Forums: Port 3003 - Forums

Jump to content

  • (2 Pages)
  • +
  • 1
  • 2
  • You cannot start a new topic
  • You cannot reply to this topic

Port 3003

#16 User is offline   esorone 

  • Private First Class
  • Icon
  • Group: Members
  • Posts: 48
  • Joined: 15-December 03

Posted 01 February 2004 - 04:25 AM

Nostremato, on Feb 1 2004, 09:09 AM, said:

anole, on Feb 1 2004, 08:46 AM, said:

On my network, where 3003 is listening, there is a Serv-U installed listening on 43958

maybe it is only a backdoor which the hackers installed :blink:

But if the hacker installed this backdoor he is scanning hier own hacks???

Don't think so.

Greetz esorone
0

#17 User is offline   Erra 

  • Staff Sergeant
  • Icon
  • Group: Members
  • Posts: 263
  • Joined: 05-January 04

Posted 02 February 2004 - 11:58 AM

Unless of course he lost his list of his hacks.... and now he is trying to find them again ;)

Of course, that would be really funny. Scanning for his Serv-U port.... :D
0

#18 User is offline   TedOb1 

  • Private First Class
  • Icon
  • Group: Members
  • Posts: 120
  • Joined: 05-October 03

Posted 02 February 2004 - 08:40 PM

Again more speculation. Could be two warring warez gangs. One trying to take over the others sites.
0

#19 User is offline   Double-=V=- 

  • Private First Class
  • Icon
  • Group: Members
  • Posts: 90
  • Joined: 22-September 03

Posted 03 February 2004 - 01:48 AM

Well he could have some kinda autohacker which doesn't log the ip's it hacked.
0

#20 User is offline   x0x 

  • Private
  • Icon
  • Group: Members
  • Posts: 3
  • Joined: 03-February 04

Posted 03 February 2004 - 07:24 AM

In situations like this searching through web pages which although may appear to be relevant can sometimes lead you into the complete opposite direction.

Instead simply capture what is in the payload using tcpdump as below :

tcpdump -X port 3003 > gotcha.txt

Now you have the payload and can analyse the capture and search based on the contents and thus giving you more chance of identifying the scan.

Greetings.

x0x
0

#21 User is offline   Reckless 

  • Private First Class
  • Icon
  • Group: Members
  • Posts: 103
  • Joined: 31-January 04

Posted 07 February 2004 - 09:04 AM

Yeah , theres a very good possiblity the person is searching for his own hacks .. on the port .. coz i did it once too :P .. Mighta lost Ips .. So is prolly scanning for Ftp ports .
0

#22 User is offline   FakoLy 

  • Corporal
  • Icon
  • Group: Members
  • Posts: 155
  • Joined: 29-November 03

Posted 07 February 2004 - 04:16 PM

if you have servu on your machine that means you have a stro on your box :)
maybe port 3003 is used by the backdoor that the pirate installed and the othter port is the port used by servu..
look in your task manager for "servudaemon.exe" process but it could have been renamed, most hackers that make stros on other computers rename their servu process into "svchost.exe" because you can have more than one svchost.exe proces at the same time...
i think the port scan on port 3003 is just another warezer that is trying to scan for vulns.. maybe to own the stro :)
just try to find the servu home directory there are surely interesting things in it :) and look in system32 for the .ini file (to install you have to upp servudaemon.exe and servudaemon.ini to the remote-box and then, rename the exe and execute it.. i think you can't rename the ini)
0

#23 Guest_anole_*

  • Group: Guests

Posted 10 February 2004 - 09:17 PM

Yep FakoLy, you're absolutely right, There were lots (many gigs) of interesting files available (but not now) for download, as well as the server files themselves!
0

#24 User is offline   mdk 

  • Private
  • Icon
  • Group: Members
  • Posts: 14
  • Joined: 04-September 03

Posted 11 February 2004 - 04:59 AM

FakoLy: wrong.
You can rename the service name, the exe and ini filename...
Search the forum for "mod servu" or something like this. Heres a tutorial.
0

#25 User is offline   nubela 

  • Private First Class
  • Icon
  • Group: Members
  • Posts: 22
  • Joined: 21-January 04

Posted 11 February 2004 - 05:42 AM

FakoLy, on Feb 8 2004, 12:16 AM, said:

if you have servu on your machine that means you have a stro on your box :)
maybe port 3003 is used by the backdoor that the pirate installed and the othter port is the port used by servu..
look in your task manager for "servudaemon.exe" process but it could have been renamed, most hackers that make stros on other computers rename their servu process into "svchost.exe" because you can have more than one svchost.exe proces at the same time...
i think the port scan on port 3003 is just another warezer that is trying to scan for vulns.. maybe to own the stro :)
just try to find the servu home directory there are surely interesting things in it :) and look in system32 for the .ini file (to install you have to upp servudaemon.exe and servudaemon.ini to the remote-box and then, rename the exe and execute it.. i think you can't rename the ini)

yea u can rename the .ini by hex editting it.
0

#26 User is offline   barty32 

  • Private First Class
  • Icon
  • Group: Members
  • Posts: 59
  • Joined: 08-February 04

Posted 12 February 2004 - 05:45 AM

I'm rather sure it's only a backd00r of another hacker
0

#27 User is offline   securitydood 

  • Private
  • Icon
  • Group: Members
  • Posts: 13
  • Joined: 11-February 04

Posted 16 February 2004 - 11:01 AM

yeah servu listening on port 43958 is the default remote administrator that runs as part of servu.

as u already commented u had been hacked and abused :(

make sure you lock your box down a little better. get a firewall installed etc etc :)

as no one else mentioned 43958 I thought I'd post this reply :) sorry if its of no use to anyone.
0

#28 Guest_DvilleStoner_*

  • Group: Guests

Posted 26 February 2004 - 02:20 AM

Nostremato, on Feb 1 2004, 09:09 AM, said:

anole, on Feb 1 2004, 08:46 AM, said:

On my network, where 3003 is listening, there is a Serv-U installed listening on 43958

maybe it is only a backdoor which the hackers installed :blink:

like 8 times ditto
0

#29 Guest_DvilleStoner_*

  • Group: Guests

Posted 26 February 2004 - 02:21 AM

Double-=V=-, on Feb 3 2004, 09:48 AM, said:

Well he could have some kinda autohacker which doesn't log the ip's it hacked.

that would be kinda dumb ehh?
0

  • (2 Pages)
  • +
  • 1
  • 2
  • You cannot start a new topic
  • You cannot reply to this topic

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users

  • Share



Our Sponsors:


SwiftLayer Affiliate Web Hosting