![]() |
|
|
|
Registered
Join Date: Apr 2000
Location: Mid-life crisis, could be anywhere
Posts: 10,382
|
I block all IP addresses outside of the U.S.
__________________
'95 993 C4 Cabriolet Bunch of motorcycles |
||
![]() |
|
Cars and Cappuccino
|
Everyday I get messages about attacks on my site listed below. Usually Russia, sometimes France and occasionally within the US - assuming no IP spoofing.
__________________
http://www.carsandcappuccino.com 1987 Grand Prix White "Outlaw" Turbo Coupe w/go-fast bits 1985 Prussian Blau M491 Targa 1977 Mexico Blue back-dated,flared,3.2,sunroof-delete Coupe 1972 Black 911 T Coupe to first factory Turbo (R5 chassis) tribute car (someday) |
||
![]() |
|
The Stick
|
Yep, hacker bots trying to spawn spam are as bad or worse than spammers themselves.
Host my own servers on a Cox Business account and they do a very good job of monitoring security and keeping the hackers a bay. Only had two incidents. A couple of users were using really out of date email clients and their SSL got hacked for their password. Got informed by Cox Business security team within the hour and they blocked the hackers IPs. Changed the accounts passwords and forced users to get new email clients and all is well.
__________________
Richard aka "The Stick" 06 Cayenne S Titanium Edition |
||
![]() |
|
It'll be legen-waitforit
Join Date: Jan 2002
Location: Calgary, Canada
Posts: 6,976
|
Your best bet is defense in depth; Cisco ASA's with Firepower are now awesome, put some F5's or Netscalers behind them (DMZ) to front the servers and put AMP for Endpoints along with AV on the servers and you should be good from DOS, Malware, etc.
I am pushing to get it mandated that ISP's & government agencies get involved and block at the source; they are already reading our email and watching to see if we are downloading movies, so why not do something useful instead. It doesn't help that all governments are part of the problem as well.....
__________________
Bob James 06 Cayman S - Money Penny 18 Macan GTS Gone: 79 911SC, 83 944, 05 Cayenne Turbo, 10 Panamera Turbo |
||
![]() |
|
Registered
|
Don't overthink this, move your site to Amazon and change elastic ip's every few months. Expensive hardware solutions like ASA, and Palo are not conducive to the little guy.
__________________
2021 Model Y 2005 Cayenne Turbo 2012 Panamera 4S 1980 911 SC 1999 996 Cab |
||
![]() |
|
It'll be legen-waitforit
Join Date: Jan 2002
Location: Calgary, Canada
Posts: 6,976
|
Amazon and Azure are just as likely to be targets as private systems, that's why they offer virtual protection systems like F5 etc.
__________________
Bob James 06 Cayman S - Money Penny 18 Macan GTS Gone: 79 911SC, 83 944, 05 Cayenne Turbo, 10 Panamera Turbo |
||
![]() |
|
![]() |
Registered
|
But for pennies you can change IP's then reroute with R53. And they do a damn good job on their side preventing DDOS and a lot of other bad stuff.
__________________
2021 Model Y 2005 Cayenne Turbo 2012 Panamera 4S 1980 911 SC 1999 996 Cab |
||
![]() |
|
Super Moderator
|
Got compromised one time... Wasn't sql injection it was an exploit of the open source I was running. They were able to get a pic file in a temp directory and used it for mass spamming. 5 years later our url is finally free of most email blacklists.
I know have a daily scan that checks all core files and file counts and alerts me if anything changes.
__________________
Chris ---------------------------------------------- 1996 993 RS Replica 2023 KTM 890 Adventure R 1971 Norton 750 Commando Alcon Brake Kits |
||
![]() |
|
The Unsettler
|
Quote:
I have one client who used to get blacklisted every other month. Took all of 15 minutes of work to get them delisted from SORBS in 3 days or less.
__________________
"I want my two dollars" "Goodbye and thanks for the fish" "Proud Member and Supporter of the YWL" "Brandon Won" |
||
![]() |
|
Burn the fire.
|
After reading this thread now I want to move all my hosting to rackspace or bluehost.
__________________
[x] Working | [_] Broken: 2017 Victory Octane [x] Working | [_] Broken: 2005 Ram 1500 SLT w/5.7L Hemi "Drive it like you stole it." |
||
![]() |
|
The Unsettler
|
Quote:
Bluehost will work if you like having your IP range regularly blacklisted. |
||
![]() |
|
![]() |
Thread Tools | |
Rate This Thread | |
|