Topic: ok the community FTP site i put up was tagged as a public leech by someone  (Read 1421 times)

0 Members and 1 Guest are viewing this topic.

Offline manitoba1073

  • FLEET ADMIRAL OF THE YARDS
  • Lt. Commander
  • *
  • Posts: 1119
  • Gender: Male
    • manitobashipyards
i believe it is NOT someone from the community.  but the ip address is 172.206.1.106   so thats the ip of the person. just so everyone knows the file created was called i 90285.  next time i find something i will be talkin to a friend of mine to have a suprise there for the ppl responible.  so i u ever open the folders of unknown in the site be very very wary and only open and D/L  stuff from known members of the community.  so plz dont think i am yelling at anyone here as again i DO NOT beleive anyone in our great community would do something like that. so plzz as a precaution watch the folders carefully. as it is a community wide folder. and for everyone's benefit.   thank you all for ur time. and i will be posting it in our other forums too

PS not sure if its condoned here, but as i am sure there are a few ppl with the talents. and i really dont wont to resort to an old friend yet, see what they can do. or leave me advise here. cause my friend can get carried away with things.



Offline Dash Jones

  • Sub-Commander of the Dark Side
  • Captain
  • *
  • Posts: 6477
  • Gender: Male
So if I understand, someone has put a file up on your site and using your bandwidth to host it?
"All hominins are hominids, but not all hominids are hominins."


"Is this a Christian perspective?

Now where in the Bible does it say if someone does something stupid you should shoot them in the face?"

-------

We have whale farms in Jersey.   They're called McDonald's.

There is no "I" in team. There are two "I"s in Vin Diesel. screw you, team.

Offline manitoba1073

  • FLEET ADMIRAL OF THE YARDS
  • Lt. Commander
  • *
  • Posts: 1119
  • Gender: Male
    • manitobashipyards
well kinda of more than that. what they tried to do is a multi folder way of hosting what ever they want with out permission or consent, and tried to prevent it from being deleted,http://archives.neohapsis.com/archives/sf/ms/2001-q2/att-1116/01-THE-END-OF-DELETERS-v2.1.txt

heres what they were trying to do in a nut shell



Offline Monty

  • Lt. Junior Grade
  • *
  • Posts: 123
  • Gender: Male
Just read that document.

While the intent of the document may be wrong... i have to admit that its pretty clever.

Out of curiosity, how did you know this was happening?

Offline toasty0

  • Application.Quit();
  • Captain
  • *
  • Posts: 8045
  • Gender: Male
Just read that document.

While the intent of the document may be wrong... i have to admit that its pretty clever.

Out of curiosity, how did you know this was happening?

And how did they know his FTP password?

As for how he knew, he pro'ly reads his cite logs unlike so many other site owners.

Jerry
MCTS: SQL Server 2005 | MCP: Windows Server 2003 | MCTS: Microsoft Certified Technology Specialist | MCT: Microsoft Certified Trainer | MOS: Microsoft Office Specialist 2003 | VSP: VMware Sales Professional | MCTS: Vista

Offline Nemesis

  • Captain Kayn
  • Global Moderator
  • Commodore
  • *
  • Posts: 13072
Sounds like a good place to add your own trojan.
Do unto others as Frey has done unto you.
Seti Team    Free Software
I believe truth and principle do matter. If you have to sacrifice them to get the results you want, then the results aren't worth it.
 FoaS_XC : "Take great pains to distinguish a criticism vs. an attack. A person reading a post should never be able to confuse the two."

Offline Bonk

  • Commodore
  • *
  • Posts: 13298
  • You don't have to live like a refugee.
No member here has posted with that IP address.

It is an AOL account (probably dial-up).

Note the details, date and time of the attack and send your concerns here: abuse@aol.net

I'd simply reccomend against running a public ftp folder, there are plenty of other more secure solutions.
(things like http://www.webfilebrowser.org/ )

Hope you get it sorted out and get that file deleted. If your ftp is infected please do not link it here in the meantime, thanks.

Offline manitoba1073

  • FLEET ADMIRAL OF THE YARDS
  • Lt. Commander
  • *
  • Posts: 1119
  • Gender: Male
    • manitobashipyards
yeap got it taken care of for now. long process but its cleaned. as for finding it, i chk everyday. lol.  logs and for new files. i have the access set to anynomus for this communtiy. so right now there current isnt a password required. so all i have to do is keep an eye on it. as thats all ppl can do is add files not change anything outside the ftp site. 



Offline Just plain old Punisher

  • Vice Admiral
  • *
  • Posts: 36927
  • Gender: Male
  • I'm not facist, I just like wearing jackboots
It's not all that hard, look people do port scans of addresses...port 21 is usually whats used for FTP. When they get responses on that port, they see how secure the FTP server is. If you have limited or no security...
Then bam, they use it for warez.

"Sex is a lot like pizza.  If you're not careful you can blister your tongue". -Dracho