Howdy, Stranger!

It looks like you're new here. If you want to get involved, click one of these buttons!


Why all brute force attempt on all of my server came from China ip? - Page 2
New on LowEndTalk? Please Register and read our Community Rules.

All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.

Why all brute force attempt on all of my server came from China ip?

2

Comments

  • youjingsenlinyoujingsenlin Member
    edited December 2014

    -_-#

  • 90% of chinese people are hackers and spammers?

  • After Mao Zedong era, China was faced with globalization era. The only way to survive is to switch from strictly ideological oriented country, to a self sufficient oriented country.

    They learn to adopt high tech and sell it back to the market with lower price and win the market.

    In the past 20 years, Shen Zhen that used to be paddy fields that every morning people line up to shit in the ditch near the field to be used for fertilizer, has become industrial complexes. Their military technology also gained rapidly and has reached the 4th G class.

    Consequently, people of China have to push themselves to learn western technology either by sending their scholars abroad, or by way of reverse engineering.

    Despite the fact that there is a great firewall that limits general public to access the Internet and death penalty for pornography, the government encourage youngsters to learn the art of CyberWar (Tsun Tzu of modern age).

    Bruteforcing is only a small area where newbies learn new technique of the above mention art :)

  • It seems like they attack every IP available. Even the RaspberryPi, sitting at my home with dynamic IP gets brute forced from few chinese IP's frequently.

    Thanked by 1webcraft
  • @linuxthefish said:
    90% of chinese people are hackers and spammers?

    They use Windows XP and got hacked by hackers, hackers use these rookies to hack others.

  • Is WindowsXP easy to be controllod by hacker? Seriously, I am a fan of WindowsXP.

  • I would recommend sshguard instead fail2ban, because the latter uses much more CPU.

  • socialssocials Member
    edited December 2014

    @psycholyzern said:
    Is WindowsXP easy to be controllod by hacker? Seriously, I am a fan of WindowsXP.

    Windows XP, especially unpatched, has numerous known exploits that can spawn a root shell in a matter of seconds for the attacker.

  • webcraftwebcraft Member
    edited December 2014

    Just ban all possible Chinese IPs. You'll notice a decrease of other attacks, too.

  • howardsl2howardsl2 Member
    edited December 2014

    Comment removed.

  • @psycholyzern : would you mind sharing your motd? (or however you show that once you log in?)

    Thanks :-)

  • @ben78 said:
    psycholyzern : would you mind sharing your motd? (or however you show that once you log in?)

    Thanks :-)

    It shows that by default. It is online.net's 1.99EUR dedi.. Centos 7 installed..
    Quite impressive right? I love this feature too

  • Silvenga said: No. That is completely uneducated, never recommend doing that.

    That guy writes in his article:

    This port can be opened without a privileged account, which means I can write a simple script that listens to port 2222 and mimics SSH in order to capture your passwords.

    Yeah it's so darn simple to write a script, that mimics SSH and then place it on my server to just wait for me to login. Or did he mean in public WiFi areas? Then there it's easy to mimic the same on 22. Really that's a stupid reason.

    You have no way of knowing if you are talking to the real SSH server or not.

    Wait, what? Oo

    That guy writes, that he is "helping other to achieve higher standards in both coding and thinking." What about the SSH handshake? Is that nothing?

    Although I agree, that it won't help much to move SSH ports, I think the article is crap.

  • @creep said:
    Botnets are not only exist with Chinese IPs, but there are backdoors in any Chinese products like 1+1 phone and Huawei. I really recommend you to stay away from any chinese products.

    I'm sure cisco even have more backdoors :p

  • @hotsnow said:
    I'm sure cisco even have more backdoors :p

    No surprise in that.

  • psycholyzern said: It shows that by default. It is online.net's 1.99EUR dedi.. Centos 7 installed.. Quite impressive right? I love this feature too

    Yeah, that's really nice. Probably something default with Centos, will check that out.
    Thanks!

  • Why are you begging for attacks from another country other than China? An attack is an attack, generally you want less of them regardless of origin.

  • @vRozenSch00n said:
    death penalty for pornography

    I ask you to find a single evidence of that.

  • hzwill said: So thats how you understand about word "pornography"?

    Nope.

  • @vRozenSch00n said:
    Nope.

    That man was sentenced to death. Not beacuse he doing some porn. Because he enslave, rape, abuse, and finally killed 2 of 6 women sexual slaves.

    Thanked by 1vRozenSch00n
  • Thank you, I stand corrected.

  • @hzwill So you are from Jiang Su?

  • @vRozenSch00n said:
    hzwill So you are from Jiang Su?

    Yes

  • It's good to know someone from the mainland who don not obfuscate the whois address :)

    Seems that Shang Hai has grown to be a Megapolitan City now.

    Thanked by 1netomx
  • How about Wu Xi? Has it grown too?

  • Already been a huge city due to the fast urbanization of china. Paid high price but also full of opportunities.

  • Yeah, I heard about that too. There are many new millionaires from Jiang Su from what I heard from my cousin.

  • @kcaj said:
    Why are you begging for attacks from another country other than China? An attack is an attack, generally you want less of them regardless of origin.

    That is not the issue here. Server in the screenshot I posted above is a new server. I just installed Centos 7 less than 24hours and already got 14464 attempt to get my password. And the attacker came from ip in China. Yet, almost all of server that I own from anoher provider has been brute forced.

    It makes me wonder why no ip from other countries attacking me? Dont worry about the safety because it was new clean installed server and surely Im gonna take important step to secure it before I start to use it for production purpose.

Sign In or Register to comment.