Security Incidents mailing list archives

abusers from multiple domains


From: Mark Robert Williams <mark_r_williams () USA NET>
Date: Fri, 20 Oct 2000 10:56:59 -0000

Here are a list of hosts which are belived to be 
compromised by "t0rn". Some of these have been 
used on irc under the nick torner. And others I have 
picked up from a quite famous IRCnet channel, 
where torn and his fellow script kiddies tend to "hang 
out".

The reason i am posting it to this list, is because i am 
quite certain the people looking after these domains 
read this list regularly and its easier then emailing 
each of them individually.

IRCnet
---------

ponyexpress.net
pontiac.campus.luth.se
www.bsd.org
cisco-partner.de
matrix.etela.sonera.fi
fiiu.org
Cvele.tb.6bone.it
nova.6bone.verstehts.net
FastEthernet4-0.HR1.SYD2.ALTER.NET
aol-dns.mdip.bt.net
qhu.mit.edu
third-west.mit.edu
taco.mit.edu
bovine.mit.edu
derelict.mit.edu
damien.mit.edu
strangelove.mit.edu
golden-gun.mit.edu
freeside.mit.edu
emilie.mit.edu
nacho.mit.edu

EFnet 
--------
hpov.re.exodus.net
tourmaline.exodus.net
scrappy.exodus.net
keynote1-bos.exodus.net
m-db.neo.clv.core.com
eldevelo.hq.ask.com
gibbon.stanford.EDU


*note how most of the efnet hosts seem to be in the 
same network/hostname as irc servers. 


*** Topic is : http://torn.kaapeli.net/gov.txt <- intresting 
reading


Current thread: