Tuesday, June 26, 2007

instmsg/aliases/orders 67.40.220.161

Hmm, here's a new one.

This IP: 67.40.220.161 from Qwest

is trying to access this URI

instmsg/aliases/orders

on our shopping cart system.

I found this on the Microsoft web site:
http://support.microsoft.com/kb/278974

Noc4Hosts bombing our server

Someone at this IP address was just attempting to access our server. Since this is a data center related company in Florida I am not sure why they would be trying to access a local service business in California. Seems a bit fishy doesn't it?

66.232.97.32

OrgName: NOC4Hosts Inc. OrgID: NOC4HAddress: 400 N Tampa StAddress: #1025City: TampaStateProv: FLPostalCode: 33602Country: USReferralServer: rwhois://rwhois.noc4hosts.com:4321/NetRange: 66.232.96.0 - 66.232.127.255

Monday, June 25, 2007

XSL Transformations and Client Side Calculations

In a recent edition of Dr. Dobb's Journal (May 2007) a couple of programmers from Turkey explain how to do client side mathematical calculations using XIM and XSLT transformations. This, they explain, is a way to offload some processing to the client side computer.

Yes, this all sounds lovely but I'm sure that most smart e-commerce programmers would instantly recognize that you should not leave any important calculations to the client side of the e-commerce process where it can be manipulated, either by the end user, or by a hacker that has infected his or her machine.

I was going to note that I've always had a somewhat significant amount of traffic from Turkey, by the way, which I find odd given what I am hosting.

Programmer beware - don't jump on everything you read as the next best thing. Consider the pros, cons and appropriate usages of each new technology option. And if you are not entirely sure how it works within your application framework, best check that out before rushing to implementation.

RackSpace potential hacker

This IP is snooping around on our servers - it is coming from a RackSpace data center:

It is either a bot or a hacker since this is not an end user computer:

207.97.207.39 resolves to"navigatormultimedia.com"
Top Level Domain: "navigatormultimedia.com"

OrgName: Rackspace.com, Ltd. OrgID: RSPCAddress: 9725 Datapoint DriveAddress: Suite 100City: San AntonioStateProv: TXPostalCode: 78229Country: USNetRange: 207.97.192.0 - 207.97.255.255

Friday, June 22, 2007

Are you worried yet?

I have been writing in this blog about the need for increased security and government involvement to resolve these problems. I have been writing that these problems are bigger than people realize and affect each and every one of us - our security, our salary, our bank accounts, credit cards, identities and our online purchases.

Today the pentagon was hacked:

http://www.networkworld.com/news/2007/062107-pentagon-shuts-down-systems-after.html?nlhtsec=0618securityalert5

Ok it happens. But how long has this been going on I wonder?

And even worse...our secretary of state says "I'm a very low-tech person."

If the government doesn't get it that they need someone who understands Internet security at the top of the chain - then we are all in big trouble. He better get high-tech or at least tech savvy pretty soon or we are all in big trouble.

Kapersky Wants to Give Awards to Hackers

Kapersky wants to give awards to hackers:

http://blogs.pcmag.com/securitywatch/2007/06/the_kaspersky_malware_awards_1.php

Not a fan. These people do not deserve awards and they probably thrive on the attention. Shame on any news organization that publishes these things. These people do not need to be given attention as if they have performed some great feat. They need to be put in jail and shown to all the world that they are hated, despised criminals that will be punished.

Kapersky says who knows malware better than the people who fight it. I say who knows malware better than the people who WRITE it.

Hmm so the logic goes if A=B and B=C then A = B. Oh never mind.

Just audit everything. Everything.

Thursday, June 21, 2007

AOL Bot

Someone on this AOL IP: 172.203.88.173 is pounding our site with the MJ12 bot - 6/21/07 10:28 a.m.

Following right on it's heels - this known hacker IP was attempting to reach the web server: 8.7.22.195

Shortly before we were hit multiple times by a known hacker IP range: 207.36.201.40

Firefox spyware

Hmm, related to my last post about IE acting all weird, I moved to Firefox and while using the Google web site got a message that it appears I have spyware on my machine. Perhaps messing up IE will get me to switch to Firefox and then... Downloading spybot now...

IPhone not secure

Hmm...this article claims the hot new iPhone is not really secure:
http://www.networkworld.com/news/2007/061907-apple-iphone-gartner.html?nlhtsec=0618securityalert4&

Tuesday, June 19, 2007

Google Security API

This is interesting - Google has a security API that can be incorporated into software programs to blacklist malicious URLS:

http://www.pcworld.com/article/id,133069-page,1/article.html

Spammers and Hackers - Going to Jail

It's about time:
http://blogs.pcmag.com/securitywatch/2007/06/more_phishers_and_spammers_in_1.php

Microsoft - Security Opinion

I am not 100% in agreement with this person. He claims he would "never blame Microsoft" because many apps are not written by Microsoft.

http://www.networkworld.com/community/?q=node/16266&nlhtsec=0618securityalert1&

I disagree. There is a certain level of security that needs to be provided at the operating system level that is beyond the application itself, and in some cases the people who own the system did not even intend to install the software, or the software is doing something other than it's intended purpose. My point here is the operating system has certain "responsibilities" shall we say to manage all these applications and it should prevent some rogue activity and provide appropriate monitoring of things it will not necessarily block so users can easily see what is happening on their system.

Additionally Microsoft does write some of these programs and has responsibility to ensure they are secure and fix any new security breaches. This is not necessarily blaming - it is a fact, however.

Additionally Microsoft needs to delve deeply into the security of things that allow communication across servers such as RPC and DCOM. I have had someone hacking on my server using these technologies - I don't even use them. Microsoft needs to ensure these cannot be used unless the server owner specifically requests to open up these channels in and out of their servers or provide some huge warning if they are open and available.

These are the areas where I would blame Microsoft if there is a security breach, or at least where they can improve and help ensure security.

Microsoft actually can have a competitive advantage over other operating systems that are open source because they have the resources, if they so choose, to pour into security on systems and provide a more cohesive solution than an open source software platform. However some people will always choose open source due the cost issue and the ability to reprogram parts of the OS if needed.

Where to report Internet Crime...

So you've been hacked, spammed, ripped off and defrauded...now what?

Here are some tips....

Here are some useful links for reporting fraud: Internet Fraud

You can report crimes at the Internet Crime Complaint center:
Internet Crime Complaint Center

If it is a crime by someone within the US, there is a link on the FBI web site.

If it is a crime committed by someone outside of the US you may want to report it to the CIA and related web sites.

You can report your hacker traffic trends at SANS Institute. The more people submit firewall logs the more information they have to analyze and compile research to help thwart hackers.

For spam you can report it in some cases to your local government officials. Some states have laws against spam and will prosecute so try your state prosecuting attorney's office. You can also report to anti-spam organizations that go after and try to prosecute spammers such as Spam Cop. Here are some good links: How to Report Spam In the case of spam if you know how to look at email headers, report the spam to the offending network - and not just the local network if it is a company - but the larger network such as AT&T, Comcast or SBC.

In the case of bots and extraneous network traffic report the excessive traffic to the offending network, same as above and the server owner if possible. In some cases you can find out the owner of a computer by doing a reverse look up on the IP address to get the domain name. You can also use tools like DNSStuff.com to look up an IP address and find out the abuse email of the offending network. Send them your logs so they have accurate information with time and date to track down the offending person or malware infected machine.

Make sure you report known bugs and affected software to the vendors that make the hardware and software that may be the source of the problem. The more people that report the problem the better the chance it will be solved.

Write to your local, state, and federal representives for issues such as fraud, identity theft, hacking and spam so they understand and address your concerns. Some of these issues on the international level require government knowledge, diplomacy, more approriate laws and better law enforcement to be resolved.

More useful links on reporting Internet crime:

Report fraud here: http://www.sec.gov/investor/pubs/cyberfraud/tellus.htm and read more about it here: http://www.usa.gov/Citizen/Topics/Internet_Fraud.shtml or here: http://www.fbi.gov/majcases/fraud/internetschemes.htm

CyberCrime: http://www.usdoj.gov/criminal/cybercrime/
http://wiki.castlecops.com/Reporting_Internet_Crime:_The_United_States_of_America

Internet Scams: http://www.scambusters.org/

Reporting Internet Crime in the UK: http://www.homeoffice.gov.uk/crime-victims/reducing-crime/internet-crime/

IFrame Hack Job

Over 10,000 legitimate web sites using IFrames were exploited and used to download malicious software to end user computers.

http://www.networkworld.com/news/2007/061907-italian-job-web-attack.html

Monday, June 18, 2007

PHP Hackers - 2007 to date

Count IP Requested Page Month
36 205.247.203.14 /PHPMYadmin/main.php 6
20 205.247.203.14 /myADMIN/main.php 6
8 205.247.203.14 /mysql-admin/main.phpmain.php 6
8 205.247.203.14 /pma/main.php 6
4 205.247.203.14 /PMA/main.phpmain.php 6
4 205.247.203.14 /pmamy/main.php 6
4 205.247.203.14 /admin/mysql/main.phpmain.php 6
4 205.247.203.14 /admin/phpmyadmin/main.phpmain.php 6
4 205.247.203.14 /admin/pma/main.phpmain.php 6
4 217.71.214.163 /cacti//graph_image.php 6
4 205.247.203.14 /db/main.phpmain.php 6
4 205.247.203.14 /mysql/main.phpmain.php 6
4 205.247.203.14 /phpMyAdmin-2.2.3/main.phpmain.php 6
4 205.247.203.14 /phpMyAdmin-2.2.7-pl1/main.phpmain.php 6
4 205.247.203.14 /phpMyAdmin-2.2.7/main.phpmain.php 6
4 205.247.203.14 /phpMyAdmin-2.7.0/main.phpmain.php 6
4 205.247.203.14 /phpMyAdmin-2.9.1/main.phpmain.php 6
4 205.247.203.14 /phpmyadmin2/main.phpmain.php 6
4 217.71.214.163 //graph_image.php 6
4 205.247.203.14 /web/phpMyAdmin/main.phpmain.php 6
4 205.247.203.14 /mysqladmin/main.phpmain.php 6
4 205.247.203.14 /phpMyAdmin-2.2.0/main.phpmain.php 6
4 205.247.203.14 /phpMyAdmin-2.2.6/main.phpmain.php 6
4 205.247.203.14 /phpMyAdmin-2.5.1/main.phpmain.php 6
4 205.247.203.14 /phpMyAdmin-2.5.4/main.phpmain.php 6
4 205.247.203.14 /phpMyAdmin-2.5.6/main.phpmain.php 6
4 205.247.203.14 /phpMyAdmin-2.6.4-pl4/main.phpmain.php 6
4 205.247.203.14 /phpMyAdmin-2.6.4/main.phpmain.php 6
4 205.247.203.14 /phpMyAdmin-2.7.0-pl2/main.phpmain.php 6
4 205.247.203.14 /phpMyAdmin-2.8.1/main.phpmain.php 6
4 205.247.203.14 /phpMyAdmin-2.8.2.1/main.phpmain.php 6
4 205.247.203.14 /phpMyAdmin-2.8.2.2/main.phpmain.php 6
4 205.247.203.14 /phpMyAdmin-2.8.2.4/main.phpmain.php 6
4 205.247.203.14 /phpMyAdmin-2.9.0.1/main.phpmain.php 6
4 205.247.203.14 /phpMyAdmin-2.9.0.2/main.phpmain.php 6
4 205.247.203.14 /phpMyAdmin-2.9.0/main.phpmain.php 6
4 205.247.203.14 /phpmyadmin/main.phpmain.php 6
4 205.247.203.14 /phpmyadmin/test.phpmain.php 6
4 205.247.203.14 /admin/main.phpmain.php 6
4 205.247.203.14 /dbadmin/main.phpmain.php 6
4 205.247.203.14 /myadmin/main.phpmain.php 6
4 205.247.203.14 /main.phpmain.php 6
2 87.106.103.182 /include/include_top.php 6
1 130.39.11.106 /index.php 6
1 218.127.216.28 /index.php 6
1 219.254.1.163 /index.php 6
1 67.82.106.110 /index.php 6
1 87.228.58.238 /index.php 6
1 122.16.74.92 /profile.php 6
1 220.102.115.237 /profile.php 6
1 67.84.237.55 /profile.php 6
1 68.102.105.73 /profile.php 6
1 68.197.29.166 /profile.php 6
1 68.226.166.235 /register.php 6
1 61.47.47.58 //index.php 6
1 195.222.29.132 //forum/admin/index.php 6
1 172.177.4.5 /index.php 6
1 24.210.154.219 /index.php 6
1 24.250.199.114 /index.php 6
1 64.178.157.212 /index.php 6
1 68.42.187.199 /index.php 6
1 70.161.19.176 /index.php 6
1 222.66.48.253 /profile.php 6
1 68.40.241.80 /profile.php 6
1 72.137.246.167 /profile.php 6
1 72.187.132.166 /profile.php 6
1 213.113.230.166 /register.php 6
1 61.102.25.233 /register.php 6
1 61.157.96.36 /register.php 6
1 65.75.109.219 /register.php 6
1 68.102.172.102 /register.php 6
1 68.94.231.55 /register.php 6
1 72.188.93.47 /register.php 6
1 86.107.156.115 /register.php 6

71.13.115.117 - Charter - Bot

71.13.115.117 is running a bot that continues to hit our sites after asking Charter for months to make it stop.

Charter Communications MDS-WI-71-13-112 (NET-71-13-112-0-1) 71.13.112.0 - 71.13.119.255Charter Communications CC04 (NET-71-8-0-0-1) 71.8.0.0 - 71.15.255.255

CONTINENTAL BROADBAND PENNSYLVANIA, INC. - HACKER

There's a hacker at this location attempting to access our sites with ColdFusion:

OrgName: CONTINENTAL BROADBAND PENNSYLVANIA, INC. OrgID: CBP-17Address: 810 Parish StCity: PittsburghStateProv: PAPostalCode: 15220Country: USNetRange: 208.40.128.0 - 208.40.207.255

IP Address: 208.40.131.148

New Horizons - Major Hacking

We are getting major hacking from this network on this IP: 205.247.203.14

OrgName: New Horizons OrgID: NEWHOR-1Address: 1231 E Dyer Rd, Ste 140City: Santa AnaStateProv: CAPostalCode: 92705Country: USNetRange: 205.247.203.0 - 205.247.203.255

They have requestsed PHP admin pages in over 200 sessions this month so far alone.

Saturday, June 16, 2007

Another Hacker - CenturyTel

This appears also to be someone hacking: 69.179.76.130 at CentryTel in Louisiana at 6/13/2007 12:55:48 PM.

Hacker - Comcast in Miami

Someone on Comcast in Miami at this IP address: 76.109.211.88 was attempting to hack our e-commerce sites by passing invalid data to our application and causing a null pointer exception. The issue has been fixed. I hope someone will monitor the activities of the user of this IP address at 6/15/2007 3:14:59 PM

Thursday, June 14, 2007

Botnets - Scourge of the Internet

SWEET. Finally big companies and the governement are honing in on this issue. It is about time and I am so happy to hear it:

http://www.networkworld.com/news/2007/061307-fbi-operation-bot-roast.html?nlhtsec=0611securityalert4

Since starting to uncover the network patterns of spam about 3 years ago when I got sick of 950 spam emails per day I have been sending out messages about how these attacks are coordinated and coming from the servers of large companies...and since then the problem has only gotten worse.

One of my biggest reasons for writing this blog was to get someone - anyone - to take notice of the underlying Internet traffic - good and bad - and do something about it. I got sick of network admins throwing up their hands and telling me I was full of it when my server was hacked or that there was nothing that can be done about it...

This is exactly what we need. We need big businesses involved and the government and even better yet, we need large hosting facilities to analyze their traffic on an anonymous but global basis to determine traffic patterns that are obviously bots and illegal activities.

This is a long awaited happy day...

Thursday, June 07, 2007

National Vulnerability Database

Here's a database of products and their vulnerabilities:

http://nvd.nist.gov/viewvpv.cfm?complete=no&vendor=yes&product=yes&version=no&vendorchar=Omniture

This can be useful when researching whether or not you want to use a particular product - how many times has it been hacked?

Omniture Vulnerabilities

Related to my last two Omniture posts I did a little research on Omniture related vulnerabilities and hacks - this is what I found:

http://securitytracker.com/alerts/2006/Dec/1017392.html

http://nvd.nist.gov/nvd.cfm?cvename=CVE-2006-6640

http://securitytracker.com/alerts/2006/Dec/1017392.html

Vulnerability using .gif files

I was talking to my boss about the possibility of an Omniture hack:

http://randominternet.blogspot.com/2007/06/omniture-hacking-again.html

He stated that he's reviewed the code and all they are doing is downloading gif files, and that Omniture is used by large sites like CNN, Amazon and Sun. (Implication: if they use it it must be secure).

My response was: that makes them a great target. Look at the pot of gold at the other end of the rainbow. There are huge user bases for these sites plus people testing and reviewing the code at these companies behind firewalls...

So anyway I said what if the execution of malicious code is in the gif files, not in the JavaScript itself? And my boss says no, they are just simple gif files.

So I thought well, I've seen hacks in image files before let's see what's out there. And I found this:
___________

http://vil.nai.com/vil/Content/v_vul26549.htm

http://www.microsoft.com/technet/security/advisory/912840.mspx

Microsoft Office Remote Code Execution Using a Malformed GIF Vulnerability - CVE-2006-1540A remote code execution vulnerability exists in Office using a GIF file. An attacker could exploit the vulnerability by constructing a specially crafted Office file that could allow remote code execution. If a user is logged on with administrative user rights, an attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less affected than users who operate with administrative user rights.
________

And guess what. If someone could get this onto the Sun web site, that is where everyone goes to download Java - on servers that run e-commerce web sites, application servers, etc. You get the picture.

I have no idea how to test this theory. Maybe someone out there can just verify nothing funky is going on...

Tuesday, June 05, 2007

The problem with your VPN

So you set up a user and you say OK, you can do stuff on the VPN that you cannot do when you're not on the VPN and that makes my server that you are remoting into secure.

Right.

Talking to a firewall administrator today at Datapipe here's how your Cisco Pix really works:

Someone logs into the VPN and gets onto the server. From there they have free reign to do anything your outbound port access allows them to do. If they can get onto the server, they can send all your data to whatever server they want outside that server if your outbound access includes FTP. Apparently if you want to restrict downloading FTP to anyone but, say, and administrative VPN user - you can't do that at the firewall level.

And it also means if you want to allow customers to upload photos, for instance, but not download data, and make their access more secure so only VPN users can upload files, that's not completely solved by a VPN.

Which means you have to count on software - your OS, your applications... and you have to manage via a Windows domain or manage each individual server and cannot globally handle these things at the network level.

And that's scary.

Monday, June 04, 2007

First Data Better Check How Internet Requests are Handled

I sent an email to First Data via their web site with some specific technical questions about processing cards over their platform(s) and integration with certain types of transactions and hardware.

Some fast talking woman just called me who either had no comprehension of my request or she sniped the information somehow from the FirstData database. She was speaking very quickly and told me she was with Express Merchant blah blah blah or something like that. She told me this is some part of First Data. Maybe it is but it is but the way this request was handled was completely innapropriate.

First she asked me if I already have a processor. In my request I stated specific information that would have answered that question. It was pretty clear that she was about to try to sell me something and that is not why I requested information from First Data. Secondly when I said that is not what I requested she said "what was your request?" Excuse me but shouldn't you have the customer's request in front of you when you are calling them to answer the questions in their request?

Basically I already got the information through other means. I had to call First Data and sit on hold forever and talk to five different departments. I had to call my software gateway and go through 3 different people over there to get partial answers. I had in depth conversations with my bank who clearly knows very little how any of this works. Then I called an equipment manufacturer of terminals for their side of the story. They clearly didn't have the big picture either. I was able to piece together the information step by step and probably have a 95% grasp of what I need to know to implement a secure solution for my client - however no thanks to First Data's convoluted phone system or uninformed phone operators, sales people, and technical staff. This is nothing against the people themselves as they are all just doing their job the way they were trained to do it. There is a lack of global understanding in the credit card industry which makes it easier for hackers and harder and more expensive for customers to get things done.

Saturday, June 02, 2007

Wrong Country? DODO

This Ip range lists a country of AP but the contact information is for AU

inetnum: 122.148.0.0 - 122.149.255.255netname: DODO-AUdescr: Layer 2 Broadband Customer Networkcountry: APadmin-c: PR93-APtech-c: PR93-APstatus: ALLOCATED PORTABLEmnt-by: APNIC-HMremarks: Send abuse reports toremarks: abuse@dodo.com.auperson: Paul Rivoliaddress: Dodo Australia Pty Ltdaddress: Level 14 / 600 St Kilda Rdaddress: Melbourneaddress: VIC 3004country: AU

Thursday, May 31, 2007

Omniture Snooping?

Someone was snooping around my local network again. When I took a look there were 3 connections to Google which seemed ok, a connection to a Belgium electronic publishing company which might be ok since I was connected to a technical article, and a connection out on port 80 to Omniture in this IP range:

Omniture TRFR-ORM-UT-OMNITURE-4 (NET-216-194-125-0-1) 216.194.125.0 - 216.194.125.255

The thing is - I never connected to Omniture. The other weird thing is, the company I am working for at the moment is using Ominture. A random internet connection?

regencypacificinc.com surfing the web?

It seems that this web server is surfing the web...
63.236.119.29 resolves to"regencypacificinc.com"
Top Level Domain: "regencypacificinc.com"

Amazon + Nutch again...

Amazon was visiting our sites with Nutch again today.

Amazon scanning my machine again

Why is someone at Amazon scanning my machine with Nutch?

72.44.62.122

ilial/Nutch-0.9 (Ilial, Inc. is a Los Angeles based Internet startup company. For more information please visit http://www.ilial.com/crawler; http://w

OrgName: Amazon.com, Inc.
OrgID: AMAZO-4
Address: Amazon Development Centre South AFrica
Address: 1200 12th Avenue South
City: Seattle
StateProv: WA
PostalCode: 98144
Country: US
NetRange: 72.44.32.0 - 72.44.63.255

Korea Hackers - again

Korea is always a major source of spam and hacking for us.

Today we were bombed by this IP: 222.122.151.181

Looking for PHP hacks.

Wednesday, May 30, 2007

Hmm. ftp.grede.com hacked?

This IP was surfing our web site...

12.34.44.226 resolves to"ftp.grede.com"
Top Level Domain: "grede.com"

Tuesday, May 29, 2007

Google Copied Me

Google copied me. Well they have a bit more resources and some interesting stuff.

http://www.eweek.com/article2/0,1895,2135462,00.asp

http://googleonlinesecurity.blogspot.com/

Monday, May 28, 2007

Hacker activity from 81.223.153.134

inetnum: 81.223.153.128 - 81.223.153.143netname: Technix-Internetdescr:descr: Technix InternetServices GmbHdescr: Wilhelm Pfeiferdescr: Wiencountry: AT

What is YPC 3.2.0

I am finding this in my logs but cannot figure out what it is in a brief web search. Hopefully someone will post some information about it.

serverpronto hacker

Here's a hacker that is blatantly attempting to bypass our bot checking software:

69.60.115.127

Infolink Information Services Inc. INFOLINK-BLK-101 (NET-69-60-96-0-1) 69.60.96.0 - 69.60.127.255Serverpronto INMM-69-60-114-0 (NET-69-60-114-0-1) 69.60.114.0 - 69.60.125.255

In fact you may want to block out all of these:

Serverpronto INMM-69-60-114-0 (NET-69-60-114-0-1) 69.60.114.0 - 69.60.125.255
Serverpronto INMM-69-60-126-0 (NET-69-60-126-0-1) 69.60.126.0 - 69.60.126.255Serverpronto INMM-64-251-14-0 (NET-64-251-14-0-1) 64.251.14.0 - 64.251.14.255Serverpronto INMM-64-251-22-0 (NET-64-251-22-0-1) 64.251.22.0 - 64.251.22.255
Serverpronto INMM-69-60-127-96 (NET-69-60-127-96-1) 69.60.127.96 - 69.60.127.111ServerPronto INMM-64-251-30-0 (NET-64-251-30-0-1) 64.251.30.0 - 64.251.31.255ServerPronto INMM-64-251-25-0 (NET-64-251-25-0-1) 64.251.25.0 - 64.251.25.255ServerPronto INMM-64-251-1-64 (NET-64-251-1-64-1) 64.251.1.64 - 64.251.1.71ServerPronto INMM-69-60-97-64 (NET-69-60-97-64-1) 69.60.97.64 - 69.60.97.71ServerPronto INMM-69-60-110-0 (NET-69-60-110-0-1) 69.60.110.0 - 69.60.110.255ServerPronto INMM-69-60-111-0 (NET-69-60-111-0-1) 69.60.111.0 - 69.60.111.255ServerPronto INMM-64-251-27-0 (NET-64-251-27-0-1) 64.251.27.0 - 64.251.27.255ServerPronto INMM-69-60-109-0 (NET-69-60-109-0-1) 69.60.109.0 - 69.60.109.255Serverpronto INMM-64-251-10-0 (NET-64-251-10-0-1) 64.251.10.0 - 64.251.10.255Serverpronto INMM-69-60-113-0 (NET-69-60-113-0-1) 69.60.113.0 - 69.60.113.255Serverpronto Shared Firewall INMM-64-251-8-0 (NET-64-251-8-0-1) 64.251.8.0 - 64.251.8.255

Thursday, May 24, 2007

Name Intelligence - Bombing our Sites

Some group called Name Itelligence was boming our sites today.

Not to mention that, some code I clearly changed last night was somehow magically reverted by this morning. I am 100% positive someone hacked both my laptop and my server. It doesn't make any sense. I don't know if this bombing by Name Intelligence is related.

OrgName: Compass Communications, Inc. OrgID: CPCMAddress: 2001 6th AvenueAddress: Suite 3205City: SeattleStateProv: WAPostalCode: 98121Country: USNetRange: 64.246.160.0 - 64.246.191.255

Tuesday, May 22, 2007

Related Hacker IPs

There is a good chance that some or all of these IPs are all related hacker IPs (though very possible some are unrelated random internet connections). The reason I say possibly is because all these IPs were blocked by our system in fairly small window:

206.196.111.201
207.8.173.133
66.36.230.11
198.173.15.250
58.61.164.138
209.164.47.89
68.178.25.149
219.72.117.14
206.196.111.201

Sunday, May 20, 2007

Internet Factory - Spain - Looking for a Hack

This IP address: 84.78.106.131

From this network:

inetnum: 84.78.0.0 - 84.79.255.255netname: YACOMNETdescr:descr: Ya.com Internet Factorycountry: es

Was searching Google for the java package that runs our web site.

Log Files Deleted

Someone deleted the log file for web sites yesterday. At least the out-of-the-box log.

Meaning they hacked my web server and were able to edit the contents of a file.

It was most likely one of these IPs - and since it appears an Australian travel related web site was also altered.

67.161.123.184 27 Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.8.1.3) Gecko/20070309 Firefox/2.0.0.3
66.52.219.150 26 Mozilla/4.0 (compatible; MSIE 6.0; Windows 98)
202.172.121.86 21 Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.8.1.1) Gecko/20061204 Firefox/2.0.0.1
70.16.86.239 21 Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0; SLCC1; .NET CLR 2.0.50727; Media Center PC 5.0; .NET CLR 3.0.04506)
219.95.201.157 15 Mozilla/5.0 (Macintosh; U; PPC Mac OS X; en) AppleWebKit/419 (KHTML, like Gecko) Safari/419.3
64.211.119.111 15 Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 1.1.4322; .NET CLR 2.0.50727)
58.109.25.142 15 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; OptusNetDSL6; FunWebProducts; .NET CLR 1.1.4322)
24.18.133.12 14 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.0.3705; .NET CLR 1.1.4322; .NET CLR 2.0.50727)
125.63.220.160 12 Mozilla/5.0 (Macintosh; U; Intel Mac OS X; fr; rv:1.8.0.11) Gecko/20070312 Firefox/1.5.0.11
24.19.27.54 12 Mozilla/5.0 (Macintosh; U; PPC Mac OS X; en) AppleWebKit/419 (KHTML, like Gecko) Safari/419.3
71.197.234.132 12 Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.8.1.3) Gecko/20070309 Firefox/2.0.0.3
121.72.139.254 11 Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.8.1.3) Gecko/20070309 Firefox/2.0.0.3
72.86.23.190 10 Mozilla/5.0 (X11; U; Linux i686; en-US; rv:1.8.0.10) Gecko/20070226 Ubuntu/breezy-security Firefox/1.5.0.10
134.7.248.129 10 Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.8.1.3) Gecko/20070309 Firefox/2.0.0.3
66.212.64.234 9 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
207.225.232.131 9 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
24.18.137.119 9 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
151.41.76.15 8 Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 1.1.4322; .NET CLR 2.0.50727; InfoPath.1; MEGAUPLOAD 1.0; Mozilla/4.0 (compatible ; MSIE 6
60.234.112.149 8 Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1)
71.231.143.8 8 Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1)
67.53.216.17 7 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322; .NET CLR 2.0.50727; InfoPath.1)
207.190.85.11 7 Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.8.1) Gecko/20061010 Firefox/2.0
12.144.142.180 7 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.0.3705)
63.83.102.35 7 Mozilla/5.0 (Macintosh; U; PPC Mac OS X; en) AppleWebKit/419 (KHTML, like Gecko) Safari/419.3
71.231.138.109 7 Mozilla/5.0 (Macintosh; U; Intel Mac OS X; en) AppleWebKit/419 (KHTML, like Gecko) Safari/419.3
87.112.66.170 7 Mozilla/5.0 (Macintosh; U; Intel Mac OS X; en) AppleWebKit/419 (KHTML, like Gecko) Safari/419.3
71.227.163.15 6 Mozilla/5.0 (Macintosh; U; PPC Mac OS X; en) AppleWebKit/312.8.1 (KHTML, like Gecko) Safari/312.6
142.167.197.76 6 Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 1.1.4322)
203.33.161.17 6 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
216.41.121.23 6 Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 1.1.4322)
24.22.183.61 6 Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727)
67.168.63.44 6 Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.8.0.11) Gecko/20070312 Firefox/1.5.0.11
71.35.174.30 6 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
71.251.36.71 5 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
76.104.198.212 5 Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.8.0.11) Gecko/20070312 Firefox/1.5.0.11
76.230.211.202 5 Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 1.0.3705; .NET CLR 1.1.4322; Media Center PC 3.1)
86.31.17.9 5 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
71.0.106.22 5 Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 1.1.4322)
71.161.6.228 5 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.0.3705; .NET CLR 1.1.4322; Media Center PC 4.0; .NET CLR 2.0.50727)
205.250.69.54 5 Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 1.1.4322)
12.210.86.95 5 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
58.168.241.202 5 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
66.174.92.162 5 Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; (R1 1.5); .NET CLR 1.1.4322)
67.171.26.65 5 Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 1.1.4322)
71.212.51.10 5 Mozilla/5.0 (Macintosh; U; PPC Mac OS X; en-us) AppleWebKit/419 (KHTML, like Gecko) Safari/419.3
71.212.77.45 4 Mozilla/5.0 (Macintosh; U; Intel Mac OS X; en) AppleWebKit/417.9 (KHTML, like Gecko) Safari/417.8
71.197.194.249 4 Mozilla/5.0 (Macintosh; U; Intel Mac OS X; en) AppleWebKit/419 (KHTML, like Gecko) Safari/419.3
71.112.216.207 4 Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 1.1.4322; .NET CLR 2.0.50727; .NET CLR 3.0.04506.30)
71.227.163.15 4 Mozilla/5.0 (Macintosh; U; PPC Mac OS X; en) AppleWebKit/419 (KHTML, like Gecko) Safari/419.3
71.212.92.77 4 Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 1.1.4322; MSN 9.0;MSN 9.1; MSNbQ002; MSNmen-us; MSNcIA)
71.231.217.113 4 Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 1.0.3705; .NET CLR 1.1.4322; Media Center PC 4.0)
71.231.114.187 4 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322; .NET CLR 2.0.50727)
67.171.29.83 4 Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 1.1.4322; .NET CLR 2.0.50727)
67.161.103.218 4 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
24.19.34.168 4 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; Avant Browser; Avant Browser; .NET CLR 1.1.4322; SpamBlockerUtility 4.8.0)
144.138.23.33 4 Mozilla/5.0 (Macintosh; U; PPC Mac OS X; en) AppleWebKit/125.2 (KHTML, like Gecko) Safari/125.7
206.196.111.201 4 metatagsdir/0.7 (+http://metatagsdir.com/directory/)
24.12.249.238 4 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.0.3705; .NET CLR 1.1.4322; Media Center PC 4.0)
24.19.50.158 4 Mozilla/5.0 (Macintosh; U; PPC Mac OS X; en) AppleWebKit/412.6 (KHTML, like Gecko) Safari/412.2
82.34.178.59 4 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
71.231.0.99 4 Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 1.1.4322; .NET CLR 2.0.50727)
71.217.78.77 3 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.0.3705; .NET CLR 1.1.4322; Media Center PC 4.0)
71.35.156.246 3 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; Boeing Kit; .NET CLR 1.1.4322; .NET CLR 2.0.50727)
76.22.52.12 3 Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.8.1.3) Gecko/20070309 Firefox/2.0.0.3
64.231.181.163 3 Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1)
67.170.102.9 3 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
70.90.186.25 3 Mozilla/5.0 (Macintosh; U; PPC Mac OS X Mach-O; en-US; rv:1.8.1.3) Gecko/20070309 Firefox/2.0.0.3
66.231.189.97 3 Gigabot/2.0 (http://www.gigablast.com/spider.html)
24.19.23.36 3 Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.8.0.11) Gecko/20070312 Firefox/1.5.0.11
24.19.242.5 3 Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.8.0.11) Gecko/20070312 Firefox/1.5.0.11
193.72.33.241 3 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
124.190.88.237 3 Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; FunWebProducts; InfoPath.1; .NET CLR 1.1.4322; .NET CLR 2.0.50727)
12.72.243.70 3 Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.7.6) Gecko/20050317 Firefox/1.0.2
24.16.59.122 3 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
65.102.190.68 3 Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0; SLCC1; .NET CLR 2.0.50727; Media Center PC 5.0; .NET CLR 3.0.04506)
71.231.115.2 3 Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.4) Gecko/20030624 Netscape/7.1 (ax)
71.121.251.187 3 Mozilla/5.0 (Macintosh; U; Intel Mac OS X; en) AppleWebKit/418.8 (KHTML, like Gecko) Safari/419.3
71.212.81.129 3 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.0.3705)
71.196.174.73 2 Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 1.0.3705; .NET CLR 1.1.4322; Media Center PC 4.0)
70.85.114.58 2 Pingdom GIGRIB (http://www.pingdom.com)
68.44.194.30 2 Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1)
69.156.172.6 2 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0)
69.255.17.229 2 Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.8.1.3) Gecko/20070309 Firefox/2.0.0.3
69.37.76.105 2 Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.7.5) Gecko/20060912 Netscape/8.1.2
76.106.5.101 2 Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.8.1.3) Gecko/20070309 Firefox/2.0.0.3
90.242.30.160 2 Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 1.1.4322)
65.222.176.122 2 Mozilla/4.0 (compatible; MSIE 6.0; Windows XP)
64.124.85.71 2 Mozilla/5.0 (compatible; BecomeBot/3.0; +http://www.become.com/site_owners.html)
24.17.245.143 2 Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 1.1.4322; Windows-Media-Player/10.00.00.3990)
66.235.51.160 2 Mozilla/5.0 (Macintosh; U; Intel Mac OS X; en-US; rv:1.8.1.3) Gecko/20070309 Firefox/2.0.0.3
67.168.95.2 2 Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.8.1.3) Gecko/20070309 Firefox/2.0.0.3
68.230.5.189 2 Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.8.1.3) Gecko/20070309 Firefox/2.0.0.3
134.7.206.157 2 Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.8.1.3) Gecko/20070309 Firefox/2.0.0.3
152.163.100.209 2 Mozilla/4.0 (compatible; MSIE 6.0; AOL 9.0; Windows NT 5.1; .NET CLR 1.1.4322)
192.85.47.2 2 Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 1.1.4322)
207.200.116.139 2 Mozilla/4.0 (compatible; MSIE 7.0; AOL 9.0; Windows NT 5.1; .NET CLR 1.1.4322)
216.82.171.6 2 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
219.206.88.11 2 Mozilla/5.0 (Windows; U; Windows NT 5.1; ja; rv:1.8.1.3) Gecko/20070309 Firefox/2.0.0.3
193.35.129.161 2 Opera/9.10 (Windows NT 5.1; U; en)
12.210.182.93 2 Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.8.0.11) Gecko/20070312 Firefox/1.5.0.11
203.109.206.194 2 Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 1.1.4322)
200.122.64.108 2 Mozilla/5.0 (Macintosh; U; PPC Mac OS X; en) AppleWebKit/419 (KHTML, like Gecko) Safari/419.3
212.227.83.83 2
207.200.116.132 2 Mozilla/4.0 (compatible; MSIE 7.0; AOL 9.0; Windows NT 5.1; .NET CLR 1.1.4322)
207.200.116.73 2 Mozilla/4.0 (compatible; MSIE 7.0; AOL 9.0; Windows NT 5.1; .NET CLR 1.1.4322)
209.53.232.173 2 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 2.0.50727)
24.18.41.26 2 Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.8.1.3) Gecko/20070309 Firefox/2.0.0.3
67.161.125.135 2 Mozilla/5.0 (Macintosh; U; PPC Mac OS X; en) AppleWebKit/419 (KHTML, like Gecko) Safari/419.3
71.121.152.254 2 Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 1.1.4322)
65.222.176.125 2 Mozilla/4.0 (compatible; MSIE 6.0; Windows XP)
84.78.106.131 2 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.0.3705; .NET CLR 1.1.4322; Media Center PC 4.0; .NET CLR 2.0.50727)
71.231.200.201 2 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; SLCC1; .NET CLR 2.0.50727; Media Center PC 5.0; .NET CLR 3.0.04506; .NET CLR 1.1.4322; InfoPat
71.35.141.83 2 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; Avant Browser; Avant Browser)
75.92.145.57 1 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322; .NET CLR 2.0.50727)
71.37.27.123 1 Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.8.1.3) Gecko/20070309 Firefox/2.0.0.3
72.179.227.82 1 Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.8.1.3) Gecko/20070309 Firefox/2.0.0.3
72.254.55.39 1 Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 2.0.50727; .NET CLR 1.1.4322; .NET CLR 3.0.04506.30)
71.240.229.185 1 Mozilla/5.0 (Macintosh; U; PPC Mac OS X; en) AppleWebKit/312.8.1 (KHTML, like Gecko) Safari/312.6
71.231.141.255 1 Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0; SLCC1; .NET CLR 2.0.50727; Media Center PC 5.0; .NET CLR 3.0.04506)
71.212.71.48 1 Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0; SLCC1; .NET CLR 2.0.50727; .NET CLR 3.0.04506)
80.254.152.84 1 Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.7.12) Gecko/20050915 Firefox/1.0.7
81.52.143.16 1 Mozilla/5.0 (Windows; U; Windows NT 5.1; fr; rv:1.8.1) VoilaBot BETA 1.2 (http://www.voila.com/)
76.205.101.176 1 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
66.180.82.87 1 Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727)
66.231.188.133 1 Gigabot/2.0 (http://www.gigablast.com/spider.html)
64.235.108.248 1 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; .NET CLR 1.1.4322)
65.214.39.180 1 Mozilla/5.0 (X11; U; Linux i686; en-US; rv:1.9a1) Gecko/20070308 Minefield/3.0a1
24.22.209.95 1 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322; .NET CLR 2.0.50727)
24.22.218.197 1 Mozilla/5.0 (Macintosh; U; PPC Mac OS X Mach-O; en-US; rv:1.8) Gecko/20051111 Firefox/1.5
60.191.80.224 1 Mozilla/5.0 (compatible; YodaoBot/1.0; http://www.yodao.com/help/webmaster/spider/; )
62.194.15.193 1 Mozilla/4.0 (compatible; MSIE 6.0; Windows 98)
64.12.116.19 1 Mozilla/4.0 (compatible; MSIE 6.0; AOL 9.0; Windows NT 5.1; SV1; .NET CLR 1.0.3705)
64.12.116.5 1 Mozilla/4.0 (compatible; MSIE 7.0; AOL 9.0; Windows NT 5.1; .NET CLR 1.0.3705; .NET CLR 1.1.4322; Media Center PC 4.0)
64.124.85.76 1 Mozilla/5.0 (compatible; BecomeBot/3.0; +http://www.become.com/site_owners.html)
64.124.85.77 1 Mozilla/5.0 (compatible; BecomeBot/3.0; +http://www.become.com/site_owners.html)
71.13.115.117 1 bot/1.0 (bot; http://; bot@bot.bot)
71.102.99.173 1 Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 1.1.4322; .NET CLR 2.0.50727)
71.168.130.247 1 Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 1.1.4322)
71.172.236.42 1 Mozilla/5.0 (Macintosh; U; PPC Mac OS X; en) AppleWebKit/419 (KHTML, like Gecko) Safari/419.3
71.197.164.190 1 Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; FunWebProducts; .NET CLR 1.1.4322; InfoPath.1)
66.249.85.85 1 Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.8.1.3) Gecko/20070309 Firefox/2.0.0.3
66.36.230.11 1
67.40.25.45 1 Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 1.0.3705; .NET CLR 1.1.4322; Media Center PC 4.0)
210.82.118.14 1 favorstarbot/1.0 (+http://favorstar.com/bot.html)
207.200.116.200 1 Mozilla/4.0 (compatible; MSIE 7.0; AOL 9.0; Windows NT 5.1; .NET CLR 1.1.4322)
216.131.91.205 1
24.11.108.250 1 Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
24.174.106.137 1 Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 1.1.4322; InfoPath.1)
24.18.137.235 1 Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 1.1.4322)
24.18.230.83 1 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
24.18.246.181 1 Mozilla/5.0 (Macintosh; U; Intel Mac OS X; en) AppleWebKit/419 (KHTML, like Gecko) Safari/419.3
24.18.246.185 1 Mozilla/5.0 (Macintosh; U; Intel Mac OS X; en-US; rv:1.8.1.3) Gecko/20070309 Firefox/2.0.0.3
207.200.116.12 1 Mozilla/4.0 (compatible; MSIE 7.0; AOL 9.0; Windows NT 5.1; .NET CLR 1.1.4322)
203.76.128.203 1 Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.8.1.3) Gecko/20070309 Firefox/2.0.0.3
195.4.221.251 1 Mozilla/5.0 (Windows; U; Windows NT 5.1; de; rv:1.8.1.2) Gecko/20070219 Firefox/2.0.0.2
12.144.142.180 1 Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 1.1.4322; .NET CLR 2.0.50727)
152.163.100.76 1 Mozilla/4.0 (compatible; MSIE 6.0; AOL 9.0; Windows NT 5.1; .NET CLR 1.1.4322)
159.226.26.99 1 Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 1.1.4322)
18.194.1.206 1 Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.8.0.11) Gecko/20070312 Firefox/1.5.0.11
193.227.227.54 1 nsjmfiurhgrkisulbfmixiholgk ecylus6oi
24.115.225.223 1 Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 1.0.3705; .NET CLR 1.1.4322; Media Center PC 4.0)
24.136.66.146 1 Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 1.1.4322)
24.16.23.32 1 Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 1.1.4322)
204.130.228.90 1 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
206.183.1.74 1 Mozilla/4.0 (compatible; T-H-U-N-D-E-R-S-T-O-N-E)
216.160.92.13 1 Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0; SLCC1; .NET CLR 2.0.50727; Media Center PC 5.0; .NET CLR 3.0.04506; .NET CLR 1.1.4322)
207.200.116.202 1 Mozilla/4.0 (compatible; MSIE 7.0; AOL 9.0; Windows NT 5.1; .NET CLR 1.1.4322)
207.200.116.8 1 Mozilla/4.0 (compatible; MSIE 7.0; AOL 9.0; Windows NT 5.1; .NET CLR 1.1.4322)
207.200.116.9 1 Mozilla/4.0 (compatible; MSIE 7.0; AOL 9.0; Windows NT 5.1; .NET CLR 1.1.4322)
207.216.51.61 1 Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 1.0.3705; Media Center PC 4.0; .NET CLR 2.0.50727; .NET CLR 3.0.04506.30; InfoPath.1)
206.80.1.253 1 Mozilla/5.0 (X11; U; Linux i686; en-US; rv:1.9a1) Gecko/20070308 Minefield/3.0a1
207.115.68.99 1 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
207.200.116.137 1 Mozilla/4.0 (compatible; MSIE 7.0; AOL 9.0; Windows NT 5.1; .NET CLR 1.1.4322)
193.35.129.169 1 Opera/9.10 (Windows NT 5.1; U; en)
193.95.154.69 1 Mozilla/5.0 (X11; U; Linux i686; en-US; rv:1.9a1) Gecko/20070308 Minefield/3.0a1
195.60.64.5 1 Mozilla/5.0 (Windows; U; Windows NT 5.1; pl; rv:1.8.1.3) Gecko/20070309 Firefox/2.0.0.3
202.191.106.20 1 Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1)
203.220.203.253 1 Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.7.5) Gecko/20041217
159.226.26.98 1 Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 1.1.4322)
190.42.83.216 1 Mozilla/5.0 (X11; U; Linux i686; en-US; rv:1.8.1.3) Gecko/20061201 Firefox/2.0.0.3 (Ubuntu-feisty)
142.68.80.30 1 Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; Hotbar 4.5.0.0; .NET CLR 2.0.50727; .NET CLR 1.1.4322)
144.132.94.218 1 Xenu Link Sleuth 1.2i
125.253.35.241 1 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
68.32.23.202 1 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
67.183.147.21 1 Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 1.0.3705; .NET CLR 1.1.4322; Media Center PC 4.0; .NET CLR 2.0.50727; .NET CLR 3.0.04506.3
67.183.220.214 1 Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 1.1.4322)
67.184.3.163 1 Mozilla/5.0 (Windows; U; Windows NT 6.0; en-US; rv:1.8.1.3) Gecko/20070309 Firefox/2.0.0.3
66.24.105.4 1 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
66.194.6.68 1 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; Q312469)
64.27.29.45 1 Mozilla/4.0 (compatible ; MSIE 6.0; Windows NT 5.1)
24.18.186.147 1 Mozilla/5.0 (Macintosh; U; Intel Mac OS X; en) AppleWebKit/419 (KHTML, like Gecko) Safari/419.3
24.18.241.84 1 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; (R1 1.5); .NET CLR 1.0.3705; .NET CLR 1.1.4322; Media Center PC 4.0; .NET CLR 2.0.50727)
24.20.208.213 1 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.0.3705; .NET CLR 1.1.4322; Media Center PC 3.1)
64.124.85.73 1 Mozilla/5.0 (compatible; BecomeBot/3.0; +http://www.become.com/site_owners.html)
64.124.85.79 1 Mozilla/5.0 (compatible; BecomeBot/3.0; +http://www.become.com/site_owners.html)
64.12.117.5 1 Mozilla/4.0 (compatible; MSIE 7.0; AOL 9.0; Windows NT 5.1; .NET CLR 1.0.3705; .NET CLR 1.1.4322; Media Center PC 4.0)
65.222.176.123 1 Mozilla/4.0 (compatible; MSIE 6.0; Windows XP)
65.243.153.100 1 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
81.219.27.49 1 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 2.0.50727; .NET CLR 1.1.4322)
82.154.42.127 1 Mozilla/5.0 (Windows; U; Windows NT 5.1; pt-BR; rv:1.8.1.3) Gecko/20070309 Firefox/2.0.0.3
83.116.238.30 1 Mozilla/5.0 (Windows; U; Windows NT 5.1; nl; rv:1.8.1.3) Gecko/20070309 Firefox/2.0.0.3
89.180.32.129 1 Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 1.1.4322; .NET CLR 2.0.50727; InfoPath.1)
71.97.249.48 1 Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 1.1.4322; IEMB3; InfoPath.1; IEMB3)
72.79.234.67 1 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
72.88.201.176 1 Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 1.1.4322)
71.216.15.25 1 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
71.217.106.179 1 Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 1.1.4322)
71.227.164.19 1 Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 1.1.4322)
69.91.157.132 1 Mozilla/5.0 (Macintosh; U; Intel Mac OS X; en-US; rv:1.8.0.11) Gecko/20070312 Firefox/1.5.0.11
70.215.92.151 1 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
70.83.131.206 1 Mozilla/5.0 (X11; U; Linux i686; en-US; rv:1.8.1.3) Gecko/20061201 Firefox/2.0.0.3 (Ubuntu-feisty)
69.29.198.44 1 Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 1.1.4322)
68.84.228.60 1 Mozilla/5.0 (Macintosh; U; Intel Mac OS X; en) AppleWebKit/419 (KHTML, like Gecko) Safari/419.3
71.101.61.14 1 Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; .NET CLR 1.0.3705; .NET CLR 1.1.4322; Media Center PC 4.0)
71.197.235.80 1 Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)

Sunday, May 13, 2007

Naval Surface Warfare Center - connected to/from my laptop?

This is odd. I'm logged into a VPN to a remote server and suddenly my terminal services connection is locking up. I check IPs I am connected to and there's the Google Toolbar notifier so I shut it off. Then my machine seems to free up and I can move the mouse around on the remote server again. But I think that was a coincidence. Shortly thereafter lock up again on my administrator account on the remote machine via Terminal Services. Another look at the IPs my machine is connected to reveals a connection to two Naval Surface Warfare Center IPs on port 80. I have no reason to be connected to these IP addresses. As far as I know I am only connected to my own web server, through the web on port 80, and through a VPN so how the heck is my machine somehow connecting to the these addresses on port 80???

128.38.52.46 and 128.38.52.34

OrgName: Naval Surface Warfare Center OrgID: NSWC-1Address: 17320 Dahlgren RoadAddress: Code XDTCity: DahlgrenStateProv: VAPostalCode: 22448-5000Country: USNetRange: 128.38.0.0 - 128.38.255.255

Friday, May 11, 2007

Organized Crime and Hacking

This article says people are "wondering" if organized crime is involved in hacking.

http://www.networkworld.com/news/2007/050907-fbi-organized-crime-cybercrime.html?nlhtsec=0507securityalert5&

DUH. Obviously this person doesn't know much about what they are writing about.

What is organized crime anyway? Is it organized when someone has a bunch of command and control bots or when there is a whole row of computers in a hut in Nigeria working on money transfer schemes from stolen funds using people who fall for their ploys?

Maybe they only mean a certain type of organized crime - Mafia. Given that the Internet is the absolute easiest way to make a whole tone of money without killing anyone or counting on too many people to get the job done, I would venture to say that any smart criminal organization would be after that pot of gold.

But the flip side of that is the Internet is all about computers and data. Computers don't lie. If the data is tracked by a really smart programmer on the other side of the fence - the good guys will have the data they need to nab the crooks much faster than traditional walking the street and trying to find scared witnesses to testify who are afraid for their lives.

OK maybe I've been watching too many cops and robbers and lawyer movies lately. But I can totally see the possibilities here and it's pretty much been reported already that certain criminal and terrorist organizations are involved in Internet crimes.

Wednesday, May 09, 2007

Good and Bad File Security From Microsoft

Microsoft seems to have a policy where you can set high security on your computer and block files that came from another computer from running. To unblock you right click on the file and choose unblock and the file can run.

Great. But what about when you download and run a program from the Internet and it has a whole bunch of files required to run and you try to run the app and get cryptic error messages and have no idea what the problem is or which file to unblock even if you do know what the problem is...this is typical Microsoft. When you change settings in your OS it can cripple and even corrupt your OS at times if you change COM and DCOM settings the wrong way.

But even worse I cannot get my work done right now (and had to stop and gripe about it) because this lovely security mechanism has blocked me from uncompressing a zip file. So yeah I turned around and unblocked it - cool, right? Not cool. When I try to unzip it still doesn't work and I am guessing it is because all the files in the zip file came from another computer - and I cannot "unblock" them because they are in a zip file! If that is not the problem not sure what is.

So I like the concept but I don't like the implementation. It would be better to allow someone to see all the files that ran, have run and are running and click on something to see what program they are associated with, which user ran them, time, date, etc. Also it needs to be easy to globally turn on and off this blocking and include those intstructions with the instructions for unblocking a file.

Wednesday, May 02, 2007

Googlebot.com surfing for PHP files?

We got a hit for a php file we don't host. Turns out the IP resolves to googlebot.com. However the bot does not identify itself as Google in the user agent so it looks suspcious. But..when I go to googlebot.com in a browser...it goes to google. What is up with that?

Thursday, April 26, 2007

Keyloggers in Keyboards

Looks like keyloggers can be implanted in keyboards. Is that why my toshiba laptop keeps croaking? It somehow wants to always type extra letters.

http://www.networkworld.com/news/2006/080806-keyboard.html?nwwpkg=alphadoggs

For Starbucks and Tmobile - Hotspot Hacks

I don't think this is all that new. I typically am on a VPN at a hotpsot (though there have been times when I wondered if someone could still access my machine).

Anyway when will the day come that someone gets hacked at Starbucks and turns around and sues them. I don't know how that would work out. I don't know if there is anything Starbucks or Tmobile can do about this (just naming the big guys here) but they certainly should try.

http://www.networkworld.com/news/2007/042507-infosec-evil-twin-wi-fi-access.html?nlhtsec=0423securityalert4&company=HP

DNS Server Hacks

I don't know how many times I suggested that potentially DNS was hacked to various companies where weird things were happening....and they blew me off like I was nuts. Like there's no way DNS can be hacked. Right.

http://www.networkworld.com/news/2007/041307-dns-vulnerability.html?nlhtsec=0416securityalert1&company=Mu%20Security

The question is, what's the fastest way to pinpoint if your DNS server is hosed?

Tuesday, April 24, 2007

Related PHP hacker IPs

The following are related hacker hits trying to access PHP pages. These IPs are related as the hits all came at the same time.

"inetnum: 59.88.0.0 - 59.99.255.255
netname: BSNLNET
descr: NIB (National Internet Backbone)
descr: Bharat Sanchar Nigam Limited
descr: Sanchar Bhawan,20, Ashoka Road, New Delhi-110001
country: IN
" 299391 BLOCKED 9jdq30c0otrp Tue Apr 24 04:59:02 PDT 2007 59.94.208.172 /index.php Mozilla/5.0 (Windows; U; Windows NT 5.0; en-US; rv:1.3a) /index.php act=Reg&CODE=00 83 7 1 4/24/2007 4:59:03 AM 24 4 4/24/2007 4:59:03 AM
"inetnum: 59.88.0.0 - 59.99.255.255
netname: BSNLNET
descr: NIB (National Internet Backbone)
descr: Bharat Sanchar Nigam Limited
descr: Sanchar Bhawan,20, Ashoka Road, New Delhi-110001
country: IN
" 299391 BLOCKED 9jdq30c0otrp Tue Apr 24 04:59:02 PDT 2007 59.94.208.172 /index.php Mozilla/5.0 (Windows; U; Windows NT 5.0; en-US; rv:1.3a) /index.php act=Reg&CODE=00 83 7 1 4/24/2007 4:59:03 AM 24 4 4/24/2007 4:59:03 AM
"Comcast Cable Communications, Inc. ATT-COMCAST (NET-71-192-0-0-1)
71.192.0.0 - 71.207.255.255
Comcast Cable Communications, IP Services WASHINGTON-16 (NET-71-197-128-0-1)
71.197.128.0 - 71.197.255.255
" 299389 BLOCKED 3bghs2pqv3ms4 Tue Apr 24 04:58:56 PDT 2007 71.200.172.74 /index.php /index.php act=Reg&CODE=00 83 7 1 4/24/2007 4:58:56 AM 24 4 4/24/2007 4:58:56 AM
299388 BLOCKED 1cabokzq2eon9 Tue Apr 24 04:58:55 PDT 2007 200.140.12.1 /register.php Mozilla/5.0 (Windows; U; Windows NT 5.0; en-US; rv:1.3a) /register.php action=signup&who=adult 83 7 1 4/24/2007 4:58:56 AM 24 4 4/24/2007 4:58:56 AM
299387 BLOCKED 5bntk8b5n6k1t Tue Apr 24 04:58:52 PDT 2007 58.142.79.54 /register.php Mozilla/5.0 (Windows; U; Windows NT 5.0; en-US; rv:1.3a) /register.php action=signup&who=adult 83 7 1 4/24/2007 4:58:52 AM 24 4 4/24/2007 4:58:52 AM
299386 BLOCKED b2idleeknprcn Tue Apr 24 04:58:51 PDT 2007 201.12.150.239 /profile.php Mozilla/5.0 (Windows; U; Windows NT 5.0; en-US; rv:1.3a) /profile.php mode=register 83 7 1 4/24/2007 4:58:51 AM 24 4 4/24/2007 4:58:51 AM
299385 BLOCKED 5k5ov71rsp1qd Tue Apr 24 04:58:47 PDT 2007 203.223.150.95 /profile.php Mozilla/5.0 (Windows; U; Windows NT 5.0; en-US; rv:1.3a) /profile.php mode=register 83 7 1 4/24/2007 4:58:48 AM 24 4 4/24/2007 4:58:48 AM

University of Minnesota bot

We just got a whole slew of hits much too fast for a normal user from this network and IP:

134.29.227.130

OrgName: Minnesota State University System OrgID: MSUSAddress: Wells Fargo PlaceAddress: 30 7th Street East, Suite 350City: St. PaulStateProv: MNPostalCode: 55101-7804Country: USNetRange: 134.29.0.0 - 134.29.255.255

This was in the user agent - not sure if related: knst2007

I can find no references to this on Google except that it's showing up on web stats reports - specifically for a lot of Univerisities.

Monday, April 23, 2007

nflplayers.com surfing the web

This web server is visiting our web sites:

66.208.26.98 resolves to"nflplayers.com"
Top Level Domain: "nflplayers.com"

iibee.com browsing web sites

This IP address points to iibee.com and seems to be a computer used to surf the web. Is this a web server or someone trying to host a site from their basement? Why is it surfing the web?

216.194.68.120 resolves to"iibee.com"Top Level Domain: "iibee.com"

ap-art.com surging the web

Here's a web server that is being used to surf our web sites:

207.234.208.96 resolves to"ap-art.com"Top Level Domain: "ap-art.com"

liggins.plus.com - surfing the web?

Hmm, should this IP address be surging the web? Seems to have an interest in our web sites.

212.159.42.175 resolves to"liggins.plus.com"
Top Level Domain: "plus.com"

turbinegenerator.com surfing the web

This ip resolves to turbinegenerator.com - seems a web server is surfing the web.

209.34.233.62 resolves to"turbinegenerator.com"
Top Level Domain: "turbinegenerator.com"

proxyout.utah.gov

Why is this proxy server for the utah government surfing our web sites? Is this a typical configuration? It could be I'm not sure.

204.113.19.8 resolves to"proxyout.utah.gov"Top Level Domain: "utah.gov"

proxy2.xter.net

Proxy server surfing our web sites?

83.217.229.147 resolves to"proxy2.xter.net"
Top Level Domain: "xter.net"

knsk.de

Here's a web server surfing our web sites...

212.1.49.129 resolves to"knsk.de"
Top Level Domain: "knsk.de"

F5 wants to secure your apps with their network hardware

Here's an interesting approach to application security from F5 Networks using their Big IP device (which was insanely expensive last time I checked):

http://www.f5.com/solutions/technology/securing_enterprise_wp.html?CMP=KNC-GoogSiteNtwk&gclid=CLuEguDO2IsCFQQRYwodll4haw

The only issue I see here is more complicated application testing and debugging. It will be harder to pinpoint errors.

I haven't thought it totally through and it's late but seems like this is a network device and should focus on network issues.

The concept of what they are doing should be done by every application however and perhaps and application framework is best suited for these things. Perhaps you could use a combination but I worry about the maintenance consequences of this.

A web server surfing the web

63.144.222.2 resolves to"www.hardeecounty.net"
Top Level Domain: "hardeecounty.net"

Sunday, April 22, 2007

Inquent = hacked?

Working away here suddenly my printer started making noise for no apparent reason. I'm guessing someone got on my network or my machine here and they are snooping around and hit the device on that port / local IP.

I looked at IPs my machine is connected to and for no apparent reason it is connected to this IP:

205.178.145.1

InQuent Technologies Inc. INQUENT-2 (NET-205-178-128-0-1) 205.178.128.0 - 205.178.191.255Network Solutions, LLC NSLLC01 (NET-205-178-145-0-1) 205.178.145.0 - 205.178.145.255

Hmmm....hacked or?

Thursday, April 19, 2007

Microsoft DNS + RPC vulnerability

And if you didn't believe me that DNS can be hacked and send you to the wrong place (as suggested in the last post about an ebay web site issue) read this:

http://securitywatch.eweek.com/exploits_and_attacks/microsoft_urges_workaround_as_worm_hits_unpatched_dns_flaw.html?kc=EWEWEMNL041807EP38A

A flaw in or explotation of the implementation of the Microsoft DNS service plus RPC (remote procedure call) service is being abused.

JavaScript hacks

Here's an interesting article on JavaScript hacks. This would apply to people going to web sites that have the attacks in the code when you download the page and the inability of various virus, malware and spybot type software figuring out that the code is actually malicious.

http://www.eweek.com/article2/0,1895,2115638,00.asp?kc=EWEWEMNL041907EP38A

Ebay site problem

Ebay has a page where you can enter a whole bunch of information if you forget your password.

There is a whole host of sensitive information you have to enter on that page to get your password.

The page is only accessible via http.

Oh but they probably submit it via https you say.

So what. Let's say their DNS gets hacked someone and people set up a fake page at that address on the servers that are being rerouted to when you think you're at ebay. The only way to know you are really at ebay is hitting the page via https because the certificate applies to a specific server. Without that you can be rerouted and when you hit submit on this bogus link you just gave a hacker your secret question/answer (which you probably used in multiple places, right?), your birth date, place of birth, etc. etc.

Scary.

Wednesday, April 18, 2007

Encoding vs. Encryption

I was working on a site that encodes cookies today and I was wondering why they did that. I was thinking that "hey, encoding is not the same as encrypting...are they doing this for security reasons?" Then I started thinking about it a little more - the distinction between encrypting and encoding. I did a quick search which provided a nice document that I am giving kudos to for backing up my thoughts on the technically correct purposes of encode and encrypt.

http://www.di-mgt.com.au/encode_encrypt.html

Friday, April 13, 2007

195.10.45.155

Here's an interesting dns resolution. Hide? Hmm.

195.10.45.155 resolves to"hide-155.nhs.uk"
Top Level Domain: "nhs.uk"

Tuesday, April 10, 2007

A surfing hosting proxy server

This IP was surfing our web sites. Looks like something good to block.

203.97.46.29 resolves to"proxy.hosting.co.nz"
Top Level Domain: "co.nz"

Websherpas.com hacked?

Hmm, websherpas.com needs to consult a higher power to prevent their server from surfing the web. This server was sniffing around our web sites:

209.102.67.2 resolves to"www.websherpas.com"
Top Level Domain: "websherpas.com"

Romania, China, Russia...

Hmm, suddenly I am getting loads of hits from Romania, China and Russia. This after a recent article I posted suggested the US as the malware capital of the world and my suggestion that the actual source of this hacking is elsewhere. I also suggested segmenting your servers for different parts of the world and known hacker countries so that hacker sources are limited to hacking their own boxes and not the rest of the boxes used by countries in the world that are not such a high percentage of Internet theives, crooks, criminals and spies (though we all have some black sheep in our family).

212.20.253.212 resolves to"euro-hostels.co.uk"

This is another web server surfing our web site. Probably hackers or hacked.

212.20.253.212 resolves to"euro-hostels.co.uk"
Top Level Domain: "co.uk"

wmanet.org surfing our web site

Hmm. Another web server surfing our web site.

216.195.194.210 resolves to"wmanet.org"
Top Level Domain: "wmanet.org"

Saturday, April 07, 2007

209.51.147.66 - Monitoring will not stop

This Ip continues to monitor our site and will not stop. Hopefully Global Net Access will look into the activities coming from this IP Address.

IPs used by same hacker(s)

Just a hunch but these IPs are probably all used by the same hacker and/or hacked servers:

221.147.153.67
203.162.3.15674.52.245.146
220.123.254.200

Friday, April 06, 2007

209.51.147.66 - HACKER

This IP either belongs to a hacker or is being used by a hacker. They bombed our site today.

Check your logs for this one...especially those in the travel industry.

Korean Hackers Are Stepping Up

In the past few days we got a number of hacker scans from Korea. We block a lot of bad ranges but suddenly they are picking up again.

Here are a few of the IP ranges:

inetnum: 125.176.0.0 - 125.191.255.255netname: XPEEDcountry: KR

inetnum: 211.104.0.0 - 211.119.255.255netname: KRNIC-KRdescr: KRNICdescr: Korea Network Information Centercountry: KR

inetnum: 211.104.0.0 - 211.119.255.255netname: KRNIC-KRdescr: KRNICdescr: Korea Network Information Centercountry: KR

inetnum: 220.88.0.0 - 220.95.255.255netname: KORNETdescr: KOREA TELECOMdescr: Network Management Centercountry: KR

inetnum: 211.104.0.0 - 211.119.255.255netname: KRNIC-KRdescr: KRNICdescr: Korea Network Information Centercountry: KR

inetnum: 211.104.0.0 - 211.119.255.255netname: KRNIC-KRdescr: KRNICdescr: Korea Network Information Centercountry: KR

inetnum: 218.144.0.0 - 218.159.255.255netname: KORNETdescr: KOREA TELECOM

inetnum: 218.234.0.0 - 218.239.255.255netname: HANANETdescr: Hanaro Telecom Co.descr: Kukje Electornics Cneter Bldg. 1445-3 Seocho-Dong Seocho-Kucountry: KR

inetnum: 222.96.0.0 - 222.122.255.255netname: KORNETdescr: KOREA TELECOMdescr: Network Management Centercountry: KR

inetnum: 58.224.0.0 - 58.239.255.255netname: HANANETcountry: KR

A string of related PHP hacker IPs

Here are a string of hits in a row from IPs in different parts of the world requesting things that are not on our server. They are requesting a specific URL, not an IP address so this is not a DNS problem where someone pointed a domain to our IP by mistake. I believe our DNS servers are set up correctly as I just double checked everything but my hosting company has a propensity for screwing up DNS records so will have to check that again. However given what they are requesting I assume these are a bunch of related hacked IPs, probably controlled by a command and control bot somewhere.

"inetnum: 220.0.0.0 - 220.63.255.255
netname: BBTECH
descr: Japan nation-wide Network of SOFTBANK BB CORP
descr: Tokyo, Japan
country: JP
" 269236 BLOCKED 7i1768n6s9ky Thu Apr 05 07:10:31 PDT 2007 220.125.98.46 /index.php Mozilla/5.0 (Windows; U; Windows NT 5.0; en-US; rv:1.3a) /index.php act=Reg&CODE=00 83 7 1 4/5/2007 7:10:31 AM 5 4 4/5/2007 7:10:31 AM
"inetnum: 218.144.0.0 - 218.159.255.255
netname: KORNET
descr: KOREA TELECOM
" 269235 BLOCKED 1n2q7vj1sj66u Thu Apr 05 07:10:28 PDT 2007 218.144.144.230 /index.php Mozilla/5.0 (Windows; U; Windows NT 5.0; en-US; rv:1.3a) /index.php act=Reg&CODE=00 83 7 1 4/5/2007 7:10:29 AM 5 4 4/5/2007 7:10:29 AM
269234 BLOCKED 17fot0jc7s1g6 Thu Apr 05 07:10:26 PDT 2007 218.239.91.102 /register.php Mozilla/5.0 (Windows; U; Windows NT 5.0; en-US; rv:1.3a) /register.php action=signup&who=adult 83 7 1 4/5/2007 7:10:27 AM 5 4 4/5/2007 7:10:27 AM
269233 BLOCKED 884p8rgc0r4b Thu Apr 05 07:10:24 PDT 2007 222.99.104.139 /register.php Mozilla/5.0 (Windows; U; Windows NT 5.0; en-US; rv:1.3a) /register.php action=signup&who=adult 83 7 1 4/5/2007 7:10:25 AM 5 4 4/5/2007 7:10:25 AM
269232 BLOCKED g6t4qf5acgdc9 Thu Apr 05 07:10:22 PDT 2007 58.226.121.105 /profile.php Mozilla/5.0 (Windows; U; Windows NT 5.0; en-US; rv:1.3a) /profile.php mode=register 83 7 1 4/5/2007 7:10:23 AM 5 4 4/5/2007 7:10:23 AM
"inetnum: 59.88.0.0 - 59.99.255.255
netname: BSNLNET
descr: NIB (National Internet Backbone)
descr: Bharat Sanchar Nigam Limited
descr: Sanchar Bhawan,20, Ashoka Road, New Delhi-110001
country: IN
" 269231 BLOCKED 1q0g62wvk2a4 Thu Apr 05 07:10:18 PDT 2007 59.93.209.25 /profile.php Mozilla/5.0 (Windows; U; Windows NT 5.0; en-US; rv:1.3a) /profile.php mode=register 83 7 1 4/5/2007 7:10:18 AM 5 4 4/5/2007 7:10:18 AM
"inetnum: 59.88.0.0 - 59.99.255.255
netname: BSNLNET
descr: NIB (National Internet Backbone)
descr: Bharat Sanchar Nigam Limited
descr: Sanchar Bhawan,20, Ashoka Road, New Delhi-110001
country: IN
" 269231 BLOCKED 1q0g62wvk2a4 Thu Apr 05 07:10:18 PDT 2007 59.93.209.25 /profile.php Mozilla/5.0 (Windows; U; Windows NT 5.0; en-US; rv:1.3a) /profile.php mode=register 83 7 1 4/5/2007 7:10:18 AM 5 4 4/5/2007 7:10:18 AM

Another php attack - XMLRPC.PHP etc.

If you are running php and using any of the files below beware - there is probably some sort of hack in them. This attack comes from 61.62.83.165

Surprise, surprise - Taiwan.

inetnum: 61.62.0.0 - 61.62.255.255netname: SONET-NETcountry: TW

Taiwan is a big hacker source. If you're not doing business there you may want to consider blocking out IPs from this country. If you're not getting any money from Taiwan the only thing you will get is a bunch of problems.

269083 BLOCKED 5dmervkrad0bs Thu Apr 05 00:29:54 PDT 2007 61.62.83.165 /phpgroupware/xmlrpc.php /phpgroupware/xmlrpc.php 83 7 1 4/5/2007 12:29:54 AM 5 4 4/5/2007 12:29:54 AM
269082 BLOCKED 1gpe1xqetqxi1 Thu Apr 05 00:29:54 PDT 2007 61.62.83.165 /phpgroupware/xmlrpc.php /phpgroupware/xmlrpc.php 83 7 1 4/5/2007 12:29:54 AM 5 4 4/5/2007 12:29:54 AM
269081 BLOCKED 4famei5pnqlkj Thu Apr 05 00:29:53 PDT 2007 61.62.83.165 /wordpress/xmlrpc.php /wordpress/xmlrpc.php 83 7 1 4/5/2007 12:29:54 AM 5 4 4/5/2007 12:29:54 AM
269080 BLOCKED 48978s37c7mpo Thu Apr 05 00:29:53 PDT 2007 61.62.83.165 /wordpress/xmlrpc.php /wordpress/xmlrpc.php 83 7 1 4/5/2007 12:29:54 AM 5 4 4/5/2007 12:29:54 AM
269079 BLOCKED 9ur4s0tv5oqc Thu Apr 05 00:29:53 PDT 2007 61.62.83.165 /b2evo/xmlsrv/xmlrpc.php /b2evo/xmlsrv/xmlrpc.php 83 7 1 4/5/2007 12:29:53 AM 5 4 4/5/2007 12:29:53 AM
269078 BLOCKED 2rkqne24ojvle Thu Apr 05 00:29:53 PDT 2007 61.62.83.165 /b2evo/xmlsrv/xmlrpc.php /b2evo/xmlsrv/xmlrpc.php 83 7 1 4/5/2007 12:29:53 AM 5 4 4/5/2007 12:29:53 AM
269077 BLOCKED vt6xth4n6s0r Thu Apr 05 00:29:52 PDT 2007 61.62.83.165 /b2/xmlsrv/xmlrpc.php /b2/xmlsrv/xmlrpc.php 83 7 1 4/5/2007 12:29:53 AM 5 4 4/5/2007 12:29:53 AM
269076 BLOCKED qiox5oyth034 Thu Apr 05 00:29:52 PDT 2007 61.62.83.165 /b2/xmlsrv/xmlrpc.php /b2/xmlsrv/xmlrpc.php 83 7 1 4/5/2007 12:29:53 AM 5 4 4/5/2007 12:29:53 AM
269075 BLOCKED e7ecb4966qpr7 Thu Apr 05 00:29:52 PDT 2007 61.62.83.165 /blogtest/xmlsrv/xmlrpc.php /blogtest/xmlsrv/xmlrpc.php 83 7 1 4/5/2007 12:29:52 AM 5 4 4/5/2007 12:29:52 AM
269074 BLOCKED 12ncmocu7lv5a Thu Apr 05 00:29:52 PDT 2007 61.62.83.165 /blogtest/xmlsrv/xmlrpc.php

Wednesday, April 04, 2007

Charter bot is back

Will it ever give up or will Charter ever do something about this bot...

Charter - bot/1.0 (bot; http://; bot@bot.bot) 267331 BLOCKED 2t10omfv05mc Wed Apr 04 07:58:34 PDT 2007 71.13.115.117 bot/1.0 (bot; http://www.bot.bot; bot@bot.bot) 83 7 1 4/4/2007 7:58:35 AM 4 4 4/4/2007 7:58:35 AM

IPs that need to be updated

Here are some interesting results looking up the information about this IP range:

inetnum: 156.54.0.0 - 156.54.255.255

remarks: This inetnum has been transfered as part of the ERX. It was present in both the ARIN and RIPE databases, so the information from both databases has been merged. If you are the mntner of this object, please update it to reflect the correct information.

Tuesday, April 03, 2007

Comcast needs to fix this domain name

This domain name information is not correct ... MN needs to be changed:

24.18.46.154 resolves to"c-24-18-46-154.hsd1.mn.comcast.net"
Top Level Domain: "comcast.net"

An exchange sever perhaps?

If this is an Exchange server what is it doing surfing our web sites?

Perhaps this stands for something else however:

64.65.150.210 resolves to"exch.seattlearch.org"
Top Level Domain: "seattlearch.org"

Bank Server surfing?

Here's a bank server in Sweden surfing the web....is this right? That's a little scary...but perhaps since I don't speak the language this is referring to a modem bank..so I'll let it slide for now =)

195.242.56.2 resolves to"clients.kaupthing.se"
Top Level Domain: "kaupthing.se

Funny looking domain resolution for a web surfer...

This one looks a little funny ...is this really the IP of an end user surfing or a server?

128.250.172.175 resolves to"guyd.psych.unimelb.edu.au"
Top Level Domain: "edu.au"

Another surfing web server? william.aeoncyberclub.com

Here's an IP with an interesting resolution:

202.7.145.118 resolves to"william.aeoncyberclub.com"
Top Level Domain: "aeoncyberclub.com"

Is this really a machine surfing the web or a human?

www.adressendeutschland.de web server surfing our web sites

This server appears to be surfing the web and appears to be a web server, though by the looks of the "site" it may be an amateur at home hosting his or her own site.

88.198.38.230 resolves to"www.adressendeutschland.de"
Top Level Domain: "adressendeutschland.de"

ozemail.com.au surfing the web

Is this really an email domain or a dsl domain? It says ozemail but then it has dsl in the URL as well. Hopefully someone in Australia can alert this email / dsl provider to find out if this server is hacked.

203.102.242.189 resolves to"189.fip-4.dsl.ozemail.com.au"
Top Level Domain: "com.au"

km6.favo.tv -- a computer user?

This Ip was hitting our site - not sure if this is part of a DSL network - a router or other networking equipment -or something totally not legitimate.

87.118.100.27 resolves to"km6.favo.tv"
Top Level Domain: "favo.tv"

A proxy server in the Phillipines

Here's a proxy server in the Philippines surfing around our web sites...

202.44.136.50 resolves to"proxy.thapra.su.ac.th"
Top Level Domain: "ac.th"

Speak Easy "scan alert" server surfing our sites?

A SpeakEasy IP with some scanalert.com application is surfing our web sites...

66.92.26.98 resolves to"scan0.scanalert.com"
Top Level Domain: "scanalert.com"

EntireWeb surfing our webs

Here's another web server IP address surfing our web sites. This is a search engine optimization company so chances are they are analyzing our sites to snipe content and/or copy our ranking techniques. I suggest you block this one out.

62.13.25.221 resolves to"www.entireweb.com"
Top Level Domain: "entireweb.com"

Monday, April 02, 2007

A web server surfing our web sites

Here's a web server surfing our web sites:

209.180.210.90 resolves to"sightlife.org"Top Level Domain: "sightlife.org"

Saturday, March 31, 2007

Favorstar.com

We keep getting hits from favorstar.com. I boldly and probably riskily went to this site and it's a Chinese site with some video and half naked women on it in bras, etc. Whatever this site is up to, it can't be any good. I also noticed they are advertising a t-shirt site in direct competition with one of ours. I can't imagine this site is up to anything good.

Wednesday, March 28, 2007

U.S. Malware Capital?

This article form Network World claims that San Jose found the most malware was hosted in the US "contrary to the belief that it was coming from other countries" not in so many words.

http://www.networkworld.com/news/2007/032607-more-evidence-of-us-as.html?nlhtsec=0326securityalert3&company=MessageGate

They almost downplay the issue that most of this malware is probably weaseled onto servers via hacking or on servers paid for by people of origin outside the U.S. Yes, there are probably a lot of US hackers - we did invent the computer after all.

It is important to keep all factors in mind while analyzing this topic. It has also been reported that many hacker and terrorist organizations buy computer networking from the US because it is more cost effective (or was) than in other countries. That may be changing with China and India in the game, I'm not sure.

Hacked servers are also a huge source of this malware and I would be interested to know the % of this 80% of malware that is on hacked servers and how much of the malware actually got onto the US computers via a hack from someone originating from another country. A person I spoke to from the FBI says about 15% of the world's computers are thought to be "command and control bots," meaning they are either set up intentionally or hacked to run code for someone who is using a command server to control a bunch of other machines to carry out their dirty work.

The author did mention the money changing hands here - and why the US is a target, but also consider that the UK is second on the list. The US, the UK. Hmmm.

Also to take into consideration would be the size of the US and the amount of computers in the US relative to other countries. I'm not sure but I'd guess there are a relatively larger number of computers here than in some other countries at this time.

But perhaps the author just meant that this is where most of the malware is running - that the U.S. is the target and our security is totally lacking, rather than highlighting the US as a source of creating and distributing malware. If you consider the malware is running on machines that can affect people all over the world it is a problem - but the cause of that problem still may be mainly coming from outside the US. Security lacking? A wake up call? With that I would have to agree.

Personally I find plenty of hacker looking traffic from all over the world. I haven't done the numbers to compare by country but there are a load of hackers in Ontario, Alaska, throughout Europe, and a ton coming out of Asia - especially China and Taiwan. There is some that comes out of Brazil and occasionally Mexico - I was bombed by France the other day (see a recent post).

The interesting thing is that probably one of the biggest hacks on credit cards at Card Service International (I believe that is correct) in Arizona a couple years ago was attributed to the Russian Mafia by the news in Australia when I was down there. People in the US said they didn't hear that - I am not sure what was reported in the US.

But I get very little hacker like traffic from Russia. Does that mean there are no hackers in Russia? No, it means they are pretty damn smart. They do their dirty work from hacked servers in other parts of the world so they are not discovered. A recent piece of malware running on tons of US servers included a built in virus checker - Kapersky - Russian by origin though they since tried to appear as they are headquartered in the US. I also think there may be some Russian hackers up in Alaska using some network - Hideout.net

So the point the author is making about most of the hacks not coming from Russia or China like everyone thinks - is twisting the facts.

RufusBot is a Dufus. 64.124.122.228

The so-called "rufus bot" is hitting us repeatedly again from this IP address: 64.124.122.228 and the stupid thing is, it is requesting pages that do not exist on our server over and over again and getting Page Not Found errors and still continues to request the pages.

Either the person that wrote the RufusBot is a dufus, or as I suggested before there is an error related to 404 errors that present a security or hacker problem. I am not sure why else these bots would try to hit pages that do not exist repeatedly. I guess they could be that stupid, but I kind of doubt it.

Saturday, March 24, 2007

Hackers - Ontario

I am still convinced there are hackers in Ontario - probably on Rogers Cable but also coming from Shaw and other networks. I think they move around.

After implementing a new filter we just got a bunch of hits in a row on pages without referrers from Toronto IPs.

Tuesday, March 20, 2007

Ask Jeeves Spoofer?

We've been getting a lot of hits supposedly from AskJeeves such as this:
57 hits this month
Ask Jeeves User Agent
65.214.44.166
Last Visit: 3/20/2007 4:20:54 PM

However this IP does not belong to any of the Ask Jeeves IP ranges as far as I can see:

Ask Jeeves ASKJEEVES-66-09 (NET-4-19-66-0-1) 4.19.66.0 - 4.19.66.255
Ask Jeeves HTW-06853 (NET-64-55-148-1-1) 64.55.148.1 - 64.55.149.254
ASK JEEVES Q0518-63-145-26-32 (NET-63-145-26-32-1) 63.145.26.32 - 63.145.26.63
ASK JEEVES TWTC-SNFO-C-ASKJEEVES-0 (NET-206-80-1-0-1) 206.80.1.0 - 206.80.1.255
ASK JEEVES Q0426-63-236-237-72 (NET-63-236-237-72-1) 63.236.237.72 - 63.236.237.79
ASK JEEVES Q0213-72-165-191-64 (NET-72-165-191-64-1) 72.165.191.64 - 72.165.191.95
ASK JEEVES ASK-JEEV33-211 (NET-12-193-211-0-1) 12.193.211.0 - 12.193.211.255
ASK JEEVES INC Q0321-65-119-214-0 (NET-65-119-214-0-1) 65.119.214.0 - 65.119.214.255
Ask Jeeves PBI-CUSTNET-6751 (NET-216-103-72-40-1) 216.103.72.40 - 216.103.72.47
Ask Jeeves SBCIS-101412-175559 (NET-64-174-153-192-1) 64.174.153.192 - 64.174.153.199
Ask Jeeves SBC067114171064020215 (NET-67-114-171-64-1) 67.114.171.64 - 67.114.171.71
ASK JEEVES MFN-B370-209-249-69-0-29 (NET-209-249-69-0-1) 209.249.69.0 - 209.249.69.7
ASK JEEVES MFN-B370-208-184-139-0-29 (NET-208-184-139-0-1) 208.184.139.0 - 208.184.139.7
ASK JEEVES MFN-B370-208-185-161-0-28 (NET-208-185-161-0-1) 208.185.161.0 - 208.185.161.15
ASK JEEVES MFN-B370-208-185-160-0-24 (NET-208-185-160-0-1) 208.185.160.0 - 208.185.160.255
ASK JEEVES MFN-B370-208-185-182-128-28 (NET-208-185-182-128-1) 208.185.182.128 - 208.185.182.143
ASK JEEVES MFN-B370-216-200-130-0-24 (NET-216-200-130-0-1) 216.200.130.0 - 216.200.130.255
ASK JEEVES MFN-B370-208-185-219-224-27 (NET-208-185-219-224-1) 208.185.219.224 - 208.185.219.255
ASK JEEVES MFN-B370-64-124-141-0-24 (NET-64-124-141-0-1) 64.124.141.0 - 64.124.141.255
ASK JEEVES MFN-B370-209-249-88-48-28 (NET-209-249-88-48-1) 209.249.88.48 - 209.249.88.63
ASK JEEVES MFN-B370-64-124-56-0-24 (NET-64-124-56-0-1) 64.124.56.0 - 64.124.56.255
ASK JEEVES BRW-11672-ASK (NET-216-143-191-128-1) 216.143.191.128 - 216.143.191.191
Ask Jeeves MFN-B370-209-66-103-0-24 (NET-209-66-103-0-1) 209.66.103.0 - 209.66.103.255

Tuesday, March 13, 2007

Stock Price Manipulation

A while back I posed the idea of manipulating stocks somehow using Internet technologies to affect prices and make a profit. Some people scoffed at me and told me how difficult this would be based on how many people would need to be involved to make this happen.

Here's proof that it can be done and something to watch out for:
Internet stock scam

Recently Real Networks has claimed that their stock price was manipulated possibly by hackers or Internet scam artists in China.

So call it a silly idea but there's a reason you've seen all that stock spam in your inbox.

I haven't done the math to see what it would take to get enough people to buy in to affect the price of a stock. I'm sure it depends on the stock and a lot of other factors. Just pondering the possibility.

Tuesday, March 06, 2007

Ebay vs. Romanian Hacker

Ebay has been plagued by a Romanian hacker lately per this article:
http://www.eweek.com/article2/0,1895,2100808,00.asp?kc=EWSTEEMNL030607EOAD

Of interest are the various tactics ebay is using to thwart this criminal which go beyond simple tactics to more complete analysis of hacker activity ...a trend in the industry which has long been needed over an above simple firewall rules and was the reason I started writing this hacker / Internet security / Internet service blog.

More analysis of specific hacker activity by humans, not machines, will help determine traffic and activity patterns to block out attacks better than any firewall rules. It is a constant, on-going effort at mutliple layers from network to firewall to OS to application - it is not a simple one time fix.

Sunday, March 04, 2007

Hacker in Japan

Japan scanning IP addresses for security flaws:

203943 BLOCKED a2ge8iqi9mcec Sun Mar 04 09:24:51 PST 2007 203.143.125.226 //ads/adxmlrpc.php Mozilla/4.0 (compatible; MSIE 6.0; Windows 98) /ads/adxmlrpc.php 3/4/2007 9:24:51 AM 3/4/2007 9:24:51 AM
203942 BLOCKED 1trlwusqdgvg5 Sun Mar 04 09:24:51 PST 2007 203.143.125.226 //Ads/adxmlrpc.php Mozilla/4.0 (compatible; MSIE 6.0; Windows 98) /Ads/adxmlrpc.php 3/4/2007 9:24:51 AM 3/4/2007 9:24:51 AM
203941 BLOCKED 4tnft3pc3kubt Sun Mar 04 09:24:50 PST 2007 203.143.125.226 //phpads/adxmlrpc.php Mozilla/4.0 (compatible; MSIE 6.0; Windows 98) /phpads/adxmlrpc.php 3/4/2007 9:24:51 AM 3/4/2007 9:24:51 AM

..repeat about 50 times

A bunch of IPs requesting stuff we don't host

The following are related hacker IPs probably controlled by a command and control bot:

74.118.71.252
124.50.43.214
60.217.227.135
210.191.147.120
203.165.129.2
210.6.97.244

They all hit our site at the same time requesting things our server does not host.

Here's another set shortly before doing something similar, probably also related to the above:

195.49.188.202
71.63.100.55
210.245.147.241
218.233.57.23272.145.6.47
218.48.127.177

71.63.100.55
210.245.147.241
218.233.57.232

Perhaps someone pointed a domain to the wrong IP since they were all hitting the same domain.

These IPs are all requesting php files -- the favorite language of the hacked and hackers as far as I can tell by the percentage of hacks in the logs on various types of web programming and scripting languages.