maemo.org - Talk

maemo.org - Talk (https://talk.maemo.org/index.php)
-   Off Topic (https://talk.maemo.org/forumdisplay.php?f=19)
-   -   Somebody's trying to hack ITT (https://talk.maemo.org/showthread.php?t=8616)

cjtenny 2007-08-08 15:59

jj
 
jjjjjjjjjj

bsterix 2007-08-08 16:08

Re: Somebody's trying to hack ITT
 
i got the same mail

adammelancon 2007-08-08 16:21

Re: Somebody's trying to hack ITT
 
I got the same email too

Rebski 2007-08-08 16:25

Re: Somebody's trying to hack ITT
 
I got an "Hello, I'm new here and just wanted to say "hi" " pm.

adammelancon 2007-08-08 16:36

Re: Somebody's trying to hack ITT
 
Quote:

Originally Posted by Rebski (Post 66650)
I got an "Hello, I'm new here and just wanted to say "hi" " pm.

I got that one too!

HumanPenguin 2007-08-08 17:29

Re: Somebody's trying to hack ITT
 
Yeah I got the Hi PM as well with a load of SPAM.

FirebirdFeuervogel 2007-08-08 17:40

Re: Somebody's trying to hack ITT
 
I'm at work at the moment so I'm not going to bust out and check out the ip like I would if I was at home, but I just wanted to add my two cents. If this IP has been used to attack other accounts and other sites, and yet for some reason is running an ftp server and a server of some sort on port 80, the computer at that ip has probably been hacked itself and is being used to remotely attack sites.

maxinflixion 2007-08-08 17:49

Re: Somebody's trying to hack ITT
 
Quote:

Originally Posted by Rebski (Post 66650)
I got an "Hello, I'm new here and just wanted to say "hi" " pm.

I got that PM as well.

chunjaenim 2007-08-08 18:35

Re: Somebody's trying to hack ITT
 
me too. the PM. 2 emails. same IP.

balerno 2007-08-08 18:35

Re: Somebody's trying to hack ITT
 
Quote:

Originally Posted by cjtenny (Post 66631)
Well, I got an email 30 mins ago saying that my account was locked down because 74.53.243.34 had been trying to log into my account. After doing a WHOIS lookup on them, I found that they had tried it with somebody else's account too: http://and-novikoff.livejournal.com/90592.html .

Hmm.

Me too, what on earth do they think that they can gain from this type of attack?

curiousj 2007-08-08 18:38

Re: Somebody's trying to hack ITT
 
yet another.

what would this guy gain from having my lame forum account?

Rocketman 2007-08-08 19:01

Re: Somebody's trying to hack ITT
 
This site isn't exactly known for the most proactive administration. The ip needs to get banned immediately and reported to the ISP. Reverse DNS reveals it to be a static ip provided by a hosting company called "The Planet" in Texas. It is likely a compromised rented server, but equally possible it could be a rented server which some script kitty is using for hacking purposes. I sure hope they didn't rent that server on daddy's credit card, cause if they did, they are in for a world of hurt.

unique311 2007-08-08 19:28

Re: Somebody's trying to hack ITT
 
I got the same ******** email also..."Hi i am new here blah blah blah..."
I thought it was a joke, because of a thread i started that was being attack on the basis that it was thought to be spam.
but i guess not.

brendan 2007-08-08 19:54

Re: Somebody's trying to hack ITT
 
i happen to be a member at forums.remote-exploit.org and both sites gave me that email. seems like there is something more than meets the eye going on here.

FirebirdFeuervogel 2007-08-08 20:01

Re: Somebody's trying to hack ITT
 
I'm starting to think this might be a fully automated attack, this box might just be trying to brute force forums in general, not for the forum accounts but for the passwords. Logic possibly being that people have a tendency to use the same username and password across multiple websites, and the person behind this is probably hoping that your PayPal account is the same thing as your ITT account. So. Make sure it isn't.

glabifrons 2007-08-08 20:06

Re: Somebody's trying to hack ITT
 
Sounds like 2 things going on here...

1. Brute force attack.
Likely rotating usernames with the passwords in an attempt to keep from getting locked out, but obviously running into dupes too quickly (causing the temporary lockouts).

2. Social engineering(?)
The guy I got the same lame private message from called himself "einstein2".
I'm not sure if there might be something embedded in the message (I didn't bother reading through the HTML), but it did include a link to http://stein.freehostia.com (which is blocked by our proxy). I would not recommend following the link, as it may host malware.

Reggie 2007-08-08 20:35

Re: Somebody's trying to hack ITT
 
I'm investigating the problem and have just blocked the IP from the firewall.

Thanks.

luketoh 2007-08-09 07:44

Re: Somebody's trying to hack ITT
 
same, i got an email from einstein2

Quote:

Hello,
I'm new here and just wanted to say "hi"

How's it going?

"Buddhism has the characteristics of what would be expected in a cosmic religion for the future: it transcends a personal God, avoids dogmas and theology; it covers both the natural & spiritual, and it is based on a religious sense aspiring from the experience of all things as a meaningful unity" - Albert Einstein

---
einstein2
http://stein.freehostia.com

Frankowitz 2007-08-09 09:23

Re: Somebody's trying to hack ITT
 
Quote:

Originally Posted by luketoh (Post 66942)
same, i got an email from einstein2

I got that mail too, Luke. I deleted it as I thought someone was playing a joke on me.
Looking a bit further at the link at the end of the message:

'Site stein.freehostia.com blocked; this is a known spyware/adware website.'

So don't visit.

Tragos 2007-08-09 14:16

Re: Somebody's trying to hack ITT
 
I just got this private message from "einstein2", too. Let's see how soon my account is locked...

sondjata 2007-08-09 14:48

Re: Somebody's trying to hack ITT
 
I got the message this morning.

boon 2007-08-09 14:57

Re: Somebody's trying to hack ITT
 
I reported this activity to abuse@theplanet.com yesterday.

Schnoidz 2007-08-13 18:13

Re: Somebody's trying to hack ITT
 
I got the "Hi" message once on July 7th. My account was not locked.


All times are GMT. The time now is 11:56.

vBulletin® Version 3.8.8