|
|||||||||||
|
RE: Company Firewall's IP Address
From: Michael S Hines <mshines(at)purdue.edu>
Date: Tue Nov 12 2002 - 19:32:09 EST
The Domain registration shows the following:
Registrant:
P.O. Box 1222
Domain Name: BONZI.COM Administrative Contact, Technical Contact:
Administrator (ADM649-ORG) admin@BONZI.COM
BONZI Software
P.O. Box 1222
San Luis Obispo, CA 93406
US
(805) 546-1955
Fax- (805) 546-1956
Record expires on 15-Sep-2009.
Domain servers in listed order: AUTH00.NS.UU.NET 198.6.1.65 AUTH61.NS.UU.NET 198.6.1.182 it returns an IP address of 63.68.55.189 pings to it this evening at 7:10 pm are failing... it may have been taken down. Bonzi owns a block of addresses - a subset of UUNET's addresses, as noted
11/12/02 19:11:27 IP block www.bonzi.com
Trying 63.68.55.189 at ARIN
63.64.0.0 - 63.127.255.255
Bonzi Software UU-63-68-54 (NET-63-68-54-0-1)
63.68.54.0 - 63.68.55.255
a web inquiry shows the following: 11/12/02 19:14:18 Browsing http://www.bonzi.com/ Fetching http://www.bonzi.com/ ... GET / HTTP/1.1 Host: www.bonzi.com Connection: close User-Agent: Sam Spade 1.14 HTTP/1.1 302 Object Moved Location: http://www.bonzi.com/bonziportal/index.asp Server: Microsoft-IIS/5.0 Content-Type: text/html Connection: close Content-Length: 165 <head><title>Document Moved</title></head> Sam Spade can be your friend - check it out at http://samspade.org/ssw/dl.html You'll have to draw your own conclusions. If you're on the Internet (and not behind a proxy) then you ARE advertising your IP addresses. Sounds like yours may have been found by a random scanner. The good news is that it appears your firewall worked, your internal address was not disclosed. And you wisely posted using a public e-mail service (not your internal network id). Only problem was Yahoo displayed the IP address of the Webmail poster in the message header - it was posted by the host IP 63.163.99.130. The lookup on that is left as an exercise for the reader... All of the above information is in the public domain and readily available using one or more of the tools that should be in an auditors toolbox. msh Michael S Hines | Phone 765-494-5875 Purdue University | FAX 765-496-1380 Information Technology@Purdue | Email mshines@purdue.edu OS/390 Systems Programmer | Certifications: 401 S Grant St | CIA, CISA, CFE, CDPWest Lafayette, IN 47907-2024 |
-----Original Message-----
I was doing security research on the internet at work yesterday....when all
of
It just bothers me that someone would be able to determine the IP address of
our firewall that easily. It seems to me that our firewall should operate
in a
Click on the following to learn more about this pop up site. http://www.bonzi.com/internetalert/ia99m.asp Do you Yahoo!? U2 on LAUNCH - Exclusive greatest hits videos http://launch.yahoo.com/u2 Received on Wed Nov 13 13:07:18 2002 This archive was generated by hypermail 2.1.8 : Wed Aug 23 2006 - 14:03:21 EDT |
||||||||||
|
|||||||||||