Re: trojan horse attack

From: dak (comp-security-firewalls_at_spamtrap.cjb.net)
Date: 01/07/05


Date: Fri, 07 Jan 2005 14:28:33 -0600

On Fri, 7 Jan 2005 20:49:16 +0100, "jeanjean" <jeanjean@france.com>
wrote:

>My fire wall announced me a trojan horse attack but fortunately blocked it.
>The address from where the attack is coming from is 84.99.130.132
>My fire wall is not able to indicate me where this address is situated (for
>all other atacks he is mentioning me the city and the country)
>Do you know where it is.

 It appears to be France.

##### BEGIN QUOTE #####
84.99.130.132 = NO REVERSE DNS (WSANO_DATA)

01/07/05 14:20:43 whois 84.99.130.132 @ whois.ripe.net
whois -h whois.ripe.net 84.99.130.132 ...
inetnum: 84.99.129.0 - 84.99.142.255
netname: N9UF-DYN-DSL
descr: Dynamic pool
descr: telehouse-2-4
country: FR
admin-c: LD699-RIPE
tech-c: LDC76-RIPE
status: ASSIGNED PA
remarks:
*************************************************************
remarks: * For spam & abuse issues please email to
abuse@gaoland.net *
remarks:
*************************************************************
mnt-by: LDCOM-MNT
changed: lir@gaoland.net 20041019
source: RIPE

route: 84.96.0.0/13
descr: LDCOM-NET
origin: AS15557
mnt-by: LDCOM-MNT
changed: lionel.mottay@neuf.com 20040414
source: RIPE

role: LDCOM Legal Contact
address: neuf telecom
address: Immeuble Quai Ouest
address: 40-42 Quai du point du jour
address: 92659 Boulogne Billancourt
address: France
fax-no: +33 1 58 63 18 18
admin-c: LD699-RIPE
tech-c: LM5867-RIPE
e-mail: lir@gaoland.net
remarks:
*************************************************************
remarks: * For spam & abuse issues please email to
abuse@gaoland.net *
remarks:
*************************************************************
nic-hdl: LD699-RIPE
mnt-by: LDCOM-MNT
changed: lir@gaoland.net 20041013
source: RIPE

role: LDCOM Networks Tech Contact
address: neuf telecom
address: Immeuble Quai Ouest
address: 40-42 Quai du point du jour
address: 92659 Boulogne Billancourt
address: France
fax-no: +33 1 70 18 15 70
e-mail: noc@gaoland.net
admin-c: LM5867-RIPE
tech-c: DG1056-RIPE
tech-c: JM1461-RIPE
nic-hdl: LDC76-RIPE
mnt-by: LDCOM-MNT
remarks:
*************************************************************
remarks: * For spam & abuse issues please email to
abuse@gaoland.net *
remarks:
*************************************************************
changed: lir@gaoland.net 20041013
source: RIPE
##### END QUOTE #####

-- 
 dak


Relevant Pages

  • Re: I am a lunatic
    ... mnt-by: AS5089-MNT ... source: RIPE # Filtered ... remarks: ... admin-c: MH22007-RIPE ...
    (uk.politics.misc)
  • Re: hacked?
    ... tech-c: RAD3-RIPE ... mnt-by: AS8708-MNT ... source: RIPE ...
    (comp.os.linux.security)
  • Re: I am a lunatic
    ... mnt-by: AS5089-MNT ... source: RIPE # Filtered ... remarks: ... admin-c: MH22007-RIPE ...
    (uk.politics.misc)
  • Am I Being Hacked?
    ... I have a dedicated server with IPowerweb where I have a couple of sites set ... % This is the RIPE Whois server. ... remarks: * Abuse Contact: http://www.t-com.de/ip-abuse in case of Spam, ... mnt-by: DTAG-NIC ...
    (microsoft.public.inetserver.iis)
  • Re: hack attempt on my server...What do you do about this?
    ... > % This is the RIPE Whois server. ... > remarks: LOCKED by the RIPE NCC due to ... a good hacker would use another system to attack other systems to hide ... If you are responsible for security, ...
    (Fedora)