Educause Security Discussion mailing list archives

Re: Microsoft the source of all evil?? Simple question


From: John Kim <jdk () BERKELEY EDU>
Date: Wed, 13 Feb 2008 09:26:08 -0800

James Moore wrote:
Anyone know more about “ofallevil.com”.  Whois shows it in Bellevue, WA,
but it is privacy protected.

http://thesource.ofallevil.com/en/us/default.aspx looks very Microsoft.

http://www.ofallevil.com/ returns a blank page.

The Bellevue, WA location seems to be the default location for all
registered using whoisprivacyprotect.com's service.

$ host thesource.ofallevil.com
thesource.ofallevil.com is an alias for www.microsoft.com.
www.microsoft.com is an alias for toggle.www.ms.akadns.net.
toggle.www.ms.akadns.net is an alias for g.www.ms.akadns.net.
g.www.ms.akadns.net is an alias for lb1.www.ms.akadns.net.
lb1.www.ms.akadns.net has address 207.46.192.254
lb1.www.ms.akadns.net has address 207.46.19.254
lb1.www.ms.akadns.net has address 207.46.193.254
lb1.www.ms.akadns.net has address 207.46.19.190
...

The name server being used is operated by totalenvironment.com.  Could be
the owner, or could be just a customer of them, since they do provide
hosting services.

Looks like a relatively harmless prank to me, unless the owner changes the
DNS record at some point to something more nefarious once it gets popular
enough.

--
John Kim
System and Network Security
http://security.berkeley.edu

Current thread: