Hackers

tht

Master of my own fate.
Oct 10, 2002
857
158
63
Planet Earth
Just received this from Codetel.

SUSPECT IP: 64.32.101.164 A user, apparently from your network, initiated the following suspicious or hostile traffic against the IP(s) indicated below....................

The IP address is unknown to me and I'm behind a firewall. I had a worm attack on my computer a while ago, one of these probably managed to steal my Codetel password. It's a single user account and I'm online all the time so no one should have been able to log on (theoretically at least). I'm just letting everybody know that some smart ass is messing around. Keep your firewalls and virus protection software up to date. I will from now change my password regularly.
 

calamardoazul

New member
Jul 29, 2003
178
0
0
60
Yes, be careful

I had experience those attacks several times. I think is the same IP address from where the attacks to my computer came. I?ve tracked the source down and those attacks came from someone located in California. Once I got the Name, The Address and email of the hacker. :angry:
 

Sanson

New member
Apr 14, 2003
129
0
0
Tht, if you have DSL, the person who has your password is still able to connect via dial up. Anyway, if he isn`t interested in connecting to the net for free, he can check your e-mail. I recommend you to download zonealarm from www.download.com .It`s a great firewall.
 

FireGuy

Rest in peace Amigo!
Aug 21, 2002
2,516
74
0
70
www.polaris-fs.com
IP

Here is some info, someone has obviously complained about a hostile act performed with your user Id. The ISP address is definitely Codetel but I assum that is your provider what was the other unknown ISP?

The person who said zomealarm was great has a lot to learn, the free issue of ZA does stop some malicious traffic but is only a shell of the real thing and lots of stuff can get through. If you try to uninstall ZA it will keep popping back to a ZoneAlarm webpage telling you some files are missing, it will not totally unistall, they want you to buy their Pro version.

Norton Internet Security is the best on the market.

Even if you are on all the time as you say, someone did a port scan got into your computer and worked in the background as you surfed the net and used your ISP and ID.

One problem you have is that Codetel uses direct allocation to their servers and you are always assigned the same net range, tracing your hacker even further can be done but with great difficulty. You say you are behind a firewall, which one?
Changing passwords will not help if you are online when hacked.
 

tht

Master of my own fate.
Oct 10, 2002
857
158
63
Planet Earth
Hlywud - Thks for info. I'm using McAfee Personal Firewall, but as I said , I had a worm attack a while ago, they probably attacked before I had a chance to upgrade my virus software (which is also McAfee). I've done a firewall test several times and never found any holes. Changing password - If the worm was a password stealer I believe someone could pick that up, thats why I said I would change it. Can't remeber the name of the worm, it's around a month ago, coincides with the hostile activity Oct. 11th.
 
Last edited:

XanaduRanch

*** Sin Bin ***
Sep 15, 2002
2,493
0
0
Was it MATSON_D? I had that all over here last week. Infected things about the times you mentioned. Came from Kazaa I think from a computer my wife and her sisters use but spread all over the network. Sent e-mails back to the hacker with passwords, etc. and also created admin priveleges for itself on the netwrok. Big mess.

Tom (aka XR)
 

arturo

Bronze
Mar 14, 2002
1,336
97
48
Kazaa

Kazaa has to be one of the top virus sources in the world just now. Hackers favor it because it is a highly efficient distribution vehicle. I would never use a machine I own to connect to Kazaa. I occasionally pull Kazaa content, but I use a public machine and scan the content before using it. I rarely use any Kazaa content on machines I own.
 

tht

Master of my own fate.
Oct 10, 2002
857
158
63
Planet Earth
XR & Arturo- Interesting! Still can't remember the name of the worm, but it happened after I had used Kazaa's web browser. Haven't used it again and never thought about it before now. I'm doing regular virusscans and was very surprised when I found that worm crap.
 

calamardoazul

New member
Jul 29, 2003
178
0
0
60
Hey!

I have Norton Firewall installed in my computer, and as I stated in my prior post, I have had several attacks. Norton Firewall has a tracking feature and every time I have run it , has pinpointed a town in California as the source of the attacks....:confused:

The IP address that Norton Firewall blocked was very alike to the one posted here...so now I`m confused:confused:
 
Last edited:

XanaduRanch

*** Sin Bin ***
Sep 15, 2002
2,493
0
0
The attacks being felt here in the DR from California should gradually decrease now that the Schwarzenegger-Davis fight is over. However watch out for more malicious worm slinging with each passing huelga as the Dominican Leonel-Bald Hippo hack attack heats up.

Tom (aka XR)
 
Re: Hey!

calamardoazul said:
I have Norton Firewall installed in my computer, and as I stated in my prior post, I have had several attacks. Norton Firewall has a tracking feature and every time I have run it , has pinpointed a town in California as the source of the attacks....:confused:

The IP address that Norton Firewall blocked was very alike to the one posted here...so now I`m confused:confused:
 
Re: Hey!

calamardoazul said:
I have Norton Firewall installed in my computer, and as I stated in my prior post, I have had several attacks. Norton Firewall has a tracking feature and every time I have run it , has pinpointed a town in California as the source of the attacks....:confused:

The IP address that Norton Firewall blocked was very alike to the one posted here...so now I`m confused:confused:

I tracked the IP address given it does refer to an origin in California, the hacker starts in California on a fake DNS, highjacks a computer connects down the line with Codetel and then highjacks the original poster computer. Hackers may go through multiple networks until they can highjack someone. Here is the information on the tracking. It may be greek to a lot of people.

3 130.152.180.21 5.317 ms isi-1-lngw2-atm.ln.net [AS226] Los Nettos origin AS
4 4.24.4.249 8.869 ms gigabitethernet5-0.lsanca1-cr3.bbnplanet.net [AS1/AS3356] GTE Internetworking / Level 3 Communications North America
5 4.24.4.2 9.733 ms p6-0.lsanca1-cr6.bbnplanet.net [AS1/AS3356] GTE Internetworking / Level 3 Communications North America
6 4.24.5.49 9.440 ms p6-0.lsanca2-br1.bbnplanet.net [AS1/AS3356] GTE Internetworking / Level 3 Communications North America
7 64.159.4.25 8.774 ms so-5-2-0.bbr1.LosAngeles1.level3.net [AS3356] Level 3 Communications North America
8 209.247.10.198 9.929 ms pos8-0.core2.LosAngeles1.Level3.net [AS3356] Level 3 Communications North America
9 64.152.193.82 7.440 ms att-level3-oc48.LosAngeles1.Level3.net [AS3356] Level 3 Communications North America
10 12.123.28.197 6.331 ms gbr6-p90.la2ca.ip.att.net (DNS error)
11 12.122.11.141 8.762 ms tbr1-p013601.la2ca.ip.att.net (DNS error)
12 12.122.10.49 36.867 ms tbr1-p012101.n54ny.ip.att.net (DNS error)
13 12.122.2.90 66.457 ms tbr2-cl1.attga.ip.att.net (DNS error)
14 12.122.9.157 65.353 ms tbr1-p012501.attga.ip.att.net (DNS error)
15 12.122.12.122 73.403 ms gbr4-p10.ormfl.ip.att.net (DNS error)
16 12.123.200.237 81.937 ms gar1-p360.miufl.ip.att.net (DNS error)
17 12.118.175.14 82.042 ms DNS error
18 196.3.74.1 116.937 ms DNS error [AS6400] CODETEL
19 196.3.74.46 118.460 ms DNS error [AS6400] CODETEL
20 196.3.74.29 118.841 ms DNS error [AS6400] CODETEL
21 172.22.192.131 119.093 ms DNS error
22 172.22.192.131 119.138 ms DNS error

Confusing to say the least
 
Last edited:

Robert

Stay Frosty!
Jan 2, 1999
20,574
341
83
dr1.com
I'm so happy I use a Mac and I'm slowly moving our complete business to Apple. None of this virus and trojan BS!

If you haven't used OSX 10.3 on an Apple, I suggest you take a look, it's a killer OS.

I have been a PC person for 20 years and hated Macs, but in the last year, Apple has changed all that for me.