I noticed www.windowsupdate.com has alot of cnames associated with it. akamai is their service provider. but look at all the cnames www.windowsupdate.com. 3600 IN CNAME windowsupdate.microsoft.nsatc.net. windowsupdate.microsoft.nsatc.net. 300 IN CNAME windowsupdate.microsoft.com.edgesuite.net. windowsupdate.microsoft.com.edgesuite.net. 779 IN CNAME a822.cd.akamai.net. wicked setup. Joe Baptista for Councillor City of Peterborough Town Ward 3 Official Campaign Site @ www.joebaptista.com Personal Web Space @ www.baptista.god The dot.GOD Registry, Limited @ http://www.dot-god.com/ Registry for .GOD and .SATAN On Thu, 16 Oct 2003, Carlos E. R. wrote:
The 03.10.09 at 15:05, Togan Muftuoglu wrote:
IIRC one of the recent worms were using windowsupdate.com with an address of 127.0.0.1 and microsoft had to drop the DNS record for windowsupdate.com
Aha! I knew there was some thing out there. :-)
If you have "snort" installed and configured and running you may see the following in your alert file
Now that you mention it... I had it running on my older machine, but for some reason, not on this system. I'm firing up Yast right now :-)
Yet this is all I can say :-(
Well, it's more than I knew.
-- Cheers, Carlos Robinson
-- Check the headers for your unsubscription address For additional commands send e-mail to suse-linux-e-help@suse.com Also check the archives at http://lists.suse.com Please read the FAQs: suse-linux-e-faq@suse.com