Here's the scoop:

Shaw calls me, tells me that my domain (untitled1.ca) has been port scanning big companies (their clients) for the last month - if it doesn't stop, they'll press charges. Whoaaa! My hosting providor says that he's 99% sure its not their server, as they have up to date PHP and MySQL and run rootkit checks every night. Good. So that leaves two possibilities

  • Some rogue computer has a *.untitled1.ca dns entry stamped all over their IP
  • My host isn't as right as he thinks he is
As a precaution, I've wiped out the MySQL database on the website. My hosting providor disabled DNS resolution until I give him notice as well. At this point, I'm looking for options. I don't wanna get sued... Here's my plan of action, I'd be grateful for input

  1. Call Shaw in the morning, get the specific ip address of the hacker
  2. See if that IP has a DNS entry for my domain
  3. If 2 = true, then KICK THAT PERSONS ASS
  4. If 2 = false, then KICK HOSTS ASS
Sigh. This is the end of my rant for the moment. God give me strength!

mb

ps: If some machine that someone else owns has a DNS entry from my domain - then legally, I'm not responsible for it - correct? Thats just like sending a speeding ticket to the registered owner of a car and saying "YOU DID IT!" when in reality, someone stole your call while you were eating lunch and decided to take it drag racing!

--
pub 1024D/9091C422 02/05/2006 Mitchell Brown <[EMAIL PROTECTED]>
    Primary key fingerprint:  812B 94BC EA0D 345A CC1C 2ED9 F7F6 5CCF 9091 C422
_______________________________________________
clug-talk mailing list
[email protected]
http://clug.ca/mailman/listinfo/clug-talk_clug.ca
Mailing List Guidelines (http://clug.ca/ml_guidelines.php)
**Please remove these lines when replying

Reply via email to