My First Server attacks

Hardware, Software, Internet, etc.

Moderators: Big-O Ryan, Big-O Mark, Matt, jester22c

Post Reply
fuuucckkers
Moderator
Moderator
Posts: 815
Joined: Sun Sep 22, 2002 3:33 pm
Contact:

My First Server attacks

Post by fuuucckkers »

As of now.. I'm scared shitless..and it's a good thing I installed Sygate Firewall Pro on my Server LAST NIGHT!

I recieved a few "Code Red" Dos attacks from one source only (someone who's infected obviously), and an Intrusion Detection System with an application name of 'inetinfo.exe'.

I tryed a WhoIS lookup on the IP of the possible intrusion and,
and it comes from someone in NY, but it looks as if they provided false WhoIs.

The Code Red Attacks come from some business out in Virginia.... :-?
User avatar
Anthony
Moderator
Moderator
Posts: 1532
Joined: Thu Sep 12, 2002 5:10 am
Location: Rochester, New York
Contact:

Post by Anthony »

Lucky you :evil:
Image
PhaseDMA - Check it out
My AIM+ FAQ
User avatar
Master Jedi
Guru
Guru
Posts: 1161
Joined: Sat Jun 15, 2002 10:34 pm
Contact:

Post by Master Jedi »

It says forums are fully functional, but I get a 403.1 error. (I think you need to enable execute permissions for anonymous users.)
fuuucckkers
Moderator
Moderator
Posts: 815
Joined: Sun Sep 22, 2002 3:33 pm
Contact:

Post by fuuucckkers »

Problem solved with the few attacked I recieved.. I just straight out blocked their individual IPs. Now my packet log is filling up with Blocked IP addresses.
fuuucckkers
Moderator
Moderator
Posts: 815
Joined: Sun Sep 22, 2002 3:33 pm
Contact:

Post by fuuucckkers »

Master Jedi wrote:It says forums are fully functional, but I get a 403.1 error. (I think you need to enable execute permissions for anonymous users.)
Boards are down. Email wont send properly. I'm in the process of installing configuring an email server shortly. Sorry for the inconvience! :-?
User avatar
Master Jedi
Guru
Guru
Posts: 1161
Joined: Sat Jun 15, 2002 10:34 pm
Contact:

Post by Master Jedi »

I can wait...
User avatar
Plasma2002b
Extreme Groupie
Extreme Groupie
Posts: 976
Joined: Thu Jul 18, 2002 11:36 pm
Location: Riverside, Ca
Contact:

Post by Plasma2002b »

wasted...... if you just keep blocking the IP's of the attackers, your just gonna get a huge block list...... cause the machines that are attacking are random.... and even if the do strike more than once, they cant do anything as long as you have the correct service pack updates..... but you can still see that they are attacking.....


ive learned to live with it and just ignore it.
Image

its teh infamous life of brian gaut to teh max0r!
fuuucckkers
Moderator
Moderator
Posts: 815
Joined: Sun Sep 22, 2002 3:33 pm
Contact:

Post by fuuucckkers »

I actually backtraced a few of the IPs that came to me with DoS attacks..and one came from some business in Texas, and one was from a Pacific Bell DNS server.

Others are just general users with servers set up im guessing.
User avatar
tone
Fanatic
Fanatic
Posts: 236
Joined: Thu Sep 12, 2002 10:51 am
Location: New Jersey
Contact:

Post by tone »

Plus they might connect through proxy which will make their ip invisible. 8)
tone
User avatar
Master Jedi
Guru
Guru
Posts: 1161
Joined: Sat Jun 15, 2002 10:34 pm
Contact:

Post by Master Jedi »

tone wrote:Plus they might connect through proxy which will make their ip invisible. 8)
Code Red only affects computers running IIS, the web server software from Micro$oft. It is very unlikely that people are serving web pages through a proxy because that can put a very heavy (and unnecessary) load on the proxy server.
User avatar
tone
Fanatic
Fanatic
Posts: 236
Joined: Thu Sep 12, 2002 10:51 am
Location: New Jersey
Contact:

Post by tone »

Master Jedi wrote:
tone wrote:Plus they might connect through proxy which will make their ip invisible. 8)
Code Red only affects computers running IIS, the web server software from Micro$oft. It is very unlikely that people are serving web pages through a proxy because that can put a very heavy (and unnecessary) load on the proxy server.
Sorry :oops:

I wasnt thinking straight, i just assumed because he said he got a company's name in Virgina and he thought that it was fake so i thought proxy.
tone
Post Reply

Who is online

Users browsing this forum: Ahrefs [Bot] and 0 guests