Someone traceroute for me please
21-08-2003, 21:52
|
#1
|
|
Inactive
Join Date: Aug 2003
Location: UK
Posts: 83
|
Someone traceroute for me please
Hey,
im under all day TCP attack on port 1084 (NOT MSBlast) from 195.157.100.129.
can someone please find out as much as possible on this for me please. I can barely even load this page & browsing or FTP is well out of the question  .
it may be some other virus, i'll give whoever it is the benfit of the doubt until i see the results etc.
thankyou in advance,
§talker
|
|
|
21-08-2003, 22:09
|
#2
|
|
Inactive
Join Date: Jun 2003
Location: Oldham
Age: 45
Services: 40 MB Sky BB with telephone and skyHD for TV :)
Posts: 320
|
Heres the location of the attacker!!!
pop an email to the abuse address!!
Cheers
DJ
role: Netscalibur UK Hostmaster
address: Netscalibur UK Ltd
address: 9 Selsdon Way
address: Cityharbour
address: London E14 9GL
address: UK
phone: +44 (0)870 887 8800
fax-no: +44 (0)870 887 8867
e-mail: hostmaster@netscalibur.co.uk
admin-c: CSP3-RIPE
admin-c: SY131-RIPE
tech-c: NSUK1-RIPE
tech-c: NSUK3-RIPE
nic-hdl: NSUK2-RIPE
remarks: Hostmaster
remarks: ****
remarks: * All abuse reports to abuse@netscalibur.co.uk
|
|
|
21-08-2003, 22:26
|
#3
|
|
Inactive
Join Date: Aug 2003
Location: UK
Posts: 83
|
tyvm The_real_dj, i'll give em a ring tommorow, always works better than abuse emails as they never get followed up
§talk
|
|
|
22-08-2003, 00:53
|
#4
|
|
Inactive
Join Date: Jul 2003
Location: Yorkshire
Posts: 162
|
How do you do a trace route
|
|
|
22-08-2003, 03:03
|
#5
|
|
Guest
Location: East London (ex-C&W)
Services: XL broadband
ntl250 modem
Posts: n/a
|
Quote:
Originally posted by tomw
How do you do a trace route
|
From a command prompt, type "tracert", followed by the address, such as:-
tracert www.nthellworld.co.uk
or
tracert 195.157.100.129
|
|
|
|
22-08-2003, 06:05
|
#6
|
|
Inactive
Join Date: Jun 2003
Location: Los Angeles, CA
Age: 46
Posts: 6,343
|
lmao...
http://195.157.100.129/
It's just a webserver...
|
|
|
22-08-2003, 11:12
|
#7
|
|
Inactive
Join Date: Aug 2003
Location: UK
Posts: 83
|
both PC's turned off last night, router was being hit HARD till 3am. Either thats an infected webserver or.....i dunno!
seems ok now though, but it was so bad yesterday that i couldn't use the net well at all
§talk
|
|
|
22-08-2003, 12:41
|
#8
|
|
Inactive
Join Date: Jun 2003
Location: Cambs
Posts: 147
|
Stalker do you still want a traceroute? I've done one if you want it.
Seb
|
|
|
22-08-2003, 12:52
|
#9
|
|
Inactive
Join Date: Aug 2003
Location: UK
Posts: 83
|
i'll take anything you have Seb, this is looking very strange from my point of view  , even more so after finding out its a webserver
§talk
|
|
|
22-08-2003, 12:54
|
#10
|
|
Inactive
Join Date: Jun 2003
Location: NW UK
Posts: 3,546
|
Has anyone thought it could have been a Spoofed IP?
It isn't a IIS webserver though lol
Server nc3-0028.web.uk.netscalibur.com on port 80 is running:
Apache/1.3.20 Sun Cobalt (Unix) mod_jk mod_ssl/2.8.4 OpenSSL/0.9.6 PHP/4.0.6 FrontPage/5.0.2.2510 mod_perl/1.26
Other information returned by server...
Requested path: /
HTTP/1.1 302 Found
Date: Fri, 22 Aug 2003 10:15:08 GMT
Location: http://nc3-0028.web.uk.netscalibur.com/
Connection: close
Content-Type: text/html; charset=iso-8859-1
Server Response time: 0.839056 seconds
|
|
|
22-08-2003, 12:58
|
#11
|
|
Inactive
Join Date: Jun 2003
Location: Surrey
Age: 59
Services: Virgin stuff
Posts: 6,407
|
Stalker, have you called them ?
|
|
|
22-08-2003, 13:00
|
#12
|
|
Inactive
Join Date: Aug 2003
Location: UK
Posts: 83
|
ive taken that into consideration but for a DOS attack, what would they hope to acheive apart from pi$*in me off
The IP resolves to netscalibur.co.uk/ which offers hosting services.
i personally dont think that a company would do anything like that as it reflects back on them, so something more sinister is looking more likely.
I think i'll leave it as long as it dosen't happen again
§talk
|
|
|
22-08-2003, 13:01
|
#13
|
|
Inactive
Join Date: Aug 2003
Location: UK
Posts: 83
|
bloody hell Lord Nikon
what did you use for that???!!!!!!
§talk
PS. no, i haven't called them, you think i should?
|
|
|
22-08-2003, 13:02
|
#14
|
|
Inactive
Join Date: Jun 2003
Location: NW UK
Posts: 3,546
|
Port Authority Database
Port 1084
Name:
ansoft-lm-2
Purpose:
Anasoft License Manager
So, no idea what would be using that IP really.
|
|
|
22-08-2003, 13:02
|
#15
|
|
Inactive
Join Date: Jun 2003
Location: Cambs
Posts: 147
|
Here you go
Quote:
Tracing route to nc3-0028.web.uk.netscalibur.com [195.157.100.129]
over a maximum of 30 hops:
1 <10 ms <10 ms <10 ms 192.168.0.1
2 10 ms 10 ms 10 ms 10.132.39.254
3 <10 ms 10 ms 10 ms cmbg-t2cam1-b-ge95.inet.ntl.com [80.1.202.161]
4 <10 ms 11 ms <10 ms cmbg-t2core-b-ge-wan61.inet.ntl.com [80.1.201.153]
5 10 ms 10 ms 10 ms nth-bb-b-so-210-0.inet.ntl.com [62.253.188.197]
6 10 ms 10 ms 21 ms nth-bb-a-ae0-0.inet.ntl.com [62.253.185.117]
7 10 ms 20 ms 20 ms gfd-bb-b-so-400-0.inet.ntl.com [62.253.185.98]
8 20 ms 10 ms 10 ms tele-ic-2-so-100-0.inet.ntl.com [62.253.185.74]
9 10 ms 40 ms 20 ms linx-gw2.uk.netscalibur.net [195.66.226.47]
10 10 ms 20 ms 30 ms g2-1.br1.th.rtr.uk.netscalibur.net [195.157.6.225]
11 10 ms 20 ms 40 ms g1-1.dist1.th.rtr.uk.netscalibur.net [195.157.6.178]
12 10 ms 20 ms 20 ms 511.cr11.th.rtr.uk.netscalibur.net [195.157.7.98]
13 10 ms 20 ms 10 ms nc3-0028.web.uk.netscalibur.com [195.157.100.129]
Trace complete.
|
Seb
|
|
|
Posting Rules
|
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
HTML code is Off
|
|
|
All times are GMT +1. The time now is 09:31.
|