Reply
Old October 9th, 2004 Top | #1
 
Maveric169's Avatar
The Voices Talk to Me
Joined: December 2002
Location: Elkhart, IN
Posts: 1,148
Reputation: 130
Power: 128

Default counter attack an attack in progress?

Well I hope this doesn't violate the rules but I have to try. I have been under a constant attack on my system for 3 days from 147.32.114.70. This computer is throwing everything but the kitchen sink at me. Every kind of attack you can think of. I have notified my ISP, they say nothing they can or will do about it. I have notified the orgination host they literally (after getting someone that speaks english) told me to F*** off and hung up.

I am sick and tired of this. Is there any means at my disposal to counter-attack? Anyway I can redirect all the packets they send to me and redirect them back to the source?

Any ideas or other means of pinting me in the right direction would be helpful. Thanks.

Disclaimer: Past performace and emerging trends are not always accurate predictors for future events. Consult your employeer reguarding overtime possibilies incase I am wrong and you have to buy more stuff.
AMD Athlon 64 3000+ | Gigabyte GA-K8NS Mobo | 1 Gig Crucial XMS Ram | Maxtor 200GB Sata Drive 8Meg Cache Primary Drive | 60GB Backup Drive | ATI 9550 | Antec Trio 430W PSU | Custom Case

Check out my new website
Maveric169 is offline   Reply With Quote
Old October 9th, 2004 Top | #2
 
LeeJend's Avatar
OSNN Veteran Addict
Joined: January 2003
Location: Fort Worth, TX
Posts: 5,261
Reputation: 3386
Power: 199

Default

Wow you have a new web pal in Eastern Europe and he has a pretty good connection. He pings at 42 milliseconds.

Define attack. Are they just pinging you to acheive denial of service or are they trying to crack your passwords?

Assuming its a ping attack - You don't have the bandwidth to do anything back at them. So your best option would be to get on IRC, haunt the hacker sites until you found somebody who would give you a BOT program. Then you crack into other peoples systems and seed the BOTs. Hundreds or thousands would be required and could take months. Once you have your BOT army you launch a denial of service attack against your attacker and hope he doesn't have a bunch of friends who then retaliate against you. Not a good plan.

If the attacker is trying to crack your passwords then you have the option of calling the FBI and reporting it as attempted identity theft. They might eventually do something.

Or, you could put up a firewall. Zonealarm is free and will make you disappear off the web. Nothing to attack. A router with DMZ turned off will do the same.

Another option is tell your POS ISP to change your IP address. If they are reluctant a few threats to litigate will spur them on. And then put up a firewall to hide your new IP so it doesn't happen again.
__________________

Thought for the new millenium:

In a world without walls and fences, who needs Windows and Gates?

- Open Office - Firefox - Thunderbird - Gimp -Ubuntu - Red Hat -
LeeJend is offline   Reply With Quote
Old October 9th, 2004 Top | #3

OSNN Folding Team  
VenomXt's Avatar
Blame me for the RAZR's
Joined: March 2004
Location: Houston, Texas
Posts: 3,442
Reputation: 1240
Power: 146

Default

how do you know about my bot army!!!!!!!!!!!! (gets under covers)
VenomXt is offline   Reply With Quote
Old October 9th, 2004 Top | #4
 
Maveric169's Avatar
The Voices Talk to Me
Joined: December 2002
Location: Elkhart, IN
Posts: 1,148
Reputation: 130
Power: 128

Default

Well currently they are scanning, and attemping to crack passwords in my system. I have since put my system under full lockdown after they were able to knock McAfee and a temp zonealarm AV systems offline. Luckly I was sitting here when that happened. Just not sure what to do, everyone, ISP wise just tells me to un-plug my PC for a while they will go away. Not an option, I will win this fight! They do have a number of UDP ports open, anything I can do with that info?

Disclaimer: Past performace and emerging trends are not always accurate predictors for future events. Consult your employeer reguarding overtime possibilies incase I am wrong and you have to buy more stuff.
AMD Athlon 64 3000+ | Gigabyte GA-K8NS Mobo | 1 Gig Crucial XMS Ram | Maxtor 200GB Sata Drive 8Meg Cache Primary Drive | 60GB Backup Drive | ATI 9550 | Antec Trio 430W PSU | Custom Case

Check out my new website
Maveric169 is offline   Reply With Quote
Old October 9th, 2004 Top | #5

OSNN Folding Team  
VenomXt's Avatar
Blame me for the RAZR's
Joined: March 2004
Location: Houston, Texas
Posts: 3,442
Reputation: 1240
Power: 146

Default

when you have to ask questions about how to attack back buddy your best off not doing anything to them. how are you connected? cant you download all the latest updates to zonealarm or anther free firewall and get off line install get on update. or id do what lee said if you had a router turn off DMZ.
VenomXt is offline   Reply With Quote
Old October 9th, 2004 Top | #6
 
LeeJend's Avatar
OSNN Veteran Addict
Joined: January 2003
Location: Fort Worth, TX
Posts: 5,261
Reputation: 3386
Power: 199

Default

If they are cracking passswords call the FBI.

Thought for the new millenium:

In a world without walls and fences, who needs Windows and Gates?

- Open Office - Firefox - Thunderbird - Gimp -Ubuntu - Red Hat -
LeeJend is offline   Reply With Quote
Old October 9th, 2004 Top | #7

OSNN Folding Team  
VenomXt's Avatar
Blame me for the RAZR's
Joined: March 2004
Location: Houston, Texas
Posts: 3,442
Reputation: 1240
Power: 146

Default

shiver.
VenomXt is offline   Reply With Quote
Old October 9th, 2004 Top | #8
 
LordOfLA's Avatar
Godlike!
Joined: February 2004
Location: Salisbury, Wiltshire, UK
Posts: 7,031
Blog Entries: 5
Reputation: 4137
Power: 213

Default

Stop whining and kill the pc for 15-20 minutes you'll force an IP change, problem solved.

As for McAfee and Zonealarm they never stood a chance neither are deisged for stopping this kind of thing.

If you are going to be stubborn get a direct line to the techs at your isp and ask them to filter the attack.

If they wont all you can do is kill the pc for the aforementioned period of time.



If HK-47 and GLaDOS had a child, the character they create would cause the video game world to overdose on awesome. -sheridanmovieguy: Dragon age forum user.
LordOfLA is offline   Reply With Quote
Old October 9th, 2004 Top | #9
 
Maveric169's Avatar
The Voices Talk to Me
Joined: December 2002
Location: Elkhart, IN
Posts: 1,148
Reputation: 130
Power: 128

Default

Well, call to FBI they took a report, disconnect and forced change of IP hacker was back in 40min (3rd time I have forced my IP change BTW). I have things locked down now to where they shouldn't be able to access anything that they can crack. They are still hammering the hell out of me though. ISP says they will not block/filter an IP address as they cannot verify that the user of the IP is doing anything illegal.

So I guess I am just screwed.

ohhh yes, I have a cable connection, the very most up-to-date update to both firewalls and AV.

Disclaimer: Past performace and emerging trends are not always accurate predictors for future events. Consult your employeer reguarding overtime possibilies incase I am wrong and you have to buy more stuff.
AMD Athlon 64 3000+ | Gigabyte GA-K8NS Mobo | 1 Gig Crucial XMS Ram | Maxtor 200GB Sata Drive 8Meg Cache Primary Drive | 60GB Backup Drive | ATI 9550 | Antec Trio 430W PSU | Custom Case

Check out my new website
Maveric169 is offline   Reply With Quote
Old October 9th, 2004 Top | #10

OSNN Folding Team  
VenomXt's Avatar
Blame me for the RAZR's
Joined: March 2004
Location: Houston, Texas
Posts: 3,442
Reputation: 1240
Power: 146

Default

maybe he has something on your comp that sending out your location. lol back in the sub seven days that used to be a fun thing to do to friends on dial up. lol but i supoise if you truly have scanned for everything then probaly not.. btw check for exclusions in your antivirus. i dont know out of my leauge. might want to change your passwords (offline) to some extremly more encrypted ones. hehe
VenomXt is offline   Reply With Quote
Old October 9th, 2004 Top | #11
 
Maveric169's Avatar
The Voices Talk to Me
Joined: December 2002
Location: Elkhart, IN
Posts: 1,148
Reputation: 130
Power: 128

Default

Originally Posted by sraycoz
maybe he has something on your comp that sending out your location. lol back in the sub seven days that used to be a fun thing to do to friends on dial up. lol but i supoise if you truly have scanned for everything then probaly not.. btw check for exclusions in your antivirus. i dont know out of my leauge. might want to change your passwords (offline) to some extremly more encrypted ones. hehe
Well that is what kinda freaked me out, is that after forcing my IP change was the fact that he was back in less than an hour not once but 3 times. The only thing I can think of is that there is something exposed like a port, or some other identifing characteristic that this person is able to single me out through a scan of the netrange. I already have some pretty heffty passwords on everything on my system so it will take them a while if they do make a connection.

I guess I just really feel like a 1 legged man in an ass kicking contest with no way to fight back against this attack. I mean I am a computer savy person but I hate the fact that all I can do is try to block the attack and not fight back.

Disclaimer: Past performace and emerging trends are not always accurate predictors for future events. Consult your employeer reguarding overtime possibilies incase I am wrong and you have to buy more stuff.
AMD Athlon 64 3000+ | Gigabyte GA-K8NS Mobo | 1 Gig Crucial XMS Ram | Maxtor 200GB Sata Drive 8Meg Cache Primary Drive | 60GB Backup Drive | ATI 9550 | Antec Trio 430W PSU | Custom Case

Check out my new website
Maveric169 is offline   Reply With Quote
Old October 9th, 2004 Top | #12
 
Tuffgong4's Avatar
The Donger Need Food!!!!
Joined: June 2002
Location: Chicago
Posts: 2,465
Reputation: 840
Power: 153

Default

never ever ever ever ever fight back...you will get it 45 times worse than what you think you can do...the best thing to do is hide behind a hardware firewall(if you have it) a software firewall and a big rock

Home
Intel E6600 \ Abit AB9 Pro \ 4 gig Corsair DDR2-667 \ EVGA 9800GT \ HDD 1 320GB sata + 1 1.5TB sata \ 1 1TB backup drive / Samsung S183L SATA DVD-RW \ Windows 7 Pro x64
Laptop
Asus UL30VT\ Intel CULV SU7300 \ 4GB Ram \ Intel Integrated + Nvidia 200m \ 500GB HDD \ 13.3 inch LED \ Windows 7 Premium x64

Tuffgong4 is offline   Reply With Quote
Old October 9th, 2004 Top | #13

OSNN Folding Team  
VenomXt's Avatar
Blame me for the RAZR's
Joined: March 2004
Location: Houston, Texas
Posts: 3,442
Reputation: 1240
Power: 146

Default

beh just go to bed leave your comp off.. dont fret with it.. if they are back by the morning then you can worry more.. as for me.. dawn of war time..
VenomXt is offline   Reply With Quote
Old October 9th, 2004 Top | #14
 
FishBoy's Avatar
Feeeesh
Joined: August 2004
Location: Khobar, Saudi Arabia (for summer vacay)
Posts: 1,685
Reputation: 530
Power: 117

Smile

hey you can ask computer geniuses around you, a guy at my school had hacker spying on his computer he had someone retaliate and they did something that just crashed their whole system as in just killed his graphics card and just made other hardware over-work till they melt somthing like that.... see if someone can do that for you...
FishBoy is offline   Reply With Quote
Old October 9th, 2004 Top | #15
 
ming's Avatar
OSNN Advanced
Joined: June 2003
Location: UK
Posts: 4,252
Reputation: 1160
Power: 162

Default

One thing you could do...Ask your ISP to change your IP...

Curent system:
Intel Quad Core 9450 | 4GB RAM | WD Raptor 36GB | nVidia 8800GT 512mb
ming is offline   Reply With Quote
Old October 9th, 2004 Top | #16
 
Maveric169's Avatar
The Voices Talk to Me
Joined: December 2002
Location: Elkhart, IN
Posts: 1,148
Reputation: 130
Power: 128

Default

Originally Posted by ming
One thing you could do...Ask your ISP to change your IP...
errr apaently you didn't read the whole thread, I have changed my IP 3X, SOAB comes back within 1 hr!

But I did finally get to talk to a security person at the ISP and they contacted the FBI agent reguarding the report I filed, so I hope between them they will do something. Bastard is still hammering the hell out of my IP. I got the IP in the banned list on my firewall so as long as this hacker punk doesn't knock them offline I think I will be ok.

Disclaimer: Past performace and emerging trends are not always accurate predictors for future events. Consult your employeer reguarding overtime possibilies incase I am wrong and you have to buy more stuff.
AMD Athlon 64 3000+ | Gigabyte GA-K8NS Mobo | 1 Gig Crucial XMS Ram | Maxtor 200GB Sata Drive 8Meg Cache Primary Drive | 60GB Backup Drive | ATI 9550 | Antec Trio 430W PSU | Custom Case

Check out my new website
Maveric169 is offline   Reply With Quote
Old October 9th, 2004 Top | #17

OSNN Folding Team  
Geffy's Avatar
OSNN Veteran Addict
Joined: March 2002
Location: United Kingdom
Posts: 7,805
Reputation: 1490
Power: 217

Default

good luck, I hope your ISP gets their thumbs out, I dont see why they would want a high packet attack on their network, its going through their servers/routers/nodes


blogtumbloglastfmflickr#rubyonrails@twitter
"I could be replaced with a very small shell script"
Geffy is offline   Reply With Quote
Old October 9th, 2004 Top | #18
 
X-Istence's Avatar
*
Joined: December 2001
Location: USA
Posts: 6,496
Reputation: 2808
Power: 220

Default

For a quick deterent, grab knoppix, an old machine, and install it on there, it should have a way for the firewall to be configured.

Set it to drop all packets from whoever is doing this. That way you don't send anything back, and you still have your upload to use, also, the attacker will then have to put more power on to saturate your download, but i doubt it would knock you offline again. unless it is a huge amount of bandwidth.

Good luck .
X-Istence is offline   Reply With Quote
Old October 9th, 2004 Top | #19
 
Maveric169's Avatar
The Voices Talk to Me
Joined: December 2002
Location: Elkhart, IN
Posts: 1,148
Reputation: 130
Power: 128

Default

Well, I booted up this morning and guess who is knocking on my firewall again for day 4. But now it looks like this person is back to scanning for open ports and not just trying certain ones over and over. I have the comp under a near full lockdown (which sucks as I can't use 90% of my programs) but it should keep me safer than I was.

>X, I wish I had an old machine to setup but I don't anymore.

Disclaimer: Past performace and emerging trends are not always accurate predictors for future events. Consult your employeer reguarding overtime possibilies incase I am wrong and you have to buy more stuff.
AMD Athlon 64 3000+ | Gigabyte GA-K8NS Mobo | 1 Gig Crucial XMS Ram | Maxtor 200GB Sata Drive 8Meg Cache Primary Drive | 60GB Backup Drive | ATI 9550 | Antec Trio 430W PSU | Custom Case

Check out my new website
Maveric169 is offline   Reply With Quote
Old October 10th, 2004 Top | #20
 
dave holbon's Avatar
OSNN Veteran Addict
Joined: May 2002
Location: London England
Posts: 1,014
Reputation: 140
Power: 133

Default

Coming from [klika.sh.cvut.cz] causing grief? Yes to knobble, no to allow.

If you are only using an internet connection (not internal network) disable NetBios over TCP/IP and block port 445 (I think). Go here for more info : -

http://www.petri.co.il/what's_port_445_in_w2k_xp_2003.htm
dave holbon is offline   Reply With Quote

Reply

Bookmarks

Thread Tools

Posting Rules

Similar Threads
Thread Thread Starter Forum Replies Last Post
Gas Attack Dark Atheist Funny Farm 0 January 24th, 2008 12:27am
DOS attack shinz Windows Desktop Systems 14 May 28th, 2004 2:16pm
Is this an attack? how to fix? leedogg Windows Desktop Systems 6 August 11th, 2003 9:05pm
Another D.O.S attack on the Internet? Nick M Windows Desktop Systems 5 November 22nd, 2002 12:31pm
Under attack!! robin.munro Windows Desktop Systems 8 April 3rd, 2002 1:31pm