Re: Extremely odd thing with Giganews DMCA?

From: David H. Lipman (DLipman~nospam~_at_Verizon.Net)
Date: 09/19/05


Date: Mon, 19 Sep 2005 20:40:52 GMT

From: "roadburner" <roadburner^at^comcast^dot^net>

|
| I thought of that one to ask him. He will double check it. He thinks not
| because only a very short time elapsed between him blocking and testing. The
| site would had have to go offline for a bit to get assigned a new address.
|
| I registered a new domain with DyDNS and subscribed to the service. Though my
| IP has stayed fixed for the 1 1/2 years I have had cable, who knows. There was
| nothing in writing that said I would have a fixed IP.
|
| I should have added that I am a bit of a privacy buff. The new PC will be
| dedicated to running a Tor node. Likewise, type 1 and 2 remailers. That was
| why I was running Mercury. As I think about it more, I had port forwarded 25
| for Mercury mail and 9001 and 9030 for the Tor node in the Netgear router.
|
| I had the Tor node setup on my primary computer at 198.168.0.2. The primary
| computer has a Symatecs firewall which only allowed connection through 9001
| and 9030 to Tor at 198.168.0.2.
|
| When I reconfigured the network, I set the new PC as 198.168.0.2, the primary
| as 3, and the laptop as 4. I had not installed a software firewall yet.
|
| Possible I could have left myself open for an attack through those ports. In
| the little over a month I had been operating a Tor node, the firewall logs
| showed the Tor ports came under attack. The firewall was configured to
| automatically close connections on a persistent attack which the logs show it
| did on 3 occasions. All Tor nodes, their IPs and their open Dirports and
| Orports are shown at: http://tinyurl.com/898o9
|
| Now I am wondering if I got "hacked" into. Possibility I guess.
|
| Very nice of you to take the time to write the scanning tool. I'll put it to
| use.
|
| Regards,
| roadburner

I looked at that log but I couldn't gleam anything from it.

Posting the URL of that log in a FireWall News Group may be helpful.

-- 
Dave
http://www.claymania.com/removal-trojan-adware.html
http://www.ik-cs.com/got-a-virus.htm


Relevant Pages

  • Re: Extremely odd thing with Giganews DMCA?
    ... for Mercury mail and 9001 and 9030 for the Tor node in the Netgear router. ... I had not installed a software firewall yet. ... Possible I could have left myself open for an attack through those ports. ... Very nice of you to take the time to write the scanning tool. ...
    (alt.computer.security)
  • Re: FTP server Service denial attack
    ... I did check the logs, it only happens for certain time ... Enabling Windows firewall on my server will do any good ... attack is from hijacked computers as the IP is allways ... With a decent IDS or firewall. ...
    (microsoft.public.inetserver.iis.ftp)
  • detecting a DDOS attack
    ... type of attack on our firewalls, though I've never heard of an attack ... behind the firewall, but I don't administer the firewall itself) don't ... I have been examining web server ... logs, and mail logs, and I scrutinize the output from LogWatch. ...
    (RedHat)
  • Re: Network Traffic Problem
    ... The logs pretty ... > much show that it isn't mail traffic, and our gateway router blocks all the ... > stats are showing the attack as well, so it's definitely from the outside). ... If you don't have a firewall, then you need to get one. ...
    (microsoft.public.win2000.networking)
  • Re: Attacks and Logs
    ... by finely scannings the firewall's logs ... If the log is just a record of "net traffic", finding a missed attack is ... firewall knows what it's doing. ...
    (comp.security.firewalls)