Page 2 of 3 FirstFirst 123 LastLast
Results 11 to 20 of 21

Thread: I want to "surprise" this hacker...

  1. #11
    Senior Member Ouroboros's Avatar
    Join Date
    Nov 2001
    Location
    Superior, WI USA
    Posts
    636

    yep

    Yep...just tried to help, and I just like playing around with that program

    Ouroboros
    "entia non sunt multiplicanda praeter necessitatem"

    "entities should not be multiplied beyond necessity."

    -Occam's Razor


  2. #12
    Senior Member
    Join Date
    Aug 2001
    Posts
    168
    can i play to your wargames!
    \"The more you ignore me... the closer i get!\"

  3. #13
    Senior Member
    Join Date
    Jan 2002
    Posts
    132

    I'm going through the same thing ...

    I host a webserver and quite a few routers here at home. As I work professionally with routers, I've come to understand that packet-level filtering, while great and granular, is not everything.

    A couple days ago, I decided to check my access_log and secure_log on my webserver ... I was getting *plenty* of script attempts. Nothing that would do anything against me, but annoying nonetheless. I wrote to root@<isp> and abuse@<isp> and waited ... and waited ... and waited. I then found a template that went something like this:

    > I would like to know if anyone has come up with a formal
    > message to send to the netblock owners, something that may
    > hold up in court if ever need be.
    >

    email:

    abuse@XXXXX - Without prejudice I submit to you this Unsolicited Commercial E-Mail is from your user XXXX. UCE is unappreciated because it costs my provider (and ultimately myself) money to process just like an unsolicited FAX. Please look into this. Thank you.

    general:

    Without prejudice: I suspect you are the culprit of blah blah blah


    It seems that this would be the best way to go.

    HOWEVER ... I am working on a Perl script (Perl wizard I am not!) to:
    * Auto-ban the offending IP from my network (both from the box and write a DENY entry to my border router,
    * Post their IP and the corresponding attack attempt text to a "wall of shame" on my webpage,
    * Send an e-mail to "abuse@<ISP>",
    * Activate a hold-down timer on above such that if a response isn't had w/in 48 hours, it'll e-mail "abuse@<ISP>" AND "abuse@<1 hop closer to myself from ISP>" ... continue working down the line until it hits abuse@localhost ...

    And I would imagine that this *should* stop quite a few script kiddies and/or rootkit'ers from impacting my network. Of course, this all depends on writing the proper heuristics to catch them in the first place!

    Anyway - what someone said initially, not to do anything illegal against them, is correct. I'm sure that ISP's have better (and more granular!) logging facilities than someone on a Windows box. And I'm sure they'd be happy to utilize this if a user, say the next user who picked up that IP from the DHCP server ... or the REAL owner of the IP that was spoofed, complained about YOU hitting their box. Much better for you to give the offending ISP a copy of the associated logs, tell them to cross-reference time with their RADIUS server, and be done with it.

    Hopefully this will help someone.

    ~N~

  4. #14
    Senior Member
    Join Date
    Jan 2002
    Posts
    132

    To add to what I said before ...

    Admins can also be really pissy. I just had one write me back - he took my "I'm looking to ban your user from my network" as "I will attack your user". <sigh> I guess I'll never never ever try to help out trib.com again.

    Anyway - definitely don't look to attack the cracker/hacker/guy who's had his box rooted - it'll end up badly.

    ~N~

  5. #15
    Senior Member
    Join Date
    Jan 2002
    Posts
    218
    Yes, I suppose the key is to be polite yet persistent at the same time when dealing with ISP's. Let them know you know your stuff, and you just want their coporation in dealing with a pest. Just do not do anything that would aloow them to hold you liable for anything.

  6. #16
    Junior Member
    Join Date
    Dec 2001
    Posts
    8

    Thumbs up Cool idea nietzsche!

    Your program idea in Perl seems to be an great idea nietzsche!!
    HOWEVER ... I am working on a Perl script (Perl wizard I am not!) to:
    * Auto-ban the offending IP from my network (both from the box and write a DENY entry to my border router,
    * Post their IP and the corresponding attack attempt text to a "wall of shame" on my webpage,
    * Send an e-mail to "abuse@<ISP>",
    * Activate a hold-down timer on above such that if a response isn't had w/in 48 hours, it'll e-mail "abuse@<ISP>" AND "abuse@<1 hop closer to myself from ISP>" ... continue working down the line until it hits abuse@localhost ...
    I would be very glad if you send me any news about the development of your Perl script!!!
    Pi.[2]=
    11. 00100100 00111111 01101010 10001000 10000101 10100011 00001000 11010011 00010011 00011001 10001010 00101110 00000011 01110000 01110011 01000100 10100100 00001001 00111000 00100010 00101001 10011111 00110001 11010000 00001000 00101110 11111010 10011000 11101100 01001110 01101100 10001001........

  7. #17
    Senior Member
    Join Date
    Jan 2002
    Posts
    132

    Perl script

    Your program idea in Perl seems to be an great idea nietzsche!!
    Thanks, I think so too.

    I would be very glad if you send me any news about the development of your Perl script!!!
    Heh - I'll keep everyone informed and make it available; there's an obvious need for it, as I'm finding. HOWEVER, I am neither a professional software engineer NOR someone with loads of time. But I do hope to have something done by the end of the week - after that, school starts up again and development time will be reduced.

    Anyway - I'll keep everyone posted on this if/when it gets done!

    ~N~

  8. #18
    Junior Member
    Join Date
    Dec 2001
    Posts
    8

    Post Perl Script

    I dont want to brag, but I do no some about perl programing so if you don't mind I would like to TRY to maybe enhance and develop your Perl since you will not have much spare-time for it!!
    Pi.[2]=
    11. 00100100 00111111 01101010 10001000 10000101 10100011 00001000 11010011 00010011 00011001 10001010 00101110 00000011 01110000 01110011 01000100 10100100 00001001 00111000 00100010 00101001 10011111 00110001 11010000 00001000 00101110 11111010 10011000 11101100 01001110 01101100 10001001........

  9. #19
    Senior Member
    Join Date
    Jan 2002
    Posts
    132

    Perl script

    I'd happily accept aid. Seeing as how I've not worked at all with Perl before the weekend. I'll roll something crude to teach myself about Perl a bit and do the bare minimum ... and then I'll turn it loose to be modified, improved, etc.

  10. #20
    Junior Member
    Join Date
    Jul 2001
    Posts
    15

    Talking

    Contact your ISP and get all inbound traffic from his IP address blocked. They should do it. I have done it myself.
    - Voodoo

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •