Link to home
Start Free TrialLog in
Avatar of Cubbybulin
Cubbybulin

asked on

Hackers

Someone is really trying to get into my server. When I look at the event log it looks like its several different people from several different IP addresses from all over the world, but the usernames are consistent which makes me think its one person only. its not the usual administrator/password combination but a username that makes me think this person knows me. I dont know too much of hacking, how is it possible though that the IP addresses/workstations are always different? Am I just wasting my time blocking those IPs one by one? Is there a way to find out who is he/his real IP address? Or what can I do? Any suggestions?
Avatar of Member_2_3684445
Member_2_3684445
Flag of Netherlands image

Instead of the IP he is using (wich might and most prob will be public proxy), why dont you block the port he is opperating on.

Or if you have IDS available you can try and find certain signatures in the packets. There is bound to be client information in the header of the tcp packets. But thats far streached for most...
Avatar of Cubbybulin
Cubbybulin

ASKER

It says: Source Port: 0
We dont have IDS - what is a good one/good price? Thanks! Is there a program that could find him?
ASKER CERTIFIED SOLUTION
Avatar of MidnightOne
MidnightOne
Flag of United States of America image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
or a old fashion Hub that is ;-)