logo

register :: reset password
there are currently 10 active sessions :: 9.6.10.755 
<main>
<!-- forum -->
<terminal />
</main>
<manual>
<preface />
<rules />
<disclaimer />
</manual>

Advanced Search

« September, 2010 »
Su Mo Tu We Th Fr Sa
  1 2 34
5 6 7891011
12131415161718
19202122232425
2627282930 

irc.freenode.net #icv

Please Support ICV

security » Hack attempt? »

« : ‹ : [1] : › : »

default.gif

Hack attempt?

Today I got these strange firewall reports of someone trying to access my lsass.exe.

Type | Program | Source IP | Direction

New Server Program | system32\lsass.exe | 221.201.209.56 | Incoming (accept)
-
Program Access | lsass.exe | - | Incoming (accept)
-
Repeat Server Program | system32\lsass.exe | 124.64.45.14 | Incoming (accept)
-
Program Access | lsass.exe | - | Incoming (accept)
-
Repeat Program | system32\lsass.exe | - | (data)
-
Program Access | lsass.exe | - | (data)


I've run a little trace on those two IP's that showed up and they both pointed to China, first one was somewhere from Liaoning and the other one from Beijing.

Both from same ISP: CNCGROUP Liaoning/Beijing Province Network

Was this really a hack attempt on my computer?

posted by Shaddar :: 2007-03-06 13:23:17
[reply]

3a7778fc5b3c3ad2641cec5f9ba977795dc38b8a.jpg

Could be.

posted by amaranthinenight :: 2007-03-06 22:22:33
[reply]

1d47f38b6533af2e24dd3062dbb0ca7756456099.jpg

is all that "New server Program | system32\lsass,exe ...etc" from the log of your firewall??

posted by Bry Spy :: 2007-03-07 12:27:35
[reply]

default.gif

yes, it's from my Zone Alarm's FW log

posted by Shaddar :: 2007-03-07 17:27:22
[reply]

default.gif

tbvh it has properties of an automated program.... and to be honest, the ip was more than likely a proxy...for eg. my ip from hour to hour reads that im in america, suadi arabia, new zeland, germany, canada, italy, and even china....only disadvantage of being hidden behind china ip is that google is banned...

and oh yeah....they were trying to hack you.... lsass.exe is a system process of the Microsoft Windows security mechanisms. It specifically deals with local security and login policies. This program is important for the stable and secure running of your computer and should not be terminated

hope that helps somewhat ...

posted by Skalragg :: 2007-03-25 20:16:58
[reply]

« : ‹ : [1] : › : »

source rendered in (0.24607706069946) seconds :: rss