Monday, April 23, 2007

nflplayers.com surfing the web

This web server is visiting our web sites:

66.208.26.98 resolves to"nflplayers.com"
Top Level Domain: "nflplayers.com"

iibee.com browsing web sites

This IP address points to iibee.com and seems to be a computer used to surf the web. Is this a web server or someone trying to host a site from their basement? Why is it surfing the web?

216.194.68.120 resolves to"iibee.com"Top Level Domain: "iibee.com"

ap-art.com surging the web

Here's a web server that is being used to surf our web sites:

207.234.208.96 resolves to"ap-art.com"Top Level Domain: "ap-art.com"

liggins.plus.com - surfing the web?

Hmm, should this IP address be surging the web? Seems to have an interest in our web sites.

212.159.42.175 resolves to"liggins.plus.com"
Top Level Domain: "plus.com"

turbinegenerator.com surfing the web

This ip resolves to turbinegenerator.com - seems a web server is surfing the web.

209.34.233.62 resolves to"turbinegenerator.com"
Top Level Domain: "turbinegenerator.com"

proxyout.utah.gov

Why is this proxy server for the utah government surfing our web sites? Is this a typical configuration? It could be I'm not sure.

204.113.19.8 resolves to"proxyout.utah.gov"Top Level Domain: "utah.gov"

proxy2.xter.net

Proxy server surfing our web sites?

83.217.229.147 resolves to"proxy2.xter.net"
Top Level Domain: "xter.net"

knsk.de

Here's a web server surfing our web sites...

212.1.49.129 resolves to"knsk.de"
Top Level Domain: "knsk.de"

F5 wants to secure your apps with their network hardware

Here's an interesting approach to application security from F5 Networks using their Big IP device (which was insanely expensive last time I checked):

http://www.f5.com/solutions/technology/securing_enterprise_wp.html?CMP=KNC-GoogSiteNtwk&gclid=CLuEguDO2IsCFQQRYwodll4haw

The only issue I see here is more complicated application testing and debugging. It will be harder to pinpoint errors.

I haven't thought it totally through and it's late but seems like this is a network device and should focus on network issues.

The concept of what they are doing should be done by every application however and perhaps and application framework is best suited for these things. Perhaps you could use a combination but I worry about the maintenance consequences of this.

A web server surfing the web

63.144.222.2 resolves to"www.hardeecounty.net"
Top Level Domain: "hardeecounty.net"

Sunday, April 22, 2007

Inquent = hacked?

Working away here suddenly my printer started making noise for no apparent reason. I'm guessing someone got on my network or my machine here and they are snooping around and hit the device on that port / local IP.

I looked at IPs my machine is connected to and for no apparent reason it is connected to this IP:

205.178.145.1

InQuent Technologies Inc. INQUENT-2 (NET-205-178-128-0-1) 205.178.128.0 - 205.178.191.255Network Solutions, LLC NSLLC01 (NET-205-178-145-0-1) 205.178.145.0 - 205.178.145.255

Hmmm....hacked or?

Thursday, April 19, 2007

Microsoft DNS + RPC vulnerability

And if you didn't believe me that DNS can be hacked and send you to the wrong place (as suggested in the last post about an ebay web site issue) read this:

http://securitywatch.eweek.com/exploits_and_attacks/microsoft_urges_workaround_as_worm_hits_unpatched_dns_flaw.html?kc=EWEWEMNL041807EP38A

A flaw in or explotation of the implementation of the Microsoft DNS service plus RPC (remote procedure call) service is being abused.

JavaScript hacks

Here's an interesting article on JavaScript hacks. This would apply to people going to web sites that have the attacks in the code when you download the page and the inability of various virus, malware and spybot type software figuring out that the code is actually malicious.

http://www.eweek.com/article2/0,1895,2115638,00.asp?kc=EWEWEMNL041907EP38A

Ebay site problem

Ebay has a page where you can enter a whole bunch of information if you forget your password.

There is a whole host of sensitive information you have to enter on that page to get your password.

The page is only accessible via http.

Oh but they probably submit it via https you say.

So what. Let's say their DNS gets hacked someone and people set up a fake page at that address on the servers that are being rerouted to when you think you're at ebay. The only way to know you are really at ebay is hitting the page via https because the certificate applies to a specific server. Without that you can be rerouted and when you hit submit on this bogus link you just gave a hacker your secret question/answer (which you probably used in multiple places, right?), your birth date, place of birth, etc. etc.

Scary.

Wednesday, April 18, 2007

Encoding vs. Encryption

I was working on a site that encodes cookies today and I was wondering why they did that. I was thinking that "hey, encoding is not the same as encrypting...are they doing this for security reasons?" Then I started thinking about it a little more - the distinction between encrypting and encoding. I did a quick search which provided a nice document that I am giving kudos to for backing up my thoughts on the technically correct purposes of encode and encrypt.

http://www.di-mgt.com.au/encode_encrypt.html

Friday, April 13, 2007

195.10.45.155

Here's an interesting dns resolution. Hide? Hmm.

195.10.45.155 resolves to"hide-155.nhs.uk"
Top Level Domain: "nhs.uk"

Tuesday, April 10, 2007

A surfing hosting proxy server

This IP was surfing our web sites. Looks like something good to block.

203.97.46.29 resolves to"proxy.hosting.co.nz"
Top Level Domain: "co.nz"

Websherpas.com hacked?

Hmm, websherpas.com needs to consult a higher power to prevent their server from surfing the web. This server was sniffing around our web sites:

209.102.67.2 resolves to"www.websherpas.com"
Top Level Domain: "websherpas.com"

Romania, China, Russia...

Hmm, suddenly I am getting loads of hits from Romania, China and Russia. This after a recent article I posted suggested the US as the malware capital of the world and my suggestion that the actual source of this hacking is elsewhere. I also suggested segmenting your servers for different parts of the world and known hacker countries so that hacker sources are limited to hacking their own boxes and not the rest of the boxes used by countries in the world that are not such a high percentage of Internet theives, crooks, criminals and spies (though we all have some black sheep in our family).

212.20.253.212 resolves to"euro-hostels.co.uk"

This is another web server surfing our web site. Probably hackers or hacked.

212.20.253.212 resolves to"euro-hostels.co.uk"
Top Level Domain: "co.uk"

wmanet.org surfing our web site

Hmm. Another web server surfing our web site.

216.195.194.210 resolves to"wmanet.org"
Top Level Domain: "wmanet.org"

Saturday, April 07, 2007

209.51.147.66 - Monitoring will not stop

This Ip continues to monitor our site and will not stop. Hopefully Global Net Access will look into the activities coming from this IP Address.

IPs used by same hacker(s)

Just a hunch but these IPs are probably all used by the same hacker and/or hacked servers:

221.147.153.67
203.162.3.15674.52.245.146
220.123.254.200

Friday, April 06, 2007

209.51.147.66 - HACKER

This IP either belongs to a hacker or is being used by a hacker. They bombed our site today.

Check your logs for this one...especially those in the travel industry.

Korean Hackers Are Stepping Up

In the past few days we got a number of hacker scans from Korea. We block a lot of bad ranges but suddenly they are picking up again.

Here are a few of the IP ranges:

inetnum: 125.176.0.0 - 125.191.255.255netname: XPEEDcountry: KR

inetnum: 211.104.0.0 - 211.119.255.255netname: KRNIC-KRdescr: KRNICdescr: Korea Network Information Centercountry: KR

inetnum: 211.104.0.0 - 211.119.255.255netname: KRNIC-KRdescr: KRNICdescr: Korea Network Information Centercountry: KR

inetnum: 220.88.0.0 - 220.95.255.255netname: KORNETdescr: KOREA TELECOMdescr: Network Management Centercountry: KR

inetnum: 211.104.0.0 - 211.119.255.255netname: KRNIC-KRdescr: KRNICdescr: Korea Network Information Centercountry: KR

inetnum: 211.104.0.0 - 211.119.255.255netname: KRNIC-KRdescr: KRNICdescr: Korea Network Information Centercountry: KR

inetnum: 218.144.0.0 - 218.159.255.255netname: KORNETdescr: KOREA TELECOM

inetnum: 218.234.0.0 - 218.239.255.255netname: HANANETdescr: Hanaro Telecom Co.descr: Kukje Electornics Cneter Bldg. 1445-3 Seocho-Dong Seocho-Kucountry: KR

inetnum: 222.96.0.0 - 222.122.255.255netname: KORNETdescr: KOREA TELECOMdescr: Network Management Centercountry: KR

inetnum: 58.224.0.0 - 58.239.255.255netname: HANANETcountry: KR

A string of related PHP hacker IPs

Here are a string of hits in a row from IPs in different parts of the world requesting things that are not on our server. They are requesting a specific URL, not an IP address so this is not a DNS problem where someone pointed a domain to our IP by mistake. I believe our DNS servers are set up correctly as I just double checked everything but my hosting company has a propensity for screwing up DNS records so will have to check that again. However given what they are requesting I assume these are a bunch of related hacked IPs, probably controlled by a command and control bot somewhere.

"inetnum: 220.0.0.0 - 220.63.255.255
netname: BBTECH
descr: Japan nation-wide Network of SOFTBANK BB CORP
descr: Tokyo, Japan
country: JP
" 269236 BLOCKED 7i1768n6s9ky Thu Apr 05 07:10:31 PDT 2007 220.125.98.46 /index.php Mozilla/5.0 (Windows; U; Windows NT 5.0; en-US; rv:1.3a) /index.php act=Reg&CODE=00 83 7 1 4/5/2007 7:10:31 AM 5 4 4/5/2007 7:10:31 AM
"inetnum: 218.144.0.0 - 218.159.255.255
netname: KORNET
descr: KOREA TELECOM
" 269235 BLOCKED 1n2q7vj1sj66u Thu Apr 05 07:10:28 PDT 2007 218.144.144.230 /index.php Mozilla/5.0 (Windows; U; Windows NT 5.0; en-US; rv:1.3a) /index.php act=Reg&CODE=00 83 7 1 4/5/2007 7:10:29 AM 5 4 4/5/2007 7:10:29 AM
269234 BLOCKED 17fot0jc7s1g6 Thu Apr 05 07:10:26 PDT 2007 218.239.91.102 /register.php Mozilla/5.0 (Windows; U; Windows NT 5.0; en-US; rv:1.3a) /register.php action=signup&who=adult 83 7 1 4/5/2007 7:10:27 AM 5 4 4/5/2007 7:10:27 AM
269233 BLOCKED 884p8rgc0r4b Thu Apr 05 07:10:24 PDT 2007 222.99.104.139 /register.php Mozilla/5.0 (Windows; U; Windows NT 5.0; en-US; rv:1.3a) /register.php action=signup&who=adult 83 7 1 4/5/2007 7:10:25 AM 5 4 4/5/2007 7:10:25 AM
269232 BLOCKED g6t4qf5acgdc9 Thu Apr 05 07:10:22 PDT 2007 58.226.121.105 /profile.php Mozilla/5.0 (Windows; U; Windows NT 5.0; en-US; rv:1.3a) /profile.php mode=register 83 7 1 4/5/2007 7:10:23 AM 5 4 4/5/2007 7:10:23 AM
"inetnum: 59.88.0.0 - 59.99.255.255
netname: BSNLNET
descr: NIB (National Internet Backbone)
descr: Bharat Sanchar Nigam Limited
descr: Sanchar Bhawan,20, Ashoka Road, New Delhi-110001
country: IN
" 269231 BLOCKED 1q0g62wvk2a4 Thu Apr 05 07:10:18 PDT 2007 59.93.209.25 /profile.php Mozilla/5.0 (Windows; U; Windows NT 5.0; en-US; rv:1.3a) /profile.php mode=register 83 7 1 4/5/2007 7:10:18 AM 5 4 4/5/2007 7:10:18 AM
"inetnum: 59.88.0.0 - 59.99.255.255
netname: BSNLNET
descr: NIB (National Internet Backbone)
descr: Bharat Sanchar Nigam Limited
descr: Sanchar Bhawan,20, Ashoka Road, New Delhi-110001
country: IN
" 269231 BLOCKED 1q0g62wvk2a4 Thu Apr 05 07:10:18 PDT 2007 59.93.209.25 /profile.php Mozilla/5.0 (Windows; U; Windows NT 5.0; en-US; rv:1.3a) /profile.php mode=register 83 7 1 4/5/2007 7:10:18 AM 5 4 4/5/2007 7:10:18 AM

Another php attack - XMLRPC.PHP etc.

If you are running php and using any of the files below beware - there is probably some sort of hack in them. This attack comes from 61.62.83.165

Surprise, surprise - Taiwan.

inetnum: 61.62.0.0 - 61.62.255.255netname: SONET-NETcountry: TW

Taiwan is a big hacker source. If you're not doing business there you may want to consider blocking out IPs from this country. If you're not getting any money from Taiwan the only thing you will get is a bunch of problems.

269083 BLOCKED 5dmervkrad0bs Thu Apr 05 00:29:54 PDT 2007 61.62.83.165 /phpgroupware/xmlrpc.php /phpgroupware/xmlrpc.php 83 7 1 4/5/2007 12:29:54 AM 5 4 4/5/2007 12:29:54 AM
269082 BLOCKED 1gpe1xqetqxi1 Thu Apr 05 00:29:54 PDT 2007 61.62.83.165 /phpgroupware/xmlrpc.php /phpgroupware/xmlrpc.php 83 7 1 4/5/2007 12:29:54 AM 5 4 4/5/2007 12:29:54 AM
269081 BLOCKED 4famei5pnqlkj Thu Apr 05 00:29:53 PDT 2007 61.62.83.165 /wordpress/xmlrpc.php /wordpress/xmlrpc.php 83 7 1 4/5/2007 12:29:54 AM 5 4 4/5/2007 12:29:54 AM
269080 BLOCKED 48978s37c7mpo Thu Apr 05 00:29:53 PDT 2007 61.62.83.165 /wordpress/xmlrpc.php /wordpress/xmlrpc.php 83 7 1 4/5/2007 12:29:54 AM 5 4 4/5/2007 12:29:54 AM
269079 BLOCKED 9ur4s0tv5oqc Thu Apr 05 00:29:53 PDT 2007 61.62.83.165 /b2evo/xmlsrv/xmlrpc.php /b2evo/xmlsrv/xmlrpc.php 83 7 1 4/5/2007 12:29:53 AM 5 4 4/5/2007 12:29:53 AM
269078 BLOCKED 2rkqne24ojvle Thu Apr 05 00:29:53 PDT 2007 61.62.83.165 /b2evo/xmlsrv/xmlrpc.php /b2evo/xmlsrv/xmlrpc.php 83 7 1 4/5/2007 12:29:53 AM 5 4 4/5/2007 12:29:53 AM
269077 BLOCKED vt6xth4n6s0r Thu Apr 05 00:29:52 PDT 2007 61.62.83.165 /b2/xmlsrv/xmlrpc.php /b2/xmlsrv/xmlrpc.php 83 7 1 4/5/2007 12:29:53 AM 5 4 4/5/2007 12:29:53 AM
269076 BLOCKED qiox5oyth034 Thu Apr 05 00:29:52 PDT 2007 61.62.83.165 /b2/xmlsrv/xmlrpc.php /b2/xmlsrv/xmlrpc.php 83 7 1 4/5/2007 12:29:53 AM 5 4 4/5/2007 12:29:53 AM
269075 BLOCKED e7ecb4966qpr7 Thu Apr 05 00:29:52 PDT 2007 61.62.83.165 /blogtest/xmlsrv/xmlrpc.php /blogtest/xmlsrv/xmlrpc.php 83 7 1 4/5/2007 12:29:52 AM 5 4 4/5/2007 12:29:52 AM
269074 BLOCKED 12ncmocu7lv5a Thu Apr 05 00:29:52 PDT 2007 61.62.83.165 /blogtest/xmlsrv/xmlrpc.php

Wednesday, April 04, 2007

Charter bot is back

Will it ever give up or will Charter ever do something about this bot...

Charter - bot/1.0 (bot; http://; bot@bot.bot) 267331 BLOCKED 2t10omfv05mc Wed Apr 04 07:58:34 PDT 2007 71.13.115.117 bot/1.0 (bot; http://www.bot.bot; bot@bot.bot) 83 7 1 4/4/2007 7:58:35 AM 4 4 4/4/2007 7:58:35 AM

IPs that need to be updated

Here are some interesting results looking up the information about this IP range:

inetnum: 156.54.0.0 - 156.54.255.255

remarks: This inetnum has been transfered as part of the ERX. It was present in both the ARIN and RIPE databases, so the information from both databases has been merged. If you are the mntner of this object, please update it to reflect the correct information.

Tuesday, April 03, 2007

Comcast needs to fix this domain name

This domain name information is not correct ... MN needs to be changed:

24.18.46.154 resolves to"c-24-18-46-154.hsd1.mn.comcast.net"
Top Level Domain: "comcast.net"

An exchange sever perhaps?

If this is an Exchange server what is it doing surfing our web sites?

Perhaps this stands for something else however:

64.65.150.210 resolves to"exch.seattlearch.org"
Top Level Domain: "seattlearch.org"

Bank Server surfing?

Here's a bank server in Sweden surfing the web....is this right? That's a little scary...but perhaps since I don't speak the language this is referring to a modem bank..so I'll let it slide for now =)

195.242.56.2 resolves to"clients.kaupthing.se"
Top Level Domain: "kaupthing.se

Funny looking domain resolution for a web surfer...

This one looks a little funny ...is this really the IP of an end user surfing or a server?

128.250.172.175 resolves to"guyd.psych.unimelb.edu.au"
Top Level Domain: "edu.au"

Another surfing web server? william.aeoncyberclub.com

Here's an IP with an interesting resolution:

202.7.145.118 resolves to"william.aeoncyberclub.com"
Top Level Domain: "aeoncyberclub.com"

Is this really a machine surfing the web or a human?

www.adressendeutschland.de web server surfing our web sites

This server appears to be surfing the web and appears to be a web server, though by the looks of the "site" it may be an amateur at home hosting his or her own site.

88.198.38.230 resolves to"www.adressendeutschland.de"
Top Level Domain: "adressendeutschland.de"

ozemail.com.au surfing the web

Is this really an email domain or a dsl domain? It says ozemail but then it has dsl in the URL as well. Hopefully someone in Australia can alert this email / dsl provider to find out if this server is hacked.

203.102.242.189 resolves to"189.fip-4.dsl.ozemail.com.au"
Top Level Domain: "com.au"

km6.favo.tv -- a computer user?

This Ip was hitting our site - not sure if this is part of a DSL network - a router or other networking equipment -or something totally not legitimate.

87.118.100.27 resolves to"km6.favo.tv"
Top Level Domain: "favo.tv"

A proxy server in the Phillipines

Here's a proxy server in the Philippines surfing around our web sites...

202.44.136.50 resolves to"proxy.thapra.su.ac.th"
Top Level Domain: "ac.th"

Speak Easy "scan alert" server surfing our sites?

A SpeakEasy IP with some scanalert.com application is surfing our web sites...

66.92.26.98 resolves to"scan0.scanalert.com"
Top Level Domain: "scanalert.com"

EntireWeb surfing our webs

Here's another web server IP address surfing our web sites. This is a search engine optimization company so chances are they are analyzing our sites to snipe content and/or copy our ranking techniques. I suggest you block this one out.

62.13.25.221 resolves to"www.entireweb.com"
Top Level Domain: "entireweb.com"

Monday, April 02, 2007

A web server surfing our web sites

Here's a web server surfing our web sites:

209.180.210.90 resolves to"sightlife.org"Top Level Domain: "sightlife.org"

Saturday, March 31, 2007

Favorstar.com

We keep getting hits from favorstar.com. I boldly and probably riskily went to this site and it's a Chinese site with some video and half naked women on it in bras, etc. Whatever this site is up to, it can't be any good. I also noticed they are advertising a t-shirt site in direct competition with one of ours. I can't imagine this site is up to anything good.

Wednesday, March 28, 2007

U.S. Malware Capital?

This article form Network World claims that San Jose found the most malware was hosted in the US "contrary to the belief that it was coming from other countries" not in so many words.

http://www.networkworld.com/news/2007/032607-more-evidence-of-us-as.html?nlhtsec=0326securityalert3&company=MessageGate

They almost downplay the issue that most of this malware is probably weaseled onto servers via hacking or on servers paid for by people of origin outside the U.S. Yes, there are probably a lot of US hackers - we did invent the computer after all.

It is important to keep all factors in mind while analyzing this topic. It has also been reported that many hacker and terrorist organizations buy computer networking from the US because it is more cost effective (or was) than in other countries. That may be changing with China and India in the game, I'm not sure.

Hacked servers are also a huge source of this malware and I would be interested to know the % of this 80% of malware that is on hacked servers and how much of the malware actually got onto the US computers via a hack from someone originating from another country. A person I spoke to from the FBI says about 15% of the world's computers are thought to be "command and control bots," meaning they are either set up intentionally or hacked to run code for someone who is using a command server to control a bunch of other machines to carry out their dirty work.

The author did mention the money changing hands here - and why the US is a target, but also consider that the UK is second on the list. The US, the UK. Hmmm.

Also to take into consideration would be the size of the US and the amount of computers in the US relative to other countries. I'm not sure but I'd guess there are a relatively larger number of computers here than in some other countries at this time.

But perhaps the author just meant that this is where most of the malware is running - that the U.S. is the target and our security is totally lacking, rather than highlighting the US as a source of creating and distributing malware. If you consider the malware is running on machines that can affect people all over the world it is a problem - but the cause of that problem still may be mainly coming from outside the US. Security lacking? A wake up call? With that I would have to agree.

Personally I find plenty of hacker looking traffic from all over the world. I haven't done the numbers to compare by country but there are a load of hackers in Ontario, Alaska, throughout Europe, and a ton coming out of Asia - especially China and Taiwan. There is some that comes out of Brazil and occasionally Mexico - I was bombed by France the other day (see a recent post).

The interesting thing is that probably one of the biggest hacks on credit cards at Card Service International (I believe that is correct) in Arizona a couple years ago was attributed to the Russian Mafia by the news in Australia when I was down there. People in the US said they didn't hear that - I am not sure what was reported in the US.

But I get very little hacker like traffic from Russia. Does that mean there are no hackers in Russia? No, it means they are pretty damn smart. They do their dirty work from hacked servers in other parts of the world so they are not discovered. A recent piece of malware running on tons of US servers included a built in virus checker - Kapersky - Russian by origin though they since tried to appear as they are headquartered in the US. I also think there may be some Russian hackers up in Alaska using some network - Hideout.net

So the point the author is making about most of the hacks not coming from Russia or China like everyone thinks - is twisting the facts.

RufusBot is a Dufus. 64.124.122.228

The so-called "rufus bot" is hitting us repeatedly again from this IP address: 64.124.122.228 and the stupid thing is, it is requesting pages that do not exist on our server over and over again and getting Page Not Found errors and still continues to request the pages.

Either the person that wrote the RufusBot is a dufus, or as I suggested before there is an error related to 404 errors that present a security or hacker problem. I am not sure why else these bots would try to hit pages that do not exist repeatedly. I guess they could be that stupid, but I kind of doubt it.

Saturday, March 24, 2007

Hackers - Ontario

I am still convinced there are hackers in Ontario - probably on Rogers Cable but also coming from Shaw and other networks. I think they move around.

After implementing a new filter we just got a bunch of hits in a row on pages without referrers from Toronto IPs.

Tuesday, March 20, 2007

Ask Jeeves Spoofer?

We've been getting a lot of hits supposedly from AskJeeves such as this:
57 hits this month
Ask Jeeves User Agent
65.214.44.166
Last Visit: 3/20/2007 4:20:54 PM

However this IP does not belong to any of the Ask Jeeves IP ranges as far as I can see:

Ask Jeeves ASKJEEVES-66-09 (NET-4-19-66-0-1) 4.19.66.0 - 4.19.66.255
Ask Jeeves HTW-06853 (NET-64-55-148-1-1) 64.55.148.1 - 64.55.149.254
ASK JEEVES Q0518-63-145-26-32 (NET-63-145-26-32-1) 63.145.26.32 - 63.145.26.63
ASK JEEVES TWTC-SNFO-C-ASKJEEVES-0 (NET-206-80-1-0-1) 206.80.1.0 - 206.80.1.255
ASK JEEVES Q0426-63-236-237-72 (NET-63-236-237-72-1) 63.236.237.72 - 63.236.237.79
ASK JEEVES Q0213-72-165-191-64 (NET-72-165-191-64-1) 72.165.191.64 - 72.165.191.95
ASK JEEVES ASK-JEEV33-211 (NET-12-193-211-0-1) 12.193.211.0 - 12.193.211.255
ASK JEEVES INC Q0321-65-119-214-0 (NET-65-119-214-0-1) 65.119.214.0 - 65.119.214.255
Ask Jeeves PBI-CUSTNET-6751 (NET-216-103-72-40-1) 216.103.72.40 - 216.103.72.47
Ask Jeeves SBCIS-101412-175559 (NET-64-174-153-192-1) 64.174.153.192 - 64.174.153.199
Ask Jeeves SBC067114171064020215 (NET-67-114-171-64-1) 67.114.171.64 - 67.114.171.71
ASK JEEVES MFN-B370-209-249-69-0-29 (NET-209-249-69-0-1) 209.249.69.0 - 209.249.69.7
ASK JEEVES MFN-B370-208-184-139-0-29 (NET-208-184-139-0-1) 208.184.139.0 - 208.184.139.7
ASK JEEVES MFN-B370-208-185-161-0-28 (NET-208-185-161-0-1) 208.185.161.0 - 208.185.161.15
ASK JEEVES MFN-B370-208-185-160-0-24 (NET-208-185-160-0-1) 208.185.160.0 - 208.185.160.255
ASK JEEVES MFN-B370-208-185-182-128-28 (NET-208-185-182-128-1) 208.185.182.128 - 208.185.182.143
ASK JEEVES MFN-B370-216-200-130-0-24 (NET-216-200-130-0-1) 216.200.130.0 - 216.200.130.255
ASK JEEVES MFN-B370-208-185-219-224-27 (NET-208-185-219-224-1) 208.185.219.224 - 208.185.219.255
ASK JEEVES MFN-B370-64-124-141-0-24 (NET-64-124-141-0-1) 64.124.141.0 - 64.124.141.255
ASK JEEVES MFN-B370-209-249-88-48-28 (NET-209-249-88-48-1) 209.249.88.48 - 209.249.88.63
ASK JEEVES MFN-B370-64-124-56-0-24 (NET-64-124-56-0-1) 64.124.56.0 - 64.124.56.255
ASK JEEVES BRW-11672-ASK (NET-216-143-191-128-1) 216.143.191.128 - 216.143.191.191
Ask Jeeves MFN-B370-209-66-103-0-24 (NET-209-66-103-0-1) 209.66.103.0 - 209.66.103.255

Tuesday, March 13, 2007

Stock Price Manipulation

A while back I posed the idea of manipulating stocks somehow using Internet technologies to affect prices and make a profit. Some people scoffed at me and told me how difficult this would be based on how many people would need to be involved to make this happen.

Here's proof that it can be done and something to watch out for:
Internet stock scam

Recently Real Networks has claimed that their stock price was manipulated possibly by hackers or Internet scam artists in China.

So call it a silly idea but there's a reason you've seen all that stock spam in your inbox.

I haven't done the math to see what it would take to get enough people to buy in to affect the price of a stock. I'm sure it depends on the stock and a lot of other factors. Just pondering the possibility.

Tuesday, March 06, 2007

Ebay vs. Romanian Hacker

Ebay has been plagued by a Romanian hacker lately per this article:
http://www.eweek.com/article2/0,1895,2100808,00.asp?kc=EWSTEEMNL030607EOAD

Of interest are the various tactics ebay is using to thwart this criminal which go beyond simple tactics to more complete analysis of hacker activity ...a trend in the industry which has long been needed over an above simple firewall rules and was the reason I started writing this hacker / Internet security / Internet service blog.

More analysis of specific hacker activity by humans, not machines, will help determine traffic and activity patterns to block out attacks better than any firewall rules. It is a constant, on-going effort at mutliple layers from network to firewall to OS to application - it is not a simple one time fix.

Sunday, March 04, 2007

Hacker in Japan

Japan scanning IP addresses for security flaws:

203943 BLOCKED a2ge8iqi9mcec Sun Mar 04 09:24:51 PST 2007 203.143.125.226 //ads/adxmlrpc.php Mozilla/4.0 (compatible; MSIE 6.0; Windows 98) /ads/adxmlrpc.php 3/4/2007 9:24:51 AM 3/4/2007 9:24:51 AM
203942 BLOCKED 1trlwusqdgvg5 Sun Mar 04 09:24:51 PST 2007 203.143.125.226 //Ads/adxmlrpc.php Mozilla/4.0 (compatible; MSIE 6.0; Windows 98) /Ads/adxmlrpc.php 3/4/2007 9:24:51 AM 3/4/2007 9:24:51 AM
203941 BLOCKED 4tnft3pc3kubt Sun Mar 04 09:24:50 PST 2007 203.143.125.226 //phpads/adxmlrpc.php Mozilla/4.0 (compatible; MSIE 6.0; Windows 98) /phpads/adxmlrpc.php 3/4/2007 9:24:51 AM 3/4/2007 9:24:51 AM

..repeat about 50 times

A bunch of IPs requesting stuff we don't host

The following are related hacker IPs probably controlled by a command and control bot:

74.118.71.252
124.50.43.214
60.217.227.135
210.191.147.120
203.165.129.2
210.6.97.244

They all hit our site at the same time requesting things our server does not host.

Here's another set shortly before doing something similar, probably also related to the above:

195.49.188.202
71.63.100.55
210.245.147.241
218.233.57.23272.145.6.47
218.48.127.177

71.63.100.55
210.245.147.241
218.233.57.232

Perhaps someone pointed a domain to the wrong IP since they were all hitting the same domain.

These IPs are all requesting php files -- the favorite language of the hacked and hackers as far as I can tell by the percentage of hacks in the logs on various types of web programming and scripting languages.

Wednesday, February 28, 2007

253-719-0012

AHA...

I figured out what this number is. I got an electronically placed and recorded call from Comcast.

When you put this number in Google however you get a ton of nasty hacker information.

Interesting.

Tuesday, February 20, 2007

Defender Technologies, DefenderHost.com - Hacker Source

Hackers have also been pinging our sites from this IP range:

OrgName: Defender Technologies Group, LLC
OrgID: DTGL
Address: 44470 Chilum Place, Building 1
Address: Suite 1197
City: Ashburn
StateProv: VA
PostalCode: 20147
Country: US
NetRange: 69.65.96.0 - 69.65.127.255

Inhoster - bad bot source

This is the latest blatant abusing network:

inetnum: 85.255.112.0 - 85.255.127.255
netname: inhoster
descr: Inhoster hosting company
descr: OOO Inhoster, Poltavskij Shliax 24, Kharkiv, 61000, Ukraine
country: UA

Saturday, February 17, 2007

Related Hacker IPs

Here's a group of related hacker IPs that hit our web sites all at once. All the IPs hit the same web site and it is an odd site for site for these IPs to be hitting:

Time of hack attempt: 2/17/07 21:42:33
65.184.191.13
211.213.118.32
75.34.23.14
212.119.45.138
71.83.46.82
12.206.187.108
59.95.212.177

In addition this IP was in the middle of this looking at another site:
89.150.197.192

Friday, February 16, 2007

Message Guard - Network Solutions

Been writing about trying out Identity Based Encryption - specificall the Message Guard service from Network Solutions provided by Voltage Security.

This is the typical message I get from other people when I try to use Network Solutions Message Guard to send them emails:
_______________

I do not have time to go do all of these steps to read the email. It takes over 5 minutes to complete this. I am the only one here in my department and this is very time consuming. Can you please just send me a regular email.
_______________

Until this is fixed, this is not a viable solution for every day use between two parties that are not both using the same service. I thought the idea was that the person only has to go through the steps one time...

I also asked Voltage Security how they guarantee that someone at their location is not able to decrypt and read the email - what policies and auditing do they have in place - and as of yet no response.

Monday, February 12, 2007

Catepillar, Inc. really Interested in Australia?

It could be legit but this past month alone we've had a huge number of hits from Catepillar, Inc. to a site for an Australian hotel booking system...maybe someone wants to take a trip, or perhaps their server is being used for monitoring unbenknownst to them?

12.2.142.7

Arrival Communications - Hacker

There appears to be a hacker at arrival communications on this IP 69.84.207.35 targeting one of our real estate web sites.
They hit our contact request form about 70 times in one day.
Shortly thereafter the publishing of the site was altered, but we were able to easily republish.

OrgName: Arrival Communication, Inc
OrgID: ARRV
Address: 5100 California Ave Suite 104
City: Bakersfield
StateProv: CA
PostalCode: 93309
Country: US

NetRange: 69.84.192.0 - 69.84.207.255

Identity Based Encryption - Update

As noted in previous posts I'm trying out Identity Based Encryption and having lots of problems with it. A lawyer on comcast can't use it, a customer couldn't access it, people I work with in Australia aren't replying so I am not sure what that meants, someone on AOL couldn't read it. It's a toss up who will be able to read it and who won't. Someone on Yahoo gets it just fine as does someone on SpeakEasy. One mail provider - ElectricMail.com - refuses to let their support staff use it.

The latest is that I just had to re-authenticate to send a message and I'm not sure why. Is this an on-going thing where you have to re-authenticate on a weekly basis?

The other thing to note is that I bought the service from Network Solutions and it is authenticating on the Voltage Security system.

Wednesday, February 07, 2007

Reverse Load Testing

In this article which talks about an attack on the root servers that support the Internet:
http://www.networkworld.com/news/2007/020707-hackers-slow-internet-root-servers.html?nlhtsec=0205securityalert3&company=

The engineers are "scratching their heads" wondering why the attack was performed.

I can think of a few reasons.

1. Reverse load testing. Hackers are trying to calculate what it will take to bring down the Internet. Bringing down the Internet could cause a myriad of disruptions that might be beneficial to a myriad of sneaky, slimy people.

2. Bringing down the Internet at a particular time when a certain crime is being committed may prevent certain communications which may then alert the authorities or warning systems to the crime underway.

3. Someone wants attention.

4. Some really flawed programming.

5. Mischief.

Tuesday, February 06, 2007

Identity Based Encryption (IBE) - Trial

So far IBE has been mildly usable. Most people were able to get it and login and read the message without any problem.

As supsected a few people were skeptical of the email and didn't want to open it until I called them since it doesn't look like your typical email.

I also had a few people have problems with it including:

#1 my boss couldn't open it on his cell phone - didn't work at all. Also he didn't want to "sign up for an account" even though I explained that's not what it is.

#2 Someone on AOL couldn't open it at all.

#3 One of my customers using Electric Mail and also I think another provider could not open the message. She tried a few different times today...going to have to call tomorrow and see if we can figure this out.

#4 Couldn't respond to tickets to my data center which is a pretty big hosting company. They have an automated system and the message came as an attachment which was then not included in their automated messaging system.

#5 I was told after asking if I could use it on a web server to send messages that it only works in Outlook - after I told them I was using Outlook already so obviously I know that. So you can't sign up for this and then send secure messages in an automated fashion to potential clients, for instance, or email receipts from an e-commerce web site or links to file downloads, etc.

A few things to resolve here...it's not quite as simple as normal email and obviously doesn't work for all scenarios.

Monday, February 05, 2007

PHP: Most Requested URLs by Hackers

Per our records, PHP is far and away the most attacked language - and we don't even host it.

These are the URLS various hackers have been scanning our boxes for in the past few months:

/phpAdsNew/adxmlrpc.php
/index.php
/profile.php
/cmd.php
/Ads/adxmlrpc.php
/register.php
/thisdoesnotexistahaha.php
/stats/cmd.php
/portal/cmd.php
/adserver/adxmlrpc.php
/adxmlrpc.php
/a1b2c3d4e5f6g7h8i9/nonexistentfile.php
/phpads/adxmlrpc.php
/web/e-commerce/database/index.php/administration/module/module/index.php
/portal/cacti/cmd.php
/xmlrpc.php
/xmlrpc/xmlrpc.php
/xmlsrv/xmlrpc.php
/blog/xmlrpc.php
/cacti/cmd.php
/drupal/xmlrpc.php
/web/phpMyAdmin/main.php
/web/phpMyAdmin/main.phpmain.php
/w3c/p3p.xml
/_vti_bin/_vti_aut/author.dll
/admin/login/index.php
/admin/pages/index.php
/admin/pages/settings.php
/admin/start/index.php
/public.php
/web/.../work/index.php
/web//work/index.php

And here are the IPs that have been up to this mischeif along with number of hits:


39 213.186.50.160
25 62.39.119.241
24 208.72.168.27
16 64.208.172.181
12 216.218.196.210
7 206.169.110.66
4 203.121.69.154
3 212.145.93.63
3 81.196.150.45
2 89.110.131.89
2 74.6.74.225
2 72.10.45.38
2 212.8.197.79
2 212.138.64.171
2 125.248.244.131
1 195.175.37.6
1 195.175.37.71
1 200.88.125.9
1 200.88.223.98
1 212.138.64.172
1 212.138.64.175
1 212.138.64.179
1 125.244.164.69
1 62.150.130.26
1 216.129.105.149
1 72.3.139.176
1 72.30.252.98
1 74.6.71.59
1 74.6.72.189
1 74.6.72.225
1 80.95.160.188
1 64.28.23.49
1 82.114.68.194
1 85.214.45.212
1 86.145.147.223

Friday, February 02, 2007

Identity Based Encryption - mail forwarding

This is interesting - I set up an IBE on an email account to test out Identity Based Encryption.

I have one account set up to forward to the other.

I sent from account A to account B.

Then account B forwarded the IBE message to create a key back to account A.

I was able to create the private key on my computer by creating a login - using a different email address than the one the email was sent to. (I was in account A - the one that sent the message).

When I went back to the email in my webmail based email account B I had the key on my machine and was able to read it even though the email address I entered when I created the key for was not the email address the mail was sent to...

Also about 5 minutes later I was forwarded the test message from account B back to account A and was able to read it without doing anything else.

Seems a bit odd. Not sure the implications of this on secure email. I will have to think this one through a bit more.

Tuesday, January 30, 2007

Identity Based Encryption

In a recent post I posted some questions about IBE or Identity Based Encryption for email which some vendors are selling at the moment and suggesting that now their email is encrypted and secure from end to end. On Network Solutions web site they even talk about sending credit cards in email not being secure, thereby implying with IBE that would be secure.

I recently asked Voltage Security about their IBE product to explain some of the problems they would have to overcome to create the encrypted email solution they propose on their web site. Most of their answers sound pretty good, except I still have questions about #5 noted below.

They also sent me a sample message so I could see how their product works. I received a secure message with a graphic button that was blocked by our mail scanning/security products and an attached html file. When I click the button to retrieve the message I have to create a user name and password to read the message and get the private key to read the message. I can see this working for internal organizations but when sending information to potential customers - I can imagine some of them not understanding what this is or being apprehensive about filling something like this out or clicking on an html attachment from a vendor they never heard of or have not worked with before - at least until and unless people get used to this concept. This may be a good solution for internal organizations however, if you trust the vendor of this technology of course and have had your own technical gurus look into the actual details. I am not an encryption expert. I am only looking at the process of getting the mail encrypted from A to B. I cannot say whether the encryption is not decryptable by the company selling it to you, for instance. But here's the scoop on the process:

Once the recipient of an IBE email receives a key they no longer have to get the key for future messages. What happens if they use a different computer?

When a person moves to a different machine, the key is then fetched again from the key server for future and past messages. There is no limit on how many keys one user can fetch as long as they properly authenticate each and every time.

What happens if they log on to web mail on a public computer in an Internet cafe? Is their private key downloaded there for future users of that machine to potentially exploit?

In a public web mail instance, they would be using ZDM, that only caches a stateless cookie that can be set to expire to meet your internal security policies. Also, once an end-user “logs out”, the session cookie is terminated, mitigating any security threat by reading secure email on a public machine. By default, there is a configurable 1 hour session timeout in case the user forgets to logout. Our ZDM cookie security has been fully vetted/tested and is currently in use by several large banks, health organizations and retail companies.

What if someone can steal the private key from the recipient’s machine - since authentication only happens on the first email they could basically read any email after that point if they have the key?

One key is only good for less than 1 week. They would only be able to read secure messages for that one user that fall within that one week session (it’ll most likely be less than half a week). We can utilize any authentication method – email answerback, or one email to prove who you are, is a highly usable, widely used industry standard (see Amazon, Yahoo, Microsoft, banks, etc) but not the most robust authentication standard. We support two-factor authentication, Windows Domain authentication, and different groups of users can be forced to authenticate by different means. The encryption method is tied down to one authentication method, giving you the flexibility to meet your security needs for secure communications.

How does IBE work with email addresses and accounts sending mail from a web server to another address, such as an order receipt?

If you are talking about automated emails, the messages must simply flow through our Voltage SecureMail Gateway, and it will encrypt using the designated recipients individual email address. Nothing special has to happen to encrypt this type of mail flow.

IBE encrypts mail from me to the person I am sending the mail to – what happens when they reply? Is that message sent unencrypted back to me? So if I have my mail encrypted so support people at my mail provider cannot read my outgoing mail, then the customer replies back to me – and my mail is unencrypted coming back from them – so it doesn’t really help? Or…is the mail back encrypted as well even if that person isn’t using IBE?

If they reply to a secure message using our integrated desktop client or ZDM, then you can force the reply or forwarded message to be secure (called “Secure Conversation”). If they don’t ever decrypt the message and simply reply to you, then your message is sent back still in its encrypted form.

My follow up questions to the answer above:

If they do decrypt the message and reply – then is it sent back unencrypted if they are not using IBE themselves or one of your products?

Scenario:
A person comes to our web site and requests product info. We send a secure encrypted message. They are not using any of your products or IBE. They open and read the mail, hit reply and send us back a question. They have outlook or their webmail system set to include the original message in the reply.

Is all our initial information now unencrypted in his reply as it travels back to us? Or once they go through the steps to decrypt the mail are they now using ZDM?

Also what if that ZDM cookie expires? Then when they reply to the message is it sent back unencrypted? Or do they have to log back in each time they read the message to get the cookie?

Hurricane Electric

Hackers live at Hurricane Electric.

I have been writing about hackers at Hurricane Electric since the beginning of this blog and their potential connection with a group of hackers in Alaska. More proof:

Sat Jan 27 21:52:17 PST 2007
216.218.196.210
/thisdoesnotexistahaha.php
Mozilla/4.0 (compatible; MSIE 6.0; Windows 98)
Sat Jan 27 21:52:17 PST 2007
216.218.196.210
/cmd.php
Mozilla/4.0 (compatible; MSIE 6.0; Windows 98)
Sat Jan 27 21:52:17 PST 2007
216.218.196.210
/portal/cmd.php
Mozilla/4.0 (compatible; MSIE 6.0; Windows 98)
Sat Jan 27 21:52:17 PST 2007
216.218.196.210
/portal/cmd.php
Mozilla/4.0 (compatible; MSIE 6.0; Windows 98)
Sat Jan 27 21:52:17 PST 2007
216.218.196.210
/stats/cmd.php
Mozilla/4.0 (compatible; MSIE 6.0; Windows 98)
Sat Jan 27 21:52:17 PST 2007
216.218.196.210
/thisdoesnotexistahaha.php
Mozilla/4.0 (compatible; MSIE 6.0; Windows 98)
Sat Jan 27 21:52:17 PST 2007
216.218.196.210
/thisdoesnotexistahaha.php
Mozilla/4.0 (compatible; MSIE 6.0; Windows 98)
Sat Jan 27 21:52:17 PST 2007
216.218.196.210
/portal/cmd.php
Mozilla/4.0 (compatible; MSIE 6.0; Windows 98)
Sat Jan 27 21:52:17 PST 2007
216.218.196.210
/stats/cmd.php
Mozilla/4.0 (compatible; MSIE 6.0; Windows 98)
Sat Jan 27 21:52:17 PST 2007
216.218.196.210
/stats/cmd.php
Mozilla/4.0 (compatible; MSIE 6.0; Windows 98)
Sat Jan 27 21:52:17 PST 2007
216.218.196.210
/cmd.php
Mozilla/4.0 (compatible; MSIE 6.0; Windows 98)
Sat Jan 27 21:52:17 PST 2007
216.218.196.210
/cmd.php
Mozilla/4.0 (compatible; MSIE 6.0; Windows 98)

Friday, January 26, 2007

Identity-Based Encryption

An interesting new approach to encrypting emails and make sure only the intended recipient can decrypt the email: Identity-Based Encryption.

This works by authenticating the email recipient based on their email address the first time they recieve an email. They are given a key and after that they can read all emails based on that key.

My questions in this case are (still resarching):

- What if someone steals their private key? Can they read all the email?

- What if the person moves to another machine that does not have the private key - will they be unable to read their mail?

- What if someone logs in at an Internet cafe to read webmail - is the email they download encrypted and will they get a new private key? In this case will the private key potentially be stored on the Internet cafe computer for abuse by future users of that machine?

It sounds really good...but will have to try it out to see if it actually works in all reality. I'll let you know... probably some encryption and verification is better than none but not sure how foolproof this is.

Another interesting idea would be to verify that the person downloading the mail to read it is contacting a server defined in the SPF records for that domain, otherwise the server storing the mail for download is not legit. Haven't thought through how this could be implemented nor do I know if this is already part of SPF, to be honest.

Identity Based Encryption

Addendum:
I did some additional research and got answers to these and other questions in this Identity Based Encryption Post: http://randominternet.blogspot.com/2007/01/identity-based-encryption_30.html

Thursday, January 25, 2007

Storing Credit Cards

Tell me one more time why anyone would opt to store credit cards and take on the associated liability?

http://www.eweek.com/article2/0,1895,2085390,00.asp

There are services that have been in business for years that specialize in keeping this data safe and allow transactions on stored credit card information through PCI compliant mechanisms.

Monday, January 22, 2007

Cybercrime More Profitable than Drugs

I suggested in a recent post that hacking is probably more profitable than selling drugs.

Apparently it is true according to a white paper from MessageLabs.

I warned recently of the need for security in programming frameworks, suggesting that just because you are behind a firewall doesn't make you "safe" from all the world.

This whitepaper also hammers this point home talking about phishing attacks. If someone can weasel one piece of spam through and get one of your 800-20,000 employees to click on the wrong link...they may be able to open the floodgate to all your corporate data.

One recent article I read on top security practices suggests encrypting - everything. Hard drives, databases, etc. Plus you need a good key management system in case someone loses their password or means of encryption and needs to reverse it.

But the point here is - email is the doorway hackers are trying to crack. And just becuase you don't see it - think again. They are pretty sly. Virus programs embedded in malware so the more obvious hacks are wiped clean, monitoring logins so when you login they vamoose, using students at Universities, disguising themselves as harmless but annoying bots...

Here's the white paper regarding the latest email attacks and IT security:

http://reg.itworld.com/servlet/Frs.frs?Context=LOGENTRY&Source=eTEXT0104hm&Source_BC=7&Script=/LP/10011793/reg&code=MSGPSA0122

Sunday, January 21, 2007

Google Imposters

Here are some IPs that recently reported themselves to be Google IP addresses to our server, however looking up those IPs seems like perhaps these are imposters.

64.202.165.132
OrgName: Go Daddy Software
OrgID: GDS-31
Address: 14455 N Hayden Road
Address: Suite 226
City: Scottsdale
StateProv: AZ
PostalCode: 85260
Country: US
NetRange: 64.202.160.0 - 64.202.191.255
CIDR: 64.202.160.0/19
NetName: GO-DADDY-SOFTWARE-INC

72.232.194.66

NetRange: 72.232.0.0 - 72.232.255.255
CIDR: 72.232.0.0/16
NetName: LAYERED-TECH-
NetHandle: NET-72-232-0-0-1
Parent: NET-72-0-0-0-0
NetType: Direct Allocation
NameServer: NS1.LAYEREDTECH.COM
NameServer: NS2.LAYEREDTECH.COM
Comment: Please send all abuse complaints to
Comment: abuse@layeredtech.com
RegDate: 2005-09-07
Updated: 2006-03-07

72.14.75.44
ISP Alliance, INC. ZCORUM (NET-72-14-64-0-1)
72.14.64.0 - 72.14.127.255
Millry.net MILLRY (NET-72-14-75-0-1)
72.14.75.0 - 72.14.75.255

___________________________

66.102.66.148

OrgName: Cingular Wireless
OrgID: CINW
Address: Cingular Wireless, LLC
Address: 12555 Cingular Way, Suite 4360
City: Alpharetta
StateProv: GA
PostalCode: 30004
Country: US
NetRange: 66.102.160.0 - 66.102.191.255

________________________________

66.102.186.15

OrgID: INKG
Address: 177 Wellington Street
Address: Suite 302
City: Kingston
StateProv: ON
PostalCode: K7L-3E3
Country: CA
NetRange: 66.102.64.0 - 66.102.95.255

__________________________________

217.160.230...

inetnum: 217.160.224.0 - 217.160.239.255

netname: SCHLUND-CUSTOMERSdescr: Schlund + Partner AGcountry: US

Saturday, January 20, 2007

Windows Defender - Cool Feature

[UPDATE: Windows Defender had all the useful functionality removed in Windows 7. So someone will have to write another application to do this all over again so Microsoft can by it for billions of dollars all over again.]

Windows Defender has a feature that is pretty cool. I don't know if they added it recently or I just missed it but it really helps pinpoint the nitty gritty of your network traffic.

If you do a netstat in a command window you can see a bunch of IP addresses and ports and try to figure out which apps are generating which of those lines of traffic - and it is a pain.

Windows Defender has a section that tells you which programs and services are connected to the network, as well as the end point IPs and ports.

For example you can see a program xyz and the local IP is your local ip address connected on port 52345 and the remote IP is IP 72.34.53.232 (randomly picked this out of my head) on port 80 (which you know means you are connected over HTTP probably to a web site but possibly to something else.

Then you can look up those IPs on DNSstuff.com or in the appropriate databases: arin.net, lacnic.net, ripe.net, apnic.net, afric.net to verify that the process claiming to be the Google Toolbar update checker is really going to a Google IP address.

Pretty cool and much needed...if you've been following this blog for the life of it back to the day when I was complaining about this problem with Windows (and reporting it to a guy that I know is in contact with Bill Gates.) Could I have made a difference? Who knows...I am just happy to see it.

What would be even more useful now (maybe it is there) would be to log all this traffic because I have a feeling hackers are monitoring logins and web sites and they know, for instance, when someone is remotely connected to or logged into a machine, when an app has been updated, and then they wait for you to get off and fire up their nasties. So whenever you look on the machine - it's clean. You never see a problem real time.....so that would be the next logical step. I'll have to do some research to see if it's in there already.

Friday, January 19, 2007

Match.com Scam

I have a friend who is always telling me stories about her friend who is on a quest to get married. She's a an attractive doctor. She must be smart as she made it through medical school.
So anyway her latest move was to try match.com. She met this "terrific" guy. He sent her a picture - he was a gorgeous black man - supposedly a model from California now on assignment in Africa. Nigeria, to be exact. Anyone involved in Internet security already knows where I am going with this...

He has this match.com profile which is PERFECT. I like walks on the beach, holding hands, watching the sunset...cuddling. Ahem. Ha! I'm cringing as my friend tells me the story...

Within one week my friend's friend is hooked. She thinks he is "the one" and he says he can tell she is "the one" and doesn't want her to talk to anyone else.

...and then it comes...the story...he has these money orders or something that he can't access and needs her to transfer some money...pretty much anyone up on Internet scams knows the routines...

But she is in love. She tells my friend about it and how she's wired this money etc. and how it showed up. Of course my friend is totally freaking about it and like what the hell - don't do it. But her friend is convinced this is a good guy and sure that he must be in love with her and the bank account is real so...she ends up asking someone else who confirms it is a scam and she tells the guys she knows what is going on. And last night I guess they called her twice.

Well I told them to report all of this to the FBI immediately on the Internet crime link...or should it be the CIA as it is international...or both...my friend says "well she reported it to Match.com and his account was somehow closed..." I urged them to report it with any phone numbers they have, etc.

And then my friend asks - so what can you do about these people in huts in Africa - she says she's seen TV shows where they have computers all lined up...what can we do? It's a government thing. There needs to be an international effort to crack down on this stuff. Everyone knows there are so many Internet scams coming out of Nigeria and ripped off software and stolen goods, and hackers in China doing espianage for the government and the Russian mafia stealing credit cards and hacker organizations like Gulli.com and spammers in Brazil. Everyone knows....but is anyone doing anything about it?

And if a doctor like my friend's friend can fall for such a scam....

Hopefully Match.com has some sort of automated program that analyzes content to look for scammer type material but I am not sure how this works with privacy laws. The least they can do is make a HUGE alert on their web site to anyone signing up for and using their account. Obliviously they are not doing that since this person did not see any such warning - or it needs to be more blatant.

Thursday, January 18, 2007

Preventing Zero Day Attacks

This looks promising. Symantec is using brains instead of a database to figure out if software is malicious or not. Something like this is definitely needed - over and above a database approach. It is too easy to change a file name - let's say if you know xyz.exe is a known hack - the hacker can simply post that file all over the place for the unwary user to download with countless other names. Zero day attacks need more than a known list of hacks because their goal is to get out and do damage in one day - before they get into that database. Also with an FBI representative claiming that 15% of the world's computers are hacked and/or controlled by command and control servers doing dirty work - and new hacked servers coming online every day, it is impossible to block out hackers based on IP address or other identifying information alone.

http://www.networkworld.com/news/2007/011707-symantec-to-use-sonar-to.html?nlhtsec=0115securityalert3&company=BMC

Tuesday, January 16, 2007

Open Resolvers - DNS

Open resolvers seem to be a problem as defined here:

http://dns.measurement-factory.com/surveys/openresolvers.html

I have a new client who is coming from one of the companies on this list of known open resolvers:

http://dns.measurement-factory.com/surveys/openresolvers/ASN-reports/20060923.html

We shall see if and what problems come out of all of this.

Here is some more technical information about open resolvers:
http://condor.depaul.edu/~jkristof/slides/dns-ctinetseminar.pdf

Wednesday, January 03, 2007

Today's blocked IPs

Here are the Ips blocked by our hacker filter:

193.110.140.148
220.181.19.187
38.98.120.70
220.181.19.187
71.13.115.117 (multiple times - reported to network but has not stopped)
220.130.191.239
206.138.130.2
64.229.220.96
88.198.43.39
62.13.25.219
220.181.19.164
216.71.96.94
206.67.139.100
38.98.120.70 (multiple)
38.100.225.5
76.215.57.44

Sunday, December 31, 2006

89.240.207.15 - Unidentified IP?

Interesting, the information for this IP address is mysteriously not found in the IP databases.

89.240.207.15

DNS Stuff reports that it resolves to the UK. The information should be found in RIPE (ripe.net) however it is not there, either.

Toshiba Power Saver - Hack or Problem?

Is there any reason why the Toshiba Satellite laptop power saver needs to dial out to the Internet? This particular piece of code has been the source of major problems on my last two computers and just had an error with a new one I bought only a couple of months ago.

Bascially the first error I saw on this computer is when it was connected to a wireless network and I shut down the connection. Then the Toshiba power saver gave me an unexpected error message.

So why is this power saver getting errors when I shut off internet access unless it is somehow dialed out to the Internet, pray tell?

Very curious as this is the same component that continually crashes even after re-building my last Toshiba about three times. Each time I start having problems with the power saver. I thought it had something to do with my third party power cord that also flaked out but on this new computer I have only used the power adaptor that came with the machine.

So either there is a hack in this software that is somehow allowing access it should not - or there is some really bad programming and error checking in the software.

I hope someone out there is reading and will do some additional testing on this besides just hackers.

Friday, December 22, 2006

For those who throw up their hands at hackers...

Hackers sell zero day exploits to Microsoft products at $50,000 a crack.

http://www.eweek.com/article2/0,1895,2073611,00.asp

Hacking is profitable. Just as is selling drugs. More so.

The internet is the new wild, wild west. Lawlessness abounds. Fend for yourself.

By the time the Marshall arrives it will be too late, and what good is one guy against a gang of thugs anyway.

Tuesday, December 12, 2006

Students, University Networks and Criminals

You'll probably never believe this but had it in my head for a while to write about the huge amount of traffic I see coming from universities that is obviously hacker traffic. I was going to suggest that maybe someone was paying students to do dirty work or possibly download "cool new stuff" which is unknowling running worms, viruses or malware. Something has to be going on at Universities because I cannot believe they are all just hacked to such a high extreme.

Lo and behold I found this article today:

http://www.pcmag.com/article2/0,1895,2070706,00.asp

Saturday, November 25, 2006

Command and Control Bots

Working away and suddenly a whole bunch of hits on my server from bots around the world lead me to suspect that these IPs are somehow working together in a coordinated attack of some kind.

Could be coincidental but just saw a whole bunch of hits in a short time period. I have been working all day and not been seeing this. These hits are from the usual suspects - Germany, Taiwan, etc.

And coincidentally - I just made a significant update to my web server. Seems as though they are monitoring changes.

64.124.85.78
64.34.145.194
64.34.145.195
66.246.252.172
38.100.225.11
193.47.80.39
220.130.191.240
219.142.118.37
212.241.204.251
38.98.120.70
64.34.145.198
88.198.43.39

Tuesday, November 21, 2006

Sites with XSS Flaws

Here's a forum of sites with XSS flaws. Verify for yourself. If you can stand the terrible language and tangents.

Sites with XSS Flaws

I accidentally found an XSS flaw on my bank's web site recently. They were trying to prevent it by using a JavaScript pop up box. Helllloooo. Who doesn't know you can turn off JavaScript these days? A bank for goodness sakes...my money at stake.

It is a small credit union. Needless to say I am in the process of changing banks.

Saturday, November 18, 2006

Sunday, November 12, 2006

Process Monitor: What is that process doing?

Microsoft took over sysinternals.com as mentioned and in so doing is replacing regmon and filmon with the Sysinternals Process Monitor.

Process Monitor

This looks to be the information requested for months in my pleas to help find out what is causing problems on a machine in past articles (of course I am just one of the many...) I haven't tried it yet but if it lives up to the description it could be very useful if and when you suspect hacking on a machine - to verify and validate every process and user and what they have been up to.

Friday, November 10, 2006

Windows Security Utilities

Here are some utilities that can be used to explore what is running on your machine:

Security Utilities

Microsoft has purchased a the site formerly Sysinternals.com which was a good source of utilities - probably used by both hackers and legitimate security professional alike.

Wednesday, November 08, 2006

Kernel bugs & vulnerabilities

Which OS has the most hacks -- and the most alarming hacks or bugs?

This month that topic is being explored by some developers on this web site with contributions accepted from other developers around the world:

Kernel Bugs

The scariest one to me so far is the GDI bug on windows that allows escalation of privileges to take over a machine. Not good and no fix available yet supposedly.

Also interesting are the tools used to find these bugs. Aren't the developers building this software familiar with and testing their software with these tools for such a critical piece of functionality such as an operating system kernel?

Yeah I might not be using them for my code but I don't have the whole world relying on the securty of my software as these vendors do.

Tuesday, November 07, 2006

Site Rippers

There are many reasons why someone may want to "rip" a site but in my opinion, it should be illegal. Things are copyrighted and available online. If you need them offline you should have to request permission from the site owner.

I would guess most people are site ripping for the purpose of reverse engineering a site either to compete with SEO rankings or to try to find a way to hack the site. For instance they can rip the site, run tests against it without hitting your web logs, and then put the program they have developed to do whatever to you web site undected - so it looks like normal traffic in your web logs.

Some site rippers are obvious - like looking in the request headers and finding the user agent. Others are more sly, doing things to cover their tracks and appear as if they were a "normal" user.

What to do about site ripping? Good question. First block the blatant ones. Second, look for traffic anomalies that don't appear to be "normal" users clicking through a site at normal speed. Finally, frequent site changes can help ensure someone has not written a program to walk through your pages and do something malicious. You can "break" their code by finding ways to change your pages frequently.

Tuesday, October 31, 2006

Codecs, Drivers, and Kapersky

Fake Codecs and Kapersky - written by hackers?

Here's something more about fake codecs and driver security hacks: Fake Codecs

I've wondered about the potential security issues with drivers for quite some time.

A note on Kapersky: Since it recognizes this hack and was used in some very sophisticated hacking in commercial software server abuse (see a recent post on a hack that installs it's own virus checker) I am wondering more and more about the virus scanner.

So I read more about it: This company seems to be "headquartered" in a number of countries all over the world, listing Russia first. I read that they have since moved headquarters to England and a visit to their web site reports a US address.

I bet it is the best virus checker out there...that doesn't mean I'll use it.

Let's say someone wanted to infiltrate the most protected and secure machines around the world? What would be the most effective way to do that?

Think Trojan horse.

Write the software that is protecting them of course.

Just a twisted idea for a movie plot.

Instead of making the world hate them - by sneaking things onto their machine or creating PR nightmares such as this supposed FBI Keylogger (Magic Lantern) has done -- the world loves them...and invites them in...yes protect my computer!

Here's a twisted thought: What if Kapersky likes the idea that Microsoft is blocking out anti-virus checkers from other vendors:

Kapersky says Vista doesn't block out anti-virus vendors

I did some research on Kapersky just for fun...I'm sure all security software has bugs but here's what I found...

Kaspersky Anti-Virus cab.ppl CAB Archive Handling Overflow
A remote overflow exists in Kapersky Anti-Virus. The 'cab.ppl' engine fails to perform proper bounds checking resulting in a buffer overflow. With a specially crafted CAB archive, a remote attacker can cause arbitrary code execution resulting in a loss of integrity.. Kapersky Buffer Overrun

"The recent compromise at Kapersky Labs, in which subscribers were potentially duped into accepting fake updates which contained the Bridex Worm, demonstrates the critical importance of this enhanced approach to update security," said John Sharp, president and CEO of Authentium in a statement...Kapersky fake downloads

Something that someone else will need to interpret Congrats, you've detected Kapersky AV

Here's another article worth a look - on security problems with your anti-virus software. One of the problems with Panda could leave your machine open to a complete take-over by a hacker. A seemingly innocent error...

Security problems in Security Software

Who's auditing the virus scanners and security software?

And who's to say all distributions of a particular software are the same?

And who's to say things aren't hiding in plain sight?

Ok yeah it's just a thought. Just kidding. Kind of.

Verify, validate, audit.

Thursday, October 26, 2006

How much of your traffic is HUMAN?

I just did an analysis of my web traffic to see how much of it came from valid potential purchasers of our products and services collectively and how much of the traffic came from some sort of automated mechanism - bots, robots, spiders, programming libraries, widgets and unidentified surfing objects.

60% of the traffic was from machines. Non-human beings. Non potential sources of income. Of course the search engines are helpful in getting traffic to us and some was our monitoring system, but 60%?? That is a lot of wasted bandwidth because not all those search engines are at all helpful. Some are actually malicious.

Monday, October 23, 2006

Stock Spam

I've written about a lot of problems related to dlls and spam spewing out of my servers. Maybe this was the source:

A hack with it's own virus checker

This piece of malware is spewing out all that stock spam you've possibly been seeing lately with some pretty advanced tactics.

The article states that the trojan uses peer-to-peer technology to communicate with command and control servers, however it does not tell you how it got on the box in the first place.

This software is making some use of dlls...a major annoyance if you read my previous posts.

Sunday, October 22, 2006

Stock Picking Service - Internet Influence?

I got a request from someone to help them market a stock picking web site. I am not yet completely sure what it is and how he makes his money. He sells a newsletter on one site and gives it away free on another site.

While researching the customer I found that there are a bunch of spam like stock postings with some apparently somewhat useful information but I am not quite sure yet if it is clearly spam or just a feeble attempt at marketing.

Then I notice this other guy's name all over related to the guy who made me the request. So I go check out the other guy's web site and he's got this video of himself and a clearly used-car salesman looking site guaranteeing people they will make money using his stock analysis / picking service.

So I start to ponder whether these guys are legit or not and then it hits me. The first guy wants me to get people to sign up for his free newsletter at 1000 people per day. In one month that would be 30,000 people.

If he says "buy this stock" and 30,000 people buy the stock - what effect will that have on that particular stock? If he says sell....

I am not sure exactly how many people it would take to influence a stock but the thought is somewhat interesting. L. Ron Hubbard, founder of Scientology and author of Dianetics, was quoted as saying "if you want to make a little money, write a book. If you want to make a lot of money - create a religion" (according to my professor of comparative religion in college). I found a reference to the statement here. That always fascinated me - that he said it, did it- and people still follow this religion even though his motivations are blatant.

The same principle kind of applies here. If you can get thousands or even millions of people to believe you have magical stock picking ability and some incredible "magical" software that helps you pick stock - and then you tell all your believers to go buy or sell something - you may be able to influence the market. And guess what. You believe in yourself too in that case...Because you know what will happen when you say "go".

Friday, October 20, 2006

Microsoft Vista Driver Authentication

In this article a Singapore security expert shows how Microsoft Vista correctly blocks a malicious driver attack, and yet how other vulnerabilities exist in the driver security process added to the operating system. Microsoft Vista driver authentication

At least I applaud Microsoft for making attempts to resolve this problem but it looks like they still have a ways to go.

My friend from Microsoft just warned me that Vista's new security model is not good, however he didn't say why. He was in the past working on something to control driver security and completely frustrated with Microsoft and his job. He used to work with really smart people and sounds like they left one by one and no one wants to solve the "really hard problems". Could it be that Microsoft is infiltrated with people who do not want to solve these problems? Or is it that they just don't want to take the risk of doing something extremely complicated and have it exploited and put their heads on the chopping block at Microsoft? Who knows.

Even if Vista's new security model is not good - could it be worse that what existed before? It seems that some level of authentication is better than none, doesn't it?

Thursday, October 19, 2006

SPF Records: Do it Now

Yes a lot of people complain about the problems with SPF records. However the problems with not using them are greater.

Right now I am getting hundreds of bounce back messages because spammers are spewing out messages using my domains.

The problem for the people who are using mail systems that do not check SPF records is that they do not know this spammer IP is not on our allowed list and that this is obviously spam. If their mail system was checking our SPF records they would not be getting the messages in the first place, and if it was a good mail system it would not be spewing out bounce messages for spoofed emails.

The problem for mail administrators and mail servers is that by not checking SPF records a lot of bandwidth and processing power is wasted. If they would first check SPF records before touching the mail then they wouldn't have to even deal with checking to see if the user really exists on the system, and storing the message at all. And possibly spammers would leave their servers alone since they can't get messages to it.

The problem for me is that the end users, our potential customers, who are uninformed about SPF records, spoofers and spamming, is that they may be reporting our email as spam to their service providers and our domain may get blocked - incorrectly - by mail administrators and mail systems that are not smart enough to look at the spf records to verify the mail is from a legitimate source.

If you are not using SPF records it could be harming your business and limiting your business opportunities. Let's say you sumbmit a request for a quote to some business in their web form - they reply to you but you never get it because their domain has been incorrectly flagged as spam. Or let's say you get a bunch of spam and block that domain entirely. Now suddenly you can't get mail from a possibly legitimate new customer who didn't know their domain had been hijacked.

As I write this I must warn however that someone out there, needs to be keeping an eye on all this rejected spam...as mentioned in previous posts it could actually be used as a form of communication by people who do not want you to know what they are writing! So hopefully someone out there is keeping an eye on legitmate AND spoofed and spam email messages.

To find out more about SPF records contact your mail provider, your hosting provider and take a look at http://www.openspf.org

If your mail provider tries to talk you out of SPF records - yes there are some issues with them - but you can define all the allowed servers to send your mail and that should resolve the problem and make your domain harder to steal and spoof. In most cases they try to talk to you this way because they don't know how to set it up correctly - get a new mail provider.

SPF may not be a perfect solution - but it is the only solution I know of right now that even attempts to resolve this problem. Maybe there are others that are better and I would love to hear about them, but my mail provider has received awards for secure email solutions and this is their recommendation.

Sunday, October 15, 2006

DDOS Attacks

This past year I was subjected to a huge amount of Fox News. I prefer the BBC and NPR any day, but I find it interesting that in all the news stories about the information posted on Al-Jazeera about the soldier/prisoner scandal I never heard anything about this:

DDOS attacks on Al-Jazeera

And let me tell you, I was with a news junky and we were watching every right wing news show known to man. Maybe the newscasters just didn't understand it. This is almost scarier because the next real war is at the computer and network level. I have written about this previously.

But enough of that. The interesting thing about this article is that DDOS attacks can cripple a web site -- and that using a private network such as Akamai can be a solution to this problem. Probably at a hefty price, of course.

Thursday, October 12, 2006

Web Site Hacks

I have mentioned most of these previously but here's another resource outlining potential web site hacks:

Web Site Hacks & How To Fix

Chargebacks - the Crime No One is Watching

I received some chargebacks on my merchant account. Supposedly they are not really chargebacks, however if I do not provide the information requested on the form back the bank within 25 days, they can take the money out of my account.

The reason listed on the piece of paper I received in the mail from my bank (Bank of America) is this: 32-Cardholder Does Not Recognize Transaction.

I contacted the cardholder and they told me they never reported any problem with the transaction to their bank. Someone is initiating this response, it is not the cardholder and therefore it is fraudulent based on the response on the document I have.

Worse yet, the document asks me to fax the account number, expiration date and all the information including a signature from the sales draft to their fax number.

Just by reading this it looks as if I have to provide the ENTIRE account number, expiration date and the customer's signature. Hmmm. Is this secure to be faxing this stuff around? When I called in they said I could just give them the last four digits. I do not even store the full card number anywhere for security reasons. (So if you're hacking my server - you're wasting your time).

Finally when I explain this is potentially a fraudulent scam and someone should look into it and try to crack down on this there is nothing they can do. They just blindly send the requested data to any bank that asks for it in any country (this is an international web site) to resolve the issue. Supposedly they would not send the information "to just anybody" but I wonder how tight that security is, based on this whole scenario, on validating where they are sending cardholder data and who has access to it.

Here's the potential: Someone, be it at Bank of America, the third party bank, or a hacker, could be intiating the charge back to me and if I miss it, the money is taken out of my account. But guess what, the cardholder never said they didn't recognize the transaction in the first place...think about it...where did that money go?? Someone's pocket - and not the right one.

Monday, October 09, 2006

PayPal Sent Me a Virus

The other day an address listed as coming from PayPal sent me a virus and it appeared to be actually coming from a PayPal email server. It was caught by the virus checker on my email system.

So I did the good citizen thing and reported it to PayPal so they would know and could look into it.

And they send me back a message stating something like:

"PayPal occasionally sends message to users...if you don't want these messages go into your preferences and change them..."

Sorry but I didn't see the option for "DON'T SEND ME VIRUSES".

Friday, October 06, 2006

Blog Spam

Here's a company using blog spamming to advertise products and presumably to try to increase search engine rankings with crap writing:

http://payperpost.com/

This company is advertising to bloggers to get paid for writing stuff for their advertisers. Heck I write fast I should probably do it but I won't - because I have some stupid principal in me that doesn't want to spew out fake garbage.

The problem with this thing is that people are spewing out fake, useless, biased content in an attempt to make money. For instance you can write about some product and you're getting paid for it. Are you going to write something negative?? And even if you would, is the advertiser going to post the negative feedback? No.

To me this is a blog spam factory and wasting everyone's time.

Wednesday, October 04, 2006

Serve-U hack?

I was running a trial of Serve-U Corporate edition. At the end of thirty days it turns to the personal edition.

Coincidentally I started to have a bunch of problems on my machine around that same time. See two posts prior.

I reported the problem with dllhost.exe to my hosting provider.

Then suddenly my ftp software stopped working. It said the executable was missing. I tried reinstalling. No dice. I then uninstalled and reinstalled the thing and now it works again.

There are various things you can do to lock it down like restricting IP access, etc so I tried that.

I don't know if this is all coincidental but I started having all these problems at the same time which I mentioned in previous posts:

- cannot access admin portal for Datapipe in Mozilla
- email bounce backs show spam from my domain names (working on spf records now)
- ftp server is hosed and have to reinstall
- web server using 100% of cpu and supposedly reboots itself while hosting techs are looking at it (hmm)
- web sites and/or local network is dog slow upon occasion - sometimes so slow images don't load at all from my web server
- dllhost.exe running on my box when supposedly dcom is locked down and all IIS services are disabled
- IIS service accounts have been re-enabled

I only report what I see....I am making no conclusions here until I pin down what is going on.

Global and Catastrophic IT Hacker Holes

This is a great read. Peter Coffee outlines some really big IT blunders that caused huge problems losing millions of dollars, blowing up huge infrastructures and causing world wide waves of hacking.

Dirty Dozen IT Blunders

Tuesday, October 03, 2006

Spam/Hack attack on a Java User Group

Just another report from the trenches. A recent message from a Java user group mailing list:

it appears that our fun little wiki site has attracted spammers from holland
and russia. their favorite mechanism so far appears to be to create bogus
accounts and upload html files which contain spam.

I am running daily reports and swatting them as I find them. In the meantime,
if anyone finds anything else I might have missed, pls let me know.

Thanks!

Monday, October 02, 2006

Recent Hacker IP Addresses

Here are some recent hacker IP addresses. How do I know? Because they are hitting my server on the IP and not on the domain names, and requesting technologies that do not exist on my server. They are most likely scanning for things with known holes in them that have not been patched. Notice that the most highly sought after holes are in PHP. See my other posts about PHP hacks.

Sat Sep 16 15:49:59 PDT 2006 81.3.160.38 /xmlrpc/xmlrpc.php
Mon Sep 25 11:24:10 PDT 2006 219.142.169.136 /sumthin
Sat Sep 23 02:31:28 PDT 2006 194.72.238.63 /
Fri Sep 22 14:35:21 PDT 2006 66.221.181.243 /xmlrpc/xmlrpc.php
Fri Sep 22 14:35:17 PDT 2006 66.221.181.243 /phpAdsNew/adxmlrpc.php
Fri Sep 22 14:35:21 PDT 2006 66.221.181.243 /xmlrpc.php
Fri Sep 22 14:35:17 PDT 2006 66.221.181.243 /phpads/adxmlrpc.php
Fri Sep 22 14:35:17 PDT 2006 66.221.181.243 /adxmlrpc.php
Fri Sep 22 14:35:17 PDT 2006 66.221.181.243 /phpadsnew/adxmlrpc.php
Fri Sep 22 14:35:17 PDT 2006 66.221.181.243 /Ads/adxmlrpc.php
Fri Sep 22 14:35:17 PDT 2006 66.221.181.243 /ads/adxmlrpc.php
Fri Sep 22 14:35:17 PDT 2006 66.221.181.243 /a1b2c3d4e5f6g7h8i9/nonexistentfile.php
Fri Sep 22 14:35:17 PDT 2006 66.221.181.243 /adserver/adxmlrpc.php
Fri Sep 22 12:24:16 PDT 2006 194.72.238.62 /
Thu Sep 21 12:42:12 PDT 2006 194.72.238.63 /
Wed Sep 20 23:29:32 PDT 2006 194.72.238.62 /
Wed Sep 20 16:12:12 PDT 2006 71.87.211.76 /_vti_bin/_vti_aut/fp30reg.dll
Wed Sep 20 00:02:43 PDT 2006 194.72.238.63 /
Tue Sep 19 09:07:31 PDT 2006 82.192.89.153 /mysql/main.php
Tue Sep 19 09:07:31 PDT 2006 82.192.89.153 /db/main.php
Tue Sep 19 09:07:30 PDT 2006 82.192.89.153 /phpmyadmin/main.php
Tue Sep 19 09:07:30 PDT 2006 82.192.89.153 /PMA/main.php
Tue Sep 19 09:07:31 PDT 2006 82.192.89.153 /admin/main.php
Sat Sep 16 15:49:55 PDT 2006 81.3.160.38 /a1b2c3d4e5f6g7h8i9/nonexistentfile.php
Sat Sep 16 15:49:56 PDT 2006 81.3.160.38 /adxmlrpc.php
Sat Sep 16 15:49:56 PDT 2006 81.3.160.38 /adserver/adxmlrpc.php
Sat Sep 16 15:49:57 PDT 2006 81.3.160.38 /phpAdsNew/adxmlrpc.php
Sat Sep 16 15:49:57 PDT 2006 81.3.160.38 /phpadsnew/adxmlrpc.php
Sat Sep 16 15:49:57 PDT 2006 81.3.160.38 /phpads/adxmlrpc.php
Sat Sep 16 15:49:58 PDT 2006 81.3.160.38 /Ads/adxmlrpc.php
Sat Sep 16 15:49:58 PDT 2006 81.3.160.38 /ads/adxmlrpc.php
Sat Sep 16 15:49:59 PDT 2006 81.3.160.38 /xmlrpc.php
Sat Sep 16 15:50:00 PDT 2006 81.3.160.38 /xmlsrv/xmlrpc.php
Sat Sep 16 15:49:59 PDT 2006 81.3.160.38 /xmlrpc.php
Sat Sep 16 15:49:58 PDT 2006 81.3.160.38 /Ads/adxmlrpc.php
Sat Sep 16 15:49:57 PDT 2006 81.3.160.38 /phpadsnew/adxmlrpc.php
Sat Sep 16 15:49:56 PDT 2006 81.3.160.38 /adserver/adxmlrpc.php
Sat Sep 16 15:49:55 PDT 2006 81.3.160.38 /a1b2c3d4e5f6g7h8i9/nonexistentfile.php
Sat Sep 16 22:17:30 PDT 2006 194.72.238.62 /
Sat Sep 16 15:49:56 PDT 2006 81.3.160.38 /adxmlrpc.php
Sat Sep 16 15:49:56 PDT 2006 81.3.160.38 /phpAdsNew/adxmlrpc.php
Sat Sep 16 15:49:57 PDT 2006 81.3.160.38 /phpads/adxmlrpc.php
Sat Sep 16 15:49:58 PDT 2006 81.3.160.38 /ads/adxmlrpc.php

Fri Sep 22 14:35:21 PDT 2006 66.221.181.243 /blogs/xmlrpc.php
Fri Sep 22 14:35:17 PDT 2006 66.221.181.243 /a1b2c3d4e5f6g7h8i9/nonexistentfile.php
Fri Sep 22 14:35:20 PDT 2006 66.221.181.243 /ads/adxmlrpc.php
Fri Sep 22 14:35:21 PDT 2006 66.221.181.243 /xmlrpc/xmlrpc.php
Fri Sep 22 14:35:21 PDT 2006 66.221.181.243 /blog/xmlrpc.php
Fri Sep 22 14:35:21 PDT 2006 66.221.181.243 /community/xmlrpc.php
Fri Sep 22 14:35:21 PDT 2006 66.221.181.243 /blogs/xmlsrv/xmlrpc.php
Sat Sep 23 02:31:28 PDT 2006 194.72.238.63 /
Fri Sep 22 14:35:20 PDT 2006 66.221.181.243 /phpadsnew/adxmlrpc.php
Mon Sep 25 10:26:23 PDT 2006 219.142.169.136 /sumthin
Mon Sep 25 11:24:10 PDT 2006 219.142.169.136 /sumthin
Mon Sep 25 13:45:56 PDT 2006 194.72.238.63 /
Tue Sep 26 12:15:09 PDT 2006 194.72.238.63 /
Wed Sep 27 05:58:18 PDT 2006 194.133.131.201 /_vti_bin/_vti_aut/fp30reg.dll
Wed Sep 27 10:57:30 PDT 2006 194.72.238.63 /
Mon Sep 11 23:04:31 PDT 2006 64.114.199.1 /
Mon Sep 11 23:04:31 PDT 2006 64.114.199.1 /
Wed Sep 13 15:35:31 PDT 2006 64.114.199.1 /
Wed Sep 13 15:35:31 PDT 2006 64.114.199.1 /
Sat Sep 16 14:41:49 PDT 2006 194.72.238.62 /
Tue Sep 19 04:12:53 PDT 2006 212.43.248.186 /
Tue Sep 19 09:07:28 PDT 2006 82.192.89.153 /admin/main.php
Tue Sep 19 09:07:28 PDT 2006 82.192.89.153 /db/main.php
Tue Sep 19 09:07:27 PDT 2006 82.192.89.153 /phpmyadmin/main.php
Tue Sep 19 09:07:28 PDT 2006 82.192.89.153 /mysql/main.php
Tue Sep 19 09:07:27 PDT 2006 82.192.89.153 /PMA/main.php
Wed Sep 20 00:02:43 PDT 2006 194.72.238.63 /
Wed Sep 20 15:02:32 PDT 2006 194.72.238.62 /
Wed Sep 20 15:57:28 PDT 2006 71.87.211.76 /_vti_bin/_vti_aut/fp30reg.dll
Thu Sep 21 12:42:12 PDT 2006 194.72.238.63 /
Thu Sep 21 16:18:31 PDT 2006 64.246.0.17 /robots.txt
Fri Sep 22 08:59:01 PDT 2006 194.72.238.62 /
Fri Sep 22 14:35:17 PDT 2006 66.221.181.243 /adxmlrpc.php
Fri Sep 22 14:35:17 PDT 2006 66.221.181.243 /adserver/adxmlrpc.php
Fri Sep 22 14:35:20 PDT 2006 66.221.181.243 /phpAdsNew/adxmlrpc.php
Fri Sep 22 14:35:20 PDT 2006 66.221.181.243 /phpads/adxmlrpc.php
Fri Sep 22 14:35:20 PDT 2006 66.221.181.243 /Ads/adxmlrpc.php
Fri Sep 22 14:35:21 PDT 2006 66.221.181.243 /xmlrpc.php
Fri Sep 22 14:35:21 PDT 2006 66.221.181.243 /xmlsrv/xmlrpc.php
Fri Sep 22 14:35:21 PDT 2006 66.221.181.243 /drupal/xmlrpc.php
Tue Sep 19 09:07:28 PDT 2006 82.192.89.153 /admin/main.php pmafind
Tue Sep 19 09:07:30 PDT 2006 82.192.89.153 /phpmyadmin/main.php pmafind
Tue Sep 19 09:07:30 PDT 2006 82.192.89.153 /PMA/main.php pmafind
Tue Sep 19 09:07:31 PDT 2006 82.192.89.153 /admin/main.php pmafind
Tue Sep 19 09:07:28 PDT 2006 82.192.89.153 /db/main.php pmafind
Tue Sep 19 09:07:27 PDT 2006 82.192.89.153 /phpmyadmin/main.php pmafind
Tue Sep 19 09:07:28 PDT 2006 82.192.89.153 /mysql/main.php pmafind
Tue Sep 19 09:07:31 PDT 2006 82.192.89.153 /db/main.php pmafind
Tue Sep 19 09:07:27 PDT 2006 82.192.89.153 /PMA/main.php pmafind
Tue Sep 19 09:07:31 PDT 2006 82.192.89.153 /mysql/main.php pmafind
Fri Sep 22 14:35:17 PDT 2006 66.221.181.243 /a1b2c3d4e5f6g7h8i9/nonexistentfile.php
Fri Sep 22 14:35:17 PDT 2006 66.221.181.243 /adserver/adxmlrpc.php
Fri Sep 22 14:35:17 PDT 2006 66.221.181.243 /adxmlrpc.php
Fri Sep 22 14:35:17 PDT 2006 66.221.181.243 /adxmlrpc.php
Fri Sep 22 14:35:17 PDT 2006 66.221.181.243 /adserver/adxmlrpc.php
Fri Sep 22 14:35:17 PDT 2006 66.221.181.243 /phpadsnew/adxmlrpc.php
Fri Sep 22 14:35:17 PDT 2006 66.221.181.243 /Ads/adxmlrpc.php
Fri Sep 22 14:35:17 PDT 2006 66.221.181.243 /ads/adxmlrpc.php
Fri Sep 22 14:35:20 PDT 2006 66.221.181.243 /phpAdsNew/adxmlrpc.php
Fri Sep 22 14:35:20 PDT 2006 66.221.181.243 /phpads/adxmlrpc.php
Fri Sep 22 14:35:20 PDT 2006 66.221.181.243 /Ads/adxmlrpc.php
Fri Sep 22 14:35:21 PDT 2006 66.221.181.243 /xmlrpc.php
Fri Sep 22 14:35:21 PDT 2006 66.221.181.243 /xmlsrv/xmlrpc.php
Fri Sep 22 14:35:21 PDT 2006 66.221.181.243 /drupal/xmlrpc.php
Fri Sep 22 14:35:21 PDT 2006 66.221.181.243 /blogs/xmlrpc.php
Fri Sep 22 14:35:21 PDT 2006 66.221.181.243 /xmlrpc.php
Fri Sep 22 14:35:17 PDT 2006 66.221.181.243 /phpads/adxmlrpc.php
Fri Sep 22 14:35:17 PDT 2006 66.221.181.243 /a1b2c3d4e5f6g7h8i9/nonexistentfile.php
Fri Sep 22 14:35:17 PDT 2006 66.221.181.243 /phpAdsNew/adxmlrpc.php
Fri Sep 22 14:35:20 PDT 2006 66.221.181.243 /ads/adxmlrpc.php
Fri Sep 22 14:35:21 PDT 2006 66.221.181.243 /xmlrpc/xmlrpc.php
Fri Sep 22 14:35:21 PDT 2006 66.221.181.243 /blog/xmlrpc.php
Fri Sep 22 14:35:21 PDT 2006 66.221.181.243 /community/xmlrpc.php
Fri Sep 22 14:35:21 PDT 2006 66.221.181.243 /blogs/xmlsrv/xmlrpc.php
Fri Sep 22 14:35:21 PDT 2006 66.221.181.243 /xmlrpc/xmlrpc.php
Fri Sep 22 14:35:20 PDT 2006 66.221.181.243 /phpadsnew/adxmlrpc.php
Sat Sep 16 15:49:55 PDT 2006 81.3.160.38 /a1b2c3d4e5f6g7h8i9/nonexistentfile.php
Sat Sep 16 15:49:56 PDT 2006 81.3.160.38 /adxmlrpc.php
Sat Sep 16 15:49:56 PDT 2006 81.3.160.38 /adserver/adxmlrpc.php
Sat Sep 16 15:49:56 PDT 2006 81.3.160.38 /adserver/adxmlrpc.php
Sat Sep 16 15:49:57 PDT 2006 81.3.160.38 /phpAdsNew/adxmlrpc.php
Sat Sep 16 15:49:57 PDT 2006 81.3.160.38 /phpadsnew/adxmlrpc.php
Sat Sep 16 15:49:57 PDT 2006 81.3.160.38 /phpadsnew/adxmlrpc.php
Sat Sep 16 15:49:57 PDT 2006 81.3.160.38 /phpads/adxmlrpc.php
Sat Sep 16 15:49:58 PDT 2006 81.3.160.38 /Ads/adxmlrpc.php
Sat Sep 16 15:49:58 PDT 2006 81.3.160.38 /Ads/adxmlrpc.php
Sat Sep 16 15:49:58 PDT 2006 81.3.160.38 /ads/adxmlrpc.php
Sat Sep 16 15:49:59 PDT 2006 81.3.160.38 /xmlrpc.php
Sat Sep 16 15:49:59 PDT 2006 81.3.160.38 /xmlrpc.php
Sat Sep 16 15:50:00 PDT 2006 81.3.160.38 /xmlsrv/xmlrpc.php
Sat Sep 16 15:49:55 PDT 2006 81.3.160.38 /a1b2c3d4e5f6g7h8i9/nonexistentfile.php
Sat Sep 16 15:49:56 PDT 2006 81.3.160.38 /adxmlrpc.php
Sat Sep 16 15:49:56 PDT 2006 81.3.160.38 /phpAdsNew/adxmlrpc.php
Sat Sep 16 15:49:57 PDT 2006 81.3.160.38 /phpads/adxmlrpc.php
Sat Sep 16 15:49:58 PDT 2006 81.3.160.38 /ads/adxmlrpc.php
Sat Sep 16 15:49:59 PDT 2006 81.3.160.38 /xmlrpc/xmlrpc.php

Sunday, October 01, 2006

Invalid SSL Certificate Accessing Hosting Company Admin Web Site

Today was trying to access the Admin console for DataPipe (a managed server I work on ) and could not access the site via https in Mozilla using HTTPS. It keeps timing out. Interestingly enough when accessing it via HTTP in Mozilla or on IE with HTTPS it would work correctly.

The weird thing here though is that one time when I tried to access via HTTPS in Mozilla, I got an error saying the SSL certificate domain name did not match the domain name I was trying to access. When I took a look at the certificate details it was pointing to a choicepoint SSL certificate. I am not sure but I think it was secure.choicepoint.net.

Interestingly choicepoint.net is in Atlanta which was probably the most major source of hacking I saw while on my previous hosting provider network. Could be a coincidence. Coincidences and random Internet connections abound.

I went to read about choicepoint on the net and found this: choicepoint

Related?