BetaONE will rise again!


Reply
  #11  
Old 14th Oct 04, 03:27 PM
rikytik's Avatar
rikytik rikytik is offline
BetaONE Supporter
 
Join Date: Jul 2001
Location: Canada
Posts: 1,051
rikytik is an unknown quantity at this point
------meanwhile, a couple hours later-----------

Sony's thread about PCAudi and War's explanation were a wake up call for me. In going thru the paces, I installed x-NetStat 5.1 and found a curious connection from the other pc on my LAN.

Hostname: moscow.eau.wi.charter.com

This didn't show up in Sygate (latest version, set to DLL Authentification, but showed up in x-NetStat with the IP of the other pc on this LAN.

I ran AdAware, Trojan Remove, Kaspersky AV 5 and nothing showed up. Finally I did a search of the registry with Registry Crawler and found moscow.eau, etc. two places in the Registry along with some other moscow things.

At that point I deleted all the cookies in IE6 (there were a lot)and then the registry entries disappeared. I don't know what to make of it.

Anyway, things are tighter here now, thanks to the Sony's thread.
Reply With Quote
  #12  
Old 14th Oct 04, 06:23 PM
Sony's Avatar
Sony Sony is offline
M.I.A.
 
Join Date: Nov 2001
Location: Down Under
Posts: 319
Sony will become famous soon enoughSony will become famous soon enough
Send a message via ICQ to Sony Send a message via MSN to Sony
Quote:
Originally posted by rikytik@Oct 14 2004, 01:27 PM
.........  Hostname: moscow.eau.wi.charter.com

This didn't show up in Sygate (latest version, set to DLL Authentification, but showed up in x-NetStat with the IP of the other pc on this LAN. 

.....

I found the same entry on my pc (see screenshot)

The weird thing is that show my internal IP with that host name!!!

I need to ivestigate this , now you got me worried

If you find more information please let me know it's time to bed here so I will have to do my homework tomorrow morning about moscow.eau.wi.charter.com

Sony
__________________
[img]http://www.bbstyles.com/sony.php[/img]
Reply With Quote
  #13  
Old 15th Oct 04, 12:07 AM
rikytik's Avatar
rikytik rikytik is offline
BetaONE Supporter
 
Join Date: Jul 2001
Location: Canada
Posts: 1,051
rikytik is an unknown quantity at this point
Wow. Really weird. Your screen shot is exactly like mine.

I thougtht it gone after a total cookie and registy clean up, but this evening that same thing logged on. With x-NetSTat I was able to kick it off, but Sygate isn't doing anything.

The saga continues.

Reply With Quote
  #14  
Old 15th Oct 04, 01:14 AM
war59312 war59312 is offline
BetaONE Supporter
 
Join Date: Jul 2001
Location: U.S.A
Posts: 2,220
war59312 has disabled reputation
Send a message via ICQ to war59312 Send a message via AIM to war59312 Send a message via MSN to war59312 Send a message via Yahoo to war59312
Try Ethereal for more info.

BTW:

Quote:

Registrant:
Charter Communications Holding Company, LLC (CHARTER25-DOM)
  12405 Powerscourt Drive
  St. Louis, MO 63131
  US

  Domain Name: CHARTER.COM

  Administrative Contact:
      MASTER, HOST  (20118779I)                     
      Charter Communications Holding Company
      12405 Powerscourt Drive
      St. Louis, MO 63131
      US
      636 733 5300 fax: 636 394 9797

  Technical Contact:
      Charter Communications  (GZDZEHXCQO)                     
      12405 Powerscourt Dr.
      St. Louis, MO 63131
      US
      314-288-3889

  Record expires on 29-Jul-2006.
  Record created on 30-Jul-1994.

  Domain servers in listed order:

  NS1.CHARTER.COM              24.196.241.11
  NS2.CHARTER.COM              24.213.60.79
  NS3.CHARTER.COM              24.197.96.17
  NS4.CHARTER.COM              24.205.1.12

Quote:

Website Title:  Charter
Response Code:  200
SSL Cert:  www.charter.com SSL is expired!
Yahoo Directory:  B2B > Broadband
Yahoo Title:  Charter Communications
Yahoo Description:  Broadband communications company.
Website Status:  Active
Reverse IP:  Web server hosts 11 websites (reverse ip tool requires free login)
Server Type:  Microsoft-IIS/5.0
IP Address:  208.223.219.206 (ARIN & RIPE IP search)
IP Location:  - Missouri - Chesterfield - Catalyst Soloutions Group
Whois History:  127 records stored
Record Type:  Domain Name
Monitor:  Monitor or Backorder
Wildcard search:  'charter' in all domains.
Other TLDs:  .com .net .org .info .biz .us
X X X X X X

Name Server:  NS1.CHARTER.COM NS2.CHARTER.COM
ICANN Registrar:  NETWORK SOLUTIONS, LLC.
Created:  30-jul-1994
Expires:  29-jul-2006
Status:  ACTIVE

Oh nice. IIS 5.0. hehe You know what that means. :P
__________________
Ad Muncher Usage Statistics for v4.7 Build 27105/1624
Adverts removed by Ad Muncher: 1,601,933
Approximate bandwidth saved: 12,515 MB
Counter started: April 2, 2003

Download: http://war59312.admuncher.com/download.shtml
Reply With Quote
  #15  
Old 15th Oct 04, 02:30 AM
Sony's Avatar
Sony Sony is offline
M.I.A.
 
Join Date: Nov 2001
Location: Down Under
Posts: 319
Sony will become famous soon enoughSony will become famous soon enough
Send a message via ICQ to Sony Send a message via MSN to Sony
Quote:
Originally posted by war59312@Oct 14 2004, 11:14 PM
Try Ethereal for more info.

BTW:
Oh nice. IIS 5.0. hehe You know what that means. :P
[snapback]215530[/snapback]

I still don't get why my internal IP is associate with that domain ?
__________________
[img]http://www.bbstyles.com/sony.php[/img]
Reply With Quote
  #16  
Old 15th Oct 04, 04:56 AM
war59312 war59312 is offline
BetaONE Supporter
 
Join Date: Jul 2001
Location: U.S.A
Posts: 2,220
war59312 has disabled reputation
Send a message via ICQ to war59312 Send a message via AIM to war59312 Send a message via MSN to war59312 Send a message via Yahoo to war59312
Quote:
Originally posted by sony@Oct 14 2004, 08:30 PM
I still don't get why my internal IP is associate with that domain ?
[snapback]215547[/snapback]
oh wtf yeah i was not even paying attendtion lol

Is that not your host name?

If it is then it just got it by resolving your internet ip address (Reverse DNS) and just told u your lan ip address instead.

If not then some program is messing with your dns server and assigning a host name to your lan ip for whatever reason. Or you isp did or whatever...
__________________
Ad Muncher Usage Statistics for v4.7 Build 27105/1624
Adverts removed by Ad Muncher: 1,601,933
Approximate bandwidth saved: 12,515 MB
Counter started: April 2, 2003

Download: http://war59312.admuncher.com/download.shtml
Reply With Quote
  #17  
Old 15th Oct 04, 11:19 AM
unicorn unicorn is offline
Senior Member
 
Join Date: Oct 2001
Location: GMT+1
Posts: 851
unicorn is on a distinguished road
war:
Quote:
BTW:
Oh nice. IIS 5.0. hehe You know what that means. :P
[snapback]215530[/snapback]
No. What does it mean? (Is it a microsoft server that is hacked by deafult?)

What is a reasonable explanation to the "moscow" part of the ip? Is that one of the web sites that is hosted by charter.com? I noticed that moscow demands a login to their website.

This thread is too confusing to me. The only conclusion I have done so far is that I should have a separate box for my www adventures. There I should start fresh every session by using a ghosted image of a clean install. Or a deep freezed version. Gonna check theese options. A separate box may be just the right thing, then I can have my computer where I really work clean and nice.
This is getting crazy. Do I want to live in such a world? Of course I do (the option seems boring) but I don't really want to spend half of my time to different security precautions.

Thanks to all that contributed here,
__________________
unicorn
Reply With Quote
  #18  
Old 15th Oct 04, 12:59 PM
rikytik's Avatar
rikytik rikytik is offline
BetaONE Supporter
 
Join Date: Jul 2001
Location: Canada
Posts: 1,051
rikytik is an unknown quantity at this point
I found the moscow thing on there again a bit ago.

There are quite a few articles around about IIS. I don't understand this problem yet.
Reply With Quote
  #19  
Old 15th Oct 04, 03:24 PM
war59312 war59312 is offline
BetaONE Supporter
 
Join Date: Jul 2001
Location: U.S.A
Posts: 2,220
war59312 has disabled reputation
Send a message via ICQ to war59312 Send a message via AIM to war59312 Send a message via MSN to war59312 Send a message via Yahoo to war59312
oh my bad...i was just kidding...i just men IIS is a pos and there are so many security issues....thats all... srry for the confusion...

lol

Um yeah I would say that a charter isp ip address....is that your ISP?

if not yeah something is going on...
__________________
Ad Muncher Usage Statistics for v4.7 Build 27105/1624
Adverts removed by Ad Muncher: 1,601,933
Approximate bandwidth saved: 12,515 MB
Counter started: April 2, 2003

Download: http://war59312.admuncher.com/download.shtml
Reply With Quote
  #20  
Old 15th Oct 04, 03:28 PM
war59312 war59312 is offline
BetaONE Supporter
 
Join Date: Jul 2001
Location: U.S.A
Posts: 2,220
war59312 has disabled reputation
Send a message via ICQ to war59312 Send a message via AIM to war59312 Send a message via MSN to war59312 Send a message via Yahoo to war59312
Um moscow.eau.wi.charter.com?

Site does not even exist it seems? At least not http.

Quote:
Originally posted by unicorn@Oct 15 2004, 05:19 AM
war:

No. What does it mean? (Is it a microsoft server that is hacked by deafult?)

What is a reasonable explanation to the "moscow" part of the ip? Is that one of the web sites that is hosted by charter.com? I noticed that moscow demands a login to their website.

This thread is too confusing to me. The only conclusion I have done so far is that I should have a separate box for my www adventures. There I should start fresh every session by using a ghosted image of a clean install. Or a deep freezed version. Gonna check theese options. A separate box may be just the right thing, then I can have my computer where I really work clean and nice.
This is getting crazy. Do I want to live in such a world? Of course I do (the option seems boring) but I don't really want to spend half of my time to different security precautions.

Thanks to all that contributed here,
[snapback]215575[/snapback]
__________________
Ad Muncher Usage Statistics for v4.7 Build 27105/1624
Adverts removed by Ad Muncher: 1,601,933
Approximate bandwidth saved: 12,515 MB
Counter started: April 2, 2003

Download: http://war59312.admuncher.com/download.shtml
Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
Sygate Personal Firewall 5.6 Beta Build 2808 war59312 Other Beta Software 0 30th Oct 04 11:56 PM
AntiVirus & Spware / Adware & Firewall Resources Article war59312 Internet Security and Privacy 2 24th Oct 04 01:45 AM
Nvidia Puts a Firewall on a Motherboard NewsBot NeoWin News 0 21st Oct 04 12:57 PM
Speed up system. greasemonkey Hardware Support 6 6th Nov 01 08:32 PM


All times are GMT +1. The time now is 09:59 PM.


Design by Vjacheslav Trushkin for phpBBStyles.com.
Powered by vBulletin® Version 3.6.5
Copyright ©2000 - 2024, Jelsoft Enterprises Ltd.