Page 1 of 1

worldgroup being hacked?

Posted: Tue May 16, 2006 7:12 pm
by Malakai
Some thing a little weird has happened.. I noticed that my router and modem had been pretty much non-stop blinking (data being sent through it) so I checked out worldgroup to see what was happening, and I see a bunch of web page errors like:

Web Page Does Not Exist chan 01
/netmail/horde//README requested by 216.177.21.106

/webmail_horde//README requested by 216.177.21.106

/horde-3.0//README requested by 216.177.21.106

/imp//README requested by 216.177.21.106

/webmail//README requested by yadda yadda

/people/horde//README ......

/projects/horde//README

/horde//README

/horde-3.0.9/README

/horde3//README

/horde2//README

/horde//README

//README

After all of this, I don't see any more errors, but data is flowing through the lines constantly, like some one is downloading a bunch of information from my pc. Could this be some one trying to find some type of exploit or backdoor?

Posted: Tue May 16, 2006 11:05 pm
by Questman
Yep, they're trying to find a hole.. or an exploit. Just monitor it.

Also make sure your e-mail service is NOT set to relay ! You could have people relaying SPAM through your box.

Posted: Mon Jun 12, 2006 9:27 pm
by Logos

I was having the same problem last year but was able to wet my windows 2000 server to block the hacker.

Posted: Thu Jun 15, 2006 5:32 am
by dspain
Logos wrote:

I was having the same problem last year but was able to wet my windows 2000 server to block the hacker.
yeah but like rick said if you allow your smtp server to relay spammers will send mail through it non-stop.

Posted: Mon Jul 03, 2006 2:19 am
by painter
dspain wrote:
Logos wrote:

I was having the same problem last year but was able to wet my windows 2000 server to block the hacker.
yeah but like rick said if you allow your smtp server to relay spammers will send mail through it non-stop.
One more thing. I am not online yet so I know it didn't come from a spammer. My system is trying to send a smtp e-mail to someone. I have installed this from a CD from Galaticomm. It would have sent it out but like I said. I am not on line yet. The address is www.daum.net. After I installed the software I found a trojin the next week and removed it. Now. Has anyone checked there system and found something?

Posted: Mon Jul 03, 2006 5:33 am
by dspain
painter wrote:
dspain wrote:
Logos wrote:
yeah but like rick said if you allow your smtp server to relay spammers will send mail through it non-stop.
One more thing. I am not online yet so I know it didn't come from a spammer. My system is trying to send a smtp e-mail to someone. I have installed this from a CD from Galaticomm. It would have sent it out but like I said. I am not on line yet. The address is www.daum.net. After I installed the software I found a trojin the next week and removed it. Now. Has anyone checked there system and found something?
you could have a cd a hacker sent out?
if ya want a legit 3.3 cd lemme know.

Posted: Mon Jul 03, 2006 9:28 pm
by Questman
I need to put the Worldgroup 3.2 CD ISO online for download. This is ridiculous.

netVillage must have crap built into the 3.3 that they distribute.

Posted: Mon Jul 03, 2006 10:51 pm
by painter
dspain wrote:
painter wrote:
dspain wrote: you could have a cd a hacker sent out?
if ya want a legit 3.3 cd lemme know.
Like I said. This CD was sent to me from Glacticomm before Mr Striker did the unthinkable. Now. I can send you a copy of the CD if you would like to look at it and see if you see something. They could have had something on that computer that made the disk. I don't know and there is no way of checking now. I might scan this disk and see if something is on it.

No one else has seen anything?

I have a problem with the Client working on Windows XP. It gives me a GP error with BTrieve and my spyware program is getting a trojin with the same name as my system. I guess it is just a line of code that the program is picking up. I just guessed it was a false read.

Posted: Mon Jul 03, 2006 10:56 pm
by painter
you could have a cd a hacker sent out?
if ya want a legit 3.3 cd lemme know.[/quote]

I only have a activation code for WG 3.0. I am registered for WG 3.0. :D

Posted: Tue Jul 04, 2006 12:25 am
by Malakai
I've had no problems with the 3.30 CD version that rick has. Maybe you have the worldgroup relaying e-mail turned on.

As far as getting worldgroup to compile a worldgroup manager for windows xp, they won't do that yet. Dspain is working on a fix for that, as well as general updating of the ICO, which I hope will be available soon.

Posted: Tue Jul 04, 2006 2:09 am
by painter
Malakai wrote:I've had no problems with the 3.30 CD version that rick has. Maybe you have the worldgroup relaying e-mail turned on.

As far as getting worldgroup to compile a worldgroup manager for windows xp, they won't do that yet. Dspain is working on a fix for that, as well as general updating of the ICO, which I hope will be available soon.
No relaying. I turned all the FTP and SMTP and everything I could see about anything to do with a echo. I even turned off worldlink.

DTL! I guess I will have to setup a old mother board and start a dos system. If the worldgroup manager works with DOS that is what I might do.

I have been trying to Telnet out with Explorer. Any tricks that you know?

Posted: Tue Jul 04, 2006 4:32 am
by dspain
Questman wrote:I need to put the Worldgroup 3.2 CD ISO online for download. This is ridiculous.

netVillage must have crap built into the 3.3 that they distribute.
yeah seems almost everyone has a problem with the 3.3 cd

Posted: Wed Jul 19, 2006 6:59 am
by Hagrid
Malakai wrote:I've had no problems with the 3.30 CD version that rick has. Maybe you have the worldgroup relaying e-mail turned on.

As far as getting worldgroup to compile a worldgroup manager for windows xp, they won't do that yet. Dspain is working on a fix for that, as well as general updating of the ICO, which I hope will be available soon.
Tere is a fix for that, if its what i think it is. I put it on my ftp server, it has the directions. This is from the sysop forum.

EDIT * I guess its already on the download file list * :)

Posted: Wed Jul 19, 2006 11:06 pm
by dspain
Hagrid wrote:
Malakai wrote:I've had no problems with the 3.30 CD version that rick has. Maybe you have the worldgroup relaying e-mail turned on.

As far as getting worldgroup to compile a worldgroup manager for windows xp, they won't do that yet. Dspain is working on a fix for that, as well as general updating of the ICO, which I hope will be available soon.
Tere is a fix for that, if its what i think it is. I put it on my ftp server, it has the directions. This is from the sysop forum.

EDIT * I guess its already on the download file list * :)
no thats just a patch hes talking about compiling it to run under XP with no patches.