Author Topic: Behind the scenes.. they try, but can't come in...  (Read 7141 times)

0 Members and 1 Guest are viewing this topic.

Offline saratogaWX

  • Administrator
  • Forecaster
  • *****
  • Posts: 9257
  • Saratoga, CA, USA Weather - free PHP scripts
    • Saratoga-Weather.org
Behind the scenes.. they try, but can't come in...
« on: July 27, 2014, 07:26:30 PM »
We've had a fairly active population of robots trying to register for the forum lately, but none have succeeded, and if they do, they still have to be manually approved and validate their email (not a likely proposition).

Here's a sample from the logs for today (27-July-2014, as of 4pm Pacific) for every IP that tried 10 or more times to register today:
Code: [Select]
Count              IP                             Owner of IP space
    190 114.222.71.101 Chinanet Jiangsu Province
     76 80.80.193.17 MTS OJSC, Russia
     57 208.105.116.114 Time Warner Cable Internet LLC
     44 95.105.29.136 OJSC "Ufanet", Russia
     38 93.124.60.38 OJSC Rostelecom, Russia
     38 86.57.195.192 RUE Beltelecom, Belarus
     38 76.112.88.76 Comcast Cable Communications, Inc., USA
     36 108.93.236.23 AT&T Internet Services
     32 37.236.167.250 EarthLink Ltd. -Orange, Iraq
     32 113.57.190.23 China Unicom HuBei Province Network
     30 98.159.142.195 Big Sandy Broadband Inc, USA
     23 91.236.75.64 Andrzej Niechcial mgr., Poland
     20 77.79.166.212 OJSC "Ufanet", Russia
     17 99.157.252.221 AT&T Internet Services
     14 46.4.103.83 Hetzner Online AG
     13 111.10.103.41 China Mobile Comm
     12 82.114.92.33 Kujtesa Net Sh.p.k., Albania
     12 188.208.15.124 SC RADOS IMPEX SRL, Romania
     12 183.141.175.143 CHINANET Zhejiang province
     11 93.118.75.160 SC EVERHOST SRL, Romania
     11 89.212.78.35 T-2, d.o.o., Slovenia
     11 36.250.178.87 China Unicom Fujian Province
     11 198.204.235.226 Data Shack
     10 95.148.151.121 OUK Broadband IP Stream, United Kingdom
     10 94.153.9.53 Kyivstar PJSC, Ukraine
     10 93.118.65.130 SC EVERHOST SRL, Romania
     10 192.99.19.154 OVH Hosting, Inc., Canada

What is interesting is that groups of IPs try the same number of times and are likely controlled by an individual bot-herder, and the attempts are from disparate geographies.  China, Russia, Ukraine play a large role (since they have lax server/IP policing against miscreants), but some US, UK, Canada hosters are in there too.

During the same period, here's the top set of IP's denied access by .htaccess due to their misbehavior
Code: [Select]
Count     IP               Owner of IP space
    408 46.119.122.105 Golden Telecom LLC, Ukraine(htaccess)
     80 195.211.155.136 Unit-IS Ltd (UA)(htaccess)
     76 193.201.224.84 Alpha-Telecom-NET (Ukraine)(htaccess)
     48 193.201.224.10 Alpha-Telecom-NET (Ukraine)(htaccess)
     48 134.249.50.51 Kyivstar GSM (Ukraine) (Blocked)(htaccess)
     42 91.200.12.39 GLUBINA-NET(UA) (Blocked)(htaccess)
     40 91.207.7.110 PP Andrey Kiselev, Ukraine(htaccess)
     38 46.118.114.182 Golden Telecom LLC, Ukraine(htaccess)
     24 91.207.5.10 PP Andrey Kiselev, Ukraine(htaccess)
     24 46.119.121.136 Golden Telecom LLC, Ukraine(htaccess)
     22 171.113.74.93 CHINANET Hubei province(htaccess)
     20 91.207.5.225 PP Andrey Kiselev, Ukraine(htaccess)
     19 107.150.50.242 DataShack North Kansas City (MO,USA)(htaccess)
     16 91.207.4.2 PP Andrey Kiselev, Ukraine(htaccess)
     16 76.164.218.194 Versaweb (Las Vegas, NV)(htaccess)
     16 27.153.137.213 CHINANET FUJIAN PROVINCE(htaccess)
     16 193.201.224.74 Alpha-Telecom-NET (Ukraine)(htaccess)
     16 193.201.224.38 Alpha-Telecom-NET (Ukraine)(htaccess)
     14 91.207.6.81 PP Andrey Kiselev, Ukraine(htaccess)
     13 95.108.244.252 Yandex LLC(RU) (Blocked)(htaccess)
     12 91.200.12.1 GLUBINA-NET(UA) (Blocked)(htaccess)
     11 107.150.59.178 DataShack North Kansas City (MO,USA)(htaccess)
     10 94.102.56.236 Ecatel Hosting (Netherlands)(htaccess)
     10 91.207.7.81 PP Andrey Kiselev, Ukraine(htaccess)
     10 91.200.13.7 GLUBINA-NET(UA) (Blocked)(htaccess)
     10 37.115.191.237 Kyivstar GSM, Kiev, Ukraine(htaccess)
     10 195.211.155.158 Unit-IS Ltd (UA)(htaccess)
     10 193.201.224.58 Alpha-Telecom-NET (Ukraine)(htaccess)

Because we started blocking (via .htaccess) a fair number of IP ranges due to robo-abuse, we've not had to suffer much with the 500-Server Error issues when accessing the forum.  That was the main reason I keep analyzing the logs daily.

Just thought you might like a small peek behind the curtain :)

Best regards,
Ken

Ken True/Saratoga, CA, USA main site: saratoga-weather.org
Davis VP1+ FARS, Blitzortung RED, GRLevel3, WD, WL, VWS, Cumulus, Meteobridge
Free weather PHP scripts/website templates - update notifications on Twitter saratogaWXPHP

Offline PaulMy

  • Forecaster
  • *****
  • Posts: 5509
    • KomokaWeather
Re: Behind the scenes.. they try, but can't come in...
« Reply #1 on: July 27, 2014, 07:30:01 PM »
Thanks Ken.  We appreciate your continued efforts.
 
Paul

Offline DanS

  • Chiang Mai weather
  • Forecaster
  • *****
  • Posts: 5434
    • ThaiWx
Re: Behind the scenes.. they try, but can't come in...
« Reply #2 on: July 27, 2014, 07:48:38 PM »
Thank you Ken, always appreciate the work you have to 'put up with'. It's interesting to see names like "Time Warner Cable Internet LLC" and "AT&T Internet Services" that appear innocent enough (to me :roll:) doing this to the forum.

Offline Dr Obbins

  • Forecaster
  • *****
  • Posts: 1152
Re: Behind the scenes.. they try, but can't come in...
« Reply #3 on: July 27, 2014, 07:59:09 PM »
With out going on too much of a rant - We see only this site, but when multiplied by the number of sites and domains in the USA, I would think that robots are pretty decent attack on US citizens let alone adding spam into the picture. Thanks for defending this portion of homeland!

Offline saratogaWX

  • Administrator
  • Forecaster
  • *****
  • Posts: 9257
  • Saratoga, CA, USA Weather - free PHP scripts
    • Saratoga-Weather.org
Re: Behind the scenes.. they try, but can't come in...
« Reply #4 on: July 27, 2014, 08:32:19 PM »
The robots are mostly operated by cybercriminals, skript-kiddies (and maybe a few nation-states) with the main purpose to get access/then spam or set up a relay/bot of their own to further their malicious purposes.  Thankfully, our hatches are battened down so there's little likelihood of them coming in by compromising our site -- we keep up to current maintenance on the SMF forum itself.

Yes, any public internet site is likely seeing some of what we see-- it's the background-noise on the internet.  A recent vulnerability in a popular WordPress plugin led to thousands of websites compromised.  The 'door-rattlers' are always with
us looking for a way in.

Oh... if you'd like to watch the probing near realtime, try this link.  Reminds me of the display in WarGames the movie :)

Best regards,
Ken
« Last Edit: July 27, 2014, 08:42:15 PM by saratogaWX »
Ken True/Saratoga, CA, USA main site: saratoga-weather.org
Davis VP1+ FARS, Blitzortung RED, GRLevel3, WD, WL, VWS, Cumulus, Meteobridge
Free weather PHP scripts/website templates - update notifications on Twitter saratogaWXPHP

Offline SlowModem

  • Weather at the speed of dialup!
  • Forecaster
  • *****
  • Posts: 6641
  • WX @ 26.4 kbs
    • Watts Bar Weather
Re: Behind the scenes.. they try, but can't come in...
« Reply #5 on: July 27, 2014, 08:53:15 PM »
Just thought you might like a small peek behind the curtain :)

Best regards,
Ken

Ken hard at work behind the curtain:

« Last Edit: July 27, 2014, 10:32:12 PM by SlowModem »
Greg Whitehead
Ten Mile, TN USA

Offline W3DRM

  • Forecaster
  • *****
  • Posts: 3360
    • Emmett Weather
Re: Behind the scenes.. they try, but can't come in...
« Reply #6 on: July 27, 2014, 09:42:35 PM »
Ken, thanks for all you do.  =D>

Looking at that display makes me wonder how anything gets done?! I wonder what the percentage of Internet traffic worldwide is legitimate and what percentage is the attempts to crack into someones network? The wasted bandwidth must be tremendous.
Don - W3DRM - Emmett, Idaho --- Blitzortung ID: 808 --- FlightRadar24 ID: F-KBOI7
Davis Wireless VP2, WD 10.37s150,
StartWatch, VirtualVP, VPLive, Win10 Pro
--- Logitech HD Pro C920 webcam (off-line)
--- RIPE Atlas Probe - 32849

Offline jhoke

  • Member
  • *
  • Posts: 9
    • Albrightsville PA Weather
Re: Behind the scenes.. they try, but can't come in...
« Reply #7 on: July 27, 2014, 09:47:18 PM »
I;ve seen stats of anywhere between 80-90% of email traffic is spam... sounds ridiculous... but when I am looking at my corporate filters, I see between 75-90% of email to our domains being blocked for spam/virus/phishing/etc.

I love playing with the data my day job provides :)

Offline CNYWeather

  • Forecaster
  • *****
  • Posts: 2295
    • CNYWeather
Re: Behind the scenes.. they try, but can't come in...
« Reply #8 on: July 28, 2014, 07:28:36 AM »
I see the comcast one in the list. That kind of sticks out from the rest.

Thanks Mr. Wizard for keeping the forum safe  :grin:
Tony




Offline gwwilk

  • Southeast Lincoln Weather
  • Forecaster
  • *****
  • Posts: 2578
    • SouthEast Lincoln, NE Weather
Re: Behind the scenes.. they try, but can't come in...
« Reply #9 on: July 28, 2014, 08:09:40 AM »

Oh... if you'd like to watch the probing near realtime, try this link.  Reminds me of the display in WarGames the movie :)

Best regards,
Ken
Thanks for all you do, Ken.  Watching the probing in real time is almost as entertaining as the real time Blitzortung activity! :shock:
Regards, Jerry Wilkins
gwwilk@gmail.com

Offline SLOweather

  • Global Moderator
  • Forecaster
  • *****
  • Posts: 3456
    • Weatherelement Moline IL
Re: Behind the scenes.. they try, but can't come in...
« Reply #10 on: July 28, 2014, 11:32:58 AM »
It's not just trying to register on forums or send spam... After watching access logs for a while, you learn why to pick "secure" passwords and otherwise secure servers. I used to think the size of the Internet gave a certain amount of security by anonymity. Not so. The bots and script kiddies just pick away at address after address until they find some way in. My new analogy is that the server is like your house. You lock the doors and close the windows and think you are safe.

But, the black hats are like ants or mice. They don't even bother with doors and windows. They just swarm the place trying to get in through any little tiny hole they can find.

I have a block of contiguous IP addresses for the virtual machines on my new server. All of the access logs looked identical; same addresses trying to get in with the same user names...

Here's a little hint. Google your favorite password. If you find it in a list, you're screwed. I did, and was. 


Offline W3DRM

  • Forecaster
  • *****
  • Posts: 3360
    • Emmett Weather
Re: Behind the scenes.. they try, but can't come in...
« Reply #11 on: July 28, 2014, 11:40:14 AM »
Ken, can you define or explain what constitutes an "attack"? I know it is probably an attempt to gain access to a site, but how do they know a probe isn't legitimate?
Don - W3DRM - Emmett, Idaho --- Blitzortung ID: 808 --- FlightRadar24 ID: F-KBOI7
Davis Wireless VP2, WD 10.37s150,
StartWatch, VirtualVP, VPLive, Win10 Pro
--- Logitech HD Pro C920 webcam (off-line)
--- RIPE Atlas Probe - 32849

Offline saratogaWX

  • Administrator
  • Forecaster
  • *****
  • Posts: 9257
  • Saratoga, CA, USA Weather - free PHP scripts
    • Saratoga-Weather.org
Re: Behind the scenes.. they try, but can't come in...
« Reply #12 on: July 28, 2014, 12:33:30 PM »
Don,
I'm mostly checking the HTTP access logs (and the FTP transfer logs) as they're the 'usual' path for door-rattlers to attempt access to the site.  I put IP ranges in blocks in .htaccess for:

1) non-prime (i.e. not Google, Yahoo, Bing) search bots that just don't play nice and overload the server with too many requests.  I consider this a 'denial of service' type attack so Baidu, Yandex and other SEO-type engines are blocked.
We do have a very few accesses that pretend to be Google, but don't come from Google servers..that is apparently a
ploy to get paid websites to cough up content without paying (some paid sites allow free access for legitimate search engines).
2) massive registration attempts, particularly from China, Russia, Ukraine, Viet Nam, and Brazil
3) any IP or username or email that appears in Stopforumspam.com is rejected -- no validation message is sent.  Also approved user registrations if they haven't been email validated in 21 days.
4) 'interesting' URLs that are either 404-Not Found or have arguments that try remote site inclusion of scripts (doesn't work here), or raw server commands (like SQL injection, which also doesn't work).

For my own sites, I do not run any software that allows upload through the web (so no WordPress, no guestbook, no picture gallery etc.). And I limit my SQL to using Mike Challis' whos-online scripts.  This keeps my 'attack-surface' available to the minimum.

By watching the logs daily, you get a sense (like SloWeather said) of what the usual looks like, and who/what is the most active (Google, Yahoo, Bing for our site).  Then you can spot anomalies like lots of 404's (somebody probing for software that isn't there), multiple registration attempts in a short time (likely a spambot)

Last week, the top registration attempts were
Code: [Select]
    368 180.110.162.222 Chinanet Jiangsu Province
    342 80.80.202.132 MTS OJSC, Russia
    330 114.222.71.101 Chinanet Jiangsu Province
    321 208.105.116.114 Time Warner Cable Internet LLC
    300 113.57.190.28 China Unicom HuBei Province Network
    270 113.57.190.21 China Unicom HuBei Province Network
    244 91.197.129.129 Operator of Virtual Data Computing LLC, Ukraine
    192 113.57.190.23 China Unicom HuBei Province Network
    182 178.23.129.34 Aspire Technology Solutions Ltd, United Kingdom
    171 180.110.163.132 Chinanet Jiangsu Province
    168 113.57.190.19 China Unicom HuBei Province Network
    163 74.216.94.60 Allstream Corp., Canada
    150 180.110.160.11 Chinanet Jiangsu Province
    128 58.48.33.142 CHINANET Hubei province
    114 109.111.6.35 MTS OJSC, Russia
The Time Warner one was actually someone's browser doing keepalive after doing a successful registration.  The China/Russia ones are all spambots.

Best regards,
Ken
Ken True/Saratoga, CA, USA main site: saratoga-weather.org
Davis VP1+ FARS, Blitzortung RED, GRLevel3, WD, WL, VWS, Cumulus, Meteobridge
Free weather PHP scripts/website templates - update notifications on Twitter saratogaWXPHP

Offline W3DRM

  • Forecaster
  • *****
  • Posts: 3360
    • Emmett Weather
Re: Behind the scenes.. they try, but can't come in...
« Reply #13 on: July 29, 2014, 11:21:37 AM »
Thanks Ken, this bit of information should make all us feel a bit more secure in knowing this forum is actively protected from the spammers and hackers even though it is a non-stop job to do so.

I also see the home page for the link you provided has some additional info regarding cyber attacks. There are many white papers on the subject (http://www.norse-corp.com/). One could spend lots of time reading through those reports.

Thanks again for the work you and the other administrators do to keep this site running smoothly.
Don - W3DRM - Emmett, Idaho --- Blitzortung ID: 808 --- FlightRadar24 ID: F-KBOI7
Davis Wireless VP2, WD 10.37s150,
StartWatch, VirtualVP, VPLive, Win10 Pro
--- Logitech HD Pro C920 webcam (off-line)
--- RIPE Atlas Probe - 32849

Offline weatherc

  • Senior Contributor
  • ****
  • Posts: 278
Re: Behind the scenes.. they try, but can't come in...
« Reply #14 on: August 11, 2014, 05:43:51 PM »
The most important, thinking such things comes only from countries like China, Russia, Ukraine, Vietnam and Brazil are naive. When i look at the IP-blocks what the firewall do on my own server, are the most blocks done for IP's in "good" countries like Germany, France, USA etc. Theese blocks are all for kiddies what try to come in to the server.

I have a few times had a "rush" on those where new blocks have been done every few minutes for a day or two. In those rushes has the IP's allways been from all around the world.

Ie. this was the saldo for just 12 minutes one day in July:
lfd on xxxx.xxxxx.xxxxx: blocked 31.148.220.30 (NL/Netherlands/
lfd on xxxx.xxxxx.xxxxx: blocked 89.67.161.34 (PL/Poland/
lfd on xxxx.xxxxx.xxxxx: blocked 178.166.83.167 (PT/Portugal/
lfd on xxxx.xxxxx.xxxxx: blocked 64.207.46.229 (US/United States/
lfd on xxxx.xxxxx.xxxxx: blocked 95.91.215.108 (DE/Germany/
lfd on xxxx.xxxxx.xxxxx: blocked 109.151.197.204 (GB/United Kingdom/
lfd on xxxx.xxxxx.xxxxx: blocked 91.190.84.2 (RU/Russian Federation/
lfd on xxxx.xxxxx.xxxxx: blocked 216.46.22.210 (CA/Canada/
lfd on xxxx.xxxxx.xxxxx: blocked 195.5.95.63 (ES/Spain/
lfd on xxxx.xxxxx.xxxxx: blocked 86.164.115.75 (GB/United Kingdom/
lfd on xxxx.xxxxx.xxxxx: blocked 213.135.232.201 (LU/Luxembourg/
lfd on xxxx.xxxxx.xxxxx: blocked 109.228.102.133 (ME/Montenegro/
lfd on xxxx.xxxxx.xxxxx: blocked 64.52.252.130 (US/United States/

// Henkka



« Last Edit: August 11, 2014, 05:46:40 PM by weatherc »

Offline saratogaWX

  • Administrator
  • Forecaster
  • *****
  • Posts: 9257
  • Saratoga, CA, USA Weather - free PHP scripts
    • Saratoga-Weather.org
Re: Behind the scenes.. they try, but can't come in...
« Reply #15 on: August 11, 2014, 06:26:39 PM »
You're quite right, Henkka... they do come from all over the world.  Wherever hosting is provided the fly-by-nights will get a quick site, and try their tricks.

Last week's stats for registration attempts shows
Quote
count   IP                      IP Space owned by
    568 93.84.15.231   RUE Beltelecom, Belarus
    304 91.217.10.186   FOP Ljashenko Igor Ivanovich, Ukraine
    300 180.110.160.200   Chinanet Jiangsu Province
    294 195.154.177.167   Iliad Entreprises hosting (France)
    216 192.99.160.34   OVH Hosting, Inc., Canada
    212 49.77.207.135   CHINANET jiangsu province
    196 36.250.160.95   China Unicom Fujian Province Network, China
    186 221.232.62.139   CHINANET Hubei province
    181 87.106.27.11   1&1 Internet AG, Germany
    171 49.77.231.210   CHINANET jiangsu province
    140 221.232.58.157   CHINANET Hubei province
    128 59.173.135.149   CHINANET Hubei province
    117 180.110.160.197   Chinanet Jiangsu Province
     98 209.113.181.74   Earthlink, Inc., USA
     96 176.213.63.163   CJSC "ER-Telecom Holding", Russia
     96 176.213.20.247   CJSC "ER-Telecom Holding", Russia
     90 95.79.80.245   CJSC "ER-Telecom Holding", Russia
     90 27.150.222.246   CHINANET FUJIAN PROVINCE
     78 5.164.192.164   CJSC "ER-Telecom Holding", Russia
     76 23.238.207.75   Psychz Networks, United States
     71 119.46.110.17   True Internet Co., Ltd., Thailand
     66 109.165.92.119   OJSC Rostelecom , Rostok, Russia
     64 178.137.87.131   Kyivstar PJSC, Ukraine
     58 46.4.103.83   Hetzner Online AG
     58 24.229.160.148   PenTeleData Inc., USA
     52 115.231.168.66   CHINANET Zhejiang province
     50 178.137.19.204   Kyivstar PJSC, Ukraine
     44 89.44.23.119   SC AIRWAY TICKET SRL, Romania
     44 88.80.21.219   PeRiQuito AB, Sweden
     44 77.87.79.239   "EuroNet" s.c. Jacek Majak, Aleksandra Kuc, Poland
     44 61.58.181.29   Taiwan Broadband Communications, Co., Ltd.
     44 200.80.103.226   MULTILINK SA, Haiti
     44 128.68.227.249   OJSC "Vimpelcom", Russia
     43 88.91.89.253   Telenor Business Solutions AS, Norway
     43 37.104.14.199   SaudiNet, Saudi Telecom Company
     43 173.166.20.90   Comcast Business Communications, LLC, USA
     41 76.24.74.105   Comcast Cable Communications, Inc., USA
     40 162.244.10.248   Power Up Hosting (Los Angeles)(htaccess)
     39 79.133.204.130   eTOP sp. z o.o., Poland
     39 2602:306:bdbd:1f80:92e6:baff:fed6:6e6b   
     39 178.137.162.10   Kyivstar PJSC, Ukraine
     38 95.79.73.193   CJSC "ER-Telecom Holding", Russia
     38 95.79.239.54   CJSC "ER-Telecom Holding", Russia
     38 94.41.112.24   JSC "Ufanet", Russia
     38 93.73.204.177   Kyivski Telekomunikatsiyni Merezhi LLC, Ukraine
     38 84.26.130.202   Ziggo B.V., Netherlands
     38 83.9.140.229   Orange Polska Spolka Akcyjna, Poland
     38 83.114.252.124   
     38 79.98.141.98   Technology & Networks Co., Russia
     38 5.34.38.177   2DAY Telecom LLP, Kazakhstan
     38 5.164.236.172   CJSC "ER-Telecom Holding", Russia
     38 5.158.235.216   INFO-LINK Cheboksary, Russia
     38 5.105.103.174   Cifrovye Dispetcherskie Sistemy, Ukraine
     38 49.143.192.214   Netropy, Korea
     38 31.31.112.53   TeNeT Scientific Production Enterprise LLC, Ukraine
     38 221.232.60.98   CHINANET Hubei province
     38 188.186.26.97   CJSC "ER-Telecom Holding", Russia
     38 178.76.216.219   ZAO "Electro-Com" Rostov, Russia
     38 176.52.96.173   
     38 148.163.51.229   Input Output Flood LLC, USA
     38 146.71.104.206   GorillaServers, Inc., USA
     37 36.250.179.244   China Unicom Fujian Province Network, China
     37 108.69.6.136   AT&T Internet Services
     36 146.0.72.165   HOSTKEY B.V., Netherlands
     34 122.164.103.178   ABTS Tamilnadu, India
     34 103.10.65.115   PT Hutchison CP Telecommunications, Indonesia
     32 94.139.234.15   Intersat Network Asbest., Russia
     32 77.87.79.196   "EuroNet" s.c. Jacek Majak, Aleksandra Kuc, Poland
     32 5.166.217.243   CJSC "ER-Telecom Holding", Russia
     32 5.166.207.143   CJSC "ER-Telecom Holding", Russia
     32 5.166.201.15   CJSC "ER-Telecom Holding", Russia
     32 5.164.219.193   CJSC "ER-Telecom Holding", Russia
     32 5.164.202.208   CJSC "ER-Telecom Holding", Russia
     32 5.164.192.165   CJSC "ER-Telecom Holding", Russia
     32 5.158.235.233   INFO-LINK Cheboksary, Russia
     32 5.158.234.175   INFO-LINK Cheboksary, Russia
     32 5.158.234.150   INFO-LINK Cheboksary, Russia
     32 5.139.85.194   OJSC Rostelecom , Rostok, Russia
     32 37.113.134.100   CJSC "ER-Telecom Holding" Chelyabinsk branch, Russia
     32 37.112.91.160   CJSC "ER-Telecom Holding", Russia
     32 193.142.30.98   Batterflyai Media ltd., Russia
     32 188.186.158.230   CJSC "ER-Telecom Holding", Russia
     32 183.160.182.189   CHINANET Anhui province
     29 199.217.118.85   Hosting Solutions International, Inc., USA
     28 75.121.217.195   CenturyTel Internet Louisiana
     28 192.183.176.166   Frontier Communications of America, Inc.
     28 176.250.249.14   British Sky Broadcasting Limited
     28 144.76.178.232   Server Block Hetzner Online, Germany
     27 220.233.19.96   Exetel Internet Service Provider, Australia
     27 111.119.227.15   Syscon Infoway Pvt.Ltd., India
     26 223.240.142.3   CHINANET Anhui province
     26 213.111.209.137   PP MainStream, Ukraine
     26 178.137.94.225   Kyivstar PJSC, Ukraine
     25 188.32.192.231   OJSC Rostelecom, Russia
     24 94.175.50.193   Virgin Media Limited, United Kingdom
     24 122.164.96.231   ABTS Tamilnadu, India
     24 107.161.154.85   Jared Taylor, United States
     23 94.242.250.62   root SA, Luxembourg
     23 72.24.107.24   CABLE ONE, INC., USA
     22 87.98.167.207   OVH SAS, France
     22 62.4.17.227   ONLINE S.A.S., France
     22 36.248.70.137   China Unicom Fujian Province Network, China
     22 178.137.83.121   Kyivstar PJSC, Ukraine
     21 37.113.132.206   CJSC "ER-Telecom Holding" Chelyabinsk branch, Russia
     21 101.55.125.71   KDTIDC, Korea
     20 96.32.205.119   Charter Comm. Cable
     20 95.69.241.116   LLC AB UKRAINE, Ukraine
     20 50.55.210.246   Frontier Communications of America, Inc.
     20 213.231.39.48   TOV TRK "Briz", Ukraine
     20 198.2.218.198   PEG TECH INC, United States
     20 178.137.17.255   Kyivstar PJSC, Ukraine
     20 176.8.89.202   Kyivstar PJSC, Ukraine
     20 176.213.133.193   CJSC "ER-Telecom Holding", Russia
     20 148.177.1.212   Johnson & Johnson, USA
     19 78.152.39.114   TripartZ B.V., Netherlands
     19 202.89.38.226   VOCUS PTY LTD, New Zealand
     18 75.172.115.203   Qwest Communications Company, LLC
     18 68.96.123.203   Cox Communications Inc.
     18 36.248.119.199   China Unicom Fujian Province Network, China
     18 192.162.19.38   FOP Budko Dmitro Pavlovich, Ukraine
     18 178.137.165.183   Kyivstar PJSC, Ukraine
     18 167.142.151.238   
     18 109.106.137.217   Svyaz-Telecom, Russian Federation
     17 95.211.98.166   LeaseWeb B.V., Netherlands
     17 209.188.46.78   Atlantic Telephone Membership Corp., USA
     17 173.217.224.188   Suddenlink Communications, USA
     17 108.245.190.181   AT&T Internet Services
     16 94.153.8.103   Kyivstar PJSC, Ukraine
     16 72.93.14.161   Verizon Online LLC
     16 31.128.81.72   Stels ISP Ltd., Ukraine
     16 184.1.34.95   Embarq Corporation
     16 178.33.131.106   OVH SAS, France
     16 109.220.55.15   Orange S.A., France
     15 80.150.85.23   Deutsche Telekom AG
     15 198.27.99.108   OVH Hosting, Inc., Canada
     15 195.189.88.117   Net-Bis s.c. Wlodzimierz Gasior, Jolanta Gadek, Poland
     15 14.151.30.216   CHINANET Guangdong province
     14 74.99.161.46   Verizon Online LLC
     14 46.246.45.163   Portlane Networks AB, Sweden
     14 217.78.187.239   Technology & Networks Co., Russia
     13 80.219.12.206   UPC Cablecom GmbH, Austria
     13 221.232.52.107   CHINANET Hubei province
     13 14.151.28.197   CHINANET Guangdong province
     13 123.64.116.229   China TieTong Telecommunications Corporation, China
     12 88.80.20.153   PeRiQuito AB, Sweden
     12 83.77.110.53   Swisscom (Schweiz) AG
     12 83.14.9.85   Orange Polska Spolka Akcyjna, Poland
     12 80.79.121.135   Aktsiaselts WaveCom, Estonia
     12 77.87.78.90   "EuroNet" s.c. Jacek Majak, Aleksandra Kuc, Poland
     12 77.87.78.5   "EuroNet" s.c. Jacek Majak, Aleksandra Kuc, Poland
     12 36.248.119.245   China Unicom Fujian Province Network, China
     12 36.248.117.203   China Unicom Fujian Province Network, China
     12 2602:ffea:a::46b5:19e   
     12 221.178.118.20   China Mobile Comm
     12 198.27.120.57   OVH Hosting, Inc., Canada
     12 195.154.181.149   Iliad Entreprises hosting (France)
     12 192.249.64.179   GMO CLOUD AMERICA INC., USA
     12 123.64.10.66   China TieTong Telecommunications Corporation, China
     12 113.167.185.81   IP FTTH static Vinh Phuc, Viet Nam
     12 111.119.227.4   Syscon Infoway Pvt.Ltd., India
     12 111.10.49.243   China Mobile Comm
     12 109.239.90.42   Six Degrees Managed Data Limited, United Kingdom
     12 108.244.94.144   AT&T Internet Services

Normally, a genuine registration takes 4 accesses (page+3 image captchas).  What I find interesting is the groups of disparate IP addresses with the same count.  It may be  that those servers/IPs are remotely controlled as a group by one botmaster.  Anyway... they don't get in to register :)

Best regards,
Ken
Ken True/Saratoga, CA, USA main site: saratoga-weather.org
Davis VP1+ FARS, Blitzortung RED, GRLevel3, WD, WL, VWS, Cumulus, Meteobridge
Free weather PHP scripts/website templates - update notifications on Twitter saratogaWXPHP

Offline weatherc

  • Senior Contributor
  • ****
  • Posts: 278
Re: Behind the scenes.. they try, but can't come in...
« Reply #16 on: August 11, 2014, 06:42:03 PM »
Quote
Normally, a genuine registration takes 4 accesses (page+3 image captchas).  What I find interesting is the groups of disparate IP addresses with the same count.  It may be  that those servers/IPs are remotely controlled as a group by one botmaster.

I guess that too.
I have set custom (lower) limits on lfd for how many try's are allowed before it blocks so they get probably hitted by that.
The amount of blocked ip's increased a lot after i lowered the limits :lol:

// Henkka

Offline saratogaWX

  • Administrator
  • Forecaster
  • *****
  • Posts: 9257
  • Saratoga, CA, USA Weather - free PHP scripts
    • Saratoga-Weather.org
Re: Behind the scenes.. they try, but can't come in...
« Reply #17 on: September 01, 2014, 12:18:34 PM »
Thought that last week (Week 35) stats for registration attempts were interesting:

Code: [Select]
Count    IP      who/where
    648 176.104.95.0 SPD Kurilov Sergiy Oleksandrovich, Ukraine UKRAINE,POLTAVS'KA OBLAST',KREMENCHUK
    465 49.77.206.25 CHINANET jiangsu province CHINA,JIANGSU,NANJING
    256 49.77.230.127 CHINANET jiangsu province CHINA,JIANGSU,NANJING
    232 221.232.52.237 CHINANET Hubei province CHINA,HUBEI,WUHAN
    212 5.166.197.41 CJSC "ER-Telecom Holding", Russia RUSSIAN FEDERATION,OMSK,OMSK
    192 46.147.106.148 CJSC "ER-Telecom Holding", Russia RUSSIAN FEDERATION,CHELYABINSK,CHELYABINSK
    180 95.79.135.105 CJSC "ER-Telecom Holding", Russia RUSSIAN FEDERATION,NIZHEGOROD,NIZHNIY NOVGOROD
    168 176.213.37.193 CJSC "ER-Telecom Holding", Russia RUSSIAN FEDERATION,NIZHEGOROD,NIZHNIY NOVGOROD
    160 95.79.67.246 CJSC "ER-Telecom Holding", Russia RUSSIAN FEDERATION,NIZHEGOROD,NIZHNIY NOVGOROD
    160 5.158.234.71 INFO-LINK Cheboksary, Russia RUSSIAN FEDERATION,CHUVASHIA,CHEBOKSARY
    154 37.112.83.107 CJSC "ER-Telecom Holding", Russia RUSSIAN FEDERATION,NIZHEGOROD,NIZHNIY NOVGOROD
    154 176.213.13.149 CJSC "ER-Telecom Holding", Russia RUSSIAN FEDERATION,NIZHEGOROD,NIZHNIY NOVGOROD
    152 91.236.75.124 Andrzej Niechcial mgr., Poland POLAND,SWIETOKRZYSKIE,PIEKOSZOW
    152 206.221.179.130 ReliableSite.Net LLC, United States UNITED STATES,NEW JERSEY,PISCATAWAY
    152 104.151.230.226 Enzu Inc, United States UNITED STATES,NEVADA,HENDERSON
    151 174.126.240.59 CABLE ONE, INC., USA UNITED STATES,ARIZONA,PRESCOTT
    144 95.79.130.100 CJSC "ER-Telecom Holding", Russia RUSSIAN FEDERATION,NIZHEGOROD,NIZHNIY NOVGOROD
    132 95.79.254.172 CJSC "ER-Telecom Holding", Russia RUSSIAN FEDERATION,NIZHEGOROD,NIZHNIY NOVGOROD
    130 68.84.152.87 Comcast Cable Communications, Inc., USA UNITED STATES,NEW MEXICO,SANTA FE
    128 95.79.202.19 CJSC "ER-Telecom Holding", Russia RUSSIAN FEDERATION,NIZHEGOROD,NIZHNIY NOVGOROD
    128 95.79.118.241 CJSC "ER-Telecom Holding", Russia RUSSIAN FEDERATION,KRASNODAR,KRASNODAR
    128 5.166.206.0 CJSC "ER-Telecom Holding", Russia RUSSIAN FEDERATION,NIZHEGOROD,NIZHNIY NOVGOROD
    128 5.164.240.185 CJSC "ER-Telecom Holding", Russia RUSSIAN FEDERATION,NIZHEGOROD,NIZHNIY NOVGOROD
    122 95.79.71.8 CJSC "ER-Telecom Holding", Russia RUSSIAN FEDERATION,NIZHEGOROD,NIZHNIY NOVGOROD
    121 198.204.236.218 Data Shack UNITED STATES,MISSOURI,NORTH KANSAS CITY
    120 5.164.232.49 CJSC "ER-Telecom Holding", Russia RUSSIAN FEDERATION,NIZHEGOROD,NIZHNIY NOVGOROD
    114 91.217.10.206 FOP Ljashenko Igor Ivanovich, Ukraine UKRAINE,KHARKIVS'KA OBLAST',KHARKIV
    114 23.88.28.98 Enzu Cloud Services (Henderson, NV, USA) UNITED STATES,NEVADA,HENDERSON
    104 176.213.14.128 CJSC "ER-Telecom Holding", Russia RUSSIAN FEDERATION,NIZHEGOROD,NIZHNIY NOVGOROD
    104 109.194.235.147 CJSC "ER-Telecom Holding", Russia RUSSIAN FEDERATION,NIZHEGOROD,NIZHNIY NOVGOROD
    102 95.79.186.23 CJSC "ER-Telecom Holding", Russia RUSSIAN FEDERATION,NIZHEGOROD,NIZHNIY NOVGOROD
     98 142.105.157.166 Time Warner Cable UNITED STATES,NEW YORK,ALBANY
     96 95.79.76.203 CJSC "ER-Telecom Holding", Russia RUSSIAN FEDERATION,NIZHEGOROD,NIZHNIY NOVGOROD
     96 95.79.71.113 CJSC "ER-Telecom Holding", Russia RUSSIAN FEDERATION,NIZHEGOROD,NIZHNIY NOVGOROD
     96 95.79.254.89 CJSC "ER-Telecom Holding", Russia RUSSIAN FEDERATION,NIZHEGOROD,NIZHNIY NOVGOROD
     96 95.79.214.184 CJSC "ER-Telecom Holding", Russia RUSSIAN FEDERATION,NIZHEGOROD,NIZHNIY NOVGOROD
     96 95.79.210.77 CJSC "ER-Telecom Holding", Russia RUSSIAN FEDERATION,NIZHEGOROD,NIZHNIY NOVGOROD
     95 111.225.65.52 CHINANET hebei province CHINA,HEBEI,SHIJIAZHUANG
     90 95.79.23.146 CJSC "ER-Telecom Holding", Russia RUSSIAN FEDERATION,NIZHEGOROD,NIZHNIY NOVGOROD
     82 5.164.216.132 CJSC "ER-Telecom Holding", Russia RUSSIAN FEDERATION,NIZHEGOROD,NIZHNIY NOVGOROD
     76 78.8.138.163 Telefonia Dialog sp.z.o.o., Poland POLAND,DOLNOSLASKIE,WROCLAW
     76 23.88.28.42 Enzu Cloud Services (Henderson, NV, USA) UNITED STATES,NEVADA,HENDERSON
     76 188.254.126.237 OJSC Rostelecom, Russia RUSSIAN FEDERATION,TULA,TULA
     76 176.222.169.69 2DAY Telecom LLP, Kazakhstan KAZAKHSTAN,ALMATY CITY,ALMATY
     76 125.212.209.51 hcmccable-net, VN (1 Tran Huu Duc, My Dinh, Tu Liem, Hanoi) VIET NAM,HO CHI MINH,THANH PHO HO CHI MINH
     72 5.164.246.155 CJSC "ER-Telecom Holding", Russia RUSSIAN FEDERATION,NIZHEGOROD,NIZHNIY NOVGOROD
     70 96.8.174.21 Guadalupe Valley Telephone Cooperative, Inc. UNITED STATES,TEXAS,SAN ANTONIO
     70 95.79.3.153 CJSC "ER-Telecom Holding", Russia RUSSIAN FEDERATION,NIZHEGOROD,NIZHNIY NOVGOROD
     70 95.79.19.216 CJSC "ER-Telecom Holding", Russia RUSSIAN FEDERATION,NIZHEGOROD,NIZHNIY NOVGOROD
     65 173.25.58.130 Mediacom Residential NY UNITED STATES,CALIFORNIA,SACRAMENTO
     64 95.79.184.42 CJSC "ER-Telecom Holding", Russia RUSSIAN FEDERATION,NIZHEGOROD,NIZHNIY NOVGOROD
     64 5.166.220.127 CJSC "ER-Telecom Holding", Russia RUSSIAN FEDERATION,NIZHEGOROD,NIZHNIY NOVGOROD
     64 5.166.208.89 CJSC "ER-Telecom Holding", Russia RUSSIAN FEDERATION,NIZHEGOROD,NIZHNIY NOVGOROD
     64 5.166.207.144 CJSC "ER-Telecom Holding", Russia RUSSIAN FEDERATION,NIZHEGOROD,NIZHNIY NOVGOROD
     64 5.166.204.140 CJSC "ER-Telecom Holding", Russia RUSSIAN FEDERATION,OMSK,RUSSKAYA POLYANA
     64 5.166.197.192 CJSC "ER-Telecom Holding", Russia RUSSIAN FEDERATION,OMSK,OMSK
     64 5.158.234.191 INFO-LINK Cheboksary, Russia RUSSIAN FEDERATION,CHUVASHIA,CHEBOKSARY
     64 37.112.73.88 CJSC "ER-Telecom Holding", Russia RUSSIAN FEDERATION,NIZHEGOROD,NIZHNIY NOVGOROD
     64 188.186.149.55 CJSC "ER-Telecom Holding", Russia RUSSIAN FEDERATION,TYUMEN',TYUMEN'
     64 176.213.8.46 CJSC "ER-Telecom Holding", Russia RUSSIAN FEDERATION,NIZHEGOROD,NIZHNIY NOVGOROD
     63 95.79.215.189 CJSC "ER-Telecom Holding", Russia RUSSIAN FEDERATION,NIZHEGOROD,NIZHNIY NOVGOROD
     59 50.179.41.171 Comcast Cable Communications Holdings, Inc, USA UNITED STATES,ILLINOIS,CHAMPAIGN
     58 64.222.103.245 FAIRPOINT COMMUNICATIONS, INC., United States UNITED STATES,VERMONT,BURLINGTON
     58 50.187.203.165 Comcast Cable Communications Holdings, Inc, USA UNITED STATES,NEW HAMPSHIRE,CONCORD
     58 5.158.234.175 INFO-LINK Cheboksary, Russia RUSSIAN FEDERATION,CHUVASHIA,CHEBOKSARY
     58 188.186.148.35 CJSC "ER-Telecom Holding", Russia RUSSIAN FEDERATION,TYUMEN',TYUMEN'
     58 109.194.238.236 CJSC "ER-Telecom Holding", Russia RUSSIAN FEDERATION,NIZHEGOROD,NIZHNIY NOVGOROD
     54 105.229.87.116 Telkom Internet, Pretoria, South Africa SOUTH AFRICA,GAUTENG,JOHANNESBURG
     52 95.79.248.26 CJSC "ER-Telecom Holding", Russia RUSSIAN FEDERATION,NIZHEGOROD,NIZHNIY NOVGOROD
     52 5.166.199.88 CJSC "ER-Telecom Holding", Russia RUSSIAN FEDERATION,NIZHEGOROD,NIZHNIY NOVGOROD
     52 5.158.235.71 INFO-LINK Cheboksary, Russia RUSSIAN FEDERATION,MOSCOW CITY,MOSCOW
     52 27.150.220.207 CHINANET Fujian Provence CHINA,FUJIAN,FUZHOU
     50 93.115.84.195 VOXILITY SRL, Romania ROMANIA,BUCURESTI,BUCHAREST
     50 5.158.234.114 INFO-LINK Cheboksary, Russia RUSSIAN FEDERATION,CHUVASHIA,CHEBOKSARY
     49 36.248.31.149 China Unicom Fujian Province CHINA,FUJIAN,FUZHOU
     47 81.0.104.213 INVITEL Zrt., Hungary HUNGARY,PEST,BUDAORS
     46 36.250.180.35 China Unicom Fujian Province CHINA,FUJIAN,PUTIAN
     46 143.233.204.28 Greek Academic & Research Computer Network, Greece GREECE,ATTIKI,ATHENS
     44 95.181.179.91 Ilyushenko Vladimir, Russia RUSSIAN FEDERATION,VLADIMIR,VLADIMIR
     44 80.255.3.68 Core-Backbone GmbH, Germany GERMANY,BAYERN,NUREMBERG
     44 41.250.211.142 IAM, Morocco MOROCCO,GRAND CASABLANCA,CASABLANCA
     44 159.224.160.164 TRIOLAN new_net, Ukraine UKRAINE,KHARKIVS'KA OBLAST',KHARKIV
     42 216.243.1.66 vanoppen.biz LLC, United States UNITED STATES,WASHINGTON,SEATTLE
     42 212.83.133.250 ONLINE S.A.S., France FRANCE,ILE-DE-FRANCE,PARIS
     41 95.154.78.37 Octopusnet Dynamic VPN, Russia RUSSIAN FEDERATION,PRIMOR'YE,VLADIVOSTOK
     41 86.13.183.129 Virgin Media Limited, UK UNITED KINGDOM,ENGLAND,CHESTER
     40 64.253.112.24 IgLou Internet Services, United States UNITED STATES,KENTUCKY,LOUISVILLE
     39 178.137.90.184 Kyivstar PJSC, Ukraine UKRAINE,KYYIV,KIEV
     38 95.79.80.167 CJSC "ER-Telecom Holding", Russia RUSSIAN FEDERATION,NIZHEGOROD,NIZHNIY NOVGOROD
     38 95.79.252.160 CJSC "ER-Telecom Holding", Russia RUSSIAN FEDERATION,NIZHEGOROD,NIZHNIY NOVGOROD
     38 95.79.194.94 CJSC "ER-Telecom Holding", Russia RUSSIAN FEDERATION,NIZHEGOROD,NIZHNIY NOVGOROD
     38 95.55.7.201 OJSC Rostelecom, Russia RUSSIAN FEDERATION,SAINT PETERSBURG CITY,SAINT PETERSBURG
     38 93.100.102.163 SkyNet Ltd., Russia RUSSIAN FEDERATION,SAINT PETERSBURG CITY,SAINT PETERSBURG
     38 89.28.45.51 STARNET S.R.L, Moldova MOLDOVA, REPUBLIC OF,CHISINAU,CHISINAU
     38 87.76.236.222 "SATELIT SERVIS" Ltd, SNS-PI-BLOCK2-NET, UA (Dvortsovaya 10, office 56, Kramatorsk, Donetsk region, Ukraine) UKRAINE,DONETS'KA OBLAST',KRAMATORS'K
     38 76.179.19.234 Time Warner Cable Internet LLC, RRACI, Herndon, US (13820 Sunrise Valley Drive) UNITED STATES,MAINE,OLD TOWN
     38 5.79.142.177 Intersvyaz-2 JSC, Russia RUSSIAN FEDERATION,CHELYABINSK,CHELYABINSK
     38 5.34.39.217 2DAY Telecom LLP, Kazakhstan KAZAKHSTAN,QOSTANAY,QOSTANAY
     38 5.166.195.75 CJSC "ER-Telecom Holding", Russia RUSSIAN FEDERATION,NIZHEGOROD,NIZHNIY NOVGOROD
     38 5.158.235.238 INFO-LINK Cheboksary, Russia RUSSIAN FEDERATION,MOSCOW CITY,MOSCOW
     38 5.158.235.128 INFO-LINK Cheboksary, Russia RUSSIAN FEDERATION,MOSCOW CITY,MOSCOW
     38 46.47.4.201 OOO "Avtotransport Trejding Jekspedicija Logistika", Russia RUSSIAN FEDERATION,KEMEROVO,KEMEROVO
     38 37.26.136.252 JSCC Interdnestrcom, Moldova MOLDOVA, REPUBLIC OF,CHISINAU,CHISINAU
     38 23.88.28.90 Enzu Cloud Services (Henderson, NV, USA) UNITED STATES,NEVADA,HENDERSON
     38 193.28.228.49 Torben Diehr trading as T-N-Media, Germany GERMANY,NORDRHEIN-WESTFALEN,HERDECKE
     38 183.160.189.137 CHINANET Anhui province CHINA,ANHUI,HEFEI
     38 176.213.60.101 CJSC "ER-Telecom Holding", Russia RUSSIAN FEDERATION,NIZHEGOROD,NIZHNIY NOVGOROD
     38 130.0.36.31 TeNeT Scientific Production Enterprise LLC, Ukraine UKRAINE,ODES'KA OBLAST',ODESSA
     38 128.68.131.25 OJSC "Vimpelcom", Russia RUSSIAN FEDERATION,MOSCOW CITY,MOSCOW
     38 125.77.219.234 CHINANET Fujian province CHINA,FUJIAN,XIAMEN
     38 121.32.178.94 CHINANET Guangdong province CHINA,GUANGDONG,GUANGZHOU
     38 111.225.76.214 CHINANET hebei province CHINA,HEBEI,SHIJIAZHUANG
     37 192.198.91.2 Centrilogic, Inc., United States UNITED STATES,NEW YORK,ROCHESTER
     36 125.213.235.34 Internet Service Provider. Thailand THAILAND,KRUNG THEP,BANGKOK
     34 67.173.229.14 Comcast Cable Communications, Inc., USA UNITED STATES,COLORADO,DENVER
     34 195.154.121.234 ONLINE S.A.S., France FRANCE,ILE-DE-FRANCE,PARIS
     34 173.60.110.93 Verizon Online LLC, VIS-BLOCK, Ashburn, US (22001 Loudoun County Parkway) UNITED STATES,CALIFORNIA,SEAL BEACH
     33 24.238.54.236 PenTeleData Inc., USA UNITED STATES,NEW JERSEY,HAMBURG
     33 23.92.208.114 Centrilogic, Inc., United States UNITED STATES,NEW YORK,ROCHESTER
     33 195.154.168.123 ONLINE S.A.S., France FRANCE,ILE-DE-FRANCE,PARIS
     33 116.251.153.162 TRUSTPOWERLTD-NZ, NZ (P.O. Box 12023 Tauranga NZ) NEW ZEALAND,BAY OF PLENTY,TAURANGA
     32 95.79.3.122 CJSC "ER-Telecom Holding", Russia RUSSIAN FEDERATION,NIZHEGOROD,NIZHNIY NOVGOROD
     32 95.79.252.99 CJSC "ER-Telecom Holding", Russia RUSSIAN FEDERATION,NIZHEGOROD,NIZHNIY NOVGOROD
     32 95.79.243.72 CJSC "ER-Telecom Holding", Russia RUSSIAN FEDERATION,NIZHEGOROD,NIZHNIY NOVGOROD
     32 95.79.243.101 CJSC "ER-Telecom Holding", Russia RUSSIAN FEDERATION,NIZHEGOROD,NIZHNIY NOVGOROD
     32 95.79.233.250 CJSC "ER-Telecom Holding", Russia RUSSIAN FEDERATION,NIZHEGOROD,NIZHNIY NOVGOROD
     32 95.79.210.69 CJSC "ER-Telecom Holding", Russia RUSSIAN FEDERATION,NIZHEGOROD,NIZHNIY NOVGOROD
     32 95.79.2.40 CJSC "ER-Telecom Holding", Russia RUSSIAN FEDERATION,NIZHEGOROD,NIZHNIY NOVGOROD
     32 95.79.18.59 CJSC "ER-Telecom Holding", Russia RUSSIAN FEDERATION,NIZHEGOROD,NIZHNIY NOVGOROD
     32 95.79.128.109 CJSC "ER-Telecom Holding", Russia RUSSIAN FEDERATION,NIZHEGOROD,NIZHNIY NOVGOROD
     32 95.79.115.62 CJSC "ER-Telecom Holding", Russia RUSSIAN FEDERATION,NIZHEGOROD,NIZHNIY NOVGOROD
     32 91.121.217.187 OVH SAS, France FRANCE,ILE-DE-FRANCE,PARIS
     32 50.129.149.113 Comcast Cable Communications Holdings, Inc, USA UNITED STATES,INDIANA,INDIANAPOLIS
     32 5.166.219.153 CJSC "ER-Telecom Holding", Russia RUSSIAN FEDERATION,NIZHEGOROD,NIZHNIY NOVGOROD
     32 5.166.214.64 CJSC "ER-Telecom Holding", Russia RUSSIAN FEDERATION,NIZHEGOROD,NIZHNIY NOVGOROD
     32 5.166.207.196 CJSC "ER-Telecom Holding", Russia RUSSIAN FEDERATION,NIZHEGOROD,NIZHNIY NOVGOROD
     32 5.164.254.27 CJSC "ER-Telecom Holding", Russia RUSSIAN FEDERATION,NIZHEGOROD,NIZHNIY NOVGOROD
     32 5.164.231.128 CJSC "ER-Telecom Holding", Russia RUSSIAN FEDERATION,NIZHEGOROD,NIZHNIY NOVGOROD
     32 5.164.214.131 CJSC "ER-Telecom Holding", Russia RUSSIAN FEDERATION,NIZHEGOROD,NIZHNIY NOVGOROD
     32 5.164.207.85 CJSC "ER-Telecom Holding", Russia RUSSIAN FEDERATION,NIZHEGOROD,NIZHNIY NOVGOROD
     32 5.164.202.105 CJSC "ER-Telecom Holding", Russia RUSSIAN FEDERATION,NIZHEGOROD,NIZHNIY NOVGOROD
     32 5.164.197.9 CJSC "ER-Telecom Holding", Russia RUSSIAN FEDERATION,NIZHEGOROD,NIZHNIY NOVGOROD
     32 5.158.235.217 INFO-LINK Cheboksary, Russia RUSSIAN FEDERATION,MOSCOW CITY,MOSCOW
     32 5.158.235.146 INFO-LINK Cheboksary, Russia RUSSIAN FEDERATION,MOSCOW CITY,MOSCOW
     32 5.158.234.50 INFO-LINK Cheboksary, Russia RUSSIAN FEDERATION,CHUVASHIA,CHEBOKSARY
     32 5.158.234.38 INFO-LINK Cheboksary, Russia RUSSIAN FEDERATION,CHUVASHIA,CHEBOKSARY
     32 46.188.123.103 2COM Co ltd., Moscow, Russia RUSSIAN FEDERATION,MOSCOW CITY,MOSCOW
     32 46.147.99.165 CJSC "ER-Telecom Holding", Russia RUSSIAN FEDERATION,CHELYABINSK,CHELYABINSK
     32 46.147.96.29 CJSC "ER-Telecom Holding", Russia RUSSIAN FEDERATION,CHELYABINSK,CHELYABINSK
     32 46.147.122.251 CJSC "ER-Telecom Holding", Russia RUSSIAN FEDERATION,NOVGOROD,VELIKIY NOVGOROD
     32 46.147.111.149 CJSC "ER-Telecom Holding", Russia RUSSIAN FEDERATION,CHELYABINSK,CHELYABINSK
     32 46.147.110.160 CJSC "ER-Telecom Holding", Russia RUSSIAN FEDERATION,CHELYABINSK,CHELYABINSK
     32 37.112.77.244 CJSC "ER-Telecom Holding", Russia RUSSIAN FEDERATION,NIZHEGOROD,NIZHNIY NOVGOROD
     32 36.250.179.26 China Unicom Fujian Province CHINA,FUJIAN,PUTIAN
     32 36.250.179.137 China Unicom Fujian Province CHINA,FUJIAN,PUTIAN
     32 36.250.173.184 China Unicom Fujian Province CHINA,FUJIAN,PUTIAN
     32 36.250.172.169 China Unicom Fujian Province CHINA,FUJIAN,PUTIAN
     32 212.129.8.35 ONLINE S.A.S., France FRANCE,ILE-DE-FRANCE,PARIS
     32 199.168.100.154 DataShack, LC, United States UNITED STATES,MISSOURI,NORTH KANSAS CITY
     32 188.186.150.159 CJSC "ER-Telecom Holding", Russia RUSSIAN FEDERATION,TYUMEN',TYUMEN'
     32 176.213.55.77 CJSC "ER-Telecom Holding", Russia RUSSIAN FEDERATION,NIZHEGOROD,NIZHNIY NOVGOROD
     32 176.213.2.158 CJSC "ER-Telecom Holding", Russia RUSSIAN FEDERATION,NIZHEGOROD,NIZHNIY NOVGOROD
     32 176.213.1.148 CJSC "ER-Telecom Holding", Russia RUSSIAN FEDERATION,NIZHEGOROD,NIZHNIY NOVGOROD
     32 14.147.84.52 CHINANET Guangdong province CHINA,GUANGDONG,GUANGZHOU
     32 109.201.193.202 Maginfo JSC, Russia RUSSIAN FEDERATION,CHELYABINSK,MAGNITOGORSK
     31 178.32.61.38 OVH SAS, France FRANCE,ILE-DE-FRANCE,PARIS
     30 75.152.17.5 CANADA,QUEBEC,GRANDE-RIVIERE
     29 99.99.168.122 AT&T Internet UNITED STATES,ILLINOIS,CICERO
     29 72.206.121.5 Cox Comm. UNITED STATES,NEBRASKA,OMAHA
     29 37.235.153.107 LANTA Ltd, Russia RUSSIAN FEDERATION,TAMBOVSKAYA OBLAST,TAMBOV
     26 5.166.217.212 CJSC "ER-Telecom Holding", Russia RUSSIAN FEDERATION,NIZHEGOROD,NIZHNIY NOVGOROD
     26 5.158.235.90 INFO-LINK Cheboksary, Russia RUSSIAN FEDERATION,MOSCOW CITY,MOSCOW
     26 46.147.99.129 CJSC "ER-Telecom Holding", Russia RUSSIAN FEDERATION,CHELYABINSK,CHELYABINSK
     26 36.250.178.114 China Unicom Fujian Province CHINA,FUJIAN,PUTIAN
     26 36.250.163.150 China Unicom Fujian Province CHINA,FUJIAN,PUTIAN
     26 104.151.231.146 Enzu Inc, United States UNITED STATES,NEVADA,HENDERSON
     25 98.156.11.43 Time Warner Cable Internet LLC UNITED STATES,KANSAS,KANSAS CITY
     25 69.128.6.140 TDS TELECOM, Madison, US (525 Junction Rd.) UNITED STATES,WISCONSIN,REESEVILLE
     25 210.98.189.147 noname network, Korea KOREA, REPUBLIC OF,SEOUL-T'UKPYOLSI,SEOUL
     24 95.78.194.130 CJSC "ER-Telecom Holding", Russia RUSSIAN FEDERATION,NOVOSIBIRSK,NOVOSIBIRSK
     24 50.189.216.188 Comcast Cable Communications Holdings, Inc, USA UNITED STATES,CONNECTICUT,BERLIN
     24 124.177.225.144 Telstra Internet, Australia AUSTRALIA,SOUTH AUSTRALIA,ADELAIDE
     23 60.182.34.1 CHINANET Zhejiang province CHINA,ZHEJIANG,HANGZHOU
     23 109.184.112.66 OJSC Rostelecom, Russia RUSSIAN FEDERATION,NOVGOROD,VELIKIY NOVGOROD
     22 60.182.178.219 CHINANET Zhejiang province CHINA,ZHEJIANG,HANGZHOU
     20 92.242.59.6 Plusinfo Network, Moscow, Russia RUSSIAN FEDERATION,MOSCOW CITY,MOSCOW
     20 76.186.176.152 Time Warner Cable Internet LLC UNITED STATES,TEXAS,ALLEN
     20 5.158.234.108 INFO-LINK Cheboksary, Russia RUSSIAN FEDERATION,CHUVASHIA,CHEBOKSARY
     20 37.57.231.132 TRIOLAN Ukraine (Blocked) UKRAINE,KHARKIVS'KA OBLAST',KHARKIV
     20 37.144.60.54 OJSC "Vimpelcom", Russia RUSSIAN FEDERATION,MOSCOW CITY,MOSCOW
     20 37.144.44.14 OJSC "Vimpelcom", Russia RUSSIAN FEDERATION,MOSCOW CITY,MOSCOW
     20 37.144.34.82 OJSC "Vimpelcom", Russia RUSSIAN FEDERATION,MOSCOW CITY,MOSCOW
     20 205.204.88.227 Netelligent Hosting Services Inc., Canada CANADA,QUEBEC,MONTREAL
     20 176.15.235.174 OJSC "Vimpelcom", Russia RUSSIAN FEDERATION,MOSCOW CITY,MOSCOW
     20 123.155.242.36 China Unicom Zhejiang province network, China CHINA,ZHEJIANG,HANGZHOU
     20 109.106.138.76 Svyaz-Telecom, Russian Federation RUSSIAN FEDERATION,VORONEZH,VORONEZH
     19 188.43.116.188 TransTeleCom, Russia RUSSIAN FEDERATION,IRKUTSK,BRATSK
Looks like the Russians and Chinese are really trying to get past our two captcha unsuccessfully (whew!).  Lots of activity from Nizhniy Novgorod, Russia. which shows now that I'm using a ip2location local database in my log processing.

Keep those shields up.. they are out to get you :)

Best regards,
Ken
« Last Edit: September 01, 2014, 12:22:38 PM by saratogaWX »
Ken True/Saratoga, CA, USA main site: saratoga-weather.org
Davis VP1+ FARS, Blitzortung RED, GRLevel3, WD, WL, VWS, Cumulus, Meteobridge
Free weather PHP scripts/website templates - update notifications on Twitter saratogaWXPHP

Offline Old Tele man

  • Singing in the rain...
  • Forecaster
  • *****
  • Posts: 1365
Re: Behind the scenes.. they try, but can't come in...
« Reply #18 on: September 01, 2014, 01:25:57 PM »
...and Captain Kirk yells: "...MORE POWER to the SHIELDS, Scotty..."
• SYS: Davis VP2 Vue/WL-IP & Envoy8X/WL-USB;
• DBX2 & DBX1 Precision Digital Barographs
• CWOP: DW6988 - 2 miles NNE of Cortaro, AZ
• WU - KAZTUCSO202, Countryside

 

anything