Democratic Underground Latest Greatest Lobby Journals Search Options Help Login
Google

anyone else getting pinged?

Printer-friendly format Printer-friendly format
Printer-friendly format Email this thread to a friend
Printer-friendly format Bookmark this thread
This topic is archived.
Home » Discuss » The DU Lounge Donate to DU
 
datasuspect Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Nov-30-04 08:49 PM
Original message
anyone else getting pinged?
by computers with ip's originating in the herndon, va/washington dc area?

in the past hour or so? excessively?
Printer Friendly | Permalink |  | Top
Avalux Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Nov-30-04 08:50 PM
Response to Original message
1. This may sound stupid (don't laugh)
how do I find out if I am?
Printer Friendly | Permalink |  | Top
 
Cats Against Frist Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Nov-30-04 08:52 PM
Response to Reply #1
3. Yeah -- me too -- I mean -- how do you check?
One time my weatherbug kept getting re-routed to Vicksburgh or Fredericksburgh, VA or something like that. Freaked me out -- and I wondered if someone was occupying my computer remotely or something. Maybe I'm crazy.
Printer Friendly | Permalink |  | Top
 
Tace Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Nov-30-04 08:59 PM
Response to Reply #3
6. Advanced Firewall Software Records All Attempts To Access Your Computer
It also traces the source of the attacks, complete with a map of the source of origination. You'll be surprised to find out how many thousands of entities world-wide are trying to figure out what you are up to. The fun part is that the attacks are directly related to your activity. Cheers.
Printer Friendly | Permalink |  | Top
 
datasuspect Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Nov-30-04 09:02 PM
Response to Reply #6
8. they can watch what i am doing
but i get really tired of the alert feature constantly popping off lately.

guess i'll have to shut that off for awhile.
Printer Friendly | Permalink |  | Top
 
datasuspect Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Nov-30-04 08:53 PM
Response to Reply #1
5. do you have a firewall
that tracks connection attempts?

mine allows me to visually track the source ip. this isn't the first time.

i've been getting back orifice trojan/netbus attacks for a couple of weeks now.

i suppose i should stop downloading jihadi training videos that float around on the internet.
Printer Friendly | Permalink |  | Top
 
Gyre Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Nov-30-04 08:52 PM
Response to Original message
2. Dual firewalls in, no pings yet
Printer Friendly | Permalink |  | Top
 
Xipe Totec Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Nov-30-04 09:02 PM
Response to Reply #2
7. Same here
And my outer firewall is set up to ignore any and all outside pings from anywhere. As far as the outside world is concerned, it's a black hole.
Printer Friendly | Permalink |  | Top
 
flvegan Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Nov-30-04 09:05 PM
Response to Reply #2
11. I'm ping-free tonight. Dual firewalls here, too.
Printer Friendly | Permalink |  | Top
 
Tandalayo_Scheisskopf Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Nov-30-04 08:52 PM
Response to Original message
4. That area...
Is STIFF with servers. Utterly stiff. Huge IT infrastructure of all domain types.

Could be a zombie attack forming.
Printer Friendly | Permalink |  | Top
 
name not needed Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Nov-30-04 09:03 PM
Response to Original message
9. Dammit Kleeb!
:D
Printer Friendly | Permalink |  | Top
 
McKenzie Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Nov-30-04 09:04 PM
Response to Original message
10. you have a static or a dynamic IP?
Edited on Tue Nov-30-04 09:05 PM by McKenzie
if it's dynamic it's possible that someone else has been hacked and you're getting the echo requests. However, even if you have a static IP it's not necessarily a hack attempt, particularly if the IP pinging you is in the US; even a script kiddy running a port scanner would have the savvy to use an anon proxy.

Is it the same port that is being scanned all the time? Is it higher or lower than 1027? Does the port number change incrementally with each probe?

If you have a firewall that operates in stealth mode it'll just drop the packet rather than block it. So if you do you are probably just one of a number of people off a particular netblock that is being scanned repeatedly. If your firewall blocks the request though it'll return as positive to the source of the scan. Which firewall you behind?

If you want to check your security go to--->>>

http://www.grc.com

and run Shields Up.

Printer Friendly | Permalink |  | Top
 
datasuspect Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Nov-30-04 09:15 PM
Response to Reply #10
13. static ip
and full stealth. invisible computer on the network.

still, i get really suspicious with these attempts at intrusion.

how do you trace an ip?

i'd like to see the registered source of some of these addresses.
Printer Friendly | Permalink |  | Top
 
McKenzie Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Nov-30-04 09:24 PM
Response to Reply #13
15. here you go
Edited on Tue Nov-30-04 09:25 PM by McKenzie
there are several online untilities that will reverse an IP and give you the name of the sysadmin and who to contact for abuse of the ISP's services; latter will be abuse @ someisp.com. (see below)

However, I'd be inclined not to mail them. 90+% of firewall alerts are nothing more than legit internet traffic. Bet it's stopped by tomorrow night.

If you want to find out which ISP, network or whatever the scans might be from this is the one I use. If it's a network dozens of people might share one IP. Don't be hasty please; just have a shifty.

http://hexillion.com/
Printer Friendly | Permalink |  | Top
 
John_H Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Nov-30-04 10:59 PM
Response to Reply #10
16. WTF? Who attacked grc.com in 2002?
and why?

"At 2:00 AM, January 11th, 2002, the GRC.COM site
was blasted off the Internet by a new (for us)
distributed denial of service attack.
Perhaps the most startling aspect of this attack was that the apparent source was hundreds of the Internet's "core routers", web servers belonging to yahoo.com, and even a machine with an IP resolving to "gary7.nsa.gov". We appeared to be under attack by hundreds of very powerful and well-connected machines."
Printer Friendly | Permalink |  | Top
 
Cadence Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Nov-30-04 09:12 PM
Response to Original message
12. I get a ton of pings and port scans logged
in my firewall software. What's the specific i.p.?
Printer Friendly | Permalink |  | Top
 
supernova Donating Member (1000+ posts) Send PM | Profile | Ignore Tue Nov-30-04 09:16 PM
Response to Original message
14. I would know if I looked at my logs
but I haven't looked in quite a while.
Printer Friendly | Permalink |  | Top
 
DU AdBot (1000+ posts) Click to send private message to this author Click to view 
this author's profile Click to add 
this author to your buddy list Click to add 
this author to your Ignore list Fri Apr 19th 2024, 01:35 PM
Response to Original message
Advertisements [?]
 Top

Home » Discuss » The DU Lounge Donate to DU

Powered by DCForum+ Version 1.1 Copyright 1997-2002 DCScripts.com
Software has been extensively modified by the DU administrators


Important Notices: By participating on this discussion board, visitors agree to abide by the rules outlined on our Rules page. Messages posted on the Democratic Underground Discussion Forums are the opinions of the individuals who post them, and do not necessarily represent the opinions of Democratic Underground, LLC.

Home  |  Discussion Forums  |  Journals |  Store  |  Donate

About DU  |  Contact Us  |  Privacy Policy

Got a message for Democratic Underground? Click here to send us a message.

© 2001 - 2011 Democratic Underground, LLC