Forums: Apache Under Winxp - Forums

Jump to content

Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

Apache Under Winxp please help me figure this out

#1 User is offline   flame 

  • Staff Sergeant
  • Icon
  • Group: Members
  • Posts: 272
  • Joined: 06-August 03

Posted 23 September 2003 - 05:50 PM

i have just noticed when i looked in my firewall logs and i found somthing strange
all activitys (about 100 till now-right at this moment) are from the same ip but diffrent port. my firewall allows it (i have apache for a reason) so my question is:
is there any program i can use to "spy" on whoever connects to my port 80 .
i mean a real log of what the "visitor"\haxor is doing .
be happy if someone could shed a light on this

:ph34r:
0

#2 User is offline   vnet576 

  • Specialist
  • Icon
  • Group: Members
  • Posts: 1,000
  • Joined: 01-August 03

Posted 23 September 2003 - 06:29 PM

I think what u're talking about is a honey pot. A good one is SPECTER Intrusion Detection System. Of course you have to buy this...but like all software there are "other" ways of aqcuiring it.

Also u did a pretty bad job masking the ip address lol. U can still see that its xxx.xxx.xxx.xxx. After doing a whois I found that its :

Army National Guard Bureau
111 S. George Mason Dr.
Arlington, VA, 22204-1373
US

What the f*ck are u running on u're server to get the army scanning u?

Of course it could be a scan/hack stro but no hacker is this good (or stupid) to hack a government server.

Please dont post the IP. Also, flame, please try to make it so we cant see it. thanks. w00dy
0

#3 User is offline   Travis 

  • Specialist
  • Icon
  • Group: Specialist
  • Posts: 2,101
  • Joined: 26-February 03

Posted 23 September 2003 - 08:21 PM

you could also use a packet sniffer such as snort or ethereal...
0

#4 User is offline   flame 

  • Staff Sergeant
  • Icon
  • Group: Members
  • Posts: 272
  • Joined: 06-August 03

Posted 24 September 2003 - 04:39 AM

:o
thanks for the attension but you misunderstood my question.
is that suspicios activity ?
and its not the army its something in Amsterdam, those dutch are ttrying to
hack into my apache... but i guess there are no exploits for apache...
thanks again . next time read carefully :(
0

#5 Guest_Ripper_*

  • Group: Guests

Posted 24 September 2003 - 05:28 AM

flame: there really are exploits for apache... just upgrade to newest version to be quite sure you won't get hacked, and then you could just deny those f*cking dutch guys (i'm a dutch guy btw :P)....

CyA
0

#6 User is offline   flame 

  • Staff Sergeant
  • Icon
  • Group: Members
  • Posts: 272
  • Joined: 06-August 03

Posted 24 September 2003 - 09:59 AM

thanks -
what is better 1.3 or the new 2.0 ?
:wacko:

and sry , probably cuzz im jelause of you ....
wish i was a dutch :) :wacko: :wacko:
0

#7 User is offline   vnet576 

  • Specialist
  • Icon
  • Group: Members
  • Posts: 1,000
  • Joined: 01-August 03

Posted 24 September 2003 - 12:10 PM

Do a whois on that ip address and its not the dutch.
0

#8 User is offline   flame 

  • Staff Sergeant
  • Icon
  • Group: Members
  • Posts: 272
  • Joined: 06-August 03

Posted 24 September 2003 - 06:07 PM

i have done whois
what whois server did u use ??
arent them all the same ...
0

#9 Guest_Hardcore_*

  • Group: Guests

Posted 29 November 2003 - 02:03 AM

www.google.com
"whois"

ARIN whois DB is good for IPs.

-Hardcore
0

Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users

  • Share



Our Sponsors:


SwiftLayer Affiliate Web Hosting