We Must Be Doing Something Right

I received a notification that someone was trying to hack into NCRenegade.com:

16 failed login attempts (4 lockout(s)) from IP 197.34.226.18 and it was blocked for 24 hours
Last user attempted: ncrenegade

Although the attack appears to have originated in London, I will never know for sure since anything can be spoofed.

David DeGerolamo

~~~~~~~~~~~~~~~~~~~

Tracing route to host-197.34.226.18.tedata.net [197.34.226.18]
over a maximum of 30 hops:

1 <1 ms <1 ms <1 ms LINKSYS04976 [192.58.158.103]
2 2 ms 2 ms 2 ms 172.18.48.1
3 2 ms 2 ms 2 ms 66.119.99.1
4 4 ms 3 ms 3 ms 10.0.62.1
5 4 ms 3 ms 3 ms 192.34.172.217
6 * * * Request timed out.
7 96 ms 96 ms 96 ms ae-1-3110.edge3.London1.Level3.net [4.69.140.198]
8 150 ms 170 ms 150 ms TELECOM-EGY.edge3.London1.Level3.net [217.163.45.234]
9 159 ms 159 ms 159 ms 10.38.125.70
10 160 ms 160 ms 160 ms 10.38.82.14
11 160 ms 160 ms 161 ms 10.38.113.97

    
Plugin by: PHP Freelancer
This entry was posted in Editorial. Bookmark the permalink.
0 0 votes
Article Rating
10 Comments
Oldest
Newest
Inline Feedbacks
View all comments
Brandon
Brandon
3 years ago

I would enable 2 factor authentication if you can. While not bullet proof it does help.

oldtimer505
3 years ago

You may be right DG. I don’t know what you or anyone else has done to attract such attention but, it would appear that someones tender feeling have been bruised. I figure it will only get worse.

Bone Fish
3 years ago

PLA, CIA, FBI, DOJ… the possibilities are endless.

Hammers Thor
3 years ago

Nice! Touching a nerve. You know what they say… when you start taking flak, you’re over the target.
OPEN THE BOMB BAY DOORS!

SW Richmond
3 years ago

“TELECOM-EGY”

197.34.226.18
ARIN points WHOIS for this IP to AFRINIC

AFRINIC says route: 197.34.224.0/19
descr: Telecom-Egypt-Data

Giza, Egypt

Traffic is no doubt routed through London, but the IP is registered to Egypt.

Matt
Matt
3 years ago
Reply to  DRenegade

Undoubtedly using a VPN and or (more likely) Tor. Make sure you have key (only) based auth into,the root system and have 2FA on the admin accounts.

Your partner Wes can vouch for me as being a fellow system operator. If you ever want to talk shop, I’m happy to help.

Bill Sullivan
Bill Sullivan
3 years ago

Consider also that it may be the Chinese. I strongly suspect that they have been blaming the Russians for years, and the Chinese have the money, people, and knowledge to spoof anything.

Arch Stanton
Arch Stanton
3 years ago

Whenever a liberal (communist) can’t beat you they try to destroy you.
NCrenegade is kryptonite to these bottom dwellers. Keep it up.

LT
LT
3 years ago

Transferring control to bombadier