r00igev@@r
Honorary Master
- Joined
- Dec 14, 2009
- Messages
- 15,645
- Reaction score
- 14,160
- Location
- Draadloos Bantha poo doo in 4ways
South Africa’s biggest forum. Discuss, discover, and connect with thousands of members.
Ultimately if the client has no idea about security and they aren't posing as a threat then its a challenge to enforce.I think ISPs should do vulnerability scans on their ranges and email subscribers with p@wned routers or infrastructure. Most ISPs in ZA provide little added value.
Search your IP on beta.shodan.io
Spare a thought for this bloke....
View attachment 1390362
There's other things that can be done.Ultimately if the client has no idea about security and they aren't posing as a threat then its a challenge to enforce.
Despite us recommending that clients not enable RDP from the outside and use firewall available to them, most of them ignore it...
Convenience vs security....
True, I can send a packet to most places in ZA with the source being a RFC1918 IP.There's other things that can be done.
Block spoofed packets, for a start. There's no reason whatsoever for a packet with a source IP outside your range to be permitted out of your customer networks
I think ISPs should do vulnerability scans on their ranges and email subscribers with p@wned routers or infrastructure. Most ISPs in ZA provide little added value.
Search your IP on beta.shodan.io
Spare a thought for this bloke....
View attachment 1390362
What is that box? Is it related to http://www.scode.co.za/ The payments system that defaults to non-encrypted?We always advise clients to make use of a firewall with a selected ip whitelist to access. Not use default RDP ports and use the build in lockout feature after 3 invalid login attempts.
Unfortunately these servers are self managed and as the ISP we only get involved when there is abuse linked to the IP.
I deal with the abuse queue every day and I take servers offline as soon as I see complaints about abuse on our hosting.
Connectivity IP's are difficult because of the number of ways it can be used in a botnet like MikroTik routers which is the MAIN contributors as well a windows computers that are compromised due to malware installed.
Love how the scode.co.za site breaks when you manually type https:// XD. It's like you're misusing it by opting for a secure connection.What is that box? Is it related to http://www.scode.co.za/ The payments system that defaults to non-encrypted?
We should create a separate thread for stupid security brainfarts.Love how the scode.co.za site breaks when you manually type https:// XD. It's like you're misusing it by opting for a secure connection.
Yep, enforce segmentation and comb them off to a VM where anything goes.We always advise clients to make use of a firewall with a selected ip whitelist to access. Not use default RDP ports and use the build in lockout feature after 3 invalid login attempts.
Unfortunately these servers are self managed and as the ISP we only get involved when there is abuse linked to the IP.
I deal with the abuse queue every day and I take servers offline as soon as I see complaints about abuse on our hosting.
Connectivity IP's are difficult because of the number of ways it can be used in a botnet like MikroTik routers which is the MAIN contributors as well a windows computers that are compromised due to malware installed.
Less system resources to DoS.What is that box? Is it related to http://www.scode.co.za/ The payments system that defaults to non-encrypted?
Having been at the receiving end of DD's incompetence several times, you have my sympathies.Update : As of this morning the attack is ongoing and we've exhausted our reliance on DD / Optinet to assist in mitigating the attack.
We are in discussion with a new provider at the moment and updates will be sent to all clients during the course of the day.
To all our clients, please accept our apologies for this and thanks for your support.
just received this:Update : As of this morning the attack is ongoing and we've exhausted our reliance on DD / Optinet to assist in mitigating the attack.
We are in discussion with a new provider at the moment and updates will be sent to all clients during the course of the day.
To all our clients, please accept our apologies for this and thanks for your support.
If it turns out to be a targeted attack from an individual or company and is provenm then I hope the culprit/s are named and shamed!Having been at the receiving end of DD's incompetence several times, you have my sympathies.
You guys (and girls) are an amazing company and I hope that whatever sinister plot is behind this does not succeed in damaging your excellent reputation.