Author Topic: XDEVS - Scrap the bots. Thank you.  (Read 3562 times)

0 Members and 1 Guest are viewing this topic.

Offline manupthehillsTopic starter

  • Contributor
  • Posts: 40
  • Country: us
XDEVS - Scrap the bots. Thank you.
« on: November 10, 2022, 04:39:20 am »
It's a bit off topics here, but I guess it will get quicker to the source.
What's happening? (Xdevs.com)
« Last Edit: November 10, 2022, 07:57:39 am by EEVblog »
 

Online mendip_discovery

  • Frequent Contributor
  • **
  • Posts: 856
  • Country: gb
Re: Scrap the bots. Thank you.
« Reply #1 on: November 10, 2022, 07:01:16 am »
TiN is Ukrainian by birth and his website may have become a target for the hacking bots. I know he had issues with the FTP being messed with a few months back. If you need any info you might find it in the waybackmachine.
Motorcyclist, Nerd, and I work in a Calibration Lab :-)
--
So everyone is clear, Calibration = Taking Measurement against a known source, Verification = Checking Calibration against Specification, Adjustment = Adjusting the unit to be within specifications.
 

Offline EEVblog

  • Administrator
  • *****
  • Posts: 37786
  • Country: au
    • EEVblog
Re: Scrap the bots. Thank you.
« Reply #2 on: November 10, 2022, 07:57:18 am »
I've email him, will let you know if he replies.
 

Online mendip_discovery

  • Frequent Contributor
  • **
  • Posts: 856
  • Country: gb
Re: XDEVS - Scrap the bots. Thank you.
« Reply #3 on: November 10, 2022, 11:44:20 am »
He is in the US so physically safe(ish).

My own website has been getting a lot of attention. I even host my local village (Parish) council website and I am having to keep a very close eye on that as it's got the script kiddies etc trying to brute force their way in.

Motorcyclist, Nerd, and I work in a Calibration Lab :-)
--
So everyone is clear, Calibration = Taking Measurement against a known source, Verification = Checking Calibration against Specification, Adjustment = Adjusting the unit to be within specifications.
 
The following users thanked this post: Mechatrommer, Roman oh

Offline JohanH

  • Frequent Contributor
  • **
  • Posts: 627
  • Country: fi
Re: XDEVS - Scrap the bots. Thank you.
« Reply #4 on: November 10, 2022, 12:45:01 pm »

My own website has been getting a lot of attention. I even host my local village (Parish) council website and I am having to keep a very close eye on that as it's got the script kiddies etc trying to brute force their way in.


Fail2ban and psad intrusion detection in combination with iptables makes a site relatively free from unwanted traffic. Occasionally permanently banning some Asian IP ranges (both IPv4 and IPv6) does wonders as well. And of course installing security updates when they are available. Also, if you run wordpress and such you are quite vulnerable. Nowadays I only have static web sites with some DB backend. FTP isn't recommended in this day and age.
 

Offline JohanH

  • Frequent Contributor
  • **
  • Posts: 627
  • Country: fi
Re: XDEVS - Scrap the bots. Thank you.
« Reply #5 on: November 10, 2022, 01:02:18 pm »

FTP isn't recommended in this day and age.

If I had to use something ftp-like (like an anonymous upload service), I would use sftp server (using ssh), create an "anonymous" user with null password, create an ssh chroot and disable shell login. Users would have to use sftp clients to upload (Filezilla, WinSCP, any linux client). Web browsers don't support ftp any more, but the "ftp" file structure can be shared read-only through the web. It's very dangerous, though, so you have to know what you are doing. I wouldn't keep anything else on the same server and block it so they can't access anything else if it's hacked.
« Last Edit: November 10, 2022, 01:21:21 pm by JohanH »
 

Offline EEVblog

  • Administrator
  • *****
  • Posts: 37786
  • Country: au
    • EEVblog
Re: XDEVS - Scrap the bots. Thank you.
« Reply #6 on: November 10, 2022, 10:17:48 pm »
I heard back from TiN

Quote
There is a DOS attack on my server going on since evening of Nov 6 from various VPNs in EU/Switzerland.
Somebody also deleted all old files in guest public FTP folder used to upload manuals/T&M stuff and uploaded bunch of russian propaganda videos instead.

As result I've put a dummy page on webserver temporarily while figuring out how to deal with this.
I'm not an IT guy and self-host my server in basement.

All site data and content are safe, so will be back up once it's resolved.

Offline Black Phoenix

  • Super Contributor
  • ***
  • Posts: 1129
  • Country: hk
Re: XDEVS - Scrap the bots. Thank you.
« Reply #7 on: November 11, 2022, 03:36:22 am »
There wasn't someone who offer to help TiN to host the website somewhere else? I remember reading that somewhere.

Probably Dave you should put both in contact, no?
 

Offline EEVblog

  • Administrator
  • *****
  • Posts: 37786
  • Country: au
    • EEVblog
Re: XDEVS - Scrap the bots. Thank you.
« Reply #8 on: November 13, 2022, 11:07:33 pm »
xdevs site is now back up and running. The bot attack has subsided.  :-+
 
The following users thanked this post: croma641, Kean, 2N3055, seebeck, DavidKo, DH7DN

Offline Zenwizard

  • Regular Contributor
  • *
  • Posts: 164
  • Country: us
Re: XDEVS - Scrap the bots. Thank you.
« Reply #9 on: November 30, 2022, 03:39:19 pm »
TiN, If there is something that I can help with in the IT space let me know. I have a very deep background in IT.

Zen
You Tube Link - Fixing broken Things
 

Offline kada

  • Contributor
  • Posts: 31
  • Country: ie
Re: XDEVS - Scrap the bots. Thank you.
« Reply #10 on: December 27, 2022, 11:38:52 pm »
xdevs is down for me unfortunately, I'm located in Ireland.  :-//
Could somebody please confirm is it still working?
 

Offline sahko123

  • Frequent Contributor
  • **
  • Posts: 318
  • Country: ie
Re: XDEVS - Scrap the bots. Thank you.
« Reply #11 on: December 27, 2022, 11:48:30 pm »
im in ireland and its alright for me
Asking for a friend
 

Offline kada

  • Contributor
  • Posts: 31
  • Country: ie
Re: XDEVS - Scrap the bots. Thank you.
« Reply #12 on: December 28, 2022, 12:00:48 am »
Thanks for the replying, looks like it's somehow related to the Chrome browser, works fine in Edge.
 


Share me

Digg  Facebook  SlashDot  Delicious  Technorati  Twitter  Google  Yahoo
Smf