Results 1 to 17 of 17

Thread: IP Block Arsehole Clients

  1. #1
    Junior Member
    Join Date
    Jan 2008
    Posts
    72
    Thanks
    0
    Thanked 0 Times in 0 Posts
    Rep Power
    201
    Reputation
    10

    Default IP Block Arsehole Clients

    Task: Rouge client ftp's client Dreambox extracts .cfg details then jumps from one user name to next as quick as I can ban, a big disruption!

    TIP: Always use root password!

    So I researched a veriaty of modem / routers, and found a popular router, typically used for gaming that has excellent IP inbound blocking feature it’s the D-Link DSL-G640T. Once set up it is a breeze to block any rouge inbound IP's.



Look Here ->
  • #2
    Senior Member z80's Avatar
    Join Date
    Jan 2008
    Posts
    5,840
    Thanks
    112
    Thanked 77 Times in 48 Posts
    Rep Power
    0
    Reputation
    708

    Default

    I use a different port forwarding rule for each client.
    In case of fire I just break that port and away she goes with no load on anything.

  • #3
    Junior Member
    Join Date
    Apr 2008
    Posts
    14
    Thanks
    0
    Thanked 0 Times in 0 Posts
    Rep Power
    0
    Reputation
    10

    Default

    Quote Originally Posted by palmac View Post
    Task: Rouge client ftp's client Dreambox extracts .cfg details then jumps from one user name to next as quick as I can ban, a big disruption!

    TIP: Always use root password!

    So I researched a veriaty of modem / routers, and found a popular router, typically used for gaming that has excellent IP inbound blocking feature it’s the D-Link DSL-G640T. Once set up it is a breeze to block any rouge inbound IP's.
    Only problem with IP blocking, is if they are bhind a dynamic IP, it will just require a modem cycle, and normally you get a different IP address.

  • #4
    Premium Member

    Join Date
    Jan 2008
    Posts
    1,920
    Thanks
    361
    Thanked 804 Times in 379 Posts
    Rep Power
    377
    Reputation
    5712

    Default

    Quote Originally Posted by z80 View Post
    I use a different port forwarding rule for each client.
    In case of fire I just break that port and away she goes with no load on anything.
    Now that's thinking outside the square!

  • #5
    Premium Member
    Join Date
    Jan 2008
    Location
    Melbourne
    Posts
    855
    Thanks
    246
    Thanked 87 Times in 69 Posts
    Rep Power
    244
    Reputation
    886

    Default

    Quote Originally Posted by z80 View Post
    I use a different port forwarding rule for each client.
    In case of fire I just break that port and away she goes with no load on anything.
    More information,.. as I can't see how a port scan wouldn't defeat this ? Assuming you have other clients coming in to the same server/serving app without IP filtering ?

  • #6
    Premium Member

    Join Date
    Jan 2008
    Posts
    1,920
    Thanks
    361
    Thanked 804 Times in 379 Posts
    Rep Power
    377
    Reputation
    5712

    Default

    Quote Originally Posted by jimbo123 View Post
    More information,.. as I can't see how a port scan wouldn't defeat this ? Assuming you have other clients coming in to the same server/serving app without IP filtering ?
    The way I see it, it would take a pretty good guess or a lot of trial and error to pick the correct client to the assigned port.
    Eg each client has their own incoming port redirected to the server port.

    Not worth the hassle for someone really.
    Last edited by warbo; 13-07-08 at 07:14 PM. Reason: Add more info

  • #7
    Senior Member z80's Avatar
    Join Date
    Jan 2008
    Posts
    5,840
    Thanks
    112
    Thanked 77 Times in 48 Posts
    Rep Power
    0
    Reputation
    708

    Default

    Quote Originally Posted by warbo View Post
    The way I see it, it would take a pretty good guess or a lot of trial and error to pick the correct client to the assigned port.

    Not worth the hassle.

    yep....especially if the deskey is not the default one.


    But i like to have fun with hackers so....

    Setup a newcs server (with no sensible service) on a dummy pc on the network for a few days....then you can watch them knock themselves out trying to hack into it ...

    just use default deskey, use Local Local, guest guest etc...
    make it easy fro them to get in and let them chip away at it.

    make it a slow PC as well....


    Of course if you know their IP why not hack them back?


    Also palmac if you care to post the offending IP I am sure a few people here would be happy to do some probeing for you...

  • #8
    Senior Member z80's Avatar
    Join Date
    Jan 2008
    Posts
    5,840
    Thanks
    112
    Thanked 77 Times in 48 Posts
    Rep Power
    0
    Reputation
    708

    Default

    Quote Originally Posted by jimbo123 View Post
    More information,.. as I can't see how a port scan wouldn't defeat this ? Assuming you have other clients coming in to the same server/serving app without IP filtering ?

    I have an app that reroutes a port to anywhere you like.
    I can put multiple lines in a cccam.cfg file for as many ports as you like.

    Then i can change the rerouted port on the fly every hour to frustrate a hacker.

    Newcs can be made to accept a password only from a specific IP as well.

  • #9
    Junior Member
    Join Date
    Jan 2008
    Posts
    72
    Thanks
    0
    Thanked 0 Times in 0 Posts
    Rep Power
    201
    Reputation
    10

    Default

    Quote Originally Posted by z80 View Post
    yep....especially if the deskey is not the default one.


    But i like to have fun with hackers so....

    Setup a newcs server (with no sensible service) on a dummy pc on the network for a few days....then you can watch them knock themselves out trying to hack into it ...

    just use default deskey, use Local Local, guest guest etc...
    make it easy fro them to get in and let them chip away at it.

    make it a slow PC as well....


    Of course if you know their IP why not hack them back?


    Also palmac if you care to post the offending IP I am sure a few people here would be happy to do some probeing for you...
    If ID'd a big sloppy kiss and a slab of VB is in store for you bud. Just gives us your nearest bottle-o, I'll pay and have them leave it on the counter for you. The kiss is optional.

    122.107.178.119

    This guy caused me dramas for weeks jumping all over my clients user names.

    dont know who he is as I did not sell him the box directly. I'm told Optus ISP and is in Melbourne?

  • #10
    Junior Member
    Join Date
    Jan 2008
    Posts
    72
    Thanks
    0
    Thanked 0 Times in 0 Posts
    Rep Power
    201
    Reputation
    10

    Default

    Quote Originally Posted by spclst69 View Post
    Only problem with IP blocking, is if they are bhind a dynamic IP, it will just require a modem cycle, and normally you get a different IP address.
    Yes dynamic IP but its still so easy to ID the bad IP and set in the filter. I'm not talking about a fllood of pricks. Just one or two. You can also set an IP range.

    z80's method no doubt would work a treat but a lot of setting up if you have more than a hand full of clients. Most of the time clients are pretty good but the odd smart arse thinks he's got it beat.

  • #11
    Senior Member covert's Avatar
    Join Date
    Jan 2008
    Location
    My Imagination
    Posts
    983
    Thanks
    31
    Thanked 34 Times in 20 Posts
    Rep Power
    233
    Reputation
    131

    Default

    A dd-wrt compatible router with Z80's method would be easy to maintain lots of clients. Since all routing table is all in a config file. dd-wrt also gives you automatic dynaic ip updating via a handful of providers. So no need to tell your clients your new IP address all the time.

    Also get your clients to use dynamic IP service and you never have to update there new IP addresses either, when they do a modem reboot. They can run a simple onboot program that will update it for them automatically or they can do it manually on the dynamic IP providers website.
    By reading this, you have already given me control over a tiny slice of your mind

  • #12
    Junior Member
    Join Date
    Jan 2008
    Posts
    72
    Thanks
    0
    Thanked 0 Times in 0 Posts
    Rep Power
    201
    Reputation
    10

    Default

    Covert, nice one!

  • #13
    Premium Member
    Join Date
    Jan 2008
    Posts
    1,558
    Thanks
    65
    Thanked 84 Times in 64 Posts
    Rep Power
    270
    Reputation
    1032

    Default

    I know this is an old post however I am looking to see if I can block a problem with an incoming client request.

    Apart from an IP address block or a port forward redirection on the router is there a setting for the Newcs server that might be able to do this.???

    Just wondering if there has been any other methods available since this was discussed in this post over 2 years ago??

  • #14
    Senior Member mborkp's Avatar
    Join Date
    Feb 2008
    Posts
    1,121
    Thanks
    526
    Thanked 300 Times in 163 Posts
    Rep Power
    264
    Reputation
    1466

    Default

    change the server port

    Cheers

    Quote Originally Posted by checkitout View Post
    I know this is an old post however I am looking to see if I can block a problem with an incoming client request.

    Apart from an IP address block or a port forward redirection on the router is there a setting for the Newcs server that might be able to do this.???

    Just wondering if there has been any other methods available since this was discussed in this post over 2 years ago??

  • #15
    Junior Member
    Join Date
    Jan 2008
    Posts
    162
    Thanks
    38
    Thanked 0 Times in 0 Posts
    Rep Power
    204
    Reputation
    10

    Default

    hi guys,whats the fix for the passwd not being able to be changed on a dreambox.i try to go telnet, passwd, and jumps to password not able to be changed.?

  • #16
    Senior Member nfnovice's Avatar
    Join Date
    Jan 2008
    Posts
    1,430
    Thanks
    261
    Thanked 336 Times in 213 Posts
    Rep Power
    282
    Reputation
    1840

    Default

    Quote Originally Posted by satbeginner View Post
    hi guys,whats the fix for the passwd not being able to be changed on a dreambox.i try to go telnet, passwd, and jumps to password not able to be changed.?
    The first fix is - Dont hijack threads with off topic questions- start your own

    the second fix is reflash the box
    Dm500, DM5620, DM600 x2, DM7000 x1, DM7020, DM7025, DM800, VU+DUO and a partridge in a pear tree
    All it takes for evil to prevail is for good men to do nothing

  • #17
    Senior Member nfnovice's Avatar
    Join Date
    Jan 2008
    Posts
    1,430
    Thanks
    261
    Thanked 336 Times in 213 Posts
    Rep Power
    282
    Reputation
    1840

    Default

    Quote Originally Posted by checkitout View Post
    I know this is an old post however I am looking to see if I can block a problem with an incoming client request.

    Apart from an IP address block or a port forward redirection on the router is there a setting for the Newcs server that might be able to do this.???

    Just wondering if there has been any other methods available since this was discussed in this post over 2 years ago??
    You can just take their user out of the Newcs.xml
    But that doesnt kill the traffic.

    You can swap to Oscam server - I see some interesting stuff in there about sending fake ecms to clients with more than one login....

    If it was me - I woul djust block there Ip at the router.. save your dreambox for what its supposed to do
    Dm500, DM5620, DM600 x2, DM7000 x1, DM7020, DM7025, DM800, VU+DUO and a partridge in a pear tree
    All it takes for evil to prevail is for good men to do nothing

  • Bookmarks

    Posting Permissions

    • You may not post new threads
    • You may not post replies
    • You may not post attachments
    • You may not edit your posts
    •