Anonymous Proxy Forum


FromMessage 
curious

10/16/2000
11:44:33 Subject: just curious

Message:
hi all. hust stumbled onto this forum and have been enlightened by some posts and giggled at
some otherz!(tho' not in a bad way;) 
one thing i did find was this:- 127.0.01 is this the number of a proxy sumwhere or this sites
IP? 

i really would like to know this as ive been port scanned a few times latley and its this
little number that keeps poppin its head up! 

after tracing the number 127.0.01 i get a 'IANI loopback' perhps sum 1 can switch the torch on
for this reply i get. incidentally,this is the only trce that ever brings this up! 

maybe im being completely naive here but i would like to know just what this 127.0.01 is. 
cheers then ;)


Tracing 127.0.0.1

10/16/2000
12:39:24 RE: just curious

Message:
127.0.0.1 is IP of local network on every PC....


Anonymous

10/16/2000
13:01:23 RE: just curious

Message:
curious, you are really stupid


curious again

10/16/2000
13:02:58 RE: just curious

Message:
thnx 4 kwik reply. 

can u tell me then, why would they be scanning me for open ports? 
thnx.


Schmeltzer

10/17/2000
02:08:03 RE: just curious

Message:
They just want to get to know you a little better bud, that's all!


grvyx

10/17/2000
03:33:25 RE: just curious

Message:
g'day curious, 

firstly, ignore the replies above (except tracing's)... especially the anonymous dickhead. 

to better explain what Tracing is saying, as far as any computer on the internet is concerned,
there are ip addresses for other computers, and an exclusive ip address for itself. its way of
referring to itself is with ip address: 127.0.0.1 it's like another way of a computer saying
"me". that would explain your loopback errors when you're trying to trace that ip address. 

it sounds a little concerning that your own computer is being port-scanned by itself! what
program is picking this stuff up? if it's picking up a trace coming from within your own
computer, i would guess one of two things (however i am far from an expert on the subject) -
either you have some sort of trojan on board looking for a way out, or your firewall software
is set to ultra-paranoid - try relaxing the settings a bit. 




curious

10/17/2000
11:48:55 RE: just curious

Message:
thnx a lot for that mate, its just the answer i was looking for (grvyx) 
im using intruder alert for port scans on my pc. the reason why im asking this is because i
installed an IP spoofer. when 'run' it said i needed a 'dll' file that was missing. i tracked
down the file and put it where it should be! almost instantaneously i was scanned. my intruder
alert did its job and told me. i put several different IP numbers into the spoofer but (yknow)
something wasn't right ! i asked a friend about it and he told me to get rid of it immediately
cause it looked like a hacker trap ! it prolly was. 
its just that this 127,,,, keeps popping up on my stealth anonymiser! and lately i noticed
that when d/ling something, half way it stops and then i notice that the monitor icons on my
tray are saying that info is coming and going (@ a very fast rate too. i did notice the noise
of the modem switching off but the icons did not give a disconnected sign (the red cross on
the icon) and then then data was transfered but i didnt do anything to star this process. i
will update my trojan d/base and see if it can find something. 
tho' i do remember a story not so long back about virtually the same thing happng (modem
cutoff) and it turned out that a way was devised to fool the user into thinking s/he was
connected but the line was redirected to a high paying international phone line which netted a
substantial amount of money. i think this could be something like that! needless to say im
monitoring the situation and if it continues ill contact my ISP. thnx all 4 your replys except
of course.........:


Hangetsu

10/18/2000
01:48:24 RE: just curious

Message:
Just a thought, but a "Land" attack is where the attacker spoofs localhost in an attempt to
make your system connect to itself requiring reboot. 
127.0.0.1 Address 
255.255.255.255 Mask 
to 
127.0.0.1 Address 
255.255.255.255 Mask 

"127.0.01 is this the number of a proxy sumwhere or this sites IP? 
i really would like to know this as ive been port scanned a few times latley and its this
little number that keeps poppin its head up!" 

Hangetsu 



grvyx

10/18/2000
02:01:36 RE: just curious

Message:
...interesting - i haven't heard of that - is that similar to some kind of nuke? 

curious says that he's been playing with a spoofer program recently - reckon that could have
anything to do with it?


curious

10/18/2000
08:54:51 RE: just curious

Message:
well it looks like there's sumthing new in the pot,lol. 
the names dave btw. intersteing point made above about attacks. just to clear 'tings up, the
app was called 'chaos' ipspoofer. also, ive noticed that when i reconnect some times my
hotmail messenger will not connect (this happens everyother time i connect!) o would hasten a
guess that i do have a trojan in my system but all relevant searches find nothing. perhaps a
new one maybe. its got me ;() 
thnx all again and im still open to advice or suggestions ;) 
cheers.


Hangetsu

10/18/2000
10:25:01 RE: just curious

Message:
curious, if you do have a trojan it needs to communicate and will attempt to open a port.
Reboot for a fresh start and do a netstat -a 
to check for listening ports. Check your win.ini to make sure of this setting: 
NullPort=None 
grvyx, "Land" is not restricted to any port and can use TCP to attack ports 0-65535. If you
run a firewall that you can specify IP#'s and ports a rule to block can be made: 
Block Remote TCP 
127.0.0.1 Address 
255.255.255.255 Mask 
ports 0-65535 
to 
127.0.0.1 Address 
255.255.255.255 Mask 
ports 0-65535 

Hangetsu 



IRONMAN

10/18/2000
20:10:42 RE: just curious

Message:
To get rid of the trojan try command antivirus that was the cure for my virus problem. It is
the most comprhensive program out there. 

http://www.commandcom.com/products/index.html 



Traviss

10/19/2000
17:58:05 RE: just curious

Message:
I Have a Off Based Question. I Have MP Hooked to Proxymitiron And I Keep Getting Error Message
From MP After It Has Been Workin And I Run a Test All Proxiys.. It Says The Port I Use To Test
Aninimity(Have ever ya Spell it) Is Blocked by FireWall Or Other Wise Unecessable. I Can Just
Change It And It Works But Its Just Weird That It Will Run(In same session) And Everyonce in
awhile When I Test Proxys It Says Its Blocked.. 

Anyway I Was just reading and Saw Somthing about Trojan And Port Needing To Be Used And
thought I Whould Ask.. I Have had a Few To Many Trojans (becouse I am Dumb) I Tried To Help My
Friend Fix One He Got And I Infected Myself But I Did Get It Off Me because I Used Safe
Installer On NetMecanic And Traced Where It Planted But I Try To The Death Of Me To Tell My
Friend And He Just Cant Get It Off Him.. AnyWays Im About To Upload It And Repost It Here If
Anyone Wants To Take a Look At It.. Hehe.. Its a AOL one To (Blushes From Still Using AOL). Ok
Thank Ya.. 

MindWaste
