Help - Search - Members - Calendar
Full Version: Strange Bedfellows - IP Bunkmating
B.I.S.S. Forums > Bluetack Forums > Global News
TeMerc
Posted by Jonathan Cohen on March 3, 2006 05:15 PM

(Thanks go to our tech team for spearheading this inquiry.)

QUOTE
Look around the SiteAdvisor team, and there’s always someone with a furrowed brow. We’re constantly discovering new scams and surreptitious online behavior. Today we'll explore a hosting practice we call “IP bunkmating." (Others call it “host multiplexing" or “IP sharing.")

Web sites are all stored on servers, and each server has an IP address. When more than one site is located at the same IP address, it could mean one of two things:
1) The hosting company decided not to allocate a unique address to each of their clients. (This isn’t a bad idea for many sites, and it’s required by some IP registries’ rules.)
2) One organization is running multiple sites on the same server. This is easier for them – fewer physical servers mean less to set up and less to maintain.

In the first case, there’s generally no relationship between the sites that happen to share a server. If you care to learn more about Web sites sharing IP addresses, you can read spyware researcher Ben Edelman’s related article. But in the second case, there’s an increased likelihood that sites will be similar. After all, a company with one “red" site might well have other bad business practices too, possibly extending into unrelated ventures. Below are some examples of sites we found based on their similarities with sites we already rated as red.

SiteAdvisor Blog
Moore
Yep good story , thanks Temerc. Thats how we track a lot of new malware sites down for our own lists. smile.gif Also a lot of the gangsters share the same DNS servers , but from different IPs.

I see regularly places like goddady that lump a few hundred thousand domains to one IP address, and you will find a cross selection of good and bad sites in amongst them... Can make it hard to IP block them , which is why we use both IP blocking and Hosts file blcoking for maximum effectiveness.

Atrivotech [ Atrivohell] / Intercage based in San Francisco is one prime example of how finding one site will to lead you to the bees nest of filth.. Site Advisor should have used them for their story .. they host large amounts of things like illegal child exploitation porn and malware hijackers which go largely ignored by the authorities and most other people for years now.


QUOTE
Make Us Laugh, Get A SiteAdvisor T-Shirt

We’d love to hear your own discoveries about ‘strange bedfellows’ sharing the same IP address. We'll send a SiteAdvisor t-shirt to anyone who submits an entry that makes us laugh out loud.


I posted a comment on their blog , lets see if they are interested in real research or just pretending.. If my comment doesnt show up then we will know they are only interested looking for laughs.

It's hard to take them seriously when all they want is to be entertained.
Moore
Guess they just want the laughs.. figures..
TeMerc
It never ceases to amaze me how many nasty sites are under one single IP. It's almost inviting the nasty scumbags to take advantage of that.

I'm sure this was not the original intent when IPs were set up. They should fix it, but I guess it's too late now.
firstaid
it is pretty easy to hide on an IP with 3 million sites sad.gif

How long would that take a crew to look through?

To long sad.gif

firstaid
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.
Invision Power Board © 2001-2012 Invision Power Services, Inc.