Wilders Security Forums  

Go Back   Wilders Security Forums > Privacy Related Topics > privacy problems
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old February 11th, 2005, 01:36 PM
perplexed
 
Posts: n/a
Default Am I in trouble? Hacked?

Hi all,

I'm rather perplexed in that some of my apps are displaying strange behaviour in that they'd want to connect to the site 64.15.205.241 first.

For example, I've just installed spywareguard from javacool and it too wants to connect to 64.15.205.241

Windows messenger same story.

What's happening?

ps
I've just done a fresh reinstall of WinXp home edition and updated it to all the latest hotfixes.
Am using Kerio 2.15
  #2  
Old February 11th, 2005, 01:38 PM
dog
 
Posts: n/a
PixelPup Re: Why?

Hi perplexed,

Could that be your ISP's DNS server?

Steve
  #3  
Old February 11th, 2005, 01:43 PM
perplexed
 
Posts: n/a
Default Re: Why?

Hi Dog,

Thanks for the reply. How do I verify whether it's my isp dns server? I never use to notice this, been using kerio 2.15 all this while. When browse 64.15.205.241 I get something like a site placeholder directory with links which seem to come from roar.com. At times it seems to be linked with www.pageseeker.com

Still perplexed
  #4  
Old February 11th, 2005, 01:49 PM
perplexed
 
Posts: n/a
Default Re: Why?

hmmm shouldn't be my isp dns server cos when I get kerio to deny it I still get to browse websites and such. Also my webbrowser doesn't seem to need to go through 64.15.205.241. Strange thing is that prior to my reinstallation of winxp, when I browse some sites like eg www.mepis.org I'd get the same placeholder directory site as 64.15.205.241

perplexed
  #5  
Old February 11th, 2005, 02:26 PM
perplexed
 
Posts: n/a
Default Re: Am I in trouble? Hacked?

snapdragin, thanks for changing the title for me. posted too quick and didn't realise i couldn't edit the title.

anyone able to provide some insight?
  #6  
Old February 11th, 2005, 02:30 PM
perplexed
 
Posts: n/a
Default Re: Am I in trouble? Hacked?

have tried lavasoft, spybot search and destroy and nothing found yet. have scanned with pc cillin 2002, avast 4.5 with no results thus far.
  #7  
Old February 11th, 2005, 02:49 PM
Cochise's Avatar
Cochise Cochise is offline
A missed friend
 
Join Date: Jan 2003
Location: North Thoresby Lincs Good Olde England
Posts: 2,549
Default Re: Am I in trouble? Hacked?

I've just Googled it??.....Don't think it's your ISP....Check it out...



Cochise,
__________________
They told me that it couldn't be done,
With a smile I went right to it,
I tackled the job they said couldn't be done,
And I couldn't Damn-well do it!
  #8  
Old February 11th, 2005, 03:04 PM
perplexed
 
Posts: n/a
Default Re: Am I in trouble? Hacked?

Quote:
Originally Posted by Cochise
I've just Googled it??.....Don't think it's your ISP....Check it out...



Cochise,

Hi Cochise,

Indeed I already highly doubt it's my ISP. The ip address seems to be associated to pageseeker.com / roar.com... The thing which perplexes me is how have they come into my system? Remember I did a fresh reinstall and immediately installed kerio and then all the security updates for winxp...

and yet?
  #9  
Old February 11th, 2005, 03:55 PM
perplexed
 
Posts: n/a
Default Re: Am I in trouble? Hacked?

Just completed a scan with ewido. No infections found.

Hmmm anyone with some ideas on what / where I should do / look / investigate next?
  #10  
Old February 11th, 2005, 04:13 PM
perplexed
 
Posts: n/a
Default Re: Am I in trouble? Hacked?

Used Kerio to block out 64.15.205.241
then blocked out 64.15.205.240

Right now i attempt to trigger this through launching windows messenger. After blocking the 2 ip addresses above... it came up with the ip address 64.15.205.180 which I've blocked...

any theories/ideas on how this can happen?
  #11  
Old February 11th, 2005, 04:51 PM
Bubba's Avatar
Bubba Bubba is offline
Global Moderator
 
Join Date: Apr 2002
Posts: 11,279
Default Re: Am I in trouble? Hacked?

Just a thought

All 3 of those IP's belong to Savvis Communications....an Internet backbone....similar to Level3 Communications, one of the largest Internet backbones in the world. At one time Level3 and Savvis had network service agreements....and they may still do. Level3 definetly helps Microsoft with their load....so perhaps Savvis is helping Level3 to help Microsoft ?

Do you lose any functions when you disallow any of those IP's....gifs, ads....etc ?
  #12  
Old February 12th, 2005, 11:26 AM
perplexed
 
Posts: n/a
Default Re: Am I in trouble? Hacked?

i'm now trying a different isp now and interestingly i'm not getting the problem. windows messenger, spyware blaster behave as one'd expect.

still i'm not sure exactly what the problem is. the "problem" isp is a reputable one who mainly deal with business customers.

Or is it more likely to be the case where... somehow my ip range is actually recorded by some server somewhere. take the case of windows messenger. after i'd blocked the first ip 64.15.205.241, the second time when i attempted to sign-in, there was a noticeable delay before the second ip 64.15.205.240 popped up as a kerio alert.

@ bubba:
No don't seem to lose any functionality. The more worrisome thing is that if you google those ip addresses, one would notice that they seem to be on the block lists of spyware addresses.

how is the mysterious communication taking place?
perplexed
  #13  
Old February 15th, 2005, 11:08 AM
perplexed
 
Posts: n/a
Default Re: Am I in trouble? Hacked?

anyone else with some thoughts on this?
  #14  
Old February 15th, 2005, 11:46 AM
Capp's Avatar
Capp Capp is offline
Very Frequent Poster
 
Join Date: Oct 2004
Location: United States
Posts: 2,125
Default Re: Am I in trouble? Hacked?

My thoughts...

run IPCONFIG /ALL to see what ip address your DNS server actually is (so you'll know)

run NETSTAT -A to see all the ports that are being accessed

That is just a start.
  #15  
Old February 15th, 2005, 02:08 PM
perplexed
 
Posts: n/a
Default Re: Am I in trouble? Hacked?

@ capp

Thanks. I'm not using the "problematic" isp at the moment. Will see what happens when i get back to it. A comparison of kerio and the output from netstat -a looks fine for the moment.

And yup ipconfig does confirm that those addresses are most certainly not the isp's dns servers. (jogged my memory when you mentioned using ipconfig)
  #16  
Old February 15th, 2005, 03:29 PM
kareldjag's Avatar
kareldjag kareldjag is offline
Frequent Poster
 
Join Date: Nov 2004
Location: Feet in France, Mind in the World
Posts: 521
Default Re: Am I in trouble? Hacked?

Hi,

If many of your trusted applications try to be connected on 64.15.205.241 on port 53, it does not mean that you have been hacked.
I think it's quite normal:this IP may be your provider.

You could make a search online: http://www.samspade.org

Or you could use IPTicker or eStop (show the ip connection):

*IPTcker: http://www.soft-trek.com.au/prjIPTicker.asp

*eStop: http://www.nwpsw.com/estopmain.html

Regards
__________________
Independent vision of Security (Security? Yeah But Well: http://www.ouaismaisbon.ch/ )
Fight child crime: http://www.circamp.eu/ http://www.virtualglobaltaskforce.com/
  #17  
Old February 15th, 2005, 03:31 PM
Capp's Avatar
Capp Capp is offline
Very Frequent Poster
 
Join Date: Oct 2004
Location: United States
Posts: 2,125
Default Re: Am I in trouble? Hacked?

Quote:
Originally Posted by perplexed
@ capp

Thanks. I'm not using the "problematic" isp at the moment. Will see what happens when i get back to it. A comparison of kerio and the output from netstat -a looks fine for the moment.

And yup ipconfig does confirm that those addresses are most certainly not the isp's dns servers. (jogged my memory when you mentioned using ipconfig)


Glad to help and sorry I couldn't be of more help. I don't know Kerio so I won't touch that one
  #18  
Old May 5th, 2005, 09:25 PM
joeseriously
 
Posts: n/a
Thumbs down Re: Am I in trouble? Hacked?

Quote:
Originally Posted by perplexed
anyone else with some thoughts on this?
DRM(digit'l rights mgmt.) as a component of M$ WINXP
  #19  
Old June 5th, 2005, 08:10 PM
dezel
 
Posts: n/a
Default Re: Am I in trouble? Hacked?

No you havn't been hacked - loooks like some nasty spyware for example Cydoor! run Hijackthis, then copy and paste the log file at www.hijackthis.de for a quick check to see whats on your comp.
  #20  
Old June 5th, 2005, 08:14 PM
bigc73542's Avatar
bigc73542 bigc73542 is offline
Retired Moderator
 
Join Date: Sep 2003
Location: SW. Oklahoma 28.360USB, 27.385LSB, 147.255+
Posts: 23,620
Default Re: Am I in trouble? Hacked?

Just in case noone has traced the Ip here it is in part
Attached Images
 
__________________
The Only Safe Computer Is Unplugged
MEMBER ASAP since 2004
Alliance of Security Analysis Professionals
  #21  
Old June 5th, 2005, 08:18 PM
bigc73542's Avatar
bigc73542 bigc73542 is offline
Retired Moderator
 
Join Date: Sep 2003
Location: SW. Oklahoma 28.360USB, 27.385LSB, 147.255+
Posts: 23,620
Default Re: Am I in trouble? Hacked?

second part
Attached Images
 
__________________
The Only Safe Computer Is Unplugged
MEMBER ASAP since 2004
Alliance of Security Analysis Professionals
  #22  
Old September 26th, 2005, 10:25 PM
bizet bizet is offline
Infrequent Poster
 
Join Date: Sep 2005
Posts: 1
Default Re: Am I in trouble? Hacked?

I just read this post searching for troubleshooting same. May this help others.

What I found is using this DOS command:

Run...Cmd..netstat -b

that showed the software using the port to that connection we are aware, in this case to SAVVIS.. the software was msnmgr.exe. Even when I was not connected to it, the app was in the system tray, once I closed the app, the connection to savvis dissapeared.

Regards
 

Wilders Security Forums > Privacy Related Topics > privacy problems « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 02:18 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums