Author Archives: dontai
Hexo from the Beginning
Hexo is a tool that allows the writer to create a web site using markdown. The web site is made of flat files, without a database. This type of web site is extremely simple, efficient, fast and hackproof. Check out my Gitlab test page.
Node.js PPA
You need to install node.js, a software package that uses javascript. For me on Ubuntu 16.04 it was painful, because the install scripts from Nodejs.org did not work, and installed a back-level version, 4.2.6, vs the most current 6.9.5. Dave helped me install.
Brute Force Login Attack, 2017 Feb 14
Happy Valentine’s Day, and someone loves me out there on the Internet, because they used a botnet to try to break into my site. You are very welcome, whomever you are, but I am trying to find out who is my secret admirer.
There are 12 IPs involved. The each try 2 times.
User Agent: Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/53.0.2785.89 Safari/537.36
Brute Force Login Attack: 2017 Feb 11
Yet another brute force attack that I would like to document. The first two, from China and India, are bad dudes.
UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:40.0) Gecko/20100101 Firefox/40.0
42.62.11.58 s Forest Eternal Com Cn, Risk 10/10, spam, bots malware (200): Spam Zero-Day, Doc.Dropper.Agent-5664104-0
117.245.8.122 s Wimax Bharat Sanchar Nigam BSNL In, Risk 7.1/10, spam, bots, malware: Spam Zero-Day, Doc.Dropper.Agent-5664104-0
213.119.94.181 s Telenet Operaties Belgium, Risk 8.6/10, spam, bots, scanning IPs
They are banned, never to return with these IPs
Parking Ticket, City of Toronto, Canada

Toronto parking ticket: Code No. 406, Park – vehicle without valid Ontario number plate properly displayed, Toronto, Canada
Freezing Rain, 2017 Feb 07, Toronto, Canada

Freezing rain in Toronto, Canada, 2017 Feb 07, 13:02. Photo by Don Tai
Pan China Brute Force Login Attack
It is always warming to see the two Chinas, the PRC and Taiwan, getting along. Today they ganged up and tried to break into my site.
60.217.64.210 s China Unicom Shandong, level 10 risk, malware Spam Zero-Day
60.248.0.230 s Hinet Chunghwa Tel Taiwan, known for bots and infected zombie computers
183.167.228.134 s Chinanet Anhui, level 10 risk, malware Spam Zero-Day
218.21.43.238 s Dou shi-BAR Yin chuan Ningxia, level 10 risk, malware Spam Zero-Day
The last one, from Ningxia, looks surprisingly small as compared to the usually huge number of IP addresses for Chinanet or China Unicom, but they are part of Chinanet Ningxia, which is large.
Generating htpasswords through SSH
If you are on Ubuntu and do not want to install htpasswd, SSH into your server
htpasswd -n id
You will be prompted, twice, for a password. The key will be generated on screen
-n: generate key on screen
id: chosen id
password: chosen pw
code will be generated, add this to password file
Notes:
password file not available from FTP
Brute Force Attacks
htpasswd
Bell Fibe 50 Home Installation: Toronto, Canada

Bell Fibe 50, wired connection to the Home Hub 3000, gave me 52mbps download and 52mbps upload using the the Ookla speed test. Toronto, Canada
