Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > comp.os.vms > #58500 > unrolled thread

Anybody know who this is?

Started by VAXman- @SendSpamHere.ORG
First post2016-06-17 13:15 +0000
Last post2016-06-20 13:14 -0400
Articles 17 — 9 participants

Back to article view | Back to comp.os.vms


Contents

  Anybody know who this is?   VAXman-  @SendSpamHere.ORG - 2016-06-17 13:15 +0000
    Re: Anybody know who this is? Ken Robinson <kenrbnsn@rbnsn.com> - 2016-06-17 09:35 -0400
      Re: Anybody know who this is?   VAXman-  @SendSpamHere.ORG - 2016-06-17 14:04 +0000
      Re: Anybody know who this is? Paul Sture <nospam@sture.ch> - 2016-06-17 16:27 +0200
    Re: Anybody know who this is? Roy Omond <roy@omond.net> - 2016-06-17 15:19 +0100
      Re: Anybody know who this is? Roy Omond <roy@omond.net> - 2016-06-17 15:31 +0100
    Re: Anybody know who this is? moroney@world.std.spaamtrap.com (Michael Moroney) - 2016-06-17 14:37 +0000
      Re: Anybody know who this is? "John E. Malmberg" <wb8tyw@qsl.net_work> - 2016-06-17 18:03 -0500
    Re: Anybody know who this is? David Turner <islandcomputersuscorp@gmail.com> - 2016-06-17 17:05 -0400
    Re: Anybody know who this is? Chris <xxx.syseng.yyy@gfsys.co.uk> - 2016-06-19 22:12 +0000
      Re: Anybody know who this is?   VAXman-  @SendSpamHere.ORG - 2016-06-20 01:31 +0000
        Re: Anybody know who this is? "John E. Malmberg" <wb8tyw@qsl.net_work> - 2016-06-19 21:10 -0500
          Re: Anybody know who this is?   VAXman-  @SendSpamHere.ORG - 2016-06-20 11:21 +0000
            Re: Anybody know who this is? "John E. Malmberg" <wb8tyw@qsl.net_work> - 2016-06-20 07:33 -0500
        Re: Anybody know who this is? Chris <xxx.syseng.yyy@gfsys.co.uk> - 2016-06-20 11:57 +0000
        Re: Anybody know who this is? Chris <xxx.syseng.yyy@gfsys.co.uk> - 2016-06-20 12:10 +0000
      Re: Anybody know who this is? Bill Gunshannon <bill.gunshannon@gmail.com> - 2016-06-20 13:14 -0400

#58500 — Anybody know who this is?

From VAXman- @SendSpamHere.ORG
Date2016-06-17 13:15 +0000
SubjectAnybody know who this is?
Message-ID<00B0AC01.50291B30@SendSpamHere.ORG>
$ TELNET 108.31.82.9

-- 
VAXman- A Bored Certified VMS Kernel Mode Hacker    VAXman(at)TMESIS(dot)ORG

I speak to machines with the voice of humanity.

[toc] | [next] | [standalone]


#58501

FromKen Robinson <kenrbnsn@rbnsn.com>
Date2016-06-17 09:35 -0400
Message-ID<mailman.314.1466170552.14919.info-vax_info-vax.com@info-vax.com>
In reply to#58500

On 2016-06-17 9:15 am, VAXman---- via Info-vax wrote:
> $ TELNET 108.31.82.9

Via Linux:

$ dig -x 108.31.82.9

; <<>> DiG 9.8.2rc1-RedHat-9.8.2-0.47.rc1.el6 <<>> -x 108.31.82.9
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 6575
;; flags: qr rd ra; QUERY: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 0

;; QUESTION SECTION:
;9.82.31.108.in-addr.arpa.      IN      PTR

;; ANSWER SECTION:
9.82.31.108.in-addr.arpa. 21599 IN      PTR     
pool-108-31-82-9.washdc.fios.verizon.net.

[toc] | [prev] | [next] | [standalone]


#58502

From VAXman- @SendSpamHere.ORG
Date2016-06-17 14:04 +0000
Message-ID<00B0AC08.251737EA@SendSpamHere.ORG>
In reply to#58501
In article <mailman.314.1466170552.14919.info-vax_info-vax.com@info-vax.com>, Ken Robinson <kenrbnsn@rbnsn.com> writes:
>
>
>On 2016-06-17 9:15 am, VAXman---- via Info-vax wrote:
>> $ TELNET 108.31.82.9
>
>Via Linux:
>
>$ dig -x 108.31.82.9
>
>; <<>> DiG 9.8.2rc1-RedHat-9.8.2-0.47.rc1.el6 <<>> -x 108.31.82.9
>;; global options: +cmd
>;; Got answer:
>;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 6575
>;; flags: qr rd ra; QUERY: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 0
>
>;; QUESTION SECTION:
>;9.82.31.108.in-addr.arpa.      IN      PTR
>
>;; ANSWER SECTION:
>9.82.31.108.in-addr.arpa. 21599 IN      PTR     
>pool-108-31-82-9.washdc.fios.verizon.net.

Did you telnet?

-- 
VAXman- A Bored Certified VMS Kernel Mode Hacker    VAXman(at)TMESIS(dot)ORG

I speak to machines with the voice of humanity.

[toc] | [prev] | [next] | [standalone]


#58507

FromPaul Sture <nospam@sture.ch>
Date2016-06-17 16:27 +0200
Message-ID<50ed3d-j88.ln1@news.chingola.ch>
In reply to#58501
On 2016-06-17, Ken Robinson <kenrbnsn@rbnsn.com> wrote:
>
>
> On 2016-06-17 9:15 am, VAXman---- via Info-vax wrote:
>> $ TELNET 108.31.82.9
>
> Via Linux:
>
> $ dig -x 108.31.82.9
>
> ; <<>> DiG 9.8.2rc1-RedHat-9.8.2-0.47.rc1.el6 <<>> -x 108.31.82.9
> ;; global options: +cmd
> ;; Got answer:
> ;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 6575
> ;; flags: qr rd ra; QUERY: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 0
>
> ;; QUESTION SECTION:
> ;9.82.31.108.in-addr.arpa.      IN      PTR
>
> ;; ANSWER SECTION:
> 9.82.31.108.in-addr.arpa. 21599 IN      PTR     
> pool-108-31-82-9.washdc.fios.verizon.net.
  ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^

FWIW telnet shows that information.

This from OS X:

telnet 108.31.82.9
Trying 108.31.82.9...
Connected to pool-108-31-82-9.washdc.fios.verizon.net.
Escape character is '^]'.

-- 
There are two hard things in computer science, and they are cache invalidation,
naming, and off-by-one errors.

[toc] | [prev] | [next] | [standalone]


#58503

FromRoy Omond <roy@omond.net>
Date2016-06-17 15:19 +0100
Message-ID<dsif8eF7ji1U1@mid.individual.net>
In reply to#58500
On 17/06/16 14:15, VAXman-@SendSpamHere.ORG wrote:
> $ TELNET 108.31.82.9
>

Looks like it's on HECnet.

Also:

  The MicroVAX 3800 and 3900 were introduced in 1989, based on the CVAX+ 
chip
  manufactured in 1.5-micrometer CMOS technology. It was 3.8 times 
faster than
  the VAX-11/780, supported up to 64 MB RAM, 9.7GB MV 3900 disks with 
max I/O
  throughput of 3.3 MB/s, and ran VMS, ULTRIX-32 and VAXELN. The processor
  included a Floating Point Accelerator, with 1 KB 60-ns on-chip and 64 KB
  120-ns on-board caches. More: http://j.mp/mvax3900

            SUPPOSE YOU HAD A VAX OF YOUR OWN.

  * Join my free public MINECRAFT server also at sanyal.duckdns.org
  * Sync time to my public NTP time server at sanyalnet-ntp.freeddns.org
  * Tune into my Bengali internet radio station at 
banglaradio.homeip.net:8000
  * Download freeware and shareware from my OpenVMS Freeware, DECUS,
    garbo.uwasa.fi and simtel.net mirrors over anonymous FTP from 
sanyal.duckdns.org
  * Direct questions and comments to supratim@riseup.net
  * Have fun!

[toc] | [prev] | [next] | [standalone]


#58505

FromRoy Omond <roy@omond.net>
Date2016-06-17 15:31 +0100
Message-ID<dsifu2F7ojnU1@mid.individual.net>
In reply to#58503
On 17/06/16 15:19, Roy Omond wrote:
> On 17/06/16 14:15, VAXman-@SendSpamHere.ORG wrote:
>> $ TELNET 108.31.82.9
>>
>
> Looks like it's on HECnet.

Johnny Billquist, who is responsible for node names and numbers, will
know who and where this node (QCOCAL 1.550) is.

[toc] | [prev] | [next] | [standalone]


#58506

Frommoroney@world.std.spaamtrap.com (Michael Moroney)
Date2016-06-17 14:37 +0000
Message-ID<nk11vd$26l$1@pcls7.std.com>
In reply to#58500
VAXman-  @SendSpamHere.ORG writes:

>$ TELNET 108.31.82.9

I believe this system was announced here maybe a month ago.

It appears to be running an emulator, the same simh one I played around with 
on a Raspberry Pi a while ago. (not saying it *is* a Raspberry Pi)

[toc] | [prev] | [next] | [standalone]


#58519

From"John E. Malmberg" <wb8tyw@qsl.net_work>
Date2016-06-17 18:03 -0500
Message-ID<nk1vko$d07$1@dont-email.me>
In reply to#58506
On 6/17/2016 9:37 AM, Michael Moroney wrote:
> VAXman-  @SendSpamHere.ORG writes:
>
>> $ TELNET 108.31.82.9
>
> I believe this system was announced here maybe a month ago.
>
> It appears to be running an emulator, the same simh one I played around with
> on a Raspberry Pi a while ago. (not saying it *is* a Raspberry Pi)

I suspect it may be related to:

http://www.openvmshobbyist.com/forum/viewthread.php?forum_id=162&thread_id=2694

Regards,
-John
wb8tyw@qsl.net_work

[toc] | [prev] | [next] | [standalone]


#58514

FromDavid Turner <islandcomputersuscorp@gmail.com>
Date2016-06-17 17:05 -0400
Message-ID<2vmdnRCIlNS5-_nKnZ2dnUU7-eWdnZ2d@supernews.com>
In reply to#58500
On 6/17/2016 9:15 AM, VAXman-@SendSpamHere.ORG wrote:
> $ TELNET 108.31.82.9
>
I think it is Hillary Clinton's mailserver  ;0)

And TELNET port is no doubt wide open.

David
Island Computers

[toc] | [prev] | [next] | [standalone]


#58629

FromChris <xxx.syseng.yyy@gfsys.co.uk>
Date2016-06-19 22:12 +0000
Message-ID<nk7571$ojr$1@gioia.aioe.org>
In reply to#58500
On 06/17/16 13:15, VAXman- @SendSpamHere.ORG wrote:
> $ TELNET 108.31.82.9
>


$ nslookup 108.31.82.9
Server:         208.67.220.220
Address:        208.67.220.220#53

Non-authoritative answer:
9.82.31.108.in-addr.arpa        name = 
pool-108-31-82-9.washdc.fios.verizon.net.

[toc] | [prev] | [next] | [standalone]


#58631

From VAXman- @SendSpamHere.ORG
Date2016-06-20 01:31 +0000
Message-ID<00B0ADFA.75E46055@SendSpamHere.ORG>
In reply to#58629
In article <nk7571$ojr$1@gioia.aioe.org>, Chris <xxx.syseng.yyy@gfsys.co.uk> writes:
>On 06/17/16 13:15, VAXman- @SendSpamHere.ORG wrote:
>> $ TELNET 108.31.82.9
>>
>
>
>$ nslookup 108.31.82.9
>Server:         208.67.220.220
>Address:        208.67.220.220#53
>
>Non-authoritative answer:
>9.82.31.108.in-addr.arpa        name = 
>pool-108-31-82-9.washdc.fios.verizon.net.

Yeah, that's so helpful.  Now, all I need to do is get my question answered.

For those that have already replied,with nslookup -- I used dig -- just what
make you thin there'd be an answer jn that? 
-- 
VAXman- A Bored Certified VMS Kernel Mode Hacker    VAXman(at)TMESIS(dot)ORG

I speak to machines with the voice of humanity.

[toc] | [prev] | [next] | [standalone]


#58633

From"John E. Malmberg" <wb8tyw@qsl.net_work>
Date2016-06-19 21:10 -0500
Message-ID<nk7ja9$8a0$1@dont-email.me>
In reply to#58631
On 6/19/2016 8:31 PM, VAXman-@SendSpamHere.ORG wrote:

> Yeah, that's so helpful.  Now, all I need to do is get my question answered.

Your question corresponded with an announcement posted on 
openvmshobbyist.com of a new HECnet node 1.550 by someone going by 
tuklu_san.

I posted the link to it earlier, but did not check what the DNS name 
resolved to.

$ nslookup sanyal.duckdns.org
Server:  google-public-dns-a.google.com
Address:  8.8.8.8

Non-authoritative answer:
Name:    SANYAL.DUCKDNS.ORG
Address:  108.31.82.9

Regards,
-John
wb8tyw@qsl.net_work

[toc] | [prev] | [next] | [standalone]


#58654

From VAXman- @SendSpamHere.ORG
Date2016-06-20 11:21 +0000
Message-ID<00B0AE4C.C75E4BD3@SendSpamHere.ORG>
In reply to#58633
In article <nk7ja9$8a0$1@dont-email.me>, "John E. Malmberg" <wb8tyw@qsl.net_work> writes:
>On 6/19/2016 8:31 PM, VAXman-@SendSpamHere.ORG wrote:
>
>> Yeah, that's so helpful.  Now, all I need to do is get my question answered.
>
>Your question corresponded with an announcement posted on 
>openvmshobbyist.com of a new HECnet node 1.550 by someone going by 
>tuklu_san.
>
>I posted the link to it earlier, but did not check what the DNS name 
>resolved to.
>
>$ nslookup sanyal.duckdns.org
>Server:  google-public-dns-a.google.com
>Address:  8.8.8.8
>
>Non-authoritative answer:
>Name:    SANYAL.DUCKDNS.ORG
>Address:  108.31.82.9
>
>Regards,
>-John
>wb8tyw@qsl.net_work

I'd like to know who to actually contact about the system.  It's W-I-D-E open
-- even guest account access described in SYS$ANNOUNCE -- and I've been seeing
my systems getting probed from that IP address.  It's gotten so bad that I had 
to disable the FTP server on one system.  There's no way in, because it's only
an anonymous FTP, but the volume of logged attemps is VERY annoying.

support
1234
12345
1111
cisco
vizxv
admin
admin
guest
123
123456
cisco
root
admin
support
vizxv
123456
dreambox
7ujMko0admin
smcadmin
supervisor
12345
cisco
admin
guest
vizxv
1234
123456
pass
vizxv
7ujMko0admin
admin
service
xc3511

... and the list goes on and on and on and on and on and on and on...

-- 
VAXman- A Bored Certified VMS Kernel Mode Hacker    VAXman(at)TMESIS(dot)ORG

I speak to machines with the voice of humanity.

[toc] | [prev] | [next] | [standalone]


#58658

From"John E. Malmberg" <wb8tyw@qsl.net_work>
Date2016-06-20 07:33 -0500
Message-ID<nk8nqu$f3q$1@dont-email.me>
In reply to#58654
On 6/20/2016 6:21 AM, VAXman-@SendSpamHere.ORG wrote:
> In article <nk7ja9$8a0$1@dont-email.me>, "John E. Malmberg" <wb8tyw@qsl.net_work> writes:
>> On 6/19/2016 8:31 PM, VAXman-@SendSpamHere.ORG wrote:
>>
>>
>> $ nslookup sanyal.duckdns.org
>> Non-authoritative answer:
>> Name:    SANYAL.DUCKDNS.ORG
>> Address:  108.31.82.9
>
> I'd like to know who to actually contact about the system.  It's W-I-D-E open
> -- even guest account access described in SYS$ANNOUNCE -- and I've been seeing
> my systems getting probed from that IP address.  It's gotten so bad that I had
> to disable the FTP server on one system.  There's no way in, because it's only
> an anonymous FTP, but the volume of logged attemps is VERY annoying.
>
> ... and the list goes on and on and on and on and on and on and on...

I have posted a request for him to remove his system from the public 
internet until he can secure it and recommended he post on comp.os.vms 
for advice on the how to secure it on the openvmshobbyist.com Emulated 
VAX Forum.

I also sent him a private message to contact you, but suggested due to 
spam filters, that posting to comp.os.vms would probably be better.

His post says that Johnny Billquist helped him get the system onto HECnet.

Regards,
-John

[toc] | [prev] | [next] | [standalone]


#58656

FromChris <xxx.syseng.yyy@gfsys.co.uk>
Date2016-06-20 11:57 +0000
Message-ID<nk8lid$l42$1@gioia.aioe.org>
In reply to#58631
On 06/20/16 01:31, VAXman- @SendSpamHere.ORG wrote:
> In article<nk7571$ojr$1@gioia.aioe.org>, Chris<xxx.syseng.yyy@gfsys.co.uk>  writes:
>> On 06/17/16 13:15, VAXman- @SendSpamHere.ORG wrote:
>>> $ TELNET 108.31.82.9
>>>
>>
>>
>> $ nslookup 108.31.82.9
>> Server:         208.67.220.220
>> Address:        208.67.220.220#53
>>
>> Non-authoritative answer:
>> 9.82.31.108.in-addr.arpa        name =
>> pool-108-31-82-9.washdc.fios.verizon.net.
>
> Yeah, that's so helpful.  Now, all I need to do is get my question answered.
>
> For those that have already replied,with nslookup -- I used dig -- just what
> make you thin there'd be an answer jn that?

Fair enough, but in defense, also tried pointing nmap at it, various
parameters, but thought the host was down :-)...

Regards,

Chris

[toc] | [prev] | [next] | [standalone]


#58657

FromChris <xxx.syseng.yyy@gfsys.co.uk>
Date2016-06-20 12:10 +0000
Message-ID<nk8mbh$mbj$1@gioia.aioe.org>
In reply to#58631
On 06/20/16 01:31, VAXman- @SendSpamHere.ORG wrote:
> In article<nk7571$ojr$1@gioia.aioe.org>, Chris<xxx.syseng.yyy@gfsys.co.uk>  writes:
>> On 06/17/16 13:15, VAXman- @SendSpamHere.ORG wrote:
>>> $ TELNET 108.31.82.9
>>>
>>
>>
>> $ nslookup 108.31.82.9
>> Server:         208.67.220.220
>> Address:        208.67.220.220#53
>>
>> Non-authoritative answer:
>> 9.82.31.108.in-addr.arpa        name =
>> pool-108-31-82-9.washdc.fios.verizon.net.
>
> Yeah, that's so helpful.  Now, all I need to do is get my question answered.
>
> For those that have already replied,with nslookup -- I used dig -- just what
> make you thin there'd be an answer jn that?

Just tried nmap again ths morning and get:

$ nmap -Pn 108.31.82.9

Starting Nmap 5.51 ( http://nmap.org ) at 2016-06-20 13:00 ope
Nmap scan report for pool-108-31-82-9.washdc.fios.verizon.net (108.31.82.9)
Host is up (0.15s latency).
Not shown: 991 filtered ports
PORT      STATE  SERVICE
21/tcp    closed ftp
22/tcp    open   ssh
23/tcp    open   telnet
81/tcp    closed hosts2-ns
113/tcp   open   auth
8001/tcp  open   vcom-tunnel
8021/tcp  open   ftp-proxy
8080/tcp  open   http-proxy
12345/tcp open   netbus

Nmap done: 1 IP address (1 host up) scanned in 13.98 seconds

Try pointing browser at port 8080...

Regards,

Chris



[toc] | [prev] | [next] | [standalone]


#58674

FromBill Gunshannon <bill.gunshannon@gmail.com>
Date2016-06-20 13:14 -0400
Message-ID<dsqmjpFr4lrU1@mid.individual.net>
In reply to#58629
On 6/19/16 6:12 PM, Chris wrote:
> On 06/17/16 13:15, VAXman- @SendSpamHere.ORG wrote:
>> $ TELNET 108.31.82.9
>>
>
>
> $ nslookup 108.31.82.9
> Server:         208.67.220.220
> Address:        208.67.220.220#53
>
> Non-authoritative answer:
> 9.82.31.108.in-addr.arpa        name =
> pool-108-31-82-9.washdc.fios.verizon.net.
>

A verizon residential copnnection.  Probably a zombied PC.

bill

[toc] | [prev] | [standalone]


Back to top | Article view | comp.os.vms


csiph-web