[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

RE: [Full-Disclosure] windowsupdate.com



<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 3.2//EN">
<HTML>
<HEAD>
<META HTTP-EQUIV="Content-Type" CONTENT="text/html; charset=iso-8859-1">
<META NAME="Generator" CONTENT="MS Exchange Server version 5.5.2653.12">
<TITLE>RE: [Full-Disclosure] windowsupdate.com</TITLE>
</HEAD>
<BODY>

<P><FONT SIZE=2>'dig' is your friend:</FONT>
</P>

<P><FONT SIZE=2>; &lt;&lt;&gt;&gt; DiG 8.3 &lt;&lt;&gt;&gt; windowsupdate.com</FONT>
<BR><FONT SIZE=2>;; res options: init recurs defnam dnsrch</FONT>
<BR><FONT SIZE=2>;; got answer:</FONT>
<BR><FONT SIZE=2>;; -&gt;&gt;HEADER&lt;&lt;- opcode: QUERY, status: NOERROR, id: 2</FONT>
<BR><FONT SIZE=2>;; flags: qr aa rd ra; QUERY: 1, ANSWER: 2, AUTHORITY: 0, ADDITIONAL: 0</FONT>
<BR><FONT SIZE=2>;; QUERY SECTION:</FONT>
<BR><FONT SIZE=2>;;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; windowsupdate.com, type = A, class = IN</FONT>
</P>

<P><FONT SIZE=2>;; ANSWER SECTION:</FONT>
<BR><FONT SIZE=2>windowsupdate.com.&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 15M IN A&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 207.46.134.94</FONT>
<BR><FONT SIZE=2>windowsupdate.com.&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 15M IN A&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 207.46.134.30</FONT>
</P>

<P><FONT SIZE=2>and</FONT>
</P>

<P><FONT SIZE=2>; &lt;&lt;&gt;&gt; DiG 8.3 &lt;&lt;&gt;&gt; v3.windowsupdate.microsoft.com</FONT>
<BR><FONT SIZE=2>;; res options: init recurs defnam dnsrch</FONT>
<BR><FONT SIZE=2>;; got answer:</FONT>
<BR><FONT SIZE=2>;; -&gt;&gt;HEADER&lt;&lt;- opcode: QUERY, status: NOERROR, id: 2</FONT>
<BR><FONT SIZE=2>;; flags: qr rd ra; QUERY: 1, ANSWER: 2, AUTHORITY: 4, ADDITIONAL: 4</FONT>
<BR><FONT SIZE=2>;; QUERY SECTION:</FONT>
<BR><FONT SIZE=2>;;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; v3.windowsupdate.microsoft.com, type = A, class = IN</FONT>
</P>

<P><FONT SIZE=2>;; ANSWER SECTION:</FONT>
<BR><FONT SIZE=2>v3.windowsupdate.microsoft.com.&nbsp; 2H IN CNAME&nbsp; v3windowsupdate.microsoft.nsatc.net.</FONT>
<BR><FONT SIZE=2>v3windowsupdate.microsoft.nsatc.net.&nbsp; 5M IN A&nbsp; 207.46.249.61</FONT>
</P>

<P><FONT SIZE=2>;; AUTHORITY SECTION:</FONT>
<BR><FONT SIZE=2>nsatc.net.&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 15h19m43s IN NS&nbsp; m.ns.nsatc.net.</FONT>
<BR><FONT SIZE=2>nsatc.net.&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 15h19m43s IN NS&nbsp; a.ns.nsatc.net.</FONT>
<BR><FONT SIZE=2>nsatc.net.&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 15h19m43s IN NS&nbsp; us-ga-1.ns.nsatc.net.</FONT>
<BR><FONT SIZE=2>nsatc.net.&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 15h19m43s IN NS&nbsp; h.ns.nsatc.net.</FONT>
</P>

<P><FONT SIZE=2>;; ADDITIONAL SECTION:</FONT>
<BR><FONT SIZE=2>m.ns.nsatc.net.&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 14h4m31s IN A&nbsp;&nbsp; 63.121.106.141</FONT>
<BR><FONT SIZE=2>a.ns.nsatc.net.&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 14h4m31s IN A&nbsp;&nbsp; 206.25.8.69</FONT>
<BR><FONT SIZE=2>us-ga-1.ns.nsatc.net.&nbsp;&nbsp; 14h28s IN A&nbsp;&nbsp;&nbsp;&nbsp; 63.150.183.46</FONT>
<BR><FONT SIZE=2>h.ns.nsatc.net.&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 14h28s IN A&nbsp;&nbsp;&nbsp;&nbsp; 63.104.225.171</FONT>
</P>

<P><FONT SIZE=2>and</FONT>
</P>

<P><FONT SIZE=2>; &lt;&lt;&gt;&gt; DiG 8.3 &lt;&lt;&gt;&gt; v4.windowsupdate.microsoft.com</FONT>
<BR><FONT SIZE=2>;; res options: init recurs defnam dnsrch</FONT>
<BR><FONT SIZE=2>;; got answer:</FONT>
<BR><FONT SIZE=2>;; -&gt;&gt;HEADER&lt;&lt;- opcode: QUERY, status: NOERROR, id: 2</FONT>
<BR><FONT SIZE=2>;; flags: qr rd ra; QUERY: 1, ANSWER: 2, AUTHORITY: 4, ADDITIONAL: 4</FONT>
<BR><FONT SIZE=2>;; QUERY SECTION:</FONT>
<BR><FONT SIZE=2>;;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; v4.windowsupdate.microsoft.com, type = A, class = IN</FONT>
</P>

<P><FONT SIZE=2>;; ANSWER SECTION:</FONT>
<BR><FONT SIZE=2>v4.windowsupdate.microsoft.com.&nbsp; 1h34m17s IN CNAME&nbsp; v4windowsupdate.microsoft.nsatc.net.</FONT>
<BR><FONT SIZE=2>v4windowsupdate.microsoft.nsatc.net.&nbsp; 1S IN A&nbsp; 207.46.249.157</FONT>
</P>

<P><FONT SIZE=2>;; AUTHORITY SECTION:</FONT>
<BR><FONT SIZE=2>nsatc.net.&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 15h19m16s IN NS&nbsp; m.ns.nsatc.net.</FONT>
<BR><FONT SIZE=2>nsatc.net.&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 15h19m16s IN NS&nbsp; a.ns.nsatc.net.</FONT>
<BR><FONT SIZE=2>nsatc.net.&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 15h19m16s IN NS&nbsp; us-ga-1.ns.nsatc.net.</FONT>
<BR><FONT SIZE=2>nsatc.net.&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 15h19m16s IN NS&nbsp; h.ns.nsatc.net.</FONT>
</P>

<P><FONT SIZE=2>;; ADDITIONAL SECTION:</FONT>
<BR><FONT SIZE=2>m.ns.nsatc.net.&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 14h4m4s IN A&nbsp;&nbsp;&nbsp; 63.121.106.141</FONT>
<BR><FONT SIZE=2>a.ns.nsatc.net.&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 14h4m4s IN A&nbsp;&nbsp;&nbsp; 206.25.8.69</FONT>
<BR><FONT SIZE=2>us-ga-1.ns.nsatc.net.&nbsp;&nbsp; 14h1s IN A&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 63.150.183.46</FONT>
<BR><FONT SIZE=2>h.ns.nsatc.net.&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 14h1s IN A&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; 63.104.225.171</FONT>
</P>
<BR>
<BR>

<P><FONT SIZE=2>Joshua Thomas</FONT>
<BR><FONT SIZE=2>Network Operations Engineer</FONT>
<BR><FONT SIZE=2>PowerOne Media, Inc.</FONT>
<BR><FONT SIZE=2>tel: 518-687-6143</FONT>
<BR><FONT SIZE=2>jthomas@poweronemedia.com </FONT>
</P>

<P><FONT SIZE=2>-----Original Message-----</FONT>
<BR><FONT SIZE=2>From: Laurent LEVIER [<A HREF="mailto:llevier@argosnet.com";>mailto:llevier@argosnet.com</A>]</FONT>
<BR><FONT SIZE=2>Sent: Wednesday, August 13, 2003 2:51 PM</FONT>
<BR><FONT SIZE=2>To: KF; Andrew Simmons</FONT>
<BR><FONT SIZE=2>Cc: Andreas Gietl; Rafa³ ^^MA g^^ Kwa½ny;</FONT>
<BR><FONT SIZE=2>full-disclosure@lists.netsys.com</FONT>
<BR><FONT SIZE=2>Subject: Re: [Full-Disclosure] windowsupdate.com</FONT>
</P>
<BR>

<P><FONT SIZE=2>Guys,</FONT>
</P>

<P><FONT SIZE=2>When you nslookup windowsupdate.microsoft.com, you get a different response </FONT>
<BR><FONT SIZE=2>from the DNS (instead of having multiple IP Addresses for this single record).</FONT>
</P>

<P><FONT SIZE=2>Testing windowsupdate.microsoft.com, then v3.windowsupdate.microsoft.com or </FONT>
<BR><FONT SIZE=2>v4.windowsupdate.microsoft.com, I got multiple answers:</FONT>
<BR><FONT SIZE=2>- 207.46.134.29</FONT>
<BR><FONT SIZE=2>- 207.46.134.30</FONT>
<BR><FONT SIZE=2>- 207.46.134.93</FONT>
<BR><FONT SIZE=2>- 207.46.134.94</FONT>
<BR><FONT SIZE=2>- 207.46.249.61</FONT>
<BR><FONT SIZE=2>- 65.54.249.61</FONT>
<BR><FONT SIZE=2>- 65.54.249.254</FONT>
</P>

<P><FONT SIZE=2>As you can see, all these are located in 3 C classes.</FONT>
</P>

<P><FONT SIZE=2>Brgrds</FONT>
</P>

<P><FONT SIZE=2>Laurent LEVIER</FONT>
<BR><FONT SIZE=2>IT Systems &amp; Networks Security Expert</FONT>
</P>
<BR>
<BR>

<P><FONT SIZE=2>_______________________________________________</FONT>
<BR><FONT SIZE=2>Full-Disclosure - We believe in it.</FONT>
<BR><FONT SIZE=2>Charter: <A HREF="http://lists.netsys.com/full-disclosure-charter.html"; TARGET="_blank">http://lists.netsys.com/full-disclosure-charter.html</A></FONT>
</P>

</BODY>
</HTML>