Overclock.net - Overclocking.net
     
 
Home Gallery Reviews Blogs Register Today's Posts Mark Forums Read Members List


Go Back   Overclock.net - Overclocking.net > Software, Programming and Coding > Networking & Security

Reply
 
LinkBack Thread Tools
Old 3 Weeks Ago   #1 (permalink)
AMD Overclocker
 
xXDarkenSoulXx's Avatar
 
amd nvidia

Join Date: Mar 2008
Location: Philadelphia,PA
Posts: 890

Rep: 56 xXDarkenSoulXx is acknowledged by some
Unique Rep: 49
Trader Rating: 7
Default Server security

Ok. Someone's been trying to get into my ftp server by trying passwords with the user name "Administrator". Funny enough the ip is from china(i don't know if the person is using a proxy or not) and I never set a user called Administrator.
Here's part of the log from filezilla:
Quote:
(000002) 10/22/2009 9:20:12 AM - (not logged in) (124.225.128.66)> Connected, sending welcome message...
(000002) 10/22/2009 9:20:12 AM - (not logged in) (124.225.128.66)> 220 FileZilla Server version 0.9.33 beta written by Tim Kosse (Tim.Kosse@gmx.de) Please visit http://sourceforge.
(000002) 10/22/2009 9:20:13 AM - (not logged in) (124.225.128.66)> USER Administrator
(000002) 10/22/2009 9:20:13 AM - (not logged in) (124.225.128.66)> 331 Password required for administrator
(000002) 10/22/2009 9:20:14 AM - (not logged in) (124.225.128.66)> PASS
(000002) 10/22/2009 9:20:14 AM - (not logged in) (124.225.128.66)> 530 Login or password incorrect!
(000002) 10/22/2009 9:20:14 AM - (not logged in) (124.225.128.66)> USER Administrator
(000002) 10/22/2009 9:20:14 AM - (not logged in) (124.225.128.66)> 331 Password required for administrator
(000002) 10/22/2009 9:20:15 AM - (not logged in) (124.225.128.66)> PASS ******
(000002) 10/22/2009 9:20:15 AM - (not logged in) (124.225.128.66)> 530 Login or password incorrect!
......
.......
.....
(000001) 10/28/2009 21:48:17 PM - (not logged in) (61.152.239.49)> USER Administrator
(000001) 10/28/2009 21:48:17 PM - (not logged in) (61.152.239.49)> 331 Password required for administrator
(000001) 10/28/2009 21:48:23 PM - (not logged in) (61.152.239.49)> PASS ***
(000001) 10/28/2009 21:48:23 PM - (not logged in) (61.152.239.49)> 530 Login or password incorrect!
(000001) 10/28/2009 21:48:37 PM - (not logged in) (61.152.239.49)> USER Administrator
(000001) 10/28/2009 21:48:37 PM - (not logged in) (61.152.239.49)> 331 Password required for administrator
(000001) 10/28/2009 21:48:43 PM - (not logged in) (61.152.239.49)> 421 Kicked by Administrator
(000001) 10/28/2009 21:48:43 PM - (not logged in) (61.152.239.49)> disconnected.
As you could see, the hacker was trying to get in from the 22 until I discovered him on the 28.

The only person that knows this address besides me is a friend, and I don't think hes the one behind this.

I have changed a few settings to prevent this in the future like
  • Setting up a new user account
  • Binding the admin interface to my server's internal ip
  • Autoban IP address after 10 failed attempts

Is there anything else that I could do to beef up my security? Chinese hackers are kind of scary. I am using a homeserver.com address, by the way.
__________________
SALESALESALESALESALE!!!

Member of:

Gr33n
Machine
Microsoft Windows Club Windows 7 Fan Club
CM 690 Club
Socket 939 Appreciation Club Mozilla Firefox Club


System: Alive
CPU
AMD Phenom II X4 940 Deneb
Motherboard
Biostar TA790GXB
Memory
OCZ Blade 4GB
Graphics Card
EVGA 9600GT
Hard Drive
WD Black 640GB+Blue 320GB
Sound Card
Xonar D2
Power Supply
Thermaltake Purepower 500W
Case
Cool Master 690
CPU cooling
Scythe Mugen 2
GPU cooling
Zalman VF-1000
OS
Windows 7 Ultimate
Monitor
Samsung 2232BW
xXDarkenSoulXx is offline   Reply With Quote
Old 3 Weeks Ago   #2 (permalink)
New to Overclock.net
 
intel ati

Join Date: Sep 2009
Location: Casa Grande, Arizona
Posts: 385

Rep: 23 scottsee is acknowledged by some
Unique Rep: 18
Trader Rating: 0
Default

Respectivly, thats a very tough question to answer for obvious reasions.

Check metasploit to see if your system is vulnerable to any know exploits, maybee install Untangle? If you're seriously intrested in locking your server(s) up, become a member over at http://www.ethicalhacker.net/ & http://forums.remote-exploit.org/ Download BT3 or BT4 and start pentesting your computers. You could also take some CEH courses If you like it enought... Tough to say without knowing what you have, and how it's configured..

You could always settup a fake box, with the admin enabled not connected to anything, let him gain access to it and see exactly what he's trying to do.. It would be entertaining..
__________________
ATX PSU design standerds (V2.2) recomend psu fans orentation is to draw intake air from the case as an exhaust.

System: Toy
CPU
i7 920 D0 #3919A704
Motherboard
Bloodrage
Memory
6g ocz 1600mhz gold
Graphics Card
Sapphire 4870 1gb
Hard Drive
barricuda 7200.11 1.5T
Power Supply
OCZ StealthxStream 700W
Case
Cool Master RC 690
CPU cooling
Mugen-2
OS
Win7/vista
Monitor
LCD 22" 5MS X223WBD

Last edited by scottsee : 3 Weeks Ago at 01:02 PM
scottsee is offline   Reply With Quote
Old 3 Weeks Ago   #3 (permalink)
4.0 GHz
 
intel ati

Join Date: Sep 2009
Location: Taunton, MA
Posts: 316

Rep: 23 DaClownie is acknowledged by some
Unique Rep: 17
Trader Rating: 0
Default

Quote:
Originally Posted by scottsee View Post
You could always settup a fake box, with the admin enabled not connected to anything, let him gain access to it and see exactly what he's trying to do.. It would be entertaining..

This. It's evil and also informative.
__________________
System: About time...
CPU
Intel Core 2 Duo E8400 @4.5GHz
Motherboard
Gigabyte GA-P45-UD3P
Memory
G.SKILL 4GB (2 x 2GB) DR2 1066
Graphics Card
Sapphire Vapor-X Radeon HD4870 1GB
Hard Drive
WD Black 500GB
Sound Card
Onboard
Power Supply
500W Raidmax
Case
Raidmax Smilodon Extreme Black
CPU cooling
Arctic Cooling Freezer 7 PRO
GPU cooling
Stock
OS
Windows 7 Home Premium
Monitor
ASUS VH226H 21.5" HDMI Widescreen
DaClownie is offline   Reply With Quote
Old 3 Weeks Ago   #4 (permalink)
New to Overclock.net
 
intel ati

Join Date: Sep 2009
Location: Casa Grande, Arizona
Posts: 385

Rep: 23 scottsee is acknowledged by some
Unique Rep: 18
Trader Rating: 0
Default

I doubt it's anything serious, if he's attempting to "get you" he's not doing a good job of beeing stealthy, you'll might want to enable your firewall to log half open awk/syn connections to see if he is silently trying to scan your computer for open ports.

You could always lock down all the ip ranges outside of your local area..
__________________
ATX PSU design standerds (V2.2) recomend psu fans orentation is to draw intake air from the case as an exhaust.

System: Toy
CPU
i7 920 D0 #3919A704
Motherboard
Bloodrage
Memory
6g ocz 1600mhz gold
Graphics Card
Sapphire 4870 1gb
Hard Drive
barricuda 7200.11 1.5T
Power Supply
OCZ StealthxStream 700W
Case
Cool Master RC 690
CPU cooling
Mugen-2
OS
Win7/vista
Monitor
LCD 22" 5MS X223WBD

Last edited by scottsee : 3 Weeks Ago at 01:09 PM
scottsee is offline   Reply With Quote
Old 3 Weeks Ago   #5 (permalink)
New to Overclock.net
 
Marma Duke's Avatar
 
intel ati

Join Date: Jul 2008
Posts: 172

Rep: 9 Marma Duke Unknown
Unique Rep: 7
Trader Rating: 1
Default

I have someone trying to do the same thing, they try 24/7 every 6 minutes with the username administrator and a different password.

Howerver the username 'administrator' doesn't exist so he's not doing so well at it.

I just banned the IP anyhow, dunno why I never did before.
__________________
System: My System
CPU
Q6600 G0
Motherboard
Asus P5K P35
Memory
4GB PC2-6400 (2x2GB)
Graphics Card
HIS 4850 512MB 710/1110
Hard Drive
Hitachi T7K500 320GB + 750GB NAS
Power Supply
EZCool 650Watt Modular
Case
Aspire X-Plorer
CPU cooling
Thermaltake Blue Orb II, Idle 32c
OS
Windows 7 7068 x64
Monitor
19" Hanns G 5ms
Marma Duke is offline   Reply With Quote
Old 3 Weeks Ago   #6 (permalink)
AMD Overclocker
 
xXDarkenSoulXx's Avatar
 
amd nvidia

Join Date: Mar 2008
Location: Philadelphia,PA
Posts: 890

Rep: 56 xXDarkenSoulXx is acknowledged by some
Unique Rep: 49
Trader Rating: 7
Default

Quote:
Originally Posted by scottsee View Post
Respectivly, thats a very tough question to answer for obvious reasions.

Check metasploit to see if your system is vulnerable to any know exploits, maybee install Untangle? If you're seriously intrested in locking your server(s) up, become a member over at http://www.ethicalhacker.net/ & http://forums.remote-exploit.org/ Download BT3 or BT4 and start pentesting your computers. You could also take some CEH courses If you like it enought... Tough to say without knowing what you have, and how it's configured..

You could always settup a fake box, with the admin enabled not connected to anything, let him gain access to it and see exactly what he's trying to do.. It would be entertaining..
Thanks for the tips. Man. That's a lot to learn!

Quote:
Originally Posted by Marma Duke View Post
I have someone trying to do the same thing, they try 24/7 every 6 minutes with the username administrator and a different password.

Howerver the username 'administrator' doesn't exist so he's not doing so well at it.

I just banned the IP anyhow, dunno why I never did before.
__________________
SALESALESALESALESALE!!!

Member of:

Gr33n
Machine
Microsoft Windows Club Windows 7 Fan Club
CM 690 Club
Socket 939 Appreciation Club Mozilla Firefox Club


System: Alive
CPU
AMD Phenom II X4 940 Deneb
Motherboard
Biostar TA790GXB
Memory
OCZ Blade 4GB
Graphics Card
EVGA 9600GT
Hard Drive
WD Black 640GB+Blue 320GB
Sound Card
Xonar D2
Power Supply
Thermaltake Purepower 500W
Case
Cool Master 690
CPU cooling
Scythe Mugen 2
GPU cooling
Zalman VF-1000
OS
Windows 7 Ultimate
Monitor
Samsung 2232BW
xXDarkenSoulXx is offline   Reply With Quote
Old 3 Weeks Ago   #7 (permalink)
PC Gamer
 
yawnbox's Avatar
 
intel ati

Join Date: Aug 2006
Location: Seattle
Posts: 1,131

Rep: 118 yawnbox is acknowledged by manyyawnbox is acknowledged by many
Unique Rep: 110
Hardware Reviews: 3
Trader Rating: 0
Default

fyi

metasploit was sold.
http://jeromiejackson.com/index.php/...etasploit-Beta


check the faqs
http://www.metasploit.com/home/faq


looking forward to the developments.
__________________

System: C0FF3748L3
CPU
2x Intel Xeon X5272
Motherboard
Intel D5400XS Skulltrail
Memory
4x HyperX 1GB FB-DDR2 4-4-4-12
Graphics Card
Asus HD 3870 X2
Hard Drive
4x Hitachi 100GB 7K200 RAID-5
Power Supply
CM RS900
Case
U2-UFO Horizon
OS
Win7 x64 + BitLocker
yawnbox is offline   Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools



All times are GMT -5. The time now is 11:57 PM.


Overclock.net is a Carbon Neutral Site Creative Commons License

Terms of Service / Forum Rules | Privacy Policy | DMCA Info | Advertising | Become an Official Vendor
Copyright © 2009 Shogun Interactive Development. Most rights reserved.
Page generated in 0.23306 seconds with 8 queries