Google Groups no longer supports new Usenet posts or subscriptions. Historical content remains viewable.
Dismiss

El Papa de Roma

1 view
Skip to first unread message

Marta Oribe

unread,
Dec 20, 2000, 3:48:21 PM12/20/00
to

Hola colegas,

Hacía muchos meses que mi sistema de triple cortafuegos descansaba
tranquilo, pero parece que "¡las verdades molestan!", y "¡la libre expresión
también molesta!".

Justo después de citar en un mensaje aquí en s.l.t. la frase:

"Decir que en s.l.t. no hay racistas y xenófobos, "como el neurótico y
cobarde palurdo Phil Dragoman", es como decir que: el Papa no entregó a
Haider, el líder ultranacionalista austríaco, una copia de su mensaje contra
la xenofobia y el racismo",

he empezado a recibir ataques por Internet desde Alemania y Gran Bretaña,
espero que les echen de sus respectivos ISPs, abajo están los 'logs' por si
alguien quiere verlos y por si les suenan esas empresas (¿Coral Racing?,
¿GTN?.

Me voy a cenar, buenas noches,

Cheers,
RAC
--
Ramiro Alvarez Clavero
(ICT Localization)
http://www.arrakis.es/~rac1/
*~*~*~*~*~*~*~*~*~*~*~*~*~*~*~*~*~*~*~*
Vuerokiraputoru wa Meiyo no Sennsi ga suki
*~*~*~*~*~*~*~*~*~*~*~*~*~*~*~*~*~*~*~*
We should recognise that without language we cannot communicate;
without communication we cannot understand and without understanding we
cannot survive. Language is the most essential of all the skills of modern
life and our civilisation will not progress until we master it.
--
#################################################

----- Mensaje original -----
De: Ramiro Alvarez Clavero
Para: k.kre...@via-net-works.de
CC: dom...@highspeed-server.de ; sup...@highspeed-server.de ;
hostm...@franken2000.de
Enviado: miércoles 20 de diciembre de 2000 21:10
Asunto: Hacking

GTN, HSMOBITNET, Highspeed-Server-EISnet GmbH (A VIA NET.WORKS Company),
etc.

Dear Sir,

My firewall has blocked Internet access to my system (Port 137, NetBIOS)
from 212.168.18.2 (Por 137, NetBIOS Name) on 20/12/00 at 20:37:24

Please, close-down the account of this user.

##############################################

----- Mensaje original -----
De: Ramiro Alvarez Clavero
Para: rich...@uk.uu.net
CC: ab...@uk.uu.net ; dor...@nmc.kpn.net
Enviado: miércoles 20 de diciembre de 2000 21:08
Asunto: Abuse


Coral Racing (GB)
UUNET (UK)
Blue Water Shipping Holland (NL)

Dear Sir,

My firewall has blocked Internet access to my system (Port 137, NetBIOS)
from 193.131.2.242 (UDP Ports 890, 891) on 20/12/00 at 20:41:41

Please, close-down the account of this user.

###################################################

Iwan Davies

unread,
Dec 20, 2000, 5:57:14 PM12/20/00
to

Hi Marta / Ramiro

With regard to your port scanning problems, I thought you might be
interested in the Gibson Research website: http://grc.com. Steve Gibson,
though a little "angeber"-ish in his style of writing, has developed some
good tools to help you test your Internet security.

Given that an American court recently ruled that port scanning itself is not
illegal (though my views on that differ somewhat), it can only be expected
that scans will be increased considerably over the next few months / years.
Usually, however, these scans that are reported on your firewall logs (do
you use ZoneAlarm? I have found it to be very reliable), especially those
that appear on the NetBios ports, are often down to badly-configured Windows
systems. Steve Gibson talks about this "Internet Background Radiation" (IBR)
extensively on his website.

On the other hand, it is possible that your system really is being scanned
by another Net user. But what of it? You are on dial-up, with a different IP
address each time you log on - in other words, someone trying to target
*you* would be trying to look for a needle in a haystack the size of Madrid,
if not bigger! So even if someone does scan you, and find an entry point,
the next time you log on you'll have a different address and they'll have to
start again from scratch.

Out-of-the-box, Windows systems are inherently insecure, and like nothing
better than to advertise their presence all over the net. Simply by removing
the bindings between TCP/IP and the NetBios protocol, you can shut this
entry point to your pc. One way of shutting your PC off almost entirely is
using a firewall, such as ZoneAlarm (http://www.zonelabs.com)

Port scans are annoying, but they do no real harm if you have a firewall,
even a free one like ZoneAlarm. The scans can come from anywhere - I have
been scanned from Spain, France, Finland, the Czech Republic, the US, and
many other countries as well as my native UK. This past week I have received
a number of scans from a network in Saudi Arabia. More often than not, as I
said above, these scans are from badly configured Windows machines that are
merely trying to advertise their presence on the network, though some
(including the Saudi Arabian ones) have been looking for the Sub7 trojan
horse program (scanning for activity on port 27374). These are a tad more
malicious, but again, as long as you have a firewall like ZoneAlarm, nothing
much is going to happen to you. Just install the firewall, set the security
settings to match your level of paranoia (mine are set to high! ;-) and
switch off the pop-up alerts... Once a week, check your logs and if you find
that you are being targeted by a single IP, get in touch with their sysadmin
(you can use a website such as http://combat.uxn.com/ to trace IP
addresses - do an IP Whois). But on the whole, don't react to individual
alerts - you'll spend more time firing off abuse notes (most probably
against poor unsuspecting grannies and grandads with badly configured
Windows machines) than you do translating!

Sorry about the length of this posting - the information is useful, honest!

Iwan


"Marta Oribe" <mor...@arrakis.es> wrote in message
news:3a411...@news.arrakis.es...

Marta Oribe

unread,
Dec 20, 2000, 8:32:26 PM12/20/00
to
 
Iwan, I know all that information and these URLs and much more... ;-)
 
I have several firewalls (hardware and software) and it's not a port scanning problem. What I posted was a summary log, the full detailed log is terrible; from 137 (Netbios, Denial of Service attacks )
139, 146,.............., to 61466 (Telecommando), 63485 (Bunker-Hill), 65000 (Devil), 65000 (Stacheldraht), etc.
 
Some months ago I was "visited" by 'Kazimas', 'Sub-7 2.1', 'Baron Night' and 'Back Orifice 2000'; this is not 'port scanning' Iwan; some of these 'novices' lost their accounts after my complaint; you know Iwan, I am a troll-hunter ;-)
 
Zone Alarm is a 'shit' beside my 'latest development firewall'; my firewall can answer the attack, first politely using a netsend() function and after.....[secret]
 
Iwan, what do you know about the IN-ADDR.ARPA entries?
 
This is an example reported to the builder of my firewall:
 
Dear Ramiro,
Possible Cause: This is the first time we received an email regarding the issues you are experiencing. For further assistance with your case please email us within 3 business days with your email history.
Sincerely,
 [snip] Technical Support
 [snip] Technologies, Inc.
 
'12/12/2000 18:46:50' 'Access 131.22.75.209.in-addr.arpa'[kee22-75-209.keesler.af.mil] [US Air Force]
'12/12/2000 18:46:51' 'Access 131.22.75.209.in-addr.arpa'[kee22-75-209.keesler.af.mil] [US Air Force]
'12/12/2000 18:46:52' 'Access 131.22.75.209.in-addr.arpa'[kee22-75-209.keesler.af.mil] [US Air Force]
'12/12/2000 18:46:53' 'Access 131.22.75.209.in-addr.arpa'[kee22-75-209.keesler.af.mil] [US Air Force]
'12/12/2000 18:46:54' 'Access 131.22.75.209.in-addr.arpa'[kee22-75-209.keesler.af.mil] [US Air Force]
[etc] <== this is just a summary log, not the detailed log.
 
Iwan, the US Air Force is touching my balls and my willy ;-)
 
I am going to test your IT 'know how': What do you know about these in-addrr.arpa entries, Iwan?
(clue: this repugnant 'sniffer' lost his Internet account after my complaint).
 
Good night,
 
Cheers,
RAC
--
Ramiro Alvarez Clavero
(ICT Localization)
http://www.arrakis.es/~rac1/
*~*~*~*~*~*~*~*~*~*~*~*~*~*~*~*~*~*~*~*
Vuerokiraputoru wa Meiyo no Sennsi ga suki
*~*~*~*~*~*~*~*~*~*~*~*~*~*~*~*~*~*~*~*
We should recognise that without language we cannot communicate;
without communication we cannot understand and without understanding we
cannot survive. Language is the most essential of all the skills of modern
life and our civilisation will not progress until we master it.
--

Iwan Davies <iwan....@ntlworld.com.invalid> escribió en el mensaje de noticias NLa06.236$fH5....@news11-gui.server.ntli.net...

Jim Tarbuck

unread,
Dec 21, 2000, 5:20:10 AM12/21/00
to

Marta Oribe <mor...@arrakis.es> wrote in message
news:3a415...@news.arrakis.es...

>Some months ago I was "visited" by 'Kazimas', 'Sub-7 2.1', 'Baron Night'
and 'Back Orifice 2000'; this is >not 'port scanning' Iwan; some of these
'novices' lost their accounts after my complaint; you know Iwan, I >am a
troll-hunter ;-)

tee hee! a troll-hunter? have you found any trolls recently, Ramiro?

you were "visited" by sub-7 and back orifice were you?
bwaaaahaaaahahahahaha!!!!!! were they knocking on your front door?

what a loser.

>Zone Alarm is a 'shit' beside my 'latest development firewall'; my firewall
can answer the attack, first >politely using a netsend() function and
after.....[secret]

yes...? what after? you're a liar ramiro, there's nothing your 'latest
development firewall' can do after, that's the only secret people need to
know.

i bet you're going to tell us you can take control of anyone's computer if
it does a port sniff on yours.

lame-ass. keep taking the pills


Iwan Davies

unread,
Dec 21, 2000, 5:59:59 AM12/21/00
to
"Marta Oribe" <mor...@arrakis.es> wrote in message
news:3a415...@news.arrakis.es...

> Iwan, I know all that information and these URLs and much more... ;-)

That's nice for you. I thought in-addr.arpa domains were obsolete by now -
goes to show, you live and learn :-)

Still doesn't mean that you are personally being targetted though. As I
said, each time you dial into your ISP, you'll get a different IP address.
Assuming you're not connected for more than around 2 hours at a time (or are
local phone calls free in Spain?) then the chances of them looking for and
finding *you* before you log off and reconnect under another IP are very,
very, very remote to the power of ten zillion zillion zillion (i.e. not very
likely). Assuming the conspiracy theory is legitimate, of course, they
presumably know what ISP you use, and can concentrate their scans for you on
specific IP range(s). In that case, why not maintain free internet accounts
with a range of different providers, between whom you can swap at random -
thereby moving IP range - a moving target is a lot harder to hit.

Finally, an entry in your firewall log tells you that the "attempt to breach
security" failed - your firewall did its job, so just laugh in the face of
the would-be intruders and sit back and enjoy your life. But don't get too
complacent - remember "no one expects the Spanish Inquisition..."

Iwan


Ramiro Alvarez Clavero

unread,
Dec 21, 2000, 8:32:45 AM12/21/00
to
There are 21 unique messages by
"Jim Tarbuck" <j...@tarbuck.com>
(numbers may be slightly skewed by cross-postings)

Number of Messages Forum
9 freeserve.chat
6 sci.lang.translation
2 uk.legal
2 comp.lang.javascript
1 alt.sports.soccer.manchester.united.scum-haters
1 fr.misc.droit

Ahí arriba puede verse el ejemplo de un 'novato macarra' que quiere hacerse
famoso a costa de insultar a los miembros veteranos de s.l.t. Lleva sólo 6
mensajes en s.l.t. y los 6 son para insultar, no ha hecho ninguna aportacion
relacionada con la traduccion a este grupo. Este es el mejor ejemplo de los
gamberros conocidos en lengua inglesa como "trolls" o "hooligans".

Do stick to translation issues or go away deranged troll, you won't be
missed!


Cheers,
RAC
--
Ramiro Alvarez Clavero
(ICT Localization)
http://www.arrakis.es/~rac1/
*~*~*~*~*~*~*~*~*~*~*~*~*~*~*~*~*~*~*~*
Vuerokiraputoru wa Meiyo no Sennsi ga suki
*~*~*~*~*~*~*~*~*~*~*~*~*~*~*~*~*~*~*~*
We should recognise that without language we cannot communicate;
without communication we cannot understand and without understanding we
cannot survive. Language is the most essential of all the skills of modern
life and our civilisation will not progress until we master it.
--

Jim Tarbuck <j...@tarbuck.com> escribió en el mensaje de noticias
91slg7$dq6$1...@newsg4.svr.pol.co.uk...

Jim Tarbuck

unread,
Dec 21, 2000, 10:59:46 AM12/21/00
to

Ramiro Alvarez Clavero <ra...@arrakis.es> wrote in message
news:3a420...@news.arrakis.es...

> There are 21 unique messages by
> "Jim Tarbuck" <j...@tarbuck.com>
> (numbers may be slightly skewed by cross-postings)
>
> Number of Messages Forum
> 9 freeserve.chat
> 6 sci.lang.translation
> 2 uk.legal
> 2 comp.lang.javascript
> 1 alt.sports.soccer.manchester.united.scum-haters
> 1 fr.misc.droit
>
> Ahí arriba puede verse el ejemplo de un 'novato macarra' que quiere
hacerse
> famoso a costa de insultar a los miembros veteranos de s.l.t. Lleva sólo 6
> mensajes en s.l.t. y los 6 son para insultar, no ha hecho ninguna
aportacion
> relacionada con la traduccion a este grupo. Este es el mejor ejemplo de
los
> gamberros conocidos en lengua inglesa como "trolls" o "hooligans".
>

"los miembros veteranos"?

no ramiro, it's only you. you're the troll. you're the one who keeps
insulting people for no reason. you're the one who keeps accusing people of
racism. i never knew they had computers in mental institutions, but maybe
you have a key to the secretary's office.

> Do stick to translation issues or go away deranged troll, you won't be
> missed!

I think the little men in white coats are going to come and find you soon.
The only contributions you've made recently are paranoid attacks on other
people, and claims that you have a firewall which is going to do something
special.


Phil Dragoman

unread,
Dec 21, 2000, 12:18:34 PM12/21/00
to

Jim Tarbuck wrote in message <91t9fv$o8u$1...@news6.svr.pol.co.uk>...

>
>Ramiro Alvarez Clavero <ra...@arrakis.es> wrote in message
>news:3a420...@news.arrakis.es...
.manchester.united.scum-haters
>> 1 fr.misc.droit
>>
>> Ahí arriba puede verse el ejemplo de un 'novato macarra' que quiere
>hacerse
>> famoso a costa de insultar a los miembros veteranos de s.l.t. Lleva sólo 6
>> mensajes en s.l.t. y los 6 son para insultar, no ha hecho ninguna
>aportacion
>> relacionada con la traduccion a este grupo. Este es el mejor ejemplo de
>los
>> gamberros conocidos en lengua inglesa como "trolls" o "hooligans".
>>
>
>"los miembros veteranos"?
>
>no ramiro, it's only you. you're the troll. you're the one who keeps
>insulting people for no reason. you're the one who keeps accusing people of
>racism. i never knew they had computers in mental institutions, but maybe
>you have a key to the secretary's office.
>

Good point, Jim. Or maybe he gets computer privileges for good behavior,
such as not soiling his nappies. Maybe the staff figures he can work off his
frustration on the internet instead of taking a meat cleaver to the other inmates.
Bet he goes through a couple of keyboards a week.

You know that he thinks he is a velociraptor, don't you? Look at his sig. He
once had somebody translate it into Japanese for him. I suppose I am now
anti-lizard (saurophobic?) for mentioning that. ;-)

Regards,
Phil

John Woodgate

unread,
Dec 21, 2000, 10:55:55 AM12/21/00
to
<mll06.32$8Y3...@news11-gui.server.ntli.net>, Iwan Davies <iwan.davies@

ntlworld.com.invalid> inimitably wrote:
>But don't get too
>complacent - remember "no one expects the Spanish Inquisition..."

OMG!!!! Now you've really been an' gorn an' dunnit. Xerophobe! Stick to
translucent tissues or get off the dinosaur!
--
Regards, John Woodgate, OOO - Own Opinions Only. Phone +44 (0)1268 747839
Fax +44 (0)1268 777124. http://www.jmwa.demon.co.uk I wanted to make a fully-
automated nuclear-powered trawler,but it went into spontaneous fishing.
PLEASE do not mail copies of newsgroup posts to me.

Iwan Davies

unread,
Dec 21, 2000, 3:48:55 PM12/21/00
to
"John Woodgate" <j...@jmwa.demon.co.uk> wrote in message
news:mgD5BdAL...@jmwa.demon.co.uk...

> <mll06.32$8Y3...@news11-gui.server.ntli.net>, Iwan Davies <iwan.davies@
> ntlworld.com.invalid> inimitably wrote:
> >But don't get too
> >complacent - remember "no one expects the Spanish Inquisition..."
>
> OMG!!!! Now you've really been an' gorn an' dunnit. Xerophobe! Stick to
> translucent tissues or get off the dinosaur!
'Onest butty bach, I 'ant done nothin! I was jest bein' friendly, like -
Goodwill to all men an all 'at...

By the way butty, all them Spanish insults bein' chucked around, like,
wossallarabouthen? I 'ant really got the lingo, see. Bit thick really in
fact, look yew, goodboy.

Anyway, I's best be off now then - hwyl iti, nadolig llawen, cyfarchion y
tymor, blwyddyn newydd dda, etc. (see - i knows some Latin, i does!) All the
best from us up by yur to yew down by there.

Iwan


Jim Tarbuck

unread,
Dec 22, 2000, 6:28:42 PM12/22/00
to

Phil Dragoman <phil.d...@literally.com> wrote in message
news:KXq06.11835$1M.31...@typhoon.ne.mediaone.net...

yes you are, and for that i imagine your port will be scanned by lizards.
or something.

with all due respect to the velociraptor theory, i'd say he's actually from
outer space.


0 new messages