Quote:
Originally posted by recoiled@Aug 19 2005, 12:56
how can you verify this?
please do :)
|
I can.
On dragon server, without even using a packet sniffer, just a simple Netstat -b, I can see that Conquer.exe has established a TCP Connection. Local Address is obviously my PC, and there is a connection open to the foreign address of customer-reverse-entry.69.59.185.100:5816.
All connections are from IE, msnmsgr.exe (MSN Messenger) and Conquer.exe. And guess what? This IP you find suspicious differs by ONE digit from the alleged backdoor IP. I have not run BJX Bot AT ALL, let alone his version of it, so that is not an issue here.
Now let me connect to phoenix real quick.
I just created a character on phoenix server. Using Netstat -b, both right after logging in and right after creating a character,we can see a connection is timing out to customer-reverse-entry.69.59.142.13:9958. So the port is 9958, and just as chocoman said, the Conquer Online Login Server is proven to be 69.59.142.13.
Now, I am in noob village.
Another netstat -b?
Conquer.exe has one established connection, TCP, and is to customer-reverse-entrty.69.59.185.108:5816. I am currently on Phoenix Server. I do believe 69.59.185.108 is the IP in question, and has just been proven to be the Phoenix Server.
Good day.