Should I be suspicious of this?

Should I be suspicious of this?

Secure Home | Search | About

Networking Firewalls - Software and hardware firewalls discussions 

Bookmark this page:  YahooMyWeb Yahoo!  Google Google  Windows Live Favorites Windows Live  del.icio.us del.icio.us  digg digg  Add to Netscape Netscape
Subject Author Date
Should I be suspicious of this? Bluuuue Rajah 06-14-2009
Posted by Bluuuue Rajah on June 14, 2009, 9:40 am
If you were  Registered and logged in, you could reply and use other advanced thread options

I'm always suspicious of sex links that point back to lawless or communist
countries, and somebody posted this link for a nipple slip pic onto agc,
but the link points back to China.

http://downunderdaily.com/Entertainment/Celebrity/bethenny-frankel-shows-
nipples-in-a-see-through-dress.html

The link makes it look like they're in Australia, which they aren't, so it
looks like they've gone to a lot of trouble to cover their trail. Norton
Security flags it as clean, but I worry that the Chinese are good enough to
get around Norton and still get a Trojan under the radar.

Should I be suspicious of this, or am I just being a fraidy cat?

Posted by Ant on June 14, 2009, 12:07 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
"Bluuuue Rajah" wrote:

> I'm always suspicious of sex links that point back to lawless or communist
> countries, and somebody posted this link for a nipple slip pic onto agc,
> but the link points back to China.

No, it doesn't. It points to 174.132.105.34 which is owned by
theplanet.com in the US.

> http://downunderdaily.com/Entertainment/Celebrity/bethenny-frankel-shows-
> nipples-in-a-see-through-dress.html
>
> The link makes it look like they're in Australia, which they aren't, so it
> looks like they've gone to a lot of trouble to cover their trail.

Hardly. They're using Hostgator.

$> host downunderdaily.com
downunderdaily.com has address 174.132.105.34

$> host 174.132.105.34
34.105.132.174.in-addr.arpa domain name pointer gator618.hostgator.com.

$> whois 174.132.105.34
OrgName: ThePlanet.com Internet Services, Inc.
...
Country: US
...
NetRange: 174.132.0.0 - 174.133.255.255
CIDR: 174.132.0.0/15
OriginAS: AS13749, AS21844, AS30315, AS36420
NetName: NETBLK-THEPLANET-BLK-15
...etc.



Posted by Bit Twister on June 14, 2009, 2:10 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
On Sun, 14 Jun 2009 13:40:34 GMT, Bluuuue Rajah wrote:

> Norton
> Security flags it as clean,

So tell me, how often is your AV database updated.
Last stats I saw was about 4,000 new pieces of malware released daily.
That works out to around 1 ever 30 seconds.

Then your AV vendor has to catch a copy, test, update their database and you
get around to downloading it sometime later.

You might want to click on some of the dates and check detection time at
http://www.commtouch.com/security-center then
click the Malware Outbreak Center link.


Posted by Robert James on June 14, 2009, 2:31 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Well, by running *nix based systems like Slackware Linux, PC-BSD and Mac OS
X, I am not worried to much. Although subscribing to Full Discloser via
email makes me wonder if I should be...

Considering that all links to it are posted on forums by newbies I would say
yes.

But I went to the site. Ugly old woman... No malware issues on Firefox on a
updated *nix box


On 14/06/2009 14:40, in article
Xns9C2A62711ECE5lkajehoriuasldfjknak@207.115.33.102, "Bluuuue Rajah"

> http://downunderdaily.com/Entertainment/Celebrity/bethenny-frankel-shows-
> nipples-in-a-see-through-dress.html

--
http://www.robertjames.50webs.com

This message may contain confidential information and is intended only for
the individual named. If you are not the named addressee you should not
disseminate, distribute or copy this e-mail. Please notify the sender
immediately by e-mail if you have received this e-mail by mistake and delete
this e-mail from your system.


Posted by FrozenNorth on June 14, 2009, 2:40 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Robert James wrote:
> Well, by running *nix based systems like Slackware Linux, PC-BSD and Mac OS
> X, I am not worried to much. Although subscribing to Full Discloser via
> email makes me wonder if I should be...
>
> Considering that all links to it are posted on forums by newbies I would say
> yes.
>
> But I went to the site. Ugly old woman... No malware issues on Firefox on a
> updated *nix box
>
Just to avoid the top-posting I did a big snip. Thought you had this
fixed up yesterday.

She is neither ugly or old, at least by my definition, but there are big
black rectangles in place of the nips, so the OP shouldn't feel like he
is missing anything.


--
Froz...

Similar ThreadsPosted
Suspicious Packets Using Yproxy August 3, 2004, 9:13 pm
How to tell if a firewall alert is suspicious or not September 15, 2005, 4:50 am
Suspicious n/a network activity October 19, 2005, 6:31 am
Need Opinion on the Following Suspicious Activity August 17, 2006, 6:23 pm
Diversion to non-responding, suspicious sites? August 3, 2006, 7:11 am
Please help me interpret a suspicious netstat SYN_SENT TCP port 1058 ? February 23, 2006, 11:27 am

The site map in XML format XML site map

Contact Us | Privacy Policy