Author
Message
Oea
Guest
[SOURCE/META] Dana's, Ladybee's.. IP Address Okay, I sent an email to both ladybee and dana with an embedded pic on my webserver
Here are the two hits i got following that
63.207.101.109 - - [28/Jul/2004:09:25:22 -0700] "GET /BEEWITHH.GIF HTTP/1.1" 200 6789
Resolves to adsl-63-207-101-109.dsl.snfc21.pacbell.net
Traceroute
1 17 ms 19 ms 19 ms 68.121.55.254
2 19 ms 19 ms 19 ms dist1-vlan50.scrm01.pbi.net [64.171.152.66]
3 19 ms 19 ms 19 ms bb1-g8-3-0.scrm01.pbi.net [64.171.152.247]
4 19 ms 19 ms 17 ms bb2-p12-0.scrm01.sbcglobal.net [151.164.188.126]
5 19 ms 19 ms 19 ms bb2-p14-3.snfc21.sbcglobal.net [151.164.188.137]
6 19 ms 19 ms 19 ms dist1-vlan30.snfc21.pbi.net [209.232.130.59]
7 19 ms 19 ms 19 ms rback30-fe2-0.snfc21.pbi.net [206.171.134.161]
8 29 ms 29 ms 29 ms adsl-63-207-101-109.dsl.snfc21.pacbell.net [63.2
07.101.109]
Trace complete.
The other might not be someone from ,teh arg, but worth noting:
68.121.54.134 - - [28/Jul/2004:09:31:43 -0700] "SEARCH /\x90\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\
xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\
xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\
xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\
xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\
xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\
xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\x
An Irvine, CA ip. I know for sure that tne SNFC is someone who has to do with the ARG, probably Dana, I'm not sure..
Post more info you find with this info here
Oea
** edited to allow the Longest String Evar to be properly formatted. Also, added a label. LABELS = GOOD -- jamesi
Posted: Wed Jul 28, 2004 6:16 pm
Oea
Guest
MOre info! Just got both these requests, again from a snfc pacbell IP
68.121.209.62 - - [28/Jul/2004:13:42:12 -0700] "OPTIONS / HTTP/1.1" 200 -
68.121.209.62 - - [28/Jul/2004:13:42:12 -0700] "OPTIONS / HTTP/1.1" 200 -
Posted: Wed Jul 28, 2004 6:22 pm
SpaceBass
The BADministrator
Joined: 20 Sep 2002 Posts: 2701 Location: pellucidar
Re: [SOURCE/META] Dana's, Ladybee's.. IP Address
Oea wrote:
The other might not be someone from ,teh arg, but worth noting:
68.121.54.134 - - [28/Jul/2004:09:31:43 -0700] "SEARCH /\x90\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\
xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\
xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\
xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\
xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\
xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\
xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\x
Um, yea. That's likely just some worm trying to exploit a server vulnerability. No need for everyone to post their server and firewall logs!
_________________
Alternate Reality Gaming
http://www.unfiction.com/
Posted: Wed Jul 28, 2004 6:23 pm
Oea
Guest
Yeah, I figured that, but this hit
63.207.101.109 - - [28/Jul/2004:09:25:22 -0700] "GET /BEEWITHH.GIF HTTP/1.1" 200 6789
Is DEFINITELY one of them, because i just put that pic on and server and hid it in an email to them...
Posted: Wed Jul 28, 2004 6:25 pm
Phosphorous
Guest
Re: [SOURCE/META] Dana's, Ladybee's.. IP Address
SpaceBass wrote:
Oea wrote:
The other might not be someone from ,teh arg, but worth noting:
68.121.54.134 - - [28/Jul/2004:09:31:43 -0700] "SEARCH /\x90\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\
xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\
xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\
xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\
xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\
xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\
xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\xb1\x02\x
Um, yea. That's likely just some worm trying to exploit a server vulnerability. No need for everyone to post their server and firewall logs!
Yeah, you're right. It's an IIS WebDAV exploit:
http://edgeos.com/threats/details.php?id=11413
http://www.microsoft.com/technet/security/bulletin/ms03-007.mspx
Posted: Wed Jul 28, 2004 7:00 pm
Oea
Guest
Yeah Yeah that's a confirmed exploit
63.207.101.109 - - [28/Jul/2004:09:25:22 -0700] "GET /BEEWITHH.GIF HTTP/1.1" 200 6789 is Dana/Ladybee tho
have fun with it
peace
Posted: Wed Jul 28, 2004 7:08 pm
inio
Decorated
Joined: 24 Jul 2004 Posts: 163 Location: Santa Cruz, CA
Re: [SOURCE/META] Dana's, Ladybee's.. IP Address
Oea wrote:
Resolves to adsl-63-207-101-109.dsl.snfc21.pacbell.net
Well... That's in character enough. Dana has DSL and is in the San Francisco area. That IP belongs to the netblock:
Rback30 SNFC21 SBCIS-100515-212525
Which likely is serviced by a CO at
303 second St, San Francisco
Which appears to be in a business district. At this point I'm feeling a little close to the curtain and stopping.
Posted: Wed Jul 28, 2004 8:33 pm
Yuri
Guest
sdfsdg Nice Work
Posted: Wed Jul 28, 2004 8:38 pm
mackdoobiest
Kilroy
Joined: 28 Jul 2004 Posts: 1
303 2nd Street Looks like a Kinko's wi-fi spot.
Posted: Wed Jul 28, 2004 9:17 pm
Anonymous Coward
Boot
Joined: 25 Jul 2004 Posts: 39
Definitely, you know, peering behind the curtain, but maybe the administrators of these forums and the Wiki could check the server logs for that IP address.
Posted: Thu Jul 29, 2004 4:16 am
Oea
Guest
Yeah, I know, peering behind the curtains... but i just had to see if it was a corperate IP, that's all I really wanted to know
When I sent the email I knew it'd be a snfc pacbell addy just because.... they are usually dynamic (unless she IS using a wifi hotspot) but still kinda neat.
Posted: Thu Jul 29, 2004 4:21 am
Phaze
Greenhorn
Joined: 27 Jul 2004 Posts: 8
Damn good idea there! Nice catch.
This reminds me of the scramble to hunt down the identity of the "Cortana Letters" machine using it's IP addy.
Posted: Thu Jul 29, 2004 4:22 am
cyanogen
Greenhorn
Joined: 25 Jul 2004 Posts: 9
07272004-access.log:63.207.101.109 - - [27/Jul/2004:14:48:44 -0400] "GET /ilb HTTP/1.1" 301 382 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; YComp 5.0.0.0)"
confirmed
lots and lots of hits.
THEY ARE WATCHING US!@#
Posted: Thu Jul 29, 2004 4:44 am
Anonymous Coward
Boot
Joined: 25 Jul 2004 Posts: 39
cyanogen wrote:
THEY ARE WATCHING US!@#
Heh.
Quote:
... the long elegance of a fine decrypt, where you pull noise aside like the flesh of a cooked trout to reveal the gleaming skeleton of signal inside.
They seem to approve of the solving of the puzzles, anyway.
Posted: Thu Jul 29, 2004 5:12 am
jibious
Guest
where'd you get irvine, ca from?
the second IP is a sacramento IP address, which is how many miles from SF? roughly 90, give or take a few.
rback6.scrm01
68.120.0.0 - 68.127.255.255
303 Second St seems to be the HQs for SBC (PacBell) Internet Services, although someone may want to check up on that - its right next to the Giants' stadium. i highly doubt the CO would be located at the address listed in ARIN's registry.
Posted: Thu Jul 29, 2004 5:52 am
Display posts from previous: All Posts 1 Day 1 Week 2 Weeks 1 Month 3 Months 6 Months 1 Year Sort by: Post Time Post Subject Author Ascending Descending