Re: Virgin Media Phorm Webwise Adverts [Updated: See Post No. 1, 77, 102 & 797]
"The figure shows a client process, “AutoUpdate (1620)” connecting to a remote host (207.44.186.90) via a socket whose state is “CLOSE-WAIT.” However, the pop-up information window and the packet dump window both show that data is actively crossing this “closed” connection. This behavior is reminiscent of a covert channel."
The Fink Paper (page 7) http://people.cs.vt.edu/~finkga/Rese...tal-Divide.pdf
Quote:
paladine@main:~$ nslookup bt.webwise.net
Non-authoritative answer:
Name: bt.webwise.net
Address: 207.44.186.90
Name: bt.webwise.net
Address: 88.208.248.102
Name: bt.webwise.net
Address: 88.208.250.66
Name: bt.webwise.net
Address: 88.208.250.85
|
*whistles*
|