LWN.net Logo

addlebrain.com

addlebrain.com

Posted Oct 26, 2004 1:57 UTC (Tue) by jtc (guest, #6246)
In reply to: The script is SOOOOOO silly by jeld
Parent article: Fake Red Hat security update

I missed where addlebrain.com fits into this, but I get the following results from HEAD:

$ HEAD addlebrain.com
200 OK
Cache-Control: private
Connection: close
Date: Tue, 26 Oct 2004 01:55:17 GMT
Server: Microsoft-IIS/6.0
Content-Type: text/html; charset=utf-8
Client-Date: Tue, 26 Oct 2004 01:51:12 GMT
Client-Response-Num: 1
Client-Transfer-Encoding: chunked
X-AspNet-Version: 1.1.4322
X-Powered-By: ASP.NET


(Log in to post comments)

addlebrain.com

Posted Oct 26, 2004 2:54 UTC (Tue) by jeld (guest, #22397) [Link]

Well... looks like you are right, except, that addlebrain.com (running IIS 6) is being redirected to www.addlebrain.com running apache. Since this is a valid site, and the email address where the script is sending cracked host info is root@addlebrain.com I figured that someone rooted one of addlebrain's boxes. Otherwise I don't know. addlebrain.com seems to belong to a company called ABM Wireless which sells cell phone accessories. MX record for addlebrain.com points to a server on everyone.net domain which is a mail hosting company. I cannot find much info about addlebrain.com IP address, but www.addlebrain.com address belongs to a dedicated web server/colocation company ThePlanet.com.

Copyright © 2008, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds