Re: What is this?
Available news archives: comp.lang.tcl - comp.lang.python - comp.security.firewalls - sci.crypt - comp.lang.php - comp.lang.javascript
Google
 
Web news.hping.org


comp.security.firewalls archive

Re: What is this?

From: Anders <andersajja@hotmail.com>
Date: Sun Sep 25 2005 - 12:55:42 CEST

Moe Trin wrote:
> In the Usenet newsgroup comp.security.firewalls, in article
> <tvhZe.146969$dP1.503923@newsc.telia.net>, Anders wrote:
>
snip
>
> I already do. They also have a few other address blocks, like
>
> 4.20.90.0 - 4.20.90.255 206.98.113.0 - 206.98.113.255
> 63.175.174.0 - 63.175.175.255 206.191.128.0 - 206.191.191.255
> 63.251.0.0 - 63.251.255.255 206.229.153.0 - 206.229.153.255
> 64.74.0.0 - 64.74.255.255 206.253.192.0 - 206.253.223.255
> 64.94.0.0 - 64.95.255.255 208.33.216.0 - 208.33.219.255
> 65.209.66.0 - 65.209.66.255 208.146.32.0 - 208.146.47.255
> 66.150.0.0 - 66.151.255.255 209.191.128.0 - 209.191.191.255
> 69.25.0.0 - 69.25.255.255 212.118.224.0 - 212.118.255.255
> 69.25.12.0 - 69.25.13.255 216.52.0.0 - 216.52.255.255
> 72.5.0.0 - 72.5.159.255 216.223.0.0 - 216.223.63.255
> 206.64.105.0 - 206.64.105.255
>

   69.25.0.0 - 69.25.255.255
   69.25.12.0 - 69.25.13.255

It looks to me that this two IP rangeīs doing the same job, or am I
wrong? Any way they are in my own blocklist now.

>
snip
>
> Sorry - didn't mean for you to try to download those newsgroups. What I
> was suggesting was using http://groups.google.com and going to the
> Advanced Group Search function. Out the words 'Internap' and / or 'PNAP' as
> the term to search for in those news groups.
>
> Results 1 - 10 of 434 from Jan 1, 2005 to Sep 24, 2005
> for Internap group:news.admin.net-abuse.* (0.14 seconds)
>
> Results 1 - 10 of 136 from Jan 1, 2005 to Sep 24, 2005
> for PNAP group:news.admin.net-abuse.* (0.14 seconds)
>

      Results 1 - 10 of 9 710 for (Internap). (0,26 seconds)

      Results 1 - 10 of 5 730 for "PNAP" (0,16 seconds)

As you stated before they realy donīt have the greatest reputation.

>
snip
>
> I looked at your headers, and it said:
>
>
>>User-Agent: Mozilla Thunderbird 1.0.6 (X11/20050912)
>
>
> If you are running X, you are probably using a *nix. Not all come with
> tcpdump, but it's fairly common. 'nmap' - yeah, that's less common.
>
> Old guy

I have tcpdump, both on my Linux (desktop) and my BSD (firewall), did
look at the tcpdump -i on my desktop while I was checking out my
firewall and it com up with almost ridiculous much information. I think
I gonna take a look at my firewall later this day just for the fun of
it, checking the var log.

Regards and ones again thank you for the time taken.

Anders
Received on Thu Sep 29 20:10:49 2005