Forum Moderators: open

Message Too Old, No Replies

Help Needed Dealing With A Persistent Hacker

         

SG_Slinger

11:37 pm on Aug 25, 2007 (gmt 0)

10+ Year Member



I was checking my business server's IIS errors logs when I ran across the following error:

2007-05-19 08:21:10 00.000.000.00 2243 00.000.000.000 80 HTTP/1.1 GET /w00tw00t.at.ISC.SANS.DFind:) 400 - Hostname -

Additional information about the those responsible for the hack attempts are as follows (retrieved from #*$!):

CustName: ----------------(hidden by me)
Address: Private Address
City: Plano
StateProv: TX
PostalCode: 75075
Country: US
RegDate: 2005-08-27
Updated: 2005-08-27

Apparently this person was trying to use the dfind hacker tool to find vulnerabilities on my server. The IP address belongs to AT&T Yahoo; and I've already contacted them by email. I believe that subsequent hack attempts have originated from this IP, however, the IP address has been masked by the use of proxies. I think that this may be someone I know because the IP is only about an hours drive from me. I'm starting to suspect a disgruntled former client who has friends living where that IP's from.

Has anyone here had any similar experiences? What do you think AT&T Yahoo's response will be? Is there anything else I can do or should not do?

I am also considering reimaging my server because of system issues but I am concerned that would erase any information needed for investigative purposes. I have saved my log files, though, on a CD but I'm thinking that AT&T Yahoo or whoever investigates this needs the server as it is.

jdMorgan

1:44 am on Aug 26, 2007 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



This has been going on literally for years... The same broken client sending invalid requests (Note your server's 400-Bad Request response). The best approach for sanity retention is probably just to ignore this.

And this is not a "hacker" -- A hacker (or more properly, "cracker") is someone who gets into your server and modifies or deletes files, an activity you will never see in your HTTP (Web access) log files. This is just a log-file polluter who sends invalid requests that will never successfully get content from any properly-configured server.

The address in Plano, Texas (not far from here) is a local network operations center for SBC/Yahoo's ISP services. So this is just some guy (or probably his zombied computer) who uses SBC/Yahoo as his ISP.

Jim

jdMorgan

1:59 am on Aug 26, 2007 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



Checking my logs, I see two of these w00tw00t's today, both from networks in The Netherlands.

Oh, the "ISC at SANS" bit in the User-agent string is the Internet Storm Center [isc.sans.org] at the SANS (SysAdmin, Audit, Network, Security) Institute, a major center for tracking Web exploits.

Someone probably got mad at them years ago, and turned this stupid client loose to get 'revenge' on them...

Jim

SG_Slinger

3:52 am on Aug 26, 2007 (gmt 0)

10+ Year Member



Thanks Jim, I guess I may be getting a little paranoid after the last server I was on was bombarded by real hackers using dictionary attacks trying to crack user passwords and such.

I had read somewhere on the SANS site, though, about the dfind tool and how it's used by hackers to case servers. Also, the CustomerName portion of the info I posted actually has a customer name; I'm thinking that it's maybe some sort of dedicated business server going through the local network operations center system. When I visit the IP through a browser I also get an under construction page.

GaryK

4:04 am on Aug 26, 2007 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



This is what you might have read at SANS:
[isc.sans.org...]
:)

SG_Slinger

6:42 am on Aug 26, 2007 (gmt 0)

10+ Year Member



That's what I read... also, the under construction page residing at the IP where this is coming from is on... IIS?

GaryK

4:00 pm on Aug 26, 2007 (gmt 0)

WebmasterWorld Senior Member 10+ Year Member



I can't find it on WebmasterWorld anymore but at one time there was a tool to help us look at the header for each page on a website. That will tell you what web server is being used. I'm sure the tool still exists so hopefully someone will post a link to it. You can also reply to the sticky I sent you asking for the IP Address so I can check the header for you. :)