09-14-2013, 08:32 PM
|
#1
|
Member
Join Date: Feb 2012
Location: Mesa, AZ
Posts: 80
|
Russian Hackers!!
I got this email earlier today:
Dear ACR_Ted,
Someone has tried to log into your account on RailPictures.Net Forums with an incorrect password at least 5 times. This person has been prevented from attempting to login to your account for the next 15 minutes.
The person trying to log into your account had the following IP address: 188.143.232.144
All the best,
RailPictures.Net Forums
Anyone else ever get one like this? The IP is somewhere in Russia...thats as far as I went in researching it. 
Ted
|
|
|
09-14-2013, 10:53 PM
|
#2
|
Senior Member
Join Date: Sep 2011
Posts: 379
|
Whoa - you managed to actually get an e-mail from the admins??
-Jacques
|
|
|
09-14-2013, 11:07 PM
|
#3
|
Banned
Join Date: Mar 2010
Location: In the California Republic
Posts: 2,774
|
Automated email.
|
|
|
09-23-2013, 12:10 PM
|
#4
|
Banned
Join Date: Aug 2009
Posts: 335
|
I have received the same message from the admins today. Anybody knows more about these hackers?
******************************
Dear Daniel SIMON,
Someone has tried to log into your account on RailPictures.Net Forums with an incorrect password at least 5 times. This person has been prevented from attempting to login to your account for the next 15 minutes.
The person trying to log into your account had the following IP address: 188.143.234.6
All the best,
RailPictures.Net Forums
|
|
|
09-23-2013, 01:55 PM
|
#5
|
Senior Member
Join Date: Dec 2002
Location: Fairfax, VA
Posts: 381
|
Yesterday, I got one that IDed 188.143.235.118
|
|
|
09-23-2013, 01:58 PM
|
#6
|
Senior Member
Join Date: Nov 2011
Location: Central NC
Posts: 236
|
Quote:
Originally Posted by ddavies
Yesterday, I got one that IDed 188.143.235.118
|
I've gotten 2 or 3 from this IP and one from the original post.
|
|
|
09-23-2013, 02:59 PM
|
#7
|
Senior Member
Join Date: Dec 2011
Location: New Jersey
Posts: 124
|
I've also received 3 or 4 of these emails in the past week, supposedly from Chris Kilroy at RP Forums, citing a similar IP address.
Now, of course, it looks like some hack job, and not anything from RP. (I was wondering who'd want to impersonate me. Chase, Joe, or Janusz, yes, but me?)
So - Are these emails from a hacker, or is RP notifying us of a hacker they've caught onto??
|
|
|
09-23-2013, 03:26 PM
|
#8
|
Junior Member
Join Date: Feb 2013
Location: West Virginia
Posts: 1
|
I have gotten a similar email three times within the past week.
-JE
"Dear Appalachianrails,
Someone has tried to log into your account on RailPictures.Net Forums with an incorrect password at least 5 times. This person has been prevented from attempting to login to your account for the next 15 minutes.
The person trying to log into your account had the following IP address: 188.143.234.6
All the best,
RailPictures.Net Forums"
|
|
|
09-23-2013, 06:24 PM
|
#9
|
Banned
Join Date: Jun 2008
Location: Tampa, FL
Posts: 5,333
|
Netblock is owned by some russian company:
reverse-ip: sexmuviki.ru
inetnum: 188.143.234.0 - 188.143.234.255
netname: ToussaintDesaulniers-net
descr: dedicated server client
country: RU
admin-c: TD2673-RIPE
tech-c: TD2673-RIPE
status: ASSIGNED PA
mnt-by: MNT-PIN
source: RIPE # Filtered
person: Toussaint Desaulniers
address: 57, cours Franklin Roosevelt 13007 MARSEILLE
phone: +49 0 9401 784 003
nic-hdl: TD2673-RIPE
mnt-by: MNT-PINSUPPORT
source: RIPE # Filtered
route: 188.143.234.0/23
descr: PINROUTE
origin: as44050
mnt-by: MNT-PIN
source: RIPE # Filtered
|
|
|
09-23-2013, 11:31 PM
|
#10
|
Senior Member
Join Date: Nov 2008
Location: Youngstown, Ohio
Posts: 168
|
Can you break that down Barney-level for folks like me?
|
|
|
09-24-2013, 01:38 AM
|
#11
|
Member
Join Date: Oct 2009
Posts: 50
|
Me too....
|
|
|
09-24-2013, 01:39 AM
|
#12
|
Member
Join Date: Oct 2009
Posts: 50
|
Got two messages Sunday and one tonight.
|
|
|
09-24-2013, 02:36 AM
|
#13
|
Senior Member
Join Date: Dec 2009
Location: Cincinnati, Ohio
Posts: 1,268
|
Ditto.....
|
|
|
09-24-2013, 03:50 AM
|
#14
|
Banned
Join Date: Jun 2008
Location: Tampa, FL
Posts: 5,333
|
In soviet Russia, computer hacks you!
|
|
|
09-24-2013, 04:05 AM
|
#15
|
Senior Member
Join Date: Dec 2011
Location: New Jersey
Posts: 124
|
I'm still hoping for the Barney-level take on this matter, too.
And does anyone know if those emails we received came from this Russian place, or was RP notifying us about real attempts to hack in?
|
|
|
09-24-2013, 09:15 AM
|
#16
|
Senior Member
Join Date: Apr 2006
Posts: 3,674
|
I don't get it - what's the point of such a hack?
They didn't ask for anything? No password or address, nothing?
/Mitch
Quote:
Originally Posted by ACR_Ted
I got this email earlier today:
Dear ACR_Ted,
Someone has tried to log into your account on RailPictures.Net Forums with an incorrect password at least 5 times. This person has been prevented from attempting to login to your account for the next 15 minutes.
The person trying to log into your account had the following IP address: 188.143.232.144
All the best,
RailPictures.Net Forums
Anyone else ever get one like this? The IP is somewhere in Russia...thats as far as I went in researching it. 
Ted
|
|
|
|
09-24-2013, 12:44 PM
|
#17
|
Senior Member
Join Date: Dec 2006
Location: Hilldale, West Virginia
Posts: 3,878
|
Quote:
Originally Posted by troy12n
In soviet Russia, computer hacks you!
|
+1
Loyd Lowry
|
|
|
09-24-2013, 02:12 PM
|
#18
|
Senior Member
Join Date: Dec 2011
Location: New Jersey
Posts: 124
|
Mitch - If this is hacking, the only thing I can think of is perhaps hackers will hack anything trying to obtain any identifying info (email addresses, IDs, passwords, zip codes) on anyone. That can then be used to hack into something else - like bank accounts or credit / debit card accounts.
A friend of mine had her debit card account hacked by someone who apparently obtained her email address and zip code somehow, then used that to change a password on the account. Then he accessed the account and purchased a couple thousand bucks worth of computer games and garbage online.
Of course, this could just be a simple glitch, too.
So ... does anyone have any more info on this?
|
|
|
09-25-2013, 08:17 PM
|
#19
|
Senior Member
Join Date: Sep 2011
Posts: 379
|
Welp, I thought I was immune, until I got one this morning. IP was 188.143.234.6
-Jacques
|
|
|
09-25-2013, 10:00 PM
|
#20
|
Junior Member
Join Date: Aug 2010
Location: Northern Ontario
Posts: 28
|
Since this is apparently widespread (I also just received a similar warning, which I believe to be a legitimate feature of vBulletin), can an admin please add to .htaccess (or forum-level IP blacklist if server-level blacklisting isn't possible)?
|
|
|
09-25-2013, 11:25 PM
|
#21
|
Banned
Join Date: Jun 2008
Location: Tampa, FL
Posts: 5,333
|
Quote:
Originally Posted by James Heinrich
Since this is apparently widespread (I also just received a similar warning, which I believe to be a legitimate feature of vBulletin), can an admin please add to .htaccess (or forum-level IP blacklist if server-level blacklisting isn't possible)?
|
Doing that will block potentially 65,000 IP addresses. The company who owns the entire class B netblock 188.143.0.0/16 is a company in Amsterdam called RIPE. They own the address space and have leased at least 188.143.232-235.0/24 to some Russian ISP or hosting provider.
You dont want to block an entire class B network, no one does that... even foreign netblocks.
|
|
|
09-25-2013, 11:38 PM
|
#22
|
Junior Member
Join Date: Aug 2010
Location: Northern Ontario
Posts: 28
|
Quote:
Originally Posted by troy12n
You dont want to block an entire class B network, no one does that... even foreign netblocks.
|
Well, at least 188.143.232-235 then.
Or, at the very least, the 4 offending IPs noted in this thread:
188.143.232.144
188.143.234.6
188.143.234.14
188.143.235.118
Last edited by James Heinrich; 09-26-2013 at 06:39 PM.
Reason: updated list of reported IPs
|
|
|
09-26-2013, 02:16 AM
|
#23
|
Senior Member
Join Date: Apr 2010
Posts: 122
|
I just received one to.
Oh the fun
Jason
|
|
|
09-26-2013, 02:43 AM
|
#24
|
Senior Member
Join Date: Nov 2008
Location: Youngstown, Ohio
Posts: 168
|
At what point does someone of importance step in and say "no need to worry, we are working this issue"?
|
|
|
09-26-2013, 04:04 AM
|
#25
|
Senior Member
Join Date: Nov 2006
Posts: 11,202
|
I suspect this is not within RP's control. In fact, they are doing what needs to be done, they are blocking further log-in attempts.
|
|
|
Thread Tools |
Search this Thread |
|
|
Display Modes |
Linear Mode
|
Posting Rules
|
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
HTML code is On
|
|
|
All times are GMT. The time now is 08:11 AM.
|