Rocksolid Light

Welcome to novaBBS (click a section below)

mail  files  register  newsreader  groups  login

Message-ID:  

"It's like deja vu all over again." -- Yogi Berra


computers / comp.os.vms / Re: Anti-virus ?

SubjectAuthor
* Anti-virus ?Niels S. Eliasen
+* Re: Anti-virus ?Ian Miller
|`* Re: Anti-virus ?John Dallman
| +- Re: Anti-virus ?Simon Clubley
| +* Re: Anti-virus ?Arne Vajhøj
| |`* Re: Anti-virus ?Dave Froble
| | +* Re: Anti-virus ?Arne Vajhøj
| | |`- Re: Anti-virus ?Dave Froble
| | `* Re: Anti-virus ?bill
| |  `- Re: Anti-virus ?Arne Vajhøj
| `* Re: Anti-virus ?Ehud Gavron
|  `- Re: Anti-virus ?John Dallman
+* Re: Anti-virus ?Dave Froble
|`* Re: Anti-virus ?Dave Froble
| `- Re: Anti-virus ?John Vottero
+* Re: Anti-virus ?Simon Clubley
|`* Re: Anti-virus ?Arne Vajhøj
| `* Re: Anti-virus ?Simon Clubley
|  +* Re: Anti-virus ?Jan-Erik Söderholm
|  |`* Re: Anti-virus ?Simon Clubley
|  | +- Re: Anti-virus ?Chris Townley
|  | +* Re: Anti-virus ?Dave Froble
|  | |`* Re: Anti-virus ?Simon Clubley
|  | | +* Re: Anti-virus ?Dave Froble
|  | | |`- Re: Anti-virus ?Simon Clubley
|  | | `* Re: Anti-virus ?Hunter Goatley
|  | |  +* Re: ssh dictionary attacks, DDoS (was: Re: Anti-virus ?)Stephen Hoffman
|  | |  |`- Re: ssh dictionary attacks, DDoSHunter Goatley
|  | |  +* Re: Anti-virus ?Steven Schweda
|  | |  |`* Re: Anti-virus ?Hunter Goatley
|  | |  | `* Re: Anti-virus ?Robert A. Brooks
|  | |  |  `- Re: Anti-virus ?Hunter Goatley
|  | |  `- Re: Anti-virus ?Mark Daniel
|  | `* Re: Anti-virus ?Johnny Billquist
|  |  +* Re: Anti-virus ?plugh
|  |  |`* Re: Anti-virus ?Johnny Billquist
|  |  | +* Re: Anti-virus ?plugh
|  |  | |`* Re: Anti-virus ?Johnny Billquist
|  |  | | `* Re: Anti-virus ?bill
|  |  | |  +* Re: Anti-virus ?Dave Froble
|  |  | |  |+- Re: Anti-virus ?cao...@pitbulluk.org
|  |  | |  |`- Re: Anti-virus ?Johnny Billquist
|  |  | |  +* Re: Anti-virus ?Single Stage to Orbit
|  |  | |  |`- Re: Anti-virus ?Johnny Billquist
|  |  | |  `- Re: Anti-virus ?Johnny Billquist
|  |  | `* Re: Anti-virus ?Brian Schenkenberger
|  |  |  `- Re: Anti-virus ?Johnny Billquist
|  |  `- Re: Anti-virus ?Simon Clubley
|  `* Re: Anti-virus ?Arne Vajhøj
|   +- Re: Anti-virus ?Arne Vajhøj
|   `- Re: Anti-virus ?plugh
+* Re: Anti-virus ?Bob Gezelter
|`* Re: Anti-virus ?Stephen Hoffman
| `- Re: Anti-virus ?Arne Vajhøj
`- Re: Anti-virus ?Arne Vajhøj

Pages:123
Re: Anti-virus ?

<ubgoj6$18s$4@news.misty.com>

  copy mid

https://www.novabbs.com/computers/article-flat.php?id=29267&group=comp.os.vms#29267

  copy link   Newsgroups: comp.os.vms
Path: i2pn2.org!i2pn.org!weretis.net!feeder6.news.weretis.net!news.misty.com!.POSTED.31-208-186-157.cust.bredband2.com!not-for-mail
From: bqt...@softjar.se (Johnny Billquist)
Newsgroups: comp.os.vms
Subject: Re: Anti-virus ?
Date: Tue, 15 Aug 2023 22:52:54 +0200
Organization: MGT Consulting
Message-ID: <ubgoj6$18s$4@news.misty.com>
References: <64d49602$0$702$14726298@news.sunsite.dk>
<ub2kbb$c590$1@dont-email.me> <ub3qam$hlh8$2@dont-email.me>
<ub59m6$rege$1@dont-email.me> <ub5fk2$sago$1@dont-email.me>
<ub5rg8$u5nr$1@dont-email.me> <ub7nkl$1di$2@news.misty.com>
<4f492589-945d-4548-bb96-f346ce4db117n@googlegroups.com>
<ubd271$g3l$2@news.misty.com> <ubg62j$2smck$1@dont-email.me>
Mime-Version: 1.0
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 7bit
Injection-Date: Tue, 15 Aug 2023 20:52:54 -0000 (UTC)
Injection-Info: news.misty.com; posting-host="31-208-186-157.cust.bredband2.com:31.208.186.157";
logging-data="1308"; mail-complaints-to="abuse@misty.com"
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:102.0)
Gecko/20100101 Thunderbird/102.14.0
In-Reply-To: <ubg62j$2smck$1@dont-email.me>
 by: Johnny Billquist - Tue, 15 Aug 2023 20:52 UTC

On 2023-08-15 17:36, Brian Schenkenberger wrote:
> On 2023-08-14 11:12:32 +0000, Johnny Billquist said:
>
>> Examples:
>>
>> . GET /wp-login.php
>>
>> (seems to be just lots of these probing if wordpress is running on the
>> host, so lots of variations on this one...)
>
> ERROR 404
> We're sorry but it looks like you're lost.
> The requested paged does not exist.

Oh. Definitely. But just by looking at the amount of such attempts, it
tells me that wp is a really bad idea to have running anywhere.
But it would never even be possible to run under RSX in the first place,
so I'm not too worried about it.

Yes. 404. And if they insist on 20 more variants, they get blocked for a
while so I don't have them DOSing my web server with stupidity.

Johnny

Re: ssh dictionary attacks, DDoS

<ubjars$3e482$1@dont-email.me>

  copy mid

https://www.novabbs.com/computers/article-flat.php?id=29269&group=comp.os.vms#29269

  copy link   Newsgroups: comp.os.vms
Path: i2pn2.org!i2pn.org!eternal-september.org!news.eternal-september.org!.POSTED!not-for-mail
From: goathun...@goatley.com (Hunter Goatley)
Newsgroups: comp.os.vms
Subject: Re: ssh dictionary attacks, DDoS
Date: Wed, 16 Aug 2023 16:16:57 -0400
Organization: A noiseless patient Spider
Lines: 70
Message-ID: <ubjars$3e482$1@dont-email.me>
References: <64d49602$0$702$14726298@news.sunsite.dk>
<ub2kbb$c590$1@dont-email.me> <ub3qam$hlh8$2@dont-email.me>
<ub59m6$rege$1@dont-email.me> <ub5fk2$sago$1@dont-email.me>
<ub5rg8$u5nr$1@dont-email.me> <ub60tt$v154$1@dont-email.me>
<ubd7ac$2atei$1@dont-email.me> <ube589$2fjjv$1@dont-email.me>
<ube847$2fufj$1@dont-email.me>
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 8bit
Injection-Date: Wed, 16 Aug 2023 20:17:00 -0000 (UTC)
Injection-Info: dont-email.me; posting-host="1c4e10d7882a199e4c661cdfcb14e4e0";
logging-data="3608834"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX19hQqu2utncWhzt4dqS8oa3kry8EssRgco="
User-Agent: Mozilla Thunderbird
Cancel-Lock: sha1:YP0Nc7dIHgysQZT9fVrlMaswuEQ=
In-Reply-To: <ube847$2fufj$1@dont-email.me>
Content-Language: en-US
 by: Hunter Goatley - Wed, 16 Aug 2023 20:16 UTC

On 8/14/2023 5:59 PM, Stephen Hoffman wrote:
>
> Put a three or so second delay ahead of each ssh connection prior to the
> password processing, and put a five or ten second delay after a failed
> password, and then a delay again before dropping the connection when
> disconnecting from a failed login.
>
> Make the delays adjustable via configuration file or via (gag) logical
> names or such, if following OpenVMS app configuration UI norms.  I've
> met a few of these that build the delay within the text shown while
> stalling, so the characters will dribble back to the originating host.

Nice suggestions, but bots don't really care how long it takes, from
what I've seen. Depends on the bots, of course.

> Adding support for fail2ban into ssh would be a nice addition if not
> already present, but adding it is probably more work than adding delays,
> and less able to handle botnet brute-force and DDoS shenanigans.

That's effectively what MultiNet's Intrusion Prevention Service is doing.

>
> That's usually either a resource leak, or resource exhaustion when
> things get too busy and all this as you are well aware, of course.

Yep. I'm just not sure where. The filtering stuff should not be using
paged pool. The search continues.

> The mail server should probably check the incoming mail server
> connection DNS for DANE or SPF or such, and force incoming connections
> to STARTTLS, and quite possibly add an RBL check.

Some of that is being done already. SPF checks are made, but that
doesn't stop connections. RBL lists are checked, but they're
surprisingly not very effective (at least the ones I'm using).

> There are a half-dozen or so settings in POSTFIX related to this
> anti-spam and related processing that can really slow the malicious
> traffic. (I'd expect OpenSMTPd has some similarities, but haven't had
> the opportunity to implement that in production.)

PreciseMail does a great job of handling the spam. The problem isn't
incoming mail, but just the connections that issue AUTH commands
repeatedly, trying to find something that works. The IPS stops them, but
there are so many from so many different IP addresses....

> Another option I've used—may or may not be an option here, and that for
> various reasons—is to relay incoming and outgoing messages via whatever
> mail server VSI is using, depending on the anti-spam and related
> capabilities of the VSI mail server. (Yeah, my suggestion around all of
> this reply including using relay is probably impolitic here, and, yeah,
> VSI might not want to "share" their mail server.)

Again, the problem isn't mail coming in. It's bots trying to find
accounts that are valid.

As I said before, blocking certain countries would go a long to stopping
the problem....

Thanks for your comments!

--
Hunter
------
Hunter Goatley, Process Software, http://www.process.com/
goathunter@goatley.com http://hunter.goatley.com/

Re: Anti-virus ?

<ubjau2$3e482$2@dont-email.me>

  copy mid

https://www.novabbs.com/computers/article-flat.php?id=29270&group=comp.os.vms#29270

  copy link   Newsgroups: comp.os.vms
Path: i2pn2.org!i2pn.org!eternal-september.org!news.eternal-september.org!.POSTED!not-for-mail
From: goathun...@goatley.com (Hunter Goatley)
Newsgroups: comp.os.vms
Subject: Re: Anti-virus ?
Date: Wed, 16 Aug 2023 16:18:07 -0400
Organization: A noiseless patient Spider
Lines: 21
Message-ID: <ubjau2$3e482$2@dont-email.me>
References: <64d49602$0$702$14726298@news.sunsite.dk>
<ub2kbb$c590$1@dont-email.me> <ub3qam$hlh8$2@dont-email.me>
<ub59m6$rege$1@dont-email.me> <ub5fk2$sago$1@dont-email.me>
<ub5rg8$u5nr$1@dont-email.me> <ub60tt$v154$1@dont-email.me>
<ubd7ac$2atei$1@dont-email.me> <ube589$2fjjv$1@dont-email.me>
<29ea4192-4364-4623-8f54-9100e7bc3605n@googlegroups.com>
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 7bit
Injection-Date: Wed, 16 Aug 2023 20:18:10 -0000 (UTC)
Injection-Info: dont-email.me; posting-host="1c4e10d7882a199e4c661cdfcb14e4e0";
logging-data="3608834"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX1/cj0kK7VQkTk6Z7wt9IGAQ0SAzhC5SKmw="
User-Agent: Mozilla Thunderbird
Cancel-Lock: sha1:/wuVVQTG3pC5T7OM8eaICeJ0HN0=
Content-Language: en-US
In-Reply-To: <29ea4192-4364-4623-8f54-9100e7bc3605n@googlegroups.com>
 by: Hunter Goatley - Wed, 16 Aug 2023 20:18 UTC

On 8/14/2023 9:29 PM, Steven Schweda wrote:
>> [...] dictionary attacks via SSH [...]
>
> Don't listen at port 22? Since I stopped port-forwarding port 22, I
> see approximately none of these. I don't see adding "-p xxxx" to a
> command as a hardship.
>
> If you want strangers to use it, then you would need to publish the
> actual port number someplace, of course, but I would expect the robots
> not to read much.

Historically, EISNER management hasn't wanted to make things difficult
for people---which I understand---otherwise, I'd have moved it from port
22 years ago. But I'm lobbying again to make that change.

--
Hunter
------
Hunter Goatley, Process Software, http://www.process.com/
goathunter@goatley.com http://hunter.goatley.com/

Re: Anti-virus ?

<ubjm76$3fkuk$1@dont-email.me>

  copy mid

https://www.novabbs.com/computers/article-flat.php?id=29273&group=comp.os.vms#29273

  copy link   Newsgroups: comp.os.vms
Path: i2pn2.org!i2pn.org!eternal-september.org!news.eternal-september.org!.POSTED!not-for-mail
From: FIRST.L...@vmssoftware.com (Robert A. Brooks)
Newsgroups: comp.os.vms
Subject: Re: Anti-virus ?
Date: Wed, 16 Aug 2023 19:30:46 -0400
Organization: A noiseless patient Spider
Lines: 11
Message-ID: <ubjm76$3fkuk$1@dont-email.me>
References: <64d49602$0$702$14726298@news.sunsite.dk>
<ub2kbb$c590$1@dont-email.me> <ub3qam$hlh8$2@dont-email.me>
<ub59m6$rege$1@dont-email.me> <ub5fk2$sago$1@dont-email.me>
<ub5rg8$u5nr$1@dont-email.me> <ub60tt$v154$1@dont-email.me>
<ubd7ac$2atei$1@dont-email.me> <ube589$2fjjv$1@dont-email.me>
<29ea4192-4364-4623-8f54-9100e7bc3605n@googlegroups.com>
<ubjau2$3e482$2@dont-email.me>
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 7bit
Injection-Date: Wed, 16 Aug 2023 23:30:46 -0000 (UTC)
Injection-Info: dont-email.me; posting-host="2c83c3a7626004df4a40c6d3e279150f";
logging-data="3658708"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX1/r5vU4SNbZlLkeKMO68rfGzwYgz02QSZsUkk/Wmp6Mmg=="
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:102.0) Gecko/20100101
Thunderbird/102.14.0
Cancel-Lock: sha1:W5tBDHzxkJJW4wiVYNGyWqNNMX4=
Content-Language: en-US
In-Reply-To: <ubjau2$3e482$2@dont-email.me>
X-Antivirus: Avast (VPS 230816-6, 8/16/2023), Outbound message
X-Antivirus-Status: Clean
 by: Robert A. Brooks - Wed, 16 Aug 2023 23:30 UTC

On 8/16/2023 4:18 PM, Hunter Goatley wrote:
> Historically, EISNER management hasn't wanted to make things difficult for
> people---which I understand---otherwise, I'd have moved it from port 22 years
> ago. But I'm lobbying again to make that change.

+1!

--

--- Rob

Re: Anti-virus ?

<ubvdh9$1rqdh$1@dont-email.me>

  copy mid

https://www.novabbs.com/computers/article-flat.php?id=29313&group=comp.os.vms#29313

  copy link   Newsgroups: comp.os.vms
Path: i2pn2.org!i2pn.org!eternal-september.org!news.eternal-september.org!.POSTED!not-for-mail
From: goathun...@goatley.com (Hunter Goatley)
Newsgroups: comp.os.vms
Subject: Re: Anti-virus ?
Date: Mon, 21 Aug 2023 06:16:07 -0400
Organization: A noiseless patient Spider
Lines: 18
Message-ID: <ubvdh9$1rqdh$1@dont-email.me>
References: <64d49602$0$702$14726298@news.sunsite.dk>
<ub2kbb$c590$1@dont-email.me> <ub3qam$hlh8$2@dont-email.me>
<ub59m6$rege$1@dont-email.me> <ub5fk2$sago$1@dont-email.me>
<ub5rg8$u5nr$1@dont-email.me> <ub60tt$v154$1@dont-email.me>
<ubd7ac$2atei$1@dont-email.me> <ube589$2fjjv$1@dont-email.me>
<29ea4192-4364-4623-8f54-9100e7bc3605n@googlegroups.com>
<ubjau2$3e482$2@dont-email.me> <ubjm76$3fkuk$1@dont-email.me>
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8; format=flowed
Content-Transfer-Encoding: 7bit
Injection-Date: Mon, 21 Aug 2023 10:16:09 -0000 (UTC)
Injection-Info: dont-email.me; posting-host="482e272e4f80048b68782ae0145fd389";
logging-data="1960369"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX1/mw6Mq5AQyh6/0VJEwPa5T1my4O+CXYqI="
User-Agent: Mozilla Thunderbird
Cancel-Lock: sha1:5iIFBTnngHauNDk2Y4AYlNClK3c=
In-Reply-To: <ubjm76$3fkuk$1@dont-email.me>
Content-Language: en-US
 by: Hunter Goatley - Mon, 21 Aug 2023 10:16 UTC

On 8/16/2023 7:30 PM, Robert A. Brooks wrote:
> On 8/16/2023 4:18 PM, Hunter Goatley wrote:
>> Historically, EISNER management hasn't wanted to make things difficult
>> for people---which I understand---otherwise, I'd have moved it from
>> port 22 years ago. But I'm lobbying again to make that change.
>
> +1!
>
And done:

https://eisner.decus.org/online/ssh

--
Hunter
------
Hunter Goatley, Process Software, http://www.process.com/
goathunter@goatley.com http://hunter.goatley.com/


computers / comp.os.vms / Re: Anti-virus ?

Pages:123
server_pubkey.txt

rocksolid light 0.9.81
clearnet tor