AplusWebMaster
Topic Starter
FYI…
- http://isc.sans.org/diary.php?storyid=1682
Last Updated: 2006-09-08 19:04:40 UTC
"…Given the options to hide the path your packets take that are available to most ISPs today I would be surprised if they would make this monitoring so noticeable. Simply tracerouting to see if you packets go through sffca.ip.att.net is too simple of a detection method.
For more details see the link*…"
* http://radar.oreilly.com/archives/2006/06/…_detecting.html
June 30, 2006
"…If you're a Windows user, fire up an MS-DOS command prompt. Now type tracert followed by the domain name of the website, e-mail host, VoIP switch, or whatever destination you're interested in. Watch as the program spits out your route, line by line.
C:\> tracert nsa.gov
…The magic string you're looking for is sffca.ip.att.net. If it's present immediately above or below a non-att.net entry, then – by Klein's allegations – your packets are being copied into room 641A, and from there, illegally, to the NSA. Of course, if Marcus is correct and AT&T has installed these secret rooms all around the country, then any att.net entry in your route is a bad sign…"

- http://isc.sans.org/diary.php?storyid=1682
Last Updated: 2006-09-08 19:04:40 UTC
"…Given the options to hide the path your packets take that are available to most ISPs today I would be surprised if they would make this monitoring so noticeable. Simply tracerouting to see if you packets go through sffca.ip.att.net is too simple of a detection method.
For more details see the link*…"
* http://radar.oreilly.com/archives/2006/06/…_detecting.html
June 30, 2006
"…If you're a Windows user, fire up an MS-DOS command prompt. Now type tracert followed by the domain name of the website, e-mail host, VoIP switch, or whatever destination you're interested in. Watch as the program spits out your route, line by line.
C:\> tracert nsa.gov
…The magic string you're looking for is sffca.ip.att.net. If it's present immediately above or below a non-att.net entry, then – by Klein's allegations – your packets are being copied into room 641A, and from there, illegally, to the NSA. Of course, if Marcus is correct and AT&T has installed these secret rooms all around the country, then any att.net entry in your route is a bad sign…"