metalrod
8th August 2001, 23:21
i have had over 1000 alerts this week!!!!!!!!
ZA blocked this - what does it mean??
i wasnt using any FTP software at the time
can somebody help thanx
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Reverse DNS Lookup of 193.253.202.148
The computer name ("domain name") identified for this IP address is:
ASte-Genev-Bois-103-1-2-148.abo.wanadoo.fr
(Note: if you see "Unavailable", instead of a computer name, that means no reverse DNS entry was found for this IP address, and so the domain name could not be identified.)
Whois Lookup of 193.253.202.148
The following information was obtained from the "whois" database for the registry with which ASte-Genev-Bois-103-1-2-148.abo.wanadoo.fr is registered. This gives administrative and contact information about ASte-Genev-Bois-103-1-2-148.abo.wanadoo.fr.
If no domain name was identified, or if it was not possible to determine which registry the IP address is registered under, and for certain foreign domains that are not currently supported, the information below was obtained from the ARIN whois database. In that case, the information is not about the specific computer at 193.253.202.148. The information in that case is administrative and contact information for the "upstream provider" that administers a block of IP addresses, of which 193.253.202.148 is only one.
Particularly in the case of ARIN database results, the whois information below includes administrative information about a group of IP addresses that are all administered together. They may be administered together because the computers are all owned by the same person or organization, but they may not be. For example, an ISP may administer a large block of IP addresses together, but the ISP doesn't own all, or even most, of the computers on its network.
Please do not assume the people named in this report are the ones who are responsible for the alert you saw. However, if you are getting repeated alerts from IP addresses in the same IP block, this is a good place to find out who administers the network. If you have identified malicious or highly suspicious activity and have ruled out configuration errors, bugs, and other benign causes, you may wish to contact a network administrator to notify him or her.
Tous droits reserves par copyright.
Voir http://www.nic.fr/outils/dbcopyright.html
Rights restricted by copyright.
See http://www.nic.fr/outils/dbcopyright.html
domain: wanadoo.fr
descr: France Telecom Interactive
descr: 41, rue Camille Desmoulins
descr: 92442 Issy Les moulineaux cedex
admin-c: CC1215-FRNIC
tech-c: FTI-FRNIC
zone-c: NFC1-FRNIC
nserver: ns.wanadoo.fr 193.252.19.10
nserver: ns.wanadoo.com
nserver: ns2.wanadoo.fr 193.252.19.11
nserver: ns2.wanadoo.com
mnt-by: FR-NIC-MNT
mnt-lower: FR-NIC-MNT
changed: ripe-dbm-updates@nic.fr 19990506
changed: auto-update@nic.fr 19990823
changed: migration-dbm@nic.fr 20001015
source: FRNIC
role: Contacts of FTI
address: France Telecom Interactive
address: 41, rue Camille Desmoulins
address: 92442 Issy Les Moulineaux cedex
phone: +33 1 41 33 39 00
fax-no: +33 1 41 33 39 01
e-mail: postmaster@wanadoo.fr
e-mail: abuse@wanadoo.fr
trouble: mail postmaster for ANY problem.
admin-c: SC1509-FRNIC
tech-c: TEFS1-FRNIC
tech-c: SC1509-FRNIC
tech-c: NS1058-FRNIC
tech-c: CC1215-FRNIC
tech-c: IH678-FRNIC
nic-hdl: FTI-FRNIC
notify: ripe.mnt@fti.net
mnt-by: FT-INTERACTIVE
changed: Patrice.Robert@fti.net 19990413
changed: Patrice.Robert@fti.net 19990415
changed: Patrice.Robert@fti.net 19990506
changed: addr-reg@rain.fr 19990921
changed: migration-dbm@nic.fr 20001015
source: FRNIC
role: NIC France Contact
address: AFNIC
address: Immeuble International
address: 2, rue Stephenson
address: Montigny le Bretonneux
address: 78181 Saint Quentin en Yvelines Cedex
address: France
phone: +33 1 39 30 83 00
fax-no: +33 1 39 30 83 01
e-mail: tech@nic.fr
trouble: Information: http://www.nic.fr/
trouble: Questions: mailto:nic@nic.fr
trouble: Spam: mailto:abuse@nic.fr
trouble: Test: mailto:ping@nic.fr
admin-c: AR41
tech-c: AR41
tech-c: PL12-FRNIC
tech-c: JP1110-FRNIC
tech-c: EM634-FRNIC
tech-c: MS1887-FRNIC
tech-c: VL-FRNIC
tech-c: PR1249-FRNIC
tech-c: PV827-FRNIC
tech-c: GO661-FRNIC
tech-c: FT1632-FRNIC
tech-c: MS32434-FRNIC
tech-c: AI1-FRNIC
nic-hdl: NFC1-FRNIC
mnt-by: FR-NIC-MNT
changed: pick@nic.fr 20010313
changed: pick@nic.fr 20010313
source: FRNIC
person: Catherine Chevalier
address: France Telecom Interactive
address: 41, rue Camille Desmoulins
address: 92442 Issy les Moulineaux cedex
phone: +33 1 41 33 39 00
fax-no: +33 1 41 33 26 75
e-mail: catherine.chevalier@wanadoo.com
nic-hdl: CC1215-FRNIC
remarks: Exploitation Manager
mnt-by: FT-INTERACTIVE
changed: Patrice.Robert@fti.net 19990205
changed: migration-dbm@nic.fr 20001015
source: FRNIC
The firewall has blocked Internet access to your computer (FTP) from 193.253.202.148 (TCP Port 4750) [TCP Flags: S].
Time: 8/8/01 23:11:10
ZA blocked this - what does it mean??
i wasnt using any FTP software at the time
can somebody help thanx
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Reverse DNS Lookup of 193.253.202.148
The computer name ("domain name") identified for this IP address is:
ASte-Genev-Bois-103-1-2-148.abo.wanadoo.fr
(Note: if you see "Unavailable", instead of a computer name, that means no reverse DNS entry was found for this IP address, and so the domain name could not be identified.)
Whois Lookup of 193.253.202.148
The following information was obtained from the "whois" database for the registry with which ASte-Genev-Bois-103-1-2-148.abo.wanadoo.fr is registered. This gives administrative and contact information about ASte-Genev-Bois-103-1-2-148.abo.wanadoo.fr.
If no domain name was identified, or if it was not possible to determine which registry the IP address is registered under, and for certain foreign domains that are not currently supported, the information below was obtained from the ARIN whois database. In that case, the information is not about the specific computer at 193.253.202.148. The information in that case is administrative and contact information for the "upstream provider" that administers a block of IP addresses, of which 193.253.202.148 is only one.
Particularly in the case of ARIN database results, the whois information below includes administrative information about a group of IP addresses that are all administered together. They may be administered together because the computers are all owned by the same person or organization, but they may not be. For example, an ISP may administer a large block of IP addresses together, but the ISP doesn't own all, or even most, of the computers on its network.
Please do not assume the people named in this report are the ones who are responsible for the alert you saw. However, if you are getting repeated alerts from IP addresses in the same IP block, this is a good place to find out who administers the network. If you have identified malicious or highly suspicious activity and have ruled out configuration errors, bugs, and other benign causes, you may wish to contact a network administrator to notify him or her.
Tous droits reserves par copyright.
Voir http://www.nic.fr/outils/dbcopyright.html
Rights restricted by copyright.
See http://www.nic.fr/outils/dbcopyright.html
domain: wanadoo.fr
descr: France Telecom Interactive
descr: 41, rue Camille Desmoulins
descr: 92442 Issy Les moulineaux cedex
admin-c: CC1215-FRNIC
tech-c: FTI-FRNIC
zone-c: NFC1-FRNIC
nserver: ns.wanadoo.fr 193.252.19.10
nserver: ns.wanadoo.com
nserver: ns2.wanadoo.fr 193.252.19.11
nserver: ns2.wanadoo.com
mnt-by: FR-NIC-MNT
mnt-lower: FR-NIC-MNT
changed: ripe-dbm-updates@nic.fr 19990506
changed: auto-update@nic.fr 19990823
changed: migration-dbm@nic.fr 20001015
source: FRNIC
role: Contacts of FTI
address: France Telecom Interactive
address: 41, rue Camille Desmoulins
address: 92442 Issy Les Moulineaux cedex
phone: +33 1 41 33 39 00
fax-no: +33 1 41 33 39 01
e-mail: postmaster@wanadoo.fr
e-mail: abuse@wanadoo.fr
trouble: mail postmaster for ANY problem.
admin-c: SC1509-FRNIC
tech-c: TEFS1-FRNIC
tech-c: SC1509-FRNIC
tech-c: NS1058-FRNIC
tech-c: CC1215-FRNIC
tech-c: IH678-FRNIC
nic-hdl: FTI-FRNIC
notify: ripe.mnt@fti.net
mnt-by: FT-INTERACTIVE
changed: Patrice.Robert@fti.net 19990413
changed: Patrice.Robert@fti.net 19990415
changed: Patrice.Robert@fti.net 19990506
changed: addr-reg@rain.fr 19990921
changed: migration-dbm@nic.fr 20001015
source: FRNIC
role: NIC France Contact
address: AFNIC
address: Immeuble International
address: 2, rue Stephenson
address: Montigny le Bretonneux
address: 78181 Saint Quentin en Yvelines Cedex
address: France
phone: +33 1 39 30 83 00
fax-no: +33 1 39 30 83 01
e-mail: tech@nic.fr
trouble: Information: http://www.nic.fr/
trouble: Questions: mailto:nic@nic.fr
trouble: Spam: mailto:abuse@nic.fr
trouble: Test: mailto:ping@nic.fr
admin-c: AR41
tech-c: AR41
tech-c: PL12-FRNIC
tech-c: JP1110-FRNIC
tech-c: EM634-FRNIC
tech-c: MS1887-FRNIC
tech-c: VL-FRNIC
tech-c: PR1249-FRNIC
tech-c: PV827-FRNIC
tech-c: GO661-FRNIC
tech-c: FT1632-FRNIC
tech-c: MS32434-FRNIC
tech-c: AI1-FRNIC
nic-hdl: NFC1-FRNIC
mnt-by: FR-NIC-MNT
changed: pick@nic.fr 20010313
changed: pick@nic.fr 20010313
source: FRNIC
person: Catherine Chevalier
address: France Telecom Interactive
address: 41, rue Camille Desmoulins
address: 92442 Issy les Moulineaux cedex
phone: +33 1 41 33 39 00
fax-no: +33 1 41 33 26 75
e-mail: catherine.chevalier@wanadoo.com
nic-hdl: CC1215-FRNIC
remarks: Exploitation Manager
mnt-by: FT-INTERACTIVE
changed: Patrice.Robert@fti.net 19990205
changed: migration-dbm@nic.fr 20001015
source: FRNIC
The firewall has blocked Internet access to your computer (FTP) from 193.253.202.148 (TCP Port 4750) [TCP Flags: S].
Time: 8/8/01 23:11:10