Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums.

You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today!

If you have any problems with the registration process or your account login, please contact us.

Post New Thread Reply

Register GFY Rules Calendar Mark Forums Read
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >
Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed.

 
Thread Tools
Old 08-22-2002, 12:54 PM   #1
HQ
Confirmed User
 
Join Date: Jan 2001
Posts: 3,539
64.105.235.252 is trying to hack me

Whoever is behind this IP, 64.105.235.252, is trying to hack me. What's the best way to look up info on an IP?
HQ is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-22-2002, 12:54 PM   #2
HQ
Confirmed User
 
Join Date: Jan 2001
Posts: 3,539
63.225.201.208 too.
HQ is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-22-2002, 12:55 PM   #3
JFPdude
Confirmed User
 
Join Date: Jan 2002
Location: Mountains of Western North Carolina.
Posts: 4,027
whois ip.num.ber
JFPdude is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-22-2002, 12:55 PM   #4
pr0
rockin tha trailerpark
 
pr0's Avatar
 
Industry Role:
Join Date: May 2001
Location: ~Coastal~
Posts: 23,088
He's probably watching you post asking this question & laughing
pr0 is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-22-2002, 12:55 PM   #5
Gary
Confirmed User
 
Join Date: Aug 2001
Location: Kimmykims couch
Posts: 6,110
Ya, thats me. sorry dude, i'll stop
__________________

Up to 35$ per join...!
Gary is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-22-2002, 12:56 PM   #6
JFPdude
Confirmed User
 
Join Date: Jan 2002
Location: Mountains of Western North Carolina.
Posts: 4,027
whois 64.105.235.252
Covad Communications (NETBLK-COVAD-IP-1-NET)
3420 Central Expressway
Santa Clara, CA 95051
US

Netname: COVAD-IP-1-NET
Netblock: 64.105.0.0 - 64.105.255.255
Maintainer: CVAD

Domain System inverse mapping provided by:

NS1.COVAD.NET 66.134.199.11
NS2.COVAD.NET 66.134.199.12
JFPdude is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-22-2002, 12:56 PM   #7
HQ
Confirmed User
 
Join Date: Jan 2001
Posts: 3,539
Quote:
Originally posted by Gary
Ya, thats me. sorry dude, i'll stop
NP, thanks for all that porn you uploaded!
HQ is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-22-2002, 12:57 PM   #8
Chris R
Confirmed User
 
Join Date: May 2001
Location: Baltimore, MD USA
Posts: 1,151
Covad Communications (NETBLK-COVAD-IP-1-NET)
3420 Central Expressway
Santa Clara, CA 95051
US

Netname: COVAD-IP-1-NET
Netblock: 64.105.0.0 - 64.105.255.255
Maintainer: CVAD

Coordinator:
Boggan, Rick (RB1873-ARIN) [email protected]
(408) 616-6766 (FAX) (408) 616-6501

Domain System inverse mapping provided by:

NS1.COVAD.NET 66.134.199.11
NS2.COVAD.NET 66.134.199.12

ADDRESSES WITHIN THIS BLOCK ARE NON-PORTABLE

for abuse issues, please contact [email protected]
Reassignment information for this block of addresses can
be found at rwhois://rwhois.laserlink.net:4321/

Record last updated on 06-Jun-2002.
Database last updated on 21-Aug-2002 20:01:34 EDT.
Chris R is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-22-2002, 12:57 PM   #9
quiet
we'll miss you our friend. RIP
 
Industry Role:
Join Date: Sep 2001
Location: Fernie, BC
Posts: 25,115
Server used for this query: [ whois.arin.net ]




Covad Communications (NETBLK-COVAD-IP-1-NET)
3420 Central Expressway
Santa Clara, CA 95051
US

Netname: COVAD-IP-1-NET
Netblock: 64.105.0.0 - 64.105.255.255
Maintainer: CVAD

Coordinator:
Boggan, Rick (RB1873-ARIN) [email protected]
(408) 616-6766 (FAX) (408) 616-6501

Domain System inverse mapping provided by:

NS1.COVAD.NET 66.134.199.11
NS2.COVAD.NET 66.134.199.12

ADDRESSES WITHIN THIS BLOCK ARE NON-PORTABLE

for abuse issues, please contact [email protected]
__________________
we'll miss you our friend. RIP
quiet is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-22-2002, 12:57 PM   #10
JFPdude
Confirmed User
 
Join Date: Jan 2002
Location: Mountains of Western North Carolina.
Posts: 4,027
whois 63.225.201.208
U S WEST Communications Services, Inc (NETBLK-USW-INTERACT99)
600 Stinson Blvd NE
Minneapolis, MN 55413
US

Netname: USW-INTERACT99
Netblock: 63.224.0.0 - 63.231.255.255
Maintainer: USW

Coordinator:
U S WEST ISOps (ZU24-ARIN) [email protected]
612-664-4689

Domain System inverse mapping provided by:

NS1.USWEST.NET 204.147.80.5
NS2.DNVR.USWEST.NET 206.196.128.1
JFPdude is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-22-2002, 12:58 PM   #11
Cogitator
Confirmed User
 
Join Date: Feb 2002
Location: Florida
Posts: 672
I use www.samspade.org

Click there and take a look
__________________
- this space intentionally left blank -
Cogitator is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-22-2002, 12:58 PM   #12
Fletch XXX
GFY HALL OF FAME DAMMIT!!!
 
Fletch XXX's Avatar
 
Join Date: Jan 2002
Location: that 504
Posts: 60,840
<h3>BaaaZZZZaaam!!!!!</h3>
__________________

Want an Android App for your tube, membership, or free site?

Need banners or promo material? Hit us up (ICQ Fletch: 148841377) or email me fletchxxx at gmail.com - recent work - About me
Fletch XXX is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-22-2002, 12:58 PM   #13
HQ
Confirmed User
 
Join Date: Jan 2001
Posts: 3,539
Quote:
Originally posted by JFPdude
whois ip.num.ber
Does not work for me.

No match for "64.105.235.252".
HQ is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-22-2002, 12:58 PM   #14
TheFLY
So Fucking Banned
 
Join Date: Jan 2001
Location: http://www.thefly.net/ --- Quit your job and live off steady traffic.
Posts: 11,856
This topic cracks me up...

Sincerely,

204.53.21.121
TheFLY is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-22-2002, 12:59 PM   #15
Auslander
Registered User
 
Join Date: Aug 2002
Location: www.whataboutbob.com
Posts: 288
Quote:
Originally posted by Cogitator
I use www.samspade.org

Click there and take a look
Spade rocks!
Auslander is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-22-2002, 12:59 PM   #16
HQ
Confirmed User
 
Join Date: Jan 2001
Posts: 3,539
Quote:
Originally posted by Cogitator
I use www.samspade.org

Click there and take a look
Kick-ass!

"for abuse issues, please contact [email protected]"
HQ is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-22-2002, 01:14 PM   #17
HQ
Confirmed User
 
Join Date: Jan 2001
Posts: 3,539
And this mother fucker is a hitbot: 212.77.204.34 Crazy what you find in your error logs.
HQ is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-22-2002, 02:04 PM   #18
salsbury
Confirmed User
 
Join Date: Feb 2002
Location: Seattle
Posts: 1,070
what's he trying to hack you with?
__________________
salsbury is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-22-2002, 02:07 PM   #19
boldy
Macdaddy coder
 
Industry Role:
Join Date: Feb 2002
Location: MacDaddy pimp coder
Posts: 2,806
Quote:
Originally posted by salsbury
what's he trying to hack you with?
I think they do it just for fun, my servers are under attack 24/7 by some dumbasses in Dubai. my servers are double firewalled ... Checkpoint and Astaro ... good luck Dubiaian fuckers
__________________
MacDaddy Coder.
boldy is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-22-2002, 02:23 PM   #20
-=HOAX=-
Confirmed User
 
Join Date: Dec 2001
Location: CrackYaMental
Posts: 4,365
nmap is a good way to snoop around in what he's got going on...
__________________
Insert Value Here.
-=HOAX=- is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-22-2002, 02:28 PM   #21
boldy
Macdaddy coder
 
Industry Role:
Join Date: Feb 2002
Location: MacDaddy pimp coder
Posts: 2,806
Quote:
Originally posted by -=HOAX=-
nmap is a good way to snoop around in what he's got going on...
nmap 4 life ... decoy scanning and shit ...
__________________
MacDaddy Coder.
boldy is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-22-2002, 04:35 PM   #22
HQ
Confirmed User
 
Join Date: Jan 2001
Posts: 3,539
Quote:
Originally posted by salsbury
what's he trying to hack you with?
Just searching for well-known files on my system. I think they were windows too. Barking up the wrong tree there!
HQ is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-22-2002, 05:05 PM   #23
-=HOAX=-
Confirmed User
 
Join Date: Dec 2001
Location: CrackYaMental
Posts: 4,365
Wed Aug 21 12:40:36 2002] [error] [client 66.28.236.25] File does not exist: /usr/local/www/data/scripts/root.exe
[Wed Aug 21 12:40:36 2002] [error] [client 66.28.236.25] File does not exist: /usr/local/www/data/MSADC/root.exe
[Wed Aug 21 12:40:36 2002] [error] [client 66.28.236.25] File does not exist: /usr/local/www/data/c/winnt/system32/cmd.exe
[Wed Aug 21 12:40:36 2002] [error] [client 66.28.236.25] File does not exist: /usr/local/www/data/d/winnt/system32/cmd.exe
[Wed Aug 21 12:40:36 2002] [error] [client 66.28.236.25] File does not exist: /usr/local/www/data/scripts/..%5c../winnt/system32/cmd
[Wed Aug 21 12:40:36 2002] [error] [client 66.28.236.25] File does not exist: /usr/local/www/data/_vti_bin/..%5c../..%5c../..%5c../w
[Wed Aug 21 12:40:36 2002] [error] [client 66.28.236.25] File does not exist: /usr/local/www/data/_mem_bin/..%5c../..%5c../..%5c../w
[Wed Aug 21 12:40:36 2002] [error] [client 66.28.236.25] File does not exist: /usr/local/www/data/msadc/..%5c../..%5c../..%5c/..Á^.
[Wed Aug 21 12:40:36 2002] [error] [client 66.28.236.25] File does not exist: /usr/local/www/data/scripts/..Á^\../winnt/system32/cmd
[Wed Aug 21 12:40:37 2002] [error] [client 66.28.236.25] File does not exist: /usr/local/www/data/scripts/..À¯../winnt/system32/cmd.
[Wed Aug 21 12:40:37 2002] [error] [client 66.28.236.25] File does not exist: /usr/local/www/data/scripts/..Á?../winnt/system32/cmd.
[Wed Aug 21 12:40:43 2002] [error] [client 66.28.236.25] File does not exist: /usr/local/www/data/scripts/..%5c../winnt/system32/cmd
[Wed Aug 21 12:40:43 2002] [error] [client 66.28.236.25] File does not exist: /usr/local/www/data/scripts/..%2f../winnt/system32/cmd



like this...
__________________
Insert Value Here.
-=HOAX=- is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-22-2002, 05:11 PM   #24
Libertine
sex dwarf
 
Libertine's Avatar
 
Join Date: May 2002
Posts: 17,860
It's nothing personal. He's probably scanning a few thousand servers to get a few win IIS ones which still have a major security hole.
You can get full control over a few hundred servers in an hour or so that way.
Libertine is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-22-2002, 05:13 PM   #25
salsbury
Confirmed User
 
Join Date: Feb 2002
Location: Seattle
Posts: 1,070
its probably not even a person, we have that shit in our logs all over the place. that's how a particular worm propogates.

of course, the person running the server should be notified, but chances are, at this point, they don't care to fix it. sadly.
__________________
salsbury is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 08-23-2002, 11:05 AM   #26
HQ
Confirmed User
 
Join Date: Jan 2001
Posts: 3,539
I wonder what "activate.php" is for? What script is this guy trying to exploit?
HQ is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Post New Thread Reply
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >

Bookmarks
Thread Tools



Advertising inquiries - marketing at gfy dot com

Contact Admin - Advertise - GFY Rules - Top

©2000-, AI Media Network Inc



Powered by vBulletin
Copyright © 2000- Jelsoft Enterprises Limited.