Forum Moderators: DixonJones

Message Too Old, No Replies

Tracking down a hacker

how do I proceed?

         

the_nerd

7:40 am on Oct 4, 2004 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



Hi,

just found hundreds of attempts to hack my server (all kinds of "funny" pages like "../system32/cmd.exe ...." and the like) All from the the same IP. Ping and tracert won't show anything.

Does anybody have experience with this kind of stuff? How do I find out who owns this IP?

mat

8:06 am on Oct 4, 2004 (gmt 0)

10+ Year Member



For all sorts of IP stuff go somewhere like samspade ... but, in this case, I wouldn't waste your time. That 'attack' is a bog-standard code-red type affair, and is unlikely to be knowingly aimed at you - it'll just be some zombie-infected box doing port scanning.

the_nerd

9:12 am on Oct 4, 2004 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



Thanks Matt,

the Server is patched up, giving back a 404 to every single "attempt", so I'll just sit back.

Maybe a little zapper would be nice to switch off those ghost-boxes remotely ;-)