Fighting Crackers at Christmas
This marks the third Christmas week in ten years where I spent an absurd amount of time fighting off bad guys on my server(s). It makes me miserable to have to spend time doing this when I could be out caroling, or skating, or socializing.
--16:23:03-- http://www.euphoria.gr/forum/files/test.pl
Resolving www.euphoria.gr... 89.234.44.185
Connecting to www.euphoria.gr|89.234.44.185|:80... connected.
HTTP request sent, awaiting response... 200 OK
Length: 32719 (32K) [text/plain]
Saving to: `test.pl.1'
0K .......... .......... .......... . 100% 72.4K=0.4s
16:23:04 (72.4 KB/s) - `test.pl.1' saved [32719/32719]
rm: cannot remove `/var/log/lastlog': Permission denied
rm: cannot remove `/var/log/wtmp': Permission denied
... a zillion recursive rm commands that would have destroyed my box elided ...
Dec 16 04:18:39 ns1 postfix/smtpd[15044]: warning: 200.103.97.142: hostname 200-103-97-142.gnace300.ipd.brasiltelecom.net.br verification failed: Name or service not known
Dec 16 04:18:39 ns1 postfix/smtpd[15044]: connect from unknown[200.103.97.142]
Dec 16 04:18:41 ns1 postfix/smtpd[15044]: NOQUEUE: reject: RCPT from unknown[200.103.97.142]: 504 5.5.2: Helo command rejected: need fully-qualified hostname; from= to= proto=ESMTP helo=
Dec 16 04:18:41 ns1 postfix/smtpd[15044]: lost connection after DATA from unknown[200.103.97.142]
Dec 16 04:18:41 ns1 postfix/smtpd[15044]: disconnect from unknown[200.103.97.142]
admin.transconf.net-access_log.2:217.33.12.98 - - [15/Dec/2007:14:46:10 -0500] "And the various rbl filters enabled stop an extraordinary amount of spam, but still quite a few get through...
POST http://lti-mail01.ltinetworks.com:25/ HTTP/1.0" 406 342
admin.transconf.net-access_log.2:217.33.12.98 - - [15/Dec/2007:14:46:10 -0500] "
CONNECT http://lti-mail01.ltinetworks.com:25 HTTP/1.0" 400 309
admin.transconf.net-error_log.2:[Sat Dec 15 14:46:10 2007] [error] [client 217.3
3.12.98] mod_security: Access denied with code 406. Pattern match "^$" at HEADER
("USER-AGENT") [severity "EMERGENCY"] [hostname "lti-mail01.ltinetworks.com"] [u
ri "http://lti-mail01.ltinetworks.com:25/"]
audit_log.1:Request: lti-mail01.ltinetworks.com 217.33.12.98 - - [15/Dec/2007:14
:46:10 --0500] "POST http://lti-mail01.ltinetworks.com:25/ HTTP/1.0" 406 342 "-"
"-" - "-"
audit_log.1:POST http://lti-mail01.ltinetworks.com:25/ HTTP/1.0
www.teklibre.com-error_log:[Sun Dec 23 15:53:37 2007] [error] [client 82.128.20.
28] PHP Notice: Undefined variable: emaillist in http://chelseacharms.com/cart/
small/longthing.txt?.inc on line 160
www.teklibre.com-error_log:[Sun Dec 23 15:54:23 2007] [error] [client 82.128.20.
28] PHP Notice: Undefined variable: emaillist in http://chelseacharms.com/cart/
small/longthing.txt?.inc on line 160
www.teklibre.com-error_log:[Tue Dec 25 01:23:58 2007] [error] [client 82.128.18.
1] PHP Notice: Undefined variable: emaillist in http://chelseacharms.com/cart/s
mall/longthing.txt?.inc on line 160
www.teklibre.com-error_log:[Tue Dec 25 01:24:05 2007] [error] [client 82.128.18.
1] PHP Notice: Undefined variable: emaillist in http://chelseacharms.com/cart/s
mall/longthing.txt?.inc on line 160
www.teklibre.com-error_log.1:[Sun Dec 16 08:00:35 2007] [error] [client 83.229.5
.133] PHP Notice: Undefined variable: emaillist in http://chelseacharms.com/car
t/small/longthing.txt?.inc on line 160
www.teklibre.com-error_log.1:[Sun Dec 16 08:01:36 2007] [error] [client 82.128.2
0.85] PHP Notice: Undefined variable: emaillist in http://chelseacharms.com/car
t/small/longthing.txt?.inc on line 160
www.teklibre.com-error_log:[Tue Dec 25 01:24:05 2007] [error] [client 82.128.18.
1] PHP Notice: Undefined variable: emaillist in http://chelseacharms.com/cart/s
mall/longthing.txt?.inc on line 160
[client 67.202.18.57] ModSecurity: Access denied with code 400 (phase 2). Match of "rx ^[a-z]{3,10}\\\\s*(?:\\\\w{3,7}?\\\\:\\\\/\\\\/[\\\\w\\\\-\\\\.\\\\/]*)??\\\\/[\\\\w\\\\-\\\\.\\\\/~%:@&=+$,;]*(?:\\\\?[\\\\S]*)??\\\\s*http\\\\/\\\\d\\\\.\\\\d$" against "REQUEST_LINE" required. [id "960911"] [msg "Invalid HTTP Request Line"] [severity "CRITICAL"] [hostname "www.transconf.net"] [uri "?"] [unique_id "WI27AAyhxKUAACKHIpIAAAAK"]
57.18.202.67.in-addr.arpa name = ec2-67-202-18-57.compute-1.amazonaws.com.
Labels: spam
Labels: laughter
Resume,Songs,
My new blog, NeX-6, My facebook page
Orgs I like
The EFF - keeping free speech in the world
Musical stuff I like
Jeff, Rick, Ardour, Jack
Prior Rants -
New song: Log Off Now
Sharing your home network better in a time of covi...
Designing for the disconnect
Email lists going down the memory hole
Instituting saner, professional source code manage...
Wireless and Wifi in 2015 - not what I dreamed of
Saving wifi! Fixing Bufferbloat! Fighting the vend...
Virgin Media - Fixing the epidemic of bufferbloat ...
49... and trying to find my navel
Wheels down on mars!
Best of the blog:
Uncle Bill's Helicopter - A speech I gave to ITT Tech - Chicken soup for engineers
Beating the Brand - A pathological exploration of how branding makes it hard to think straight
Inside the Internet Mind - trying to map the weather within the global supercomputer that consists of humans and google
Sex In Politics - If politicians spent more time pounding the flesh rather than pressing it, it would be a better world
Getting resources from space - An alternative to blowing money on mars using NEAs.
On the Columbia - Why I care about space
Authors I like:
Doc Searls
Where's Cherie?
UrbanAgora
Jerry Pournelle
The Cubic Dog
Evan Hunt
The Bay Area is talking
Brizzled
Zimnoiac Emanations
Eric Raymond
Unlocking The Air
Bob Mage
BroadBand & Me
SpaceCraft
Selenian Boondocks
My Pencil
Transterrestial Musings
Bear Waller Hollar
Callahans