Pelican Parts Forums

Pelican Parts Forums (http://forums.pelicanparts.com/)
-   Off Topic Discussions (http://forums.pelicanparts.com/off-topic-discussions/)
-   -   Are anyone else's websites under attack? (http://forums.pelicanparts.com/off-topic-discussions/919218-anyone-elses-websites-under-attack.html)

motion 06-23-2016 01:58 PM

I block all IP addresses outside of the U.S.

tdw28210 06-23-2016 02:09 PM

Everyday I get messages about attacks on my site listed below. Usually Russia, sometimes France and occasionally within the US - assuming no IP spoofing.

RKDinOKC 06-23-2016 09:43 PM

Yep, hacker bots trying to spawn spam are as bad or worse than spammers themselves.

Host my own servers on a Cox Business account and they do a very good job of monitoring security and keeping the hackers a bay.

Only had two incidents. A couple of users were using really out of date email clients and their SSL got hacked for their password. Got informed by Cox Business security team within the hour and they blocked the hackers IPs. Changed the accounts passwords and forced users to get new email clients and all is well.

stealthn 06-24-2016 03:00 PM

Your best bet is defense in depth; Cisco ASA's with Firepower are now awesome, put some F5's or Netscalers behind them (DMZ) to front the servers and put AMP for Endpoints along with AV on the servers and you should be good from DOS, Malware, etc.

I am pushing to get it mandated that ISP's & government agencies get involved and block at the source; they are already reading our email and watching to see if we are downloading movies, so why not do something useful instead.

It doesn't help that all governments are part of the problem as well.....

Scott R 06-24-2016 05:19 PM

Don't overthink this, move your site to Amazon and change elastic ip's every few months. Expensive hardware solutions like ASA, and Palo are not conducive to the little guy.

stealthn 06-24-2016 05:23 PM

Amazon and Azure are just as likely to be targets as private systems, that's why they offer virtual protection systems like F5 etc.

Scott R 06-24-2016 05:52 PM

Quote:

Originally Posted by stealthn (Post 9174199)
Amazon and Azure are just as likely to be targets as private systems, that's why they offer virtual protection systems like F5 etc.

But for pennies you can change IP's then reroute with R53. And they do a damn good job on their side preventing DDOS and a lot of other bad stuff.

cstreit 06-24-2016 06:30 PM

Got compromised one time... Wasn't sql injection it was an exploit of the open source I was running. They were able to get a pic file in a temp directory and used it for mass spamming. 5 years later our url is finally free of most email blacklists.

I know have a daily scan that checks all core files and file counts and alerts me if anything changes.

stomachmonkey 06-24-2016 07:36 PM

Quote:

Originally Posted by cstreit (Post 9174262)
Got compromised one time... Wasn't sql injection it was an exploit of the open source I was running. They were able to get a pic file in a temp directory and used it for mass spamming. 5 years later our url is finally free of most email blacklists.

I know have a daily scan that checks all core files and file counts and alerts me if anything changes.

Did you request delisting?

I have one client who used to get blacklisted every other month.

Took all of 15 minutes of work to get them delisted from SORBS in 3 days or less.

Brando 06-25-2016 07:19 AM

After reading this thread now I want to move all my hosting to rackspace or bluehost.

stomachmonkey 06-26-2016 05:40 AM

Quote:

Originally Posted by Brando (Post 9174681)
After reading this thread now I want to move all my hosting to rackspace or bluehost.

Rack space is fine.

Bluehost will work if you like having your IP range regularly blacklisted.


All times are GMT -8. The time now is 03:00 AM.

Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2025, vBulletin Solutions, Inc.
Search Engine Optimization by vBSEO 3.6.0
Copyright 2025 Pelican Parts, LLC - Posts may be archived for display on the Pelican Parts Website


DTO Garage Plus vBulletin Plugins by Drive Thru Online, Inc.