broad.km.yn.dynamic.163data.com.cn [220.163.1.229]</span> failed - POSSIBLE BREAK-IN ATTEMPT! : <span style="color: #ff0000;">240 time(s)</span><br />
reverse mapping checking getaddrinfo for 56h29.xjtu.edu.cn [202.117.56.29] failed - POSSIBLE BREAK-IN ATTEMPT! : 54 time(s)<br />
reverse mapping checking getaddrinfo for 202.53.76.24.nettlinx.com [202.53.76.24] failed - POSSIBLE BREAK-IN ATTEMPT! : 45 time(s)<br />
Address 218.28.103.202 maps to pc0.zz.ha.cn, but this does not map back to the address - POSSIBLE BREAK-IN ATTEMPT! : 373 time(s)<br />
Address 72.9.228.73 maps to marisil.org, but this does not map back to the address - POSSIBLE BREAK-IN ATTEMPT! : 6 time(s)<br />
Address 72.9.228.73 maps to marisil.org, but this does not map back to the address - POSSIBLE BREAK-IN ATTEMPT! : 6 time(s)<br />
reverse mapping checking getaddrinfo for 74.126.30.110.static.a2webhosting.com [74.126.30.110] failed - POSSIBLE BREAK-IN ATTEMPT! : 15 time(s)<br />
reverse mapping checking getaddrinfo for 74.126.30.110.static.a2webhosting.com [74.126.30.110] failed - POSSIBLE BREAK-IN ATTEMPT! : 15 time(s)</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.rayfoo.info/2009/10/ssh-brute-force-connection-attempts-fail/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

