Author |
Topic |
|
Graphite Goodness
New Member
USA
88 Posts |
Posted - 01 Apr 2002 : 11:55:52
Someone using Timaclover's login and pass has logged into the 68kmla server and gave both guest and reg. accounts a heave-how and made everyone unnamed guests with no permissions turned on. Go ahead try yourself! The name of this culprit was "www.gshag33.tk" his i/p was "64.166.61.59". When I messaged him he said he had to go and then disconnected me. |
cinemafia
Guerrilla Recon Leader
USA
2965 Posts |
Posted - 01 Apr 2002 : 11:59:20
Aha, so that why I haven't been able to login! What a b*stardo! 666th poster and 666th thread-creator Mod of the Mac II series Forums Total 68K Macs liberated: 7 Regular Disappear! Edited by - cinemafia on 01 Apr 2002 12:01:58 |
Trash80toG-4
NIGHT STALKER
USA
2899 Posts |
Posted - 01 Apr 2002 : 12:12:00
i don't do hotline so i can't check it out, which end of this alleged incident is the april fools joke? jt ™
|
cinemafia
Guerrilla Recon Leader
USA
2965 Posts |
Posted - 01 Apr 2002 : 12:15:48
quote: which end of this alleged incident is the april fools joke?
Well, as far as I can tell, the 68kMLA Hotline server has been inaccessible for at least two weeks... 666th poster and 666th thread-creator Mod of the Mac II series Forums Total 68K Macs liberated: 7 Regular Disappear! |
TiMacLover
Senior Member
USA
1282 Posts |
Posted - 01 Apr 2002 : 12:33:39
Ok I just got up right now and Graphite told me, I have been asking Da Penguin about secruity and stuff, another sad thing is that you can actually get the IP of a Hotline server and steal anyone's password on that server, it is really easy, I am glad if this is not some joke that my password was a dumb one not one I use for other things. I'll look some more into this.Jeremy "I'll see you on the Dark Side Of The Moon" - Pink Floyd Covert Ops 68k 68k Hacks General Macs Liberated:16 |
Trash80toG-4
NIGHT STALKER
USA
2899 Posts |
Posted - 01 Apr 2002 : 12:34:13
quote:
Well, as far as I can tell, the 68kMLA Hotline server has been inaccessible for at least two weeks...
jt ™
|
TiMacLover
Senior Member
USA
1282 Posts |
Posted - 01 Apr 2002 : 15:42:08
what? IM serious!Jeremy "I'll see you on the Dark Side Of The Moon" - Pink Floyd Covert Ops 68k 68k Hacks General Macs Liberated:16 |
FireWire is fast
General, 4 star
USA
1559 Posts |
Posted - 01 Apr 2002 : 15:47:10
any hackers in the house which would like to wreck havoc via his IP address?...-------------------- keeper of the website and beholder of the Quadra/Centris Stick of Justice™ -------------------- |
Da Penguin
Senior Member
USA
1094 Posts |
Posted - 01 Apr 2002 : 16:45:38
Ok first off my lesson has been to read ALL the forums before positng....duh penguin *hits head* (i poseted aboot this in 'website' if anyone ants waht i have on it. Ok, anyhue, From waht I have found TiMac supposedly has a book mark of my server on his server for hotline.I *think*, i acquired this knowledge only a day ago when someone else was logged in and HONESTLY knew and tried asking me why he was in an admin account. So it looks like this has been all an honest mistake. However, in the past it has been the same person who has UL'd.........PPC!!!!!!! apps before. So his IP has been banned yadda yadda. As fore my IP, it changes on a 4-5 day basis, and i JUST changged it purposly now, so security should be all better *hopes*. As for why the server hasbeen down, new one lines in the whole house and OS problems. Ugh, such a long day. If I come up with anything else, Ill post back. Over and out.~The Penguin |Captain, Intelligence Operations| There is only one path and that is the path that you take, but you can take more than one path. 68k.torpedobird.com <-- Hotline Server |
cinemafia
Guerrilla Recon Leader
USA
2965 Posts |
Posted - 01 Apr 2002 : 16:47:50
Thanks for the heads up, Penguin! I'll be looking forward to gettign back on the server soon! 666th poster and 666th thread-creator Mod of the Mac II series Forums Total 68K Macs liberated: 7 Regular Disappear! |
Da Penguin
Senior Member
USA
1094 Posts |
Posted - 01 Apr 2002 : 16:49:47
One more thing for Ti., Mail me with a new password for your account. It has been temp suspended just incase. Also, all accounts have been rightfully restored, just fyi. Maile me with any complaints or yadda yadda, magicpenguin@mac.com.~The Penguin |
TiMacLover
Senior Member
USA
1282 Posts |
Posted - 01 Apr 2002 : 21:41:02
OMG! I am soo sorry, I really need to remeber what to and not to share! Sorry guys!Jeremy "I'll see you on the Dark Side Of The Moon" - Pink Floyd Covert Ops 68k 68k Hacks General Macs Liberated:16 |
Tallgeese
Full Member
USA
523 Posts |
Posted - 01 Apr 2002 : 23:25:31
Bugger! Such problems! I suppose these are just logistical issues common to any army.Sgt. Tallgeese Thread Lord of Darkness Apple II Squad Leader 68k Mac Liberation Army 68k Macs Liberated: 4 |
raWr
Junior Member
Tuvalu
491 Posts |
Posted - 02 Apr 2002 : 00:40:45
http://samspade.org/t/asn?a=5678traceroute adsl-64-166-61-59.dsl.frsn01.pacbell.net Pac Bell Internet Services (NETBLK-PBI-NET-8) PBI-NET-8 64.160.0.0 - 64.175.255.255 FRSN01 ADSL Rback2 PPPoX (NETBLK-SBCIS-1001030-163039) SBCIS-1001030-163039 64.166.60.0 - 64.166.63.255 Fleet Covert Ops Padlock Magnet |
~Coxy
Leader, Tactical Ops Unit
Australia
2822 Posts |
Posted - 02 Apr 2002 : 05:27:42
For a moment there I was worried about some permanent damage...Good to here that nothing too bad happened. ~Coxy - Leader, Tactical Operations Unit 00014 Macs liberated |
raWr
Junior Member
Tuvalu
491 Posts |
Posted - 02 Apr 2002 : 07:15:47
" >From: "policy@pbi.net" <kana1@pbi.net> >Reply-To: "policy@pbi.net" <kana1@pbi.net> >To: Pál ----------- <littlegreencube@hotmail.com> >Subject: SBCIS Policy Department (KMM154940V34120L0KM) >Date: Tue, 02 Apr 2002 01:56:04 -0600 > >THIS IS AN AUTO-RESPONSE MESSAGE - PLEASE DO NOT REPLY TO THIS MESSAGE > >Please read carefully! This may be the only response we send you. > >Thank you for writing Pacific Bell's Internet Policy Department. This >address is designated for reporting violations of Pacific Bell's Terms & >Conditions and Acceptable Use Policy. > >We make every effort to investigate all reports of abusive activity in >a timely manner. The information that you have provided will be used to >investigate the incident for violations of our Acceptable Use Policy and >Terms & Conditions, which you can view at: > >http://public.pacbell.net/faq/ > >If you are a Pacific Bell Internet customer writing concerning >problems you are having with your Internet Service, please direct your >message >to the Technical Support Department at: support@pacbell.net. > >Since the current volume of email prohibits a personal reply to each >report, unless additional information is required, THIS MAY BE THE ONLY >RESPONSE YOU WILL RECEIVE. > >When reporting violations, please follow these guidelines in order to >significantly expedite the investigation process: > >-> To report unsolicited commercial email (UCE/spam), please forward >the entire message, including full headers, leaving the original subject > > >line intact. You will recognize full headers by the "received" line(s) >shown. If you need assistance in enabling full headers, please refer to >the help section of your email client. > >-> To report off-topic commercial newsgroup postings, please forward a >copy of the offending post, including full headers, leaving the original >subject line intact. > >-> To report scans, probes, hacking attempts, or similar activity, >please include an excerpt of your auto-generated log files showing >ONLY THE INCIDENTS PERTAINING TO PACIFIC BELL INTERNET, cut & pasted >directly into the email message, including: > > *Offending IP Address > *Date > *Specific Time > *Time Zone > *Source/Destination Ports > *Any other brief pertinent details > >***Screenshots cannot be accepted in lieu of log excerpts.*** > >***Please DO NOT INCLUDE TRACEROUTES, WHOIS LOOKUPS, or PING results, >as these do not contribute to the investigation, and can often cause the > > >message to become "garbled" or unreadable.*** > >***Please make sure that you are not sending an attachment that is in >a proprietary format (i.e. a log file readable only by your firewall >program or one that requires special software to view, .xls). If you do >send an attachment, please note the format type in your email >message.*** > >---------------------------- >Pacific Bell Internet >Policy Department >abuse@pacbell.net >----------------------------"
I need the log files (I assume you have those!) sent to my email account. Time to stir things up Fleet Covert Ops
Padlock Magnet |
AnubisTTP
Junior Member
USA
308 Posts |
Posted - 02 Apr 2002 : 07:16:34
Well Timaclovers iBook was just stolen and then someone breaks into the hotline server using his account. Doesn't it stand to reason that whoever did it is the one who stole his ibook, and that that person got the location of the server and the admin password out of his bookmarks or something. And unless the culprit has a static IP adderess I don't think we can do a portflood or launch much of any other type of "hack attack" aganst him.AnubisTTP 68k Macintosh Liberation Army Macs Liberated:15 |
Trash80toG-4
NIGHT STALKER
USA
2899 Posts |
Posted - 02 Apr 2002 : 07:33:15
quote:
And unless the culprit has a static IP adderess I don't think we can do a portflood or launch much of any other type of "hack attack" aganst him.
even if the effort turns out fruitless, exploring possibilities and formulation SOP for next time and a how-to for site content is a really good idea, IMHO! some of you net geeks should pitch in, i'm useless on this one! jt ™
|
raWr
Junior Member
Tuvalu
491 Posts |
Posted - 02 Apr 2002 : 08:35:10
Like i said - email me the logs, I'll take care of it. Since he has DSL (assuming he is a moron and that is his real IP address (highly likely)) his IP number is static. I on the other hand use a modem pool. Not that i h4><><0r, but still I also need date, time etc. Read the above mail thouroughly and then send files to me. ps ALL THAT HAXX0R IS BELONGS TO ME.Fleet Covert Ops Padlock Magnet Edited by - raWr on 02 Apr 2002 08:40:36 |
Da Penguin
Senior Member
USA
1094 Posts |
Posted - 02 Apr 2002 : 13:34:51
rawr, i got to almost the same conclusion today in school...heh, funny. Anyhue, i DO still need to know which logs you need, hotline splits them into -UL's -DL's -Account Mods -Attempted and working connections -ErrorsIm just tryin to keep file size down, even if u do have DSL. I'll snip up the parts you want, or send you the whole file. Let me know via email once again. Thanks for your help that I am unfortuneatly to busy to handle as of right now. Anyhue, lemme know. Magicpenguin@ mac.com As for the attacker loggin in again and all. He attempted to login only a few hours later that nite, but hasnt since. His IP has been banned, which will temp keep him from connecting period. All Accounts have also been rotated and passwords swapped out. Extra redundant systems have been taken into account, this unfortuneatley includes removing some features from admins, but this is the price of security apparently. Still, I'm happy I'm running a mac, makes it that much harder for them to screw anything up too bad ;) ~The Penguin |Captain, Intelligence Operations| There is only one path and that is the path that you take, but you can take more than one path. 68k.torpedobird.com <-- Hotline Server |
Tallgeese
Full Member
USA
523 Posts |
Posted - 02 Apr 2002 : 15:04:35
TRS-80, I'm with you... I feel like a netard. I learned most of my stuff before this 'inter-web' thing took off... I feel so old and out of it. Sgt. Tallgeese Thread Lord of Darkness Apple II Squad Leader 68k Mac Liberation Army 68k Macs Liberated: 4 |
AnubisTTP
Junior Member
USA
308 Posts |
Posted - 02 Apr 2002 : 15:34:10
Well I pinged the IP to see if it was connected and then did a port scan. I got replys on port 135 (the location service port according to AGnettools) and 139 (the NETBIOS Session Service port according to AGnettools).I am pretty sure NETBIOS is a PC thing, so it was most likely not done from a Mac.AnubisTTP 68k Macintosh Liberation Army Macs Liberated:15 |
Trash80toG-4
NIGHT STALKER
USA
2899 Posts |
Posted - 02 Apr 2002 : 15:55:38
quote:
TRS-80, I'm with you... I feel like a netard. I learned most of my stuff before this 'inter-web' thing took off... I feel so old and out of it.
i try to keep the distinction between the net and the web clear in my own head at least! never really did the net, but the First-Class bbs interactions weren't all that different than this joint, except for the LINKS and google!who was the guy who nailed the hackers (clifford stoller ?)? i've got a couple of really good magazine articles about net security, maybe i should get a firewall with as much time as i've been keeping the connection/browser running in the background while i'm "working!" i feel out of it in terms of the nuts and bolts of that xml - html kinda stuff, but figuring the ins and outs of the information systems i think i'm finally starting to get a handle on! maybe i CAN still learn a trick or two! jt ™
|
TiMacLover
Senior Member
USA
1282 Posts |
Posted - 02 Apr 2002 : 16:38:12
WO WOW WOW NO....Ok what is all this turing people in thing? I mean this is what happen when I had my own hotline server up I had my Links folder on sharing cause I have some good servers and I fotgot that I had the 68kMLA one with my login, someone mistakely downloaded and loged in thinking otherwise no hacking, the iBook was stolen a lil while ago and it was in OS X boot with a login so its useless Jeremy "I'll see you on the Dark Side Of The Moon" - Pink Floyd Covert Ops 68k 68k Hacks General Macs Liberated:16 |
Graphite Goodness
New Member
USA
88 Posts |
Posted - 02 Apr 2002 : 19:45:41
Hold on a second. It said Fresno in the information that raWr found. I leave a few miles away from Fresno. I dont know anyone with DSL though. Theres only one person I know who is stupid enough to do this and he has cable. I'm thinking he was a wuss and used one of his friend's connections.I'd ask him if he did it , but he lies out of his teeth.
|
Da Penguin
Senior Member
USA
1094 Posts |
Posted - 02 Apr 2002 : 21:03:04
Whoa, enough of the policing of internet and rampaging on a bounty hunt mission. Simple Lil mistake on Ti's part. although you did get one thing wrong Ti, this person def knew what they was doing. Aboot a month ago they tried UL'ing PPC files. And now this under the same name. That is until they changed there name to 'new admin' screwedd with my admin account, then deleted it as well as lots of crucial files. Person knew what they was doing. BUT it has been stopped and no need to be completely alarmist IMHO. Then again maybe im just being too passive. Just my two cents~The Penguin |Captain, Intelligence Operations| There is only one path and that is the path that you take, but you can take more than one path. 68k.torpedobird.com <-- Hotline Server |
Tallgeese
Full Member
USA
523 Posts |
Posted - 02 Apr 2002 : 21:05:53
I think we'd better calm down before we turn into the "68k Mac Vigilante Posse"Sgt. Tallgeese Thread Lord of Darkness Apple II Squad Leader 68k Mac Liberation Army 68k Macs Liberated: 4 |
MacMoose
Junior Member
USA
176 Posts |
Posted - 02 Apr 2002 : 21:14:05
quote:
I think we'd better calm down before we turn into the "68k Mac Vigilante Posse"
Can I be the guy with the pitchfork? ------------------ MacMoose Medical Spec., 68k MLA Total 68K Macs liberated: 9 and counting ------------------
|
Tallgeese
Full Member
USA
523 Posts |
Posted - 02 Apr 2002 : 21:17:26
Only if I get to be Batman!Sgt. Tallgeese Thread Lord of Darkness Apple II Squad Leader 68k Mac Liberation Army 68k Macs Liberated: 4 |
raWr
Junior Member
Tuvalu
491 Posts |
Posted - 03 Apr 2002 : 00:11:10
I say we screw them.Fleet Covert Ops Padlock Magnet |
~Coxy
Leader, Tactical Ops Unit
Australia
2822 Posts |
Posted - 03 Apr 2002 : 06:12:00
quote:
who was the guy who nailed the hackers (clifford stoller ?)? i've got a couple of really good magazine articles about net security, maybe i should get a firewall with as much time as i've been keeping the connection/browser running in the background while i'm "working!"
Clifford Stoll, I think, if you're referring to "The Cuckoo's Egg" (which was fiction.)~Coxy - Leader, Tactical Operations Unit 00014 Macs liberated |
Trash80toG-4
NIGHT STALKER
USA
2899 Posts |
Posted - 03 Apr 2002 : 07:44:47
quote:
quote:
who was the guy who nailed the hackers (clifford stoller ?)?
Clifford Stoll, I think, if you're referring to "The Cuckoo's Egg" (which was fiction.)
thanks, not remembering that name was killin' me! as i recall, the book was a fictionalized account of stoll's real life experiences. his contrarian views on the web were even more refreshing than dvorak columns. now i 've learned that there are two books full of them, thanks!the blurbs are very interinsing and quite on topic: http://shop.barnesandnoble.com/bookSearch/isbnInquiry.asp?userid=18OVQP4L6U&mscssid=VJQJ39GQVPMK8KV26VSWA6UFJB74D0V4&isbn=0-385-24946-2 jt ™ back again: why does the software seem to handle aome long urls and not others? this one comes out fine, others get munged up, anybody got a clue? i was also wondering if there is a site that decodes isbn #'s and tells what category a book is in along with all the other info. Edited by - trash80toG-4 on 03 Apr 2002 07:59:56 |
~Coxy
Leader, Tactical Ops Unit
Australia
2822 Posts |
Posted - 03 Apr 2002 : 08:11:55
Are you referring to his non-fiction book: "Silicon Snake Oil" or something like that I think it was called.Oh, and the URLs get screwed up not based on length, but when a site like google or altavista uses another URL as an index in, say, double quotes: www.abc.com/cache=2348239482348283+"www.xyz.com" ~Coxy - Leader, Tactical Operations Unit 00014 Macs liberated |
Trash80toG-4
NIGHT STALKER
USA
2899 Posts |
Posted - 03 Apr 2002 : 09:42:21
quote:
Are you referring to his non-fiction book: "Silicon Snake Oil" or something like that I think it was called.
the newer books andhis rep in the web community stem from his notoriety gained from events fictionalised in the original story. they do not appear to be referred to as fictional in the blurbs explaining who he is. i think i remember hearing about him in news stories from before the publication of cuckoos egg, but i could be wrong. check the blurbs, is it listed under fiction?jt ™
|
~Coxy
Leader, Tactical Ops Unit
Australia
2822 Posts |
Posted - 03 Apr 2002 : 17:50:50
In our libraries it was listed under fiction, and his commentary books were non-fiction and under 004.~Coxy - Leader, Tactical Operations Unit 00014 Macs liberated |
titok16
Junior Member
USA
116 Posts |
Posted - 04 Apr 2002 : 00:32:36
enuf about books, lets establish 68ks as "hack machines" sweet i wish we could find jeremys ibook while dancing to mission impossible musicTito Tito Macs Liberated: Powerbook 145 Powerbok 150 Powerbook 160 Apple \\c (now dead) |
raWr
Junior Member
Tuvalu
491 Posts |
Posted - 04 Apr 2002 : 11:33:26
Little update..."The use of Southwestern Bell Internet accounts to attempt to gain unauthorized access to a host, server or network is prohibited by our Acceptable Use Policy which may be found at the following URL: http://public.swbell.net/faq/ I will investigate your complaint and take appropriate action. On behalf of Southwestern Bell Internet, I apologize for any inconvenience caused by our customer. Please do not hesitate to write again if you have any questions or if you wish to report other instances of abuse by Southwestern Bell Internet customers." --------------------------------------------------------- Pacific Bell Internet Policy Department abuse@pacbell.net ---------------------------------------------------------
Penguin: I trust that you know which parts of the logfiles I need. ;) You know, when was he online, what connection, UL, DL etc etc... How big are the logfiles? RAWR.
Fleet Covert Ops Padlock Magnet |
Trash80toG-4
NIGHT STALKER
USA
2899 Posts |
Posted - 04 Apr 2002 : 11:42:25
quote:
Penguin: I trust that you know which parts of the logfiles I need. ;) You know, when was he online, what connection, UL, DL etc etc... How big are the logfiles?
good work, raWr and penguin, tag em' an' bag em'! *gives thumbs up!* jt ™
|
raWr
Junior Member
Tuvalu
491 Posts |
Posted - 05 Apr 2002 : 04:11:30
combat.uxn.comRAWR. Fleet Covert Ops Padlock Magnet |