Gnutella Forums  

Go Back   Gnutella Forums > Off Topic Discussion > Site Feedback
Register FAQ The Twelve Commandments Members List Calendar Arcade Find the Best VPN Today's Posts

Site Feedback For feedback on Gnutella Forums.
For feedback on a specific Gnutella client, please post in one of the forums above; ie: Current Gnutella Client Forums
Site Feedback is only about issues in reference to this forum, NOT about a gnutella program usage problem


Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old March 29th, 2001
Novicius
 
Join Date: March 28th, 2001
Location: England
Posts: 3
Colin Wills is flying high
Exclamation Someone tried to hack me after gnutting!

This isn't a complaint but just a warning. Please forward to gnutters esp. in the UK.

After using gnut on Linux I had a check of network activity using netstat (I'm a bit paranoid about P2P). I got a lot of this sort of thing:

tcp 1 0 modem-39.kole-tang:2550 212.69.222.50:www CLOSE_WAIT tcp 1 0 modem-39.kole-tang:2550 212.69.222.50:www CLOSE_WAIT tcp 1 0 modem-39.kole-tang:2550 212.69.222.50:www CLOSE_WAIT tcp 1 0 modem-39.kole-tang:2550 212.69.222.50:www CLOSE_WAIT tcp 0 348 modem-39.kole-tang:2695 212.69.222.50:www ESTABLISHED tcp 1 0 modem-39.kole-tang:2550 212.69.222.50:www CLOSE_WAIT tcp 0 361 modem-39.kole-tang:2698 212.69.222.50:www ESTABLISHED tcp 0 357 modem-39.kole-tang:2697 212.69.222.50:www ESTABLISHED tcp 0 0 modem-39.kole-tang:2696 212.69.222.50:www ESTABLISHED

which looks like a hack (I'm not sure).

http://212.69.222.50 turned out to host a homepage for some sort of private investigation company (Midland Administration Service, 6 Somers Road, Rugby, CV22 7DE) which is rather fishy!

Next I had a look with gnut using:

gnut> find 212.69.222.50
Searching the gnutella network for: 212.69.222.50
Press any key to continue
2 responses received.
Current query is '212.69.222.50'
All responses:
1)212.69.222.50.exe
130.214.55.236:99 size:8.00K ref: 0 speed: 512
2)212.69.222.50.exe
192.168.1.10:99 size:8.00K ref: 0 speed: 512

I would advise against downloading and running this!


------------------
Reply With Quote
  #2 (permalink)  
Old March 29th, 2001
Gnutella Veteran
 
Join Date: February 19th, 2001
Location: st paul, MN,
Posts: 117
lightstone is flying high
Post

Looks like that servant wanted to down load a file you had set up for sharing.

On your serch for the IP address( which won't connect you to that host, if thats what you want add it to your connects list) you got exact matchs with the .exe THIS IS A KNOWN WORM. Read :
http://www.securityportal.com/pr/pr.20010228200811.html

[This message has been edited by lightstone (edited 03-29-2001).]
Reply With Quote
  #3 (permalink)  
Old March 29th, 2001
Novicius
 
Join Date: March 28th, 2001
Location: England
Posts: 3
Colin Wills is flying high
Post

When I was looking at netstat I had closed gnut, and I hadn't been sharing anything. I am not infected with the Mandragore Worm as I haven't downloaded or run any EXEs and if I had they wouldn't have done anything as I run Linux.

Certainly that EXE looks like the worm. Perhaps I was just seeing an attempt to contact the worm, which wasn't there. I need to learn to read the netstat output.

------------------


[This message has been edited by Colin Wills (edited 03-30-2001).]

[This message has been edited by Colin Wills (edited 03-30-2001).]
Reply With Quote
  #4 (permalink)  
Old March 30th, 2001
Gnutella Veteran
 
Join Date: February 19th, 2001
Location: st paul, MN,
Posts: 117
lightstone is flying high
Post

Ok, I think you had been on the network and that 'Posts" your IP as a good Host and somebody was trying to establish an "Inbound" connection.

You are right about the worm, the search was telling you what it had found and those host are infected.

"Just because you are paranoid doesn't mean they arn't after you!"
Reply With Quote
  #5 (permalink)  
Old March 30th, 2001
Novicius
 
Join Date: March 28th, 2001
Location: England
Posts: 3
Colin Wills is flying high
Cool

I've downloaded snort (http://www.snort.org/) - just in case.
Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
Is it possible to hack or trace into limewire? vicarious Getting Started Using LimeWire + WireShare 10 July 1st, 2012 07:35 AM
can people hack into my computer?? sharky6665 General Gnutella / Gnutella Network Discussion 2 March 16th, 2007 05:26 PM
there is a HACK out now for XoloX Unregistered Support: General 6 December 3rd, 2001 10:53 PM
Whats this ? Hack ? Unregistered Open Discussion topics 2 August 30th, 2001 12:32 AM


All times are GMT -7. The time now is 03:07 AM.


Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2025, vBulletin Solutions, Inc.
SEO by vBSEO 3.6.0 ©2011, Crawlability, Inc.

Copyright © 2020 Gnutella Forums.
All Rights Reserved.