View Full Version : Kinda off topic but i have to ask...
Nasse
31st January 2002, 19:29
My firewall detects someone trying to "hack" my computer using sub 7 and netbus... i got his ip on several occasions... anyone knows what to do??? :confused: :confused:
UHT
31st January 2002, 19:51
do a lookup to find the host of the ip and then send an email detailing times and ip addresses to that isp
Nasse
31st January 2002, 19:54
the thing is i dont know how to look up that.... i knew of a page before that could do that... but i forgot it... anyone knows of a good way of getting the isp??
Doom9
31st January 2002, 20:49
for european IPs: www.ripe.net -> whois
for north american IPs: www.arin.net -> whois
if it's from somewhere else.. search for whois in google and you'll eventually come to a list of all IP registrars worldwide.. I don't recall the url
gldblade
31st January 2002, 21:41
This is all assuming the hacker's IP doesn't change. If it's dynamic (as with dial-up connections), then this might be a small problem. Also, some ISPs have IPs that serve more than one person at a time.
MxxCon
1st February 2002, 02:40
i say ignore it.
if you have fireall up and antivirus up to date and you are sure that your computre is not infected just ignore that.
it's usual "internet background noise".
some ppl scan whole class c subnets. they are not nessarly targeting YOU personaly. you just happened to be in their scan range.
you are just another light post they are passing by on information super highway:cool:
Nasse
1st February 2002, 20:17
i do not wanna ignore this...
Date: 2002-01-31 Time: 20:02:45
Rule "Default Block Backdoor/SubSeven Trojan horse" blocked (213.116.247.137,Backdoor-g-1(1243)). Details:
Inbound TCP connection
Local address,service is (213.116.247.137,Backdoor-g-1(1243))
Remote address,service is (213.116.254.59,4910)
Process name is "N/A"
i think its a trojan...
thanks doom ill check the sites...:)
int 21h
1st February 2002, 20:21
inetnum: 213.116.248.0 - 213.116.255.255
netname: UUNET-DAN-SE
descr: UUNET DAN STOCKHOLM
country: SE
admin-c: SB855-RIPE
tech-c: NS5468-RIPE
status: ASSIGNED PA
remarks: --------------------------------
remarks: In case of network abuse please
remarks: use the following address:
remarks:
remarks: abuse@(country code).uu.net
remarks:
remarks: So if abuse originated in UK you
remarks: would use abuse@uk.uu.net
remarks: --------------------------------
mnt-by: AS705-MNT
changed: nichols@uk.uu.net 20010903
source: RIPE
So you email abuse@se.uu.net with a log of the stuff that is happening.
Or you just walk over to them and kick their ass, since they are at the same campus/Uni as you. :)
Nasse
1st February 2002, 20:28
I just got that thingy... i think im gonna do both...:D :D thanks for the help everyone...
vBulletin® v3.8.5, Copyright ©2000-2012, Jelsoft Enterprises Ltd.