About
Community
Bad Ideas
Drugs
Ego
Erotica
Fringe
Society
Technology
register | bbs | search | rss | faq | about
meet up | add to del.icio.us | digg it
Go Back   Community > Technology > Network (in)Security
FAQ Members List Calendar Search Today's Posts Mark Forums Read

Network (in)Security Interesting hacks and cracks. Info on firewalls, TCP/IP, encryption, networks, and security. The ins and outs of the phone system, caller services, how things work, what's illegal and what's not, cellular phones, beepers, telephony legislation, the PUC, ISDN, taps, who's listening, and switches. Talking about phones, hacking systems, technical advice, and such is completely LEGAL in the United States -- it's covered by the First Amendment. What's illegal is conspiracy to commit a crime. So if you say something like "Meet me at 2am so we can crack a can" or "I changed my cell phone's number myself" you are criminally liable. Stating "You can crack a can by doing thus-and-so" or "If you wanted to change a cell phone's number, you could do it like so" is perfectly OK. Posting passwords, calling card numbers, or credit card numbers is forbidden on this network. Posting such info will get you booted off the net.

Reply
 
Thread Tools Display Modes
 #1 
Old 2004-12-23, 15:07
Shmoo Shmoo is offline
Regular
 
Default DoD NetworkInformationCenter,Out going packets detected

I was over at my dad's house with his pc, as i'd been asked to get rid of some of the spyware and stuff on there. After replacing the hosts file and running adaware etc, I installed protowall and imported the latest sourced black list IPs etc. And about an hour after installation i got out-going packets to.

quote:

BLOCKED [!] - Destination is DoD Network Information Center (11.10.1.2) [protocol: UDP / destport: 2990]

&

BLOCKED [!] - Destination is DoD Network Information Center (11.10.1.2) [protocol:

TCP / destport: 2990]



I did some quick searches of the web but it didn't turn up anything becides going to the DoD NIC site and getting told i shouldn't look at anything unless i was supposed to be there. My only guess is that the US government is watching me. lol. It's not a reserved IP address is it? shrug.

quote:

OrgName: DoD Network Information Center

OrgID: DNIC

Address: 7990 Science Applications Ct

Address: M/S CV 50

City: Vienna

StateProv: VA

PostalCode: 22183-7000

Country: US

NetRange: 11.0.0.0 - 11.255.255.255

CIDR: 11.0.0.0/8

NetName: DODIIS

NetHandle: NET-11-0-0-0-1

Parent:

NetType: Direct Allocation

Comment: DoD Intel Information Systems

Comment: Defense Intelligence Agency

Comment: Washington, DC 20301 US

RegDate: 1984-01-19

Updated: 1998-09-26



I did some netbased traceroutes. Mostly they disappear. (I think that's what's happening.)

quote:

traceroute to 11.10.1.2 (11.10.1.2), 30 hops max, 40 byte packets

1 lon1-9 (195.149.20.130) 0.421 ms 0.284 ms 0.262 ms

2 lon1-6 (195.149.20.132) 0.299 ms 0.343 ms 0.310 ms

3 246.ge6-0.mpr1.lhr1.uk.above.net (213.161.78.109) 0.325 ms !H 0.266 ms !H *

No responses



quote:

traceroute: Warning: Multiple interfaces found; using 212.74.64.46 @ hme0

traceroute to 11.10.1.2 (11.10.1.2), 30 hops max, 40 byte packets

1 fe5-0-svc2.LON.router.COLT.NET (212.74.64.33) 0.860 ms 0.768 ms 0.697 ms

2 * * *

3 * * *

4 * * *

5 * * *

6 * * *

7 * * *

8 * * *

9 * * *

10 * * *

11 * * *

12 * * *

13 * * *

14 * * *

15 * * *



quote:

1 zinc-FE-4-7.cac.washington.edu (140.142.3.1) 1 ms 0 ms 1 ms

2 uwbr1-ge1-2.cac.washington.edu (140.142.150.23) 0 ms 1 ms 0 ms



^ the last one washington based, i guess ya can tell.

and so research tells me this:

sourced: (http://www.nic.mil/whatwedo.html)

quote:

What we do:

The Department of Defense Network Information Center (DoD NIC) provides worldwide operational support to the military and DoD community connected to the NIPRNet and SIPRNet backbones

The organizational structure of the DoD NIC supports two environments that are unclassified yet sensitive, supported by the Network Information Center (NIC) and classified (secret) supported by the SIPRNet Support Center (SSC).



sourced: (http://www.notbored.org/nipr.html)

quote:

NIPRNET

The "NIPRNET," the Unclassified but Sensitive Internet Protocol Router Network (formerly called the Non-secure Internet Protocol Router Net), is a network of Internet protocol routers owned by the Department of Defense (DOD). Created by the Defense Information Systems Agency (DISA), NIPRNET is used to exchange unclassified but sensitive information between "internal" users. It can thus be distinguished from the Secret Internet Protocol Router Network (SIPRNET), which is used by the DOD to exchange classified information in a totally secure environment. NIPRNET is also increasingly used by the DOD to allow its personnel to gain access the Internet without leaving their own computers open to "reverse entry" by hackers, foreign militaries, terrorists, etc etc.



sourced: (http://www.fas.org/irp/program/disseminate/siprnet.htm)

quote:

Secret Internet Protocol Router Network (SIPRNET)

SIPRNET replaces the DDN DSNET1 as the SECRET portion of DISN. Its complete architecture will be achieved by constructing a new worldwide backbone router system. The primary method for secret-level network connectivity is via Base secret-level networks which in turn provide Base Router connectivity to SIPRNET. Various DOD router services and systems will migrate onto the SIPRNET backbone router network to serve the long-haul data transmission needs of the users. Transmission services will use smart multiplexer and 512 kilobits per second (kbps) channels. Other transmission services will be acquired or leased as needed. Future expansion will progress to the T1 circuit data rate of 1.544 Megabits (Mbps) and potentially to the T3 data rate of 45 Mbps. High speed packet switched service will be provided through the use of IP routers. This SECRET router layer of the DISN is intended to support national defense C3I requirements, to include the issuing of COMSEC keys used with the STU-III to make secure dial-up SIPRNET comm server connections.

The Secret Internet Protocol Router Network (SIPRNET) has matured to be the core of our warfighting command and control capability. Many expeditionary commanders ask for SIPRNET ahead of secure voice when deploying their forces. SIPRNET is fast becoming the defacto standard of preferred data services, even over NIPRNET. The SIPRNET is the new, worldwide router-based network replacing the older X.25-based packet switched network (the Defense Secure Network One (DSNET1) of the Defense Data Network (DDN)). The initial SIPRNET backbone router network went online 3 March 1994. Subscribers started coming on line shortly thereafter. The SIPRNET WAN (as of 31 May 1995) consisted of a collection of 31 backbone routers interconnected by high-speed serial links to serve the long-haul data transport needs of secret-level DoD subscribers. Additional SIPRNET backbone routers are being planned to meet increased customer requirements. SIPRNET supports the DoD standard Transmission Control Protocol/Internet Protocol (TCP/IP) protocol service. Subscribers within the DoD and other Government Agencies are able to use the SIPRNET for passing datagrams at the Secret-Not Releasable to Foreign Nationals (SECRET-NOFORN) classification level.



Input appreciated. I realise i'm being a little paranoid.

edit: Anyone know what BOSCAP service is?

[This message has been edited by Shmoo (edited 12-23-2004).]
 #2 
Old 2004-12-23, 18:58
evilduck evilduck is offline
Regular
 
Default Re: DoD NetworkInformationCenter,Out going packets detected

Is there anymore information on the packets that the machine tried to send? It would be invaluably useful to find out what the packets contained.

The only thing that comes to mind is that the machine is infected by something that's attempting a DDOS or similar, rather than the DoD is watching your dads computer.
 #3 
Old 2004-12-24, 01:49
Shmoo Shmoo is offline
Regular
 
Default Re: DoD NetworkInformationCenter,Out going packets detected

Yeah. That's a reasonable assumption. However, if you look at the trace route, even a massive swamping to one IP would do nothing because erroneous packets will be dropped by the private routers? right? I dunno. Nothing else has tried to send to DoD, if i ever get another detection i'll start running packet sniffers.
 #4 
Old 2004-12-24, 03:19
jamez jamez is offline
Regular
 
Default Re: DoD NetworkInformationCenter,Out going packets detected

the service was called quicksuite.

perhaps a trojan uses that port too and they are scannning for trojans or something.

http://www.bekkoame.ne.jp/~s_ita/port/port2900-2999.html

ofcourse its not a DDOS attempt u idiot.

there would be WAY more than 2 packets, from more than one computer, more than likely using spoofed ip's and it would be on a port that is always open instead of this one thats very uncommon.

and the governemnt isnt watching u, u dumbass.

what the hell do u think 2 packets can show them what your doing?

if they were, not only would you not know or have a clue but they'd be even less inclined to communicate with your computer
 
To the best of our knowledge, the text on this page may be freely reproduced and distributed.
 

totse.com certificate signatures
 
 
About | Community | Bad Ideas | Drugs | Ego | Erotica | Fringe | Society | Technology
Hot Topics