DOS kougeki nara ripana hanzai. kaki no kanrisha ni mail shiyou. sosite kougekisha wo tokutei surunoda!!
[ JPNIC & JPRS database provides information on network administration. Its ] [ use is restricted to network administration purposes. For further infor- ] [ mation, use 'whois -h whois.nic.ad.jp help'. To suppress Japanese output, ] [ add'/e' at the end of command, e.g. 'whois -h whois.nic.ad.jp xxx/e'. ]
Network Information: [ネットワーク情報] a. [IPネットワークアドレス] 61.195.0.0-61.195.31.0 b. [ネットワーク名] DTI-NET f. [組織名] 株式会社 ドリーム・トレイン・インターネット g. [Organization] DREAM TRAIN INTERNET INC. m. [運用責任者] ST3000JP n. [技術連絡担当者] TS8661JP p. [ネームサーバ] ns.dti.ad.jp p. [ネームサーバ] ns2.dti.ad.jp y. [通知アドレス] [email protected] [割当年月日] 2001/08/09 [返却年月日] [最終更新] 2001/08/09 12:13:01 (JST) [email protected]
Klez.E is the most common world-wide spreading worm.It's very dangerous by corrupting your files. Because of its very smart stealth and anti-anti-virus technic,most common AV software can't detect or clean it. We developed this free immunity tool to defeat the malicious virus. You only need to run this tool once,and then Klez will never come into your PC. NOTE: Because this tool acts as a fake Klez to fool the real worm,some AV monitor maybe cry when you run it. If so,Ignore the warning,and select 'continue'. If you have any question,please mail to me.
ここね。 Network Information: [ネットワーク情報] a. [IPネットワークアドレス] 210.169.233.192/28 b. [ネットワーク名] NRIDATA-NET f. [組織名] エヌ・アール・アイデータサービス株式会社 g. [Organization] NRI Data Services,Ltd. m. [運用責任者] KS1824JP n. [技術連絡担当者] OK106JP y. [通知アドレス] [email protected]
C:\>ftp 210.169.233.194 Connected to 210.169.233.194. 220 nsitsrv.nridata.co.jp FTP server ready. User (210.169.233.194:(none)): anonymous 331 Guest login ok, send your complete e-mail address as password. Password: 230 Guest login ok, access restrictions apply. ftp> dir 200 PORT command successful. 150 Opening ASCII mode data connection for /bin/ls. total 4 d--x--x--x 2 0 0 1024 Feb 29 2000 bin d--x--x--x 2 0 0 1024 Feb 29 2000 etc drwxr-xr-x 2 0 0 1024 Feb 29 2000 lib drwxr-sr-x 2 0 50 1024 Nov 25 1999 pub 226 Transfer complete. ftp: 249 bytes received in 0.03Seconds 8.03Kbytes/sec. ftp> bye 221-You have transferred 0 bytes in 0 files. 221-Total traffic for this session was 623 bytes in 1 transfers. 221-Thank you for using the FTP service on nsitsrv.nridata.co.jp. 221 Goodbye.
From:AmericanHomeownersAssociation< [email protected] > To: Subject:Friend,HereAreYour2FREEAirlineTickets Date** Received:from[216.242.142.56]by *.com with ESMTP id ** Received:from a (216.242.142.54)bylsmail7.oin-1.com (LSMTP for Windows NT v1.1b) with SMTP id ** From [email protected] This email is not sent unsolicited. This is an Opt-In Network mailing! This message is sent to subscribers ONLY. The e-mail subscription address is: [email protected] To unsubscribe please click here. or Send an email with the word 'remove' in the subject line to [email protected] Or you may mail us at: PO BOX 810052 Boca Raton, Fl 33481-0052 ---------------------------- From:COPYDVD's< [email protected] > Reply-To:COPYDVD's< [email protected] > Subject:DuplicateDVDMoviesonAnyCD-R Received:from[64.32.34.150]by **.com with ESMTPid ** Received:(qmail aaa invoked by uid 5) From [email protected] To unsubscribe from the Hi-Speed Media mailing list, please enter your e-mail address above and click "REMOVE" or click here. ----------------------
From:equalaMail< [email protected] > Subject:Make up to $6000/month working from home Received: from [66.70.89.30] by **.com with ESMTP id ** Received: by dpm2.emailsvc.net (PowerMTA(TM) v1.5) (envelope-from< [email protected] >) From [email protected] Message-ID:< [email protected] > This EqualaMAIL Promotion was sent to you as a valued subscriber. If you would rather not receive emails from EqualaMail and would like to like to delete your name from our list please click here. Questions, Opinions or Feedback Email Us or write us at; Equalamail,PO Box 23248, Ft. Lauderdale, Fl. 33307 ------------------------ From:FreeCards< [email protected] > Subject:250 full-color business/personal cards FREE! Unlimited refills! Received:from[65.118.100.150]by **.com with ESMTP id ** From [email protected] X-Sender: offer888.net Complain-To: [email protected] You received this email because you signed up at one of Offer888.com's websites or you signed up with a party that has contracted with Offer888.com. To unsubscribe from the Offer888.com list, visit http://opt-out.offer888.net/[email protected] ------------------------
From: [email protected] Reply-To: [email protected] Subject:Re:Need Helpwithyourbills Received:from bldg13.com ([206.137.224.27]) by *.com with Microsoft SMTPSVC(5.0.2195.4905) Received: from dqyck.netscape.net ([63.175.91.20]) by bldg13.com (8.10.2+Sun/8.10.2) with SMTP id Message-Id:< [email protected] > X-Mailer:Microsoft Outlook Express 5.00 Return-Path: [email protected]
Free 1 Minute Debt Consolidation Quote * Quickly and easily reduce Your Monthly Debt Payments Up To 60% We are a 501c Non-Profit Organization that has helped 1000's consolidate their debts into one easy affordable monthly payment. For a Free - No Obligation quote to see how much money we can save you, please read on. --------------------- From: [email protected] Subject : Have all other diet programs failed you? Received: from [207.33.16.6] by *.com with ESMTP id ** Received:(from pmguser@localhost)by s1062.mb00.net (8.8.8pmg/8.8.5) From [email protected] Message-Id:< [email protected] > X-Info: Report abuse to list owner at [email protected] X-PMG-Userid: funnymoney * To remove yourself from this mailing list, point your browser to: http://i.mb00.net/remove?funnymoney * Enter your email address ( [email protected] ) in the field provided and click "Unsubscribe". The mailing list ID is "funnymoney". -----------------------
From:ITTTechnicalInstitute< [email protected] > Subject:The Good News Is At ITT Technical Institute! Received:from[216.242.142.45] by *.com with ESMTP From [email protected] Message-ID:< [email protected] > X-Mailer:Mozilla 4.04 [en] (Win95; I) This email is not sent unsolicited. This is an Opt-In Network mailing! This message is sent to subscribers ONLY. Send an email with the word 'remove' in the subject line to [email protected] Or you may mail us at: PO BOX 810052 Boca Raton, Fl 33481-0052 ---------------------- From:"Lower My Bills"< [email protected] > Subject:Eliminate ourDebt!Reduce Your Payments by 50% Received: from [209.223.117.227] by *.com (3.2) with ESMTP id Received:fromlocalhost(root@localhost)by db22.ad360.com (8.11.6/8.11.6) From [email protected] ---------------- From:MrTrivia< [email protected] > Reply-To:MrTrivia< [email protected] > Subject:30-Second Trivia Received: from [64.32.34.160] by *.com with ESMTP id Received: (qmail 1234invoked by uid 5) From [email protected] To unsubscribe from the Hi-Speed Media mailing list, please enter your e-mail address above and click "REMOVE" or click here. ------------------
From:< [email protected] > Reply-To:< [email protected] > Subject:Ultra PasswordsisnowatUltraXXXPasswords.com! Received: from [210.100.160.60] by *.com with ESMTP Received: from 90.16.216.225 ([90.16.216.225]) by smtp013.mail.yahou.com with NNFMP Received: from pet.vosni.net ([38.169.181.93])by rly-xr02.nikavo.net with NNFMP Received: from unknown (193.67.43.63)by mail.gimmixx.net with SMTP Received: from 72.172.15.102 ([72.172.15.102]) by loxi.pianstvu.net with NNFMP From [email protected] X-Mailer: Microsoft Outlook, Build 10.0.2 Dear Ultra Passwords newsletter subscriber,
On May 2nd 2002, our domain UltraPasswords.com was illegally HIJACKED! We are fighting to get our name back as soon as possible, but for now please visit our working mirror at our NEW name at UltraXXXPasswords.com! --------------- From:UncovertheTRUTH< [email protected] > Subject:Uncover the TRUTH about ANYONE! Received: from hispeedmailer.com ([64.32.34.150]) by *.com with Microsoft SMTPSVC(5.0.2195.4905) Return-Path: [email protected]
inetnum: 211.52.0.0 - 211.63.255.255 netname: KRNIC-KR descr: KRNIC descr: Korea Network Information Center country: KR admin-c: HM127-AP tech-c: HM127-AP remarks: ****************************************** remarks: KRNIC is the National Internet Registry remarks: in Korea under APNIC. If you would like to remarks: find assignment information in detail remarks: please refer to the KRNIC Whois DB remarks: http://whois.nic.or.kr/english/index.html remarks: ****************************************** mnt-by: APNIC-HM mnt-lower: MNT-KRNIC-AP changed: [email protected] 20000216 changed: [email protected] 20010606 source: APNIC
From:TheCooptNetwork< [email protected] > Subject:$100GiftVoucher>NoCostComputerLearning>FromVideoProfessor Received:from[216.98.14.2]by ** with ESMTP id ** Received:by emailsvc.net(PowerMTA(TM) v2)(envelope-from < [email protected] >) From [email protected] Message-ID:< [email protected] > Video Professor knows that by giving you a gift voucher to spend on ANY of our $100 computer lessons, you'll see the quality of our CD-ROM's and come back for more. AND, you'll have enough left over to take the popular 'Home Depot Home Improvement 1-2-3' CD FREE as well. All we ask is that you pay just $6.95 to cover shipping and handling. A small price to pay, for such great products. So don't delay. Redeem your special voucher today! Choose your lesson from the following subjects: Windows XP, ME, 98, or 95, Word, Excel, Quicken, Internet, PowerPoint, Outlook, FrontPage, WordPerfect, Works, Access, Lotus 1-2-3, DOS. *You only pay $6.95 shipping and handling conveniently billed to your Visa, Mastercard, American Express of Discover card. When you order, you will also receive additional lessons without obligation to purchase. IBM & PC compatible computers only. Limit one free lesson per household. Running time is approximately 60 minutes. Some restrictions may apply. This COOPTnetwork Promotion was sent to you as a valued subscriber. If you would rather not receive emails from the COOPTnetwork and would like to delete your name from our list please click here. Questions, Opinions or Feedback Email Us or write us at; COOPTnetwork,PO Box 23248, Ft. Lauderdale, Fl. 33307
Received: from 211.57.215.226 (HELO 211.57.216.195) (211.57.215.226) by **.jp with SMTP Received:from[63.85.85.236] by smtp-server6.tampabay.rr.com with SMTP Received:from unknown(124.215.35.163) by rly-xw01.mx.aol.com with QMQP Received:from unknown(28.35.188.67) by rly-xl04.mx.aol.com with esmtp Received: from rly-xw01.mx.aol.com ([153.196.56.114]) by lax-ca.osd.concentric.net with SMTP From:ltxcLaura< [email protected] > CC: [email protected][email protected] [email protected] Subject:Hey! mgivu Sender:ltxcLaura< [email protected] > X-Mailer: Microsoft Outlook Express 5.50.4133.2400
America's #1 Government Grant Program! The Federal Government Gives Away Billions of Dollars In Grants Each & Every Year (Free Money!) T ake Advantage Of This Opportunity Today And Change Your Life Forever 30 DAY MONEY BACK GUARANTEE! Can't wait on the mail? You can receive our fabulous Grant Guide Book in one easy Download! Start searching for Grants In Minutes! Simply order your Grant Guide Book today by sending $25 Cash, Check or Money Order with your e-mail address enclosed to:
From:Approved< [email protected] > Reply-To:Approved< [email protected] > Subject:Applytoday!100%GuaranteedMastercard! Received:from hispeedmailer.com ([64.32.34.150]) by ** with Microsoft SMTPSVC(5.0.2195.4905) Received:(qmailinvoked by uid 5) Return-Path: [email protected] Message-ID:< [email protected] > *Issue guarantee applies as long as bank issuing cards is issuing the store-valued cards, and $100 offer is not valid in circumstances beyond our control that result in a non-issue of a card. The ChexCard may be substituted for another card with similar features.. For all other requests, please do not reply to this email. Instead, go to www.masterbuxx.com. There you will find answers to many common questions, along with a form for contacting us if you can't find the information you're looking for. --------------- From:InkJetDept< [email protected] > Reply-To:InkJetDept< [email protected] > Subject:PrinterCartridges-Saveupto80%-Inkjet&LaserToners Received:from[64.32.34.185] by ** with ESMTP id ** Received:(qmailinvoked by uid 5) From [email protected]
From: [email protected] Subject:RefinanceYourMortgage Received:from[24.168.101.40] by ** with ESMTP id ** Received:from yahoo.ca[66.134.56.234] by mattmontalto.com (SMTPD10-2.0) From [email protected] X-Mailer:WEBmail 0.00 Message-Id:< [email protected] > Free Mortgage Loan Analysis - No obligation! We are a national mortgage lender referral service who specializes in helping homeowners get the loans you need to: Pay off big bills and stop creditors from calling Make those long needed home improvements Refinance your home at a better rate Get cash out for nearly anything *Now is the time to take advantage of falling interest rates!* If you are a current real property owner in the United States and would like to obtain more information regarding our offer, please fill out the form below and send it back to us. It only takes a few minutes, and there are absolutely no obligations!
From:Approved< [email protected] > Reply-To:Approved< [email protected] > To: [email protected][email protected] Subject:A CreditCardIsWaitingForYou! llCreditTypesWelcome! Received:from [64.32.34.150] by hispeedmedia.com with ESMTP id ** Received:(qmail invoked by uid 6) From [email protected] This email was sent to you by, Hi-Speed Media Inc., a marketing partner of First PREMIER Bank, not from the Bank itself. Please direct all concerns about this email or your inclusion on this list to our email address listed above. To unsubscribe from the Hi-Speed Media mailing list, please enter your e-mail address above and click "REMOVE" or click here.
>>228 # nmap (V. 2.54BETA34) scan initiated Sat May 18 10:52:35 2002 as: nmap -v -sS -P0 -F -O -o test.txt 38.pool2.dslosaka.att.ne.jp Interesting ports on 38.pool2.dslosaka.att.ne.jp (165.76.141.38): (The 1093 ports scanned but not shown below are in state: closed) Port State Service 25/tcp open smtp 80/tcp open http 135/tcp open loc-srv 139/tcp open netbios-ssn 443/tcp open https 1025/tcp open listen 1026/tcp open nterm 6666/tcp open irc-serv 7007/tcp open afs3-bos Remote OS guesses: Windows Millennium Edition (Me), Win 2000, or WinXP, MS Windows2000 Professional RC1/W2K Advance Server Beta3 TCP Sequence Prediction: Class=random positive increments Difficulty=101669 (Good luck!) IPID Sequence Generation: Busy server or unknown class
# Nmap run completed at Sat May 18 10:52:41 2002 -- 1 IP address (1 host up) scanned in 6 seconds
From:"APA"< [email protected] > Reply-To: [email protected] To: [email protected][email protected] [email protected] Subject:You're alreadyApproved Received:froml3.3web45.com([66.185.166.27]) by *.com with Microsoft SMTPSVC(5.0.2195.4905) Received:(qmailinvoked by uid 7) Message-ID:< [email protected] > Return-Path: [email protected] ClickforMail never sends unsolicited email. You have received this message because you registered with ClickforMail OR one of our carefully selected marketing partners. If you no longer wish to receive these offers, please follow the instructions at the bottom of this message. Do You Meet These Criteria? Live in the United States? Have a Social Security Number? 18 Years of Age or Older? Have a Valid Checking or Savings Account? Have Valid Job or other Income of at Least $750.00/month? Have a Home Phone Number? No Pending Bankruptcy? No current delinquencies in past 60 days? If you answered YES to all of these simple questions we GUARANTEE that you will receive a credit card with up to a $5000 credit limit.
If you would no longer like to receive e-mail from us you can unsubscribe CLICK HERE: The preceding message was sent to you as an opt-in subscriber to ClickforMail. If you wish to unsubscribe please follow this link: http://remove.3web45.com/[email protected]
From:E-MailSavings< [email protected] > To: [email protected][email protected] [email protected][email protected] Subject:SALE->VideoSurveillance,UNDER$50BUCKS! Received:from[216.34.75.50]by l3.3web45.com with ESMTP id ** Received:(qmailinvokedfrom6) Received:from mail.link2buy.com (216.34.74.50) by 10.3.220.33 with SMTP From [email protected] Message-ID:< [email protected] > In less than 10 minutes, you can set up a professional surveillance camera without ever breaking a sweat. How? Introducing the XCam2, a wireless video camera that broadcasts LIVE COLOR video to any TV, VCR or PC* within 100 feet. That means no wires and no mess! If you order now, you'll also receive a FREE motion-activated VCR Commander: automatically record video from your camera straight to your VCR! Gigantic $100 VALUE! This is a recurring mailing. If you wish to unsubscribe from this list, please click here, reply to this email with "unsubscribe" as the subject, or copy and paste the link below into your browser address bar. http://link2buy.com/c/ES/[email protected]&P=ES2044_20020515_665 Any third-party offers contained in this email are the sole responsibility of the offer originator. Copyright 2002 E-MailSavings
From:EqualaMAIL< [email protected] > To : [email protected][email protected] [email protected][email protected] [email protected] Subject:Offensive content on YOUR PC? Find out now! Received:from[66.70.89.20] by link2buy.com with ESMTP id ** Received:by dpm1.emailsvc.net (PowerMTA(TM) v1.5) (envelope-from< [email protected] >) Received: from mail (10.224.72.159) by 10.0.0.2 with SMTP From [email protected] Message-ID:< [email protected] > ============================================================================= The following offer was mailed by EqualaMAIL on behalf of contentwatch.com ============================================================================= Think there's no offensive content on your PC? Think again. It's possible to pick up objectionable files by accident from the Internet! Check now to be sure you're safe! FREE PC Check! No Obligation. Just Information. http://track.coopt.com/track.php?c_lid=1146&c_uid=12345678. ========================================================================== This EqualaMAIL Promotion was sent to you as a valued subscriber. If you would rather not receive emails from EqualaMail and would like to delete your name from our list please click below: http://track.coopt.com/members/[email protected]&a=12345678. Questions, Opinions or Feedback Email: [email protected] or write at: Equalamail, PO Box 23248, Ft. Lauderdale, Fl. 33307 ==========================================================================
(1)アドレス=211.133.251.18 (2)時刻=2002/05/19 22:53:30 (3)手口=FTP port probe ただしBlackIceでFireWalled
そいで、解析スレっつーことで、相手の素性を調査: nmap -v -sS -F -P0 -O sv.ranklink.net Interesting ports on sv.ranklink.net (211.133.251.18): (The 1093 ports scanned but not shown below are in state: closed) Port State Service 21/tcp open ftp 22/tcp open ssh 23/tcp open telnet 25/tcp open smtp 53/tcp open domain 80/tcp open http 110/tcp open pop-3 5432/tcp open postgres 8082/tcp open blackice-alerts Remote operating system guess: Linux 2.1.19 - 2.2.19 Uptime 295.763 days (since Sat Jul 28 04:48:29 2001) TCP Sequence Prediction: Class=random positive increments Difficulty=3492248 (Good luck!) IPID Sequence Generation: Incremental ※nmapのバージョンは V. 2.54BETA34 (Win32用をWidows2000で使用した)
公式サイトは http://www.tux.org/pub/security/ で、ここにはソースからおいてあります。 Windowsユーザーで、Visual C++ Ver 6 以降を所有しているならばこのソース(というかワークス ペースからして用意してくれているという親切ぶり)をDLしてコンパイル すれば最新版が手に入りますです。
Received:from 212.96.209.242(EHLO mail.admradugny)(212.96.209.242) by **withSMTP Received:from smtp0000.mail.yahoo.com (phys068a.chem.msu.ru [195.208.208.79]) by mail.admradugny with SMTP (Microsoft Exchange Internet Mail Service Version 5.50.1000.10) Reply-to: [email protected] From: [email protected] To: Subject:NakedPicsIPromised3719 Remember me? Click here to see the nude pictures of me that Lucky Ass took. Click here if you want me to remove you from my address book and e-mail list. http://www.free-porn-space.com/optout.html
From:"Wireless Offers"< [email protected] > Reply-To: [email protected] To: [email protected][email protected] [email protected][email protected] Subject:Greetings,whyhaven'tyouclaimedyourFREEphone? Received:from [66.185.166.50] by ** with ESMTP id ** Received:(qmailinvokedbyuid9) Message-ID:< [email protected] > *Free phone offer subject to VoiceStream Wireless credit approval. A one-time activation fee of $25 applies to all new activations. Coverage not available in all areas. Offer fulfilled by SimplyWireless.com, a VoiceStream authorized dealer. See site for additional offer details. **$30 mail-in rebate is available for new VoiceStream service plans $30 and greater. $30 mail-in rebate valid until 13/32/00. This e-mail was sent to you by Clickformail.com on behalf of SimplyWireless.com. You are receiving this e-mail because you are registered with Clickformail.com or one of it's affiliates, and agreed at that time to receive special offers via e-mail. If you no longer want to receive e-mail from Clickformail.com please click the remove link found on this page to be removed immediately. The preceding message was sent to you as an opt-in subscriber to ClickforMail. If you wish to unsubscribe please follow this link: http://c4m.2net34.com/[email protected] lick here if you want me to remove you from my address book and e-mail list. http://www.free-porn-space.com/optout.html To unsubscribe from the Offer888.com list, visit http://opt-out.offer888.net/[email protected]
[Tue May 21 10:31:16 2002] [error] [client 43.235.16.82] File does not exist: /usr/apache/htdocs/scripts/root.exe [Tue May 21 10:31:16 2002] [error] [client 43.235.16.82] File does not exist: /usr/apache/htdocs/MSADC/root.exe [Tue May 21 10:31:16 2002] [error] [client 43.235.16.82] File does not exist: /usr/apache/htdocs/c/winnt/system32/cmd.exe [Tue May 21 10:31:16 2002] [error] [client 43.235.16.82] File does not exist: /usr/apache/htdocs/d/winnt/system32/cmd.exe [Tue May 21 10:31:16 2002] [error] [client 43.235.16.82] File does not exist: /usr/apache/htdocs/scripts/..%5c../winnt/system32/cmd.exe [Tue May 21 10:31:16 2002] [error] [client 43.235.16.82] File does not exist: /usr/apache/htdocs/_vti_bin/..%5c../..%5c../..%5c../winnt/system32/cmd.exe [Tue May 21 10:31:16 2002] [error] [client 43.235.16.82] File does not exist: /usr/apache/htdocs/_mem_bin/..%5c../..%5c../..%5c../winnt/system32/cmd.exe [Tue May 21 10:31:16 2002] [error] [client 43.235.16.82] File does not exist: /usr/apache/htdocs/msadc/..%5c../..%5c../..%5c/..チ../..チ../..チ../winnt/system32/cmd.exe [Tue May 21 10:31:16 2002] [error] [client 43.235.16.82] File does not exist: /usr/apache/htdocs/scripts/..チ../winnt/system32/cmd.exe [Tue May 21 10:31:16 2002] [error] [client 43.235.16.82] File does not exist: /usr/apache/htdocs/scripts/..タッ../winnt/system32/cmd.exe [Tue May 21 10:31:16 2002] [error] [client 43.235.16.82] File does not exist: /usr/apache/htdocs/scripts/..チ・./winnt/system32/cmd.exe [Tue May 21 10:31:16 2002] [error] [client 43.235.16.82] File does not exist: /usr/apache/htdocs/scripts/..%5c../winnt/system32/cmd.exe [Tue May 21 10:31:16 2002] [error] [client 43.235.16.82] File does not exist: /usr/apache/htdocs/scripts/..%2f../winnt/system32/cmd.exe
The penetration method: Back stealth.!! There was access which amounts to no less than 367 times to 1433 ports. The router permitted access to 1433 at 20:15.
■お客が来た Date=2002/05/29 Time=21:17:06 IP=200.180.209.154 Port=22 (blocked by BlackICE)
■素性調査 nmap (V. 2.54BETA34) -v -sS -F -P0 -O 200.180.209.154 Port State Service 21/tcp open ftp 23/tcp open telnet 79/tcp open finger 98/tcp open linuxconf 113/tcp open auth 513/tcp open login 514/tcp open shell 31337/tcp open Elite Remote operating system guess: Linux 2.1.19 - 2.2.19 Uptime 1.997 days (since Mon May 27 20:30:48 2002) TCP Sequence Prediction: Class=random positive increments Difficulty=5525243 (Good luck!) IPID Sequence Generation: Busy server or unknown class
Network Information: [ネットワーク情報] a. [IPネットワークアドレス] 133.5.0.0 b. [ネットワーク名] KITE f. [組織名] 九州大学 g. [Organization] Kyushu University m. [運用責任者] SA031JP n. [技術連絡担当者] YK1737JP n. [技術連絡担当者] DI031JP p. [ネームサーバ] ns.nc.kyushu-u.ac.jp p. [ネームサーバ] nsb.nc.kyushu-u.ac.jp y. [通知アドレス] [割当年月日] [返却年月日] [最終更新] 1998/09/07 14:04:52 (JST) [email protected]
Network Information: [ネットワーク情報] a. [IPネットワークアドレス] 211.13.168.0 b. [ネットワーク名] HNB-NET f. [組織名] 日立ネットビジネス株式会社 g. [Organization] Hitachi netBusiness, Ltd m. [運用責任者] TI4440JP n. [技術連絡担当者] TT5610JP p. [ネームサーバ] ns1.hnb-yokohama1.com p. [ネームサーバ] ns2.hnb-yokohama1.com y. [通知アドレス] [email protected] [割当年月日] 2001/04/23 [返却年月日] [最終更新] 2001/04/23 13:11:45 (JST) [email protected]
Record last updated on 28-Jun-2001. Database last updated on 28-May-2002 23:38:30 EDT.
The ARIN Registration Services Host contains ONLY Internet Network Information: Networks, ASN's, and related POC's. Please use the whois server at rs.internic.net for DOMAIN related Information and whois.nic.mil for NIPRNET Information.
毎日こいつからアタックされます。 210.165.249.1 inetnum: 210.165.128.0 - 210.165.255.255 netname: INFOSPHERE descr: InfoSphere (NTT PC Communications, Inc.) country: JP admin-c: HH1558JP tech-c: RK448JP tech-c: SO1352JP remarks: This information has been partially mirrored by APNIC from remarks: JPNIC. To obtain more specific information, please use the remarks: JPNIC whois server at whois.nic.ad.jp. (This defaults to remarks: Japanese output, use the /e switch for English output) remarks: This information has been partially mirrored by APNIC from remarks: JPNIC. To obtain more specific information, please use the remarks: JPNIC whois server at whois.nic.ad.jp. (This defaults to remarks: Japanese output, use the /e switch for English output) changed: [email protected] 19980512 changed: [email protected] 20020529 source: JPNIC
Received: from web14107.mail.yahoo.com (216.136.172.137) by ** with SMTP Message-ID:< [email protected] > Received: from [209.29.83.220] by web14107.mail.yahoo.com via HTTP From:CecillaBethany< [email protected] > Subject:Try this site and enjoy it. To: 第三者中継可能!!!!!!!!!!!!!!!!!!!!!!!!!!!!! mail.worldvision.or.kr (pri=10) 問題あり:不正な中継を受け付けます。 (210.103.141.136) ORDB database...登録されています。 maps realtime blackhole list...登録されていません。
211.220.55.186 何度もファイアーウォールされました inetnum: 211.220.49.0 - 211.220.69.255 netname: KORNET-XDSL-PUSAN-KR descr: PUSAN NODE descr: 75 4KA JUNGANGDONG JUNGKU descr: PUSAN descr: 600-711 country: KR admin-c: GP1325-KR tech-c: WK4412-KR remarks: This IP address space has been allocated to KRNIC. remarks: For more information, using KRNIC Whois Database remarks: whois -h whois.nic.or.kr mnt-by: MNT-KRNIC-AP changed: [email protected] 20020527 source: KRNIC
person: GilSoon Park country: KR phone: +82-2-747-9213 fax-no: +82-2-766-5901 e-mail: [email protected] nic-hdl: GP1325-KR remarks: This information has been partially mirrored by APNIC from remarks: KRNIC. To obtain more specific information, please use the remarks: KRNIC whois server at whois.krnic.net. mnt-by: MNT-KRNIC-AP changed: [email protected] 20020527 source: KRNIC
Network Information: [ネットワーク情報] a. [IPネットワークアドレス] 218.47.164.0-218.47.255.0 b. [ネットワーク名] PLALA f. [組織名] 株式会社 ぷららネットワークス g. [Organization] Plala Networks Inc. m. [運用責任者] MN2905JP n. [技術連絡担当者] HS3694JP p. [ネームサーバ] dns1.plala.or.jp p. [ネームサーバ] dns2.plala.or.jp p. [ネームサーバ] ns-tk061.ocn.ad.jp y. [通知アドレス] [割当年月日] 2002/01/29 [返却年月日] [最終更新] 2002/01/29 15:52:03 (JST) [email protected]
Network Information: [ネットワーク情報] a. [IPネットワークアドレス] 218.41.0.0-218.41.63.0 b. [ネットワーク名] SO-NET f. [組織名] SO-Net サービス g. [Organization] SO-Net Service m. [運用責任者] MK2734JP n. [技術連絡担当者] YY1426JP n. [技術連絡担当者] SW314JP p. [ネームサーバ] dnss3.so-net.ne.jp p. [ネームサーバ] dnss4.so-net.ne.jp p. [ネームサーバ] dnss5.so-net.ne.jp p. [ネームサーバ] dnss6.so-net.ne.jp p. [ネームサーバ] dnss7.so-net.ne.jp p. [ネームサーバ] dnss8.so-net.ne.jp p. [ネームサーバ] dnss9.so-net.ne.jp y. [通知アドレス] [email protected] y. [通知アドレス] [email protected] [割当年月日] 2001/10/25 [返却年月日] [最終更新] 2001/10/25 16:22:11 (JST) [email protected]
Received:from 207.199.147.226 (EHLO logix-xchange.logixusa.com) (207.199.147.226) by ** with SMTP Received:from smtp0422.mail.yahoo.com (210.52.27.5 [210.52.27.5]) by logix-xchange.logixusa.com with SMTP (Microsoft Exchange Internet Mail Service Version 5.5.2650.21) id ** Date** From:"Marc Korshak"< [email protected] > To: [email protected][email protected][email protected] [email protected] [email protected][email protected] Subject:Introducing HGH: The Most Powerful Anti-Obesity Drug Ever
Human Growth Hormone Therapy Lose weight while building lean muscle mass and reversing the ravages of aging all at once. Remarkable discoveries about Human Growth Hormones (HGH) are changing the way we think about aging and weight loss.
As seen on NBC, CBS, and CNN, and even Oprah! The health discovery that actually reverses aging while burning fat, without dieting or exercise! This proven discovery has even been reported on by the New England Journal of Medicine. Forget aging and dieting forever! And it's Guaranteed!
不正アクセスの種類Traceroute 不正アクセスの送信元61.124.180.165 調べたら Network Information: [ネットワーク情報] a. [IPネットワークアドレス] 61.124.0.0-61.124.255.0 b. [ネットワーク名] INFOWEB f. [組織名] InfoWeb(富士通株式会社) g. [Organization] InfoWeb(Fujitsu Ltd.) m. [運用責任者] KH071JP n. [技術連絡担当者] AI018JP p. [ネームサーバ] ns1.hyper.web.ad.jp p. [ネームサーバ] ns2.hyper.web.ad.jp y. [通知アドレス] [email protected] [割当年月日] 2001/01/31 [返却年月日] [最終更新] 2001/02/02 10:39:04 (JST) [email protected]
[email protected] http://www.ordb.org/lookup/?host=mx1.1premio.com このホストは ORDB.org に不正中継ホストとして登録されています。 データベースの検索結果: mx1.1premio.com (65.121.18.77) Look up this host in non-ORDB RBL's (May take a while to load) ORDB.org への初回登録日時: 2002-06-03 16:09 CET 初回送信ホスト: 193.163.158.1 最終検査日時: 2002-06-03 16:09 CET 不正中継が確認されたメールのヘッダ情報: Return-Path: Delivered-To: marvin@bockscar.ordb.org Received: from qvp0017.freeyankeedom.com (unknown [65.121.18.11]) by BocksCar.ORDB.org (Postfix) with ESMTP id C9DC7584C for ; Mon, 3 Jun 2002 16:09:22 +0200 (CEST) Received: from localhost.localdomain (62.242.234.108 [62.242.234.108]) by qvp0017.freeyankeedom.com [169.254.2.54] with ESMTP (Dimac Mail Server 1.0.1.0 XP) id FCFF25C46BE14FF2BA90B0F8B19E371D at Mon, 3 Jun 2002 08:03:00 -0600 (envelope-from [email protected] ) for marvin@marvin.ordb.org From: [email protected] To: marvin@marvin.ordb.org X-ORDB-Envelope-From: [email protected] X-ORDB-Envelope-To: marvin@marvin.ordb.org Subject: ORDB.org check (0.3904331943305340.0517962571) ip=65.121.18.77 Message-Id: <20020603140922.C9DC7584C@BocksCar.ORDB.org> Date: Mon, 3 Jun 2002 16:09:22 +0200 (CEST)
http://www.ordb.org/lookup/?host=email.qves.com このホストは ORDB.org に不正中継ホストとして登録されています。 データベースの検索結果: email.qves.com (65.121.18.51) Look up this host in non-ORDB RBL's (May take a while to load) ORDB.org への初回登録日時: 2002-05-21 19:33 CET 初回送信ホスト: 24.68.215.101 最終検査日時: 2002-05-24 00:04 CET 不正中継が確認されたメールのヘッダ情報: Return-Path: Delivered-To: marvin@groundzero.ordb.org Received: from qvp0017.freeyankeedom.com (unknown [65.121.18.11]) by groundzero.ordb.org (Postfix) with ESMTP id 66B745B10F for ; Fri, 24 May 2002 00:02:44 +0200 (CEST) Received: from groundzero.ordb.org (62.242.0.190 [62.242.0.190]) by qvp0017.freeyankeedom.com [169.254.2.54] with ESMTP (Dimac Mail Server 1.0.1.0 XP) id 24DEB3EBF2A445089FC5A08AE96D813B at Thu, 23 May 2002 15:56:36 -0600 (envelope-from [email protected] ) for marvin@marvin.ordb.org From: [email protected] To: marvin@marvin.ordb.org X-ORDB-Envelope-From: [email protected] X-ORDB-Envelope-To: [email protected] Subject: ORDB.org check (0.7115356861751390.4228052941) ip=65.121.18.51 Message-Id: <20020523220244.66B745B10F@groundzero.ordb.org> Date: Fri, 24 May 2002 00:02:44 +0200 (CEST)
person: Won Kang address: Korea Telecom address: 128-9 Youngundong Chongroku address: SEOUL address: 463-711 country: KR phone: +82-2-747-9213 fax-no: +82-2-766-5901 e-mail: [email protected] nic-hdl: WK81-AP mnt-by: MNT-KRNIC-AP changed: [email protected] 20010523 source: APNIC
person: GilSoon Park country: KR phone: +82-2-747-9213 fax-no: +82-2-766-5901 e-mail: [email protected] nic-hdl: GP20-KR remarks: This information has been partially mirrored by APNIC from remarks: KRNIC. To obtain more specific information, please use the remarks: KRNIC whois server at whois.krnic.net. mnt-by: MNT-KRNIC-AP changed: [email protected] 20020603 source: KRNIC
inetnum: 24.0.0.0 - 24.255.255.255 netname: IANA-NETBLOCK-24 descr: This network range is not allocated to APNIC. descr: descr: If your whois search has returned this message, then you have descr: searched the APNIC whois database for an address that is descr: allocated by another Regional Internet Registry (RIR). descr: descr: Please search the other RIRs at whois.arin.net or whois.ripe.net descr: for more information about that range. country: AU admin-c: IANA1-AP tech-c: IANA1-AP remarks: For general info on spam complaints email [email protected]. remarks: For general info on hacking & abuse complaints email [email protected]. mnt-by: MAINT-APNIC-AP mnt-lower: MAINT-APNIC-AP changed: [email protected] 20020530 source: APNIC
http://hq.mcafeeasap.com/trojans.asp A Trojan Horse is a program that pretends to have a set of useful or desirable features, but actually contains a damaging payload. Since it does not replicate, a Trojan Horse is not technically a virus, but it may delete the contents of a hard drive!
Network Information: [ネットワーク情報] a. [IPネットワークアドレス] 61.203.0.0-61.203.127.0 b. [ネットワーク名] BIGLOBE-2 f. [組織名] BIGLOBEサービス(日本電気株式会社) g. [Organization] NEC Corporation m. [運用責任者] TN265JP n. [技術連絡担当者] NK032JP p. [ネームサーバ] ns02.mesh.ad.jp p. [ネームサーバ] ns03.mesh.ad.jp y. [通知アドレス] [email protected] [割当年月日] 2001/03/22 [返却年月日] [最終更新] 2001/06/21 16:13:00 (JST) [email protected]
Jun ** **:**:** hostname sendmail[99999]: XXX99999: <[email protected]>... we do not relay Jun ** **:**:** hostname sendmail[99999]: XXX99999: ruleset=check_rcpt, arg1=<[email protected]>, relay=********.ne.jp [211.*.*.*], reject=551 <[email protected]>... we do not relay Jun ** **:**:** hostname sendmail[99999]: XXX99999: from=<[email protected] >, size=0, [211.*.*.*]
http://www.ordb.org/lookup/?host=email.qves.com データベースの検索結果: email.qves.com (65.121.18.51) Look up this host in non-ORDB RBL's (May take a while to load) ORDB.org への初回登録日時: 2002-05-21 19:33 CET 初回送信ホスト: 24.68.215.101 最終検査日時: 2002-06-10 22:33 CET 不正中継が確認されたメールのヘッダ情報: Return-Path: Delivered-To: [email protected] Received: from qvp0017.freeyankeedom.com (unknown [65.121.18.11]) by BocksCar.ORDB.org (Postfix) with ESMTP id 7CC7B585D for ; Mon, 10 Jun 2002 22:33:31 +0200 (CEST) Received: from localhost.localdomain (194.255.24.146 [194.255.24.146]) by qvp0017.freeyankeedom.com [169.254.2.54] with ESMTP (Dimac Mail Server 1.0.1.0 XP) id 9A3A9115AE394AEB8C1C1F847BE9466B at Mon, 10 Jun 2002 14:26:26 -0600 (envelope-from [email protected]) for [email protected] From: [email protected] To: [email protected] X-ORDB-Envelope-From: [email protected] X-ORDB-Envelope-To: [email protected] Subject: ORDB.org check (0.8423967043346390.7953904771) ip=65.121.18.51 Message-Id: <[email protected]> Date: Mon, 10 Jun 2002 22:33:31 +0200 (CEST)
http://www.ordb.org/lookup/?host=mail.financialhost.com データベースの検索結果: mail.financialhost.com (65.121.18.51) Look up this host in non-ORDB RBL's (May take a while to load) ORDB.org への初回登録日時: 2002-05-21 19:33 CET 初回送信ホスト: 24.68.215.101 最終検査日時: 2002-06-10 22:33 CET 不正中継が確認されたメールのヘッダ情報: Return-Path: Delivered-To: marvin@bockscar.ordb.org Received: from qvp0017.freeyankeedom.com (unknown [65.121.18.11]) by BocksCar.ORDB.org (Postfix) with ESMTP id 7CC7B585D for ; Mon, 10 Jun 2002 22:33:31 +0200 (CEST) Received: from localhost.localdomain (194.255.24.146 [194.255.24.146]) by qvp0017.freeyankeedom.com [169.254.2.54] with ESMTP (Dimac Mail Server 1.0.1.0 XP) id 9A3A9115AE394AEB8C1C1F847BE9466B at Mon, 10 Jun 2002 14:26:26 -0600 (envelope-from [email protected] ) for marvin@marvin.ordb.org From: [email protected] To: marvin@marvin.ordb.org X-ORDB-Envelope-From: [email protected] X-ORDB-Envelope-To: marvin@marvin.ordb.org Subject: ORDB.org check (0.8423967043346390.7953904771) ip=65.121.18.51 Message-Id: <20020610203331.7CC7B585D@BocksCar.ORDB.org> Date: Mon, 10 Jun 2002 22:33:31 +0200 (CEST)
Network Information: [ネットワーク情報] a. [IPネットワークアドレス] 218.45.130.0-218.45.131.0 b. [ネットワーク名] IRUMACABLE f. [組織名] 入間ケーブルテレビ株式会社 g. [Organization] Iruma CATV m. [運用責任者] NO697JP n. [技術連絡担当者] NO697JP p. [ネームサーバ] dns1.jdserve.com p. [ネームサーバ] ns01.ictv.ne.jp p. [ネームサーバ] ns02.ictv.ne.jp y. [通知アドレス] [email protected] y. [通知アドレス] [email protected] [割当年月日] 2002/02/07 [返却年月日] [最終更新] 2002/02/27 10:07:27 (JST) [email protected]
azoogle.com (pri=0) <220-main.azoogle.com ESMTP Exim 3.35 #1 <220-We do not authorize the use of this system to transport unsolicited, <220 and/or bulk e-mail. >HELO rlytest.nanet.co.jp <250 main.azoogle.com Hello ns.nanet.co.jp [210.164.52.3] >MAIL FROM:< TESThttp://www.nanet.co.jp/rlytest/[email protected] > <250 < TESThttp://www.nanet.co.jp/rlytest/[email protected] > is syntactically correct >RCPT TO:<[email protected]> <550-Host ns.nanet.co.jp (rlytest.nanet.co.jp) [210.164.52.3] is not permitted <550-to relay through main.azoogle.com. <550-Perhaps you have not logged into the pop/imap server in the last 30 minutes. <550-You may also have been rejected because your ip address <550-does not have a reverse DNS entry. <550 relaying to <[email protected]> prohibited by administrator
Network Information: [ネットワーク情報] a. [IPネットワークアドレス] 210.139.128.0-210.139.255.0 b. [ネットワーク名] SO-NET f. [組織名] So-netサービス(ソニーコミュニケーションネットワーク株式会社) g. [Organization] So-net Service(Sony Communication Network Corporation) m. [運用責任者] MK2734JP n. [技術連絡担当者] YY1426JP n. [技術連絡担当者] SW314JP p. [ネームサーバ] dnss3.so-net.ne.jp p. [ネームサーバ] dnss4.so-net.ne.jp p. [ネームサーバ] dnss5.so-net.ne.jp p. [ネームサーバ] dnss6.so-net.ne.jp p. [ネームサーバ] dnss7.so-net.ne.jp p. [ネームサーバ] dnss8.so-net.ne.jp p. [ネームサーバ] dnss9.so-net.ne.jp y. [通知アドレス] [email protected] y. [通知アドレス] [email protected] [割当年月日] 1997/11/04 [返却年月日] [最終更新] 2000/05/08 11:32:38 (JST) [email protected]
inetnum: 210.160.210.104 - 210.160.210.111 netname: INSSP descr: INSQUARE CO.,Ltd. country: JP admin-c: RE005JP tech-c: RE005JP remarks: This information has been partially mirrored by APNIC from remarks: JPNIC. To obtain more specific information, please use the remarks: JPNIC whois server at whois.nic.ad.jp. (This defaults to remarks: Japanese output, use the /e switch for English output) remarks: This information has been partially mirrored by APNIC from remarks: JPNIC. To obtain more specific information, please use the remarks: JPNIC whois server at whois.nic.ad.jp. (This defaults to remarks: Japanese output, use the /e switch for English output) changed: [email protected] 20011218 changed: [email protected] 20020529 source: JPNIC
From:"Legal Council"< [email protected] > To: [email protected][email protected][email protected] Subject:re:Hire a Reputable Law Firm Inexpensively Date** Received:from [209.63.151.252] by ** with ESMTP id ** Received: from qvp0079 ([169.254.6.8]) by email.qves.com with Microsoft SMTPSVC(5.0.2195.2966) From [email protected] Message-ID:< [email protected] > X-Mailer: Microsoft CDO for Windows 2000 X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2462.0000 Return-Path: [email protected]
http://www.ordb.org/lookup/?host=email.qves.com データベースの検索結果: email.qves.com (65.121.18.51) Look up this host in non-ORDB RBL's (May take a while to load) ORDB.org への初回登録日時: 2002-05-21 19:33 CET 初回送信ホスト: 24.68.215.101 最終検査日時: 2002-06-10 22:33 CET 不正中継が確認されたメールのヘッダ情報: Return-Path: Delivered-To: [email protected] Received: from qvp0017.freeyankeedom.com (unknown [65.121.18.11]) by BocksCar.ORDB.org (Postfix) with ESMTP id 7CC7B585D for ; Mon, 10 Jun 2002 22:33:31 +0200 (CEST) Received: from localhost.localdomain (194.255.24.146 [194.255.24.146]) by qvp0017.freeyankeedom.com [169.254.2.54] with ESMTP (Dimac Mail Server 1.0.1.0 XP) id 9A3A9115AE394AEB8C1C1F847BE9466B at Mon, 10 Jun 2002 14:26:26 -0600 (envelope-from [email protected]) for [email protected] From: [email protected] To: [email protected] X-ORDB-Envelope-From: [email protected] X-ORDB-Envelope-To: [email protected] Subject: ORDB.org check (0.8423967043346390.7953904771) ip=65.121.18.51 Message-Id: <[email protected]> Date: Mon, 10 Jun 2002 22:33:31 +0200 (CEST)
211.115.216.98 inetnum: 211.115.216.0 - 211.115.216.255 netname: GNG-IDC-IMC-KR descr: IMC descr: 395-65 Shindeabang-Dong DongJak-Gu descr: SEOUL descr: 156-010 country: KR admin-c: JJ1496-KR tech-c: JJ1497-KR remarks: This IP address space has been allocated to KRNIC. remarks: For more information, using KRNIC Whois Database remarks: whois -h whois.nic.or.kr remarks: This information has been partially mirrored by APNIC from remarks: KRNIC. To obtain more specific information, please use the remarks: KRNIC whois server at whois.krnic.net. mnt-by: MNT-KRNIC-AP changed: [email protected] 20020610 source: KRNIC
person: Jeawan Jeong country: KR phone: +82-2-2105-6242 fax-no: +82-2-2105-6242 e-mail: [email protected] nic-hdl: JJ1496-KR remarks: This information has been partially mirrored by APNIC from remarks: KRNIC. To obtain more specific information, please use the remarks: KRNIC whois server at whois.krnic.net. mnt-by: MNT-KRNIC-AP changed: [email protected] 20020610 source: KRNIC
Network Information: [ネットワーク情報] a. [IPネットワークアドレス] 210.226.40.0-210.226.41.0 b. [ネットワーク名] AIC-NET f. [組織名] 山形県産業創造支援センター g. [Organization] Assistance for Industrial Creativity in Yamagata m. [運用責任者] NI458JP n. [技術連絡担当者] SK1945JP p. [ネームサーバ] aic-gw.gw.aic.pref.yamagata.jp p. [ネームサーバ] ns-tk022.ocn.ad.jp p. [ネームサーバ] yens.ygw.yamagata-rit.go.jp y. [通知アドレス] [email protected] [割当年月日] 1999/05/21 [返却年月日] [最終更新] 2002/02/15 10:08:21 (JST) [email protected] ]
Return-Path: <[email protected]> Received: from tip2 ([61.211.246.69]) by t-mta5.odn.ne.jp with ESMTP id <[email protected]> Received: from jobin ([192.168.0.90]) by tip2 (8.9.3+3.2W/3.7W) with SMTP id PAA04882 Message-Id: <200106070618.PAA04882@tip2> From: mail <[email protected]> Date: Mon, 17 Jun 2002 06:59:14 +0900 Subject: =?ISO-2022-JP?B?GyRCTCQ+NUJ6OS05cCIoGyhCIBskQkpzPTdAKSVQJUohPBsoQiYbJEIjUCNSJE43bxsoQg==?= MIME-Version: 1.0 Content-Type: text/plain; charset="ISO-2022-JP" Content-Transfer-Encoding: 7bit X-Mailer: Oshirase-Mailer
http://www.ordb.org/lookup/?host=email.qves.com データベースの検索結果: email.qves.com (65.121.18.51) Look up this host in non-ORDB RBL's (May take a while to load) ORDB.org への初回登録日時: 2002-05-21 19:33 CET 初回送信ホスト: 24.68.215.101 最終検査日時: 2002-06-10 22:33 CET 不正中継が確認されたメールのヘッダ情報: Return-Path: Delivered-To: [email protected] Received: from qvp0017.freeyankeedom.com (unknown [65.121.18.11]) by BocksCar.ORDB.org (Postfix) with ESMTP id 7CC7B585D for ; Mon, 10 Jun 2002 22:33:31 +0200 (CEST) Received: from localhost.localdomain (194.255.24.146 [194.255.24.146]) by qvp0017.freeyankeedom.com [169.254.2.54] with ESMTP (Dimac Mail Server 1.0.1.0 XP) id 9A3A9115AE394AEB8C1C1F847BE9466B at Mon, 10 Jun 2002 14:26:26 -0600 (envelope-from [email protected]) for [email protected] From: [email protected] To: [email protected] X-ORDB-Envelope-From: [email protected] X-ORDB-Envelope-To: [email protected] Subject: ORDB.org check (0.8423967043346390.7953904771) ip=65.121.18.51 Message-Id: <[email protected]> Date: Mon, 10 Jun 2002 22:33:31 +0200 (CEST)
このホストは ORDB.org に不正中継ホストとして登録されています。 データベースの検索結果: 207.224.126.193 (207.224.126.193) Look up this host in non-ORDB RBL's (May take a while to load) ORDB.org への初回登録日時: 2001-11-14 15:43 CET 初回送信ホスト: 205.244.188.12 最終検査日時: 2002-03-13 09:21 CET 不正中継が確認されたメールのヘッダ情報: Return-Path: Delivered-To: marvin@groundzero.ordb.org Received: from server.techlinebayarea.com (unknown [207.224.126.193]) by groundzero.ordb.org (Postfix) with ESMTP id D14025B158 for ; Wed, 13 Mar 2002 09:21:27 +0100 (CET) Received: from groundzero.ordb.org ([62.242.0.190]) by server.techlinebayarea.com with SMTP (Microsoft Exchange Internet Mail Service Version 5.5.2653.13) id W32PFYF7; Wed, 13 Mar 2002 00:09:35 -0800 X-ORDB-Envelope-MAIL-FROM: X-ORDB-Envelope-RCPT-TO: From: spamtest@[207.224.126.193] To: marvin@ordb.org Subject: ORDB.org check (0.3283845200203360.0644541382) (0) Message-Id: <20020313082127.D14025B158@groundzero.ordb.org> Date: Wed, 13 Mar 2002 09:21:27 +0100 (CET)
このホストは ORDB.org に不正中継ホストとして登録されています。 データベースの検索結果: 207.224.126.193 (207.224.126.193) Look up this host in non-ORDB RBL's (May take a while to load) ORDB.org への初回登録日時: 2001-11-14 15:43 CET 初回送信ホスト: 205.244.188.12 最終検査日時: 2002-03-13 09:21 CET 不正中継が確認されたメールのヘッダ情報: Return-Path: Delivered-To: marvin@groundzero.ordb.org Received: from server.techlinebayarea.com (unknown [207.224.126.193]) by groundzero.ordb.org (Postfix) with ESMTP id D14025B158 for ; Wed, 13 Mar 2002 09:21:27 +0100 (CET) Received: from groundzero.ordb.org ([62.242.0.190]) by server.techlinebayarea.com with SMTP (Microsoft Exchange Internet Mail Service Version 5.5.2653.13) id W32PFYF7; Wed, 13 Mar 2002 00:09:35 -0800 X-ORDB-Envelope-MAIL-FROM: X-ORDB-Envelope-RCPT-TO: From: spamtest@[207.224.126.193] To: marvin@ordb.org Subject: ORDB.org check (0.3283845200203360.0644541382) (0) Message-Id: <20020313082127.D14025B158@groundzero.ordb.org> Date: Wed, 13 Mar 2002 09:21:27 +0100 (CET)
Asia Pacific Network Information Centre This IP address range is not registered in the ARIN database. For details, refer to the APNIC Whois Database via WHOIS.APNIC.NET or http://www.apnic.net/apnic-bin/whois2.pl IMPORTANT NOTE: APNIC is the Regional Internet Registry for the Asia Pacific region. APNIC does not operate networks using this IP address range and is not able to investigate spam or abuse reports relating to these addresses. For more help, refer to http://www.apnic.net/info/faq/abuse/
Record last updated on 18-Dec-2000. Database last updated on 21-Jun-2002 19:59:57 EDT.
The ARIN Registration Services Host contains ONLY Internet Network Information: Networks, ASN's, and related POC's. Please use the whois server at rs.internic.net for DOMAIN related Information and whois.nic.mil for NIPRNET Information. TCP Connection Attempted on Protected Port
Asia Pacific Network Information Centre This IP address range is not registered in the ARIN database. For details, refer to the APNIC Whois Database via WHOIS.APNIC.NET or http://www.apnic.net/apnic-bin/whois2.pl IMPORTANT NOTE: APNIC is the Regional Internet Registry for the Asia Pacific region. APNIC does not operate networks using this IP address range and is not able to investigate spam or abuse reports relating to these addresses. For more help, refer to http://www.apnic.net/info/faq/abuse/
Record last updated on 18-Dec-2000. Database last updated on 21-Jun-2002 19:59:57 EDT. SERVER のコンピュータがあなたのコンピュータの TCP ポート80 に接続しようとしました。 TCP ポート80 は通常 "World Wide Web HTTP" サービスまたはプログラムが使用します。HTTP は、WWW ページを提供および要求するために使用されます。
発信元のコンピュータがユーザのマシンで Web サーバをスキャンしたか、また・ NS.APNIC.NET o.coク・x The ARIN Registration Services Host contains ONLY Internet Network Information: Networks, ASN's, and related POC's. Please use the whois server at rs.internic.net for DOMAIN related Information and whois.nic.mil for NIPRNET Information.
発信元のコンピュータがユーザのマシンで Web サーバをスキャンしたか、またはトロイの木馬「Executor」をスキャンした可能性がありますが、NeoWatch のセキュリティ フィルタによってブロックされました。「Executor」 は、標準の HTTP ポート 80 を使用するトロイの木馬です。
このイベントはHackerコミュニティーの活動と関係があるかもしれません。このイベントを報告することをお勧めします。メイン画面の『イベントを報告する』リンクから実行してください。 Asia Pacific Network Information Center (NET-APNIC4) APNIC AU
Netname: APNIC4 Netblock: 218.0.0.0 - 218.255.255.255 Maintainer: AP
Coordinator: Administrator, System (SA90-ARIN) [No mailbox] +61 7 3858 3100
Asia Pacific Network Information Centre This IP address range is not registered in the ARIN database. For details, refer to the APNIC Whois Database via WHOIS.APNIC.NET or http://www.apnic.net/apnic-bin/whois2.pl IMPORTANT NOTE: APNIC is the Regional Internet Registry for the Asia Pacific region. APNIC does not operate networks using this IP address range and is not able to investigate spam or abuse reports relating to these addresses. For more help, refer to http://www.apnic.net/info/faq/abuse/
Record last updated on 18-Dec-2000. Database last updated on 21-Jun-2002 19:59:57 EDT.
The ARIN Registration Services Host contains ONLY Internet Network Information: Networks, ASN's, and related POC's. Please use the whois server at rs.internic.net for DOMAIN related Information and whois.nic.mil for NIPRNET Information.
Asia Pacific Network Information Centre This IP address range is not registered in the ARIN database. For details, refer to the APNIC Whois Database via WHOIS.APNIC.NET or http://www.apnic.net/apnic-bin/whois2.pl IMPORTANT NOTE: APNIC is the Regional Internet Registry for the Asia Pacific region. APNIC does not operate networks using this IP address range and is not able to investigate spam or abuse reports relating to these addresses. For more help, refer to http://www.apnic.net/info/faq/abuse/
Record last updated on 18-Dec-2000. Database last updated on 21-Jun-2002 19:59:57 EDT. IP アドレス 218.71.9.159 のコンピュータがあなたのコンピュータの TCP ポート80 に接続しようとしました。 TCP ポート80 は通常 "World Wide Web HTTP" サービスまたはプログラムが使用します。HTTP は、WWW ページを提供および要求するために使用されます。
発信元のコンピュータがユーザのマシンで Web サーバをスキャンしたか!C.NET @甌 The ARIN Registration Services Host contains ONLY Internet Network Information: Networks, ASN's, and related POC's. Please use the whois server at rs.internic.net for DOMAIN related Information and whois.nic.mil for NIPRNET Information.
nsca01.mesh.ad.jp inetnum: 210.147.0.0 - 210.147.255.255 netname: NEC-MESH descr: C&C Internet Service mesh descr: (NEC Corporation) country: JP admin-c: TN265JP tech-c: NK032JP remarks: This information has been partially mirrored by APNIC from remarks: JPNIC. To obtain more specific information, please use the remarks: JPNIC whois server at whois.nic.ad.jp. (This defaults to remarks: Japanese output, use the /e switch for English output) remarks: This information has been partially mirrored by APNIC from remarks: JPNIC. To obtain more specific information, please use the remarks: JPNIC whois server at whois.nic.ad.jp. (This defaults to remarks: Japanese output, use the /e switch for English output) changed: [email protected] 19970226 changed: [email protected] 20020619 source: JPNIC
このホストは ORDB.org に不正中継ホストとして登録されていません。 データベースの検索結果: kingkong.mach10hosting.com (198.87.240.184) Look up this host in non-ORDB RBL's (May take a while to load) ホスト kingkong.mach10hosting.com は ORDB.org のデータベースに登録されていません。
このホストは ORDB.org に不正中継ホストとして登録されていません。 データベースの検索結果: mail.mach10hosting.com (204.1.28.201) Look up this host in non-ORDB RBL's (May take a while to load) ホスト mail.mach10hosting.com は ORDB.org のデータベースに登録されていません。
通信していた nsh1.enjoy.ne.jp のコンピュータが、予想していないポート(UDP ポート1098)にアクセスしようとしました。 UDP ポート10・F [ JPNIC & JPRS database provides information on network administration. Its ] [ use is restricted to network administration purposes. For further infor- ] [ mation, use 'whois -h whois.nic.ad.jp help'. To suppress Japanese output, ] [ add'/e' at the end of command, e.g. 'whois -h whois.nic.ad.jp xxx/e'. ]
Domain Information: a. [Domain Name] ENJOY.NE.JP d. [Network Service Name] DEODEO Internet Service l. [Organization Type] Network Service m. [Administrative Contact] KM057JP n. [Technical Contact] HS221JP n. [Technical Contact] HN2413JP n. [Technical Contact] SN2019JP n. [Technical Contact] MK5262JP p. [Name Server] ns.enjoy.ne.jp p. [Name Server] ns.enjoy.ad.jp p. [Name Server] nso1.enjoy.ne.jp y. [Reply Mail] [email protected] y. [Reply Mail] [email protected] y. [Reply Mail] [email protected] [State] Connected (2003/02/28) [Registered Date] 1997/02/14 [Connected Date] 1997/02/19 [Last Update] 2001/01/16 11:22:01 (JST) [email protected] Rights restricted by copyright. See http://www.apnic.net/db/dbcopyright.html (whois7.apnic.net)
このホストは ORDB.org に不正中継ホストとして登録されていません。 データベースの検索結果: smtp.dealmate.com (216.145.9.173) Look up this host in non-ORDB RBL's (May take a while to load) ホスト smtp.dealmate.com は ORDB.org のデータベースに登録されていません。 データベースの検索結果: mail.dealmate.com (216.145.9.172) Look up this host in non-ORDB RBL's (May take a while to load) ホスト mail.dealmate.com は ORDB.org のデータベースに登録されていません。 データベースの検索結果: 208.198.128.91 (208.198.128.91) Look up this host in non-ORDB RBL's (May take a while to load) ホスト 208.198.128.91 は ORDB.org のデータベースに登録されていません。 データベースの検索結果: 10.16.1.111 (10.16.1.111) Look up this host in non-ORDB RBL's (May take a while to load) ホスト 10.16.1.111 は ORDB.org のデータベースに登録されていません。
このホストは ORDB.org に不正中継ホストとして登録されていません。 データベースの検索結果: smtp.dealmate.com (216.145.9.173) Look up this host in non-ORDB RBL's (May take a while to load) ホスト smtp.dealmate.com は ORDB.org のデータベースに登録されていません。 データベースの検索結果: mail.dealmate.com (216.145.9.172) Look up this host in non-ORDB RBL's (May take a while to load) ホスト mail.dealmate.com は ORDB.org のデータベースに登録されていません。 データベースの検索結果: 208.198.128.91 (208.198.128.91) Look up this host in non-ORDB RBL's (May take a while to load) ホスト 208.198.128.91 は ORDB.org のデータベースに登録されていません。 データベースの検索結果: 10.16.1.111 (10.16.1.111) Look up this host in non-ORDB RBL's (May take a while to load) ホスト 10.16.1.111 は ORDB.org のデータベースに登録されていません。
このホストは ORDB.org に不正中継ホストとして登録されていません。 データベースの検索結果: 211.184.224.60 (211.184.224.60) Look up this host in non-ORDB RBL's (May take a while to load) ホスト 211.184.224.60 は ORDB.org のデータベースに登録されていません。
Network Information: [ネットワーク情報] a. [IPネットワークアドレス] 210.153.102.0 b. [ネットワーク名] SUITE-NET f. [組織名] サーバ貸し出しサービス(株式会社NTTPCコミュニケーションズ) g. [Organization] Server Rental Service (NTTPCCommunications,Inc.) m. [運用責任者] HH1558JP n. [技術連絡担当者] RK448JP p. [ネームサーバ] ns3.sphere.ad.jp p. [ネームサーバ] ns4.sphere.ad.jp y. [通知アドレス] [email protected] [割当年月日] 2002/03/08 [返却年月日] [最終更新] 2002/03/08 16:12:12 (JST) [email protected]
Network Information: [ネットワーク情報] a. [IPネットワークアドレス] 210.130.0.0-210.130.161.0 b. [ネットワーク名] IIJNET f. [組織名] IIJ インターネット g. [Organization] IIJ Internet m. [運用責任者] TM003JP n. [技術連絡担当者] JY018JP p. [ネームサーバ] dns0.iij.ad.jp p. [ネームサーバ] dns1.iij.ad.jp y. [通知アドレス] [email protected] [割当年月日] 1996/10/09 [返却年月日] [最終更新] 1998/01/30 09:21:25 (JST) [email protected]
Network Information: [ネットワーク情報] a. [IPネットワークアドレス] 203.138.78.0-203.138.80.0 b. [ネットワーク名] SUITE-NET f. [組織名] サーバ貸し出しサービス(株式会社NTTPCコミュニケーションズ) g. [Organization] Server Rental Service (NTTPCCommunications,Inc.) m. [運用責任者] HH1558JP n. [技術連絡担当者] RK448JP p. [ネームサーバ] ns3.sphere.ad.jp p. [ネームサーバ] ns4.sphere.ad.jp y. [通知アドレス] [email protected] y. [通知アドレス] [email protected] [割当年月日] 2001/05/28 [返却年月日] [最終更新] 2001/05/30 17:35:37 (JST) [email protected]
inetnum: 0.0.0.0 - 255.255.255.255 netname: IANA-BLK descr: The whole IPv4 address space country: NL admin-c: IANA1-RIPE tech-c: IANA1-RIPE status: ALLOCATED UNSPECIFIED remarks: The country is really worldwide. remarks: This address space is assigned at various other places in remarks: the world and might therefore not be in the RIPE database. mnt-by: RIPE-NCC-HM-MNT mnt-lower: RIPE-NCC-HM-MNT mnt-routes: RIPE-NCC-NONE-MNT changed: [email protected] 20010529 changed: [email protected] 20020625 source: RIPE
role: Internet Assigned Numbers Authority address: see http://www.iana.org. e-mail: [email protected] admin-c: IANA1-RIPE tech-c: IANA1-RIPE nic-hdl: IANA1-RIPE remarks: For more information on IANA services remarks: go to IANA web site at http://www.iana.org. mnt-by: RIPE-NCC-MNT changed: [email protected] 20010411 source: RIPE
netname: CNCNET descr: China Netcom Corp. Beijing descr: New Telecommunication Carrier Based on IP Backbone country: CN admin-c: YZ213-AP tech-c: YZ213-AP mnt-by: APNIC-HM mnt-lower: MAINT-CN-ZM28 changed: [email protected] 20010919 changed: [email protected] 20020703 source: APNIC
These blocks are reserved for special purposes. Please see RFC 1918 for additional information.
Record last updated on 12-Oct-2001. Database last updated on 8-Jul-2002 20:01:39 EDT.
The ARIN Registration Services Host contains ONLY Internet Network Information: Networks, ASN's, and related POC's. Please use the whois server at rs.internic.net for DOMAIN related Information and whois.nic.mil for NIPRNET Information.