Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Up and Running » Security » Security » Conerning The On Going Denial of Service Attacks Today.
Uniqs:
12006
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
Post a:
Post a:
New Variant Of Intrusive Online Scanner »
« Failed Critical Update/ Windows Update  
page: 1 · 2 · 3

zbestwun2001

join:2005-12-08
Van Nuys, CA
·DSL EXTREME
·Teleblend

Conerning The On Going Denial of Service Attacks Today.

If you see this secondary login page shown during a DDS attack please do not log into it.

It is also bogus website that set off every alarm in my system it could when I tried to see what it was about.

Just wait till the regular page comes back up for your Security safety

Here is what the page looks like, I took a snapshot of it .



Be safe,
zb1

tmpchaos
Requiescat in pace
Premium,Mod
join:2000-04-28
Hoboken, NJ
clubs:

Re: Conerning The On Going Denial of Service Attacks Today.

Moving to /Security... I think here may be other issues involved.

sashwa
Pixie Cat Crunchin' n Foldin'
Premium,Mod
join:2001-01-29
Alcatraz
clubs:

Re: Conerning The On Going Denial of Service Attacks Today.

Thanks, tmp. I blew that move.

shearer
Northern Lights
Premium
join:2002-06-18
Toronto, ON
clubs:

Re: Conerning The On Going Denial of Service Attacks Today.

If 209.122.192.190 is a bogus site, that should mean the DSLR web server has been hacked. AFAIK DSLR has only been DDOSed, not hacked. right?

SnowyOne
Premium
join:2003-04-05
Kailua, HI
·RoadRunner Cable
·Clearwire Wireless


1 edit

Re: Conerning The On Going Denial of Service Attacks Today.

said by shearer See Profile :

If 209.122.192.190 is a bogus site, that should mean the DSLR web server has been hacked. AFAIK DSLR has only been DDOSed, not hacked. right?
You got that right, but to clear up any confusion 209.122123.192.190 is not a bogus site, it's a legit DSLR address

onDvine
Premium
join:2005-01-29
So. CA, USA
clubs:
·Verizon Online DSL


1 edit
I followed that link and logged in.

Guess it's time to change my password. At least I have no tool points to be stolen.

Edit:
said by shearer See Profile :

... DSLR has only been DDOSed, not hacked. right?
I hope not. Then I don't need to change anything. When I logged in I did get access to this site.

La Luna
Surviving Ashraful
Premium
join:2001-07-12
Warwick, NY
clubs:
·Optimum Online
·Vonage


1 edit
said by zbestwun2001 See Profile :

If you see this secondary login page shown during a DDS attack please do not log into it.

It is also bogus website that set off every alarm in my system it could when I tried to see what it was about.

Just wait till the regular page comes back up for your Security safety

Here is what the page looks like, I took a snapshot of it .

Huh?

»Re: ddos

We all saw that page earlier, Justin put it up with the alternative IP. What are these "alarms" of which you speak, and are you sure you don't have some other issues going on?

edit: added question
--
10,880 DEADLY TERROR ATTACKS SINCE 9/11~~TEAM DISCOVERY
Can't feel you anymore, don't need you anymore, don't believe you anymore, I don't need you anymore

JohnQPublic
Premium
join:2002-03-22
Xanadu

said by zbestwun2001 See Profile :

If you see this secondary login page shown during a DDS attack please do not log into it.

It is also bogus website that set off every alarm in my system it could when I tried to see what it was about.
I guess I better get some better alarms. I've been using the IP address all afternoon. I've been posting to it, too.

mike12806
Premium
join:2007-08-28
Milton, MA

Re: Conerning The On Going Denial of Service Attacks Today.

Wait....so was that IP address-login site legit or not? If it was legit, then a Mod definitely needs to delete that first post....

SnowyOne
Premium
join:2003-04-05
Kailua, HI
·RoadRunner Cable
·Clearwire Wireless

Re: Conerning The On Going Denial of Service Attacks Today.

said by mike12806 See Profile :

Wait....so was that IP address-login site legit or not? If it was legit, then a Mod definitely needs to delete that first post....
It's 100% legitimate

Doctor Olds
I Need A Remedy For What's Ailing Me.
Premium,VIP
join:2001-04-19
1970 442 W30
clubs:

Re: Conerning The On Going Denial of Service Attacks Today.

said by SnowyOne See Profile :

It's 100% legitimate
It's 1000% Legit.

It's Too Legit To Quit!©

It's The Real McCoy!©

It's The Real Thing, Coca-Cola!©
--
What’s the point of owning a supercar if you can’t scare yourself stupid from time to time?

La Luna
Surviving Ashraful
Premium
join:2001-07-12
Warwick, NY
clubs:
·Optimum Online
·Vonage


1 edit
said by mike12806 See Profile :

Wait....so was that IP address-login site legit or not? If it was legit, then a Mod definitely needs to delete that first post....
Yes, it's legit, read the link in my thread oops, I mean post!

mike12806
Premium
join:2007-08-28
Milton, MA

Re: Conerning The On Going Denial of Service Attacks Today.

Oh yes! I saw Justin's post this morning anyways...DOH!
Hangetsu

join:2007-12-22
West Chester, PA
So... If the IP address is legit, can we safely say the OP was incorrect, and the page (and link) were safe?

JohnQPublic
Premium
join:2002-03-22
Xanadu

said by JohnQPublic See Profile :

said by zbestwun2001 See Profile :

If you see this secondary login page shown during a DDS attack please do not log into it.

It is also bogus website that set off every alarm in my system it could when I tried to see what it was about.
I guess I better get some better alarms. I've been using the IP address all afternoon. I've been posting to it, too.
I need to get my eyes checked. I see the difference now. The notice I saw this morning gave the IP address 209.123.192.190.

Obviously whoever made the announcement later made a typo. I cannot connect to the IP address the OP quoted.

shearer
Northern Lights
Premium
join:2002-06-18
Toronto, ON
clubs:
I agree since the IP is confirmed legit please delete the OP's post and bin this thread.
Otherwise it might give noob users unnecessary scares

cabana
now in peppermint
Assistant
join:2000-07-07
New York, NY

Re: Conerning The On Going Denial of Service Attacks Today.

I believe that ".122" is not correct -- the addy direction was -- 209.123.192.190 -- I think it bears closer look...

La Luna
Surviving Ashraful
Premium
join:2001-07-12
Warwick, NY
clubs:
·Optimum Online
·Vonage


1 edit

Re: Conerning The On Going Denial of Service Attacks Today.

said by cabana See Profile :

I believe that ".122" is not correct -- the addy direction was -- 209.123.192.190 -- I think it bears closer look...
Awww, now you've gone and done it!

If that is incorrect (which is the same as everyone else saw), where (and what) is the correct one that Justin posted about here?:

»Re: ddos

What I saw at 9:30AM:

Thu Apr 10 09:18:25 EDT 2008
============================

Valued users:

unfortunately we have a DDOS (distributed denial of
service attack) currently aimed at our pages, rather
than give you page timeouts and errors I've decided to
show this page so I have some time to work around the
problem (eta uncertain).

Since we recognize you have a login cookie, you
are reading a message pitched at existing users.
Feel free to use a temporary alternate path:

ht tp://209.122.192.190/login

(you will need to login)

I am not sure if we will have to flip this around, so don't
be surprised if it also stops working for a while and
you have to return to www.dslreports.com for more info!

--
10,880 DEADLY TERROR ATTACKS SINCE 9/11~~TEAM DISCOVERY
Can't feel you anymore, don't need you anymore, don't believe you anymore, I don't need you anymore

mike12806
Premium
join:2007-08-28
Milton, MA

1 edit

Re: Conerning The On Going Denial of Service Attacks Today.

i had .123 too.....although is it possible it was being hosted on more than one ip???
SipSizzurp
Fo' Shizzle
Premium
join:2005-12-28
Hilo, HI
·RoadRunner Cable

said by La Luna See Profile :

Awww, now you've gone and done it!
Got us back up a few hours sooner. Stupid rushin basterds obviously bought it. Didn't even bother to check ERIN.
Hangetsu

join:2007-12-22
West Chester, PA

said by shearer See Profile :

I agree since the IP is confirmed legit please delete the OP's post and bin this thread.
Otherwise it might give noob users unnecessary scares
Yeah, it might give us unnecessary scares!

Wait...

zbestwun2001

join:2005-12-08
Van Nuys, CA
·DSL EXTREME
·Teleblend


1 edit
All I know is this, I click on it and it set off Sitehound.

It directed it to www.interracial-comics.com.

I don't know how they did it but that's what I saw.

zb1

whois for that site:

Registrant:
am
Vabaduse
Tartu Tartumaa 20306
EE
Registrar: 000DOM
Domain Name: INTERRACIAL-COMICS.COM
Created on: 30-MAR-04
Expires on: 26-MAR-09
Last Updated on: 05-MAR-07
Administrative Technical Contact:
S Alex ircomix@yahoo.com

mike12806
Premium
join:2007-08-28
Milton, MA

Re: Conerning The On Going Denial of Service Attacks Today.

i'm guessing its also possible Justin made a typo in his very busy day...

cabana
now in peppermint
Assistant
join:2000-07-07
New York, NY

Host:
AT&T Southeast
56k Lookout (Broad..

Re: Conerning The On Going Denial of Service Attacks Today.

said by mike12806 See Profile :

i'm guessing its also possible Justin made a typo in his very busy day...
could be ... I believe there were 6 updates total - 3 on the "shutdown" url -- and then 3 updates "shutdown1" url --

I checked my history though -- I only see my having hit the "123" -- perhaps someone else on IE can check to see if they ever hit "122" ...

SnowyOne
Premium
join:2003-04-05
Kailua, HI
·RoadRunner Cable
·Clearwire Wireless

Re: Conerning The On Going Denial of Service Attacks Today.

said by cabana See Profile :

said by mike12806 See Profile :

i'm guessing its also possible Justin made a typo in his very busy day...
could be ... I believe there were 6 updates total - 3 on the "shutdown" url -- and then 3 updates "shutdown1" url --

I checked my history though -- I only see my having hit the "123" -- perhaps someone else on IE can check to see if they ever hit "122" ...
I added to the confusion by using the IP in the original screenshot. It's been corrected to reflect the correct IP

sashwa
Pixie Cat Crunchin' n Foldin'
Premium,Mod
join:2001-01-29
Alcatraz
clubs:
·Comcast
·Alameda Power & Te..

Host:
Broadband Modem (H..
MSN
DSL Extreme
Windstream
Southeast Asian Br..
I just checked my IE history, cabana. I used the "123" when I got in this morning around 7 am PDT. When I try the "122" page I get "Internet Explorer cannot display the page".
--
TH ~ NE ~ EPN ~ NC ~ TD

justin
Australian
join:1999-05-28
Brooklyn, NY

Host:
IPv6
Business Connectiv..
Home/Office setup ..
Console/Handheld g..
Console Tech
I don't know about your own config but the "ip site" is also www2.dslreports.com and it is on another port we have. There isn't anything bad on it or anything that would redirect anyone or capture anyones passwords. I'll change it to a redirect back to www.dslreports.com at some point.
Kiwi
Premium
join:2003-05-26
USA
·Comcast
·Aristotle Internet

I watched and noted this site did have a DDOS, but no hack was evident.

Amazing, people with too much time on their hands, could be better spent improving the human condition than wasting the energy on a worthless end result. There certainly are some true morons out there.
SUMware
Premium
join:2002-05-21


1 edit
»www.dnsstuff.com/tools/ipall.ch?···.192.190
IP Information - 209.122.192.190
IP address: 209.122.192.190
Reverse DNS: [No reverse DNS entry per master.dns.erols.net.]
Reverse DNS authenticity: [Unknown]
ASN: 6079
ASN Name: RCN-AS
IP range connectivity: 2
Registrar (per ASN): ARIN
Country (per IP registrar): US [United States]
Country Currency: USD [United States Dollars]
Country IP Range: 209.122.0.0 to 209.123.255.255
Country fraud profile: Normal
City (per outside source): Allentown, Pennsylvania
Country (per outside source): US [United States]
Private (internal) IP? No
IP address registrar: whois.arin.net
- - - - - - - - - - - - -
»www.dnsstuff.com/tools/ipall.ch?···.109.175
IP Information - 209.123.109.175
IP address: 209.123.109.175 (DSLR Login Page)
Reverse DNS: www.dslreports.com.
Reverse DNS authenticity: [Unknown]
ASN: 8001
ASN Name: NET-ACCESS-CORP
IP range connectivity: 1
Registrar (per ASN): ARIN
Country (per IP registrar): US [United States]
Country Currency: USD [United States Dollars]
Country IP Range: 209.122.0.0 to 209.123.255.255
Country fraud profile: Normal
City (per outside source): Morris Plains, New Jersey
Country (per outside source): US [United States]
Private (internal) IP? No
IP address registrar: whois.arin.net

swhx7
Premium
join:2006-07-23
Elbonia
Some security software may give an alert simply because there's a link using an IP directly instead of a domain name - a common trick in phishing emails and other scams.
dave
Premium,MVM
join:2000-05-04
not in ohio

1 edit
Damn damn damn damn. I fell for it.

EDITED shortly thereafter.

Damn damn damn damn. I fell for the false-alarm posting!

So my password isn't compromised, right?

cabana
now in peppermint
Assistant
join:2000-07-07
New York, NY

Host:
AT&T Southeast
56k Lookout (Broad..

Re: Conerning The On Going Denial of Service Attacks Today.

said by dave See Profile :

Damn damn damn damn. I fell for it.

EDITED shortly thereafter.

Damn damn damn damn. I fell for the false-alarm posting!

So my password isn't compromised, right?
I think the consensus was that it was a typo that appeared for a short time and was corrected -- no compromises. But in this situation of course -- always good to double check... it is one of the few times that paranoia is good

Name Game
Premium
join:2002-07-07
North Myrtle Beach, SC

I am afraid so dave. But be firm and they will give it back.

said by dave See Profile :

Damn damn damn damn. I fell for it.

EDITED shortly thereafter.

Damn damn damn damn. I fell for the false-alarm posting!

So my password isn't compromised, right?

--
Gladiator Security Forum »www.gladiator-antivirus.com/ Missing Kids »www.missingkids.com/

BeesTea
Network Janitor
Premium,VIP
join:2003-03-08
00000

said by dave See Profile :

So my password isn't compromised, right?
You're fine. I've been using your password for ages and no one has ever guessed it!

=)
--
Overpower, overcome.
dave
Premium,MVM
join:2000-05-04
not in ohio
·Verizon Online DSL
·Verizon FIOS

Re: Conerning The On Going Denial of Service Attacks Today.

If anyone gets upset by anything I posted in the last year or so, it wasn't me that said it. It was BeesTea See Profile.

However, anything you liked was posted by me.

Name Game
Premium
join:2002-07-07
North Myrtle Beach, SC

Re: Conerning The On Going Denial of Service Attacks Today.

I logged into that 209.122.192.190 and got this warning.

La Luna
Surviving Ashraful
Premium
join:2001-07-12
Warwick, NY
clubs:

1 edit
Just checked my history in Fx....I was also logged in with *123*.

However, I changed my PW because everyone got me nervous.
quatrix
Premium
join:2005-02-11
Davie, FL

said by zbestwun2001 See Profile :

If you see this secondary login page shown during a DDS attack please do not log into it.

It is also bogus website that set off every alarm in my system it could when I tried to see what it was about.
Next time just try the common sense alarm.

La Luna
Surviving Ashraful
Premium
join:2001-07-12
Warwick, NY
clubs:

1 edit
Dup post

Name Game
Premium
join:2002-07-07
North Myrtle Beach, SC

Re: Conerning The On Going Denial of Service Attacks Today.

said by La Luna See Profile :

Dup post
See..too much multitasking..you must be eating up all the bandwidth
--
Gladiator Security Forum »www.gladiator-antivirus.com/ Missing Kids »www.missingkids.com/

La Luna
Surviving Ashraful
Premium
join:2001-07-12
Warwick, NY
clubs:
·Optimum Online
·Vonage

Re: Conerning The On Going Denial of Service Attacks Today.

said by Name Game See Profile :

said by La Luna See Profile :

Dup post
See..too much multitasking..you must be eating up all the bandwidth
It's not me. It's the gremlins.

Name Game
Premium
join:2002-07-07
North Myrtle Beach, SC

Re: Conerning The On Going Denial of Service Attacks Today.

Yup..I agree..got a few of those errors myself..dave might be trying to log back on with the wrong switch.
--
Gladiator Security Forum »www.gladiator-antivirus.com/ Missing Kids »www.missingkids.com/

woody7
Premium
join:2000-10-13
Torrance, CA
·EarthLink
·DSL EXTREME

Re: Conerning The On Going Denial of Service Attacks Today.

This looks like my setup, when I was having connection problems they wanted me disconnect my router and connect directly to my computer, yea right.....morons....I was on my way to work, and didn't want to crawl under my desk, great picture, I guess neatness does count...
--
BlooMe

La Luna
Surviving Ashraful
Premium
join:2001-07-12
Warwick, NY
clubs:
·Optimum Online
·Vonage

BeesTea See Profile and dave See Profile.

By the way, could some of you leave now, the site is getting a little sluggish again. TIA.

See 6 replies to this post

La Luna
Surviving Ashraful
Premium
join:2001-07-12
Warwick, NY
clubs:
·Optimum Online
·Vonage

hmmm, anyone else starting to get these?:

The page you requested is currently unavailable due a temporary construction error.
You may press BACK and try again.

If the condition continues, please try later when we have corrected the problem.
Resources (if the problem is isolated):
# site help forum

In the event of an extended outage all dslreports.com urls will temporarily return a system status page that we will update as we can.
--
10,886 DEADLY TERROR ATTACKS SINCE 9/11~~TEAM DISCOVERY
Can't feel you anymore, don't need you anymore, don't believe you anymore, I don't need you anymore
Forums » Up and Running » Security » SecurityNew Variant Of Intrusive Online Scanner »
« Failed Critical Update/ Windows Update  
page: 1 · 2 · 3


Monday, 30-Nov 21:21:36 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10 years online! © 1999-2009 dslreports.com.
page compression OFF
Most commented news this week
· [45] Baltimore To Ban Lazy Cable Installs
· [38] Broadband Killed The Game Console
· [30] Rural Carriers Quickly Embracing Fiber
· [28] AT&T Top Lobbyist Cicconi Has His Feelings Hurt
· [23] Charter Exits Chapter 11
· [19] Midcontinent Socked With Easement Lawsuit
· [3] Monday Morning Links
· [2] Monday Evening Links
Most people now reading
· Is Microsoft Technet ok to use for my family PC's? [Microsoft Help]
· Considering Leaving Vonage, who should I Consider? [VOIP Tech Chat]
· Wind getting a little more aggressive [TekSavvy]
· Windows 7 boot manager editing questions [Microsoft Help]
· Heating - my dad gave me this advice... [Home Repair & Improvement]
· Issues tonight in North TX? [AT&T Southwest]
· Connecting to Google Voice Via SIP [VOIP Tech Chat]
· [Internet] Gaming problem for "Heroes of Newerth" ( New bell Upd [Bell Canada]
· [Future9] New subcriber problem info [VOIP Tech Chat]
· [Newsgroups] Newzleech down? [Filesharing Software]