{"id":680,"date":"2014-04-29T02:05:46","date_gmt":"2014-04-29T06:05:46","guid":{"rendered":"http:\/\/www.glaver.org\/blog\/?p=680"},"modified":"2015-10-08T20:54:20","modified_gmt":"2015-10-09T00:54:20","slug":"ipv4scan-com-scan-or-scam","status":"publish","type":"post","link":"https:\/\/www.glaver.org\/blog\/?p=680","title":{"rendered":"IPv4Scan.com &#8211; scan or scam?"},"content":{"rendered":"<p>One of my occasional consulting customers called me in a panic because all of their HP printers printed out the same page at the same time:<\/p>\n<p><small><code>GET http:\/\/ipv4scan.com\/hello\/check.txt HTTP\/1.1<br \/>\nHost: ipv4scan.com<br \/>\nAccept-Encoding: gzip, deflate, compress<br \/>\nAccept: *\/*<br \/>\nUser-Agent: IPv4Scan (+http:\/\/ipv4scan.com)<\/code><\/small><\/p>\n<p>Now, I have nothing against most network measurement bots. Most are useful, and the rest are usually well-intentioned, even if they are counterproductive. The one thing these have in common is that they have a page that tells you what they&#8217;re doing, why they&#8217;re doing it, and who to contact if you have further questions.<\/p>\n<p>The <a href=\"http:\/\/ipv4scan.com\">http:\/\/IPv4Scan.com<\/a> page does none of those:<\/p>\n<p><img decoding=\"async\" src=\"ipv4scan.jpg\" alt=\"Screen capture\" \/><\/p>\n<p>There is no contact information provided on the page, there is no statement of how the data is being used (other than that it is &#8220;not for sale, rental or release&#8221;). The web page source does not contain any useful contact information, either. So they&#8217;re collecting this data for their own, unspecified, purposes.<\/p>\n<p>Ok, maybe it is legit, just with a spectacularly bad public relations campaign. Let&#8217;s look and see who is behind this:<\/p>\n<p><small><code>(0:115) host:~terry# jwhois ipv4scan.com<br \/>\n[whois.internet.bs]<br \/>\nDomain Name: IPV4SCAN.COM<br \/>\nRegistry Domain ID: 1824307886_DOMAIN_COM-VRSN<br \/>\nRegistrar WHOIS Server: whois.internet.bs<br \/>\nRegistrar URL: http:\/\/www.internetbs.net<br \/>\nUpdated Date: 2013-08-30T10:37:11Z<br \/>\nCreation Date: 2013-08-30T10:21:44Z<br \/>\nRegistrar Registration Expiration Date: 2014-08-30T10:21:44Z<br \/>\nRegistrar: Internet.bs Corp.<br \/>\nRegistrar IANA ID: 814<br \/>\nRegistrar Abuse Contact Email: abuse@internet.bs<br \/>\nRegistrar Abuse Contact Phone:<br \/>\nReseller:<br \/>\nDomain Status: clientTransferProhibited<br \/>\nRegistry Registrant ID:<br \/>\nRegistrant Name: Domain Administrator<br \/>\nRegistrant Organization: Fundacion Private Whois<br \/>\nRegistrant Street: Attn: ipv4scan.com, Aptds. 0850-00056<br \/>\nRegistrant City: Panama<br \/>\nRegistrant State\/Province:<br \/>\nRegistrant Postal Code: Zona 15<br \/>\nRegistrant Country: PA<br \/>\nRegistrant Phone: +507.65967959<br \/>\nRegistrant Phone Ext:<br \/>\nRegistrant Fax:<br \/>\nRegistrant Fax Ext:<br \/>\nRegistrant Email: 5230a6158jiing35@5225b4d0pi3627q9.privatewhois.net<br \/>\nRegistry Admin ID:<br \/>\nAdmin Name: Domain Administrator<br \/>\nAdmin Organization: Fundacion Private Whois<br \/>\nAdmin Street: Attn: ipv4scan.com, Aptds. 0850-00056<br \/>\nAdmin City: Panama<br \/>\nAdmin State\/Province:<br \/>\nAdmin Postal Code: Zona 15<br \/>\nAdmin Country: PA<br \/>\nAdmin Phone: +507.65967959<br \/>\nAdmin Phone Ext:<br \/>\nAdmin Fax:<br \/>\nAdmin Fax Ext:<br \/>\nAdmin Email: 5230a6157t3qutyb@5225b4d0pi3627q9.privatewhois.net<br \/>\nRegistry Tech ID:<br \/>\nTech Name: Domain Administrator<br \/>\nTech Organization: Fundacion Private Whois<br \/>\nTech Street: Attn: ipv4scan.com, Aptds. 0850-00056<br \/>\nTech City: Panama<br \/>\nTech State\/Province:<br \/>\nTech Postal Code: Zona 15<br \/>\nTech Country: PA<br \/>\nTech Phone: +507.65967959<br \/>\nTech Phone Ext:<br \/>\nTech Fax:<br \/>\nTech Fax Ext:<br \/>\nTech Email: 5230a615n285uy95@5225b4d0pi3627q9.privatewhois.net<br \/>\nName Server: ns-canada.topdns.com<br \/>\nName Server: ns-usa.topdns.com<br \/>\nName Server: ns-uk.topdns.com<br \/>\nDNSSEC: unsigned<br \/>\nURL of the ICANN WHOIS Data Problem Reporting System: http:\/\/wdprs.internic.net\/<br \/>\n>>> Last update of WHOIS database: 2014-04-29T05:00:41Z <<<<\/code><\/small><\/p>\n<p>Ok, so they're hiding behind a privacy service, but seem to be located in Panama. Let's see if the IP address they're using matches:<\/p>\n<p><small><code>(0:116) host:~terry# host ipv4scan.com<br \/>\nipv4scan.com has address 93.174.93.51<br \/>\nipv4scan.com mail is handled by 5 smtp09.topdns.com.<br \/>\nipv4scan.com mail is handled by 5 smtp01.topdns.com.<br \/>\n(0:117) host:~terry# jwhois 93.174.93.51<br \/>\n[whois.ripe.net]<br \/>\n% This is the RIPE Database query service.<br \/>\n% The objects are in RPSL format.<br \/>\n%<br \/>\n% The RIPE Database is subject to Terms and Conditions.<br \/>\n% See http:\/\/www.ripe.net\/db\/support\/db-terms-conditions.pdf<\/p>\n<p>% Note: this output has been filtered.<br \/>\n%       To receive output for a database update, use the \"-B\" flag.<\/p>\n<p>% Information related to '93.174.93.0 - 93.174.93.255'<\/p>\n<p>% Abuse contact for '93.174.93.0 - 93.174.93.255' is 'admin@ecatel.net'<\/p>\n<p>inetnum:        93.174.93.0 - 93.174.93.255<br \/>\nnetname:        NL-ECATEL<br \/>\ndescr:          ECATEL LTD<br \/>\ndescr:          Dedicated servers<br \/>\ndescr:          http:\/\/www.ecatel.net\/<br \/>\ncountry:        NL<br \/>\nadmin-c:        EL25-RIPE<br \/>\ntech-c:         EL25-RIPE<br \/>\nstatus:         ASSIGNED PA<br \/>\nmnt-by:         ECATEL-MNT<br \/>\nmnt-lower:      ECATEL-MNT<br \/>\nmnt-routes:     ECATEL-MNT<br \/>\nsource:         RIPE # Filtered<\/p>\n<p>role:           Ecatel LTD<br \/>\naddress:        P.O.Box  19533<br \/>\naddress:        2521 CA The Hague<br \/>\naddress:        Netherlands<br \/>\nabuse-mailbox:  abuse@ecatel.info<br \/>\nremarks:        ----------------------------------------------------<br \/>\nremarks:        ECATEL LTD<br \/>\nremarks:        Dedicated and Co-location hosting services<br \/>\nremarks:        ----------------------------------------------------<br \/>\nremarks:        for abuse complaints : abuse@ecatel.info<br \/>\nremarks:        for any other questions : info@ecatel.info<br \/>\nremarks:        ----------------------------------------------------<br \/>\nadmin-c:        EL25-RIPE<br \/>\ntech-c:         EL25-RIPE<br \/>\nnic-hdl:        EL25-RIPE<br \/>\nmnt-by:         ECATEL-MNT<br \/>\nsource:         RIPE # Filtered<\/p>\n<p>% Information related to '93.174.88.0\/21AS29073'<\/p>\n<p>route:          93.174.88.0\/21<br \/>\ndescr:          AS29073, Route object<br \/>\norigin:         AS29073<br \/>\nmnt-by:         ECATEL-MNT<br \/>\nsource:         RIPE # Filtered<\/p>\n<p>% This query was served by the RIPE Database Query Service version 1.72 (DBC-WHOIS3)<\/code><\/small><\/p>\n<p>So, they're using an IP address allocated to Ecatel in the Netherlands. Not exactly close to Panama, is it? Let's see if that address is actually in the Netherlands:<\/p>\n<p><small><code>(0:118) host:~terry# traceroute ipv4scan.com<br \/>\ntraceroute to ipv4scan.com (93.174.93.51), 64 hops max, 52 byte packets<br \/>\n [snip]<br \/>\n 8  be2094.ccr21.bos01.atlas.cogentco.com (154.54.30.14)  20.530 ms<br \/>\n    be2097.ccr22.bos01.atlas.cogentco.com (154.54.30.118)  19.664 ms<br \/>\n    be2095.ccr21.bos01.atlas.cogentco.com (154.54.30.38)  20.657 ms<br \/>\n 9  be2387.ccr22.lpl01.atlas.cogentco.com (154.54.44.166)  85.582 ms  85.667 ms<br \/>\n    be2386.ccr21.lpl01.atlas.cogentco.com (154.54.44.162)  85.388 ms<br \/>\n10  be2183.ccr42.ams03.atlas.cogentco.com (154.54.58.70)  95.882 ms<br \/>\n    be2182.ccr41.ams03.atlas.cogentco.com (154.54.77.245)  95.035 ms<br \/>\n    be2183.ccr42.ams03.atlas.cogentco.com (154.54.58.70)  97.517 ms<br \/>\n11  be2311.ccr21.ams04.atlas.cogentco.com (154.54.74.90)  130.510 ms<br \/>\n    be2312.ccr21.ams04.atlas.cogentco.com (154.54.74.94)  94.574 ms<br \/>\n    be2311.ccr21.ams04.atlas.cogentco.com (154.54.74.90)  101.849 ms<br \/>\n12  149.11.38.179 (149.11.38.179)  101.548 ms  118.302 ms  102.141 ms<br \/>\n13  server.anonymous-hosting-service.com (93.174.93.51)  98.234 ms  97.335 ms  96.958 ms<\/code><\/small><\/p>\n<p>Ok, the server is in Amsterdam, Netherlands. But hiding behind anonymous-hosting-service.com seems suspicious. Let's see where <i>they<\/i> are:<\/p>\n<p><small><code>(0:119) host:~terry# jwhois anonymous-hosting-service.com<br \/>\n[Querying whois.verisign-grs.com]<br \/>\n[Redirected to whois.onlinenic.com]<br \/>\n[Querying whois.onlinenic.com]<br \/>\n[whois.onlinenic.com]<\/p>\n<p>Domain Name: anonymous-hosting-service.com<br \/>\nRegistry Domain ID:<br \/>\nRegistrar WHOIS Server: whois.onlinenic.com<br \/>\nRegistrar URL: http:\/\/www.onlinenic.com<br \/>\nUpdated Date: 2014-04-06 03:14:38<br \/>\nCreation Date: 2009-09-08<br \/>\nRegistrar Registration Expiration Date: 2015-09-08<br \/>\nRegistrar: Onlinenic Inc<br \/>\nRegistrar IANA ID: 82<br \/>\nRegistrar Abuse Contact Email: onlinenic-enduser@onlinenic.com<br \/>\nRegistrar Abuse Contact Phone: +1.5107698492<br \/>\nDomain Status: clientTransferProhibited<br \/>\nRegistry Registrant ID:<br \/>\nRegistrant Name: Laura Yun<br \/>\nRegistrant Organization: Vindo International Ltd.<br \/>\nRegistrant Street: Oliaji TradeCenter - 1st floor<br \/>\nRegistrant City: Victoria<br \/>\nRegistrant State\/Province: Mahe<br \/>\nRegistrant Postal Code: 5567<br \/>\nRegistrant Country: SC<br \/>\nRegistrant Phone: +248.6629012<br \/>\nRegistrant Phone Ext:<br \/>\nRegistrant Fax: +248.24822575500<br \/>\nRegistrant Fax Ext:<br \/>\nRegistrant Email: anonymous.client@vindohosting.com<br \/>\nRegistry Admin ID:<br \/>\nAdmin Name: Laura Yun<br \/>\nAdmin Organization: Vindo International Ltd.<br \/>\nAdmin Street: Oliaji TradeCenter - 1st floor<br \/>\nAdmin City: Victoria<br \/>\nAdmin State\/Province: Mahe<br \/>\nAdmin Postal Code: 5567<br \/>\nAdmin Country: SC<br \/>\nAdmin Phone: +248.6629012<br \/>\nAdmin Phone Ext:<br \/>\nAdmin Fax: +248.24822575500<br \/>\nAdmin Fax Ext:<br \/>\nAdmin Email: anonymous.client@vindohosting.com<br \/>\nRegistry Tech ID:<br \/>\nTech Name: Laura Yun<br \/>\nTech Organization: Vindo International Ltd.<br \/>\nTech Street: Oliaji TradeCenter - 1st floor<br \/>\nTech City: Victoria<br \/>\nTech State\/Province: Mahe<br \/>\nTech Postal Code: 5567<br \/>\nTech Country: SC<br \/>\nTech Phone: +248.6629012<br \/>\nTech Phone Ext:<br \/>\nTech Fax: +248.24822575500<br \/>\nTech Fax Ext:<br \/>\nTech Email: anonymous.client@vindohosting.com<br \/>\nName Server: ns1.anonymous-hosting-service.com<br \/>\nName Server: ns2.anonymous-hosting-service.com<br \/>\nURL of the ICANN WHOIS Data Problem Reporting System: http:\/\/wdprs.internic.net\/<br \/>\n>>> Last update of WHOIS database: 2014-04-06 03:14:38 <<<<\/code><\/small><\/p>\n<p>Well, this is definitely fishy. No legitimate survey would be hiding behind so many levels of indirection.<\/p>\n<p>I used the site's form to \"opt out\" 0.0.0.0\/1 with an email address requesting they contact me about their project. I've also sent email to the abuse contacts shown above, pointing them to this blog entry, in the hope that they can get some sort of explanation from their customer.<\/p>\n<p>In the meantime, you may want to fine-tune your firewall rules to prevent this type of probe. That would (at a minimum) include blocking all outside connection attempts on ports 80 (http) and 443 (https) to anything on your network that <b>is not<\/b> intended to be a public web server. I <b>cannot<\/b> recommend using their opt-out form as there is no indication of what they do with the information. For all I know, it has the same effect as sending \"unsubscribe\" in response to a spam email - it just targets you for more spam.<\/p>\n<p>If I receive any information from my inquiries, I'll update this blog entry accordingly.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>One of my occasional consulting customers called me in a panic because all of their HP printers printed out the same page at the same time: GET http:\/\/ipv4scan.com\/hello\/check.txt HTTP\/1.1 Host: ipv4scan.com Accept-Encoding: gzip, deflate, compress Accept: *\/* User-Agent: IPv4Scan (+http:\/\/ipv4scan.com) Now, I have nothing against most network measurement bots. Most are useful, and the rest [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[3,4],"tags":[],"_links":{"self":[{"href":"https:\/\/www.glaver.org\/blog\/index.php?rest_route=\/wp\/v2\/posts\/680"}],"collection":[{"href":"https:\/\/www.glaver.org\/blog\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.glaver.org\/blog\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.glaver.org\/blog\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.glaver.org\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=680"}],"version-history":[{"count":10,"href":"https:\/\/www.glaver.org\/blog\/index.php?rest_route=\/wp\/v2\/posts\/680\/revisions"}],"predecessor-version":[{"id":805,"href":"https:\/\/www.glaver.org\/blog\/index.php?rest_route=\/wp\/v2\/posts\/680\/revisions\/805"}],"wp:attachment":[{"href":"https:\/\/www.glaver.org\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=680"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.glaver.org\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=680"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.glaver.org\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=680"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}