Thursday, May 14, 2009

Downloaded Software - Permissions Wish List

It would be very cool if Microsoft and other operating systems would allow you to configure permissions for each executable and what they can access in the system (if there is not a way to do this already).

For instance, I just downloaded some code from some guy I never met that had something I needed posted in a newsgroup. The guy's been on the newsgroup for a while but how do I know he's legit? He sent me exe's not source code so who knows what's in that - but I really need this little functionality because it will save me a ton of time.

So anyway, I'm sitting here debating if I should use this thing or not and that's when I was thinking it would be really cool if I could just right click on this little exe and set up permissions for it - whether or not it can access the Internet inbound or outbound - specify which IPs and ports it can access for some internal testing I need to do with it (is related to TCP/IP and sockets). Additionally I would like to be able to specify which user accounts it can run under and what directories and files it can access - and whether it can read/write/modify/delete those files or in those directories.

It would also be nice if I could set my default permissions for new files and executables and then alert me if some exe or program of some sort is trying to access something for which it doesn't have permission and let me decide if I want to give it permission or not.

Saturday, May 09, 2009

Email Providers - Half a TLS Solution

Recently a person I had problems emailing due to issues with Postini told me that they were responding to my messages - but I am not getting them. I had looked up this person's mail server information and it looks as though that mail server supports TLS. However apparently that is only TLS inbound, and not outbound.

What is the point of mail services that only provide one way TLS encryption? That's only half a solution.

I believe the mail provider in this case is BlueHost - an ISP which I believe is out of Denver - however there are so many other webmail and Exchange and other mail solutions that do not provide two way TLS encrytpion it is almost impossible to find a complete end to end solution.

In fact, if you try to find a mail provide that does provide two way TLS enforcement that works with Exchange and allows you to have your own Postini account...good luck.

On top of that even if you find TLS enforcement both ways, I've been following the email list from the ITEF on TLS and apparently depending on how each aspect of TLS is set up and implemented may affect whether or the particular implementation of TLS is actually very secure. It's like a chain - and a chain is only as strong as it's weakest link.

I'm not a TLS expert but I can figure out enough from reading what's going on that there may be one small piece of the TLS implementation that basically undermines the whole set up.

Friday, May 01, 2009

Firefox 3.0.10 - listening for INCOMING requests?

Just installed 3.0.10

Norton reports this version of Firefox is listening for INCOMING requests? Why?

When I block this Firefox dooesn't work.

Http is to go out, get info and pull it down, not listen for and allow other computers to connect to my machine. What is going on here?

Saturday, April 25, 2009

Calls on Inactive Number

It is interesting that I get phone calls on an invalid phone number that has been temporarily disabled. The phone numbers are clearly crappy phone calls where someone is trying to sell me garbage about publishing books or something.

How is it that when these people call this number they are able to get passed through to me on my other phones when supposedly this number is inactivated? Are they basically hacking some system to get through? Or did the phone company make some kind of mistake when they parked my number?

I have long wondered if somehow this number was hacked in some way. I switched my business number to a local number and suddenly got a bunch of leads and calls. It was kind of odd because shortly after the switch - it kind of died down again.

Additionally, one of the guys who hired me suddenly couldn't call me anymore. Not sure how he fixed it. Now other people are complaining they have called me but where not able to get through.

Is this all random? Are our phone systems all hacked too?

Friday, April 17, 2009

Images in frames not showing up in IE8

Another interesting change in IE8 - images in frames do not show up in the parent page is HTTPS and the inner frame is trying to display images from a url using HTTP.

I'm torn on this point. First it's better security to enforce a whole page to be completely https. On the other hand do you know how many web sites are going to be completely non-functional by enforcing this? Additionally this is not the functionality provided by other browsers. I think people will just switch over to a browswer that works in this case.

What are the implications of displaying an image from an http url vs an https url on an https encrypted site? It's just an image, not a page with functionality right? However sometimes images can be used to create hacks (search on hack + gif, etc. in Google).

I'm not so sure about this but will just have to make it work somehow in case it doesn't change I guess.

Mac BotNet - Zombie Macintosh Computers

This article points out three things:

Mac BotNet

1. If you download free software off the Internet there may be malware embedded in it. Free is not always free. Who's auditing free software anyway?

2. This is the first reported Mac botnet. Macs are vulnerable as much as PCs, they just aren't typically targeted as much. Most likely if the Mac user base grows significantly this will change. Also if Mac is not as attacked and Mac is not as on top of security like Windows and encouraging computer owners to update, Mac owners may be more vulnerable. Update your software!

3. Web sites that allow comments after their articles and don't pay attention or moderate them are  degrading the quality of their sites.

Tuesday, April 14, 2009

Directory Harvest Attacks - Asia

Recent directory harvest attacks from RIPE and LACNIC:

Begin Time 04/14 10:31:35
End Time 04/14 10:32:47
IP Address 217.197.245.64

Begin Time 04/14 20:56:20
End Time 04/14 20:57:48
IP Address 201.170.118.229

Begin Time 04/14 21:00:38
End Time 04/14 21:02:07
IP Address 201.21.233.128

Weird QuickTime Issue

I uploaded a .tif file to a web site and then when I tried to download it, QuickTime was trying to open it. Why is QuickTime, a movie application, trying to download a .tif file and other static images in my browser? That's odd isn't it?

Then, I tried to change the browser plugin to NOT open any static images - tiffs, jpgs, gifs, etc. I also stopped it from auto playing movies. I restarted my browser. After doing that the plugin continued to try to download the tifs. Why?

I searched around for a way to completely eliminate the plugin from my browsers but couldn't figure that out in a quick fashion, so I ended up just completely removing QuickTime from my computer. After doing that I was able to download the tif files without any problem and without them being embedded in my browser, which is NOT what I wanted.

Is there something odd going on here with QuickTime? I know QuickTime is included with QuickBooks for some reason. Not sure what that was all about.

IE8 - Lots of problems

Is anyone else having a lot of problems with Internet Explorer 8 like I am? Basically a lot of forms aren't working because it seems like some ways to access the DOM or document object model have somehow changed. These same sites work in IE 7 and also Firefox so not sure why they don't work in IE 8. I cannot believe these changes are not affecting other web sites as the programming is very common. Nothing obscure or tricky going on in these web sites - just getting values out of fields via the document object model. What's up with these changes?

Recent Directory Harvest Attacks

Looks like there were quite a few directory harvest attacks around Easter. Perhaps those repsonsible for these directory harvest attacks figured people would have better things to do on the holidays than pay attention to their mail servers.


Begin Time 04/13 23:55:33
End Time 04/13 23:56:47
IP Address 71.68.21.45
Road Runner HoldCo LLC

Begin Time 04/12 20:11:27
End Time 04/12 20:12:59
IP Address 206.252.161.165
Earthlink, Inc.

Begin Time 04/12 15:57:26
End Time 04/12 15:58:59
IP Address 69.171.162.121
Cricket Communications Inc

Begin Time 04/12 12:53:01
End Time 04/12 12:54:39
IP Address 71.188.170.110
Verizon Internet Services Inc.

Begin Time 04/12 09:44:12
End Time 04/12 09:45:51
IP Address 72.14.74.9
ISP Alliance, INC. / Sjoberg Cable MNCABLE

Thursday, April 09, 2009

Intuit.com - Backup.com - Security Issues

I just tried to get an email from Intuit. They send automated emails from a system and those emails never come to me. They just sent me a temporary password for a system and I'm not getting the email. I'm 99% sure I was entering the right password in the first place and I don't think I ever changed that password so not sure why it wasn't working.

When I do an nslookup to get the mx records for Intuit.com I get 5 mail servers IP addresses. I checked in Postini and these IP addresses are not blocked. Additionally this domain does not have TLS enforcement on. No, the emails are not in any spam boxes.

So I've been on hold going around in circles with this person online who clearly is not a native English speaker and although I asked if this email was coming from an INTUIT.COM email server many times, finally I asked him - is this email coming from within the US? All intuit mail servers are on a 12.x.x.x IP address so if coming from an INTUIT.COM mail server this email would be coming from the US (ARIN).

Finally the guy admits that the mail is coming from a server in India. I have some IP ranges blocked in India due to spam. Aha. Now we are getting somewhere. So to unblock these mail servers I need to know the specific server from which the mail is coming.

Personally, I would rather that Intuit send such emails from within the United States. I also did not like the fact that Intuit is using some unknown mail server to send my passwords for all my backup information around and that it is not one of the intuit specified mail servers so I can enforce TLS encryption and receive my password securely. I also tried to check if Intuit mail servers support TLS and got booted off the mail server so not sure if it is safe to force TLS and ensure emails regarding my backup service and financial applications are secure.

But at this point I thought I understood what the problem was. Wrong.

After getting escalated again to another manager he told me that the mail was not coming from INTUIT.COM but rather BACKUP.com. So again I look up the mail servers and can see that the mail is coming from 4 Symantec mail servers. Again I dig through with nslookup and figure out that these mail servers are in the US (Arin) and are not blocked by my mail system.

The manager suggests sending to an alternate email address. OK that will take two days for them to set up and in the meantime my password is floating around out there. Great.

But wait...just as he's about to do this...he notices that the email address in the online backup system is spelled wrong. Two letters are transposed in the system. Hmm. I have gotten many emails from Intuit and I know that I have not recently changed my email address with them. So apparently my emails from them at some point started going to this alternate misspelled domain name. I checked and the domain name WAS previously registered. That means apparently in the past someone would be able to get my emails from them and potentially get hints as to what my password was and/or call into them and get my backup password information.

Of course they assure me no one else has gotten into my backups. Probably because they do not want to be liable when it is uncovered that someone has stolen all the financial and business information I have been backing up with them.

I assume when Intuit has you put in email addresses for a backup system which is highly critical, that they verify the person who put in the email got an email back from them before they start sending passwords out this way to that email address.

This is a pretty serious problem if you ask me. I am now wondering who has stolen all my data that I have tried to back up with them for security reasons.

Finally -- I'm wondering how, after they reset my password to a temporary password - I can still backup my files. If the password has been reset shouldn't access to the backup system be denied if my local software is using the old password?
_____

OK I just got a call from Intuit again and this manager I was speaking to told me they have regenerated the password email. I still do not have any emails from them. I am calling in again. The person I got on the phone is trying to get information from me and I'm telling him just to get me back to that person so I don't have to spend another hour and a half on the phone....

...ok got through to that person again. Apparently he called and told me the email went through but he checked some system and the change to the email to correct it was not made. So he's going to go back and check again. He says usually this process takes a couple of days and he's pushing it through so I appreciate that. It's just kind of a huge hassle to get this resolved.
____

Hours later...still no email from Intuit. I guess I'll have to call tomorrow a.m.
____

Next day... I had two emails telling me this issue was resolved and asking for feed back...trying to call again...they are making me go through all the questions again and asking what the problem is over and over again...this is really annoying. Don't they have my business name and all that related to the case number?

...OK the manager I was supposed to ask for is going ot call me back in 15-20 minutes....
____

I got a call. It was more than 15-20 but I got a call so that's good. I had to leave my house by that time to run errands so wasn't at my computer. The email hadn't arrived by the time I left my house. The manager re-initiated the email shortly after he called me and when I was able to login to my computer a few minutes later the email finally arrived.

The strange thing is that he told me he received confirmation that the automated emails were sent prior to this one - they never arrived. So why did this one?
____

And in summary...I don't trust online backup anymore. Encryption shemcryption. It doesn't matter if someone can compromise your password - and even after the password has been changed, the software still allows access to upload and download files. Somehow my email got changed in their system, someone set up a fake domain potentially and got access to the files.

Security is not about encryption only. Security is about process and people and auditing and verification and surprise random testing and monitoring.

From here on out I think I'll figure out a way to encrypt my local files before I send them over to the online backup service. This is a total pain as it depends on me remembering my password to encrypt and decrypt the files however so it's a pain.

I think I will also set up a periodic test to download and decrypt my files to make sure someone has not again changed my email, gotten my password, etc. But now it's probably too late. Someone probably has my pertinent data if they already got in there and there's not much I can do about it.
___

Oh and for the record, the email did not come from backup.com OR intuit.com. It would be nice if the service people knew what they were talking about in that regard as well. However it should still be coming from an Intuit mail server and those servers should publish that they use TLS so people can enforce end to end TLS.

Wednesday, April 08, 2009

Firefox Keylogger

When I start up Firefox using some software that is supposed to alert to keyloggers it says there's some keystroke polling/logging going on when Firefox starts up. When I block whatever this software is, nothing I type into Firefox shows up. The same is not true of Internet Explorer. Maybe this keystroke logging / polling is part of Firefox and to be expected. Wish I understood this better and could see exactly what Firefox is doing.

Clearwire Nodes

Yesterday I noticed one clearwire node in my local network while using my Clearwire card. I restricted access from that node to my computer. Then others popped up as noted in my last post. The thing I find odd is that yesterday I only had one node in my newtork after using Clearwire for quite a while. Since blocking that one node, I've got tons of Clearwire nodes popping up in my network constantly. Today when I checked there were 53 Clearwire nodes in my network with "protected" access to my machine, whatever that means.

Also strange - today when I turned on my computer and had my clearwire card plugged in, my computer would not boot up. It kind of froze on start up. The disk was spinning like it was trying to do something but it just kind of sat there. This may have nothing to do with Clearwire at all and just a coincidence. I removed the Clearwire card, rebooted, and the computer was fine. Then I restarted again with the Clearwire card, and it was fine again.

Not sure if any of this is related or matters, just reporting what I see.

Tuesday, April 07, 2009

Machine Accessing My Computer on Clearwire Network?

I was just checking out what was out there connecting to my computer while logged into Clearwire. I noticed a strange machine I didn't recognize had restricted access to my computer. I blocked all access. Then another machine poppoed up. I blocked that one. And so on and so on until I blocked 7 different IP addresses. When I looked them up they all belonged to Clearwire, the network I happen to be connected to at the moment.

So my question is, why does a clearwire machine need access to my computer while connected to their network? After blocking these machines my network still seems to work, so I don't think this is required for network connectivity. In my opinion these machines should not be connecting to my machine. I should connect to their machines when I choose, not vice versa. Is this intentional for some type of network optimization, or is something more devious going on here?

The IPs in question which are aparently a variety of Microsoft, Apple and other adaptors are:

96.26.200.234
75.92.204.151
75.92.167.167
96.26.197.19
75.92.248.37
74.61.30.136
74.60.6.73

Sunday, April 05, 2009

Different Browser - Different Google - Same Computer

Just wondering why when I search in Google on the same computer with two different browsers I get different search results for some keywords. I thought Mozilla was off in the past and IE was correct. Now I'm not sure anymore. I know all caching is turned off on my machine. I also turned off a bunch of add-ons and even uninstalled Google toolbar to see if that made a difference. What in the world is going on...is Google displaying different results based on user agent? Is my ISP caching results? Is IE8 doing something weird? What?

I looked further and have something called Search Wiki running. I am not sure how that got onto my computer. Did I install it? I don't remember installing it...The strange thing is it used to only be in Firefox - now it's in IE 8 but it's no longer in Firefox. When I choose to move pages up or down using Search Wiki it totally skews Google results across searches I didn't alter and removes other pages I haven't removed from the search results as well.

I can see pros and cons of this application. The biggest con of all would be someone altering a person's search results on their computer to make them think they have #1 Google rankings when they don't. Con as in con man. But this tool does have some useful application like blocking out sites from search results you don't like. Problem with that is it pretty much skews all your search results across broad categories of pages which I'm not sure is a good thing since Googles search algorithms already work pretty well. I found using search after that had some problems when the results were skewed.

Wednesday, April 01, 2009

Network Solutions certificate re-issue seems to be broken

When I submit a request to reissue a certificate at the Network Solutions web site I get a blank screen after submitting the request. After calling in today I emailed back and forth with someone through their ticket system. After fixing a few issues on my email system, my emails worked up to the point where I sent them the certificate request. However when I sent them the CSR, suddenly the guy noticed that someone started managing the queue and taking out all the messages when they had previously been ignoring it. The CSR took quite a while to come through while the other messages came through almost instantly. He put me on hold for five minutes while he waited for it and finally came back on the phone when he got it. At that point they were supposed to send me back a signed certificate. However sending a certificate through their automated system failed. It never came through. So finally the guy (again, as always) just manually emailed me the certificate. This has happened for the past three years. When I tried to get the issue resolved with the guy, he said basically all SRS Plus people have to get their certs this way. It never works.

For three years? The directions on the web site are wrong for three years? They haven't fixed their systems for three years? Network Solutions is a big company right?

So, I cannot get the reissue to work on the web site, I cannot get the cert off the web site because some tab I'm supposed to see is missing, their automated system for sending me a certificate doesn't work, and my emails get flagged as spam when they are not, and they get more messages from me than I've actually sent.

Not sure what is going on, but I did not send 17 emails to them. I did not send Viagra spam. The second guy told me he didn't see any spam in the system from me as the first guy claimed. Who is telling the truth here? Why is my email getting flagged as spam?

It is hard to believe with these kind of issues that these certificates are reliable.

On the phone however the guy claimed someone has hacked the Verisign EV certificates in some super secret presentation. Basically they could hack a PayPal cert. Is this true or is this just some line to keep people from buying an EV cert? Who knows.

I think it would take getting a PHD to have the time to study and validate all these things. Maybe I will.
---

Update. Finally working.

Ok there is no issue with my SPF records. SPF records are good.

Email is going through Postini.

Messages previously failing are getting through. Emails are flowing in from places I haven't gotten email from in a month or months.

I can look up email servers to see if they support inbound TLS. I have been able to resolve some inbound and outbound TLS restrictions finally and people say they are getting the emails.

I was able to get my SSL cert from Network Solutions after two weeks in a very odd fashion and unbelievable install it and it worked (only the second try this time and didn't really have to go around in circles on hold for hours like last time - though I did have to call in twice and they called me twice).

I just hope the SSL cert is legit after all that rigamarole.

Recent Directory Harvest Attacks

Event Type Directory Harvest Attack
Begin Time 04/01 13:39:07
End Time 04/01 13:40:21
IP Address 68.204.153.83

Event Type Directory Harvest Attack
Begin Time 04/01 01:05:49
End Time 04/01 01:07:03
IP Address 68.40.159.253

Event Type Directory Harvest Attack
Begin Time 03/30 17:13:50
End Time 03/30 17:14:57
IP Address 173.78.34.160

Monday, March 30, 2009

Directory Harvest Attacks

Recent directory harvest attacks:

03/30 10:02:59 by IP: 98.215.146.62 - Comcast

03/29 11:06:51 by IP: 71.1.227.69 - Embarq

03/28 22:32:19 by IP: 71.245.168.231 - Verizon

Email Attachments Replaced In Transit

Don't think your email can be altered in transit? Don't see a need for TLS? Find out how the Dalai Lama and US government computers have recently been hacked? The Dalai Lama had email attachments appearing to be from coworkers replaced in transit:

Emails Hacked In Transit

Using TLS is at least a starting point to help reduce this kind of thing. I am not well versed enough to know if it would prevent what the Chinse hackers did in this case to swap out email attachments in transit, however at least it provides authentication on both ends of the message and fixes a few problems in SSL.

Gmail Spamming Network Solutions

I have a gmail email address and a business email address that I have used to email Network Solutions in the past. Someone has bombarded Network Solutions with spam from my email addresses - both of them - so my email addresses got blocked by Network Solutions. The person at Network Solutions said the emails contained Viagra spam among other things.

The most annoying thing is that Network Solutions will not give me any of the mail headers so I can see who is doing it. The second most annoying thing is that I have set up TLS communication between myself and Network Solutions SSL. They had to email me the attachment via GMail - which is obviously not very secure.

I have contended for a long time that someone has been messing with my email and this pretty much confirms it. Coinicidence that it was both my gmail account and my business account? I doubt it.

So is it a problem with Gmail that someone can spoof my address to Network Solutions? Is this a problem with Gmail SPF records or lack thereof? Or is the problem that Network Solutions systems are not correctly checking SPF records and cannot tell the difference between spam and real emails that are actually from me?

The other problem with this whole scenario is the Network Solutions person said they were getting my emails, and replying to them. How is it that if my email address was blacklisted due to spam, they can still RECEIVE my emails (potentially spam) but not SEND emails to me? This doesn't really make sense to me. Don't you usually block spam? When they send to me they get no errors - so they didn't know they couldn't get emails to me until I called them and complained that someone really needs to fix this.

Additionally, they at first did not want to add the week onto my certificate for the time I have spent trying to get this to work - when the problem was not my fault. I cannot control their mail servers and know they are trying to email me but they cannot. This whole thing is very odd.

The other interesting thing is that they say they are sending these emails from the UK. This cannot be true because I have a block on emails from the UK. And it is also quite coincidental that one of my customers has been complaining suddenly that he cannot send emails to/from the UK -- but when he sent me the email header in question -- it was coming out of Texas.

Really, what is going on here? When is anyone going to believe that our email systems are really hacked and messed up and everyone needs to start using TLS (if that even works but it seems to be better due to authentication on both sides of the equation).

Thursday, March 26, 2009

123People - 123 People

Norton is reporting that 123 People is hosting drive by download software. Not to mention the completely bogus information they are displaying on their site. This site is bad news. Don't give them any "correct" information either, because who knows how they are using it.

Network Solutions SSL Cannot Email Me....

Just wondering what the problem is with Network Solutions trying to email me. Kind of odd - I've been a customer of theirs for years. Seems like the last few times I requested SSL certificates they couldn't send me an email with the new cert. They are fixing the problem now but I find this all kind of strange. Why me? Why a problem with my email address? What is going on? Email is so frustrating.

TLS Enforcement From Postini - Was Never Working?

Ok I've had TLS enforcement turned on in Postini since I got it for a particular domain of a company at which I was working. I just not got an error message stating that I cannot email this company because their mail server does not support TLS. I just used nslookup and telnet to test these mail servers and in fact they do not support TLS. So I don't know for how many months this "TLS Enforcement Policy" was not working. At all. I was sending messages to and from this client thinking they were encrypted.

Monday, March 23, 2009

Delay in TLS failure notifications

Apparently when using Postini TLS policy enforcement, there is quite a delay if you send an email to someone and their inbound server does not support TLS. It looks like it takes about a day or longer, so if you turn on TLS you won't know for some time that your email didn't go through.

Sunday, March 22, 2009

Volt Email Servers - TLS Failure

I tried TLS enforcement while sending to Volt email servers using Postini's TLS enforcement policies. I get a bounce back message saysing Volt servers do not support end to end TLS enforcement.

The error message is:
Technical details of temporary failure:
Google tried to deliver your message, but it was rejected by the recipient domain. We recommend contacting the other email provider for further information about the cause of this error. The error that the other server returned was: 451 451 Recipient does not support STARTTLS - psmtp (state 14).


This is very surprising since Volt is a very large technical staffing company. Why wouldn't they want the most secure email possible to protect the identities of their employees and their business communications?

The other odd thing is that I sent to another Volt person and the email seemed to go through. Either that or the TLS failure messages are very delayed and I haven't gotten that failure message yet, which seems odd. Shouldn't the message rejection be immediately available? Isn't there a way to test an email server to see if it supports TLS prior to sending the message so I don't get a whole bunch of failures over time and wastes mail server resources when they continually try to resend when an email server doesn't support TLS?

At any rate not sure why Volt email servers don't support TLS. This seems kind of odd. Additionally a person at Volt could not email me for some reason. There seems to be something strange going on with their mail servers.

Google - MD5 Cipher

I just noticed that in my error messages on Google an MD5 Cipher is being used:

version=TLSv1/SSLv3 cipher=RC4-MD5

I am not an expert on TLS and SSL but the latest SSL hack that got a lot of hoopla in the news was using an SSL certificate with MD5 encryption. It has been widely reported that SHA is much more secure and MD5 has been vulnerable for a while. Why is Google using MD5 in that case?

MD5 hacked

Wednesday, March 18, 2009

Postini Didn't Block Specified IP

Yesterday a customer complained about not getting email from one of his customers. I thought maybe the customer was in an IP range blocked by Postini so I asked him for a mail header if he could provide one.

For some reason an email was able to get through at some point and we haven't made any changes on our Postini account recently (unless Postini and Google Apps are making these changes related to the string of problems noted in my blogs since November on those Postini/Google Apps problems).

The thing I don't understand is that the IP address should have been blocked according to our mail configuration settings in the first place. This particular IP address that should have been blocked was coming through Microsoft's Hotmail service. The last IP in the email address was the Microsoft hotmail product. The originating IP address was in the UK in a range we had blocked.

Apparently, Postini must be only blocking the last mail server in the header but not the originating IP address, which could be problematic obviously. Hackers and spammers can simply go through a "good" mail server you don't want to block no matter what their particular originating IP address is and you cannot block them.

It would be better if Postini could somehow look at that originating IP address (if that's not what it's doing).

Maybe the issue here is that maybe different email headers have different formats and it can be tricky to parse out the originating IP. What if email headers had to conform to an XML standard with a schema to validate them. Would that help drill down to the correct IP address? Maybe backwards compatibility could be provided to parse out old headers and stuff them into XML - but if they don't work the mail gets rejected - with a message telling the person to upgrade their mail server to an XML header compliant system.

Additionally mail headers could have details encrypted in transit except for what is required to get the mail from end to end with some sort of hash to make sure the message was not altered in transit.

Just dreaming here on a better way to solve mail problems...

Microsoft Mail Problems

I've had a string of people lately complaining about problems with Microsoft "in the cloud" mail products and/or having problems sending messages to me from this service.

Someone trying to email me who uses one of their services somehow (not sure exactly how he's set up but there's a Microsoft IP of some kind in the set up) is having problems emailing me. I've checked all the IPs he's using and his mail server IP and they're not blocked.

A girlfriend of a friend was complaining that she was having problems with her Microsoft mail. Not sure the details there.

Then, strangely a customer complained that he could not get messages from someone. When a message finally did get through it came from a Microsoft mail product - from an IP that should have been blocked by Postini. The Microsoft IP was ok but it originated from a blocked IP.

Not sure what is going on here exactly, just been hearing about and having problems myself with mail related to Microsoft's online mail services in various ways.

Friday, March 13, 2009

Phone Problems

Seriously having communication problems related to my business. Today a person with a potential large project called me. My phone rang once, on my end and dropped off. On his end he said the phone rang and rang and rang and then went to a fast busy signal.

What is going on? It is seriously disturbing when important customers are trying to reach you and they get all kinds of weird problems like those I have described with my email below and other types of phone problems.

So my question is - how do you know when a lot of potential customers are being redirected to some other third party or cannot reach you for some reason? If you got a call from someone you don't even know and they couldn't reach you - they would assume you were out of business or something like that...you'd never know you missed their call.

This is all very bothersome if you start wondering how many phone calls, emails, sales leads and other things your business may be missing due to problems like this.

Saturday, March 07, 2009

123People.com Posting Private Information

123People.com is posting personal and private information including email addresses on the web - easy for spammers to scrape. That's lovely. Additionally they are posting completely bogus information including addresses and phone numbers.

It is looks like they are probably scraping this information off social networks and possibly other sources based on the information I've seen so far.

It may also be somehow related to the Manta site which also displays completely bogus information about businesses, because I found some similar information on both sites. Could be a coincidence but at least these sites are related because they both post bogus information.

Thursday, March 05, 2009

How secure is Postini if your mail is hacked before it gets there?

I have been having problems with Postini lately. Or maybe it's not Postini - maybe it's before the mail ever gets to Postini.

Thursday, February 26, 2009

New Problem with IE8 and Frames

There's a new problem with IE8. Some pages in frames aren't displaying images correctly. Redirecting to a new page within a frame doesn't seem to work at all in some cases, probably when going to a new URL. This same thing works fine in older versions of IE and Firefox.

Windows Defender Startup Programs


[UPDATE: Windows Defender had all the useful functionality removed in Windows 7. So someone will have to write another application to do this all over again so Microsoft can by it for billions of dollars all over again.] 

Windows Defender has a nifty tool which allows you to see which programs automatically run at start up, in addition to looking at which programs exist in your start menu. I did notice that Windows Defender does not tell you all programs / services that have started however, because I recently installed the Pronto Edit Professional2 from Philips (for customizing/programming remotes to control devices) and it seems to start up the ProntoData.exe service but is not listed in the programs that run at start up in Windows Defender. This is a service so maybe the Windows Defender tool is only intended to list programs, not services, but seems like it would be good to list services as well.

IE 8 Copy / Paste URL Bug Fixed

Looks like the copy paste bug mentioned in prior blog posts has been fixed in IE8. Not it's a bit more usable. I noticed that it seems to load some web sites faster than Firefox but I think I installed something Google related in Firefox that allows me to promote and demote urls in Google - perhaps it is a browser add-on and not Firefox causing this difference. I haven't had time to dig into it further.

Tuesday, February 24, 2009

Excel Exploit Can Take Over Your Machine

Beware of opening Excel files from people you don't know:

Excel Exploit

This exploit allows running random code when the Excel file is opened and can allow an attacker to compromise and take over your machine. Secunia reports that this attack is being actively exploited.

Tuesday, February 10, 2009

Slow Going on Email Solutions

Ok I got one email problem solved. My mail provider sent me a server I can use to send mail to my customers via TLS. I plugged it in at Postini and it seems to work so one problem solved.

I also finally got a response from Google - asking me if my issue had been resolved. I guess a response to my email from November is a step in the right direction, however they still have not resolved the problem yet. I am hoping they are working on it now however. I forwarded them a copy of the email that is failing due to the mail not being properly sent through Postini. As noted in previous posts, Postini claims this is due to Google Apps not correctly running a script to send my mail out through Postini. So far it is still not working, but at least I can hope again.

Friday, February 06, 2009

Google's Motto - Don't Be Evil

[UPDATE: The site in question was apparently finally put out of business]

Here is Google's stance on slander, defamation of character and other such things posted on web sites:

http://www.google.com/support/websearch/bin/request.py?contact_type=defamation1&ctx=contactpolicy

Recently someone contacted a fried of mine and sent a post on a web site which was anonymously posted and contained clearly made up, derogatory information. Many requests have been made to Google to remove the information and they are apparently not getting the requests or ignoring them.

Additionally, Google provides information on how to contact a web site's owner. However in the case of the above site, the site owner is hidden by GoDaddy's DomainsByProxy service. Therefore contacting them is virtually impossible. Contacting them via the web site does no good. Whomever is managing the site refuses to remove the information.

I understand the idea that Google cannot police the world and remove information from every bad web site in existence, however when information is clearly being posted about someone who doesn't want that information and they provide clear requests to Google and can prove that they are the person about whom the unwanted information has been posted, doesn't Google bear some responsibility, similar to how a newspaper may be liable for publishing inaccurate information?

Take the case of Annie Oakley - a newspaper organization published in newspapers around the country some defamatory information. She successfully sued and won in something like 23 out of 25 court cases around the US to get back her good name. The newspaper didn't make up the story, but they spread the story. By leaving these clearly unwanted and untrue pages posted in Google after someone requests they be removed, Google is aiding and abetting the web site owner in posting information that can hurt other peoples' reputations and lives.

As a side note, in the case of Annie Oakley, she wasted her life away trying to get back her good name and probably didn't do her a lot of good. It's probably just best to ignore the ridiculous things posted on the Internet because people who really know you will know the truth.

I understand it will be hard for Google to control every web site out there and we don't want them to really, but when the information is completely untrue and unwanted, can they not be a "good citizen" of the world and take it down? Wasn't Google's motto at one point "Don't Be Evil"?

Thursday, January 29, 2009

Mail Companies Not Receiving in TLS

Postini is now requiring mail companies to receive in TLS in order enforce TLS encryption. The interesting thing was they were advertising they supported TLS encryption and I had added some domains and tested it out and they went through, so I assumed those communications were secure.

Turns out what was really happening is that the messages were sent from the original mail company in TLS but then my mail provider only accepts via SMTP or SSL (which according to Postini is not really for mail but for web servers and I have heard that TLS is a newer, better version of SSL).

So anyway my mail was TLS from the sender to Postini and after that unencrypted - the whole time I thought it was secure.

Time for a new mail provider.

One of these days...someday...I will have secure email. There must be a way.

Tuesday, January 27, 2009

Government Information Technology - Amazing.

So in order to file wage reports for my company I have to fax a letter to the SSA authorizing myself, the owner, to file wage reports for the company before they will set me up in their online system. Does anyone else see how illogical this is? Since when is the owner of a company not allowed to file wage reports for a company?

Oh and they want me to fax it on letterhead. As if that is some kind of security. Isn't that something they used to do 20 years ago in the stone ages of the Internet?

Saturday, January 24, 2009

Spammers 1/24/2009

Road Runner is definitely the champion of spam if you view the traffic from the past few weeks. It seems that whomever is generating the Road Runner spam is randomly generating email addresses to try to find addresses that are not in use. It seems like they take an address that was once valid and alter it slightly to come up a with a new address.

For instance bill@microsoft.com might become ill@microsoft.com or tbill@microsoft.com

This kind of goes back to my idea that someone is trying to find addresses that are NOT valid on a network and send emails around that won't get to a legitimate end user but allows the "spammers" to filter these messages through the Internet. Is this some kind of covert messaging?

Another possible reason I conjured up was that perhaps they are taking previous email addresses that are now being rejected (with the help of Postini) and altering them to try to figure out what the address has changed to. Not sure - just imaging the reasons.

Or perhaps they are looking for unused addresses to try to use those addresses on unsecured mail systems to hijack the business of the other company.

As for Joe's Datacenter - someone responded to one email telling me they have gotten rid of the customer causing the spam. However it seems like the spam is not one customer but filtering through their different customers and IP ranges. Has one master device or computer been hacked? Is someone internally who supports all these systems generating this spam? Are the servers not patched and up to date? Who knows.

At any rate here are some spammers for the week:

75.127.101.248
OrgName: Global Net Access, LLC
NetRange: 75.127.64.0 - 75.127.127.255
Sat, 24 Jan 2009 14:41:37 -0800 (PST)
Sat, 24 Jan 2009 12:18:18 -0800 (PST)
Fri, 23 Jan 2009 09:15:20 -0800 (PST)

66.69.125.73
OrgName: Road Runner HoldCo LLC
NetRange: 66.68.0.0 - 66.69.255.255
Sat, 24 Jan 2009 13:10:33 -0800 (PST)

76.164.209.162
OrgName: R & D Technologies, LLC
NetRange: 76.164.192.0 - 76.164.239.255
Sat, 24 Jan 2009 12:41:39 -0800 (PST)
Sat, 24 Jan 2009 18:16:19 -0800 (PST)
Sat, 24 Jan 2009 22:23:51 -0800 (PST)
Sun, 25 Jan 2009 08:47:30 -0800 (PST)

208.94.240.219
Aarons.Net JOESDATACENTER (NET-208-94-240-0-1)
208.94.240.0 - 208.94.247.255
DataTran Systems, LLC. JDC-CUST-1173-240-209 (NET-208-94-240-208-1)
208.94.240.208 - 208.94.240.223
Sat, 24 Jan 2009 08:16:38 -0800 (PST)

208.94.244.30
Aarons.Net JOESDATACENTER (NET-208-94-240-0-1)
208.94.240.0 - 208.94.247.255
Provectus, Inc JDC-CUST-1101-244-1 (NET-208-94-244-0-1)
208.94.244.0 - 208.94.244.31
Fri, 23 Jan 2009 21:12:19 -0800 (PST)

208.85.3.23
OrgName: Turnkey Internet Inc.
NetRange: 208.85.0.0 - 208.85.7.255
Fri, 23 Jan 2009 21:12:19 -0800 (PST)
Fri, 23 Jan 2009 03:26:19 -0800 (PST)

72.12.80.251
OrgName: Oxford Networks
NetRange: 72.12.64.0 - 72.12.95.255
Thu, 22 Jan 2009 23:29:46 -0800 (PST)

207.36.1.66
Affinity Internet, Inc AFFINITY-207-36-0-0 (NET-207-36-0-0-1)
207.36.0.0 - 207.36.255.255
Affinity Dedicated AFFIN-DED-207-36-0 (NET-207-36-0-0-2)
207.36.0.0 - 207.36.8.255
Sun, 25 Jan 2009 00:33:59 -0800 (PST)

64.38.65.173
OrgName: Curatel, LLC
NetRange: 64.38.64.0 - 64.38.95.255
Sun, 25 Jan 2009 01:25:16 -0800 (PST)

64.150.180.60
OrgName: Abacus America Inc.
NetRange: 64.150.176.0 - 64.150.191.255
Sun, 25 Jan 2009 07:24:03 -0800 (PST)

NOTE: Abacus America has long been in the spammer IP range list - for years I have seen them send spam to my accounts. What is up over there?

38.98.244.88
OrgName: PSINet, Inc.
NetRange: 38.0.0.0 - 38.255.255.255
Sun, 25 Jan 2009 12:20:43 -0800 (PST)

NOTE: Cogentco is another network range that is notoriously generating spam of all kinds - from garbage traffic on my web server using various bots to spam in my in box. They are on the Performance Systems International network.

67.216.82.105
OrgName: Travail Systems, LLC
NetRange: 67.216.80.0 - 67.216.95.255
Sun, 25 Jan 2009 12:22:13 -0800 (PST)

Travail Systems continues to spam - repeatedly.

Mzima Networks, Inc. NETBLK-MZIMA-04 (NET-67-201-0-0-1)
67.201.0.0 - 67.201.63.255
Sirius Telecom MZIMA04-CUST-SIRIUSTELE04 (NET-67-201-20-0-1)
67.201.20.0 - 67.201.20.255


209.250.246.167
OrgName: RackVibe LLC
NetRange: 209.250.224.0 - 209.250.255.255
Sun, 25 Jan 2009 13:48:01 -0800 (PST)

Tuesday, January 20, 2009

Spammers This week

It appears that some spammers in Latin America are somehow targeting Gmail.

What is also interesting - I sent an abuse to Travail Systems below. I bcc'd myself at another email address. I did NOT get a copy of the abuse report.

Also the email address for support@turnkeyinternet.net apparently doesn't work. I sent an abuse message to them and it bounces.

Windstream's abuse email also fails:
This is an automatically generated Delivery Status Notification.
Delivery to the following recipients failed.
abuse@pmxbypass.windstream.com
I sent the abuse notice to abuse@windstream.com as directed by the Arin Windstream records.

Here are some other spammers:

24.59.64.55
OrgName: Road Runner HoldCo LLC
NetRange: 24.58.0.0 - 24.59.255.255
Tue, 20 Jan 2009 12:19:14 -0800 (PST)

63.223.125.89
OrgName: Beyond The Network America, Inc.
NetRange: 63.216.0.0 - 63.223.255.255
Tue, 20 Jan 2009 09:18:10 -0800 (PST)

64.208.60.90
OrgName: Global Crossing
NetRange: 64.208.0.0 - 64.209.127.255
Tue, 20 Jan 2009 08:41:40 -0800 (PST)

67.216.82.109
OrgName: Travail Systems, LLC
NetRange: 67.216.80.0 - 67.216.95.255
Tue, 20 Jan 2009 07:21:40 -0800 (PST)

67.205.109.27
OrgName: iWeb Technologies Inc.
NetRange: 67.205.64.0 - 67.205.127.255
Tue, 20 Jan 2009 06:55:01 -0800 (PST)

67.218.251.108
CAROLINANET a division of Guilford Communications Inc. GUILFORDCOMM-NETWORK-3 (NET-67-218-224-0-1)
67.218.224.0 - 67.218.255.255
Rashton Management RASHTON-MANAGEMENT (NET-67-218-251-0-1)
67.218.251.0 - 67.218.251.255
Tue, 20 Jan 2009 04:55:57 -0800 (PST)

12.130.137.155
AT&T WorldNet Services ATT (NET-12-0-0-0-1)
12.0.0.0 - 12.255.255.255
CERFnet ATTENS-SJC1-2 (NET-12-130-128-0-1)
12.130.128.0 - 12.130.191.255
Responsys ATTENS-010369-005186 (NET-12-130-137-0-1)
12.130.137.0 - 12.130.137.255
Tue, 20 Jan 2009 03:34:24 -0800 (PST)

208.85.3.60
OrgName: Turnkey Internet Inc.
NetRange: 208.85.0.0 - 208.85.7.255
Tue, 20 Jan 2009 03:10:55 -0800 (PST)
Mon, 19 Jan 2009 03:05:24 -0800 (PST)

207.29.231.80
OrgName: N.T. Technology, Inc.
NetRange: 207.29.224.0 - 207.29.255.255
Tue, 20 Jan 2009 00:54:57 -0800 (PST)

209.195.71.60
OrgName: Cybersurf Inc.
NetRange: 209.195.64.0 - 209.195.127.255
Mon, 19 Jan 2009 01:05:40 -0800 (PST)

148.84.103.88
OrgName: Lehman College
NetRange: 148.84.0.0 - 148.84.255.255
Tue, 20 Jan 2009 13:12:18 -0800 (PST)

67.213.215.223
OrgName: Hosting Services, Inc.
NetRange: 67.213.208.0 - 67.213.223.255
Mon, 19 Jan 2009 21:27:05 -0800 (PST)

63.223.125.119
OrgName: Beyond The Network America, Inc.
NetRange: 63.216.0.0 - 63.223.255.255
Mon, 19 Jan 2009 07:40:42 -0800 (PST)

208.101.34.32
OrgName: SoftLayer Technologies Inc.
NetRange: 208.101.0.0 - 208.101.63.255
Mon, 19 Jan 2009 06:08:40 -0800 (PST)

72.20.52.112
OrgName: Staminus Communications
NetRange: 72.20.0.0 - 72.20.63.255
Mon, 19 Jan 2009 00:53:04 -0800 (PST)

64.12.143.152
OrgName: America Online, Inc.
NetRange: 64.12.0.0 - 64.12.255.255
Tue, 20 Jan 2009 13:08:28 -0800 (PST)

24.59.64.55
OrgName: Road Runner HoldCo LLC
NetRange: 24.58.0.0 - 24.59.255.255
Tue, 20 Jan 2009 12:19:12 -0800 (PST)
Tue, 20 Jan 2009 12:18:58 -0800 (PST)
Tue, 20 Jan 2009 12:18:43 -0800 (PST)

69.106.224.158
AT&T Internet Services SBCIS-SIS80 (NET-69-104-0-0-1)
69.104.0.0 - 69.111.255.255
PLTN13 internal SBC06910622400020040415130719 (NET-69-106-224-0-1)
69.106.224.0 - 69.106.239.255
Tue, 20 Jan 2009 11:42:17 -0800 (PST)

205.188.249.131
OrgName: America Online, Inc
NetRange: 205.188.0.0 - 205.188.255.255
Tue, 20 Jan 2009 11:20:14 -0800 (PST)

71.218.44.227
OrgName: Qwest Communications Corporation
NetRange: 71.208.0.0 - 71.223.255.255
Tue, 20 Jan 2009 10:27:15 PST

174.130.41.206
OrgName: Windstream Communications Inc
NetRange: 174.130.0.0 - 174.131.255.255
Tue, 20 Jan 2009 15:35:23 -0800 (PST)

67.41.158.60
OrgName: Qwest Communications Corporation
NetRange: 67.40.0.0 - 67.42.255.255
Wed, 21 Jan 2009 21:28:40 -0800 (PST)

70.110.157.188
OrgName: Verizon Internet Services Inc.
NetRange: 70.109.192.0 - 70.111.255.255
Wed, 21 Jan 2009 21:26:29 -0800 (PST)


69.11.145.242
TDS TELECOM NETBLK-TDSNET-BLK (NET-69-11-128-0-1)
69.11.128.0 - 69.11.255.255
Scholars Academy QRTZAZ-SCHOLARS-TDSNET-NETBLK (NET-69-11-145-236-1)
69.11.145.236 - 69.11.145.255
Wed, 21 Jan 2009 20:26:44 -0800 (PST)

67.176.56.235
Comcast Cable Communications, Inc. COMCAST (NET-67-160-0-0-1)
67.160.0.0 - 67.191.255.255
Comcast Cable Communications, Inc COLORADO-14 (NET-67-176-0-0-1)
67.176.0.0 - 67.176.127.255
Wed, 21 Jan 2009 19:42:58 -0800 (PST)

204.133.215.98
Qwest Communications Corporation QWEST-INET-34 (NET-204-131-0-0-1)
204.131.0.0 - 204.134.255.255
ALLEN PARTNERS LLC Q0102-204-133-215-96 (NET-204-133-215-96-1)
204.133.215.96 - 204.133.215.103
Wed, 21 Jan 2009 19:23:20 -0800 (PST)

69.7.202.226
CIMCO Communications, Inc. CIMCO (NET-69-7-192-0-1)
69.7.192.0 - 69.7.223.255
Mr Bult's Inc MRBULTS1 (NET-69-7-202-224-1)
69.7.202.224 - 69.7.202.255
Wed, 21 Jan 2009 17:48:04 -0800 (PST)

74.67.167.126
OrgName: Road Runner HoldCo LLC
NetRange: 74.64.0.0 - 74.79.255.255
Wed, 21 Jan 2009 17:16:52 -0800 (PST)

70.251.240.31
AT&T Internet Services SBCIS-SIS80 (NET-70-240-0-0-1)
70.240.0.0 - 70.255.255.255
PPPoX Pool - Bras17 RCSNTX.912658 SBC07025124000023050815184827 (NET-70-251-240-0-1)
70.251.240.0 - 70.251.241.255

99.194.184.117
OrgName: CenturyTel Internet Holdings, Inc.
NetRange: 99.194.0.0 - 99.195.255.255
Wed, 21 Jan 2009 15:36:43 -0800 (PST)

97.82.255.36
Charter Communications NETBLK-CHARTER-NET (NET-97-80-0-0-1)
97.80.0.0 - 97.95.255.255
Charter Communications HCK-NC-97-82-192 (NET-97-82-192-0-1)
97.82.192.0 - 97.82.255.255
Wed, 21 Jan 2009 12:48:10 -0800 (PST)


69.109.163.215
AT&T Internet Services SBCIS-SIS80 (NET-69-104-0-0-1)
69.104.0.0 - 69.111.255.255
PLTNCA internal SBC06910916000020040526144923 (NET-69-109-160-0-1)
69.109.160.0 - 69.109.175.255
Wed, 21 Jan 2009 12:37:19 -0800 (PST)

68.16.221.212
OrgName: BellSouth.net Inc.
NetRange: 68.16.0.0 - 68.19.255.255
Wed, 21 Jan 2009 11:15:32 -0800 (PST)

67.14.243.208
OrgName: Primecast
NetRange: 67.14.224.0 - 67.14.255.255

69.86.20.17
EarthLink, Inc. ERLK-CBL-TW-NYC (NET-69-86-0-0-1)
69.86.0.0 - 69.86.255.255
EARTHLINK INC ERLK-TW-NYC55 (NET-69-86-16-0-1)
69.86.16.0 - 69.86.23.255
Wed, 21 Jan 2009 07:24:50 -0800 (PST)

71.50.209.121
OrgName: Embarq Corporation
NetRange: 71.48.0.0 - 71.55.255.255
Wed, 21 Jan 2009 05:19:19 -0800 (PST)

Monday, January 19, 2009

Spam Genereted From Contact IP Ranges

Ok so here's the deal. People email me. These are people I'm doing business with, working on projects with, etc. It seems like as soon as I get an email from someone I start getting spam from their mail server. Or perhaps (it seems like) valid mail messages are being swapped out with spam messages.

I've got Postini and set up Google Apps. I just met someone new and the guy tried to send me an email and said it was rejected by Postini due to being on my blocked IP spammer list. The guy sent me the email rejection notice and in it there was a mail server in Toronto Canada - that is not blocked. Later the guy sent me his home IP address. That address is also not blocked. Why the heck is this guy's email getting blocked?

Here's another one - I am working with a couple of guys. One of the guys is using 1 and 1 Internet. Somehow while working with these guys I get spam from 1 and 1 and block out that range, not realizing that this is the range used by the guys I'm working with.

Another one - working with a designer in Colorado. Suddenly I'm getting spam from her network. I block the range not realizing it's someone I'm working with.

Is this all purely coincidental? Really?

I swear it seems like someone is replacing valid messages with spam content. I don't really have the means to pin this down at the moment.

Additionally I keep contacting Google because Google Apps has never worked right with Postini. I swear they are not getting my messages. I've been trying to get this stuff working since November. I'm about to just cancel it.

Storm *bleep* er

So these guys are trying to supposedly protect you from yourselves:

http://blogs.zdnet.com/security/?p=2396&tag=nl.e550

Excuse me, but I'd rather you didn't divert my web traffic without my knowledge or installing things on my computers without my consent.

A better approach might be to somehow notify the users and/or the networks involved who have infected machines.

For instance if there's an infected computer at Internet, Look up the associated domain owner on whois.sc or the affected IP and contact the network from whence the nasty traffic is coming - or somehow otherwise alert the user that their computer is infected.

Additionally more PR could be done to let people know what is going on by contacting major newspapers and TV stations and provide information on how people can determine if their computers are infected.

Those would be a more reasonable steps to resolve this problem.

3.5m Hosts Affected by Conficker

The Conficker worm is spreading fast, as well as variations thereof. Is anyone not aware that they should be updating their software with the latest security patches by now?

Of interest also is that this worm sells supposed security software which in turn affects the computers. How ironic.

This is using the Trojan horse model of so-called security software that actually does the opposite of the purpose for which you purchased it. I mentioned this as a possible problem with security software in general in a previous post.

Friday, January 16, 2009

Bogus Traffic - Google Search Partners

We just turned on some ads for Google Search Partners and as it turns out the search partners generate .12% click rate for some words while Google search was generating a .03% click rate. This traffic was absolutely completely bogus. The words the people were clicking through on were completely unrelated to the site we were advertising for and somehow that word got added in there by one of Google's automated tools. We obviously quickly removed it. I have reported this issue to Google. Hopefully they will do something about it fast and return the money for the bogus clicks.

Thursday, January 15, 2009

premiuminterestscompany.cn - hacker site?

Just got a popup from my virus scanner that this site is hacked and is a "misleading application"

http://www.premiuminterestscompany.cn

Chinese domain.

Tuesday, January 13, 2009

Gmail Email Not Sending Securely

No surprise since Gmail is a free service but I just noticed messages are getting rejected from my other email system because Gmail doesn't sent via TLS and that is a requirement on my other email system - to force emails in to be sent securely.

Sunday, January 11, 2009

Recent Spammer IPs

Not including the international spammers which are easy to block out by blocking out all of Ripe, Apnic, Lacnic and Afrinic using Postini (see previous posts) here are some recent spammers. What is interesting is that over the years I keep seeing the same networks over and over again as primary offenders. Windstream Communications, McLeod, RoadRunner...these names come up over and over in conjunction with my spam logs. Are the spammers living in the areas where these networks exist...or is someone on their network staff the source of, or supporting the spammers? Or do these companies just not have a handle on their networks and are easily hacked by spammers since the spam looks similar to spam coming from all over the world?

71.30.191.140
Windstream Communications Inc WINDSTREAM-COMMUNICATIONS (NET-71-28-0-0-1)
71.28.0.0 - 71.31.255.255
Alltel - Sugar Land 71-30-176-0 (NET-71-30-176-0-1)
71.30.176.0 - 71.30.191.255

24.175.196.120
OrgName: Road Runner HoldCo LLC
NetRange: 24.174.0.0 - 24.175.255.255

75.176.78.236
OrgName: Road Runner HoldCo LLC
NetRange: 75.176.0.0 - 75.191.255.255

72.40.171.22

Earthlink, Inc. ERLK-CBL-TW-SOUTHEAST (NET-72-40-0-0-1)
72.40.0.0 - 72.40.255.255
EARTHLINK,INC ERLK-TW-TAMPABAY02 (NET-72-40-160-0-1)
72.40.160.0 - 72.40.175.255

71.160.116.227

Verizon Internet Services Inc.
VIS-BLOCK (NET-71-160-0-0-1)
71.160.0.0 - 71.161.63.255
VANESSA, KIM DSL (NET-71-160-116-224-1)
71.160.116.224 - 71.160.116.231

74.129.71.177
OrgName: INSIGHT COMMUNICATIONS COMPANY, L.P.
NetRange: 74.128.0.0 - 74.143.255.255

69.59.6.2
OrgName: Ygnition Networks, Inc.
NetRange: 69.59.0.0 - 69.59.15.255

70.94.31.189
OrgName: Road Runner HoldCo LLC
NetRange: 70.92.0.0 - 70.95.255.255

72.134.100.178
OrgName: Road Runner HoldCo LLC
NetRange: 72.128.0.0 - 72.135.255.255

24.205.232.15
Charter Communications CHARWR (NET-24-205-0-0-1)
24.205.0.0 - 24.205.255.255
Charter Communications CH-SLO-24-205-224-255 (NET-24-205-224-0-1)
24.205.224.0 - 24.205.255.255

71.72.60.112
OrgName: Road Runner HoldCo LLC
NetRange: 71.64.0.0 - 71.79.255.255

71.190.133.68
OrgName: Verizon Internet Services Inc.
NetRange: 71.181.128.0 - 71.191.255.255

207.191.218.118
OrgName: McLeodUSA Incorporated
NetRange: 207.191.192.0 - 207.191.223.255

72.183.35.81
OrgName: Road Runner HoldCo LLC
NetRange: 72.176.0.0 - 72.191.255.255

71.104.126.19
OrgName: Verizon Internet Services Inc.
NetRange: 71.96.0.0 - 71.127.255.255

98.113.14.251
OrgName: Verizon Internet Services Inc.
NetRange: 98.108.0.0 - 98.119.255.255

207.40.4.37
SprintSPRINTLINK-BLKR (NET-207-40-0-0-1)
207.40.0.0 - 207.43.255.255
Avalon Internet & Networking SPRINTLINK (NET-207-40-4-0-1)
207.40.4.0 - 207.40.4.255

70.127.1.45
OrgName: Road Runner HoldCo LLC
NetRange: 70.112.0.0 - 70.127.255.255

68.161.149.184
OrgName: Verizon Internet Services Inc.
NetRange: 68.160.0.0 - 68.163.255.255

OrgName: Road Runner HoldCo LLC
NetRange: 24.31.32.0 - 24.31.255.255

OrgName: Verizon Internet Services Inc.
NetRange: 71.169.192.0 - 71.173.63.255

64.208.60.7
OrgName: Global Crossing
NetRange: 64.208.0.0 - 64.209.127.255

OrgName: Road Runner HoldCo LLC
NetRange: 75.176.0.0 - 75.191.255.255

69.6.64.151
WholesaleBandwidth, Inc. WHOLE-2 (NET-69-6-0-0-1)
69.6.0.0 - 69.6.79.255
Media Breakaway, LLC MBL-BLK-69-6-64-0 (NET-69-6-64-0-1)
69.6.64.0 - 69.6.64.255

96.3.121.153
OrgName: Midcontinent Media, Inc.
NetRange: 96.2.0.0 - 96.3.255.255

208.82.112.141
OrgName: Network Data Center Host, Inc.
NetRange: 208.82.112.0 - 208.82.119.255

206.135.204.201
OrgName: MegaPath Networks Inc.
NetRange: 206.135.0.0 - 206.135.255.255

66.180.213.25
Martin Strauss Technologies, LLC STRAUSS-NETSPACE (NET-66-180-208-0-1)
66.180.208.0 - 66.180.223.255
TT Technology Partners, LLC. MSTL-UU5-TTTECH-VZ03 (NET-66-180-212-0-1)
66.180.212.0 - 66.180.213.255

207.29.228.146
OrgName: N.T. Technology, Inc.
NetRange: 207.29.224.0 - 207.29.255.255


WholesaleBandwidth, Inc. WHOLE-2 (NET-69-6-0-0-1)
69.6.0.0 - 69.6.79.255
Tekmailer.com TEK-BLK-69-6-19-0 (NET-69-6-19-0-1)
69.6.19.0 - 69.6.19.255

OrgName: CityNet
NetRange: 64.135.224.0 - 64.135.255.255

64.56.67.232
OrgName: Vrtservers, Inc
NetRange: 64.56.64.0 - 64.56.79.255

66.162.220.242
OrgName: tw telecom holdings, inc.
NetRange: 66.162.0.0 - 66.162.255.255

72.18.198.228
A+Hosting, Inc. PREMIANET (NET-72-18-192-0-1)
72.18.192.0 - 72.18.207.255
Blair Multimedia SERVERPOINT-CUSTOMER-BLAIRMULTIMEDIA02 (NET-72-18-198-166-1)
72.18.198.166 - 72.18.198.229

70.42.206.178
Internap Network Services Corporation PNAP-09-2005 (NET-70-42-0-0-1)
70.42.0.0 - 70.42.255.255
Martin Strauss Technologies, LLC INAP-MIA003-STRAUSS-23182 (NET-70-42-204-0-1)
70.42.204.0 - 70.42.207.255
TT Technology Partners, LLC. STRAUSS-INAP-BORDER5-TTTECH (NET-70-42-206-0-1)
70.42.206.0 - 70.42.206.255

207.154.32.89
OrgName: Hosted Solutions Acquisition, LLC
NetRange: 207.154.0.0 - 207.154.63.255

208.85.3.18
OrgName: Turnkey Internet Inc.
NetRange: 208.85.0.0 - 208.85.7.255

69.65.38.60
OrgName: GigeNET
NetRange: 69.65.0.0 - 69.65.63.255

24.55.189.18
Puerto Rico Cable Acquisition Company Inc. CHOICE-CM7 (NET-24-55-160-0-1)
24.55.160.0 - 24.55.191.255
Ponce Site- Choice Cable TV PONCE-NET-CPE-20 (NET-24-55-189-0-1)
24.55.189.0 - 24.55.190.255
64.208.60.5
OrgName: Global Crossing
NetRange: 64.208.0.0 - 64.209.127.255

66.63.178.213
OrgName: OC3 Networks & Web Solutions, LLC
NetRange: 66.63.160.0 - 66.63.191.255

216.185.52.93
OrgName: Alentus Corporation
NetRange: 216.185.32.0 - 216.185.63.255

208.94.243.180
OrgName: Aarons.Net
NetRange: 208.94.240.0 - 208.94.247.255

67.216.80.150
OrgName: Travail Systems, LLC
NetRange: 67.216.80.0 - 67.216.95.255

69.6.10.181
WholesaleBandwidth, Inc. WHOLE-2 (NET-69-6-0-0-1)
69.6.0.0 - 69.6.79.255
Media Breakaway, LLC MBL-BLK-69-6-10-0 (NET-69-6-10-0-1)
69.6.10.0 - 69.6.10.255

207.154.32.110
OrgName: Hosted Solutions Acquisition, LLC
NetRange: 207.154.0.0 - 207.154.63.255

216.139.195.188
OrgName: E Solutions Corporation
NetRange: 216.139.192.0 - 216.139.207.255

206.135.204.194
OrgName: MegaPath Networks Inc.
NetRange: 206.135.0.0 - 206.135.255.255

67.218.251.53
CAROLINANET a division of Guilford Communications Inc. GUILFORDCOMM-NETWORK-3 (NET-67-218-224-0-1)
67.218.224.0 - 67.218.255.255
Rashton Management RASHTON-MANAGEMENT (NET-67-218-251-0-1)
67.218.251.0 - 67.218.251.255

69.30.231.87
OrgName: WholeSale Internet, Inc.
NetRange: 69.30.192.0 - 69.30.255.255

208.91.133.84
NETRIPLEX LLC NETR-AVL-1 (NET-208-91-128-0-1)
208.91.128.0 - 208.91.135.255
Dimension 4 Networks LLC NETRIPLEX-AVL-208-91-133-0 (NET-208-91-133-0-1)
208.91.133.0 - 208.91.133.255

66.165.240.12
OrgName: Cyber World Internet Services, Inc.
NetRange: 66.165.224.0 - 66.165.255.255

207.29.231.72
OrgName: N.T. Technology, Inc.
NetRange: 207.29.224.0 - 207.29.255.255

96.225.229.87
OrgName: Verizon Internet Services Inc.
NetRange: 96.224.0.0 - 96.255.255.255

68.54.123.33
OrgName: Comcast Cable Communications, Inc.
NetRange: 68.32.0.0 - 68.63.255.255

24.103.190.191
OrgName: Road Runner HoldCo LLC
NetRange: 24.103.0.0 - 24.103.255.255

74.60.40.251
OrgName: Clearwire US LLC
NetRange: 74.60.0.0 - 74.61.255.255

68.191.222.48
Charter Communications CHARTER-NET-7BLK (NET-68-184-0-0-1)
68.184.0.0 - 68.191.255.255
Charter Communications DNT-TX-68-191-208 (NET-68-191-208-0-1)
68.191.208.0 - 68.191.223.255

12.186.102.94
AT&T WorldNet Services ATT (NET-12-0-0-0-1)
12.0.0.0 - 12.255.255.255
HORIZON WEST HEALTHCARE, INC HORIZON-96-102-88 (NET-12-186-102-88-1)
12.186.102.88 - 12.186.102.95

162.89.0.47
OrgName: City of Austin, Texas
NetRange: 162.89.0.0 - 162.89.255.255

71.175.45.36
OrgName: Verizon Internet Services Inc.
NetRange: 71.173.96.0 - 71.180.255.255

24.152.209.113
OrgName: PenTeleData Inc. - Cable
NetRange: 24.152.192.0 - 24.152.255.255

208.181.172.39
TELUS Communications Inc. TELAC-BLK5 (NET-208-181-0-0-1)
208.181.0.0 - 208.181.255.255
Irenyx Data Group Inc. (Digital Ark) IRENYX-CA (NET-208-181-172-0-1)
208.181.172.0 - 208.181.173.255

71.94.2.117
Charter Communications NETBLK-CHARTER-NET (NET-71-80-0-0-1)
71.80.0.0 - 71.95.255.255
Charter Communications REN-NV-71-94-0 (NET-71-94-0-0-1)
71.94.0.0 - 71.94.31.255

76.181.213.174
OrgName: Road Runner HoldCo LLC
NetRange: 76.181.0.0 - 76.181.255.255

65.182.200.112
OrgName: Hosting.com, Inc.
NetRange: 65.182.192.0 - 65.182.223.255

72.236.19.121
Level 3 Communications, Inc. LVLT-ORG-72-236 (NET-72-236-0-0-1)
72.236.0.0 - 72.237.255.255
Sabre Technologies, Inc. TELCOVE-KMCSVNH-SABRE (NET-72-236-19-0-1)
72.236.19.0 - 72.236.19.255

207.158.45.92
American Internet Services, LLC. AIS-WEST2 (NET-207-158-0-0-1)
207.158.0.0 - 207.158.63.255
Quexion LLC AIS-QUEXION-NETBLK1 (NET-207-158-45-0-1)
207.158.45.0 - 207.158.45.255

128.177.32.53
OrgName: Abovenet Communications, Inc
NetRange: 128.177.0.0 - 128.177.255.255

208.86.252.174
OrgName: NEXCESS.NET L.L.C.
NetRange: 208.86.248.0 - 208.86.255.255

71.34.22.123
OrgName: Qwest Communications Corporation
NetRange: 71.32.0.0 - 71.39.255.255

69.107.113.62
AT&T Internet Services SBCIS-SIS80 (NET-69-104-0-0-1)
69.104.0.0 - 69.111.255.255
PLTN13 internal SBC06910711200020040415135102 (NET-69-107-112-0-1)
69.107.112.0 - 69.107.127.255

67.79.170.12
OrgName: Road Runner HoldCo LLC
NetRange: 67.78.0.0 - 67.79.255.255

138.89.215.194
OrgName: Verizon Internet Services Inc.
NetRange: 138.89.0.0 - 138.89.255.255

74.211.85.199
OrgName: Baja Broadband
NetRange: 74.211.0.0 - 74.211.95.255

65.35.64.243
OrgName: Road Runner HoldCo LLC
NetRange: 65.35.0.0 - 65.35.255.255

70.106.208.125
OrgName: Verizon Internet Services Inc.
NetRange: 70.106.0.0 - 70.109.127.255

96.36.137.107
Charter Communications NETBLK-CHARTER-NET (NET-96-32-0-0-1)
96.32.0.0 - 96.42.255.255
Charter Communications CMP-NC-96-36-128 (NET-96-36-128-0-1)
96.36.128.0 - 96.36.159.255

63.243.120.2
PaeTec Communications, Inc. PAETECCOMM (NET-63-243-0-0-1)
63.243.0.0 - 63.243.127.255
Netacie Inc NET47656 (NET-63-243-120-0-1)
63.243.120.0 - 63.243.121.255

76.171.214.56
OrgName: Road Runner HoldCo LLC
NetRange: 76.168.0.0 - 76.175.255.255

207.119.71.188
OrgName: CenturyTel Internet Holdings, Inc.
NetRange: 207.118.0.0 - 207.119.255.255

141.157.241.56
Verizon Internet Services Inc. VIS-141-149 (NET-141-149-0-0-1)
141.149.0.0 - 141.158.255.255
Verizon Internet Services VZ-DSLDIAL-NYCMNY-14 (NET-141-157-192-0-1)
141.157.192.0 - 141.157.255.255

67.166.95.53
Comcast Cable Communications, Inc. COMCAST (NET-67-160-0-0-1)
67.160.0.0 - 67.191.255.255
Comcast Cable Communications, Inc. OREGON-12 (NET-67-166-80-0-1)
67.166.80.0 - 67.166.95.255

69.14.214.163
OrgName: WideOpenWest Finance LLC
NetRange: 69.14.0.0 - 69.14.255.255

76.251.95.218
AT&T Internet Services SBCIS-SBIS-6BLK (NET-76-192-0-0-1)
76.192.0.0 - 76.255.255.255
ACTIVE ATHLETE MEDIA-070925215520 SBC-76-251-95-216-29-0709255532 (NET-76-251-95-216-1)
76.251.95.216 - 76.251.95.223

76.120.202.3
Comcast Cable Communications, Inc. JUMPSTART-5 (NET-76-96-0-0-1)
76.96.0.0 - 76.127.255.255
Comcast Cable Communications, Inc. E-TENNESSEE-11 (NET-76-120-192-0-1)
76.120.192.0 - 76.120.255.255

64.150.158.153
HTC Communications, LLC HTCC (NET-64-150-128-0-1)
64.150.128.0 - 64.150.159.255
HTC - DSL Modem Pool HTC-64-150-158-0-24 (NET-64-150-158-0-1)
64.150.158.0 - 64.150.158.255

96.246.121.182
OrgName: Verizon Internet Services Inc.
NetRange: 96.224.0.0 - 96.255.255.255

74.95.150.81
Comcast Business Communications, Inc. CBC-CM-4 (NET-74-92-0-0-1)
74.92.0.0 - 74.95.255.255
Comcast Business Communications, Inc. HOUSTON-CBC-1 (NET-74-95-148-0-1)
74.95.148.0 - 74.95.151.255
Paloma Resources PALOMA-RESOURCES (NET-74-95-150-80-1)
74.95.150.80 - 74.95.150.87

67.204.201.242
PERSONA COMMUNICATIONS INC. PERS-CENTRAL (NET-67-204-192-0-1)
67.204.192.0 - 67.204.255.255
Persona Communications PERSONA-CEN-SUDBURY (NET-67-204-192-0-2)
67.204.192.0 - 67.204.207.255

151.213.146.241
OrgName: Windstream Communications Inc
NetRange: 151.213.0.0 - 151.213.255.255

216.254.239.75
PrairieWave Telecommunications, Inc. 216-254-224-0-1 (NET-216-254-224-0-1)
216.254.224.0 - 216.254.255.255
PrairieWave Cable Modem DHCP CMDB-216-254-239-0 (NET-216-254-239-0-1)
216.254.239.0 - 216.254.239.255

207.102.144.67
WestNet, Inc. WESTNET-W5 (NET-206-206-0-0-1)
206.206.0.0 - 206.207.255.255
Arizona Tri-University Network (ASU, UA, NAU) WEST-206-207-128-ARIZ (NET-206-207-128-0-1)
206.207.128.0 - 206.207.255.255
Embry-Riddle Aeronautical Univeristy ERAU (NET-206-207-155-0-1)
206.207.155.0 - 206.207.159.255

71.194.215.247
Comcast Cable Communications, Inc. ATT-COMCAST (NET-71-192-0-0-1)
71.192.0.0 - 71.207.255.255
Comcast Cable Communications, Inc. ILLINOIS-24 (NET-71-194-0-0-1)
71.194.0.0 - 71.194.255.255

67.214.82.158
TEL WEST COMMUNICATIONS LLC TELWEST-BLK (NET-67-214-64-0-1)
67.214.64.0 - 67.214.95.255
Lustig Orthodontics - FT Worth TELWE-CUST-67-214-82-156 (NET-67-214-82-156-1)
67.214.82.156 - 67.214.82.159

98.27.246.240
OrgName: Road Runner HoldCo LLC
NetRange: 98.24.0.0 - 98.31.255.255

206.253.55.111
OrgName: Pioneer Long Distance
NetRange: 206.253.32.0 - 206.253.63.255

71.134.247.244
AT&T Internet Services SBCIS-SIS80 (NET-71-128-0-0-1)
71.128.0.0 - 71.159.255.255
PPPoX Pool - bras18a.pltnca SBCIS-111705083239 (NET-71-134-240-0-1)
71.134.240.0 - 71.134.255.255

216.14.119.83
OrgName: EBOUNDHOST.com
NetRange: 216.14.112.0 - 216.14.127.255

64.221.90.86
OrgName: XO Communications
NetRange: 64.220.0.0 - 64.221.255.255

75.77.96.168
OrgName: NuVox Communications, Inc.
NetRange: 75.77.0.0 - 75.77.255.255

173.110.223.103
OrgName: Sprint PCS
NetRange: 173.96.0.0 - 173.117.255.255

75.91.239.21
OrgName: Windstream Communications Inc
NetRange: 75.88.0.0 - 75.91.255.255

69.65.38.60
OrgName: GigeNET
NetRange: 69.65.0.0 - 69.65.63.255

216.49.123.172
OrgName: Perry-Spencer Communications, Inc.
NetRange: 216.49.96.0 - 216.49.127.255

iWeb Technologies Inc. IWEB-BLK-03 (NET-72-55-128-0-1)
72.55.128.0 - 72.55.191.255
iWeb Dedicated CL IWEB-CL-T058-01SH (NET-72-55-156-32-1)
72.55.156.32 - 72.55.156.63

72.20.52.118
OrgName: Staminus Communications
NetRange: 72.20.0.0 - 72.20.63.255

66.197.221.69
OrgName: Network Operations Center Inc.
NetRange: 66.197.128.0 - 66.197.255.255

69.50.84.151
OrgName: Cynergycomm.net, Inc
NetRange: 69.50.80.0 - 69.50.95.255

74.189.93.50
OrgName: BellSouth.net Inc.
NetRange: 74.160.0.0 - 74.191.255.255

99.225.236.10
OrgName: Rogers Cable Communications Inc.
NetRange: 99.224.0.0 - 99.255.255.255

68.121.242.112
OrgName: AT&T Internet Services
NetRange: 68.120.0.0 - 68.127.255.255

24.27.25.212
OrgName: Road Runner HoldCo LLC
NetRange: 24.24.0.0 - 24.29.255.255

Rogers Cable Communications Inc. ROGERS-CAB-100 (NET-208-97-64-0-1)
208.97.64.0 - 208.97.127.255
REMAX York Mills REMAX (NET-208-97-88-120-1)
208.97.88.120 - 208.97.88.127

76.83.124.83
OrgName: Road Runner HoldCo LLC
NetRange: 76.80.0.0 - 76.95.255.255

76.17.193.148
Comcast Cable Communications, Inc. WESTERN-1 (NET-76-16-0-0-1)
76.16.0.0 - 76.31.255.255
Comcast Cable Communications, Inc. MINNESOTA-10 (NET-76-17-128-0-1)
76.17.128.0 - 76.17.255.255

173.67.18.140
OrgName: Verizon Internet Services Inc.
NetRange: 173.64.0.0 - 173.79.255.255

207.225.26.53
OrgName: Qwest Communications Corporation
NetRange: 207.224.0.0 - 207.225.255.255

216.139.100.115
OrgName: Grand River Mutual Telephone Corporation
NetRange: 216.139.96.0 - 216.139.127.255

64.12.143.152
OrgName: America Online, Inc.
NetRange: 64.12.0.0 - 64.12.255.255

216.96.105.218
Windstream Communications Inc WINDSTREAM (NET-216-96-0-0-1)
216.96.0.0 - 216.96.127.255
Elyria Ford 216-96-105-216 (NET-216-96-105-216-1)
216.96.105.216 - 216.96.105.223

12.214.181.116
AT&T WorldNet Services ATT (NET-12-0-0-0-1)
12.0.0.0 - 12.255.255.255
Mediacom Communications Corp MEDIACOMCC-12-214-128-0-ILLINOIS (NET-12-214-128-0-1)
12.214.128.0 - 12.214.191.255

204.188.164.91
Savvis SAVVIS (NET-204-188-144-0-1)
204.188.144.0 - 204.188.191.255
Cable & Wireless Antigua CW-204-188-160 (NET-204-188-160-0-1)
204.188.160.0 - 204.188.175.255
Cable & Wiresles Tortola CWAG-204-188-164-0 (NET-204-188-164-0-1)
204.188.164.0 - 204.188.164.255

66.235.61.5
Broadstripe MDM-BLOCK-1 (NET-66-235-0-0-1)
66.235.0.0 - 66.235.63.255
Millennium Digital Media SEATTLE-MILLENNIUM-DIGITAL-MEDIA (NET-66-235-61-0-1)
66.235.61.0 - 66.235.61.255

66.152.140.5
OrgName: PenTeleData Inc.
NetRange: 66.152.128.0 - 66.152.159.255

204.186.29.156
OrgName: PenTeleData Inc.
NetRange: 204.186.0.0 - 204.186.255.255

66.76.20.130
OrgName: Suddenlink Communications
NetRange: 66.76.0.0 - 66.76.255.255

66.249.52.10
OrgName: Mebtel Communications
NetRange: 66.249.32.0 - 66.249.63.255

70.135.126.124
AT&T Internet Services SBCIS-SIS80 (NET-70-128-0-0-1)
70.128.0.0 - 70.143.255.255
PPPoX Pool - bras4.skt2ca SBCIS-110205121845 (NET-70-135-112-0-1)
70.135.112.0 - 70.135.127.255

68.115.160.210
Charter Communications CHARTER-NET-6BLK (NET-68-112-0-0-1)
68.112.0.0 - 68.119.255.255
Charter Communications ASH-CBN-68-115-160-0-20 (NET-68-115-160-0-1)
68.115.160.0 - 68.115.175.255

72.87.168.208
OrgName: Verizon Internet Services Inc.
NetRange: 72.87.64.0 - 72.92.127.255

98.140.80.65
OrgName: Cavalier Telephone
NetRange: 98.140.0.0 - 98.141.255.255

208.53.136.239
FDCservers.net
NetRange: 208.53.128.0 - 208.53.191.255

Liberty Cablevision of Puerto Rico LTD LIBERTYPR (NET-24-138-192-0-1)
24.138.192.0 - 24.138.255.255
Liberty Cablevision - Caguas LIBERTYPR (NET-24-138-192-0-2)
24.138.192.0 - 24.138.203.255

Thursday, January 08, 2009

OpenSSL Hack - SSL Spoofing

More SSL certificate problems: http://secunia.com/advisories/33338/

OpenSSL hack allows spoofing a secure web site would be possible. In other words you think you're logging into a secure site but you're actually logging into an impostor...

Redhat published a fix for OpenSSL:

http://secunia.com/advisories/33442/

So did FreeBSD:

http://secunia.com/advisories/33445/

Saturday, January 03, 2009

Microsoft Password Expiration Issue

I have figured out that when your password is expiring, each time you logout via Terminal Services, it decrements the days until you have to reset the password, instead of decrementing it at the end of each day.

What that means is, if I have a time limit on remote logins and I'm logging in and out all day long then it keeps decrementing the password expiration days so I have to create a new password sooner than should actually be required.

Weird Referral Links in Web Requests

We're getting weird sites referring us traffic. Today I got some traffic from this url:

http://salondirectory.com

Apparently this site is linking to our site which has absolutely nothing to do with salons. I believe the links are being put there for search engine spam reasons - maybe to get rankings via linking to credible sites. Otherwise - I have no idea why a salon web site is linking to a totally unrelated type of site.

The traffic came from Comcast:
24.22.220.185 at 1/3/2009 8:50:07 PM PST

We got another request referred by this site:
http://quick-cash-secret.votelah.com
from 202.184.124.13 at 1/3/2009 7:59:34 PM PST

Here's a really odd one:
stream://1/
from 216.231.44.147 at 1/3/2009 9:18:40 AM

And this one
http://www.alivelocal.com/jump2

We are not putting our site on all these other weird sites - not sure how it is getting there or why.

NaverBot - BadBot

NaverBot is a bad bot that is not obeying robots.txt.

http://help.naver.com/customer_webtxt_02.jsp

WebDataCentreBot - Bad Bot

WebDataCentreBot does not obey robots.txt.

AISearchBot - Bad Bot

This is what the AISearchBot looks like:

AISearchBot (Email: aisearchbot@gmail.com; If your web site doesn't want to be crawled, please send us a email.)

This is a bad bot because rather than post a page where you can find out how to exclude them from hitting your site in a standard web through robots.txt, they try to get you to send them your email address and by so doing reveal your IP address as well. Hopefully they will fix this and provide standard instructions for robots.txt in the near future.

December 2008 Bots

This summary is not available. Please click here to view the post.

Friday, January 02, 2009

Unpatched IE 6 Bugs

Here are a list of unpatched or "partially fixed" bugs in IE6 according to Secunia.com. Some of these date back to 2003. Though some of considered only slightly problematic or slight chance and hence seems like they were not patched, some of the bugs in this list could cause a lot of problems if they happen to a particular user.

Additionally I found it interesting that Secunia lists a higher percentage of "advisories" unpatched in IE7. However going through the whole list of items for IE7 there are only 9 unpatched items compared to over 20 below. I would conclude based on that, the traffic I have mentioned in previous posts that looks a bit odd, and just by comparing the different types of bugs outstanding that IE7 is a much better browser choice if concerned about security.

Unpatched IE6 Bug - FTP Injection

IE 6 may disclose sensitive information with OnKeyDown event

Printing table of links from IE6 or IE7

IE6 and IE7 FTP credentials exposure

IE6 allows faking a URL in the address bar

Internet Explorer 6 or 7 File Upload Form Keystroke Event Cancel Vulnerability

IE6 hidden network share weakness

IE5 and IE6 Drag and Drop Vulnerability

IE6 - Trick a use to go to a malicious site

IE6 - XMLHTTP HTTP Request Injection

IE6 - Microsoft Internet Explorer Dialog Origin Spoofing Vulnerability


IE6 Microsoft Internet Explorer Popup Title Bar Spoofing Weakness



IE6 Internet Explorer Global Variables Local File Detection Weakness


IE6 - Window Injection Vulernability

IE6 - save as picture download spoofing - trick users into downloading malicious files

IE6 - cookie vulnerability
Note this bug says partially fixed.

IE6 - bypass file download security warning and save as displays different file extension than actual


Internet Explorer Flash/Excel Content Status Bar Spoofing Weakness


IE6 - Detect the presence of local files
(partial fix)

IE6 - cross domain cookie vulnerability

IE5 & IE6 address bar - faking urls
(partial fix)

IE6 - create popup content overlay
(partial fix)

IE6 bug - fake urls (partial fix)

IE6 - Cross frame scripting restriction bypass

IE6 - Internet Explorer File Identification Variant

IE6 - Exposure of Installed Components

IE6 - Internet Explorer Custom HTTP Error Script Injection Vulnerability (partial fix)

IE6 - Exposes sensitive information (partial fix)

Dell Ships with IE6

This is interesting - Dell ships XP computers with IE6 that is known to be far less secure than IE7. Why? Don't they care about the security of their customers?

Dell ships with insecure browser

IE6 Traffic - Not from IE6 Browser

Something odd happened today. A person reported getting a message we display to people who have old browsers. The person sent the error message in question. When I looked up the traffic in our logs the traffic indicated the user was visiting the site with an IE6 browser. However the person says she doesn't use IE and doesn't want to use IE. The only traffic from this particular IP address was all from IE browsers and nothing else.

So what is going on here? Potentially we have a bug in our software, however I have not seen this error myself before. What I think is probably happening is that there's some sort of caching software on the network this person is using and when they came to the site they got some page that was cached by some previous visitor who was using an IE6 browser. The other option is that this person has some sort of malware or web add-on that is somehow making her traffic look like it's coming from an IE6 browser when it is not.

If there was actually caching software that was causing this problem, however, then why was I able to find in my logs the exact request matching hers that resulted in this message? If the page was cached somewhere I shouldn't be seeing her request in my logs at all would I?

So was there a computer between her computer and my server that is intercepting requests, passing it to our server, viewing the content, and then passing it back to the user's machine? That seems like what is probably happening but how can I know for sure? In that case, let's say you were contacting your bank. This intermediary would be doing screen shots of every web page you visit. If this intermediary software was one machine intercepting all the requests, I would also expect to only see one user agent coming to that site from that IP address - but I saw multiple - and they were all IE browsers. This person says she doesn't use IE because she doesn't like it.

Hmmm. What's up? More evidence of very suspicious IE6 traffic and doubtful that most of the IE traffic out there is legit.