AplusWebMaster
Topic Starter
FYI…
- http://isc.sans.org/diary.php?date=2005-07-30
Updated July 30th 2005 21:26 UTC
"After spending a couple of hours following up on a malware incident late Friday night, I have come to the conclusion that ICANN could do us all a tremendous favor by pulling the .info and .biz Top Level Domains (TLDs). It strongly looks to me as if 98% of all domains underneath these two TLDs belong to nefarious web sites in one of the countries-where-ISPs-ignore-all-complaints (CWIIAC). Some companies have started to zapp all access to .biz and .info… While you're at it, you might want to check your logs for access going to hXXp ://195.225.176.25. This site is a particular "friend" of mine, it has been around since February or so, and is of course located in one of the CWIIAC. Currently, the site is serving up IE exploits from hXXp ://195.225.176.25/user.scripts/u217/dir38500256.cgi, but I wont be surprised if this URL has already been shifted by now. The site itself and the exploits it contains will likely stay, though, as long as Ukraine is among the CWIIAC."

- http://isc.sans.org/diary.php?date=2005-07-30
Updated July 30th 2005 21:26 UTC
"After spending a couple of hours following up on a malware incident late Friday night, I have come to the conclusion that ICANN could do us all a tremendous favor by pulling the .info and .biz Top Level Domains (TLDs). It strongly looks to me as if 98% of all domains underneath these two TLDs belong to nefarious web sites in one of the countries-where-ISPs-ignore-all-complaints (CWIIAC). Some companies have started to zapp all access to .biz and .info… While you're at it, you might want to check your logs for access going to hXXp ://195.225.176.25. This site is a particular "friend" of mine, it has been around since February or so, and is of course located in one of the CWIIAC. Currently, the site is serving up IE exploits from hXXp ://195.225.176.25/user.scripts/u217/dir38500256.cgi, but I wont be surprised if this URL has already been shifted by now. The site itself and the exploits it contains will likely stay, though, as long as Ukraine is among the CWIIAC."