Hmmm...

Jan. 13th, 2005 01:57 pm
lovingboth: (Default)
[personal profile] lovingboth
Update: it seems this odd "feature" of windowsupdate - you know, the way you get critical security patches - is indeed genuine. Gosh.


Remember the person who ran an attachment on an email pretending to be from his hotmail account which he knew he didn't send?

Something interesting is happening on our PCs, and although Sophos reckons there's no infection, it may well be linked.

Can you run the following two from the command line (Windows 9x: Start / Programs / MS-DOS Prompt, Win 2k/XP: Start / Programs / Command line, Linux: ... probably don't need to be told!)

  ping windowsupdate.microsoft.com

  ping v4.windowsupdate.microsoft.com

(Ping sends a small 'hello' message to the destination and expects a 'hello' back, but it's the IP address I'm particularly interested in...)

What's the result?

(no subject)

Date: 2005-01-13 02:04 pm (UTC)
From: [identity profile] ramtops.livejournal.com
PING windowsupdate.microsoft.nsatc.net (207.46.134.92): 56 data bytes
(no reply)

PING v4windowsupdate.microsoft.nsatc.net (207.46.245.126): 56 data bytes
(no reply)

Rather than that...

Date: 2005-01-13 02:21 pm (UTC)
ext_5939: (Default)
From: [identity profile] bondagewoodelf.livejournal.com
... on Linux I did an nslookup:

Name: windowsupdate.microsoft.nsatc.net
Address: 207.46.134.24
Name: windowsupdate.microsoft.nsatc.net
Address: 207.46.249.56

Name: v4windowsupdate.microsoft.nsatc.net
Address: 207.46.244.222
Name: v4windowsupdate.microsoft.nsatc.net
Address: 64.4.20.220
Name: v4windowsupdate.microsoft.nsatc.net
Address: 64.4.20.252

So, you're expecting to find different results, but only any of these mentioned above.

Re: Rather than that...

Date: 2005-01-13 02:25 pm (UTC)
ext_5939: (Default)
From: [identity profile] bondagewoodelf.livejournal.com
but only any of these mentioned above.

Unless you, apparently, live somewhere else in the world and you are directed somewhere else.

Re: Rather than that...

Date: 2005-01-13 06:09 pm (UTC)
From: [identity profile] drdoug.livejournal.com
Er ... but Microsoft still controls microsoft.com, so can easily change the pointers to nsatc.net (etc) if necessary.

I'm pretty sure this is just plain old outsourcing - Savvis does serious heavy-lifting network stuff, and Microsoft is one of their big name punters.

(Incidentally, I'm not surprised that the hosts in question drop pings on the floor - that's just what I'd do with such high-profile sites that to any script kiddie have "DoS ME!" written in foot-high letters of fire on 'em.)

Profile

lovingboth: (Default)
Ian

July 2025

S M T W T F S
  12345
6 789101112
13141516171819
20212223242526
2728293031  

Most Popular Tags

Active Entries

Style Credit

Expand Cut Tags

No cut tags