1. Welcome! Please take a few seconds to create your free account to post threads, make some friends, remove a few ads while surfing and much more. ClutchFans has been bringing fans together to talk Houston Sports since 1996. Join us!

Attacked by hackers !

Discussion in 'BBS Hangout' started by DaDakota, May 8, 2003.

Tags:
  1. DaDakota

    DaDakota Balance wins
    Supporting Member

    Joined:
    Mar 14, 1999
    Messages:
    129,602
    Likes Received:
    40,169
    Well,

    We got attacked at our company today, we have discovered that someone was using our web site to launch attacks at others causing some DNS's to ban our address.

    We have cleared out the rascal, and had to change our IP address.

    We have updated our DNS account and are awaiting the update to hit all the internet.

    Kids...sheesh !!

    :)

    DD
     
  2. A-Train

    A-Train Member

    Joined:
    Jan 1, 2000
    Messages:
    15,997
    Likes Received:
    39
    Hmmm...I was wondering why I got a pic of two nekkid chicks tounging each other when I cliked on the link to your bio...not that I'm complaining, or anything...
     
  3. coma

    coma Member

    Joined:
    Jul 17, 2001
    Messages:
    3,347
    Likes Received:
    10
    Have you found out how they got in and patched up that hole?
     
  4. DaDakota

    DaDakota Balance wins
    Supporting Member

    Joined:
    Mar 14, 1999
    Messages:
    129,602
    Likes Received:
    40,169
    Coma,

    Yep.

    DD
     
  5. coma

    coma Member

    Joined:
    Jul 17, 2001
    Messages:
    3,347
    Likes Received:
    10
    Damn! I was going to offer you my services at a cc.net discount. :D
     
  6. DaDakota

    DaDakota Balance wins
    Supporting Member

    Joined:
    Mar 14, 1999
    Messages:
    129,602
    Likes Received:
    40,169
    Could you guys try to access my companies web server? We need to see if DNS has updated.



    Click here

    Thanks,

    DD
     
  7. weakfromtoday

    weakfromtoday Member
    Supporting Member

    Joined:
    Dec 5, 2002
    Messages:
    3,681
    Likes Received:
    2,306
    didn't load for me DD, i tried 3 times.

    Brian
     
  8. Deckard

    Deckard Blade Runner
    Supporting Member

    Joined:
    Mar 28, 2002
    Messages:
    57,814
    Likes Received:
    41,261
    Same here. No workie. :(
     
  9. mr_oily

    mr_oily Member

    Joined:
    Dec 22, 2000
    Messages:
    2,183
    Likes Received:
    1
    Me neither, I tried a few times too.


    oh yeah, glad I could offer my technical assistance!
     
  10. DaDakota

    DaDakota Balance wins
    Supporting Member

    Joined:
    Mar 14, 1999
    Messages:
    129,602
    Likes Received:
    40,169
    Try again later please....I am trying to see how long it takes before people get routed properly.

    DD
     
  11. coma

    coma Member

    Joined:
    Jul 17, 2001
    Messages:
    3,347
    Likes Received:
    10
    DD,

    DNS changes usually take 8 hrs to propagate to all root servers.
     
  12. DaDakota

    DaDakota Balance wins
    Supporting Member

    Joined:
    Mar 14, 1999
    Messages:
    129,602
    Likes Received:
    40,169
    Curses....8 hours....man, I will have a lot of mail bouncing than.

    DD
     
  13. Rockets2K

    Rockets2K Clutch Crew

    Joined:
    Mar 22, 2000
    Messages:
    18,050
    Likes Received:
    1,271
    still no dice...unfortunate.

    just curious, as a network security type of guy, what attack did they use?
     
  14. SmeggySmeg

    SmeggySmeg Member

    Joined:
    Feb 23, 1999
    Messages:
    14,887
    Likes Received:
    123
    still nothing Dak
     
  15. RocketsPimp

    RocketsPimp Member

    Joined:
    Feb 15, 1999
    Messages:
    13,812
    Likes Received:
    194
  16. DaDakota

    DaDakota Balance wins
    Supporting Member

    Joined:
    Mar 14, 1999
    Messages:
    129,602
    Likes Received:
    40,169
    They uploaded a Mirc file hidden on our directory and were not attacking us per se but using our address to launch attacks. They were getting in through our FTP site. We had an old FTP account that we left open as some stuff was needed by the General public....not anymore.

    What alerted us was that our access to various BBS servers was blocked, and we wondered why..took a look at our server and noticed a bunch of weird apps running and they were hidden.

    So we did a scan some tracing and discovered the guy in Denmark hacking in and using our bandwidth...we shut him down and changed our IP to another one to avoid the blocks that have been put in place.

    A very long day to say the least.

    DD
     
  17. Rockets2K

    Rockets2K Clutch Crew

    Joined:
    Mar 22, 2000
    Messages:
    18,050
    Likes Received:
    1,271
    yall allowed upload rights to an (what i assume was) an anonymous ftp account? or did they manage to get past the deny write access rights?

    I ask at this point because of my open anonymous ftp account on my server. I havent checked it lately, but I imagine I need to just to make sure that no one has used a similar method on my ftp server.
     
  18. Sonny

    Sonny Member

    Joined:
    Mar 20, 2001
    Messages:
    5,436
    Likes Received:
    8
    It worked for me DaDa.
     
  19. DaDakota

    DaDakota Balance wins
    Supporting Member

    Joined:
    Mar 14, 1999
    Messages:
    129,602
    Likes Received:
    40,169
    Not to mention that the guy was storing stolen passwords on our server. We have tons of .wpl files that are passwords for Win 98 machines.

    We moved those and shut him down....hopefully he is done with our site...but we will be watching much closer now.

    Also we are switching to a more secure router...we have a linksys one but that is not sufficient anymore.

    Oh well.

    DD
     
  20. Major

    Major Member

    Joined:
    Jun 28, 1999
    Messages:
    41,727
    Likes Received:
    16,321
    Curses....8 hours....man, I will have a lot of mail bouncing than.


    Your mail won't bounce... The other server will try for about 2 days before returning it if it can't get a collection. It'll all slowly flow in.
     

Share This Page