I just caught a hacker!

Page 2 - Seeking answers? Join the AnandTech community: where nearly half-a-million members share solutions and discuss the latest tech.

Entity

Lifer
Oct 11, 1999
10,090
0
0


<< Task Manager says im running IEXPLORER.EXE

but when i end it.. it just cloes internet explorer... <confused>
>>



iexpLorer.exe vs. iexpiorer.exe...get it?

Rob
 

UberNeuman

Lifer
Nov 4, 1999
16,937
3,087
126
KBrinks - it's named "iexpiore.exe" and not "iexplore.exe"- which is clever because it's so easy to overlook....


damn! I should have been first!!!!

 

spazntwich1

Banned
Apr 22, 2001
839
0
0


<<

<< be on the lookout for "iexpiore.exe" showing in your task manager. >>



because of that comment you've just made every newb dump in his pants.

notice the spelling difference, tools!
>>



Hehe, you're absolutely right, and I hadn't thought about that. I apologize in advance for all of the explorer windows that are going to be killed, in the past or the future.
 

spazntwich1

Banned
Apr 22, 2001
839
0
0


<< wow im such a stupid idiot.. meh

but thanks
>>



Heh, don't worry about it man. We learn by making mistakes.
 

slag

Lifer
Dec 14, 2000
10,473
81
101
No offense, but it sounds like you didnt "catch" anyone as much as you noticed someone attempting to control your computer. Catching someone doing something malicious like that is 100x harder than just finding the person. Good luck getting any isp to do anything about it. I swear those abuse@blahblahblah email addresses dump directly to the deleted items folder.

Joe
 

spazntwich1

Banned
Apr 22, 2001
839
0
0


<< No offense, but it sounds like you didnt "catch" anyone as much as you noticed someone attempting to control your computer. Catching someone doing something malicious like that is 100x harder than just finding the person. Good luck getting any isp to do anything about it. I swear those abuse@blahblahblah email addresses dump directly to the deleted items folder.

Joe
>>



I hear what you're saying about him probably not getting in trouble in real life. However, after disassembling this virus, it turns out it's hard wired to send notices to ONE SPECIFIC USER. If I notify the IRCops on DALnet, they can ban that nickname, rendering all of the infected computers useless.
 

lo5750ul

Senior member
Jul 18, 2001
744
0
76


<< I then used Zonealarm to find out that this specific virus connects me to a DALnet server, to await instructions. >>

My biggest concern is that your ZoneAlarm did not pick it up in the first place and stop your computer from ever connecting! Do you not use ZoneAlarm all the time?
 

spazntwich1

Banned
Apr 22, 2001
839
0
0


<<

<< I then used Zonealarm to find out that this specific virus connects me to a DALnet server, to await instructions. >>

My biggest concern is that your ZoneAlarm did not pick it up in the first place and stop your computer from ever connecting! Do you not use ZoneAlarm all the time?
>>



Nope, I just installed it once I suspected I had this trojan. Believe me, it's not getting uninstalled anytime soon though!
 

n0cmonkey

Elite Member
Jun 10, 2001
42,936
1
0
Just give us the damn username. You cant wait forever. With all the people here there will be someone on who can check.
 

spazntwich1

Banned
Apr 22, 2001
839
0
0


<< Just give us the damn username. You cant wait forever. With all the people here there will be someone on who can check. >>



Check what exactly?

If it makes you all feel better, I've also found his ICQ address. This trojan seems somewhat insidious, in that it also sends an email to somewhere (I'm working on it) with your IP address, open port, and the password, as well as sending a message with your info in it to him on icq.
 

n0cmonkey

Elite Member
Jun 10, 2001
42,936
1
0


<<

<< Just give us the damn username. You cant wait forever. With all the people here there will be someone on who can check. >>



Check what exactly?
>>



Site on irc and wait to get his ip address and uhmmm whatnot



<< If it makes you all feel better, I've also found his ICQ address. This trojan seems somewhat insidious, in that it also sends an email to somewhere (I'm working on it) with your IP address, open port, and the password, as well as sending a message with your info in it to him on icq. >>



Sounds like the typical trojan. The goner virus supposedly sent out msgs over aim too while deleting firewalls and whatnot.
 

SammyBoy

Diamond Member
Jan 7, 2001
3,570
1
0
dude. No one is gonna log into a server with no people in it and get hundreds of messages. thats what bots do. besides...if the bot isnt in there, chances are this is old news and the kid has abandoned it or something. Also...just cuz you think its sloppily done, it doesnt take much to use a proxy.
 

Bozo Galora

Diamond Member
Oct 28, 1999
7,271
0
0
How Goner suspects were tracked down
By John Leyden
Posted: 10/12/2001 at 13:23 GMT

Messages coded into the Goner worm and monitoring of the IRC channel used to control its activities led to the arrest of four suspected Israeli virus writers over the weekend.

One of the actions of Goner, which normally spreads as an infected attached-to-email message, is to install denial of service scripts for the mIRC Internet Relay Chat client. By monitoring the #pentagonex channel used to control the worm's activities, security experts working for DALnet IRC were able to track down its suspected creators.

Emma Monks, a volunteer with DALnet's exploits prevention team, said that after disabling the worm's denial of service abilities, which were believed to be targeted at a rival gang's ISP, DALnet's team set to track down the virus authors.

When activated the Goner worm displays a message, apparently from the author to his friends:

"Pentagone - coded by: suid. tested by ThE_SKuLL and [satan]. greetings to: TraceWar, k9-unit, stef16, ^Reno. Greetings also to nonick2 out there where ever you are."

DALnet records the IP address of anyone setting up an IRC channel which combined with the nicknames featured in the message the virus generates gave investigators vital clues.

Monks explained that by cross references the nicknames of those attempting to control drones from compromised machines on the channel with its database gave the IP addresses of members of the virus writing gang.

This information was turned over to the FBI, which in turn passed it on to the Israeli police. The four teenagers who were arrested on Friday are held in a juvenile detention centre pending a court appearance today and their computers have been seized. If convicted they could face a sentence of between three to five years in jail.

Goner is a fairly simple in its design, but it contains some nasty tricks up its sleeve including an attempt to disable antivirus and personal firewall applications. It spreads by ICQ as well as by Outlook. More details on the worm can be found here. ®
 

mr_cheesy

Senior member
Oct 11, 1999
809
0
76
honestly I believe givingthe culprits IP to users/victims will result in action. best case scenario with an isp- they- delete his account. if it was his in the first place.
 

spazntwich1

Banned
Apr 22, 2001
839
0
0


<< dude. No one is gonna log into a server with no people in it and get hundreds of messages. thats what bots do. besides...if the bot isnt in there. >>



Nobody except this kid apparently. Just last night at about 10:20, he logged onto DALnet for a short period of time. I've got him on my notify list with mIRC set to auto-whois him. The previous time he had logged on, he was using an AOL ip, and he was using another one last night.

With his IP, I did a quick portscan of his computer. He's running an FTP server from his computer, and the sign on message is "Welcome to Satanz Crewz FTP. Don't hammer it or you will get banned. Abuse it and lose it".

So yes, this kid is amazingly sloppy. I wouldn't even be suprised if the AOL account he was using was his own legit one. Now all that's left is for me to call AOL with his ip and logon time. If they don't do anything, I'm going to bring a lawsuit against them.



<< chances are this is old news and the kid has abandoned it or something. >>



Nope. I mostly noticed that I had this trojan after I came to my computer saturday morning and found out I had been uploading to... somewhere all night. This kid has stolen SOMETHING from my computer, which means he has also broken into it. I'm contacting AOL today. If they don't do anything...
 

n0cmonkey

Elite Member
Jun 10, 2001
42,936
1
0
I think we all took the wrong approach here. Instead of praising this guy for catching the twerp, I think we should be smacking him on the head for letting a script kiddiot get into his machine.. :/
 

spazntwich1

Banned
Apr 22, 2001
839
0
0


<< HOw did he get into your system anyways? >>



I explained it in an earlier post.

As for you n0cmonkey, it was dumb for me to get the trojan on my comp, but don't you think it's a good thing to actually get this script kiddie off the internet? Or do you not care about the hundreds of computers infected and vulnerable to this kid?

I think you're just angry I didn't give you the nick of the guy so YOU could go and jack all of the compromised computers.
 

n0cmonkey

Elite Member
Jun 10, 2001
42,936
1
0


<<

<< HOw did he get into your system anyways? >>



I explained it in an earlier post.

As for you n0cmonkey, it was dumb for me to get the trojan on my comp, but don't you think it's a good thing to actually get this script kiddie off the internet? Or do you not care about the hundreds of computers infected and vulnerable to this kid?

I think you're just angry I didn't give you the nick of the guy so YOU could go and jack all of the compromised computers.
>>



If you get him off the internet I will kiss your ass. It wont happen. The ISPs do not care, the police wont be able to do anything about it, the FBI wont care until he does THOUSANDS of dollars worth of damage. Best thing you could do is take the compromised machines and format them for the owners. I think you have bigger problems to worry about than trying to get your dick sucked over this one. You let him have your machine, however termporary it was, make sure it doesnt happen again and dont think anyone will do anything about some 13yo script kiddiot.
 
sale-70-410-exam    | Exam-200-125-pdf    | we-sale-70-410-exam    | hot-sale-70-410-exam    | Latest-exam-700-603-Dumps    | Dumps-98-363-exams-date    | Certs-200-125-date    | Dumps-300-075-exams-date    | hot-sale-book-C8010-726-book    | Hot-Sale-200-310-Exam    | Exam-Description-200-310-dumps?    | hot-sale-book-200-125-book    | Latest-Updated-300-209-Exam    | Dumps-210-260-exams-date    | Download-200-125-Exam-PDF    | Exam-Description-300-101-dumps    | Certs-300-101-date    | Hot-Sale-300-075-Exam    | Latest-exam-200-125-Dumps    | Exam-Description-200-125-dumps    | Latest-Updated-300-075-Exam    | hot-sale-book-210-260-book    | Dumps-200-901-exams-date    | Certs-200-901-date    | Latest-exam-1Z0-062-Dumps    | Hot-Sale-1Z0-062-Exam    | Certs-CSSLP-date    | 100%-Pass-70-383-Exams    | Latest-JN0-360-real-exam-questions    | 100%-Pass-4A0-100-Real-Exam-Questions    | Dumps-300-135-exams-date    | Passed-200-105-Tech-Exams    | Latest-Updated-200-310-Exam    | Download-300-070-Exam-PDF    | Hot-Sale-JN0-360-Exam    | 100%-Pass-JN0-360-Exams    | 100%-Pass-JN0-360-Real-Exam-Questions    | Dumps-JN0-360-exams-date    | Exam-Description-1Z0-876-dumps    | Latest-exam-1Z0-876-Dumps    | Dumps-HPE0-Y53-exams-date    | 2017-Latest-HPE0-Y53-Exam    | 100%-Pass-HPE0-Y53-Real-Exam-Questions    | Pass-4A0-100-Exam    | Latest-4A0-100-Questions    | Dumps-98-365-exams-date    | 2017-Latest-98-365-Exam    | 100%-Pass-VCS-254-Exams    | 2017-Latest-VCS-273-Exam    | Dumps-200-355-exams-date    | 2017-Latest-300-320-Exam    | Pass-300-101-Exam    | 100%-Pass-300-115-Exams    |
http://www.portvapes.co.uk/    | http://www.portvapes.co.uk/    |