Page 1 of 1

fallingstar dude stop it already

Posted: Tue Aug 01, 2006 11:11 pm
by Red Squirrel

Code: Select all

Status 3 alarm triggered August 1, 2006, 11:38:37 pm by IP: 202.156.6.62.

"Rule [202.156.6.62] matched with [202.156.6.62]
Reason: Iceteks Forum Spammer (username: FallingStar) (userid: 1207) (Points: 89)"
[code]


That ACL is permanent, you're not getting in!  If you're reading this it's probably through the google cache.  :huh:   Or do an ipconfig /renew or something, the acl is not THAT hard to beat....



This dude has been trying to get in for at least a couple months now. :lol:  Noob. 

[color=#888888][size=85]Archived topic from Iceteks,  old topic ID:4478, old post ID:35886[/size][/color]

fallingstar dude stop it already

Posted: Wed Aug 02, 2006 12:01 am
by Red Squirrel
speaking of spammers, this is another thats been trying to hit the site, but through the news submission form: 82.179.172.131 Have fun. It looks like a russian webhost of some sort.

Code: Select all

Initiating SYN Stealth Scan against 82.179.172.131 [65535 ports] at 23:59
Discovered open port 80/tcp on 82.179.172.131
Discovered open port 53/tcp on 82.179.172.131
SYN Stealth Scan Timing: About 0.41% done; ETC: 02:00 (2:01:07 remaining)
SYN Stealth Scan Timing: About 1.31% done; ETC: 01:15 (1:15:23 remaining)
SYN Stealth Scan Timing: About 2.39% done; ETC: 01:02 (1:01:27 remaining)
[code]


I did a quick scan and those were the only ports opened unfortunately, and its running apache and not IIS, but someone who knows DNS more then me may know what to do with that port 53....<_>  

If the rest of the scan returns something fun that the quick scan missed I'll post it up.  

[color=#888888][size=85]Archived topic from Iceteks,  old topic ID:4478, old post ID:35889[/size][/color]

fallingstar dude stop it already

Posted: Wed Aug 02, 2006 4:58 pm
by Death
:rolleyes: spammers.

Archived topic from Iceteks, old topic ID:4478, old post ID:35892

fallingstar dude stop it already

Posted: Wed Aug 02, 2006 7:58 pm
by Wren
Seems this is the only excitement as of late! :stir the pot:

We are a sorry lot! :roflmao2:

Archived topic from Iceteks, old topic ID:4478, old post ID:35895

fallingstar dude stop it already

Posted: Wed Aug 02, 2006 8:13 pm
by Red Squirrel
Actually I decided to do some reasearch on the IP of fallingstar but it turns out it might be some kind of internet proxy so not always the same person as originally. It just so happened that whoever got caught spamming was using that proxy so now it's blocked.

Doing stealth port scan as usual, only port 80 open, and nothing interesting on it. Just an error page.

Archived topic from Iceteks, old topic ID:4478, old post ID:35899