ラベル NZNOG の投稿を表示しています。 すべての投稿を表示
ラベル NZNOG の投稿を表示しています。 すべての投稿を表示

5/07/2009

NZNOG@May 6, 2009

Date: Wed, 6 May 2009 10:34:50 +1000
Subject: [nznog] Wholesale DSL Opportunity


All,

We are looking at expanding our national Australian network into New Zealand, and as such we are looking for a partner to assist us with this.
In the short term, we are looking for Transit and also access to Telecom NZ DSL tails(to be handed off as L2TP sessions over Ethernet preferably).
Handoff location would be Sky Tower.

Is there anyone interested in this opportunity - please contact me off list

Thanks




Ben Cornish
National Network Manager


OZがNZに進出しようとしている?!
国を跨いでのネットワーク敷設って、法令とか監督官庁との兼ね合いとか、大変じゃないのかな?

4/22/2009

NZNOG@Apr 21, 2009

Date: Tue, 21 Apr 2009 12:14:05 +1200
Subject: [nznog] msn.co.nz

So, I wouldn't normally make a post like this, but I figure one or two
people might notice this at some point in the next day or so:

mj@coalface:~$ whois msn.co.nz | egrep ^ns_name
ns_name_01: fatih1.turkguvenligi.info
ns_name_02: fatih2.turkguvenligi.info

mj@coalface:~$ whois msn.co.nz | egrep ^domain_datelastmodified
domain_datelastmodified: 2009-04-21T09:44:21+12:00

From my resolver's cache:

;; ANSWER SECTION:
msn.co.nz. 3282 IN A 202.58.48.29

;; AUTHORITY SECTION:
msn.co.nz. 20363 IN NS ns4.msft.net.
msn.co.nz. 20363 IN NS ns5.msft.net.
msn.co.nz. 20363 IN NS ns1.msft.net.
msn.co.nz. 20363 IN NS ns2.msft.net.
msn.co.nz. 20363 IN NS ns3.msft.net.

;; ADDITIONAL SECTION:
ns1.msft.net. 1571 IN A 207.68.160.190
ns2.msft.net. 1593 IN A 65.54.240.126
ns3.msft.net. 18367 IN A 213.199.161.77
ns4.msft.net. 18367 IN A 207.46.66.126
ns5.msft.net. 1302 IN A 65.55.238.126

From the new NS:

;; ANSWER SECTION:
msn.co.nz. 14400 IN A 95.211.11.163

;; AUTHORITY SECTION:
msn.co.nz. 86400 IN NS fatih1.turkguvenligi.info.
msn.co.nz. 86400 IN NS fatih2.turkguvenligi.info.

;; ADDITIONAL SECTION:
fatih1.turkguvenligi.info. 14400 IN A 95.211.11.163
fatih2.turkguvenligi.info. 14400 IN A 95.211.11.163

It's not still April Fools, is it?

-Mike


MSNニュージーランドがハイジャックされた模様。
SQLインジェクションでネームサーバが書き換えられたらしいとのこと。

4/02/2009

NZNOG@Apr 1, 2009

Date: Wed, 01 Apr 2009 17:38:12 +1300
From: Gerard Creamer
Subject: [nznog] NZNOG NOC list
To: NZNOG
Message-ID: <49D2EFB4.9010705@netspace.net.nz>
Content-Type: text/plain; charset=ISO-8859-1; format=flowed


Hi,

Something broke on the NZNOG website when we moved servers and a bunch
of NOC list changes were lost. I have reentered as many as I have been
able to find based on emails but would appreciate it if you could all
check your entries.

http://www.nznog.org/?page_id=6

If there is a problem with your entry please email abuse and amendments
to info (at) nznog.org and I'll get onto fixing them up. If there are
no problems with your entry please keep your abuse and general
mutterings about competence to yourself :^)

Cheers,
Gerard

NZNOGではNOC Listというものを公開中。
AS番号、ドメイン名、管理者メールアドレス、電話番号、担当者名などを公開中。
個人情報が云々という前に、トラブル時に迅速な対応を取るためにお互いの
コンタクト先を把握しておくのは重要。
日本ではINOC-DBAに登録してる人も少なそうだし、(更新されてないかもしれないし、担当者に連絡が付かないかもしれない)Whois情報が最後の砦だったりする。
あとはJANOG等の呑み会で仲良くなってお互いの携帯電話番号を交換するとか。
#属人的になってしまうけれど。

3/27/2009

NZNOG@Mar 26, 2009

Date: Thu, 26 Mar 2009 09:55:22 +1300
From: Philip D'Ath
Subject: [nznog] Linksys + Netgear Worm
To: "nznog@list.waikato.ac.nz"
Message-ID:

Content-Type: text/plain; charset="iso-2022-jp"

Oh joy, a worm is now out that infects Linksys and NetGear DSL routers.


http://blogs.zdnet.com/BTL/?p=15197

'Psyb0t' worm infects Linksys, Netgear home routers, modems

More information has surfaced about the botnet ?psyb0t,? the first known to be capable of directly infecting home routers and cable/DSL modems.

It was first observed infecting a Netcomm NB5 modem/router in Australia.

Members of the website DroneBL, a real-time IP tracker that scans for and botnets and vulnerable machines, came to the conclusion that the ?psyb0t? (or ?Network Bluepill?) botnet was a test run to prove the technology. After the botnet?s discovery and public outing, the botnet operator swiftly shut it down, APC reports.

[Read more: Stealthy router-based botnet worm squirming]

However, the most recently discovered generation (dubbed ?version 18? in the code) targets a wide range of devices, and contains the shellcode for over 30 different Linksys models, 10 Netgear models, and 15 other models of cable and DSL modems, APC reports. It did not specify which models.

APC:

A list of 6000 usernames and 13,000 passwords were also included, to be used for brute force entry to Telnet and SSH logins which are open to the LAN and sometimes even the public WAN side of the routers. Generally, routers do not lock a user out after a number of incorrect password attempts, making brute force attacks possible.

According to DroneBL, any router that uses a MIPS processor and runs the Linux Mipsel operating system (a simple operating system for MIPS Processors) is vulnerable if they have the router administration interface, or sshd/telnetd in a DMZ, with weak username/passwords. DroneBL noted this includes devices flashed with the open-source firmwares openwrt and dd-wrt, and the group also said that other routers may be vulnerable, as it had observed the bot running on routers based on the Vxworks operating system.

Clearly, exploiting a home network ? which are growing in popularity ? has its benefits: they rarely power down, and a router attack enables hackers to exploit a network with greater levels of stealth, since there?s no affect on individual PCs on the network, APC writes.

In fact, the staff of DroneBL wrote that the exploit is very difficult to detect, and the only way to discover it is to monitor traffic going in and out of the router itself ?beyond the reach of desktop computer software.

In the past, exploits on professional-grade Cisco routers were easier to detect, as Cisco provides dedicated ports for connecting to the router, monitoring internal performance and configuring them. However, the vast majority of home routers sacrifice these features for the sake of cost savings.

DroneBL says that the botnet is capable of scanning for vulnerable PHPMyAdmin and MySQL installations, and can also disable access to the control interfaces of a router, (meaning a factory reset is necessary to clear the worm).

DroneBL was successful in shutting down the Command & Control channel that the botnet utilized, and the DNS that was hosted with afraid.org was also nullrouted. The Command & Control channel is now defunct, but at the height of its penetration, the botnet was suspected to control 100,000 hosts.

Worse, the author of the botnet claimed to have infected 80,000 routers at one point while chatting anonymously on an IRC channel.

WHAT DEVICES ARE AFFECTED

According to Drone BL:

We don?t know. There are so many devices out there that we could not possibly know.

Your best bet would be to take action to upgrade the device firmware and secure any passwords if there is concern that the device may be vulnerable. Such actions will help to avoid exploitation by the worm.

WHAT TO DO

According to DroneBL:

Ports 22, 23 and 80 are blocked as part of the infection process (but NOT as part of the rootkit itself, running the rootkit itself will not alter your iptables configuration).

If these ports are blocked, you should perform a hard reset on your device, change the administrative passwords, and update to the latest firmware. These steps will remove the rootkit and ensure that your device is not reinfected.


リンクシスやネットギアのADSLルータにWorm(増殖型のコンピュータウィルス)が報告されたという話。
SSL/Telnet/HTTPのポートがブロックされてたら感染の恐れがあるのでハードリセットしてね。パスワードも変えてね、とのこと。
ホームルータはなにかない限りいじらないので忘れがち・・・

日本版Slashdotでも記事「mipsel搭載ルータやモデムを狙い、ボットネット形成するワーム」になりましたね。

3/13/2009

NZNOG@Mar 12, 2009

From: Andy Linton [mailto:asjl@lpnz.org]
Sent: Thursday, March 12, 2009 12:07 PM
To: jon.brewer@araneo.net.nz
Cc: NZNOG List
Subject: Re: [nznog] NZNOG & Discussion Topics


On 12/03/2009, at 11:41 , Jonathan Brewer wrote:

> Hi Folks,
>
> For the health and happiness of users of this list, could we perhaps
> keep discussions to OSI Layer 5-1?

So who'll get the job of looking after process that examines whether
people get cut off because a particular IP address downloaded X at
time Y?

You can be sure it won't be the sales, marketing, legal, HR, finance
people in your organisations!

By the way, if we allow only Layers 5-1 in this forum, then we'd
remove all mail, web and other application nonsense. Fine by me!

andy

NZNOGでは人探しをしようとしたらトピックはLayer1から5に限るという人と、
それに縛られず自由に議論をしようという様々な立場の人が入り乱れて議論中。
Charterに書いてなかったっけ?