am I bieng hacked?

Silver-0-surfer

Well-Known Member
Joined
Jan 5, 2008
Messages
317
Reaction score
7
Location
CPT
Hi

As the title suggests I think i'm bieng hacked/spammed/malwared.

I installed Cain & able to play around with at home and everything was cool, until about an hour ago I see all these IPs comming up in C&A saying wether they have been deneid or allowed access.

So I type in a couple of those IP's into my browser and a few don't return anything but I got to 2 apache test pages 1 CentOS and 1 fedora,also got to these 2 pages http://165.145.63.156 and http://165.145.219.38/?q=node/1

I googled 1 of the IPs and it gave me this URL http://www.projecthoneypot.org/ip_165.145.191.58 saying (I only skimmed it but)

"The Project Honey Pot system has detected behavior from the IP address consistent with that of a mail server and dictionary attacker. Below we've reported some other data associated with this IP. This interrelated data helps map spammers' networks and aids in law enforcement efforts. If you know something about this IP, please leave a comment."

So I called telkom to see if I can pull any logs off the 100wr router but got no help.

Wierd thing is reboot modem and get a new Dynamic IP and I still get this in C&A..

I'm freaking out a bit,also intreauged, so can any1 tell me how can I tell if im bieng compromised?

Thnx
 
Well, is the communication inbound or outbound?
If it is outbound, it is likely to be a virus or something on your PC.
Are you sure that C&A does not check for updates?

Is this game original, not modified in any way?
I know sometimes its nice to crack a game so that you dont have to swap game discs all the time, but it is possible if it is cracked that the cracker might have writen a hidden code inside and since your game is allready in your processes it already have access to your system.
 
Well, is the communication inbound or outbound?
If it is outbound, it is likely to be a virus or something on your PC.
Are you sure that C&A does not check for updates?

Is this game original, not modified in any way?
I know sometimes its nice to crack a game so that you dont have to swap game discs all the time, but it is possible if it is cracked that the cracker might have writen a hidden code inside and since your game is allready in your processes it already have access to your system.

Cain and Able isn't a game, and if you don't know that, you have no right in advising anyone on this subject.

OP, you could just block the IPs on your firewall? The fact that you still get hits from those IPs after cycling your own IP indicates that you may have a bit of malware on your system broadcasting your IP to the attacker.
 
Suggestion : install smoothwall or IPCop and have it log the IP's coming in.

You'll also be able to block bad IP's more efficiently with Smoothwall than with a windows firewall.
 
Ye thanx, installed malwarbytes and updated my AV. turns out it was a malware issue. disconnected from the net, started in safe mode and scanned and cleaned everything yesterday.

no more strange behavior on C&A :)

thnx guys
 
dude the amount of portscans and vulnerability scans on the net are endless. chances are your disconnect just cycled your IP. Next time it appears somewhere or someone elses machine has it and announces it and then you get it you will be scanned again etc. etc.

Just keep the f/w running nicely and its all good.
 
Dude just check that your anti-virus still works, at University the lecturer installed C&A in one of our security practicals and it broke his anti-virus.
 
Top
Sign up to the MyBroadband newsletter
X