Security Incidents mailing list archives
Re: 216.65.124.73 / sexwebsites.com admin
From: rginski () CO PINELLAS FL US (Richard Ginski)
Date: Wed, 24 May 2000 16:24:47 -0400
As a matter of fact, we brought this issue up to incidents () securityfocus com. We currently reset any connection
attempts from our network to this address, 216.65.124.73. Below is some info you may be interested in. We have seen
many different destination ports being used. This is just an example:
Source Address: our.ip.address.
Source Port: 1035
Source MAC Address: our mac address
Destination Address: 216.65.124.73
Destination Port: 524
Destination MAC Address: 00:90:27:0E:3D:65
Protocol: TCP (6)
We have also had an incident in which we suspect DNS cache poisoning. We would enter an internal URLl and would be
re-directed to this site. Would you know anything about this? We're trying to find out why both of these incidents seem
to have this single IP address in common (216.65.124.73) ?
spanno <dan () SPANNO COM> 05/23/00 01:58PM >>>
hi,
This is a server I admin for sexwebsites.com - it is a
free hosting service for adult sites. Is this trojan making
http requests to my server ? if so I'd like to see them then
I can trace and terminate what account it is.
I am interested to find if this is a DoS attack against my
server or some kind of scam, I would appreciate if anyone
has packet logs to send them and if theres anything anyone
needs help from me with please just e-mail: dan () spanno com
dan
Current thread:
- 216.65.124.73 / sexwebsites.com admin spanno (May 23)
- <Possible follow-ups>
- Re: 216.65.124.73 / sexwebsites.com admin Richard Ginski (May 24)
