You're now on the archive server. Commenting has been disabled.

From GE Commercial Finance to Zero Hedge, With Love

Sacrilege's picture




GE Commercial Finance, Stamford Connecticut:

On behalf of the Zero Hedge staff, I want to take a minute to apologize for our filtering your 439 packets today at our firewall. It's a bit touchy, and being the keen judge of character that it is, decided it no longer had to tolerate your toxic packet underwriting. In the future, we ask that you refrain from sending innocuous requests to random ports on our boxes in search of things clearly beyond your grasp.

Further, if this is a desperate ex-girlfriend attention ploy from the likes of CNBC carried out third party: we'll kindly remind you high school is over.

tcp connect log:

07/28/2009 13:47:26 Host: 8.4.8.12/8.4.8.12 Port: 21 TCP Blocked


fw connect log:

pkts bytes target prot opt in out source destination

439 25460 DROP all -- any any 8.4.8.12 anywhere

traceroute:

16 GE-COMMERCI.hsa1.Stamford1.Level3.net (63.208.150.2) 103.728 ms !X * *




Comment viewing options

Select your preferred way to display the comments and click "Save settings" to activate your changes.
Tue, 07/28/2009 - 20:53 | Link to Comment Bearish News
Bearish News's picture

Interesting. Is there any explanation for this, other than someone within their network scanning for vulnerabilities on ZH servers?

Tue, 07/28/2009 - 20:58 | Link to Comment Sacrilege
Sacrilege's picture

There's always an explanation, it's just whether you buy it.

Wed, 07/29/2009 - 07:19 | Link to Comment Anonymous
Tue, 07/28/2009 - 23:51 | Link to Comment Anonymous
Tue, 07/28/2009 - 20:56 | Link to Comment silencedogood
silencedogood's picture

Hmm....someone trying to connect to your FTP port...wonder why?  Perhaps a means to examine the packets to determine the OS you are running?  Or try to determine the version of FTP ( I hope the hell you are running SFTP at the least!) so they can compromise it.  Or they did this to have YOU block all of their employees from seeing the truth on your website.  Perhaps opening up port 80 for all (assuming your http daemon is hardened!) so GE employees can peruse your site.  Most likely explanation is the packets were spoofed to see if you are monitoring...

-Silence

Tue, 07/28/2009 - 22:21 | Link to Comment SWRichmond
SWRichmond's picture

There are any number of progs you can run to spoof a from address probe; nmap comes to mind.

hat tip to fyodor

 

Tue, 07/28/2009 - 22:46 | Link to Comment aldousd
aldousd's picture

yeah, it's like planting evidence. scanning ports, or sending syn's though is all you can really do, unless you already own the network you're trying to attack.  if you can somehow predict the sequence numbers, you might get a connection open by blindly sending an ack with a lucky time delay, but that's as far as you'd get. you'd be hard pressed to get any response from spoofed source ips. (Though it can be done, it's not likely from a script kiddie or a person just dicking around with nmap.)

Wed, 07/29/2009 - 00:48 | Link to Comment Anonymous
Tue, 07/28/2009 - 23:58 | Link to Comment Anonymous
Tue, 07/28/2009 - 20:57 | Link to Comment texpat
texpat's picture


Just watching Beaker.

His message of hope somewhat undermined by the 'emergency liquidation' ads by auction.com in the commercial break.

None of those 5/3.5 houses at $499 will sell anywhere near that.

Hahaha, dissing the blogs now!!!!!

Tue, 07/28/2009 - 20:57 | Link to Comment Anonymous
Tue, 07/28/2009 - 21:00 | Link to Comment wheaties
wheaties's picture

It's gonna happen sooner or later.  At least it's not like wikipedia where certain entries are modified by corporate entities to reflect only a favorible faxsimile to their real selves.

Tue, 07/28/2009 - 21:01 | Link to Comment Anonymous
Wed, 07/29/2009 - 12:58 | Link to Comment Anonymous
Tue, 07/28/2009 - 21:03 | Link to Comment Anonymous
Tue, 07/28/2009 - 21:15 | Link to Comment deadhead
deadhead's picture

17651....i'm with you on this re non computer guy.....that said, I will say that there was a point today when the ZH servers were desperately slow....the first thing I wondered was if there was some kind of attack.  I'm hoping someone can at least list the various scenarios of what might have been occurring.  thanks.

Tue, 07/28/2009 - 21:26 | Link to Comment Marla Singer
Marla Singer's picture

No.  We moved from ZH1 completely.  We had to adjust the webserver settings for the increased load so things were slow for a bit this afternoon.  I'm pretty sure there wasn't any kind of attack.

Tue, 07/28/2009 - 22:08 | Link to Comment samiam6
samiam6's picture

interesting stuff, miss marla.  fyi, i was running netscape while browsing the site earlier today and, on three different attempts, it went all "not responding" on me when i tried to open the original gecc page in a new tab.  i was forced to ctrl-alt-del and start over each time.

Wed, 07/29/2009 - 01:33 | Link to Comment D.O.D.
D.O.D.'s picture

samiam6, dito, I thought it was my connection at first, but google and msn came up right away... interesting to note, at the same time this issue occured with ZH, I had the same problem with bloomberg.com, for about 5 minutes, but no other websites...peculiar indeed...

Tue, 07/28/2009 - 22:22 | Link to Comment SWRichmond
SWRichmond's picture

I was wondering about a ddos.  piss off anyone lately?

Tue, 07/28/2009 - 22:35 | Link to Comment deadhead
deadhead's picture

Thank you Marla...glad to hear that.  I was also concerned that perhaps chainey was screwing around with the computers while you and TD were out fly fishing.

Tue, 07/28/2009 - 22:39 | Link to Comment Quantum Noise
Quantum Noise's picture

Marla, that doesn't mean they were well intentioned. Maybe GECC was setting up their own geek PPT in case you guys decide at some future time to post something that might seriously harm them. For example, a DDoS attack needs to be planned well ahead as it cannot be done on the fly.

Wed, 07/29/2009 - 00:33 | Link to Comment Anonymous
Tue, 07/28/2009 - 21:17 | Link to Comment Marla Singer
Marla Singer's picture

Looks like someone over at GE Commercial Finance was trying to find the secret access numbers to our secret safe deposit box secretly containing our secret gold depository bearer certificates.  Or just looking for open services to hack browse.

Tue, 07/28/2009 - 21:21 | Link to Comment deadhead
deadhead's picture

Thank you Marla..... I hope you guys are in a position to take some action on this. 

Tue, 07/28/2009 - 23:17 | Link to Comment Arm
Arm's picture

Sure they could report a criminal complaint; this is exactly the evidence used to catch naughty 15 year olds. 

But ZH would have to put their real names and provide police access to their logs....   something tells me GE counted on that.

Wed, 07/29/2009 - 08:47 | Link to Comment aldousd
aldousd's picture

If they were trying to bait anyone on, it would have to be much more nefarious of an action than this. This is simply like 'oops, I typed the wrong ip address, and I didn't get in.' Sort of like trying to go to the wrong directory in a website by mistyping the url.  There is no way this is anywhere near qualified to be a criminal action, unless it was persistent and some other symptoms were evident.  For example, if you hit some fake website and tack on the name admin_page.php to the end of the url, the chances that you'll get anything meaningful are very slim, and that it would let you do anything if it were a real address are even slimmer. But still, there would be no grounds for a criminal charge for simply knocking on the door like that.

Wed, 07/29/2009 - 08:49 | Link to Comment aldousd
aldousd's picture

sorry to reply to my own post, but if you want another example, type ftp://whitehouse.gov into your browser's address bar. That's exactly what someone did to zerohedge.com in this example, or at least, what it could have been.  

Wed, 07/29/2009 - 00:09 | Link to Comment Anonymous
Wed, 07/29/2009 - 00:58 | Link to Comment Anonymous
Tue, 07/28/2009 - 23:29 | Link to Comment My cognitive di...
My cognitive dissonance's picture

It wasn't me, man.

I was with a buddy...er...from outta town, yeah, yeah that's right and all day too.

On a more serious note.

These Jackals seem to stop at nothing. You must be really on too something.

 

Wed, 07/29/2009 - 00:18 | Link to Comment My cognitive di...
My cognitive dissonance's picture

My bad.

What I meant to say wuz..."You must be really on something. Like, Adderall®.

How do you do it?

A friend needs to know.

Signed

MCD

 

Tue, 07/28/2009 - 21:17 | Link to Comment Anonymous
Tue, 07/28/2009 - 21:53 | Link to Comment Anonymous
Tue, 07/28/2009 - 22:00 | Link to Comment Cheeky Bastard
Cheeky Bastard's picture

it all depends if Becky Quick is on or not ... she is definitely a porn material ... the rest of them ... blah ... maybe tits Cabrera fits into that picture, but she is more of a MILF material ....

Wed, 07/29/2009 - 01:56 | Link to Comment jester
jester's picture

it all depends if Becky Quick is on or not ... she is definitely a porn material

With a name like that, how could she not be porn material?

Tue, 07/28/2009 - 21:18 | Link to Comment MinnesotaNice
MinnesotaNice's picture

Sounds like the end of the relationship between GE/CNBC and ZeroHedge is going to be rocky... appears like GE/CNBC is interested in some bad 'breakup sex' which as we all know will only lead to regrets... just move on GE/CNBC... your boyfriend has dumped you.

Tue, 07/28/2009 - 21:21 | Link to Comment Anonymous
Tue, 07/28/2009 - 21:22 | Link to Comment Anonymous
Tue, 07/28/2009 - 21:25 | Link to Comment Anonymous
Tue, 07/28/2009 - 21:26 | Link to Comment Anonymous
Tue, 07/28/2009 - 21:30 | Link to Comment Anonymous
Wed, 07/29/2009 - 00:45 | Link to Comment Anonymous
Tue, 07/28/2009 - 21:35 | Link to Comment ShankyS
ShankyS's picture

Quick idea for the ZH logo - My Cognitive has a full eclipse for photo. This would make a really cool O to put the H in. Kind of doomsdayish and end of timesish that fits the theme. IMO of course. It would make for a really cool black t-shirt with the eclipse with the H in the middle.

Tue, 07/28/2009 - 21:37 | Link to Comment Anonymous
Tue, 07/28/2009 - 21:42 | Link to Comment svendthrift
svendthrift's picture

What's calculated risk been sayin?

Tue, 07/28/2009 - 22:36 | Link to Comment Anonymous
Tue, 07/28/2009 - 22:54 | Link to Comment svendthrift
svendthrift's picture

Green shoots? That's soooo early July. Haven't we moved on? The recession is over. Green shoots are now green trees. Dow to 36,000 and all that. Fuck, I wish the smoke-shop downstairs hadn't gone bankrupt on the weekend. I'd like to celebrate our new, improved prosperity with a cigar!

Tue, 07/28/2009 - 21:43 | Link to Comment Anonymous
Tue, 07/28/2009 - 23:19 | Link to Comment Arm
Arm's picture

It's not a guy in a cubicle that is doing it.  =D

Probably some of their guys in IT with or without permission from management.   IT guys have the porn, video games and all those toys they don't let you have, on all day

Tue, 07/28/2009 - 21:46 | Link to Comment Lothar the Rott...
Lothar the Rottweiler's picture

Ugh.  I give up.  There is no reason for some stupid conflict between ZH and CR.  Both have a niche, and some of it is crossover.  How many folks here read Denninger (sp?), and others?

We're short everything, we're long everything.

I know only that it means caveat emptor, but still...

No need for this when the info battle needs to be won.  In my personal opinion, of course.

Tue, 07/28/2009 - 22:00 | Link to Comment Anonymous
Tue, 07/28/2009 - 22:38 | Link to Comment Anonymous
Tue, 07/28/2009 - 23:01 | Link to Comment Anonymous
Tue, 07/28/2009 - 23:17 | Link to Comment Anonymous
Tue, 07/28/2009 - 23:21 | Link to Comment Arm
Arm's picture

Eddie Murphy?

Tue, 07/28/2009 - 23:59 | Link to Comment Sacrilege
Sacrilege's picture

I don't really care who you are -- create a login if you wish; the features are better.

And thanks for the support!

Tue, 07/28/2009 - 23:27 | Link to Comment Anonymous
Wed, 07/29/2009 - 00:24 | Link to Comment Anonymous
Wed, 07/29/2009 - 00:45 | Link to Comment Anonymous
Tue, 07/28/2009 - 22:04 | Link to Comment guignol
guignol's picture

I wouldn't worry too much about this. Port scanning

happens everyday to almost any sight. Script kiddies looking

for easy vulnerabilities, any 5 yr old can download this stuff

from http://astalavista.box.sk/  As long as you ain't running really

old un-patched versions, you should be ok.

 

You guys rock....glad you covered your tracks:

Whois Record

Registrant:
 Arx Anstalt

 [ELIDED --- Let's not encourage them.... yes its public info but please do not discuss details of network configuration here, thanks!  -- Marla]

Tue, 07/28/2009 - 22:42 | Link to Comment deadhead
deadhead's picture

I think I went to college with an Arx Anstalt in the mid 70's.  We tripped together at a few Grateful Dead concerts. 

Tue, 07/28/2009 - 22:05 | Link to Comment Anonymous
Tue, 07/28/2009 - 22:44 | Link to Comment Quantum Noise
Quantum Noise's picture

Well, Marla needs to pay for her cigarettes somehow, don't you think?

Tue, 07/28/2009 - 22:06 | Link to Comment Anonymous
Tue, 07/28/2009 - 22:28 | Link to Comment Sacrilege
Sacrilege's picture

Very unlikely given all the information on the box.

Wed, 07/29/2009 - 00:24 | Link to Comment Sacrilege
Sacrilege's picture

Thanks!

Tue, 07/28/2009 - 22:28 | Link to Comment DebtorShredder
DebtorShredder's picture

High School is over!

What...huh...Who?

HOW COME I'M ALWAYS THE LAST TO KNOW THESE THINGS!!!

Tue, 07/28/2009 - 22:29 | Link to Comment Anonymous
Tue, 07/28/2009 - 23:14 | Link to Comment Anonymous
Tue, 07/28/2009 - 22:32 | Link to Comment Anonymous
Tue, 07/28/2009 - 22:34 | Link to Comment Anonymous
Tue, 07/28/2009 - 22:41 | Link to Comment Comrade de Chaos
Comrade de Chaos's picture

Priceless, was it the reason the loading of this site was slow this morning? And one would think that with their "imagination & innovation at work" someone would do a better job, or at least hired some Russian hackers to look clean. 

Naughty sugar high!

p.s. just saw the Moon movie, amazing it stresses how far we could go to sacrifies an idnividual (or dozen) for the "common" good of humanity, etc. Wonder, how many sacrifices our government is willing to take (almost said make, fat chance....) 

Tue, 07/28/2009 - 22:43 | Link to Comment Gilgamesh
Gilgamesh's picture

Been looking to see if anyone has torrented Moon yet, but it sounds like it might be worth the theater price for once.

Tue, 07/28/2009 - 22:56 | Link to Comment Anonymous
Tue, 07/28/2009 - 22:57 | Link to Comment Anonymous
Tue, 07/28/2009 - 23:02 | Link to Comment SDRII
SDRII's picture

TD,

Any insight into whya UBS has halted trading of leveraged ETFs? per Bloomberg

Tue, 07/28/2009 - 23:12 | Link to Comment Anonymous
Tue, 07/28/2009 - 23:24 | Link to Comment Arm
Arm's picture

Since when do banks care if you make money?

Tue, 07/28/2009 - 23:24 | Link to Comment Arm
Arm's picture

Since when do banks care if you make money?

Tue, 07/28/2009 - 23:22 | Link to Comment Anonymous
Wed, 07/29/2009 - 05:28 | Link to Comment Anonymous
Tue, 07/28/2009 - 23:25 | Link to Comment Anonymous
Tue, 07/28/2009 - 23:31 | Link to Comment kote
kote's picture

Seriously people?  First, GE's firewall would pick up a virus randomly scanning.  Second, you think GE is stupid enough to maliciously scan from a corporate IP?  You think someone within GE is stupid enough to so blatantly attempt illegal activity on their own from work?

A reader from GE was curious about the site and checked for an ftp.  Nothing to see here.

Tue, 07/28/2009 - 23:37 | Link to Comment DebtorShredder
DebtorShredder's picture

Shhhh....keep it down.

This stuff always makes for a good story. People love conflict.

Tue, 07/28/2009 - 23:41 | Link to Comment Anonymous
Wed, 07/29/2009 - 00:09 | Link to Comment Sacrilege
Sacrilege's picture

The two most probable reasons for the number of packets are simultaneous connects to multiple ports, or repeated http requests made after the fact. Both are funny.

Wed, 07/29/2009 - 00:46 | Link to Comment DebtorShredder
DebtorShredder's picture

I would delete your post. It's unnecessary information for the people.

If I understand your test, I don't like your setup.

Wed, 07/29/2009 - 13:10 | Link to Comment kote
kote's picture

So... someone tried to connect to the ftp once, and then you blocked multiple connection attempts from GE readers sharing the same NAT gateway?

Call the FBI immediately.

Wed, 07/29/2009 - 00:13 | Link to Comment Anonymous
Wed, 07/29/2009 - 05:33 | Link to Comment Anonymous
Tue, 07/28/2009 - 23:49 | Link to Comment Anonymous
Wed, 07/29/2009 - 00:13 | Link to Comment Anonymous
Wed, 07/29/2009 - 00:47 | Link to Comment channel_zero
channel_zero's picture

Why does the GE IP address trace back to a corn field in Kansas?

Because that's where the host IP is.  It's not quite that simple, but close enough. 

Wed, 07/29/2009 - 00:14 | Link to Comment Anonymous
Wed, 07/29/2009 - 00:19 | Link to Comment Anonymous
Wed, 07/29/2009 - 01:03 | Link to Comment Anonymous
Wed, 07/29/2009 - 00:19 | Link to Comment Anonymous
Wed, 07/29/2009 - 07:00 | Link to Comment Arm
Arm's picture

Deleted

Wed, 07/29/2009 - 00:19 | Link to Comment Anonymous
Wed, 07/29/2009 - 00:35 | Link to Comment Anonymous
Wed, 07/29/2009 - 00:42 | Link to Comment channel_zero
channel_zero's picture

TD, please don't run another story like this.  It's foolish.

Some PC tries to connect to 21 and it's satan coming to shut the site down. 

Please move along.  Nothing  to see here.

However, your admin is one of a very small number people who *actually* check their logs.  Boring as hell, but worth a once-over.

Wed, 07/29/2009 - 00:50 | Link to Comment Anonymous
Wed, 07/29/2009 - 00:53 | Link to Comment Anonymous
Wed, 07/29/2009 - 01:14 | Link to Comment mark mchugh
mark mchugh's picture

Just FYI - I was unable to connect to ZH this morning (10:00 AM????)

 

Wed, 07/29/2009 - 01:38 | Link to Comment D.O.D.
D.O.D.'s picture

It seems odd that someone with the wherewithal to "ring the back door bell", would be foolish enough to not ping off of an anonymous IP... either they wanted you to know it was them, or someone else wanted you to think it was them...

Either way, seems like project mayhem is going exactly as planned sir...

Wed, 07/29/2009 - 02:04 | Link to Comment russell
russell's picture

Probably some entry-level unix admin playing games while his co-workers smoke cigarettes:

JerkoffShell@GenitalElectric.cpff.tlgp%man nmap|grep amateur

No manual entry for Fuck You Keith Olbermann

Wed, 07/29/2009 - 05:37 | Link to Comment Eagle
Eagle's picture

Those were flash packets. They wanted to detect what the new articles were before they were posted, so rebuttals would be instantly available.

Wed, 07/29/2009 - 06:36 | Link to Comment silencedogood
silencedogood's picture

Tyler/Marla,

One of the hats I wear is as a high level Info Sec kinda guy.  I have no doubt YOU know this but for the rest of the IT neophytes out there to 'prove' the packets came from GE, you would damn near have to get logs (via court orders) and collected in a secure manner of every device and up to including the external gateway routers of GE.  Moreover, with this you MIGHT get a court order demanding GE's logs.  They have good attorneys, good luck there.  Additionally, the state wont do this so this would have to be a federal investigation.  OH, did I mention that the servers would most likely have to be in the US for the FBI's NIPC to investigate and over $5,000 in lost "value"...and more likely a minimum of $10,000 and certain pre-reqs must be met.  Did you have a AUP...blah blah kinda stuff but if you don't have disclaimers (including ones if folks try to login via FTP, ...etc) then they won't take the case either.  My STRONG guess is this is someone who spoofed GE's IP address, did a port scan on your servers just to fuck with you.  Now these folks know you can detect port scans.  Let me tell you...IF THEY WANT IN THEY WILL GET IN.  Unless you have a team of highly skilled blue and red teams to not only test your servers but to protect them 24/7 a highly skilled cracker will blow right thru your security.  To counter this ensure that you continue keeping your servers redundant, and ensure to have round robin DNS with many servers to help kills DDOS attacks.  If you have control over your border routers you can quickly block DDOS attacks at the gateway vs having to do anything crazy with your webserver.    Now what do YOU have Corporate Crackers or very motivated government crackers (THEY EXIST!!)..I would argue it is NOT your shopping cart as that is small time game and that isn't even processed by you.  WHAT YOU POTENTIALLY HAVE are IP addresses of annonymous AND pseudononymous posters.  Your webserver as do your border routers tends to log (via RDNS)  this data to your web server and other network device log files.  By getting this data,  information can be gleaned to determine not only WHO YOU ARE but everyone else here that sends e-mail to or thru your SMTP/POP servers and/or visits or posts on your site.  I would ensure your techno geeks know to sanitize (or securely encrypts!)  all server/router IP addy visit logs, sanitizes (or securely encrypts!) your e-mail logs...etc.  Those are what a corporate or government cracker would want.  The fact they did this and YOU CAUGHT THEM means it could have been a test OR most likely some stupid script kiddie playing with software on mommy and daddys computer checking to see if they can mess with your heads.  They did just that...  Just my 2 cents...

-Silence

Wed, 07/29/2009 - 08:37 | Link to Comment Miles Kendig
Miles Kendig's picture

Copper in both respects...

Wed, 07/29/2009 - 10:10 | Link to Comment deadhead
deadhead's picture

thank you for taking the time to write about this Silence.  I'm one of the IT neophytes and appreciate the explanation.

I hope that the government gets my emails to ZH as they will shudder when they discover what an important person I am (lol!).

 

 

 

Thu, 07/30/2009 - 01:10 | Link to Comment spud
spud's picture

I'm not so sure proving they're GE is paramount, it's just kinda fun enough to assume they are (based on effort expended to hide simple port scan vs. risk of action by zh to authenticate vs. gain of spoofing GE's router).

> Let me tell you...IF THEY WANT IN THEY WILL GET IN.

I dunno, zero day today does have meaning, but call me a betting man to say roo^h^h^hSacrilege is on his game and knows a port scan when he sees one.

Pressed, if you were "high level Info Sec kinda guy" you'd know better (*cough* dmca *cough*) than to flap in caps about their setup, risks, etc.

When ankle bitin' port scans register in (never mind mess with) the BOFH cranium, I'll give up on learning *nix.

Wed, 07/29/2009 - 08:06 | Link to Comment Miles Kendig
Miles Kendig's picture

Layne would sing; Again.

Wed, 07/29/2009 - 08:38 | Link to Comment Anonymous
Wed, 07/29/2009 - 10:01 | Link to Comment Anonymous
Wed, 07/29/2009 - 12:10 | Link to Comment Anonymous
Wed, 07/29/2009 - 13:07 | Link to Comment Anonymous
Wed, 07/29/2009 - 15:13 | Link to Comment Anonymous
Wed, 07/29/2009 - 15:39 | Link to Comment Anonymous
Wed, 07/29/2009 - 16:38 | Link to Comment Anonymous
Do NOT follow this link or you will be banned from the site!