|
|
 |
 |
 |
 |
register |
bbs |
search |
rss |
faq |
about
|
 |
 |
meet up |
add to del.icio.us |
digg it
|
 |
 |
| Network (in)Security Interesting hacks and cracks. Info on firewalls, TCP/IP, encryption, networks, and security. The ins and outs of the phone system, caller services, how things work, what's illegal and what's not, cellular phones, beepers, telephony legislation, the PUC, ISDN, taps, who's listening, and switches. Talking about phones, hacking systems, technical advice, and such is completely LEGAL in the United States -- it's covered by the First Amendment. What's illegal is conspiracy to commit a crime. So if you say something like "Meet me at 2am so we can crack a can" or "I changed my cell phone's number myself" you are criminally liable. Stating "You can crack a can by doing thus-and-so" or "If you wanted to change a cell phone's number, you could do it like so" is perfectly OK. Posting passwords, calling card numbers, or credit card numbers is forbidden on this network. Posting such info will get you booted off the net. |
 |
|
|
#1
 2004-12-23, 15:07
|
Shmoo 
Regular
|
|
|
|
DoD NetworkInformationCenter,Out going packets detected
I was over at my dad's house with his pc, as i'd been asked to get rid of some of the spyware and stuff on there. After replacing the hosts file and running adaware etc, I installed protowall and imported the latest sourced black list IPs etc. And about an hour after installation i got out-going packets to.
quote:
BLOCKED [!] - Destination is DoD Network Information Center (11.10.1.2) [protocol: UDP / destport: 2990]
&
BLOCKED [!] - Destination is DoD Network Information Center (11.10.1.2) [protocol:
TCP / destport: 2990]
I did some quick searches of the web but it didn't turn up anything becides going to the DoD NIC site and getting told i shouldn't look at anything unless i was supposed to be there. My only guess is that the US government is watching me. lol. It's not a reserved IP address is it? shrug.
quote:
OrgName: DoD Network Information Center
OrgID: DNIC
Address: 7990 Science Applications Ct
Address: M/S CV 50
City: Vienna
StateProv: VA
PostalCode: 22183-7000
Country: US
NetRange: 11.0.0.0 - 11.255.255.255
CIDR: 11.0.0.0/8
NetName: DODIIS
NetHandle: NET-11-0-0-0-1
Parent:
NetType: Direct Allocation
Comment: DoD Intel Information Systems
Comment: Defense Intelligence Agency
Comment: Washington, DC 20301 US
RegDate: 1984-01-19
Updated: 1998-09-26
I did some netbased traceroutes. Mostly they disappear. (I think that's what's happening.)
quote:
traceroute to 11.10.1.2 (11.10.1.2), 30 hops max, 40 byte packets
1 lon1-9 (195.149.20.130) 0.421 ms 0.284 ms 0.262 ms
2 lon1-6 (195.149.20.132) 0.299 ms 0.343 ms 0.310 ms
3 246.ge6-0.mpr1.lhr1.uk.above.net (213.161.78.109) 0.325 ms !H 0.266 ms !H *
No responses
quote:
traceroute: Warning: Multiple interfaces found; using 212.74.64.46 @ hme0
traceroute to 11.10.1.2 (11.10.1.2), 30 hops max, 40 byte packets
1 fe5-0-svc2.LON.router.COLT.NET (212.74.64.33) 0.860 ms 0.768 ms 0.697 ms
2 * * *
3 * * *
4 * * *
5 * * *
6 * * *
7 * * *
8 * * *
9 * * *
10 * * *
11 * * *
12 * * *
13 * * *
14 * * *
15 * * *
quote:
1 zinc-FE-4-7.cac.washington.edu (140.142.3.1) 1 ms 0 ms 1 ms
2 uwbr1-ge1-2.cac.washington.edu (140.142.150.23) 0 ms 1 ms 0 ms
^ the last one washington based, i guess ya can tell.
and so research tells me this:
sourced: (http://www.nic.mil/whatwedo.html)
quote:
What we do:
The Department of Defense Network Information Center (DoD NIC) provides worldwide operational support to the military and DoD community connected to the NIPRNet and SIPRNet backbones
The organizational structure of the DoD NIC supports two environments that are unclassified yet sensitive, supported by the Network Information Center (NIC) and classified (secret) supported by the SIPRNet Support Center (SSC).
sourced: (http://www.notbored.org/nipr.html)
quote:
NIPRNET
The "NIPRNET," the Unclassified but Sensitive Internet Protocol Router Network (formerly called the Non-secure Internet Protocol Router Net), is a network of Internet protocol routers owned by the Department of Defense (DOD). Created by the Defense Information Systems Agency (DISA), NIPRNET is used to exchange unclassified but sensitive information between "internal" users. It can thus be distinguished from the Secret Internet Protocol Router Network (SIPRNET), which is used by the DOD to exchange classified information in a totally secure environment. NIPRNET is also increasingly used by the DOD to allow its personnel to gain access the Internet without leaving their own computers open to "reverse entry" by hackers, foreign militaries, terrorists, etc etc.
sourced: (http://www.fas.org/irp/program/disseminate/siprnet.htm)
quote:
Secret Internet Protocol Router Network (SIPRNET)
SIPRNET replaces the DDN DSNET1 as the SECRET portion of DISN. Its complete architecture will be achieved by constructing a new worldwide backbone router system. The primary method for secret-level network connectivity is via Base secret-level networks which in turn provide Base Router connectivity to SIPRNET. Various DOD router services and systems will migrate onto the SIPRNET backbone router network to serve the long-haul data transmission needs of the users. Transmission services will use smart multiplexer and 512 kilobits per second (kbps) channels. Other transmission services will be acquired or leased as needed. Future expansion will progress to the T1 circuit data rate of 1.544 Megabits (Mbps) and potentially to the T3 data rate of 45 Mbps. High speed packet switched service will be provided through the use of IP routers. This SECRET router layer of the DISN is intended to support national defense C3I requirements, to include the issuing of COMSEC keys used with the STU-III to make secure dial-up SIPRNET comm server connections.
The Secret Internet Protocol Router Network (SIPRNET) has matured to be the core of our warfighting command and control capability. Many expeditionary commanders ask for SIPRNET ahead of secure voice when deploying their forces. SIPRNET is fast becoming the defacto standard of preferred data services, even over NIPRNET. The SIPRNET is the new, worldwide router-based network replacing the older X.25-based packet switched network (the Defense Secure Network One (DSNET1) of the Defense Data Network (DDN)). The initial SIPRNET backbone router network went online 3 March 1994. Subscribers started coming on line shortly thereafter. The SIPRNET WAN (as of 31 May 1995) consisted of a collection of 31 backbone routers interconnected by high-speed serial links to serve the long-haul data transport needs of secret-level DoD subscribers. Additional SIPRNET backbone routers are being planned to meet increased customer requirements. SIPRNET supports the DoD standard Transmission Control Protocol/Internet Protocol (TCP/IP) protocol service. Subscribers within the DoD and other Government Agencies are able to use the SIPRNET for passing datagrams at the Secret-Not Releasable to Foreign Nationals (SECRET-NOFORN) classification level.
Input appreciated. I realise i'm being a little paranoid.
edit: Anyone know what BOSCAP service is?
[This message has been edited by Shmoo (edited 12-23-2004).]
|
|
#2
 2004-12-23, 18:58
|
evilduck 
Regular
|
|
|
|
Re: DoD NetworkInformationCenter,Out going packets detected
Is there anymore information on the packets that the machine tried to send? It would be invaluably useful to find out what the packets contained.
The only thing that comes to mind is that the machine is infected by something that's attempting a DDOS or similar, rather than the DoD is watching your dads computer.
|
|
#3
 2004-12-24, 01:49
|
Shmoo 
Regular
|
|
|
|
Re: DoD NetworkInformationCenter,Out going packets detected
Yeah. That's a reasonable assumption. However, if you look at the trace route, even a massive swamping to one IP would do nothing because erroneous packets will be dropped by the private routers? right? I dunno. Nothing else has tried to send to DoD, if i ever get another detection i'll start running packet sniffers.
|
|
#4
 2004-12-24, 03:19
|
jamez 
Regular
|
|
|
|
Re: DoD NetworkInformationCenter,Out going packets detected
the service was called quicksuite.
perhaps a trojan uses that port too and they are scannning for trojans or something.
http://www.bekkoame.ne.jp/~s_ita/port/port2900-2999.html
ofcourse its not a DDOS attempt u idiot.
there would be WAY more than 2 packets, from more than one computer, more than likely using spoofed ip's and it would be on a port that is always open instead of this one thats very uncommon.
and the governemnt isnt watching u, u dumbass.
what the hell do u think 2 packets can show them what your doing?
if they were, not only would you not know or have a clue but they'd be even less inclined to communicate with your computer
|
|
 |
 |
To the best of our knowledge, the text on this page may be freely reproduced and distributed.

totse.com certificate signatures
|
 |
 |
About | Community | Bad Ideas | Drugs | Ego | Erotica | Fringe | Society | Technology
|
 |
 |
 |
 |
|
|