Postcards From The Firewall

Lancecastor

Lit's Most Beloved Poster
Joined
May 14, 2002
Posts
54,670
Here's a fun one:

219.165.244.130 is a reserved address

The Internet Assigned Numbers Authority (IANA) has reserved this address for its own use. Unless you are on a network that is actively involved in the development of the system for assigning IP addresses, this address was probably forged in order to hide the identity of the sender.
 
Re: Re: Re: Postcards From The Firewall

Lancecastor said:
No? Qui est la?

Japan as well.
Just to state this,either it's some japanese that is pinging you that your Firewall picked up or someone is using an "Anonymizer" going through a third party proxy to ping people.

You're probably not singled out as one usually sets a scanner up to ping a whole slew of IPs in batches and then see where the door is open to go check if they seem to hold interest.
 
My firewall blocks port scans a dozen time a day. It's just internet crud.
 
Harbinger said:
My firewall blocks port scans a dozen time a day. It's just internet crud.

Yup,which is why I dislike this crying wolf that's been going on here lately.
 
Re: 219.165.244.130

Lancecastor said:
No? Qui est la?
Code:
[b]219.165.244.130

;; res options: init recurs defnam dnsrch
;; got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 4
;; flags: qr rd ra; QUERY: 1, ANSWER: 1, AUTHORITY: 3, ADDITIONAL: 3
;; QUERY SECTION:
;; 130.244.165.219.in-addr.arpa, type = ANY, class = IN

;; ANSWER SECTION:
130.244.165.219.in-addr.arpa.  20h22m53s IN PTR  n244130.ap.plala.or.jp.

;; AUTHORITY SECTION:
244.165.219.IN-ADDR.ARPA.  23h46m19s IN NS  dns1.plala.or.jp.
244.165.219.IN-ADDR.ARPA.  23h46m19s IN NS  dns2.plala.or.jp.
244.165.219.IN-ADDR.ARPA.  23h46m19s IN NS  ns-tk061.ocn.ad.jp.

;; ADDITIONAL SECTION:
dns1.plala.or.jp. 23h56m34s IN A 210.153.0.129
dns2.plala.or.jp. 23h56m34s IN A 210.153.0.130
ns-tk061.ocn.ad.jp. 23h56m34s IN A 202.234.233.103

;; Total query time: 55 msec
;; FROM: endymion to SERVER: default -- 0.0.0.0
;; WHEN: Mon Dec  9 23:47:00 2002
;; MSG SIZE  sent: 46  rcvd: 222[/b]
 
Re: Re: Re: Postcards From The Firewall

Lancecastor said:
No? Qui est la?

tu n'est pas venu m'aider dans mon thread le castor....tu me manques...
 
People should be reminded to have good firewall protection, and know how to use it, but not because of any threat from here.
 
Pagliacci said:
Yup,which is why I dislike this crying wolf that's been going on here lately.

I agree. People should put their packets on the table or shut up.

Anonymized or bulk port sweeps, at least we're all talking entire IP addresses instead of playing The Great Carnac.
 
Re: Re: Re: Re: Postcards From The Firewall

roxanne69 said:
tu n'est pas venu m'aider dans mon thread le castor....tu me manques...

Je m'ennuie de vous
 
Does anyone know where I can get info on the kinds of probes that my computer is getting?

I found one website with a little info on one of the kinds of probes.. but I haven't had much luck with the others.
 
Re: Re: 219.165.244.130

Byron In Exile said:
Code:
[b]219.165.244.130


244.165.219.IN-ADDR.ARPA.  23h46m19s IN NS  dns1.plala.or.jp.
[/B][/QUOTE] 

Thanks.

I get a lot of plala.or.jp port pokes.
 
Whois 219.165.244.130 ?

Code:
[b]% [whois.apnic.net node-2]

inetnum:      219.160.0.0 - 219.165.255.255
netname:      OCN
descr:        OCN Provided By NTT-Communications which is ISP
descr:        in Chiyoda-ku, Tokyo, Japan
country:      JP
admin-c:      MK99-AP
tech-c:       TH64-AP
remarks:      ************************************************
remarks:      Allocated to JPNIC member. Authoritative
remarks:      information regarding assignments and allocation
remarks:      made from within this block can also be queried
remarks:      at whois.nic.ad.jp. To obtain an English output
remarks:      query whois -h whois.nic.ad.jp x.x.x.x/e
remarks:      ************************************************
mnt-by:       MAINT-JPNIC
mnt-lower:    MAINT-JPNIC
changed:      [email]hostmaster@apnic.net[/email] 20020408
changed:      [email]hm-changed@apnic.net[/email] 20020904
status:       ALLOCATED PORTABLE
source:       APNIC

person:       Mitsuhiko Kozaka
address:      NTT Dewamachi Bldg.
address:      4-1,Dewa-machi,
address:      Kanazawa-shi, ISHIKAWA
address:      920-0963 JAPAN
country:      JP
phone:        +81 76 232 9200
fax-no:       +81 76 265 7013
e-mail:       [email]jpnic@soc.ocn.ad.jp[/email]
nic-hdl:      MK99-AP
mnt-by:       MAINT-JP-OCN
changed:      [email]tateyama@soc.ocn.ad.jp[/email] 20010718
source:       APNIC

person:       Tamiyoshi Higashinaka
address:      NTT Dewamachi Bldg.
address:      4-1,Dewa-machi,
address:      Kanazawa-shi, ISHIKAWA
address:      920-0963 JAPAN
country:      JP
phone:        +81 76 232 9200
fax-no:       +81 76 265 7013
e-mail:       [email]jpnic@soc.ocn.ad.jp[/email]
nic-hdl:      TH64-AP
mnt-by:       MAINT-JP-OCN
changed:      [email]tateyama@soc.ocn.ad.jp[/email] 20010717
source:       APNIC

inetnum:      219.165.128.0 - 219.165.255.255
netname:      PLALA
descr:       Plala Networks Inc.
country:      JP
admin-c:      MN2905JP
tech-c:       HS3694JP
remarks:      This information has been partially mirrored by APNIC from
remarks:      JPNIC. To obtain more specific information, please use the
remarks:      JPNIC whois server at whois.nic.ad.jp. (This defaults to
remarks:      Japanese output, use the /e switch for English output)
changed:      [email]apnic-ftp@nic.ad.jp[/email] 20020808
remarks:      This information has been partially mirrored by APNIC from
remarks:      JPNIC. To obtain more specific information, please use the
remarks:      JPNIC whois server at whois.nic.ad.jp. (This defaults to
remarks:      Japanese output, use the /e switch for English output)
changed:      [email]apnic-ftp@nic.ad.jp[/email] 20021113
source:       JPNIC[/b]
 
Look, dammit, this is just an outfit I wear. I live in Kentucky, I swear!
 
freakygurl said:
Is that "crying wolf" line directed at me :)

No not really,you posed a question.
it was one sincere question in what seems to have become a snoballing misch-masch of baying at the moon that nothing on this place is safe and that Lit is in fact just a cover for the collected hackers of the western world,doing nothing but reading PMs and trying to get into your computer.

It pisses me off that grown people behave like a bunch of three year olds scared about the dark.
 
Re: Re: Re: Re: Re: Re: Postcards From The Firewall

roxanne69 said:

Thank God you didn't reply in French. I'd have worn out poor babelfish for sure. :)
 
Pagliacci

Thanks for answering my question. :)

And again, for the record, I'm asking questions because.. I'm curious not because I care. My firewall is stopping a lot of shit... from Lit, From yahoo and from MSN messenger. It's doing the job I installed it to do.

A year ago.. I was firewall free.. because I knew nothing about it. Now that I have one, I'm curious as to what it does.. how it does it.. and why things probe my ports. Computers fasinate me.
 
freakygurl said:
Pagliacci

Thanks for answering my question. :)

And again, for the record, I'm asking questions because.. I'm curious not because I care. My firewall is stopping a lot of shit... from Lit, From yahoo and from MSN messenger. It's doing the job I installed it to do.

A year ago.. I was firewall free.. because I knew nothing about it. Now that I have one, I'm curious as to what it does.. how it does it.. and why things probe my ports. Computers fasinate me.

I know you are,that's why I'm responding :)
Now why did you say that Yahoo and MSN ping you as well,people will start a gazillion threads about how their IMs and webacm photos are being seen and IM logs being read by Yahoo and MSN personnel and that their privacy is in jeopardy ;)

I'm off to the bath though.
 
Back
Top