Re: "SRC=69.28.159."

From: Moe Trin (ibuprofin_at_painkiller.example.tld)
Date: 12/11/04

  • Next message: tosh: "nmap (Windows version) erroneously detects smtp and pop3 port open (Bug?)"
    Date: Fri, 10 Dec 2004 18:02:03 -0600
    
    

    In article <69qdnQLHxNM67CTcRVn-hQ@acadia.net>, Newsbox wrote:

    >I have a lot of log entries from the same netblock/domain, and want to
    >know why.

    A count of hits from the block doesn't provide clues. What ports (source,
    destination), what addresses? What else is going on on your system(s) at
    the time? Is there any reason you might be talking to those hosts?

    >[root@localhost root]# host 69.28.159.7
    >7.159.28.69.in-addr.arpa domain name pointer
    >cdn-69-28-159-7.iad.llnw.net.
    >
    >[root@localhost root]# whois

    Why are you running network applications as root?

    [compton ~]$ whois -h whois.arin.net 69.28.159.7
    [whois.arin.net]

    OrgName: Limelight Networks, LLC
    OrgID: LLNW
    Address: 2220 W. 14th Street
    City: Tempe
    StateProv: AZ
    PostalCode: 85281
    Country: US

    ReferralServer: rwhois://rwhois.llnw.net:4321/

    [snip]

    OrgAbuseHandle: LNAD-ARIN
    OrgAbuseName: Limelight Networks Abuse Dept
    OrgAbusePhone: +1-602-850-5095
    OrgAbuseEmail: ipadmin@limelightnetworks.com

    [snip]
    [compton ~]$

    An rwhois query seem to indicate that specific address is a corporate
    address, rather than a customer.

    >(me:) What is this? Maybe an ad agency that is connected to a site I use?

    Possible - not enough details.

    > Else why am I getting this for weeks on end? The firewall is obviously
    >blocking it so I need not worry. Or should I? It seems to happen at the
    >same time in the early morning here.

    Again - not enough details. FWIW, the 'IAD' _suggests_ a Northern Virginia
    location (IAD is the airport code for Washington Dulles, while LAX is Los
    Angles, SJC is San Jose, and LGA is La Guardia in New York). As you are
    posting from a Stentor address block, the 'cdn' in the hostname you looked
    up _could_ refer to 'Canadian' but that's pure speculation.

    >Should I call them? Would they care?

    If this is all you show, no - don't bother wasting their/your time. If you
    have some details of nefarious deeds (including relatively accurate times,
    specific ports/addresses, etc), then it might be worth a shot. You might
    also google for them in the news.admin.net-abuse.* mewsgroups.

    >I'm changing computers and os's tomorrow (or next week?), so if this box
    >is killed, it's ok for me. I don't yet have any reason to think it is
    >killed. Just would like to understand wtf is going on here.

    Look at the source and destination port numbers. Look at the source
    addresses. Is there any pattern?

    (Note: While I am near Phoenix, I have nothing to do with Limelight.
    They are in the Phoenix telephone book, but not in the Yellow Pages,
    and I get no response to http:www.llnw.net which forwards to
    www.limelightnetworks.com - so you know as much as I do about them.)

            Old guy


  • Next message: tosh: "nmap (Windows version) erroneously detects smtp and pop3 port open (Bug?)"

    Relevant Pages

    • Re: EDI problems
      ... pick it up send to destination, ... I've restarted the EDI subsystem, rebooted, check ... ports etc and place it on ... > a vpc on my laptop and it works fine, the send and receive ports for EDI work ...
      (microsoft.public.biztalk.general)
    • router rules
      ... i am very new to firewall concepts. ... allow always if destination port=443 & protocol = tcp ... looked up a port list of protocols and allowed them via destined ports. ...
      (Security-Basics)
    • Re: "SRC=69.28.159."
      ... Is there any reason you might be talking to those ... Looks like they are all coming from port 80 and going to various ports ... unpriveledged users. ... > Look at the source and destination port numbers. ...
      (comp.os.linux.security)
    • Re: 2 routes to a single end point ?
      ... >>I would like to know whether it is possible to define two direct routes ... The destination is a machine with 1 Gigabit/s interface. ... It has 6 input ports and 1 output port. ...
      (comp.os.linux.networking)

  • Quantcast