![]() |
2010-02-21
, 07:46
|
Posts: 26 |
Thanked: 25 times |
Joined on Jan 2010
@ USA, Maine
|
#2
|
![]() |
2010-02-21
, 08:17
|
Posts: 4 |
Thanked: 0 times |
Joined on Feb 2010
|
#3
|
![]() |
2010-02-21
, 18:34
|
Posts: 4 |
Thanked: 0 times |
Joined on Feb 2010
|
#4
|
![]() |
2010-02-21
, 19:38
|
Posts: 247 |
Thanked: 91 times |
Joined on Jan 2008
@ London/M4 Corridor
|
#5
|
![]() |
2010-02-21
, 23:12
|
Posts: 4 |
Thanked: 0 times |
Joined on Feb 2010
|
#6
|
This is my first thread, so hopefully it's in the right place. My apologies in advance if it doesn't meet criteria for posting.
I'd like to preface this comment with "I'm by no means an expert in the Maemo platform" but while in my N900 tonight, I decided to look at some of the standard sys commands and see the various output, one of which was lsof.
When looking at the output of LSOF, I noticed something that let me perplexed and a little startled. Skyhost was showing some connections to residential IPs from my phone. I originally thought it could be someone I was connected to in my user list, but I don't know anyone in the cities that are listed. Enclosed is some of my output:
skyhost 1512 user 32u IPv4 7582 TCP 172.16.1.39:61639->adsl-99-140-255-188.dsl.chcgil.sbcglobal.net:4146 (ESTABLISHED)
skyhost 1512 user 33u IPv4 9601 TCP 172.16.1.39:54667->adsl-99-141-65-59.dsl.chcgil.sbcglobal.net:64489 (ESTABLISHED)
skyhost 1512 user 34u IPv4 9602 TCP 172.16.1.39:56348->adsl-99-139-124-85.dsl.emhril.sbcglobal.net:61988 (ESTABLISHED)
skyhost 1470 user 33u IPv4 9601 TCP 172.16.1.39:54667->adsl-99-141-65-59.dsl.chcgil.sbcglobal.net:64489 (ESTABLISHED)
skyhost 1501 user 33u IPv4 9601 TCP 172.16.1.39:54667->adsl-99-141-65-59.dsl.chcgil.sbcglobal.net:64489 (ESTABLISHED)
skyhost 1502 user 33u IPv4 9601 TCP 172.16.1.39:54667->adsl-99-141-65-59.dsl.chcgil.sbcglobal.net:64489 (ESTABLISHED)
skyhost 1504 user 33u IPv4 9601 TCP 172.16.1.39:54667->adsl-99-141-65-59.dsl.chcgil.sbcglobal.net:64489 (ESTABLISHED)
skyhost 1507 user 33u IPv4 9601 TCP 172.16.1.39:54667->adsl-99-141-65-59.dsl.chcgil.sbcglobal.net:64489 (ESTABLISHED)
skyhost 1508 user 33u IPv4 9601 TCP 172.16.1.39:54667->adsl-99-141-65-59.dsl.chcgil.sbcglobal.net:64489 (ESTABLISHED)
skyhost 1510 user 33u IPv4 9601 TCP 172.16.1.39:54667->adsl-99-141-65-59.dsl.chcgil.sbcglobal.net:64489 (ESTABLISHED)
skyhost 1511 user 33u IPv4 9601 TCP 172.16.1.39:54667->adsl-99-141-65-59.dsl.chcgil.sbcglobal.net:64489 (ESTABLISHED)
skyhost 1512 user 33u IPv4 9601 TCP 172.16.1.39:54667->adsl-99-141-65-59.dsl.chcgil.sbcglobal.net:64489 (ESTABLISHED)
skyhost 1451 user 32u IPv4 7391 TCP 172.16.1.39:56832->cpe-72-230-248-72.rochester.res.rr.com:17568 (ESTABLISHED)
skyhost 1451 user 33u IPv4 9445 TCP 172.16.1.39:63008->172.16.1.41:5370 (ESTABLISHED)
All of these sessions were from different boot sequences. At first I thought, maybe these are connections to SKYPE but I highly doubt Skype is using residential machines for their infrastructure.
Here are the Maxmind results:
http://www.maxmind.com/app/locate_ip?ips=72.230.148.55
http://www.maxmind.com/app/locate_ip?ips=99.54.68.11
http://www.maxmind.com/app/locate_ip?ips=99.140.255.188
It must be noted that I don't know anyone in Rochester or Des Moines (I do outside of Houston but can't get confirmation on their IP), nor have anyone on my list that I've communicated with who could be there.
I don't know enough about the Maemo 5 platform to do a proper forensics analysis and with all of the updates that happen, it's really hard to look at binaries and see if things are not right.
Anyone have any thoughts? Maybe this is a non-issue and I'm being super paranoid...
P.S. Each IP disappeared after boot and a new random one comes up everytime.
Last edited by tylerdurden; 2010-02-21 at 18:36. Reason: Added bold tags to the title