Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos network security services platform







Full Disclosure: Re: Strange connection from google desktop search

Re: Strange connection from google desktop search

From: Steve R <steve_r125_at_yahoo.co.uk>
Date: Sun, 6 Mar 2005 05:06:34 +0000 (GMT)

--- RandallM <randallm_at_fidmail.com> wrote:
> The following established connection was noticed:
> TCP xxx.xxx.x.xx:2869 64.233.187.104:80
> ESTABLISHED 2824
>
> Process viewer reported it to be:
> Googledesktop.exe
>
> SamSpade says:
>
> 03/05/05 21:54:31 whois 64.233.187.104
> I don't recognise any domain in 187.104, trying
> internic
>
> whois -h whois.internic.net 187.104 ...
>
> Whois Server Version 1.3
>
> Domain names in the .com and .net domains can now be
> registered
> with many different competing registrars. Go to
> http://www.internic.net
> for detailed information.
>
> No match for "187.104".
>
> 03/05/05 22:07:21 finger @ 64.233.187.104
> finger @ 64.233.187.104 failed, no such host
>
> 03/05/05 22:07:47 dns 64.233.187.104
> No DNS for this address
> (host doesn't exist)

FYI,

Output from ARIN WHOIS
Search results for: 64.233.187.104

OrgName: Google Inc.
OrgID: GOGL
Address: 2400 E. Bayshore Parkway
City: Mountain View
StateProv: CA
PostalCode: 94043
Country: US

NetRange: 64.233.160.0 - 64.233.191.255
CIDR: 64.233.160.0/19
NetName: GOOGLE
NetHandle: NET-64-233-160-0-1
Parent: NET-64-0-0-0-0
NetType: Direct Allocation
NameServer: NS1.GOOGLE.COM
NameServer: NS2.GOOGLE.COM
Comment:
RegDate: 2003-08-18
Updated: 2004-03-05

TechHandle: ZG39-ARIN
TechName: Google Inc.
TechPhone: +1-650-318-0200
TechEmail: arin-contact_at_google.com

OrgTechHandle: ZG39-ARIN
OrgTechName: Google Inc.
OrgTechPhone: +1-650-318-0200
OrgTechEmail: arin-contact_at_google.com

# ARIN WHOIS database, last updated 2005-03-05 19:10
# Enter ? for additional hints on searching ARIN's
WHOIS database.

Send instant messages to your online friends http://uk.messenger.yahoo.com
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html
Received on Mar 06 2005

[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]