botnet alert?

Is something wrong? Do you have any suggestions? Let us know.
Post Reply
skydyr
Oza
Posts: 2495
Joined: Wed Aug 01, 2012 8:06 am
GD Posts: 0
Universal go server handle: skydyr
Online playing schedule: When my wife is out.
Location: DC
Has thanked: 156 times
Been thanked: 436 times

botnet alert?

Post by skydyr »

Just a heads up for the admins: I'm getting an error trying to browse to life in 19x19. Our firewall is blocking the site because it thinks it is a botnet command and control server. The relevant IP is 50.62.100.1.
I'm not sure if this is a spurious error, or related to another site hosted with the same IP, or legitimate, but it may be worth looking into.
User avatar
moyoaji
Lives in sente
Posts: 773
Joined: Fri Jun 14, 2013 12:53 pm
Rank: KGS 1 kyu
GD Posts: 0
Universal go server handle: moyoaji
Location: Michigan, USA
Has thanked: 143 times
Been thanked: 218 times

Re: botnet alert?

Post by moyoaji »

Apparently, that IP address hosts over 150 different domains. Out of all of those, I wouldn't be surprised if one is not a legitimate site.

http://www.iptodomain.com/ip-50-62-100-1.php
"You have to walk before you can run. Black 1 was a walking move.
I blushed inwardly to recall the ignorant thoughts that had gone through
my mind before, when I had not realized the true worth of Black 1."

-Kageyama Toshiro on proper moves
User avatar
Jordus
Site Admin
Posts: 1125
Joined: Fri Dec 04, 2009 6:06 pm
Rank: KGS 9k
GD Posts: 0
Universal go server handle: Jordus
Location: Allegan, MI, USA
Has thanked: 16 times
Been thanked: 116 times
Contact:

Re: botnet alert?

Post by Jordus »

If you are not familiar with how IP address works it is not unheard of for one address to host multiple domains. So it would not be uncommon to get accidentally associated with something. You also run into issues with IP spoofers etc. Its not something I would personally worry about, however, what firewall are you speaking of? I can send our webhost an email to let them know whats going on. They may want to send an official heads up notice that they don't need to be doing that for all the domains associated to that IP.
I'm thinking...
skydyr
Oza
Posts: 2495
Joined: Wed Aug 01, 2012 8:06 am
GD Posts: 0
Universal go server handle: skydyr
Online playing schedule: When my wife is out.
Location: DC
Has thanked: 156 times
Been thanked: 436 times

Re: botnet alert?

Post by skydyr »

It's our corporate firewall. It's a Sonicwall (now dell) and IIRC pulls its lists from them. It seems to have resolved itself, so it may have been spuriously listed. Never hurts to check, though.
Post Reply