Old 15th February 2005, 23:55   #1
ClassicRox
Senior Member
 
Join Date: Jul 2002
Posts: 218
Hacking?

Over the last 3 days, I've been getting this kind of log entries:

<02/15/05@19:00:40> [source] invalid password from GET / HTTP/1.0 67.175.231.7
<02/15/05@19:08:14> [source] invalid password from GET / HTTP/1.0 67.175.231.7
<02/15/05@19:15:58> [source] invalid password from GET / HTTP/1.0 67.175.231.7
<02/15/05@19:23:28> [source] invalid password from GET / HTTP/1.0 67.175.231.7

That's only a small portion of it. It seems to repeat itself every 7 1/2 to 8 minutes, as you can see by the log.

Is this someone trying to hack my admin password? If so, what should I do about it?
ClassicRox is offline   Reply With Quote
Old 16th February 2005, 11:26   #2
NumbCore
Junior Member
 
Join Date: Feb 2005
Location: New Jersey
Posts: 49
Send a message via AIM to NumbCore
Block the IP address?
NumbCore is offline   Reply With Quote
Old 16th February 2005, 11:51   #3
NJK
FRISIAN (MOD)
 
NJK's Avatar
 
Join Date: Sep 2003
Location: in a house
Posts: 16,103
ip number 67.175.231.7 tracks back to :

OrgName: Comcast Cable Communications, IP Services
OrgID: CCCIS
Address: 1800 Bishops Gate Blvd.
City: Mount Laurel
StateProv: NJ
PostalCode: 08054-4628
Country: US

below is the e-mail adress to send a complaint about this ip adress.


OrgAbuseHandle: NAPO-ARIN
OrgAbuseName: Network Abuse and Policy Observance
OrgAbusePhone: +1-856-317-7272
OrgAbuseEmail: abuse@comcast.net

Each Thursday a new show on Celtica Radio with Darkwave music.

WINAMPSHOUTCAST
NJK is offline   Reply With Quote
Old 16th February 2005, 13:27   #4
CraigF
Passionately Apathetic
Administrator
 
CraigF's Avatar
 
Join Date: May 2000
Location: Hell
Posts: 5,435
hardly a case of contacting abuse. they are just hitting your shoutcast default page. probably tracking your listener figures, or maybe song playing/history.

CraigF is offline   Reply With Quote
Old 16th February 2005, 18:46   #5
MegaRock
Forum King
 
MegaRock's Avatar
 
Join Date: Jun 2003
Location: Inside my water bong
Posts: 6,865
Send a message via ICQ to MegaRock Send a message via Yahoo to MegaRock
Guess I should throw this into the thread. After the well known security hole in 1.9.4 I noticed that being a station with no on-demand programming there should be no attempts to connect to the /content/ directory without a reason.

I am seeing this alot in my log files:

<02/14/05@00:00:11> [dest: 83.192.249.42] Invalid resource request( HTTP/1.0)
<02/14/05@00:00:14> [dest: 83.192.249.42] Invalid resource request( HTTP/1.0)
<02/14/05@00:00:15> [dest: 83.192.249.42] Invalid resource request( HTTP/1.0)
<02/14/05@00:00:15> [dest: 83.192.249.42] starting stream (UID: 597)[L: 7]{A: shoutcastsource}(P: 1)
<02/15/05@15:15:05> [dest: 193.179.245.70] Invalid resource request( HTTP/1.0)
<02/15/05@15:15:05> [dest: 193.179.245.70] Invalid resource request( HTTP/1.0)
<02/15/05@15:15:06> [dest: 193.179.245.70] starting stream (UID: 5983)[L: 69]{A: shoutcastsource}(P: 9)
<02/15/05@15:15:08> [dest: 193.179.245.70] connection closed (3 seconds) (UID: 5983)[L: 68]{Bytes: 24576}(P: 9)
<02/15/05@15:15:09> [dest: 193.179.245.70] starting stream (UID: 5984)[L: 69]{A: shoutcastsource}(P: 9)
<02/15/05@15:15:00> [dest: 193.179.245.70] Invalid resource request( HTTP/1.0)
<02/15/05@15:12:33> [dest: 193.179.245.70] Invalid resource request( HTTP/1.0)
<02/15/05@15:12:33> [dest: 193.179.245.70] starting stream (UID: 5969)[L: 69]{A: shoutcastsource}(P: 12)

The first thing I notice is the player name being 'shoutcastsource' which as far as I know is not a legitimate player. Since in my log files I can see what one would expect of someone trying to hack the server - first trying the /content/ hack then checking to see if the stream is still up before continuing.

As I can see this occuring over several days repeatedly these are the kind of people I would report immediately as it is either a person manually going through a list trying to knock servers offline or someones computer infected with a virus or some type of worm and again people who have infected computers deserve to be removed from the internet until they clean up their PC's.

Whats your thoughts on this?

Megarock Radio - St. Louis Since 1998!
Don't click this link!
Corporate Radio Sucks! No suits, all rock!
MegaRock is offline   Reply With Quote
Old 16th February 2005, 23:10   #6
Jay
Moderator Alumni
 
Jay's Avatar
 
Join Date: May 2000
Location: Next Door
Posts: 8,942
put your foil hats away. Someone is just connecting via a client on the source port. No hack attempt just an idiot alert.
Jay is offline   Reply With Quote
Old 16th February 2005, 23:28   #7
MegaRock
Forum King
 
MegaRock's Avatar
 
Join Date: Jun 2003
Location: Inside my water bong
Posts: 6,865
Send a message via ICQ to MegaRock Send a message via Yahoo to MegaRock
...but my foil hat looks kewl!

Megarock Radio - St. Louis Since 1998!
Don't click this link!
Corporate Radio Sucks! No suits, all rock!
MegaRock is offline   Reply With Quote
Reply
Go Back   Winamp & Shoutcast Forums > Shoutcast > Shoutcast Technical Support

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump