PDA

View Full Version : [ubuntu] 8:10 Intrepid, Help hack attempt!


KEE
August 16th, 2009, 01:38 AM
this ips are trying and breaking my firestarter fire wall Time:Aug 15 21:36:24 Direction: Unknown In:eth0 Out: Port:135 Source:96.54.7.229 Destination:96.54.115.44 Length:52 TOS:0x00 Protocol:TCP Service:DCOM-scm
Time:Aug 15 21:36:37 Direction: Unknown In:eth0 Out: Port:445 Source:96.54.116.145 Destination:96.54.115.44 Length:52 TOS:0x00 Protocol:TCP Service:Microsoft-ds
Time:Aug 15 21:36:40 Direction: Unknown In:eth0 Out: Port:445 Source:96.54.116.145 Destination:96.54.115.44 Length:52 TOS:0x00 Protocol:TCP Service:Microsoft-ds
Time:Aug 15 21:37:11 Direction: Unknown In:eth0 Out: Port:445 Source:84.110.152.27 Destination:96.54.115.44 Length:48 TOS:0x00 Protocol:TCP Service:Microsoft-ds
Time:Aug 15 21:37:14 Direction: Unknown In:eth0 Out: Port:445 Source:84.110.152.27 Destination:96.54.115.44 Length:48 TOS:0x00 Protocol:TCP Service:Microsoft-ds
Time:Aug 15 21:38:59 Direction: Unknown In:eth0 Out: Port:135 Source:96.49.178.54 Destination:96.54.115.44 Length:64 TOS:0x00 Protocol:TCP Service:DCOM-scm
Time:Aug 15 21:39:02 Direction: Unknown In:eth0 Out: Port:135 Source:96.49.178.54 Destination:96.54.115.44 Length:64 TOS:0x00 Protocol:TCP Service:DCOM-scm
Time:Aug 15 21:45:52 Direction: Unknown In:eth0 Out: Port:135 Source:96.54.7.229 Destination:96.54.115.44 Length:52 TOS:0x00 Protocol:TCP Service:DCOM-scm
Time:Aug 15 21:46:45 Direction: Unknown In:eth0 Out: Port:135 Source:96.54.12.184 Destination:96.54.115.44 Length:52 TOS:0x00 Protocol:TCP Service:DCOM-scm
Time:Aug 15 21:46:45 Direction: Unknown In:eth0 Out: Port:445 Source:96.54.12.184 Destination:96.54.115.44 Length:52 TOS:0x00 Protocol:TCP Service:Microsoft-ds
Time:Aug 15 21:49:15 Direction: Unknown In:eth0 Out: Port:445 Source:96.54.12.184 Destination:96.54.115.44 Length:52 TOS:0x00 Protocol:TCP Service:Microsoft-ds
Time:Aug 15 21:51:12 Direction: Unknown In:eth0 Out: Port:445 Source:96.52.201.135 Destination:96.54.115.44 Length:64 TOS:0x00 Protocol:TCP Service:Microsoft-ds
Time:Aug 15 21:51:15 Direction: Unknown In:eth0 Out: Port:445 Source:96.52.201.135 Destination:96.54.115.44 Length:64 TOS:0x00 Protocol:TCP Service:Microsoft-ds
Time:Aug 15 21:52:18 Direction: Unknown In:eth0 Out: Port:445 Source:96.54.97.254 Destination:96.54.115.44 Length:48 TOS:0x00 Protocol:TCP Service:Microsoft-ds
Time:Aug 15 21:55:19 Direction: Unknown In:eth0 Out: Port:135 Source:96.54.7.229 Destination:96.54.115.44 Length:52 TOS:0x00 Protocol:TCP Service:DCOM-scmTime:Aug 15 21:56:06 Direction: Unknown In:eth0 Out: Port:445 Source:96.54.3.153 Destination:96.54.115.44 Length:64 TOS:0x00 Protocol:TCP Service:Microsoft-ds
Time:Aug 15 21:56:13 Direction: Unknown In:eth0 Out: Port:445 Source:96.54.72.84 Destination:96.54.115.44 Length:52 TOS:0x00 Protocol:TCP Service:Microsoft-ds
Time:Aug 15 21:56:13 Direction: Unknown In:eth0 Out: Port:135 Source:96.54.72.84 Destination:96.54.115.44 Length:52 TOS:0x00 Protocol:TCP Service:DCOM-scm
Time:Aug 15 21:57:03 Direction: Unknown In:eth0 Out: Port:445 Source:79.33.244.60 Destination:96.54.115.44 Length:52 TOS:0x00 Protocol:TCP Service:Microsoft-ds
Time:Aug 15 21:57:06 Direction: Unknown In:eth0 Out: Port:445 Source:79.33.244.60 Destination:96.54.115.44 Length:52 TOS:0x00 Protocol:TCP Service:Microsoft-ds
Time:Aug 15 21:57:22 Direction: Unknown In:eth0 Out: Port:445 Source:96.54.12.184 Destination:96.54.115.44 Length:52 TOS:0x00 Protocol:TCP Service:Microsoft-ds
Time:Aug 15 21:57:25 Direction: Unknown In:eth0 Out: Port:445 Source:96.54.12.184 Destination:96.54.115.44 Length:52 TOS:0x00 Protocol:TCP Service:Microsoft-ds
Time:Aug 15 21:57:33 Direction: Unknown In:eth0 Out: Port:445 Source:96.54.116.145 Destination:96.54.115.44 Length:52 TOS:0x00 Protocol:TCP Service:Microsoft-ds
Time:Aug 15 22:00:48 Direction: Unknown In:eth0 Out: Port:135 Source:96.251.161.95 Destination:96.54.115.44 Length:64 TOS:0x00 Protocol:TCP Service:DCOM-scm
Time:Aug 15 22:00:50 Direction: Unknown In:eth0 Out: Port:135 Source:96.251.161.95 Destination:96.54.115.44 Length:64 TOS:0x00 Protocol:TCP Service:DCOM-scm
Time:Aug 15 22:01:22 Direction: Unknown In:eth0 Out: Port:445 Source:96.54.116.145 Destination:96.54.115.44 Length:52 TOS:0x00 Protocol:TCP Service:Microsoft-ds
Time:Aug 15 22:01:25 Direction: Unknown In:eth0 Out: Port:445 Source:96.54.116.145 Destination:96.54.115.44 Length:52 TOS:0x00 Protocol:TCP Service:Microsoft-dsTime:Aug 15 22:14:15 Direction: Unknown In:eth0 Out: Port:135 Source:96.54.7.229 Destination:96.54.115.44 Length:52 TOS:0x00 Protocol:TCP Service:DCOM-scm
Time:Aug 15 22:18:17 Direction: Unknown In:eth0 Out: Port:445 Source:96.54.3.153 Destination:96.54.115.44 Length:64 TOS:0x00 Protocol:TCP Service:Microsoft-ds
Time:Aug 15 22:18:38 Direction: Unknown In:eth0 Out: Port:445 Source:96.54.12.184 Destination:96.54.115.44 Length:52 TOS:0x00 Protocol:TCP Service:Microsoft-ds
Time:Aug 15 22:18:40 Direction: Unknown In:eth0 Out: Port:445 Source:96.54.12.184 Destination:96.54.115.44 Length:52 TOS:0x00 Protocol:TCP Service:Microsoft-ds
Time:Aug 15 22:19:38 Direction: Unknown In:eth0 Out: Port:445 Source:93.81.8.182 Destination:96.54.115.44 Length:48 TOS:0x00 Protocol:TCP Service:Microsoft-ds
Time:Aug 15 22:19:41 Direction: Unknown In:eth0 Out: Port:445 Source:93.81.8.182 Destination:96.54.115.44 Length:48 TOS:0x00 Protocol:TCP Service:Microsoft-ds
Time:Aug 15 22:21:48 Direction: Unknown In:eth0 Out: Port:445 Source:195.13.176.6 Destination:96.54.115.44 Length:48 TOS:0x00 Protocol:TCP Service:Microsoft-ds
Time:Aug 15 22:21:51 Direction: Unknown In:eth0 Out: Port:445 Source:195.13.176.6 Destination:96.54.115.44 Length:48 TOS:0x00 Protocol:TCP Service:Microsoft-ds
Time:Aug 15 22:23:42 Direction: Unknown In:eth0 Out: Port:135 Source:96.54.7.229 Destination:96.54.115.44 Length:52 TOS:0x00 Protocol:TCP Service:DCOM-scm
Time:Aug 15 22:29:54 Direction: Unknown In:eth0 Out: Port:445 Source:116.111.208.124 Destination:96.54.115.44 Length:52 TOS:0x00 Protocol:TCP Service:Microsoft-ds
Time:Aug 15 22:29:57 Direction: Unknown In:eth0 Out: Port:445 Source:116.111.208.124 Destination:96.54.115.44 Length:52 TOS:0x00 Protocol:TCP Service:Microsoft-ds
Time:Aug 15 22:33:07 Direction: Unknown In:eth0 Out: Port:135 Source:96.54.7.229 Destination:96.54.115.44 Length:52 TOS:0x00 Protocol:TCP Service:DCOM-scm
Time:Aug 15 22:33:35 Direction: Unknown In:eth0 Out: Port:445 Source:201.250.215.196 Destination:96.54.115.44 Length:48 TOS:0x00 Protocol:TCP Service:Microsoft-ds
Time:Aug 15 22:33:38 Direction: Unknown In:eth0 Out: Port:445 Source:201.250.215.196 Destination:96.54.115.44 Length:48 TOS:0x00 Protocol:TCP Service:Microsoft-ds
Time:Aug 15 22:34:30 Direction: Unknown In:eth0 Out: Port:135 Source:96.48.204.226 Destination:96.54.115.44 Length:64 TOS:0x00 Protocol:TCP Service:DCOM-scm
Time:Aug 15 22:34:36 Direction: Unknown In:eth0 Out: Port:445 Source:78.48.237.100 Destination:96.54.115.44 Length:52 TOS:0x00 Protocol:TCP Service:Microsoft-ds
Time:Aug 15 22:34:36 Direction: Unknown In:eth0 Out: Port:445 Source:78.48.237.100 Destination:96.54.115.44 Length:52 TOS:0x00 Protocol:TCP Service:Microsoft-ds every time these ips attack my firewall. pidgin says it sign on another computer or devise. Please Help!!! I keep changing my account information but i dont know how long it will last

KEE
August 16th, 2009, 02:14 AM
man is there anything I can do??? I have aliases that's changed too every now and then. it changes to like just my email. is it a bug? haha i doubt it. it wouldn't say it was logged in on another computer or devise. need help PLEEASSE and thank you . im like racing around the Internet changing account information and such along with passwords.

lisati
August 16th, 2009, 02:16 AM
http://ubuntuforums.org/showthread.php?t=919472

KEE
August 16th, 2009, 02:26 AM
http://ubuntuforums.org/showthread.php?t=919472

i i tried that once but its not working well with my pc stuff =/ it used to say, before I removed it!, snort could not start when I tried turn it on =/ its that the only thing I can do? I wish i can just banned these ips from my pc that would be kool. sigh

http://ubuntuforums.org/showthread.php?t=1116140

KEE
August 16th, 2009, 02:34 AM
sorry for the spelling ...kinda tired i have been at this all day..this person or persons is like reading my keys or like seeing what im seeing on my pc... i changed some stuff that i would only know like passwords questions and address, passwords and even emergency emails but its still says this email messenger has sign on another computer or devise...

KEE
August 16th, 2009, 02:59 AM
is there an anti virus or anti anti hack for ubuntu? like Avira AntiVir Control Center or block ice???

lisati
August 16th, 2009, 03:01 AM
is there an anti virus or anti anti hack for ubuntu? like Avira AntiVir Control Center or block ice???

Check out the stickies (http://ubuntuforums.org/forumdisplay.php?f=338)

KEE
August 16th, 2009, 03:03 AM
Check out the stickies (http://ubuntuforums.org/forumdisplay.php?f=338)

yeah those dont work very well...is that all ?

sasho_zl
August 16th, 2009, 05:07 AM
First paste here the result of that command: lsof -i -n -P
This could tell us if the hacker is using specific service.
Second - remove Firestarter! It's old and unsupported and it could even be the reason the hacker got in in a first place. You can install Shorewall or gufw. Instructions for installing the most recent Shorewall firewall I have wrote here - http://ubuntuforums.org/showthread.php?p=7736369#post7736369

Just make sure to disconnect from the internet when you are performing the installation.

cprofitt
August 16th, 2009, 11:46 AM
Here (https://help.ubuntu.com/community/Uncomplicated_Firewall_ufw) is a firewall how-to; though I am not sure if it will help.

tomasrey88
August 17th, 2009, 01:10 PM
if ur not runnin a server, then just turn off, and turn on again awhile later and the ip address is different. if you have a fixed ip, call your isp and have them change your ip.

if that doesn't work or if you are running a server, then block his ip with your firewall. type in his ip address in your block list on your firewall.

if that doesn't work, use several other computers and repeatedly ping him. This "may" keep his system busy enough so he can't bother you. Notice that I said "may" and not "will".

BTW, I invite you to take a look at my question:
http://ubuntuforums.org/showthread.php?t=1242310

Enjoy,
:guitar: