Free Republic
Browse · Search
News/Activism
Topics · Post Article

To: Travis McGee; Lazamataz
How about the power companies that run our grid, pipelines, etc?

Some of the stuff I've seen still RUNNING the power companies is downright scary.

I won't say which companies, however some of them are still running Windows NT 4.0 Servers running core functions at the power plant. Most of these servers are now virtualized to eliminate the problem of hardware failures however they're still not protected properly with multi-layer security (DMZ, Web, App, Core network zones) or multi-factor authentication systems to prevent unauthorized access.

BTW: Just last week I caught several Russian hackers using DNS spoofing through compromised South American, Netherlands and Spain based companies trying to hack into one of our public FTP Servers. They tried brute force SSH password cracking and executed over 59,000 brute force attempts in just over 3 minutes.

They didn't get in because we require matching certificates and dual-factor authentication for Internet exposed services and within their first 10 attempts (which happened in microseconds) I had an alert fired off and tracing programs already running to determine the true locations of the Russian hackers.

My own opinion based on the results I collected is that it was Russian State Sponsored hacking. It had to be due to its sophistication, the sheer volume of brute force password attempts in such a small amount of time, and the fact that the IP's traced back to Russian Government facilities.

Granted, I'm not supposed to say those things outside the bank and the FBI (who we work with on these things -- they're working with ALL the top tier banks directly) certainly wouldn't "approve" of my saying it.

17 posted on 12/20/2014 6:56:14 AM PST by usconservative (When The Ballot Box No Longer Counts, The Ammunition Box Does. (What's In Your Ammo Box?))
[ Post Reply | Private Reply | To 9 | View Replies ]


To: usconservative

I know it’s SFTP but still, can’t you autoblock an IP after X number of failed attempts? You wouldn’t necessarily slow throughput if you limited the filter to authentication. Once a channel was established, pass through the filter without incident.


18 posted on 12/20/2014 7:00:47 AM PST by Lazamataz ("Two parties, governing AGAINST the will of the people, not with the consent of the governed." --MrB)
[ Post Reply | Private Reply | To 17 | View Replies ]

To: usconservative

Your public FTP is still SFTP, right?


19 posted on 12/20/2014 7:01:26 AM PST by Lazamataz ("Two parties, governing AGAINST the will of the people, not with the consent of the governed." --MrB)
[ Post Reply | Private Reply | To 17 | View Replies ]

To: usconservative; Lazamataz

Thanks for the inside baseball on this stuff.

It is fascinating.

The scope and tenacity of hackers is not to be underestimated.


23 posted on 12/20/2014 7:09:01 AM PST by exit82 ("The Taliban is on the inside of the building" E. Nordstrom 10-10-12)
[ Post Reply | Private Reply | To 17 | View Replies ]

To: usconservative; CodeToad; Joe Brower

Thanks for the inside view.


41 posted on 12/20/2014 12:38:35 PM PST by Travis McGee (www.EnemiesForeignAndDomestic.com)
[ Post Reply | Private Reply | To 17 | View Replies ]

Free Republic
Browse · Search
News/Activism
Topics · Post Article


FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson