Insert BS here A place to discuss anything you want!

Hackers Are Stupid

Thread Tools
 
Search this Thread
 
Old Mar 15, 2003 | 04:21 PM
  #11  
phinsup's Avatar
Administrator
 
Joined: Jul 2001
Posts: 24,416
From: Stuart, FL
Default

It all depends, what are they trying to do? Gain access to the server or is someone just emailing you virus's
Old Mar 15, 2003 | 04:25 PM
  #12  
JT-Imports's Avatar
Thread Starter
Senior Member
 
Joined: Sep 2002
Posts: 2,342
Default

Both last night...



I was getting a ***** load of viruses and my server told me they were trying

to get it.



I was able to track them and get their name, does their name have any value? I also have their computer number and where in the world they are, or is this info bunk?
Old Mar 15, 2003 | 04:29 PM
  #13  
75 Repu's Avatar
Senior Member
 
Joined: Aug 2002
Posts: 4,848
From: Mike is a Liar!
Default

Old Mar 15, 2003 | 04:33 PM
  #14  
JT-Imports's Avatar
Thread Starter
Senior Member
 
Joined: Sep 2002
Posts: 2,342
Default

Its all good, I just keep on
Old Mar 15, 2003 | 04:38 PM
  #15  
pengaru's Avatar
Senior Member
 
Joined: Apr 2002
Posts: 2,930
From: IL
Default

it depends on what it is they are doing, if you have the source ip address of the connections being used for whatever you suspect is some form of attack... they can very likely be useless. Often people will use remote systems to attack others, so you might just have the source address of another compromised host... which would require you to contact the administrator of that host and they would have to find out where those connections are coming form and so on until the true origin is found.
Old Mar 15, 2003 | 04:42 PM
  #16  
JT-Imports's Avatar
Thread Starter
Senior Member
 
Joined: Sep 2002
Posts: 2,342
Default

Thanks Pengaru---Sounds like I should just keep my guns up.. Thanks though
Old Mar 15, 2003 | 04:52 PM
  #17  
phinsup's Avatar
Administrator
 
Joined: Jul 2001
Posts: 24,416
From: Stuart, FL
Default

Originally Posted by JT-Imports' date='Mar 15 2003, 02:25 PM
Both last night...



I was getting a ***** load of viruses and my server told me they were trying

to get it.



I was able to track them and get their name, does their name have any value? I also have their computer number and where in the world they are, or is this info bunk?
Odds are it's junk and they are just using a proxy or something to move around.
Old Mar 15, 2003 | 06:38 PM
  #18  
works2r's Avatar
Senior Member
 
Joined: Mar 2002
Posts: 255
Default

just put in a reverse proxy, and you'll get rid of most of the problems.. actually.

if you're running microsuck, swap to a unix based system and some unix sec guides, probably alot easier.

no patches on a regular basis, etc.



works for me.
Old Mar 15, 2003 | 06:42 PM
  #19  
Joe Flo's Avatar
Senior Member
 
Joined: Dec 2002
Posts: 1,142
From: Houston Texas
Default

EVERYONE- Do the hackers ever give up? The virus are just coming in 4 and 5 at a time, so I was just curious.


Nope....I have met two in my life. Really wierd people. They see it as a challenge and they wont stop until they do what they wanted to. It sad that people would want to do that. Both of the guys I knew used it for good and went out and got real jobs that pay them really well now.
Old Mar 15, 2003 | 07:22 PM
  #20  
pengaru's Avatar
Senior Member
 
Joined: Apr 2002
Posts: 2,930
From: IL
Default

Originally Posted by phinsup' date='Mar 15 2003, 10:52 PM
[quote name='JT-Imports' date='Mar 15 2003, 02:25 PM'] Both last night...



I was getting a ***** load of viruses and my server told me they were trying

to get it.



I was able to track them and get their name, does their name have any value? I also have their computer number and where in the world they are, or is this info bunk?
Odds are it's junk and they are just using a proxy or something to move around. [/quote]

open proxy servers **** me off, so many of our servers get flooded by distributed attacks based on open proxy lists.



the other day I blocked more than 1000 addresses from a server that were hosts running open http proxy software getting used in an attack.



most of the addresses were on cable, morons with NT boxes probably not even aware they are running a public proxy.



All times are GMT -5. The time now is 02:35 AM.