Author
Message
WolfHawk
Entrenched
Joined: 15 Nov 2006 Posts: 1247 Location: St. Louis
Stormalong wrote:
So I try to login with the default ('admin', 'initial') and presto, I'm connected.
Interestingly it shows the auth count (Auth: 18, best 348 Unauth: 0 (0.00% intrusion)) that we know and love from port 1313.
Sadly, it does not seem to respond to any commands I type in after being connected.
Ok, I tried this myself and it looks like I got a slightly different result however I claim no knowledge of hacking. I am (shh, at work) on a mac running OSX. I used "admin" as the user name, and "initial" as the password:
[Edit] forgot to mention I'm using the Safari browser[/Edit]
[Edit 2] Um, I did post an image here didn't I? Was it removed for some reason? [/Edit]
Description
Filesize
58.26KB
Viewed
193 Time(s)
Posted: Tue May 15, 2007 3:51 pm
Last edited by WolfHawk on Wed May 16, 2007 2:06 am; edited 1 time in total
cissmiace
Entrenched
Joined: 24 Mar 2007 Posts: 867 Location: Manchester UK
Please forgive me if this is a really silly thing to suggest, but I was wondering if anyone has overlayed whats being spewed out from the servers (?) - all the language etc with the red circled words?
Its probably really silly suggestion
_________________I am the very model of a scientist Salarian!
Posted: Tue May 15, 2007 5:09 pm
poeticexplosion
Veteran
Joined: 17 Jan 2006 Posts: 109 Location: Chicago
WolfHawk wrote:
Stormalong wrote:
So I try to login with the default ('admin', 'initial') and presto, I'm connected.
Interestingly it shows the auth count (Auth: 18, best 348 Unauth: 0 (0.00% intrusion)) that we know and love from port 1313.
Sadly, it does not seem to respond to any commands I type in after being connected.
Ok, I tried this myself and it looks like I got a slightly different result however I claim no knowledge of hacking. I am (shh, at work) on a mac running OSX. I used "admin" as the user name, and "initial" as the password:
[Edit] forgot to mention I'm using the Safari browser[/Edit]
As far as I can tell, that's what I get too.
_________________Playing: Must Love Robots
Played: Who is Benjamin Stove?
Posted: Tue May 15, 2007 7:10 pm
Occultus
Boot
Joined: 27 Apr 2007 Posts: 37
The space data is all directly copied from this star catalogue (pdf)
Posted: Tue May 15, 2007 7:46 pm
Caterpillar
Unfictologist
Joined: 25 Sep 2002 Posts: 1887 Location: cem's otherbody
Holy mother of Yog-Sothoth! I think I've to find a new ARG...lol
I just read these three pages and am now feeling especially deficient.
Plaudits to those of you with the know how - it's talent, real talent!
Posted: Tue May 15, 2007 8:20 pm
konamouse
Official uF Dietitian
Joined: 02 Dec 2002 Posts: 8010 Location: My own alternate reality
Add my kudos as well.
I think all of this will bring us out of the Pilot and into the Meat of the ARG????
_________________
'squeek'
r u a Sammeeeee? I am Forever!
Posted: Tue May 15, 2007 8:34 pm
danteIL
Unfictologist
Joined: 08 May 2006 Posts: 1990
Ronomi? Has anybody else downloaded the Port 1031 data from ronomi.com?
I've started to, and although it's hard to tell from the garbage in there, it looks different to me. I'm monitoring to see if different text stuff comes up, although so far nothing (i.e., no text, not the same text again). I thought I'd ask, though...
Posted: Wed May 16, 2007 10:56 am
jegger
Decorated
Joined: 05 Aug 2004 Posts: 222 Location: Atlanta, GA
Re: Ronomi?
danteIL wrote:
Has anybody else downloaded the Port 1031 data from ronomi.com?
I've started to, and although it's hard to tell from the garbage in there, it looks different to me. I'm monitoring to see if different text stuff comes up, although so far nothing (i.e., no text, not the same text again). I thought I'd ask, though...
I took a look at the BOF, and the same text is there. [META] I imagine that the PM's are using virtual hosts on the same box for ronomi and sentryoutpost. That means that the same ports would be open with the same data.[/META]
_________________Played: I Love Bees, Lost Experience, World Without Oil
Playing: Dharma Wants You
Posted: Wed May 16, 2007 11:08 am
danteIL
Unfictologist
Joined: 08 May 2006 Posts: 1990
Re: Ronomi?
jegger wrote:
I took a look at the BOF, and the same text is there. [META] I imagine that the PM's are using virtual hosts on the same box for ronomi and sentryoutpost. That means that the same ports would be open with the same data.[/META]
Thanks! But what is 'the BOF'?
Posted: Wed May 16, 2007 11:14 am
Phaedra
Lurker v2.0
Joined: 21 Sep 2004 Posts: 4033 Location: Here, obviously
Beginning of file?
_________________Voted Most Likely to Thread-Jack and Most Patient Explainer in the ILoveBees Awards.
World Champion: Cruel 2B Kind
Posted: Wed May 16, 2007 11:19 am
danteIL
Unfictologist
Joined: 08 May 2006 Posts: 1990
Phaedra wrote:
Beginning of file?
Ah that would make sense.
The problem was I never saw a definitive answer for the correct offset to use for the beginning of the file, so I guessed at -5910000.
Anyway, I just found the text
Quote:
ol days, we'll have to test the hypotheses to know the answer. And the only way to test in this
in the ronomi download. This was also in the SO download, so it seems pretty likely that the same stuff is both places..
Posted: Wed May 16, 2007 11:25 am
James Stone
Decorated
Joined: 30 Sep 2006 Posts: 174 Location: England
Re: Ronomi?
danteIL wrote:
Has anybody else downloaded the Port 1031 data from ronomi.com?
Yes, I have. It is exactly the same.
_________________"All fixed set patterns are incapable of adaptability or pliability. The truth is outside of all fixed patterns."
Posted: Wed May 16, 2007 11:30 am
Stormalong
Decorated
Joined: 09 Oct 2003 Posts: 213 Location: Ontario, Canada
I took jegger's portscan and did some detective work and summarized.
Code:
PORT SERVICE
21/tcp ftp
22/tcp ssh
23/tcp telnet
25/tcp smtp (doesn't accept mail for sentryoutpost.com or ronomi.com)
80/tcp http
113/tcp auth
548/tcp unknown
587/tcp SMTP (doesn't accept mail for sentryoutpost.com or ronomi.com, same as 25?)
836/tcp unknown (closes port after any data entry)
1031/tcp file dump (Offset> prompt, not always open)
1217/tcp unknown (connection closes immediately)
1313/tcp repeating AUTH report
4196/tcp HTTP (PerlMUD 2.0)
4197/tcp unknown (tries to telnet somewhere)
4198/tcp HTTP (PerlMUD 2.0...same as 4196?)
5217/tcp (repeating message, choraz terminate)
5222/tcp Jabber client port
5269/tcp Jabber server-to-server port
5666/tcp possibly Nagios NPRE
47541/tcp unknown (closes port after any data entry, acts much like 836)
Edit: fixed a mistake
_________________Jimmy has fancy plans, and pants to match.
Posted: Wed May 16, 2007 2:26 pm
Last edited by Stormalong on Wed May 16, 2007 2:42 pm; edited 2 times in total
jegger
Decorated
Joined: 05 Aug 2004 Posts: 222 Location: Atlanta, GA
Stormalong, it seems that you got 1031 and 1217 reversed
_________________Played: I Love Bees, Lost Experience, World Without Oil
Playing: Dharma Wants You
Posted: Wed May 16, 2007 2:33 pm
Display posts from previous: All Posts 1 Day 1 Week 2 Weeks 1 Month 3 Months 6 Months 1 Year Sort by: Post Time Post Subject Author Ascending Descending