North American Network Operators Group

Date Prev | Date Next | Date Index | Thread Index | Author Index | Historical

Re: the Intercage mess

  • From: Paul Ferguson
  • Date: Thu Sep 25 02:46:19 2008

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

On Wed, Sep 24, 2008 at 10:45 PM, Paul Ferguson <[email protected]>
wrote:


>>> Why is Intercage hosting Cernel.net?
>>>
>>> cernel.net -A-> 69.50.176.227
>>>
>>> AS      | IP               | AS Name
>>> 27595   | 69.50.176.227    | INTERCAGE - InterCage, Inc.
>>>
>>> I guess this was just a mistake, right?
>>>
>>> Oh, and of course, Cernel.net was registered with... wait for it...
>>> Estdoamins.
>>>
>>> And this was very recent.
>>>
>>> Go figure.
>>>
>>
>> A bit more:
>>
>> A glance at DNS relationships between Intercage, Cernel, and Rove
>> Digital are apparent when digging around on DNS dependencies -- lookup
>> cernel.net at the BFK DNSLogger:
>>
>> http://www.bfk.de/bfk_dnslogger.html
>>
>> ns2.protectdetails.com   A      69.50.176.229
>> ns1.esthost.com  A      69.50.176.229
>> ens1.esthost.com         A      69.50.176.229
>> ns2.esthost.com  A      69.50.176.229
>> ns2.cernel.net   A      69.50.176.229
>>
>> AS      | IP               | AS Name
>> 27595   | 69.50.176.229    | INTERCAGE - InterCage, Inc.
>>
>
>
> Oops. I forgot to add:
>
> ns2.spb-traffic.com      A      69.50.176.227
> ns2.site-people.com      A      69.50.176.227
> ns2.estsecure.com        A      69.50.176.227
> rovedigital.com  A      69.50.176.227
> ns2.rovedigital.com      A      69.50.176.227
> ans2.rovedigital.com     A      69.50.176.227
> dev.rovedigital.com      A      69.50.176.227
> ns2.mega-all.com         A      69.50.176.227
> ns2.cernel.net   A      69.50.176.227
> alpha.cernel.net         A      69.50.176.227
> beta.cernel.net  A      69.50.176.227
>

Just in case anyone needs a refresher on Rove Digital:

http://voices.washingtonpost.com/securityfix/2008/09/estdomains_a_sordid_hi
story_an.html

- - ferg

-----BEGIN PGP SIGNATURE-----
Version: PGP Desktop 9.6.3 (Build 3017)

wj8DBQFI2zOrq1pz9mNUZTMRAmjeAKDrsXVJuhk1Um8/92cjg51xDUrXOACeJlC0
7rhjnPNtWrPNPEFR+vG4i+k=
=SMP+
-----END PGP SIGNATURE-----

-- 
"Fergie", a.k.a. Paul Ferguson
 Engineering Architecture for the Internet
 fergdawgster(at)gmail.com
 ferg's tech blog: http://fergdawg.blogspot.com/