republican-creole
Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Up and Running » Security » Security » Hacker attaicking?
Search Topic:
Uniqs:
226
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
Post a:
Post a:
how do you remove default C$ share? »
« GWF's, useless logs, and abuse desks.  
AuthorAll Replies


hysteriakr
Dancing Phoenix

join:2002-11-07
Little Ferry, NJ
clubs:

Hacker attaicking?

Click for full size
I had constant freeze on my computer so I checked if it was outside attack. I looked at Incoming Log of BEFSR41 V2 and it has tons of 65.200.216.156 with different ports of it even when im not doing anything. Loot at screenshot.
--
-*~(--)~*--*~(--)~*--*~(--)~*--*~(--)~*--*~(--)~*--*~(--)~*--*~(--)~*--*~(--)~*--*~(--)~*- -*~(--)~*--*~(--)~*-

LowWaterMark
Premium
join:2002-05-16
Wallingford, CT

Are there more fields available in that log? Source port, protocol, flags and most especially, a timestamp would be very useful here. Without a time on each record we can't tell if those came in one every 10 minutes or one every 1/100 of a second. It makes a difference.
--
Use the most powerful combo Firewall/AV/AT package available - "Common Sense" - It can be upgraded daily!


Zupe
Premium,MVM
join:2001-11-29
New York, NY
clubs:
reply to hysteriakr
That IP seems to resolve to the site MP3.com, have you visited that site, listened to streaming music, etc.?
--
Pinky: I think so, Brain, but "Snowball for Windows"?


Interceptor
We want... A Shrubbery
Premium
join:2000-07-24
Birmingham, AL


reply to hysteriakr
Could you have recently been downloading music or at least connected to mp3.com? The IP resolves to that, and the destination ports are in the range that might be typically seen in a reply.

Mike

Darn it! Beat to the draw again!
[text was edited by author 2003-08-08 18:49:08]


hysteriakr
Dancing Phoenix

join:2002-11-07
Little Ferry, NJ
clubs:


I was listening from Mp3.com then exited it and it was keep showing 3 per 10 seconds in average. But why would they send data even after it was disconnected for 10 minutes after the disconnection?

its sending data for 30 minutes now :P Even the computer is rebooted.
--
-*~(--)~*--*~(--)~*--*~(--)~*--*~(--)~*--*~(--)~*--*~(--)~*--*~(--)~*--*~(--)~*--*~(--)~*- -*~(--)~*--*~(--)~*-

[text was edited by author 2003-08-08 20:18:32]


jdong
Eat A Beaver, Save A Tree.
Premium
join:2002-07-09
Rochester, MI
clubs:


said by hysteriakr See Profile:
I was listening from Mp3.com then exited it and it was keep showing 3 per 10 seconds in average. But why would they send data even after it was disconnected for 10 minutes after the disconnection?

its sending data for 30 minutes now :P Even the computer is rebooted.
--
-*~(--)~*--*~(--)~*--*~(--)~*--*~(--)~*--*~(--)~*--*~(--)~*--*~(--)~*--*~(--)~*--*~(--)~*- -*~(--)~*--*~(--)~*-

[text was edited by author 2003-08-08 20:18:32]

The server might not know that you've disconnected. Just wait it out.
--
Coming to .NET 2.0
Computer.Think(),Server.Crash(),Server.DOSAttack(me).
Coming to Visual C++
CDotNetBannerAd in title bar,short int64 and long bool data types
Forums » Up and Running » Security » Securityhow do you remove default C$ share? »
« GWF's, useless logs, and abuse desks.  


Saturday, 05-Dec 03:24:41 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10 years online! © 1999-2009 dslreports.com.republican-creole
page compression OFF
Most commented news this week
· [163] Comcast Releasing Promised Usage Meter
· [145] Avast Antivirus Has Gone Mad
· [126] Comcast Makes NBC Universal Acquisition Official
· [104] Graduate Student Unveils Sprint's GPS Sharing With Feds
· [101] Google Invades ISP, OpenDNS Turf With Google Public DNS
· [89] The Bandwidth Hog Does Not Exist
· [83] FCC Ponders Moving From PSTN To IP Voice
· [81] Latest Consumer Reports Survey Not Kind To AT&T
· [74] Sprint Defuses GPS Privacy Media Bomb
· [70] Baltimore To Ban Lazy Cable Installs
Most people now reading
· False positive in Avast! or is it real? [Security]
· 3.x Feral Druid - Bear Tanking Guide [World of Warcraft]
· Google takes aim at browser redirection [Security]
· DNS options, what are YOU using? [TekSavvy]
· Evading throttling with uTP / uTorrent 1.9a [TekSavvy]
· Windows 7 boot manager editing questions [Microsoft Help]
· What to use while demonoid is down? [Filesharing Software]
· Connecting to Google Voice Via SIP [VOIP Tech Chat]
· [Rant] Disrespect of PTO [Rants, Raves, and Praise]
· RG Firmware update to VDSL2 this morning [AT&T U-verse]