Sign in to follow this  
Followers 0
horus22

port 3724

4 posts in this topic

I don't have port 3724 set in ApexDC's settings, but everytime I use ApexDC++, Outpost firewall shows lots of simultaneous connections(over 100, from a single IP) for ApexDC++ on this port.

Yesterday, for example I blocked that specific IP address, but today, it's a new IP, blocked this one too. I'm 101% sure, that tomorrow it will be a new IP.

Any ideas?

Share this post


Link to post
Share on other sites

It seems that those IPs are related to some WoW servers, and my ApexDC++ client is used to flood them on port 3724.

Who could be able to control my DC client to do these things?

I thought that I was being attacked on port 3724, but it's the other way, my client is used to attack some addresses on port 3724.

Share this post


Link to post
Share on other sites

Probably you are on a hub that is vulnerable to the CTM exploit in the NMDC protocol. There is plenty of information about this on the web.

Share this post


Link to post
Share on other sites

what should I do?

How can I identify the hub?

Sometimes ApexDC++ is making ~3000 TCP connections on a single IP, and a single port.

The IP and the port varies from time to time.

Right now, it's doing this again, and I can't even control apex, it doesn't respond....

Share this post


Link to post
Share on other sites
Sign in to follow this  
Followers 0