Democratic Underground Latest Greatest Lobby Journals Search Options Help Login
Google

Please help - Whois this, don't know what to make of this

Printer-friendly format Printer-friendly format
Printer-friendly format Email this thread to a friend
Printer-friendly format Bookmark this thread
This topic is archived.
Home » Discuss » The DU Lounge Donate to DU
 
tnlefty Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Aug-15-03 04:31 PM
Original message
Please help - Whois this, don't know what to make of this
I came in and my firewall was goin' nuts so I backtraced the address that had tried to access a port and I don't understand this.

The Whois for 200.152.97.160 is part of LACNIC and the info. states that "this whois server contains only DOD information". RS.INTERNIC.NET was listed and so was www.internic.net, which is operated by the Dept. of Commerce. I tried to retrieve info. from there, but it seems that it is purposely untraceable or I just don't know what I'm doing....so that's my question: Who the hell is this and why are they so hard to track and why are they trying to access my computer??!!! Okay that's 3 questions.

Any help would be greatly appreciated.
Printer Friendly | Permalink |  | Top
LoneStarLiberal Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Aug-15-03 04:33 PM
Response to Original message
1. What Port?
What port is this address trying to access? If its tcp/135, you're looking at Blaster/Lovesan.
Printer Friendly | Permalink |  | Top
 
tnlefty Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Aug-15-03 04:39 PM
Response to Reply #1
4. I don't know
And even worse, I don't know how to find out. The info. in the firewall's log is TCP with the local IP 68.208.45.33 and from that I found the other DOD stuff.
Printer Friendly | Permalink |  | Top
 
Chuckup Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Aug-15-03 04:36 PM
Response to Original message
2. Here, this may help
OrgName: Latin American and Caribbean IP address Regional Registry
OrgID: LACNIC
Address: Potosi 1517
City: Montevideo
StateProv:
PostalCode: 11500
Country: UY

NetRange: 200.0.0.0 - 200.255.255.255
CIDR: 200.0.0.0/8
NetName: LACNIC-200
NetHandle: NET-200-0-0-0-1
Parent:
NetType: Allocated to LACNIC
NameServer: TINNIE.ARIN.NET
NameServer: NS.LACNIC.ORG
NameServer: NS.DNS.BR
NameServer: NS2.DNS.BR
Comment: This IP address range is under LACNIC responsibility for further
Comment: allocations to users in LACNIC region.
Comment: Please see http://www.lacnic.net/ for further details, or check the
Comment: WHOIS server located at whois.lacnic.net
RegDate: 2002-07-27
Updated: 2003-06-12

TechHandle: LACNIC-ARIN
TechName: LACNIC Hostmaster
TechPhone: (+55) 11 5509-3522
TechEmail: abuse@lacnic.net

OrgTechHandle: LACNIC-ARIN
OrgTechName: LACNIC Hostmaster
OrgTechPhone: (+55) 11 5509-3522
OrgTechEmail: abuse@lacnic.net
Printer Friendly | Permalink |  | Top
 
Tandalayo_Scheisskopf Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Aug-15-03 04:39 PM
Response to Reply #2
3. Most likely:
Somone found a server that was open in .uy and is using this for blaster scans and 'bot placement.
Printer Friendly | Permalink |  | Top
 
tnlefty Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Aug-15-03 04:49 PM
Response to Reply #2
8. thanks, I saw all of that
And from there I got the 200.152.97.160 info. that states it contains DOD info.
Printer Friendly | Permalink |  | Top
 
LynneSin Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Aug-15-03 04:40 PM
Response to Original message
5. I so not understand the crap my firewall is screening out
what are these people trying to do to get into my computer?

Do they have lives or what?
Printer Friendly | Permalink |  | Top
 
LoneStarLiberal Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Aug-15-03 04:41 PM
Response to Original message
6. Welcome to Brazilian Script Kiddies
I pulled this from lacnic (Latin American NIC). This is a well known ISP in the security field for all the script kiddies that try to hack around from it. There are no "hacking" laws in Brazil hence you see a lot of decidedly illegal and somewhat illegal activity originating from Brazilian IPs.

And don't waste your time reporting them. These clowns don't care and even if they did there's nothing they can do about it. My advice is just blow it off. If it persists, consider returning something to your pesky sender.

inetnum: 200.128/9
status: allocated
owner: Comite Gestor da Internet no Brasil
ownerid: BR-CGIN-LACNIC
responsible: Frederico A C Neves
address: Av. das Nações Unidas, 11541, 7° andar
address: 04578-000 - São Paulo - SP
country: BR
phone: +55 11 9119-0304 []
owner-c: CGB
tech-c: CGB
inetrev: 200.128/9
nserver: NS.DNS.BR
nsstat: 20030814 AA
nslastaa: 20030814
nserver: NS1.DNS.BR
nsstat: 20030814 AA
nslastaa: 20030814
nserver: NS2.DNS.BR
nsstat: 20030814 AA
nslastaa: 20030814
remarks: These addresses have been further assigned to Brazilian users.
remarks: Contact information can be found at the WHOIS server located
remarks: at whois.registro.br and at http://whois.nic.br
created: 19950104
changed: 20020902

nic-hdl: CGB
person: Comite Gestor da Internet no Brasil
e-mail: blkadm@NIC.BR
address: Av. das Nações Unidas, 11541, 7° andar
address: 04578-000 - São Paulo - SP
country: BR
phone: +55 19 9119-0304 []
created: 20020902
changed: 20020902
Printer Friendly | Permalink |  | Top
 
Paragon Donating Member (1000+ posts) Send PM | Profile | Ignore Fri Aug-15-03 04:41 PM
Response to Original message
7. Just a packet sniffer
Small-time wannabe hackers use them to try to find open connections that aren't blocked by a firewall.

Your firewall is just doing its job - and it should have an option to turn off those notifications to you. They can get annoying after a while.
Printer Friendly | Permalink |  | Top
 
DU AdBot (1000+ posts) Click to send private message to this author Click to view 
this author's profile Click to add 
this author to your buddy list Click to add 
this author to your Ignore list Fri May 10th 2024, 03:16 AM
Response to Original message
Advertisements [?]
 Top

Home » Discuss » The DU Lounge Donate to DU

Powered by DCForum+ Version 1.1 Copyright 1997-2002 DCScripts.com
Software has been extensively modified by the DU administrators


Important Notices: By participating on this discussion board, visitors agree to abide by the rules outlined on our Rules page. Messages posted on the Democratic Underground Discussion Forums are the opinions of the individuals who post them, and do not necessarily represent the opinions of Democratic Underground, LLC.

Home  |  Discussion Forums  |  Journals |  Store  |  Donate

About DU  |  Contact Us  |  Privacy Policy

Got a message for Democratic Underground? Click here to send us a message.

© 2001 - 2011 Democratic Underground, LLC