Just caught a CalPoly machine scanning for a backdoor... UPDATE!

WoundedWallet

Platinum Member
Oct 9, 1999
2,325
0
0
I usually receive many scans on my DSL connection, but this one came in for my earthlink dial-up.

It was for "Backdoor-g-1 (1243)" service and the remote address was for a machine inside CalPoly Pomona 134.71.52.100

If you want to see here is the print screen

I know there is a site collecting IPs for offending script kiddies, but they are a pain to make a report.

I think I should contact CalPoly to tell they have a Zombie. But should I contact anybody else? If so who?
 

jimmygates

Platinum Member
Sep 4, 2000
2,134
2
81
Cow Poly Pomona...heh I use to live 5 minutes away from there...



See if you can find the housing director and contact him.


P.S. You live anywhere near Walnut? I grew up there


-Jimbo
 

WoundedWallet

Platinum Member
Oct 9, 1999
2,325
0
0
I just sent an email to the Domain Name coordinator and to the President. I figure once he sees that the president was CCed, he will try to do something about it.

No I don't live near Pomona, I'm on the west side.
 

amnesiac

Lifer
Oct 13, 1999
15,781
1
71
Nice. Keep us posted on the outcome of this. I'd like to see that retard wannabe h4x0r caught. Stupid nerds don't have anything better to do than poke around in other peoples stuff.. sheesh..
 

bUnMaNGo

Senior member
Feb 9, 2000
964
0
0
heh I help run a linux server at nubi-net (a pc gaming center in Rowland Heights) and some fegs decided it would be fun to run an rcon exploit on our server. now I have 100's of logs full of this:

L 02/04/2001 - 20:09:02: Bad Rcon from "24.41.43.39:27001":"(rcon "ADT""sayADT&quot"
L 02/04/2001 - 20:09:02: Bad Rcon from "24.41.43.39:27001":"(rcon "ADU""sayADU&quot"
L 02/04/2001 - 20:09:02: Bad Rcon from "24.41.43.39:27001":"(rcon "ADV""sayADV&quot"
L 02/04/2001 - 20:09:02: Bad Rcon from "24.41.43.39:27001":"(rcon "ADW""sayADW&quot"

needless to say, I did an nslookup on it, and low and behold- a Charter/Earthlink cable modem subscriber in Walnut or West Covina. I emailed abuse@earthlink.net but so far all I've gotten is an autoresponse. btw jimmygates I used to live in Diamond Bar Well I still do but I go to school up in Santa Cruz
 

WoundedWallet

Platinum Member
Oct 9, 1999
2,325
0
0
I finally received a very laconic answer from some unthankfull bureaucrat.

"this is a student in one of our dorms. I received a number of reports this morning of suspicious activity originating from this address, and the connection has been deactivated pending further investigation."

One would think that a CalPoly student would know better... But then maybe not, if the answer I got represents the school's philosophy.
 

Deicide

Banned
Mar 5, 2000
376
0
0
What the hell do you want them to do? Shoot the kid? Cutting off his net connection sounds like a good solution to me, they're not going to kick him out for scanning somebody.
 

PattySmear

Banned
Feb 4, 2001
84
0
0


<< &quot;this is a student in one of our dorms. I received a number of reports this morning of suspicious activity originating from this address, and the
connection has been deactivated pending further investigation.&quot;
>>




Hah talk about inflated ego.

Realize that your lone system barely registers a blip on their radar screen.
 

Cheapster

Senior member
Dec 31, 2000
238
0
0
I had a similiar problem but couldn't get a good response after emailing the coordinator about the abuse.
 

Napalm381

Platinum Member
Oct 10, 1999
2,724
0
0


<< Hah talk about inflated ego >>

It has nothing to do with his ego. His was reporting a student using university bandwidth to perform unscrupulous, if not illegal, activity. What's egotistical about reporting criminals?
 

PattySmear

Banned
Feb 4, 2001
84
0
0


<< It has nothing to do with his ego. His was reporting a student using university bandwidth to perform unscrupulous, if not illegal, activity. What's egotistical about reporting criminals? >>



I thought my post was pretty straight forward. Let me explain it to you.

The &quot;inflated ego&quot; comment was directed to his dissatisfaction with the University's more than adequate response. It seemed like he wanted the University to dish out even more punishment to the student, hence the &quot;inflated ego&quot; comment. Understand?

 

Napalm381

Platinum Member
Oct 10, 1999
2,724
0
0
His use of the term &quot;laconic&quot; was quite appropriate and unegotistical. The response is of the &quot;thanks, we're clueless&quot; attention, too often seen of indifferent sysadmins.
 

PattySmear

Banned
Feb 4, 2001
84
0
0


<< His use of the term &quot;laconic&quot; was quite appropriate and unegotistical. The response is of the &quot;thanks, we're clueless&quot; attention, too often seen of indifferent sysadmins. >>




The fact that the original poster expected anything more than a concise reply is evidence of his inflated ego. What more does he want, a junior g-man badge?


 

Thanatopsis

Golden Member
Feb 7, 2000
1,464
1
0
Pattysmear, you remind me of another fanatic liberal that went by the name of 2ndhandnews.

I didn't really think that WoundedWallet's post called for a flame. Just saying

<< Realize that your lone system barely registers a blip on their radar screen. >>

would have been sufficient.
 

PattySmear

Banned
Feb 4, 2001
84
0
0


<< I didn't really think that WoundedWallet's post called for a flame. >>




Woah! I haven't even begun to flame, nor do I intend to due to the number of thin skinned members 'round these parts.
 

jmcoreymv

Diamond Member
Oct 9, 1999
4,264
0
0
And since when was port scanning illegal? Thats right, its not, deal with it, we all get port scanned.
 

Napalm381

Platinum Member
Oct 10, 1999
2,724
0
0
(1) Port scanning, while not illegal, is certainly not an activity that most college students have any legitimate reason to do.

(2) Although I am not sure, I would suspect that the university has firm rules against using the university network for such shady activities.

Don't confuse &quot;thin-skinned&quot; with &quot;people who attempt to discuss things in a generally rational manner&quot;. When you use such derogatory language, be prepared to treated accordingly.
 

Jmman

Diamond Member
Dec 17, 1999
5,302
0
76
Most people detect port probes through software firewalls like Blackice Defender or others. I must get scanned 50 times a day. It pretty much is a waste of time trying to do anything about it since it happens so often.... Of course I do have a firewall myself though!!
 

WoundedWallet

Platinum Member
Oct 9, 1999
2,325
0
0
Patty,
as you and Deicide assumed incorrectly, I wasn't expecting an answer with explanantions of their actions. But I did expect a &quot;thank you&quot; at the end of the note.

If you consider expecting a thanks to be an ego problem, then you're right. But in my world it's just a sign of politness. A trait that many people don't have anymore, including you.

jmcoreymv,
port scanning is not illegal as you said. But it is known that our Universities were and possibly still are being used in DDoS attacks. My original message to the school was for them to check to see if one of their machines was compromised. I didn't think that it was a lone stupid kid fishing around. But apparently there are many stupid kids around.
 
sale-70-410-exam    | Exam-200-125-pdf    | we-sale-70-410-exam    | hot-sale-70-410-exam    | Latest-exam-700-603-Dumps    | Dumps-98-363-exams-date    | Certs-200-125-date    | Dumps-300-075-exams-date    | hot-sale-book-C8010-726-book    | Hot-Sale-200-310-Exam    | Exam-Description-200-310-dumps?    | hot-sale-book-200-125-book    | Latest-Updated-300-209-Exam    | Dumps-210-260-exams-date    | Download-200-125-Exam-PDF    | Exam-Description-300-101-dumps    | Certs-300-101-date    | Hot-Sale-300-075-Exam    | Latest-exam-200-125-Dumps    | Exam-Description-200-125-dumps    | Latest-Updated-300-075-Exam    | hot-sale-book-210-260-book    | Dumps-200-901-exams-date    | Certs-200-901-date    | Latest-exam-1Z0-062-Dumps    | Hot-Sale-1Z0-062-Exam    | Certs-CSSLP-date    | 100%-Pass-70-383-Exams    | Latest-JN0-360-real-exam-questions    | 100%-Pass-4A0-100-Real-Exam-Questions    | Dumps-300-135-exams-date    | Passed-200-105-Tech-Exams    | Latest-Updated-200-310-Exam    | Download-300-070-Exam-PDF    | Hot-Sale-JN0-360-Exam    | 100%-Pass-JN0-360-Exams    | 100%-Pass-JN0-360-Real-Exam-Questions    | Dumps-JN0-360-exams-date    | Exam-Description-1Z0-876-dumps    | Latest-exam-1Z0-876-Dumps    | Dumps-HPE0-Y53-exams-date    | 2017-Latest-HPE0-Y53-Exam    | 100%-Pass-HPE0-Y53-Real-Exam-Questions    | Pass-4A0-100-Exam    | Latest-4A0-100-Questions    | Dumps-98-365-exams-date    | 2017-Latest-98-365-Exam    | 100%-Pass-VCS-254-Exams    | 2017-Latest-VCS-273-Exam    | Dumps-200-355-exams-date    | 2017-Latest-300-320-Exam    | Pass-300-101-Exam    | 100%-Pass-300-115-Exams    |
http://www.portvapes.co.uk/    | http://www.portvapes.co.uk/    |