Forum Articles
  Welcome back Join CF
You are here You are here: Home | Forum | Someone traceroute for me please

You are currently viewing our boards as a guest which gives you limited access to view most of the discussions, articles and other free features. By joining our Virgin Media community you will have full access to all discussions, be able to view and post threads, communicate privately with other members (PM), respond to polls, upload your own images/photos, and access many other special features. Registration is fast, simple and absolutely free so please join our community today.


Welcome to Cable Forum
Go Back   Cable Forum > Virgin Media Services > Virgin Media Internet Service
Register FAQ Community Calendar

Someone traceroute for me please
Reply
 
Thread Tools
Old 21-08-2003, 21:52   #1
Stalker
Inactive
 
Join Date: Aug 2003
Location: UK
Posts: 83
Stalker is an unknown quantity at this point
Send a message via ICQ to Stalker
Question Someone traceroute for me please

Hey,

im under all day TCP attack on port 1084 (NOT MSBlast) from 195.157.100.129.

can someone please find out as much as possible on this for me please. I can barely even load this page & browsing or FTP is well out of the question .

it may be some other virus, i'll give whoever it is the benfit of the doubt until i see the results etc.

thankyou in advance,

§talker
Stalker is offline   Reply With Quote
Advertisement
Old 21-08-2003, 22:09   #2
The_real_dj
Inactive
 
The_real_dj's Avatar
 
Join Date: Jun 2003
Location: Oldham
Age: 45
Services: 40 MB Sky BB with telephone and skyHD for TV :)
Posts: 320
The_real_dj is just really niceThe_real_dj is just really niceThe_real_dj is just really niceThe_real_dj is just really niceThe_real_dj is just really niceThe_real_dj is just really nice
Heres the location of the attacker!!!
pop an email to the abuse address!!

Cheers

DJ


role: Netscalibur UK Hostmaster
address: Netscalibur UK Ltd
address: 9 Selsdon Way
address: Cityharbour
address: London E14 9GL
address: UK
phone: +44 (0)870 887 8800
fax-no: +44 (0)870 887 8867
e-mail: hostmaster@netscalibur.co.uk
admin-c: CSP3-RIPE
admin-c: SY131-RIPE
tech-c: NSUK1-RIPE
tech-c: NSUK3-RIPE
nic-hdl: NSUK2-RIPE
remarks: Hostmaster
remarks: ****
remarks: * All abuse reports to abuse@netscalibur.co.uk
The_real_dj is offline   Reply With Quote
Old 21-08-2003, 22:26   #3
Stalker
Inactive
 
Join Date: Aug 2003
Location: UK
Posts: 83
Stalker is an unknown quantity at this point
Send a message via ICQ to Stalker
tyvm The_real_dj, i'll give em a ring tommorow, always works better than abuse emails as they never get followed up

§talk
Stalker is offline   Reply With Quote
Old 22-08-2003, 00:53   #4
tomw
Inactive
 
Join Date: Jul 2003
Location: Yorkshire
Posts: 162
tomw is an unknown quantity at this point
How do you do a trace route
tomw is offline   Reply With Quote
Old 22-08-2003, 03:03   #5
XFS03
Guest
 
Location: East London (ex-C&W)
Services: XL broadband ntl250 modem
Posts: n/a
Quote:
Originally posted by tomw
How do you do a trace route
From a command prompt, type "tracert", followed by the address, such as:-

tracert www.nthellworld.co.uk
or
tracert 195.157.100.129
  Reply With Quote
Old 22-08-2003, 06:05   #6
Richard M
Inactive
 
Join Date: Jun 2003
Location: Los Angeles, CA
Age: 46
Posts: 6,343
Richard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze array
Richard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze arrayRichard M has a bronze array
lmao...

http://195.157.100.129/

It's just a webserver...
Richard M is offline   Reply With Quote
Old 22-08-2003, 11:12   #7
Stalker
Inactive
 
Join Date: Aug 2003
Location: UK
Posts: 83
Stalker is an unknown quantity at this point
Send a message via ICQ to Stalker
both PC's turned off last night, router was being hit HARD till 3am. Either thats an infected webserver or.....i dunno!

seems ok now though, but it was so bad yesterday that i couldn't use the net well at all

§talk
Stalker is offline   Reply With Quote
Old 22-08-2003, 12:41   #8
Seb
Inactive
 
Join Date: Jun 2003
Location: Cambs
Posts: 147
Seb is an unknown quantity at this point
Stalker do you still want a traceroute? I've done one if you want it.

Seb
Seb is offline   Reply With Quote
Old 22-08-2003, 12:52   #9
Stalker
Inactive
 
Join Date: Aug 2003
Location: UK
Posts: 83
Stalker is an unknown quantity at this point
Send a message via ICQ to Stalker
i'll take anything you have Seb, this is looking very strange from my point of view , even more so after finding out its a webserver

§talk
Stalker is offline   Reply With Quote
Old 22-08-2003, 12:54   #10
Lord Nikon
Inactive
 
Join Date: Jun 2003
Location: NW UK
Posts: 3,546
Lord Nikon has a bronze arrayLord Nikon has a bronze arrayLord Nikon has a bronze array
Lord Nikon has a bronze arrayLord Nikon has a bronze arrayLord Nikon has a bronze arrayLord Nikon has a bronze arrayLord Nikon has a bronze arrayLord Nikon has a bronze arrayLord Nikon has a bronze arrayLord Nikon has a bronze arrayLord Nikon has a bronze arrayLord Nikon has a bronze arrayLord Nikon has a bronze array
Has anyone thought it could have been a Spoofed IP?


It isn't a IIS webserver though lol

Server nc3-0028.web.uk.netscalibur.com on port 80 is running:

Apache/1.3.20 Sun Cobalt (Unix) mod_jk mod_ssl/2.8.4 OpenSSL/0.9.6 PHP/4.0.6 FrontPage/5.0.2.2510 mod_perl/1.26

Other information returned by server...

Requested path: /
HTTP/1.1 302 Found
Date: Fri, 22 Aug 2003 10:15:08 GMT
Location: http://nc3-0028.web.uk.netscalibur.com/
Connection: close
Content-Type: text/html; charset=iso-8859-1

Server Response time: 0.839056 seconds
Lord Nikon is offline   Reply With Quote
Old 22-08-2003, 12:58   #11
Nemesis
Inactive
 
Join Date: Jun 2003
Location: Surrey
Age: 59
Services: Virgin stuff
Posts: 6,407
Nemesis has a nice shiny starNemesis has a nice shiny starNemesis has a nice shiny star
Nemesis has a nice shiny starNemesis has a nice shiny starNemesis has a nice shiny starNemesis has a nice shiny starNemesis has a nice shiny starNemesis has a nice shiny starNemesis has a nice shiny starNemesis has a nice shiny starNemesis has a nice shiny starNemesis has a nice shiny starNemesis has a nice shiny starNemesis has a nice shiny starNemesis has a nice shiny starNemesis has a nice shiny starNemesis has a nice shiny star
Send a message via MSN to Nemesis
Stalker, have you called them ?
Nemesis is offline   Reply With Quote
Old 22-08-2003, 13:00   #12
Stalker
Inactive
 
Join Date: Aug 2003
Location: UK
Posts: 83
Stalker is an unknown quantity at this point
Send a message via ICQ to Stalker
ive taken that into consideration but for a DOS attack, what would they hope to acheive apart from pi$*in me off

The IP resolves to netscalibur.co.uk/ which offers hosting services.

i personally dont think that a company would do anything like that as it reflects back on them, so something more sinister is looking more likely.

I think i'll leave it as long as it dosen't happen again

§talk
Stalker is offline   Reply With Quote
Old 22-08-2003, 13:01   #13
Stalker
Inactive
 
Join Date: Aug 2003
Location: UK
Posts: 83
Stalker is an unknown quantity at this point
Send a message via ICQ to Stalker
bloody hell Lord Nikon

what did you use for that???!!!!!!

§talk

PS. no, i haven't called them, you think i should?
Stalker is offline   Reply With Quote
Old 22-08-2003, 13:02   #14
Lord Nikon
Inactive
 
Join Date: Jun 2003
Location: NW UK
Posts: 3,546
Lord Nikon has a bronze arrayLord Nikon has a bronze arrayLord Nikon has a bronze array
Lord Nikon has a bronze arrayLord Nikon has a bronze arrayLord Nikon has a bronze arrayLord Nikon has a bronze arrayLord Nikon has a bronze arrayLord Nikon has a bronze arrayLord Nikon has a bronze arrayLord Nikon has a bronze arrayLord Nikon has a bronze arrayLord Nikon has a bronze arrayLord Nikon has a bronze array
Port Authority Database

Port 1084

Name:
ansoft-lm-2

Purpose:
Anasoft License Manager


So, no idea what would be using that IP really.
Lord Nikon is offline   Reply With Quote
Old 22-08-2003, 13:02   #15
Seb
Inactive
 
Join Date: Jun 2003
Location: Cambs
Posts: 147
Seb is an unknown quantity at this point
Here you go

Quote:
Tracing route to nc3-0028.web.uk.netscalibur.com [195.157.100.129]
over a maximum of 30 hops:

1 <10 ms <10 ms <10 ms 192.168.0.1
2 10 ms 10 ms 10 ms 10.132.39.254
3 <10 ms 10 ms 10 ms cmbg-t2cam1-b-ge95.inet.ntl.com [80.1.202.161]
4 <10 ms 11 ms <10 ms cmbg-t2core-b-ge-wan61.inet.ntl.com [80.1.201.153]
5 10 ms 10 ms 10 ms nth-bb-b-so-210-0.inet.ntl.com [62.253.188.197]
6 10 ms 10 ms 21 ms nth-bb-a-ae0-0.inet.ntl.com [62.253.185.117]
7 10 ms 20 ms 20 ms gfd-bb-b-so-400-0.inet.ntl.com [62.253.185.98]
8 20 ms 10 ms 10 ms tele-ic-2-so-100-0.inet.ntl.com [62.253.185.74]
9 10 ms 40 ms 20 ms linx-gw2.uk.netscalibur.net [195.66.226.47]
10 10 ms 20 ms 30 ms g2-1.br1.th.rtr.uk.netscalibur.net [195.157.6.225]
11 10 ms 20 ms 40 ms g1-1.dist1.th.rtr.uk.netscalibur.net [195.157.6.178]
12 10 ms 20 ms 20 ms 511.cr11.th.rtr.uk.netscalibur.net [195.157.7.98]
13 10 ms 20 ms 10 ms nc3-0028.web.uk.netscalibur.com [195.157.100.129]

Trace complete.
Seb
Seb is offline   Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT +1. The time now is 15:05.


Server: osmium.zmnt.uk
Powered by vBulletin® Version 3.8.11
Copyright ©2000 - 2026, vBulletin Solutions Inc.
All Posts and Content are © Cable Forum