About
Community
Bad Ideas
Drugs
Ego
Erotica
Fringe
Society
Technology
register | bbs | search | rss | faq | about
meet up | add to del.icio.us | digg it
Go Back   Community > Technology > Network (in)Security
FAQ Members List Calendar Search Today's Posts Mark Forums Read

Network (in)Security Interesting hacks and cracks. Info on firewalls, TCP/IP, encryption, networks, and security. The ins and outs of the phone system, caller services, how things work, what's illegal and what's not, cellular phones, beepers, telephony legislation, the PUC, ISDN, taps, who's listening, and switches. Talking about phones, hacking systems, technical advice, and such is completely LEGAL in the United States -- it's covered by the First Amendment. What's illegal is conspiracy to commit a crime. So if you say something like "Meet me at 2am so we can crack a can" or "I changed my cell phone's number myself" you are criminally liable. Stating "You can crack a can by doing thus-and-so" or "If you wanted to change a cell phone's number, you could do it like so" is perfectly OK. Posting passwords, calling card numbers, or credit card numbers is forbidden on this network. Posting such info will get you booted off the net.

Reply
 
Thread Tools Display Modes
 #1 
Old 2002-09-18, 01:05
Dr Spock Dr Spock is offline
Regular
 
Default Suspicious

For the last 2 days ive been getting alerts like this one on zonealarm:

FWIN,2002/09/17,20:00:11 -6:00 GMT,66.177.176.226:2736,12.253.84.2:6346,TCP (flags:S)

(thats from the log)

It says TCP port 6346, which I know is the gnuttel port, but I havent run limewire in 2 days, and the port its coming from is running up the spectrum, trying just about everything. Any ideas whats up?
 #2 
Old 2002-09-18, 08:52
cense cense is offline
Regular
 
Default Re: Suspicious

Well, a can tell you a few things, but probably none of which are useful to you.

- TCP - means it was/is a Transmission Control Protocol packet
- (flags:S) - means it was/is a SYN (Synchronize sequence number) packet.
- FWIN - im not sure what this means. i would assume WIN stands for window but i dont know what the "F" is all about.

quote:
the port its coming from is running up the spectrum
That is very perculiar transmission behavior.

Overall, im not quite sure what is going on. Do you get this from the same IP every time or is it always different IPs? Any more info might help.
 #3 
Old 2002-09-18, 11:28
Moderator
 
Default Re: Suspicious

duh, if you�ve got a static IP or gnu runs at startup, I asume someone hasn�t seen that you went offline, his gnu is still trying to download the files you�ve offered. As long as it�s not FWOUT and no ports are open it�s not dangerous.
 #4 
Old 2002-10-06, 12:44
SchwipSchwap SchwipSchwap is offline
Regular
 
Default Re: Suspicious

Hi!
I have a similar problem.

As soon as i start my internet connection
my Firewall(Zonealarm) gets TCP (flags:s) to all
kind of ports from 80 to filecharing
from different sources and regular udp connections to port 137.

I have a dynamic IP, but its so regular that it cant be connection from someone who had my IP befor me.

When i start filecharing i get also (flags:ap) and (flags:af) (even incoming from internal-sources 194.0... and my same networkname) ,when i change
my filechanging-port and restart my connection i get port-scans.

I know somebody is trying to hacking me.

How can i figure out who is doing this,
because i can only block the person with the IPs from the portscans?
 #5 
Old 2002-10-06, 17:15
Chunkmiester Chunkmiester is offline
Regular
 
Default Re: Suspicious

Look at it like this SchwipSchwap-
Your ip changes everytime you connect to the net (in your case anyway)
Still- you have continual high rated alerts on many different ports
Now then- how would someone be able to attack you as soon as you connect without harvesting your ip?
They would have to have some wat of identifing you as there target everytime you are online.

This to me spells out TROJAN in 50 foot high neon letters

There are numerous online tests to see if you have trojans- they are not hard to find at all.

Chunkmiester
Oh- and one afterthought- its possible that its some sort of adware doing the deed- get adaware from www.lavasoftusa.com and clean the adaware off your comp (it does it for you)
 #6 
Old 2002-10-06, 17:23
Chunkmiester Chunkmiester is offline
Regular
 
Default Re: Suspicious

Oh and to track them down get the source ip from zone alarm's log and whois it. I am pretty sure you are a newbie so go here: http://soz.web.govital.net/whois.htm
and put the ip into the correct box- for europe you need the Ripe server, for us you need the Arin server and for asia you need the Apnic server. The results should show you what isp the attacker is on and an email or contact number for the isp's abuse of service department. call them up or email them and send a copy of Zone Alarm's log and this person should soon be blacklisted for internet access

Chunkmiester
Beware of proxies though- look for the Source Ip number in zonealarm and not the destination or from ip number.
 
To the best of our knowledge, the text on this page may be freely reproduced and distributed.
 

totse.com certificate signatures
 
 
About | Community | Bad Ideas | Drugs | Ego | Erotica | Fringe | Society | Technology
Hot Topics