|
|
 |
 |
 |
 |
register |
bbs |
search |
rss |
faq |
about
|
 |
 |
meet up |
add to del.icio.us |
digg it
|
 |
 |
| Network (in)Security Interesting hacks and cracks. Info on firewalls, TCP/IP, encryption, networks, and security. The ins and outs of the phone system, caller services, how things work, what's illegal and what's not, cellular phones, beepers, telephony legislation, the PUC, ISDN, taps, who's listening, and switches. Talking about phones, hacking systems, technical advice, and such is completely LEGAL in the United States -- it's covered by the First Amendment. What's illegal is conspiracy to commit a crime. So if you say something like "Meet me at 2am so we can crack a can" or "I changed my cell phone's number myself" you are criminally liable. Stating "You can crack a can by doing thus-and-so" or "If you wanted to change a cell phone's number, you could do it like so" is perfectly OK. Posting passwords, calling card numbers, or credit card numbers is forbidden on this network. Posting such info will get you booted off the net. |
 |
|
|
#1
 2002-10-19, 19:36
|
e-ray 
Regular
|
|
|
|
Under attack
Hi people, need help again... My computer is connected to a school/campus network. It's been very "quiet" until recently, but about a week ago I started getting loads of port scans and DNS non-internet lookups, originating from the same IP address from local network. Like 10 port probes at a time etc. So should I fret about it, and/or what could I do about it? Currently running Zone Alarm and Black Ice, and IE security is set on high for both zones. Thanks.
Edit: spelling
[This message has been edited by e-ray (edited 10-19-2002).]
|
|
#2
 2002-10-19, 20:24
|
|
Regular
|
|
somewhere up there
|
|
Re: Under attack
Talk to their administrator first.
|
|
#3
 2002-10-21, 10:25
|
skalez 
Regular
|
|
|
|
Re: Under attack
I've heard things about black ice, for example, it does nothing at all. But you have zone alarm, so you'll be right.
|
|
#4
 2002-10-22, 00:06
|
CDG 
Regular
|
|
|
|
Re: Under attack
Why are you running both firewalls at the same time? I have never seen such a case but they might fuck eachother up by assigning different port permmisons and such, just a suggestion, but get rid of blackice.
You might want to ping him back a few times when he port scans you just to tell the guy you are there. You might want to talk to your systems admin, but this might be one of your friends trying something. Talk to everyone you know in the same local area network and try to get their ip addresses.
I wouldnt worry about this, since theres not much he can really do about you. I would back up my computer to disks just incase this guy gets through and does something evil. Also, virus scan to make sure you werent infected with a virus, or had a trojan installed.
|
|
#5
 2002-10-22, 18:32
|
e-ray 
Regular
|
|
|
|
Re: Under attack
Update: attacks from said address have stopped, yet I started getting EXACTLY the same from another address (in local network, too). WTF??? As for running two firewalls, it was suggested on another forum a while ago. Can't remember the exact circumstances (or even the forum), though, so reconsidering it. Thanks.
[This message has been edited by e-ray (edited 10-22-2002).]
|
|
#6
 2002-10-22, 19:02
|
|
Regular
|
|
somewhere up there
|
|
Re: Under attack
If you have a look at the new address it should be very similar to the first one. That would mean they are in the same local area network and most likely the attacker has just switched computers. Either that or the college has switched addresses for the computers. So in short it ain't over yet.
|
|
#7
 2002-10-22, 23:23
|
maxim420 
Regular
|
|
|
|
Re: Under attack
Hello,
I am new here, but I do deal with network security alot. First of all if you decide to cancel out one firewall, I recommend you do some homework on the one you decide to keep. Though ZoneAlarm is very popular and widely administered, BlackIce is used by several government agancies this is a fact. Second there is software available that can make you invisible as far as IP's go on the internet. This might now help for this occasion if the "Hacker" has already obtained them, but it can help for future reference. One that I am aware of is ANOYMIZER. Im sure there are several more. It might not stop all attacks, but hey every step you take makes another mile for them. Lastly you should make sure your OS is always as updated as possible e.g. Windows Update, Anit-Virus update, etc. I hope this helps.
|
|
#8
 2002-10-23, 01:21
|
CDG 
Regular
|
|
|
|
Re: Under attack
The last user has a good point. You can simply set your computer to absorb all ping requests and not accept any incoming connections. Although this would be a huge disadvantage if you are running some service on your computer.
|
|
#9
 2002-10-25, 22:21
|
Parity_Error 
Regular
|
|
|
|
Re: Under attack
Honestly if you are running Windows and if he is any good he will eventually get in. Black Ice is great software, and I highly recommend it, but here is an alternative.
Leave a hole for him to get in, and create a a directory Accounts_Passwords with a home grown phone book program that appears to store accounts and passwords.
However make the program bite when it is run / installed. You can write something quick and dirty that just overwrites the MBR or whatever.
Parity_Error
|
|
#10
 2002-10-25, 23:07
|
tylerde2006 
Regular
|
|
|
|
Re: Under attack
i wouldnt let him in....but just tell the adminstrater or cops, if you can warn him to stop then do it...but otherwise bust his ass
i dont know shit about security but im shir ur adminastrater does
|
|
#11
 2002-10-28, 08:46
|
e-ray 
Regular
|
|
|
|
Re: Under attack
SHIT! The jerk got in and deleted a couple of pdf's. I'm trying to find out to whom the address belongs... Anyway, a question about Windows: how much difference (security-wise) is there between various Windows versions and which one would be the safest? I simply don't have the time to learn Linux right now. Thanks.
|
|
#12
 2002-10-29, 08:47
|
Jadedfool 
Regular
|
|
|
|
Re: Under attack
get an NT based one, and make sure that you format and do a complete reinstall everytime you've been compromised.
alternately, keep your current version, and be sure to keep up with the service packs after you reinstall...
|
|
#13
 2002-10-31, 19:44
|
timbotimbo 
Regular
|
|
|
|
Re: Under attack
few reasons i dont bother using a personal firewall at all and especially not blackice. http://online.securityfocus.com/bid/4950 http://online.securityfocus.com/bid/4025 http://online.securityfocus.com/bid/1389 http://online.securityfocus.com/archive/1/275710 http://online.securityfocus.com/archive/1/255134 this one i found particularly amusing regarding the "smart technology" http://online.securityfocus.com/archive/1/294746
|
|
 |
 |
To the best of our knowledge, the text on this page may be freely reproduced and distributed.

totse.com certificate signatures
|
 |
 |
About | Community | Bad Ideas | Drugs | Ego | Erotica | Fringe | Society | Technology
|
 |
 |
 |
 |
|
|