bunn: (canoeing)
[personal profile] bunn
Scrolling quickly through messages telling me which IP addresses have been autoblocked on various websites that I work on, because of dodgy-looking activity over the festive season, I notice that there is a sudden upswing in Russian and Ukrainian IP addresses.  (My sites are almost all hosted in the UK, because dealing with the data wrangles of hosting outside the EU is a headache I do not need).

Normally, attempts to get into my websites come largely from the USA and (inexplicably) France.   The orthodoxy, I believe,  is to assume that these US attacks are not really from the US, but are from US-based machines hijacked from Eastern Europe.  (I don't know about the French thing.  Nobody else seems to be specially targeted by the French, so I have seen no discussion on it).

I don't know what to make of the sudden prominence of Russian IPs.  Have the US authorities cracked down on the hijacked machines?  Are the new attacks reported as Russian and Ukrainian, actually now coming from hijackers physically located in the USA, in a kind of weird symmetry?  Is it entirely chance?

I'll probably never know.  I can only feel vaguely reassured that the software is doing its thing and nobody is complaining. 

Date: 2017-01-04 08:50 am (UTC)
ext_189645: (Default)
From: [identity profile] bunn.livejournal.com
No, that does make sense! But these notifications are not just for visitors, they are for attempted attacks - ie, some software tried to guess a password, or submit a form with code in the submission, or access a location that would only exist if I was using some gadget that has a known vulnerability. Usually they do it repeatedly and the speed of resubmission is one way you can tell it can't be human.

So I don't think it's just people out there are using Tor to look at my websites, although probably they are, and some of them definitely have international audiences anyway. It was specifically the pattern among attacks that caught my eye.

Date: 2017-01-04 11:28 am (UTC)
From: [identity profile] kas2umi.livejournal.com
Oooh, I understand now. Thanks for the clarification! Dunno what more advice to give than to be careful if those attacks continue!

Profile

bunn: (Default)
bunn

January 2026

S M T W T F S
     123
45678910
11121314151617
18192021222324
25262728293031

Most Popular Tags

Style Credit

Expand Cut Tags

No cut tags
Page generated Jan. 2nd, 2026 11:48 am
Powered by Dreamwidth Studios