Probeert ICQ mijn server te hacken ?

Pagina: 1
Acties:

  • OgWok
  • Registratie: Augustus 2001
  • Laatst online: 06:25

OgWok

U.N.C.L.E.

Topicstarter
In mijn Linux server log bestanden kwan ik vandaag dit tegen:

code:
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
Nov 11 09:14:23 clarkconnect snort: [1:1287:2] WEB-IIS scripts access [Classification: access to a potentually vulnerable web application] [Priority: 2]: {TCP} 192.168.1.106:1309 -> 205.188.248.89:80
Nov 11 09:14:23 clarkconnect snort: [1:1287:2] WEB-IIS scripts access [Classification: access to a potentually vulnerable web application] [Priority: 2]: {TCP} 192.168.1.106:1311 -> 205.188.248.89:80
Nov 11 09:14:23 clarkconnect snort: [1:1287:2] WEB-IIS scripts access [Classification: access to a potentually vulnerable web application] [Priority: 2]: {TCP} 192.168.1.106:1309 -> 205.188.248.89:80
Nov 11 09:17:39 clarkconnect snort: [1:1287:2] WEB-IIS scripts access [Classification: access to a potentually vulnerable web application] [Priority: 2]: {TCP} 192.168.1.106:1334 -> 205.188.248.89:80
Nov 11 09:17:39 clarkconnect snort: [1:1287:2] WEB-IIS scripts access [Classification: access to a potentually vulnerable web application] [Priority: 2]: {TCP} 192.168.1.106:1335 -> 205.188.248.89:80
Nov 11 09:17:40 clarkconnect snort: [1:1287:2] WEB-IIS scripts access [Classification: access to a potentually vulnerable web application] [Priority: 2]: {TCP} 192.168.1.106:1334 -> 205.188.248.89:80
Nov 11 09:20:07 clarkconnect snort: [1:1287:2] WEB-IIS scripts access [Classification: access to a potentually vulnerable web application] [Priority: 2]: {TCP} 192.168.1.106:1428 -> 64.12.164.153:80
Nov 11 09:20:07 clarkconnect snort: [1:1287:2] WEB-IIS scripts access [Classification: access to a potentually vulnerable web application] [Priority: 2]: {TCP} 192.168.1.106:1429 -> 64.12.164.153:80
Nov 11 09:27:15 clarkconnect snort: [1:1287:2] WEB-IIS scripts access [Classification: access to a potentually vulnerable web application] [Priority: 2]: {TCP} 192.168.1.106:1535 -> 64.12.164.153:80
Nov 11 09:27:15 clarkconnect snort: [1:1287:2] WEB-IIS scripts access [Classification: access to a potentually vulnerable web application] [Priority: 2]: {TCP} 192.168.1.106:1536 -> 64.12.164.153:80
Nov 11 09:27:15 clarkconnect snort: [1:1287:2] WEB-IIS scripts access [Classification: access to a potentually vulnerable web application] [Priority: 2]: {TCP} 192.168.1.106:1535 -> 64.12.164.153:80
Nov 11 09:27:15 clarkconnect snort: [1:1287:2] WEB-IIS scripts access [Classification: access to a potentually vulnerable web application] [Priority: 2]: {TCP} 192.168.1.106:1536 -> 64.12.164.153:80
Nov 11 09:27:15 clarkconnect snort: [1:1287:2] WEB-IIS scripts access [Classification: access to a potentually vulnerable web application] [Priority: 2]: {TCP} 192.168.1.106:1535 -> 64.12.164.153:80
Nov 11 09:28:08 clarkconnect snort: [1:1287:2] WEB-IIS scripts access [Classification: access to a potentually vulnerable web application] [Priority: 2]: {TCP} 192.168.1.106:1629 -> 64.12.164.153:80
Nov 11 09:28:08 clarkconnect snort: [1:1287:2] WEB-IIS scripts access [Classification: access to a potentually vulnerable web application] [Priority: 2]: {TCP} 192.168.1.106:1631 -> 64.12.164.153:80
Nov 11 09:28:09 clarkconnect snort: [1:1287:2] WEB-IIS scripts access [Classification: access to a potentually vulnerable web application] [Priority: 2]: {TCP} 192.168.1.106:1629 -> 64.12.164.153:80
Nov 11 09:28:09 clarkconnect snort: [1:1287:2] WEB-IIS scripts access [Classification: access to a potentually vulnerable web application] [Priority: 2]: {TCP} 192.168.1.106:1631 -> 64.12.164.153:80
Nov 11 09:28:09 clarkconnect snort: [1:1287:2] WEB-IIS scripts access [Classification: access to a potentually vulnerable web application] [Priority: 2]: {TCP} 192.168.1.106:1629 -> 64.12.164.153:80


Beide ip-adressen leiden naar de ICQ website (205.188.248.89 & 64.12.164.153). Ik gebruik geen ICQ. Moet ik mij ernstig zorgen maken en zo ja hoe dit te stoppen ? Suggesties, tips welkom.

MacPro Core i5 750, Mac Mini, hier en daar een verdwaalde pc.....


  • Predator
  • Registratie: Januari 2001
  • Laatst online: 13:26

Predator

Suffers from split brain

PNS -> NT

Gebruik je trillian ?

Everybody lies | BFD rocks ! | PC-specs


  • Erkens
  • Registratie: December 2001
  • Niet online

Erkens

Fotograaf

is dit geen uitgaand verkeer?
naar poort 80, webserver dus?

  • OgWok
  • Registratie: Augustus 2001
  • Laatst online: 06:25

OgWok

U.N.C.L.E.

Topicstarter
Nee trillian gebruik ik niet. Wat kan dat voor mij doen?

MacPro Core i5 750, Mac Mini, hier en daar een verdwaalde pc.....


  • ArthurMorgan
  • Registratie: Januari 2001
  • Niet online
OgWok schreef op 11 november 2002 @ 20:54:
Nee trillian gebruik ik niet. Wat kan dat voor mij doen?
Nee aan trillian heb je niks om dit te voorkomen. Trillian is een IM programma met als onderdeel ICQ, maar sommigen hebben dat niet helemaal door.

Wat het probleem veroorzaakt zie ik alleen niet zo snel, dus we zoeken door :)


Het lijkt iig wel uitgaand verkeer, maar dan zou het nog een trojan kunnen zijn... Alleen uit de gegevens die je nu geeft valt heel weinig af te leiden. Je gebruikt geen ICQbased programma's? ook geen andere instant messengers?

<ik ken trouwens geen trojans die naar de ICQservers connecten :+ >

Never explain yourself to people who are committed to misunderstanding you.


Verwijderd

Op deze pagina's staan ook links naar mirabilis.com(ICQ), kijk maar waarvandaan die icq plaatjes komen. http://online.mirabilis.c...ne.dll?icq=77226351&img=5 over poort 80

  • Erkens
  • Registratie: December 2001
  • Niet online

Erkens

Fotograaf

Verwijderd schreef op 11 november 2002 @ 21:09:
Op deze pagina's staan ook links naar mirabilis.com(ICQ), kijk maar waarvandaan die icq plaatjes komen. http://online.mirabilis.c...ne.dll?icq=77226351&img=5 over poort 80
precies, het was got die jou aan het hacken was >:) :+
tik die ip's maar eens in in je browser:

http://205.188.248.89

http://64.12.164.153

  • OgWok
  • Registratie: Augustus 2001
  • Laatst online: 06:25

OgWok

U.N.C.L.E.

Topicstarter
Inderdaad heeft het te maken met de ICQ pictogrammen die bij de replies staan. Niets aan de hand dus.

MacPro Core i5 750, Mac Mini, hier en daar een verdwaalde pc.....


  • Erkens
  • Registratie: December 2001
  • Niet online

Erkens

Fotograaf

OgWok schreef op 11 november 2002 @ 21:25:
Inderdaad heeft het te maken met de ICQ pictogrammen die bij de replies staan. Niets aan de hand dus.
het is dus een kwestie van logfiles leren lezen, want dan had je gezien dat het uitgaand verkeer was ;)
Pagina: 1