KymcoForum.com

General => General Discussion => Topic started by: GLV55 on December 14, 2014, 06:02:16 PM

Title: Why are we getting Russian spam?
Post by: GLV55 on December 14, 2014, 06:02:16 PM
All of a sudden there is a ton of crap being posted by some Russian spammer on this forum. Moderator needs to exorcise the demon!  >:(  We didn't go through the Cold War only to have to put up with this junk. Grrrr!
Title: Re: Why are we getting Russian spam?
Post by: zombie on December 14, 2014, 08:37:11 PM
I have not seen it yet but lately there is a flood of spam on the net. It's coming from three different sources. One is a server in the Netherlands that is known for allowing illegal Internet traffic (ie: spammers/hackers), another is a china based server that is primarily hacking whatever it gets a return "ping" from, and the third is in the Russian federation. that one is a compilation of spam, and DOS attacks.

The only thing that can be done (on Skad's end) is weather the storm until the servers are shut down. or temporally block the IP ranges the attacks are coming from. The issue there is legit net users are also in the ranges of the attacks.

The net is a dangerous place. I am completely surprised that 90% of the users are not knowingly experiencing issues w/ their equipment. Perhaps it is only 2-3% that realize there is even an issue.
Title: Re: Why are we getting Russian spam?
Post by: GLV55 on December 15, 2014, 12:57:29 AM
The Kymco forum hereby authorizes Zombie to seek out and destroy on our behalf!
Title: Re: Why are we getting Russian spam?
Post by: AMAC1680 on December 15, 2014, 01:08:49 AM
I saw, it was all over .
Don't know why I didn't understand any of it but had 6 vodka tonics while reading it......

Be big.
AMAC
Title: Re: Why are we getting Russian spam?
Post by: zombie on December 15, 2014, 01:26:08 AM
The Kymco forum hereby authorizes Zombie to seek out and destroy on our behalf!

I only go after the ones that target me. Otherwise I'd never leave the computer.
 It's easy to shut down a server... All you really need is an army of zombie computers or several smaller more powerful servers that have open ports.
 Be careful what emails you open or what links you click on porn sites.
There are lists of "zombie computers" on every hacking web site/forum.

WiKi
"Zombies can be used to conduct distributed denial-of-service attacks, a term which refers to the orchestrated flooding of target websites by large numbers of computers at once. The large number of Internet users making simultaneous requests of a website's server are intended to result in crashing and the prevention of legitimate users from accessing the site.[3] A variant of this type of flooding is known as distributed degradation-of-service. Committed by "pulsing" zombies, distributed degradation-of-service is the moderated and periodical flooding of websites, done with the intent of slowing down rather than crashing a victim site. The effectiveness of this tactic springs from the fact that intense flooding can be quickly detected and remedied, but pulsing zombie attacks and the resulting slow-down in website access can go unnoticed for months and even years.[4]"

http://blog.pluralsight.com/videos/ethical-hacking-how-to-create-a-dos-attack (http://blog.pluralsight.com/videos/ethical-hacking-how-to-create-a-dos-attack)

I love this stuff. It's more fun that scooters.
Title: Re: Why are we getting Russian spam?
Post by: zombie on December 15, 2014, 01:28:29 AM
I saw, it was all over .
Don't know why I didn't understand any of it but had 6 vodka tonics while reading it......

Be big.
AMAC

3 triple Martini's... When I sit on the roof, I can see your house.
Title: Re: Why are we getting Russian spam?
Post by: GLV55 on December 15, 2014, 02:57:02 AM
Pardon the French....or maybe Russian......b@st@rds!
Title: Re: Why are we getting Russian spam?
Post by: zombie on December 15, 2014, 03:36:26 AM
Skads gonna have to ban the account. That's all there is.

I forgot about signing up as a member.

I do wish they had better products... I don't need the blue pill (yet) ;D
Title: Re: Why are we getting Russian spam?
Post by: AMAC1680 on December 15, 2014, 06:52:22 AM
3 triple Martini's... When I sit on the roof, I can see your house.

Stop looking down on me, comrade ...... :o

Be Big,
AMAC
Title: Re: Why are we getting Russian spam?
Post by: zombie on December 15, 2014, 07:52:32 AM
I was looking up.  ::)

То, что я увидел, глядя страшно борщ из меня .
Title: Re: Why are we getting Russian spam?
Post by: bluesin on December 15, 2014, 01:23:32 PM
I reported this to Skad yesterday .

I have a warped(slightly ) sense of humor...but those went too far .

Being a Swede I had 8 straight shots of Skandia vodka.... my eyes still burned , but - I vcould fly ( I think? ) . ???
Title: Re: Why are we getting Russian spam?
Post by: zombie on December 15, 2014, 03:08:43 PM
That's how I wound up on the roof.
Three drinks, and  I was chasing a turtle.
Next thing I knew I was stuck up there (he knocked down the ladder). Then...  he (the turtle) started chasing my dogs down the street on my scooter.

Thank god for Twinkles. When he came outside to smoke a Cig. I just stepped off, onto his head, went inside, and called it a night.
Title: Re: Why are we getting Russian spam?
Post by: bluesin on December 15, 2014, 03:22:30 PM
That's how I wound up on the roof.
Three drinks, and  I was chasing a turtle.
Next thing I knew I was stuck up there (he knocked down the ladder). Then...  he (the turtle) started chasing my dogs down the street on my scooter.

Thank god for Twinkles. When he came outside to smoke a Cig. I just stepped off, onto his head, went inside, and called it a night.

Glad you made it down safely ! Surprised winkles was tall enough after the leg surgery . Must have been what he was smoking :

https://www.youtube.com/watch?v=UyY-6oh0Ow8 (https://www.youtube.com/watch?v=UyY-6oh0Ow8)
Title: Re: Why are we getting Russian spam?
Post by: zombie on December 15, 2014, 03:28:03 PM
No... you have no idea... That SOB is HUGE! Even w/ no legs.

Ps... I go everywhere but never leave this town... 8)
 
Title: Re: Why are we getting Russian spam?
Post by: skadamo on December 15, 2014, 08:37:28 PM
Thanks for the patience on this guys.

I run multiple forums and they were all getting a lot of spammers the last few days.

Zombie, that is interesting info about the source servers. I'm interested to hear where you found it.

These spam users are all automated. The spammers must have a human being go in and figure out the security question on the registration page. Then they create a script that looks for the text of the question and then specifies the right answer it pulls from a database. On some sites I removed a single character from the question and it stopped the spammer registrations. In the defense of the spammers they don't make it too hard to stop them so they give me fighting chance. :D I know some are capable of taking this site down if they really want to so I will be cautious about what I say about them ;)
Title: Re: Why are we getting Russian spam?
Post by: zombie on December 15, 2014, 10:04:59 PM
"Zombie, that is interesting info about the source servers. I'm interested to hear where you found it. "

Pm'd.

Yeah... No need to piss these guys off, and start a muscle flexing contest. They have the entire net to mess with. It's like a few million, against one fight.
You got US tho (if that helps)...
Title: Re: Why are we getting Russian spam?
Post by: 1g0g on December 16, 2014, 03:08:20 PM
in Russia, too, a lot of spam before Christmas, many believe that this is an American spam))
Title: Re: Why are we getting Russian spam?
Post by: bluesin on December 16, 2014, 05:57:28 PM
Avoid ALL posts by AlbertMer today ( unless you want to play casino games with Russian hackers ) .
Title: Re: Why are we getting Russian spam?
Post by: 1g0g on December 16, 2014, 09:40:37 PM
 ;D ;D
Title: Re: Why are we getting Russian spam?
Post by: zombie on December 16, 2014, 10:01:16 PM
The US is just as guilty as everyone else with one real exception. The rest of the world is busy finding zombie computers to spread the spam, while the US is actually hacking servers around the world to seize control, and eventually shut down the net.

If your next question is "How do you know this?"

I was at the meeting...
Title: Re: Why are we getting Russian spam?
Post by: 1g0g on December 17, 2014, 09:30:05 AM
If your next question is "How do you know this?"
I was at the meeting...

 :o
Title: Re: Why are we getting Russian spam?
Post by: zombie on December 17, 2014, 06:52:04 PM
 8)    :-*
Title: Re: Why are we getting Russian spam?
Post by: zombie on December 17, 2014, 08:06:00 PM
Ok, here it is in real time...
 I just got a "port scan". The IP is  (94.102.51.20)
Went to...   http://whatismyipaddress.com (http://whatismyipaddress.com)
The ip comes back...
General IP Information

IP:   94.102.51.20
Decimal:   1583756052
Hostname:   94.102.51.20
ISP:   Ecatel LTD
Organization:   Ecatel LTD
Services:   None detected
Type:   
Assignment:   Static IP
Blacklist:   
Geolocation Information

Country:   Netherlands nl flag
State/Region:   Noord-Holland
City:   Amsterdam
Latitude:   52.35  (52° 20′ 60.00″ N)
Longitude:   4.9167  (4° 55′ 0.12″ E)

Google search for Ecatel LTD...
Cloudflare and Ecatel working together to help Cyber crimals ...
www.webhostingtalk.com (http://www.webhostingtalk.com) › ... › Dedicated Server
Aug 14, 2012 - 15 posts - ‎7 authors
I am here to inform you all of Ecatel's and Cloudflare's relationship. Ecatel want proof of there clients doing anything illegal? Well isn't hosting a ...

This is what most of you are not seeing happen to your PC's.
If there is any flaw in your security (ie: your PC returns their ping) your PC is now the one that is forwarding their spam/or worse.
They find an open in port, transmit their data which flows thru your out port, and carries your IP to the next destination.
Generally they are looking for zombies. Computers to do their bidding. The more they find the larger their influence on the net, and the more spam they can deliver.

To stop them you need either Fort Knox firewall or Eset NOD firewall, AND Peer Block.
Fort Knox or ESET are the only firewalls I know of the report both port scans, AND MAC spoofing. Once they report a potential attack you can add that IP to Peer Blocks block list, and sleep tight.

Without these reports... there is no way of knowing if/when you are zombified.
Title: Re: Why are we getting Russian spam?
Post by: bluesin on December 18, 2014, 01:10:28 PM
Thanks for the info ! Good to know.
Title: Re: Why are we getting Russian spam?
Post by: zombie on December 23, 2014, 12:05:46 AM
It's more important than most think. Cyber attacks are not happening less often.

They are happening thousands of times an hour. It's a game of odds if your system is using sub par or antiquated security.
The firewall is the front line of defense.

This is where you go to test your firewall. I'll bet 80% of you that take the test will fail.
If you do, I can show you where to get what you need for free.

https://www.grc.com/x/ne.dll?bh0bkyd2 (https://www.grc.com/x/ne.dll?bh0bkyd2)
Title: Re: Why are we getting Russian spam?
Post by: zombie on December 27, 2014, 10:57:16 PM
Here's an update on all this...

My GF, and her GF were using my living room PC. It's a sophisticated rig to say the least.
I can manage it because I built it but these two gals had no clue what all the warnings/notifications meant.

They went about their business, and shut it down. When I powered up this morning I started seeing, "Florida Dept. of Banking and Finance" show up on PeerBlock.
Looking at the source it was originating from MY PC.

Open the firewall logs to find my Opera Browser auto Update is the program sending this. Opera was not even running, just the updater.

I ran several virus scans/nothing. I ran several "rootkit" checks/nothing. I ran several Malware checks/nothing.

Finally I opened the Opera folder, and removed the auto update file, and re-installed a new EXE. file.
The traffic stopped.

I was not here when this began so I can not say where this "Worm?Trojan" came from but without PeerBlock, and the firewall combo I have, my PC would be doing who knows what, and who knows where.

My suspicion is my computer was zombified to do someone else's dirty work.
It's a scary place, the web... Just for example... PeerBlock is right now set on my pc to block 1,339,593,233 ip's
That's Billion w/ a B. These are only the KNOWN ip's you don't want contacting or being contacted tru your pc.

Check it out for yourself. You'll be amazed at what is connecting thru your pc every time you switch it on...

http://www.peerblock.com/ (http://www.peerblock.com/)

https://www.iblocklist.com/ (https://www.iblocklist.com/)

Here's another Very good firewall... free. It does NOT detect MAC spoofing but it does log everything.

http://www.privacyware.com/products.html (http://www.privacyware.com/products.html)



Title: Re: Why are we getting Russian spam?
Post by: GLV55 on December 28, 2014, 05:41:00 PM
Ummm.....wow.....way over my head. Just glad you're on our side, Z. (You are on our side, right?)
Title: Re: Why are we getting Russian spam?
Post by: zombie on December 28, 2014, 07:30:29 PM
!,000,000,000,000 % GLV!

I actually know very little about all of this stuff. I do know enough to follow the bread crumbs but that's about it.
Coding is like magic/alchemy to me so I stick to software, and researching cures to problems.

Another example... 2 nights ago I was D'loading that movie "The Interview". (the one N.Korea is "supposedly" upset about)
Normally I see a lot of "anti P2P groups based in the US attempting to infiltrate, and stop p2p swarms.

On this torrent there are dozens of China based organizations attempting to stop it or at least get info on who/where. Chinese universities/Govt. based organizations, and LOTS of different IP's based in Beijing. Normally they don't bother with pirate traffic.

Just sayin... There are MANY more bad guys out there than just the NSA.

Ps... If you get the chance to see that movie... go for it. It is F'n funny!!!
Title: Re: Why are we getting Russian spam?
Post by: GLV55 on December 29, 2014, 04:16:10 AM
Thanks for the tip on the movie!
Title: Re: Why are we getting Russian spam?
Post by: zombie on December 29, 2014, 05:57:38 AM
 ;)