PDA

View Full Version : Ping Of Death Detect



atiVidia
04-12-2004, 10:50 PM
thank god its dropping them tho. is there any way for me to trace the IP?

Apr/12/2004 13:44:08

Ping of Death Detect

211.13.139.79:33108

141.156.251.147:6881

Packet Dropped

it repeats on random intervals of either 10 or 20 minutes. nowhere in between.


wht the hell???





lol every1 running a broadband account better have a firewall. if u dont SHAME ON U!!! :angry:

@ vb: not sure if this belongs in hardware world or internet world your pick. prolly internet world tho lol...

Mad Cat
04-12-2004, 11:03 PM
IP address: 211.13.139.79
Host name: e139079.ppp.asahi-net.or.jp

TraceRoute to 211.13.139.79 [e139079.ppp.asahi-net.or.jp]

Hop (ms) (ms) (ms)  IP Address Host name
1 0 0 0  66.46.176.3 -
2 0 0 0  216.191.97.41 pos5-3.core1-mtl.bb.allstream.net
3 16 0 16  216.191.65.173 pos2-1.core2-tor.bb.allstream.net
4 15 31 16  216.191.65.198 pos9-0.gwy1-chi.bb.allstream.net
5 15 16 16  216.191.65.38 po-9-2.pr1.ord2.us.mfnx.net
6 16 15 16  64.125.29.118 so-2-2-0.cr1.ord2.us.above.net
7 62 78 63  64.125.30.213 so-4-0-0.mpr3.sjc2.us.above.net
8 78 63 62  64.125.29.153 so-0-0-0.cr1.sjc3.us.above.net
9 172 171 157  64.125.30.9 so-2-2-0.cr2.nrt3.jp.above.net
10 172 172 156  64.125.30.50 pos2-0.er3a.nrt3.jp.above.net
11 218 219 219  209.249.200.14 router-asahinet.nrt3.above.net
12 219 203 219  202.224.32.82 tkybi2.asahi-net.or.jp
13 234 219 234  202.224.36.138 osknip.asahi-net.or.jp
14 219 218 219  211.13.136.3 osknia3.asahi-net.or.jp
15 593 Timed out 640  211.13.139.79 e139079.ppp.asahi-net.or.jp

Trace complete


Third Level Domains are Registered under .jp.
You are attempting to look up a level 2 domain.


--------------------------------------------------------------------------------

WHOIS whois.nic.ad.jp or.jp:

[ JPNIC & JPRS database provides information on network administration. Its  ]
[ use is restricted to network administration purposes. For further infor-    ]
[ mation, use 'whois -h whois.nic.ad.jp help'. To suppress Japanese output,  ]
[ add'/e' at the end of command, e.g. 'whois -h whois.nic.ad.jp xxx/e'.      ]

Domain Information:
a. [Domain Name]                OR.JP
g. [Organization]              Organization Domain
l. [Organization Type]         
m. [Administrative Contact]     
n. [Technical Contact]         
p. [Name Server]                a.dns.jp
p. [Name Server]                b.dns.jp
p. [Name Server]                c.dns.jp
p. [Name Server]                d.dns.jp
p. [Name Server]                e.dns.jp
p. [Name Server]                f.dns.jp
y. [Reply Mail]               
[State]                        Reserved
[Registered Date]               
[Connected Date]               
[Last Update]                  2003/08/20 18:13:02 (JST)


--------------------------------------------------------------------------------

.jp is for Japan
Root: ICANN
Registration web site: http://www.nic.ad.jp/
Whois server: whois.nic.ad.jp
Whois web interface: http://whois.nic.ad.jp/cgi-bin/whois_gw
Third Level Domains Registered
Cost: Fees is Japanese.
Dispute Policy: http://www.nic.ad.jp/en/regist/dom/doc/jp-drp-policy-e.html
ICANN records: http://www.iana.org/root-whois/jp.htm
Notes: .ac.jp, .ad.jp, .co.jp, .ed.jp, .go.jp, .gr.jp, .ne.jp, .or.jp, and .geo.jp are registered. Dispute policy uses wording from the ICANN Universal Domain Name Dispute Resolution Policy (UDRP).
Updated: May 6, 2001

.jp

is not in the Xwhois database

DNS Records for or.jp:

query from dns.consumer.net to get an authoritative nameserver

NameServer used for query: c.dns.jp



Answer records
or.jp 1 NS c.dns.jp 86400s
or.jp 1 NS b.dns.jp 86400s
or.jp 1 NS a.dns.jp 86400s
or.jp 1 NS f.dns.jp 86400s
or.jp 1 NS e.dns.jp 86400s
or.jp 1 NS d.dns.jp 86400s

Authority records

Additional records
c.dns.jp 1 A 165.76.0.98 86400s
b.dns.jp 1 A 202.12.30.131 86400s
a.dns.jp 1 28 [16 bytes] 86400s
a.dns.jp 1 A 203.119.1.1 86400s
f.dns.jp 1 28 [16 bytes] 86400s
f.dns.jp 1 A 150.100.2.3 86400s
e.dns.jp 1 28 [16 bytes] 86400s
e.dns.jp 1 A 192.50.43.53 86400s
d.dns.jp 1 28 [16 bytes] 86400s
d.dns.jp 1 A 210.138.175.244 86400s

DNS Records for asahi-net.or.jp


query from dns.consumer.net to get an authoritative nameserver

NameServer used for query: dns1.asahi-net.or.jp



Answer records
asahi-net.or.jp 1 NS crusader.asahi-net.or.jp 86376s
asahi-net.or.jp 1 NS dns1.asahi-net.or.jp 86376s

Authority records

Additional records
crusader.asahi-net.or.jp 1 A 202.224.39.8 28776s
dns1.asahi-net.or.jp 1 A 202.224.32.19 28776s


Network IP address lookup:

whois whois.arin.net 211.13.139.79:



OrgName:    Asia Pacific Network Information Centre
OrgID:      APNIC
Address:    PO Box 2131
City:      Milton
StateProv:  QLD
PostalCode: 4064
Country:    AU

ReferralServer: whois://whois.apnic.net

NetRange:  210.0.0.0 - 211.255.255.255
CIDR:      210.0.0.0/7
NetName:    APNIC-CIDR-BLK2
NetHandle:  NET-210-0-0-0-1
Parent:   
NetType:    Allocated to APNIC
NameServer: NS1.APNIC.NET
NameServer: NS3.APNIC.NET
NameServer: NS4.APNIC.NET
NameServer: NS.RIPE.NET
NameServer: TINNIE.ARIN.NET
NameServer: DNS1.TELSTRA.NET
Comment:    This IP address range is not registered in the ARIN database.
Comment:    For details, refer to the APNIC Whois Database via
Comment:    WHOIS.APNIC.NET or http://www.apnic.net/apnic-bin/whois2.pl
Comment:    ** IMPORTANT NOTE: APNIC is the Regional Internet Registry
Comment:    for the Asia Pacific region. APNIC does not operate networks
Comment:    using this IP address range and is not able to investigate
Comment:    spam or abuse reports relating to these addresses. For more
Comment:    help, refer to http://www.apnic.net/info/faq/abuse
Comment:   
RegDate:    1996-07-01
Updated:    2004-03-30

OrgTechHandle: AWC12-ARIN
OrgTechName:  APNIC Whois Contact
OrgTechPhone:  +61 7 3858 3100
OrgTechEmail:  [email protected]

# ARIN WHOIS database, last updated 2004-04-11 19:15
# Enter ? for additional hints on searching ARIN's WHOIS database.

Ashashi is the company that does the 100mbit broadband in Japan. If you were using IRC to download at the time, this is probably and IRC bot.


IP address: 141.156.251.147
Host name: pool-141-156-251-147.res.east.verizon.net

TraceRoute to 141.156.251.147 [pool-141-156-251-147.res.east.verizon.net]

Hop (ms) (ms) (ms)  IP Address Host name
1 0 0 0  66.46.176.3 -
2 0 0 0  216.191.97.41 pos5-3.core1-mtl.bb.allstream.net
3 0 16 0  216.191.65.173 pos2-1.core2-tor.bb.allstream.net
4 0 16 0  216.191.65.243 srp2-0.gwy1-tor.bb.allstream.net
5 15 16 31  12.125.142.5 -
6 15 16 31  12.123.5.222 gbr6-p80.cgcil.ip.att.net
7 32 15 16  12.123.6.37 ggr2-p390.cgcil.ip.att.net
8 16 31 16  192.205.32.98 att-gw.chi.qwest.net
9 15 16 31  205.171.139.61 cer-core-02.inet.qwest.net
10 31 16 16  205.171.139.10 cer-core-03.inet.qwest.net
11 47 47 47  205.171.8.165 dca-core-01.inet.qwest.net
12 47 47 47  205.171.9.10 dca-core-03.inet.qwest.net
13 47 47 47  205.171.209.114 -
14 47 47 47  205.171.251.22 dcx-edge-02.inet.qwest.net
15 47 47 47  208.46.127.254 -
16 47 31 47  130.81.10.89 so-7-0-0-0.bb-rtr1.res.verizon-gni.net
17 47 47 46  130.81.9.38 so-2-0-0-0.core-rtr1.res.verizon-gni.net
18 47 47 47  130.81.11.26 a3-0-0-1716.dsl-rtr4.res.verizon-gni.net
19 Timed out 1906 2562  141.156.251.147 pool-141-156-251-147.res.east.verizon.net

Trace complete

Domain registry query for verizon.net:

Whois Server Version 1.3

Domain names in the .com and .net domains can now be registered
with many different competing registrars. Go to http://www.internic.net
for detailed information.

  Domain Name: VERIZON.NET
  Registrar: EMARKMONITOR INC. DBA MARKMONITOR
  Whois Server: whois.markmonitor.com
  Referral URL: http://www.markmonitor.com
  Name Server: NS2.BELLATLANTIC.NET
  Name Server: NS1.BELLATLANTIC.NET
  Name Server: NS2.VERIZON.NET
  Name Server: NS4.VERIZON.NET
  Status: REGISTRAR-LOCK
  Updated Date: 24-sep-2003
  Creation Date: 06-jul-1999
  Expiration Date: 06-jul-2004


>>> Last update of whois database: Mon, 12 Apr 2004 07:09:44 EDT <<<

NOTICE: The expiration date displayed in this record is the date the
registrar&#39;s sponsorship of the domain name registration in the registry is
currently set to expire. This date does not necessarily reflect the expiration
date of the domain name registrant&#39;s agreement with the sponsoring
registrar.&nbsp; Users may consult the sponsoring registrar&#39;s Whois database to
view the registrar&#39;s reported date of expiration for this registration.

TERMS OF USE: You are not authorized to access or query our Whois
database through the use of electronic processes that are high-volume and
automated except as reasonably necessary to register domain names or
modify existing registrations; the Data in VeriSign Global Registry
Services&#39; ("VeriSign") Whois database is provided by VeriSign for
information purposes only, and to assist persons in obtaining information
about or related to a domain name registration record. VeriSign does not
guarantee its accuracy. By submitting a Whois query, you agree to abide
by the following terms of use: You agree that you may use this Data only
for lawful purposes and that under no circumstances will you use this Data
to: (1) allow, enable, or otherwise support the transmission of mass
unsolicited, commercial advertising or solicitations via e-mail, telephone,
or facsimile; or (2) enable high volume, automated, electronic processes
that apply to VeriSign (or its computer systems). The compilation,
repackaging, dissemination or other use of this Data is expressly
prohibited without the prior written consent of VeriSign. You agree not to
use electronic processes that are automated and high-volume to access or
query the Whois database except as reasonably necessary to register
domain names or modify existing registrations. VeriSign reserves the right
to restrict your access to the Whois database in its sole discretion to ensure
operational stability.&nbsp; VeriSign may restrict or terminate your access to the
Whois database for failure to abide by these terms of use. VeriSign
reserves the right to modify these terms at any time.

The Registry database contains ONLY .COM, .NET, .EDU domains and
Registrars.


--------------------------------------------------------------------------------

WHOIS whois.markmonitor.com verizon.net:

MarkMonitor.com - The Leader in Corporate Domain Management
----------------------------------------------------------
For Global Domain Consolidation, Research & Intelligence,
and Enterprise DNS, go to: www.markmonitor.com
----------------------------------------------------------

The Data in MarkMonitor.com&#39;s WHOIS database is provided by MarkMonitor.com
for information purposes, and to assist persons in obtaining information
about or related to a domain name registration record.&nbsp; MarkMonitor.com
does not guarantee its accuracy.&nbsp; By submitting a WHOIS query, you agree
that you will use this Data only for lawful purposes and that, under no
circumstances will you use this Data to: (1) allow, enable, or otherwise
support the transmission of mass unsolicited, commercial advertising or
solicitations via e-mail (spam); or&nbsp; (2) enable high volume, automated,
electronic processes that apply to MarkMonitor.com (or its systems).
MarkMonitor.com reserves the right to modify these terms at any time.
By submitting this query, you agree to abide by this policy.

Registrant:
Verizon Trademark Services LLC (DOM-382081)
1320 North Court House Road
Arlington VA 22201
US

&nbsp; &nbsp; Domain Name: verizon.net

Registrar Name: Markmonitor.com
Registrar Whois: whois.markmonitor.com
Registrar Homepage: http://www.markmonitor.com

&nbsp; &nbsp; Administrative Contact:
Christian R. Andersen (NIC-14209143)&nbsp; Verizon
600 Hidden Ridge Drive HQE03H14
Irving TX 75038
US
[email protected]
+1.9727187621
Fax- -
&nbsp; &nbsp; Technical Contact, Zone Contact:
Verizon GNI - IP System Operations (NIC-14209152)
1880 CAMPUS COMMONS DR
RESTON VA 20191-1512
US
[email protected]
1-7032954206
Fax- 1-

&nbsp; &nbsp; Created on..............: 1999-Jul-06.
&nbsp; &nbsp; Expires on..............: 2004-Jul-06.
&nbsp; &nbsp; Record last updated on..: 2004-Feb-07 10:05:57.

&nbsp; &nbsp; Domain servers in listed order:

&nbsp; &nbsp; NS1.BELLATLANTIC.NET&nbsp;
&nbsp; &nbsp; NS2.BELLATLANTIC.NET&nbsp;
&nbsp; &nbsp; NS2.VERIZON.NET&nbsp; 151.203.0.86
&nbsp; &nbsp; NS4.VERIZON.NET&nbsp; 151.203.0.87

MarkMonitor.com - The Leader in Corporate Domain Management
----------------------------------------------------------
For Global Domain Consolidation, Research & Intelligence,
and Enterprise DNS, go to: www.markmonitor.com
----------------------------------------------------------



--------------------------------------------------------------------------------

.net is for "Network" which is a Generic Top Level Domain (gTLD) - Not associated with a country
Root: ICANN
Registration web site: http://www.internic.net
Whois server: whois.markmonitor.com
Whois web interface: http://www.internic.net
Second Level Domains Registered
Cost: Varies depending upon registrar
Dispute Policy: http://www.icann.org/udrp/udrp.htm
Notes: Domains registered by many competing registrars. Prices vary. Whois is a 2-step process. the registry is first checked to see which registrar controls the domain and that specific registrar&#39;s whois database is queried to see ownership information.
Updated: July 22, 2001

DNS Records for verizon.net:

query from dns.consumer.net to get an authoritative nameserver

NameServer used for query: ns2.bellatlantic.net



Answer records
verizon.net 1 NS ns2.verizon.net 80271s
verizon.net 1 NS ns1.bellatlantic.net 80271s
verizon.net 1 NS ns4.verizon.net 80271s
verizon.net 1 NS ns2.bellatlantic.net 80271s

Authority records

Additional records
ns2.verizon.net 1 A 151.203.0.86 80271s
ns1.bellatlantic.net 1 A 199.45.32.40 155985s
ns4.verizon.net 1 A 151.203.0.87 80271s
ns2.bellatlantic.net 1 A 199.45.32.41 155985s

DNS Records for east.verizon.net


query from dns.consumer.net to get an authoritative nameserver

NameServer used for query: ns1.bellatlantic.net



Answer records
east.verizon.net 1 NS ns2.bellatlantic.net 69583s
east.verizon.net 1 NS ns1.bellatlantic.net 69583s

Authority records

Additional records
ns2.bellatlantic.net 1 A 199.45.32.41 155983s
ns1.bellatlantic.net 1 A 199.45.32.40 155983s


Network IP address lookup:

whois whois.arin.net 141.156.251.147:



OrgName:&nbsp; &nbsp; Verizon Internet Services
OrgID:&nbsp; &nbsp; &nbsp; VRIS
Address:&nbsp; &nbsp; 1880 Campus Commons Dr
City:&nbsp; &nbsp; &nbsp; Reston
StateProv:&nbsp; VA
PostalCode: 20191
Country:&nbsp; &nbsp; US

NetRange:&nbsp; 141.149.0.0 - 141.158.255.255
CIDR:&nbsp; &nbsp; &nbsp; 141.149.0.0/16, 141.150.0.0/15, 141.152.0.0/14, 141.156.0.0/15, 141.158.0.0/16
NetName:&nbsp; &nbsp; VIS-141-149
NetHandle:&nbsp; NET-141-149-0-0-1
Parent:&nbsp; &nbsp; NET-141-0-0-0-0
NetType:&nbsp; &nbsp; Direct Allocation
NameServer: NSDC.BA-DSG.NET
NameServer: GTEPH.BA-DSG.NET
Comment:&nbsp; &nbsp;
RegDate:&nbsp; &nbsp;
Updated:&nbsp; &nbsp; 2002-08-22

TechHandle: ZV20-ARIN
TechName:&nbsp; Verizon Internet Services
TechPhone:&nbsp; +1-703-295-4583
TechEmail:&nbsp; [email protected]

OrgAbuseHandle: VISAB-ARIN
OrgAbuseName:&nbsp; VIS Abuse
OrgAbusePhone:&nbsp; +1-703-295-4583
OrgAbuseEmail:&nbsp; [email protected]

OrgTechHandle: ZV20-ARIN
OrgTechName:&nbsp; Verizon Internet Services
OrgTechPhone:&nbsp; +1-703-295-4583
OrgTechEmail:&nbsp; [email protected]

# ARIN WHOIS database, last updated 2004-04-11 19:15
# Enter ? for additional hints on searching ARIN&#39;s WHOIS database.

The second is Verizon or a Verizon IP. Report it to the AbuseEmail just a little above, and say they have made attempted attacks on your PC.

atiVidia
04-12-2004, 11:18 PM
the second ip u traced is mine lol

the first one is the one in question. no, i dont have IRC at all



thx for the help anyways lol :D

what site did u use to trace the IPs?

oh shit u practically know my street address now thats not f__king good <_<

tesco
04-12-2004, 11:27 PM
Originally posted by atiVidia@12 April 2004 - 18:18
oh shit u practically know my street address now thats not f__king good <_<
:lol: thanks for pointing that out, now i do to :lol: dont worry im not a serial killer lol.

Mad Cat
04-12-2004, 11:30 PM
You could still email Verizon abuse about yourself :P

Anyway, were you using IRC at the time? And was it connecting properly?

atiVidia
04-12-2004, 11:55 PM
Originally posted by Mad Cat+12 April 2004 - 18:30--></div><table border='0' align='center' width='95%' cellpadding='3' cellspacing='1'><tr><td>QUOTE (Mad Cat &#064; 12 April 2004 - 18:30)</td></tr><tr><td id='QUOTE'>You could still email Verizon abuse about yourself :P

Anyway, were you using IRC at the time? And was it connecting properly?[/b]
<!--QuoteBegin-me who feels like a total idiot for not properly conveying his message@12 April 2004 - 18:18
no, i dont have IRC at all[/quote]

Mad Cat
04-13-2004, 12:00 AM
Sorry, I&#39;m drunk and tired. Seems some Japanese man was trying to connect to you then.

Could be from any peer to peer app though, I know a couple of people on this board have that 100mbit.

atiVidia
04-13-2004, 12:05 AM
Originally posted by Mad Cat@12 April 2004 - 19:00
Sorry, I&#39;m drunk and tired. Seems some Japanese man was trying to connect to you then.

Could be from any peer to peer app though, I know a couple of people on this board have that 100mbit.
no normal person on this board in the US could afford that :lol:


prolly one of those fscked fiber-optic connections going to 1/3 of all japanese hauses nowadays <_<


lucky japs... why do they always get the cool things 6 months to n years before we do???








:angry: :angry: :angry:

[no offense to any japanese ppls on this forum was intended. if you were offended, please PM me with the offending line and i will remove it ASAP. Thanks]

RGX
04-13-2004, 12:37 AM
Thanks for your IP :P.

Maryland i take it? Nanjemoy perhaps?

atiVidia
04-13-2004, 12:40 AM
Originally posted by RGX@12 April 2004 - 19:37
Thanks for your IP :P.
lol doesnt matter anymore my ip reset