Security Incidents mailing list archives

Re: Odd response from Taiwanese ISP


From: Philippe Bourcier <philippe () CYBERABUSE ORG>
Date: Wed, 22 Nov 2000 00:07:57 +0100

Re

At anti Anti-Hack (@CyberAbuse) we mailed them about:

dns.emtek.idv.tw (211.75.220.99) - running the Kiky's rootkit
203.75.43.172 (203.75.43.172) - same
http://www.documents.cyberabuse.org/?doc=12

210.61.37.51 - box now fixed, which was running Stacheldraht
http://www.documents.cyberabuse.org/?doc=4


We never had any reply from them, but they fixed the box the first time we
mailed.
We will see what they do about the Kiky's (mailed Sunday)

Philippe Bourcier
-------------------------------------
www.documents.cyberabuse.org


Greetings All,
             A little off topic but I can't think of anywhere else to
post this.

Below is the response I got to a report sent to abuse () hinet net.  The
report described a extentive scan of our address space for machines
running LPD (tcp port 515) and included accurate times and log records.

I really don't know what to make of this.  It looks to me as if Hinet
does not have an AUP and that they will only act on complaints that the
police will prosecute on.

Does anyone else have any iformation on what is going on here?

Cheers, Russell,


--- Begin Forwarded Message ---
Date: Mon, 20 Nov 2000 14:44:20 +0800
From: XXXXXqXHXXXXXXXXXqXXXAXXXX <spam () ms1 hinet net>
Subject: Reply from HiNet
Sender: XXXXXqXHXXXXXXXXXqXXXAXXXX <spam () ms1 hinet net>
To: Security () auckland ac nz

Reply-To: XXXXXqXHXXXXXXXXXqXXXAXXXX <spam () ms1 hinet net>
Message-ID: <200011201001.SAA25508 () ms63 hinet net>



Dear Sir/Madam ,
If you would like to report about the cracker leeter. Please send it to
criminal
investigation department then they will submit it with it with formal
documentation.
Please send mail to cybercop () cib gov tw
Sorry for the inconveniences.

Yours faithfully

CHT-D
Customer Care Center

[ my original report deleted ]

--- End Forwarded Message ---



Current thread: