home *** CD-ROM | disk | FTP | other *** search
- Path: sparky!uunet!mcsun!uknet!warwick!dcs.warwick.ac.uk!sunserver1.aston.ac.uk!uhura!evansmp
- From: evansmp@uhura.aston.ac.uk (Mark Evans)
- Newsgroups: comp.security.misc
- Subject: Re: System "pleasure.com"
- Message-ID: <1992Jul23.213650.17172@aston.ac.uk>
- Date: 23 Jul 92 21:36:50 GMT
- References: <1992Jul23.144712.547@ulowell.ulowell.edu>
- Sender: usenet@aston.ac.uk (Usenet administrator)
- Organization: Aston University
- Lines: 40
- Nntp-Posting-Host: uhura
-
- oneill@cs.ulowell.edu (Brian 'Doc' O'Neill) writes:
- : Has anyone else heard of this system? I'm getting tons of FTP connections
- : from it.
- :
- : The domain "pleasure.com" does not actually exist. The IP address used is
- : 192.160.196.5, which is mapped to "pleasure.com". The IP address actually
- : belong to InteleCom Data Systems (NET-NET-IDS-COM).
- Oddly I can't resolve the name at all.
- Both attempting a forward mapping of pleasure.com
- and a reverse mapping of 192.160.196.5.
- What nameserver are you using?
- (I am trying with a root of ns.nic.ddn.mil)
- ids.net resloves to 155.212.1.2 and 192.67.241.11
- The later fails a reverse mapping.
- ids.com
- gives an MX record to idsvax.ids.risc.net, which resolves to 155.212.1.2
- the same as ids.net, but not an alias
- :
- : Isn't mapping to a false name against the rules?
- :
- : This site appears to a BBS for erotica gifs and such, which may violate some
- : of the regulations of some networks. Apparently a user can have that system
- : ftp files to their own account, which is why I see the FTP connections.
- : however I am concerned about the methods used to do this, as it may require
- : the divluging of the users password.
- I have seen this method used on other BBS's personally I don't like it,
- as it involves entering a password for another system to get it to work.
- BBS downloading should be done by connecting to an FTP server on the
- BBS machine, loging into the BBS, then running an FTP client to connect to
- your machine is the WRONG way to do it.
- Also it dosn't work with packages like NCSA telnet, which use a one time
- password system, entered at the time the server prompts you.
- Taking all the parameters, then firing up an ftp process is braindead!
- Also connections in to a machine, from unexpected places tend to alarm
- sys-admins.
- --
- -------------------------------------------------------------------------
- Mark Evans |evansmp@uhura.aston.ac.uk
- +(44) 21 565 1979 (Home) |evansmp@cs.aston.ac.uk
- +(44) 21 359 6531 x4039 (Office) |
-