Security Incidents mailing list archives

Re: 216.65.124.73 / sexwebsites.com admin


From: rginski () CO PINELLAS FL US (Richard Ginski)
Date: Wed, 24 May 2000 16:24:47 -0400


As a matter of fact, we brought this issue up to incidents () securityfocus com. We currently reset any connection 
attempts from our network to this address, 216.65.124.73. Below is some info you may be interested in. We have seen 
many different destination ports being used. This is just an example:

        Source Address: our.ip.address.
        Source Port: 1035
        Source MAC Address: our mac address
        Destination Address: 216.65.124.73
        Destination Port: 524
        Destination MAC Address: 00:90:27:0E:3D:65
        Protocol: TCP (6)
         

We have also had an incident in which we suspect DNS cache poisoning. We would enter an internal URLl and would be 
re-directed to this site. Would you know anything about this? We're trying to find out why both of these incidents seem 
to have this single IP address in common (216.65.124.73) ?

spanno <dan () SPANNO COM> 05/23/00 01:58PM >>>
hi,

    This is a server I admin for sexwebsites.com - it is a 
free hosting service for adult sites. Is this trojan making 
http requests to my server ? if so I'd like to see them then 
I can trace and terminate what account it is. 

I am interested to find if this is a DoS attack against my 
server or some kind of scam, I would appreciate if anyone 
has packet logs to send them and if theres anything anyone 
needs help from me with please just e-mail: dan () spanno com 

dan


Current thread: