Re: possible hacker

From: Robert Moir (robert.moir@ntlworld.com)
Date: 09/22/02


From: "Robert Moir" <robert.moir@ntlworld.com>
Date: Sun, 22 Sep 2002 19:52:26 +0100


"scott" <scott@kobashi.com> wrote in message
news:4b7e01c26236$6cc549a0$2ae2c90a@phx.gbl...
> cdm.microsoft.com is hacking
> http://windowsupdate.microsoft.com/.
> http://cdm.microsoft.com/update/certs/dancert.htm It is a
> german site. When I hit update and clicked on the link on
> top of the cert before downloading critical components
> installer. If you go to cdm.microsoft.com it redirects to
> http://windowsupdate.microsoft.com/

cdm.microsoft.com appears to be a valid microsoft site. According to
samspade.org that maps to IP number 207.46.131.197, which ARIN lists as
belonging to Microsoft.

SAMSPADE
cdm.microsoft.com resolves to 207.46.131.197
traceroute cdm.microsoft.com
cdm.microsoft.com resolves to 207.46.131.197
Do not contact either Los Nettos (ln.net) or Centergate Research Group
(centergate.com) based on the results of this traceroute.
 3 130.152.80.30 3.047 ms isi-1-lngw2-pos.ln.net [AS226] Los Nettos
origin AS
 4 198.172.117.161 8.195 ms ge-2-3-0.a02.lsanca02.us.ra.verio.net
[AS2914] Verio
 5 129.250.29.136 9.922 ms xe-1-0-0.r21.lsanca01.us.bb.verio.net
[AS2914] Verio
 6 129.250.2.187 19.378 ms p16-1-1-0.r21.snjsca04.us.bb.verio.net
[AS2914] Verio
 7 129.250.2.198 13.070 ms p16-1-1-2.r21.plalca01.us.bb.verio.net
[AS2914] Verio
 8 129.250.5.82 33.898 ms p16-0-1-1.r20.sttlwa01.us.bb.verio.net
[AS2914] Verio
 9 129.250.2.15 34.129 ms p16-0-0-0.r03.sttlwa01.us.bb.verio.net
[AS2914] Verio
10 129.250.9.18 34.155 ms p1-0.microsoft.sttlwa01.us.bb.verio.net
[AS2914] Verio
11 207.46.154.13 30.703 ms DNS error [AS8070] MICROSOFT
12 207.46.155.17 30.986 ms DNS error [AS8070] MICROSOFT
13 207.46.129.146 33.117 ms DNS error [AS8070] MICROSOFT
14 207.46.131.197 30.766 ms cdm.microsoft.com [AS8070] MICROSOFT

ARIN
Search results for: 207.46.131.197

OrgName: Microsoft
OrgID: MICROS-3

NetRange: 207.46.0.0 - 207.46.255.255
CIDR: 207.46.0.0/16
NetName: MICROSOFT-GLOBAL-NET
NetHandle: NET-207-46-0-0-1
Parent: NET-207-0-0-0-0
NetType: Direct Assignment
NameServer: DNS1.CP.MSFT.NET
NameServer: DNS2.CP.MSFT.NET
NameServer: DNS1.TK.MSFT.NET
NameServer: DNS1.DC.MSFT.NET
NameServer: DNS1.SJ.MSFT.NET
Comment:
RegDate: 1997-03-31
Updated: 2001-06-20

TechHandle: ZM39-ARIN
TechName: Microsoft
TechPhone: +1-425-936-4200
TechEmail: noc@microsoft.com

# ARIN Whois database, last updated 2002-09-21 19:05
# Enter ? for additional hints on searching ARIN's Whois database.



Relevant Pages