Security Basics mailing list archives

RE: Possible PayPal security problem


From: "Weir, Jason" <jason.weir () nhrs org>
Date: Wed, 19 Dec 2007 16:35:05 -0500

Looks good to me, here is what nslookup says

G:\>nslookup
Default Server:  xx.xx.xx
Address:  xx.xx.xx.xx

set q=all
www.paypal.com
Server:  xx.xx.xx
Address:  xx.xx.xx.xx

Non-authoritative answer:
www.paypal.com  internet address = 66.211.168.209
www.paypal.com  internet address = 66.211.168.65
www.paypal.com  internet address = 66.211.168.97
www.paypal.com  internet address = 66.211.168.193
www.paypal.com  MX preference = 10, mail exchanger = lore.ebay.com
www.paypal.com  MX preference = 10, mail exchanger = data.ebay.com
www.paypal.com  MX preference = 10, mail exchanger = gort.ebay.com

lore.ebay.com   internet address = 66.135.195.181
data.ebay.com   internet address = 66.135.195.180
gort.ebay.com   internet address = 216.113.167.215

-Jason

-----Original Message-----
From: listbounce () securityfocus com [mailto:listbounce () securityfocus com]
On Behalf Of Bob Dienhart
Sent: Wednesday, December 19, 2007 1:21 PM
To: 'Albert R. Campa'; 'Harry Henry Gebel'
Cc: security-basics () securityfocus com
Subject: RE: Possible PayPal security problem


Flush your DNS cache and any browser history.  Then try connecting via
IP
rather than url.  I just ping'd "www/paypal.com" and that url resolved
to
66.211.168.209 from where I sit, which is in snowy Milwaukee.  Can
anybody
collaborate that address as a valid one for PayPal?

Bob Dienhart


Current thread: