Omega Owners Forum

Please login or register.

Login with username, password and session length
Advanced search  

News:

Welcome to OOF

Pages: [1] 2 3  All   Go Down

Author Topic: Hackers...  (Read 3514 times)

0 Members and 1 Guest are viewing this topic.

Ian_D

  • Omega Baron
  • *****
  • Offline Offline
  • Gender: Male
  • York
  • Posts: 2432
    • View Profile
Hackers...
« on: 28 July 2009, 19:47:09 »

Currently got some idiot attempting to hack into my server again (as usual, over FTP)...

He’s been at it for 24 hrs now doing a brute force attack (seems to be about 3-4 attacks per second).

What do they get out of it?

Anyway, I've looked into his IP and found out he’s from China, and have emailed his ISP. Wonder if they will do anything about it??  ::) I bet not.  :-/

Anyone else have any servers? How often do you get attempted hackings?

Wonder how often OOF's servers get attacked too   :-?
Logged
[size=12]
LMF are utter rubbish - dont buy steering idlers from them! You've been warned![/size]

Ziad

  • Omega Knight
  • *****
  • Offline Offline
  • Gender: Male
  • Bahrain
  • Posts: 1030
  • They say money talks,but all mine says is Goodbye!
    • View Profile
Re: Hackers...
« Reply #1 on: 28 July 2009, 20:04:21 »

Bloody hackers!  >:( they should be electrocuted!   ::)
Logged

Lizzie_Zoom

  • Guest
Re: Hackers...
« Reply #2 on: 28 July 2009, 20:17:29 »

Can't you send a crippling virus out into the hackers system? :-/

If that seems like a stupid question, sorry, it is because I know little about computer systems! ::) ::) ::)

To me it just appears to be a logical thing to do; attack is the best form of defence!! :D :D :D ;) ;)
Logged

Mr Skrunts

  • Get A Life!!
  • *****
  • Offline Offline
  • Gender: Male
  • Skruntie Land.
  • Posts: 25695
  • 3.O Elite Saloon with all the toys,
    • 2003 CD 2.2 Auto
    • View Profile
Re: Hackers...
« Reply #3 on: 28 July 2009, 20:20:19 »

When I started to move home in june my mates phone picked up there were 3 local wireless connections, 2 x BT and something else.  1 of the BT accounts was insecure.

When I met my new neighber, she mentioned she had a full BT vision and interenet package, so out of curriosity I mentioned the insecure BT service, for which I got told straight her's was secure yada yada yads........    Ok so I left it at that.


last week she came and warned me that hers and her sons computers had been hacked and somehow damaged, plus her mobile had been hacked.

Sadly I wasnt interested and I feel she had been warned she may have had an open connection and that she was addamant she was 100% safe.


and no, I had nothing to do with it, I wouldnt even know where to start.
« Last Edit: 28 July 2009, 20:33:09 by skruntie »
Logged
Ask yourself :  " WHY do I believe in what I believe?"

Remember that my opinions expressed here are not representative of the opinions of other members on the OOF Forum.

cem_devecioglu

  • Guest
Re: Hackers...
« Reply #4 on: 28 July 2009, 20:30:36 »

they are using some programs which makes automatic password trials..

if possible, stop ftp service..

and some sql drivers are also vulnerable to external attacks ..
« Last Edit: 28 July 2009, 20:31:15 by cem_devecioglu »
Logged

Jimbob

  • Global Moderator
  • *****
  • Offline Offline
  • Gender: Male
  • Chester / Flintshire
  • Posts: 24530
  • I like traffic lights, but only when they're green
    • E250 Est / Golf GTI
    • View Profile
Re: Hackers...
« Reply #5 on: 28 July 2009, 20:32:58 »

I get an attack on my ftp every day or 2, 15 or so invalid logins and the ip is blacklisted and doesnt even allow a logon attempt  :y

tunnie

  • Get A Life!!
  • *****
  • Offline Offline
  • Gender: Male
  • Surrey
  • Posts: 37593
    • Zafira Tourer & BMW 435i
    • View Profile
Re: Hackers...
« Reply #6 on: 28 July 2009, 20:47:48 »

Quote
Currently got some idiot attempting to hack into my server again (as usual, over FTP)...

He’s been at it for 24 hrs now doing a brute force attack (seems to be about 3-4 attacks per second).

What do they get out of it?

Anyway, I've looked into his IP and found out he’s from China, and have emailed his ISP. Wonder if they will do anything about it??  ::) I bet not.  :-/

Anyone else have any servers? How often do you get attempted hackings?

Wonder how often OOF's servers get attacked too   :-?

Not sure you need the 's'  ::)
Logged

nick v6

  • Omega Baron
  • *****
  • Offline Offline
  • Gender: Male
  • walsall / west midlands
  • Posts: 4584
    • View Profile
Re: Hackers...
« Reply #7 on: 28 July 2009, 21:25:08 »

Quote
Currently got some idiot attempting to hack into my server again (as usual, over FTP)...

He’s been at it for 24 hrs now doing a brute force attack (seems to be about 3-4 attacks per second).

What do they get out of it?

Anyway, I've looked into his IP and found out he’s from China, and have emailed his ISP. Wonder if they will do anything about it??  ::) I bet not.  :-/

Anyone else have any servers? How often do you get attempted hackings?

Wonder how often OOF's servers get attacked too   :-?

pm me his ip ;) :y
Logged
just need to tax the tank now:)

TheBoy

  • Administrator
  • *****
  • Offline Offline
  • Gender: Male
  • Brackley, Northants
  • Posts: 107163
  • I Like Lockdown
    • Whatever Starts
    • View Profile
Re: Hackers...
« Reply #8 on: 28 July 2009, 21:42:34 »

Yeah, I have loads of hack attempts across all servers here. Mostly stopped at firewall, though obviously some services I have to allow through.

Some of my websites I've set up to email me when a SQL Injection hack is attempted - go through phases of getting several hundred attempts per day, yet other days just a handful.


Generally, in my experience, if you open it up for anonymous, but block writes, and have nothing in there, they won't try brute force.


Set up a pair of new servers for work, on a previously unused subnet. The second the ACLs were lifted from the edge network, non-stop constant probing started.


Thats just part of having a server on the net.
Logged
Grumpy old man

Ian_D

  • Omega Baron
  • *****
  • Offline Offline
  • Gender: Male
  • York
  • Posts: 2432
    • View Profile
Re: Hackers...
« Reply #9 on: 28 July 2009, 22:14:50 »

I cant see them getting in over FTP really, my password is 11 characters long, contains both letters and numbers, and it also contains capital letters! So good look to them! (Famous last words  ;D)

Just checked servers log file, and its still growing!  ;D

Heres a snippet of the log file: (Servers clock is correct, but the log file must be GMT as its 1 hr behind)

#Software: Microsoft Internet Information Services 6.0
#Version: 1.0
#Date: 2009-07-27 19:17:19
#Fields: time c-ip cs-method cs-uri-stem sc-status sc-win32-status
19:17:19 220.128.178.146 [9]USER Administrator 331 0
19:17:19 220.128.178.146 [9]PASS - 530 1326
19:17:19 220.128.178.146 [9]USER Administrator 331 0
19:17:20 220.128.178.146 [9]PASS - 530 1326
19:17:20 220.128.178.146 [9]USER Administrator 331 0
19:17:20 220.128.178.146 [9]PASS - 530 1326
19:17:21 220.128.178.146 [9]USER Administrator 331 0
19:17:21 220.128.178.146 [9]PASS - 530 1326
19:17:21 220.128.178.146 [9]USER Administrator 331 0
19:17:22 220.128.178.146 [9]PASS - 530 1326
19:17:24 220.128.178.146 [9]USER Administrator 331 0
19:17:24 220.128.178.146 [9]PASS - 530 1326

skip forward 26 hours......

21:18:03 220.128.178.146 [18]USER Amanda 331 0
21:18:04 220.128.178.146 [18]PASS - 530 1326
21:18:04 220.128.178.146 [18]USER Amanda 331 0
21:18:04 220.128.178.146 [18]PASS - 530 1326
21:18:05 220.128.178.146 [18]USER Amanda 331 0
21:18:05 220.128.178.146 [18]PASS - 530 1326
21:18:05 220.128.178.146 [18]USER Amanda 331 0
21:18:06 220.128.178.146 [18]PASS - 530 1326
21:18:06 220.128.178.146 [18]USER Amanda 331 0
21:18:06 220.128.178.146 [18]PASS - 530 1326
21:18:07 220.128.178.146 [18]USER Amanda 331 0
21:18:07 220.128.178.146 [18]PASS - 530 1326
Logged
[size=12]
LMF are utter rubbish - dont buy steering idlers from them! You've been warned![/size]

djm1964

  • Senior Member
  • ****
  • Offline Offline
  • Gender: Male
  • Herts
  • Posts: 706
  • The Boys Are Back In Town
    • View Profile
Re: Hackers...
« Reply #10 on: 28 July 2009, 22:18:20 »

Quote
I get an attack on my ftp every day or 2, 15 or so invalid logins and the ip is blacklisted and doesnt even allow a logon attempt  :y
whats an ftp pls ?
Logged
Thin Lizzy are still the the best Rock band ever ! R.I.P Phil Lynott never forgotten .

Ian_D

  • Omega Baron
  • *****
  • Offline Offline
  • Gender: Male
  • York
  • Posts: 2432
    • View Profile
Re: Hackers...
« Reply #11 on: 28 July 2009, 22:19:36 »

Quote
they are using some programs which makes automatic password trials..

if possible, stop ftp service..

and some sql drivers are also vulnerable to external attacks ..

Yes cem, its definitely a program which is doing the attack.

It started with the 'Administrator' Account, and it now looks like its onto a username dictionary list as it keeps changing every hour or so  ;D

I guess I could disable FTP, but I will just leave it for now, after all, its wasting their time!  ;D

SQL Injection is something I've read a little bit about, but I was under the impression that them bugs have been fixed now?
Logged
[size=12]
LMF are utter rubbish - dont buy steering idlers from them! You've been warned![/size]

Ian_D

  • Omega Baron
  • *****
  • Offline Offline
  • Gender: Male
  • York
  • Posts: 2432
    • View Profile
Re: Hackers...
« Reply #12 on: 28 July 2009, 22:21:24 »

Quote
Quote
I get an attack on my ftp every day or 2, 15 or so invalid logins and the ip is blacklisted and doesnt even allow a logon attempt  :y
whats an ftp pls ?
File Transfer Protocol....

In simple terms, its a means of moving files from both to and from one machine to another over a network such as the internet.
Logged
[size=12]
LMF are utter rubbish - dont buy steering idlers from them! You've been warned![/size]

TheBoy

  • Administrator
  • *****
  • Offline Offline
  • Gender: Male
  • Brackley, Northants
  • Posts: 107163
  • I Like Lockdown
    • Whatever Starts
    • View Profile
Re: Hackers...
« Reply #13 on: 28 July 2009, 22:23:48 »

Quote
Quote
they are using some programs which makes automatic password trials..

if possible, stop ftp service..

and some sql drivers are also vulnerable to external attacks ..

Yes cem, its definitely a program which is doing the attack.

It started with the 'Administrator' Account, and it now looks like its onto a username dictionary list as it keeps changing every hour or so  ;D

I guess I could disable FTP, but I will just leave it for now, after all, its wasting their time!  ;D

SQL Injection is something I've read a little bit about, but I was under the impression that them bugs have been fixed now?
Firstly, ensure your Administrator account is not called Administrator - too easy target!

Shut FTP if not using - they will eventually crack the password (unless you change regularly).  Also, its eating your bandwidth.

SQL Injection is not an MS bug, its a website developer bug, so no patches as such from MS (website developer may or may not issue a patch)
Logged
Grumpy old man

TheBoy

  • Administrator
  • *****
  • Offline Offline
  • Gender: Male
  • Brackley, Northants
  • Posts: 107163
  • I Like Lockdown
    • Whatever Starts
    • View Profile
Re: Hackers...
« Reply #14 on: 28 July 2009, 22:24:24 »

Quote
Quote
Quote
I get an attack on my ftp every day or 2, 15 or so invalid logins and the ip is blacklisted and doesnt even allow a logon attempt  :y
whats an ftp pls ?
File Transfer Protocol....

In simple terms, its a means of moving files from both to and from one machine to another over a network such as the internet.
And insecure, and generally considered 'old hat' now.
Logged
Grumpy old man
Pages: [1] 2 3  All   Go Up
 

Page created in 0.013 seconds with 17 queries.