Hundreds of thousands of webpages belonging to businesses, government agencies, and schools have been infiltrated by scammers pushing Viagra, Tadalafil, and other drugs. The towns of Birmingham and Horwich in the UK and Princeton University in the US are among those who have been hacked. Yahoo searches here, here, and here …


    Sadly, I am really starting to wonder what abuse reports affect people in charge. Most of the time (been doing that for 10 years now), you just never get a reply.

    So what about firewalls

    Seems the author believes FTP passwords might be to blame.

    This is shocking on two fronts, firstly the password must have been so weak that it was cracked before anybody spotted the event logs with thousands of password attempts in it. Secondly FTP was publicly open. The latter is I hear very common. Why don't these people use even the simplest of firewalls, come on, IPTABLES and limiting the application to specific IP's has massive protection without any cost and maybe 2-3 hours of reading the manual and experimenting on an old PC. This is really basic security and so many establishments seem to constantly fall to this method of infiltration.

    I know some webhosting companies allow access from all sorts of IP's and without firewalling, but this is completely unnecessary, they need to insist their customers have a static IP. How many Webdesigners can't afford a couple of bucks extra a month for a static IP (You seen the prices the webbies charge!).

    I personally dislike FTP and don't have it installed, but for other required apps, a simple IPTABLES firewall keeps nosy Joe from even a single entry in my security logs.

    As for emergency access, the 3G connection is invaluable when out on the road, but this is simple by using an account without any privs, and the machine does nothing but allow SSH, and no password being set (ssh passphrases instead). This makes the crackers job somewhat difficult, and not to mention the machine regularly gets hosed thanks to a read-only USB install (one of those USB disks with a physical ro/rw switch).

    It's the idiots that actually buy from these scammers that are largely to blame. If people stopped responding to spam and other such crap then it would go away.

    Shoot the messenger

    Who's serving up these ads? Line them up and shoot them. Or fine them or something, whatever's easier.

    I May Have Seen One

    There was a text ad for a casino at the top of one of the pages of a web site on the history of playing cards I visited earlier today, and yet the other pages ot that site had no ads.

    This was in the middle of their course on the history of playing cards; I believe it was a British site at that.

    re: what about firewalls

    Doesn't matter how many attempts it took if no one is actively monitoring the logs. Even an automated log parser/blocker like DenyHosts or Fail2ban is of limited use if a large botnet is trying to brute-force a password.

    "It's the idiots that actually buy from these scammers that are largely to blame."

    Indeed. The trouble is that it only takes a response rate of 0.01% or so to make the spam (highly) profitable. If you know of a human society where the moron rate is << 0.01% (or < 1% for that matter), I'd love to relocate there.

