<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
		>
<channel>
	<title>Comments for This Way Up, Seattle, Washington.</title>
	<atom:link href="http://thiswayupseattle.wordpress.com/comments/feed/" rel="self" type="application/rss+xml" />
	<link>http://thiswayupseattle.wordpress.com</link>
	<description>It&#039;s Not Just About Housing or Shelter, It&#039;s About People!</description>
	<lastBuildDate>Fri, 10 Sep 2010 05:26:26 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
	<item>
		<title>Comment on Tim Harris Speaks of Revolution by stuartbramhall</title>
		<link>http://thiswayupseattle.wordpress.com/2010/09/09/tim-harris-speaks-of-revolution/#comment-260</link>
		<dc:creator><![CDATA[stuartbramhall]]></dc:creator>
		<pubDate>Fri, 10 Sep 2010 05:26:26 +0000</pubDate>
		<guid isPermaLink="false">http://thiswayupseattle.org/?p=7244#comment-260</guid>
		<description><![CDATA[You left out the assassination in Seattle in 1981 of the Filipino organizers for the cannery workers union Domingo and Viernes. The assassination was organized jointly by the FBI and Marcos agents. The Committee for Justice for Domingo and Viernes sued the US government and during discovery, uncovered documents revealing that the FBI had infiltrated the union and essentially orchestrated the assassination - though Marcos agents filed the actual shots. As in the case of the assassination of Black Panther leader Fred Hampton, the US government quietly settled with the families rather than allowing it to go to court.

I write about this and my own close encounter with the seamier side of US intelligence (related to 30 years of grassroots political organizing in Seattle between 1983 and 2002) in my recent memoir: THE MOST REVOLUTIONARY ACT: MEMOIR OF AN AMERICAN REFUGEE (www.stuartbramhall.com). I currently live in exile in New Zealand.]]></description>
		<content:encoded><![CDATA[<p>You left out the assassination in Seattle in 1981 of the Filipino organizers for the cannery workers union Domingo and Viernes. The assassination was organized jointly by the FBI and Marcos agents. The Committee for Justice for Domingo and Viernes sued the US government and during discovery, uncovered documents revealing that the FBI had infiltrated the union and essentially orchestrated the assassination &#8211; though Marcos agents filed the actual shots. As in the case of the assassination of Black Panther leader Fred Hampton, the US government quietly settled with the families rather than allowing it to go to court.</p>
<p>I write about this and my own close encounter with the seamier side of US intelligence (related to 30 years of grassroots political organizing in Seattle between 1983 and 2002) in my recent memoir: THE MOST REVOLUTIONARY ACT: MEMOIR OF AN AMERICAN REFUGEE (www.stuartbramhall.com). I currently live in exile in New Zealand.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Sociopaths of US and World History by Flash</title>
		<link>http://thiswayupseattle.wordpress.com/2008/10/27/sociopaths-of-us-and-world-history/#comment-259</link>
		<dc:creator><![CDATA[Flash]]></dc:creator>
		<pubDate>Tue, 08 Jun 2010 16:23:20 +0000</pubDate>
		<guid isPermaLink="false">http://thiswayupseattle.wordpress.com/?p=550#comment-259</guid>
		<description><![CDATA[But from time to time I have be stricken to allow that the fit domain is an enigma, a innocuous poser that is made rueful on our own fuming assault to spell out it as allowing it had an underlying truth.]]></description>
		<content:encoded><![CDATA[<p>But from time to time I have be stricken to allow that the fit domain is an enigma, a innocuous poser that is made rueful on our own fuming assault to spell out it as allowing it had an underlying truth.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Ten Cars to Live in After Your Home Gets Repossessed! by Всеволод Кузьмичев</title>
		<link>http://thiswayupseattle.wordpress.com/2008/10/24/ten-cars-to-live-in-after-your-home-gets-reposessed/#comment-248</link>
		<dc:creator><![CDATA[Всеволод Кузьмичев]]></dc:creator>
		<pubDate>Wed, 21 Apr 2010 06:48:22 +0000</pubDate>
		<guid isPermaLink="false">http://thiswayupseattle.wordpress.com/?p=426#comment-248</guid>
		<description><![CDATA[Как всегда просто супер обьёмная статья и как всегда дочитал до конца :)]]></description>
		<content:encoded><![CDATA[<p>Как всегда просто супер обьёмная статья и как всегда дочитал до конца <img src='http://s0.wp.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Homelessness in the World-Part 1 by Naresh Rupani</title>
		<link>http://thiswayupseattle.wordpress.com/2009/07/26/homelessness-in-the-world-part-1/#comment-245</link>
		<dc:creator><![CDATA[Naresh Rupani]]></dc:creator>
		<pubDate>Thu, 04 Feb 2010 20:39:18 +0000</pubDate>
		<guid isPermaLink="false">http://thiswayupseattle.wordpress.com/?p=3274#comment-245</guid>
		<description><![CDATA[Helping someone is helping yourself. If I visit America someday will definately do something for the homeless children. JAI SHANI DEV]]></description>
		<content:encoded><![CDATA[<p>Helping someone is helping yourself. If I visit America someday will definately do something for the homeless children. JAI SHANI DEV</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Law Students Think Civil Justice System is Important by DougEvova</title>
		<link>http://thiswayupseattle.wordpress.com/2009/02/11/law-students-think-civil-justice-system-is-important/#comment-242</link>
		<dc:creator><![CDATA[DougEvova]]></dc:creator>
		<pubDate>Fri, 01 Jan 2010 22:51:17 +0000</pubDate>
		<guid isPermaLink="false">http://thiswayupseattle.wordpress.com/?p=2561#comment-242</guid>
		<description><![CDATA[Unadulterated words, some truthful words man. Thx for makin my day.]]></description>
		<content:encoded><![CDATA[<p>Unadulterated words, some truthful words man. Thx for makin my day.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on A Sociopath by Федор</title>
		<link>http://thiswayupseattle.wordpress.com/2009/04/30/a-sociopath/#comment-241</link>
		<dc:creator><![CDATA[Федор]]></dc:creator>
		<pubDate>Mon, 28 Dec 2009 00:08:12 +0000</pubDate>
		<guid isPermaLink="false">http://thiswayupseattle.wordpress.com/?p=3002#comment-241</guid>
		<description><![CDATA[Увлекательно написано. Практически за душу берет, ну и заставляет поразмышлять над собственным блогом.]]></description>
		<content:encoded><![CDATA[<p>Увлекательно написано. Практически за душу берет, ну и заставляет поразмышлять над собственным блогом.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Law Students Think Civil Justice System is Important by 100 Best Blogs for Law School Students &#124; Online Schools</title>
		<link>http://thiswayupseattle.wordpress.com/2009/02/11/law-students-think-civil-justice-system-is-important/#comment-238</link>
		<dc:creator><![CDATA[100 Best Blogs for Law School Students &#124; Online Schools]]></dc:creator>
		<pubDate>Wed, 25 Nov 2009 19:33:12 +0000</pubDate>
		<guid isPermaLink="false">http://thiswayupseattle.wordpress.com/?p=2561#comment-238</guid>
		<description><![CDATA[[...] This Way Up: From a student at the University of Washington, Seattle, this blogger writers about being an advocate while still in school. [...]]]></description>
		<content:encoded><![CDATA[<p>[...] This Way Up: From a student at the University of Washington, Seattle, this blogger writers about being an advocate while still in school. [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Law Students Think Civil Justice System is Important by Audrey</title>
		<link>http://thiswayupseattle.wordpress.com/2009/02/11/law-students-think-civil-justice-system-is-important/#comment-235</link>
		<dc:creator><![CDATA[Audrey]]></dc:creator>
		<pubDate>Mon, 12 Oct 2009 12:21:05 +0000</pubDate>
		<guid isPermaLink="false">http://thiswayupseattle.wordpress.com/?p=2561#comment-235</guid>
		<description><![CDATA[HELLO]]></description>
		<content:encoded><![CDATA[<p>HELLO</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Sociopaths of US and World History by Bill Bartmann</title>
		<link>http://thiswayupseattle.wordpress.com/2008/10/27/sociopaths-of-us-and-world-history/#comment-232</link>
		<dc:creator><![CDATA[Bill Bartmann]]></dc:creator>
		<pubDate>Fri, 18 Sep 2009 07:18:23 +0000</pubDate>
		<guid isPermaLink="false">http://thiswayupseattle.wordpress.com/?p=550#comment-232</guid>
		<description><![CDATA[Cool site, love the info.  I do a lot of research online on a daily basis and for the most part, people lack substance but, I just wanted to make a quick comment to say I&#039;m glad I found your blog.  Thanks,

A definite great read...:)

&lt;a href=&quot;http://wiki.jfrog.org/confluence/display/~bill-bartmann&quot; rel=&quot;nofollow&quot;&gt;-Bill-Bartmann&lt;/a&gt;]]></description>
		<content:encoded><![CDATA[<p>Cool site, love the info.  I do a lot of research online on a daily basis and for the most part, people lack substance but, I just wanted to make a quick comment to say I&#8217;m glad I found your blog.  Thanks,</p>
<p>A definite great read&#8230;:)</p>
<p><a href="http://wiki.jfrog.org/confluence/display/~bill-bartmann" rel="nofollow">-Bill-Bartmann</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Ahhhh! by fkdupdad</title>
		<link>http://thiswayupseattle.wordpress.com/2009/07/18/ahhhh/#comment-230</link>
		<dc:creator><![CDATA[fkdupdad]]></dc:creator>
		<pubDate>Mon, 20 Jul 2009 21:09:35 +0000</pubDate>
		<guid isPermaLink="false">http://thiswayupseattle.wordpress.com/?p=3173#comment-230</guid>
		<description><![CDATA[cute!]]></description>
		<content:encoded><![CDATA[<p>cute!</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Arcata Cops Gone Wild by Dignity Advocate</title>
		<link>http://thiswayupseattle.wordpress.com/2009/06/13/arcata-cops-gone-wild/#comment-228</link>
		<dc:creator><![CDATA[Dignity Advocate]]></dc:creator>
		<pubDate>Tue, 07 Jul 2009 07:14:57 +0000</pubDate>
		<guid isPermaLink="false">http://thiswayupseattle.wordpress.com/?p=3089#comment-228</guid>
		<description><![CDATA[Dear This Way Up,

Stories like this get me so riled up! 

We have a major problem here in Portland too -- having to do with the criminalization of homelessness (with anti-camping law here, etc.), and this helps reinforce attitudes among some bullying cops here that &#039;the homeless got it comin.&#039;

Glad for your writing here. The poorest of the poor need defenders daily! They also need housing and green work opportunities!
 
Dave
http://dignityadvocate.wordpress.com/]]></description>
		<content:encoded><![CDATA[<p>Dear This Way Up,</p>
<p>Stories like this get me so riled up! </p>
<p>We have a major problem here in Portland too &#8212; having to do with the criminalization of homelessness (with anti-camping law here, etc.), and this helps reinforce attitudes among some bullying cops here that &#8216;the homeless got it comin.&#8217;</p>
<p>Glad for your writing here. The poorest of the poor need defenders daily! They also need housing and green work opportunities!</p>
<p>Dave<br />
<a href="http://dignityadvocate.wordpress.com/" rel="nofollow">http://dignityadvocate.wordpress.com/</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Syn-Tax or Sin Tax by constituant</title>
		<link>http://thiswayupseattle.wordpress.com/2009/03/19/syn-tax-or-sin-tax/#comment-219</link>
		<dc:creator><![CDATA[constituant]]></dc:creator>
		<pubDate>Wed, 08 Apr 2009 21:42:37 +0000</pubDate>
		<guid isPermaLink="false">http://thiswayupseattle.wordpress.com/?p=2744#comment-219</guid>
		<description><![CDATA[I&#039;m just beginning to research the history or development of the sin-tax. My question is where&#039;s the cap on this tax?! I also would like to see some financial&#039;s for the $ the state has and will receive. I&#039;ll continue looking.  I also want to know what can be done, legally, against the state for this outrageous and very discriminatory tax. Thanks!]]></description>
		<content:encoded><![CDATA[<p>I&#8217;m just beginning to research the history or development of the sin-tax. My question is where&#8217;s the cap on this tax?! I also would like to see some financial&#8217;s for the $ the state has and will receive. I&#8217;ll continue looking.  I also want to know what can be done, legally, against the state for this outrageous and very discriminatory tax. Thanks!</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Sacramento tent city is just one of dozens in an ailing America by llabesab</title>
		<link>http://thiswayupseattle.wordpress.com/2009/03/13/sacramento-tent-city-is-just-one-of-dozens-in-an-ailing-america/#comment-213</link>
		<dc:creator><![CDATA[llabesab]]></dc:creator>
		<pubDate>Wed, 18 Mar 2009 05:49:34 +0000</pubDate>
		<guid isPermaLink="false">http://thiswayupseattle.wordpress.com/2009/03/13/sacramento-tent-city-is-just-one-of-dozens-in-an-ailing-america/#comment-213</guid>
		<description><![CDATA[MICHELLE MUST EAT LOTS OF PROTEIN AND MAY EVEN FOLLOW AN &quot;A-ROD&quot; DIET.  HAVE YOU CHECKED OUT THOSE BICEPS, DELTOIDS, LATTISIMI, AND TRAPEZOIDS.  CHARLES ATLAS!  WHERE ARE YOU WHEN WE NEED YOU??

IF I WERE THE ANOINTED ONE, I WOULD SEND MICHELLE TO HAVE A &quot;WOMAN-TO-WOMAN&quot; TALK WITH NANCY PELOSI IN A SHED.  THEY WOULD NEED TH MEDICS TO CARRY NANCY ON THAT AIR FORCE JET SHE TAKES TO MEXIFORNIA!!]]></description>
		<content:encoded><![CDATA[<p>MICHELLE MUST EAT LOTS OF PROTEIN AND MAY EVEN FOLLOW AN &#8220;A-ROD&#8221; DIET.  HAVE YOU CHECKED OUT THOSE BICEPS, DELTOIDS, LATTISIMI, AND TRAPEZOIDS.  CHARLES ATLAS!  WHERE ARE YOU WHEN WE NEED YOU??</p>
<p>IF I WERE THE ANOINTED ONE, I WOULD SEND MICHELLE TO HAVE A &#8220;WOMAN-TO-WOMAN&#8221; TALK WITH NANCY PELOSI IN A SHED.  THEY WOULD NEED TH MEDICS TO CARRY NANCY ON THAT AIR FORCE JET SHE TAKES TO MEXIFORNIA!!</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Example to be made from Harassment by trackthehack</title>
		<link>http://thiswayupseattle.wordpress.com/2008/11/23/example-to-be-made-from-harasment/#comment-47</link>
		<dc:creator><![CDATA[trackthehack]]></dc:creator>
		<pubDate>Mon, 24 Nov 2008 11:53:06 +0000</pubDate>
		<guid isPermaLink="false">http://thiswayupseattle.wordpress.com/?p=1523#comment-47</guid>
		<description><![CDATA[Yeah...  218.23.53.228 tried to get in my stuff.  My computer was compromised recently and I had to remove it... Scarry stuff, I have spent the last couple days changing all my passwords and working from another computer.  I am become more aware of these threats and do not like it. 

One other thing... immediately after the attempt was blocked several other IP addresses sent various different requests to the destination computer.  I am taking this seriously and have locked down my computer, using firefox, script controll now and only reputable sights on the computer as if they compromised my acounts I would not be liking it.

SiteTheory had this to say about the IP:

Analysis: Possible MS Baster or various other Worm Attack

06:12:16 Host: 2.b2.374a.static.theplanet.com/74.55.178.2
         Port: 1433 TCP Blocked
         Analysis: Probable Scan for MS SQL Server - Most likely malicious
_____________________________

SANS institute says about the IP listed above:  see detailed sans results below my ZoneAlarm output.

Reports: 	91384 (how many people have reported it.

Targets: 	55345

That is how I found this forum, after googling a firewall blocked attempt on my computer.  Read all this as the most interesting information did not come from zone alarm...

I searched the net for the IP address and came up with the info below the zonealarm report.  Here is the search string.  Please not that I have replaced the whois email address with &quot;xxx&quot; so that these entities are not spammed though if yo want to see the data just follow think.

http://www.google.com/search?hl=en&amp;q=218.23.53.228&amp;btnG=Search

ZoneAlarm blocked and provided the following information

11-22-2008 Firewall TCP (Flag:S) Source 218.23.53.228 (TCP Port 6000) to 76.22.58.xxx (TCP Port 2967) was blocked medium

ZoneAlarm Security Suite has blocked access to port 2967 on your computer

ZoneAlarm Security Suite has successfully stopped local network or Internet traffic from reaching your computer. No breach in your security has occurred. Your computer is safe.
	
What happened?	
	
ZoneAlarm Security Suite blocked traffic to port 2967 on your machine from port 6000 on a remote computer whose IP address is 218.23.53.228. This communication attempt may have been a port scan, or simply one of the millions of unsolicited commercial or network control messages that are routinely sent out over the Internet. Such unsolicited messages are often called Internet background noise.	
		
Should I be concerned?	
		
This alert should not be a cause for concern. ZoneAlarm Security Suite has protected your machine according to the firewall settings you have selected.
	
What should I do?	
	
You do not need to do anything about this alert unless one of your programs is not functioning correctly or is unable to complete a task. In that case, you can temporarily lower your security level to medium to allow traffic to reach your computer. . Additional Program configuration options can be found in the help files.

he most common cause of this alert is that ZoneAlarm Security Suite may not be configured properly to allow traffic through the firewall. Please refer to the help files for information on configuring programs to function correctly with ZoneAlarm Security Suite. Possible explanations for the alert include:

    * The communication may have been a legitimate attempt by your ISP, a mail server, or another service attempting to authenticate your IP address or host name.

    * The ZoneAlarm Security Suite Internet Lock may be engaged

    * There may be excessive network congestion or other network problems that prevent information from being transmitted completely and correctly.

Details about 218.23.53.228, the IP address of the computer that caused the alert you received from ZoneAlarm Security Suite, are provided in the Whois report below. The information in the Whois report comes from the Regional Internet Registry (RIR) for the region where 218.23.53.228 is located: ARIN, RIPE, LACNIC or APNIC. The name of the RIR appears in the Whois report.

The Whois report includes the name, address and contact information for the Internet Service Provider (ISP) that administers the block of IP addresses that contains 218.23.53.228. The report probably does not list the administrator of the specific computer at IP address 218.23.53.228.

You should not assume that individuals listed in this report are responsible for the alert you received on your computer.

Whois Information	
	
		

% [whois.apnic.net node-2]
% Whois data copyright terms    http://www.apnic.net/db/dbcopyright.html

inetnum:      218.22.0.0 - 218.23.255.255
netname:      CHINANET-AH
country:      CN
descr:        CHINANET Anhui province network
descr:        Data Communication Division
descr:        China Telecom
admin-c:      CH93-AP
tech-c:       AT318-AP
status:       ALLOCATED PORTABLE
mnt-by:       APNIC-HM
mnt-lower:    MAINT-CHINANET-AH
changed:    xxx@apnic.net 20060322
source:       APNIC

role:         ANHUI TELECOM
address:      305 Changjiang West Road
address:      Hefei Anhui China
country:      CN
phone:        +86 0551 5185089
fax-no:       +86 0551 5185500
e-mail:       xxx@anhuitelecom.com
trouble:      send spam reports to xxx@ah163.com
trouble:      and abuse reports to xxx@ah163.com
trouble:      Please include detailed information and
trouble:      times in GMT+8:00
admin-c:      LW604-AP
tech-c:       LW604-AP
nic-hdl:      AT318-AP
remarks:      http://www.ah163.net
notify:       wxxx@anhuitelecom.com
mnt-by:       MAINT-CHINANET-AH
changed:      xxx@anhuitelecom.com 20060323
source:       APNIC

person:       Chinanet Hostmaster
nic-hdl:      CH93-AP
e-mail:       xxx@ns.chinanet.cn.net
address:      No.31 ,jingrong street,beijing
address:      100032
phone:        +86-10-58501724
fax-no:       +86-10-58501724
country:      CN
changed:      xxx@cndata.com 20070416
mnt-by:       MAINT-CHINANET
source:       APNIC

*****One of the Search Results was from SANS to which I have provided the link... and results below....

http://isc.sans.org/ipinfo.html?ip=218.023.053.228

IP Info (218.23.53.228)
IP Address (click for more detail): 	218.23.53.228
Hostname: 	218.23.53.228
Country: 	CN
AS: 	4134
AS Name: 	CHINANET-BACKBONE No.31,Jin-rong Street
Reports: 	91384
Targets: 	55345
First Reported: 	2008-08-04
Most Recent Report: 	2008-11-24
Comment: 	- none -

Note: This data is updated periodially. In order to refresh the data, click here. Not all source IPs in our database are &quot;attackers&quot;. There are a few common false positives. For example, hosts that participate in P2P networks, mail servers and DNS servers are some of the most common issues. You can see more details if you click on the number of reports. This may allow you to conclude if a host is a false positive or not.
Whois Info

[Querying whois.apnic.net]
[whois.apnic.net]
% [whois.apnic.net node-2]
% Whois data copyright terms    http://www.apnic.net/db/dbcopyright.html

inetnum:      218.22.0.0 - 218.23.255.255
netname:      CHINANET-AH
country:      CN
descr:        CHINANET Anhui province network
descr:        Data Communication Division
descr:        China Telecom
admin-c:      CH93-AP
tech-c:       AT318-AP
status:       ALLOCATED PORTABLE
mnt-by:       APNIC-HM
mnt-lower:    MAINT-CHINANET-AH
changed:      xxx@apnic.net 20060322
source:       APNIC

role:         ANHUI TELECOM
address:      305 Changjiang West Road
address:      Hefei Anhui China
country:      CN
phone:        +86 0551 5185089
fax-no:       +86 0551 5185500
e-mail:       xxx@anhuitelecom.com
trouble:      send spam reports to xxx@ah163.com
trouble:      and abuse reports to xxx@ah163.com
trouble:      Please include detailed information and
trouble:      times in GMT+8:00
admin-c:      LW604-AP
tech-c:       LW604-AP
nic-hdl:      AT318-AP
remarks:      http://www.ah163.net
notify:       xxx@anhuitelecom.com
mnt-by:       MAINT-CHINANET-AH
changed:      xxxx@anhuitelecom.com 20060323
source:       APNIC

person:       Chinanet Hostmaster
nic-hdl:      CH93-AP
e-mail:       xxx@ns.chinanet.cn.net
address:      No.31 ,jingrong street,beijing
address:      100032
phone:        +86-10-58501724
fax-no:       +86-10-58501724
country:      CN
changed:     xxxy@cndata.com 20070416
mnt-by:       MAINT-CHINANET
source:       APNIC


http://sitetheory.com/index.php?m=portsentry

Beginning 11/12/2008
13:50:20 Host: 228.53.23.218.broad.static.hf.ah.cndata.com/218.23.53.228
         Port: 2967 TCP Blocked
         Analysis: Stack-based buffer overflow in Symantec Antivirus
10:24:49 Host: adsl-074-172-016-248.sip.asm.bellsouth.net/74.172.16.248
         Port: 135 TCP Blocked
       
  Analysis: Possible MS Baster or various other Worm Attack
06:12:16 Host: 2.b2.374a.static.theplanet.com/74.55.178.2
         Port: 1433 TCP Blocked
         Analysis: Probable Scan for MS SQL Server - Most likely malicious]]></description>
		<content:encoded><![CDATA[<p>Yeah&#8230;  218.23.53.228 tried to get in my stuff.  My computer was compromised recently and I had to remove it&#8230; Scarry stuff, I have spent the last couple days changing all my passwords and working from another computer.  I am become more aware of these threats and do not like it. </p>
<p>One other thing&#8230; immediately after the attempt was blocked several other IP addresses sent various different requests to the destination computer.  I am taking this seriously and have locked down my computer, using firefox, script controll now and only reputable sights on the computer as if they compromised my acounts I would not be liking it.</p>
<p>SiteTheory had this to say about the IP:</p>
<p>Analysis: Possible MS Baster or various other Worm Attack</p>
<p>06:12:16 Host: 2.b2.374a.static.theplanet.com/74.55.178.2<br />
         Port: 1433 TCP Blocked<br />
         Analysis: Probable Scan for MS SQL Server &#8211; Most likely malicious<br />
_____________________________</p>
<p>SANS institute says about the IP listed above:  see detailed sans results below my ZoneAlarm output.</p>
<p>Reports: 	91384 (how many people have reported it.</p>
<p>Targets: 	55345</p>
<p>That is how I found this forum, after googling a firewall blocked attempt on my computer.  Read all this as the most interesting information did not come from zone alarm&#8230;</p>
<p>I searched the net for the IP address and came up with the info below the zonealarm report.  Here is the search string.  Please not that I have replaced the whois email address with &#8220;xxx&#8221; so that these entities are not spammed though if yo want to see the data just follow think.</p>
<p><a href="http://www.google.com/search?hl=en&#038;q=218.23.53.228&#038;btnG=Search" rel="nofollow">http://www.google.com/search?hl=en&#038;q=218.23.53.228&#038;btnG=Search</a></p>
<p>ZoneAlarm blocked and provided the following information</p>
<p>11-22-2008 Firewall TCP (Flag:S) Source 218.23.53.228 (TCP Port 6000) to 76.22.58.xxx (TCP Port 2967) was blocked medium</p>
<p>ZoneAlarm Security Suite has blocked access to port 2967 on your computer</p>
<p>ZoneAlarm Security Suite has successfully stopped local network or Internet traffic from reaching your computer. No breach in your security has occurred. Your computer is safe.</p>
<p>What happened?	</p>
<p>ZoneAlarm Security Suite blocked traffic to port 2967 on your machine from port 6000 on a remote computer whose IP address is 218.23.53.228. This communication attempt may have been a port scan, or simply one of the millions of unsolicited commercial or network control messages that are routinely sent out over the Internet. Such unsolicited messages are often called Internet background noise.	</p>
<p>Should I be concerned?	</p>
<p>This alert should not be a cause for concern. ZoneAlarm Security Suite has protected your machine according to the firewall settings you have selected.</p>
<p>What should I do?	</p>
<p>You do not need to do anything about this alert unless one of your programs is not functioning correctly or is unable to complete a task. In that case, you can temporarily lower your security level to medium to allow traffic to reach your computer. . Additional Program configuration options can be found in the help files.</p>
<p>he most common cause of this alert is that ZoneAlarm Security Suite may not be configured properly to allow traffic through the firewall. Please refer to the help files for information on configuring programs to function correctly with ZoneAlarm Security Suite. Possible explanations for the alert include:</p>
<p>    * The communication may have been a legitimate attempt by your ISP, a mail server, or another service attempting to authenticate your IP address or host name.</p>
<p>    * The ZoneAlarm Security Suite Internet Lock may be engaged</p>
<p>    * There may be excessive network congestion or other network problems that prevent information from being transmitted completely and correctly.</p>
<p>Details about 218.23.53.228, the IP address of the computer that caused the alert you received from ZoneAlarm Security Suite, are provided in the Whois report below. The information in the Whois report comes from the Regional Internet Registry (RIR) for the region where 218.23.53.228 is located: ARIN, RIPE, LACNIC or APNIC. The name of the RIR appears in the Whois report.</p>
<p>The Whois report includes the name, address and contact information for the Internet Service Provider (ISP) that administers the block of IP addresses that contains 218.23.53.228. The report probably does not list the administrator of the specific computer at IP address 218.23.53.228.</p>
<p>You should not assume that individuals listed in this report are responsible for the alert you received on your computer.</p>
<p>Whois Information	</p>
<p>% [whois.apnic.net node-2]<br />
% Whois data copyright terms    <a href="http://www.apnic.net/db/dbcopyright.html" rel="nofollow">http://www.apnic.net/db/dbcopyright.html</a></p>
<p>inetnum:      218.22.0.0 &#8211; 218.23.255.255<br />
netname:      CHINANET-AH<br />
country:      CN<br />
descr:        CHINANET Anhui province network<br />
descr:        Data Communication Division<br />
descr:        China Telecom<br />
admin-c:      CH93-AP<br />
tech-c:       AT318-AP<br />
status:       ALLOCATED PORTABLE<br />
mnt-by:       APNIC-HM<br />
mnt-lower:    MAINT-CHINANET-AH<br />
changed:    <a href="mailto:xxx@apnic.net">xxx@apnic.net</a> 20060322<br />
source:       APNIC</p>
<p>role:         ANHUI TELECOM<br />
address:      305 Changjiang West Road<br />
address:      Hefei Anhui China<br />
country:      CN<br />
phone:        +86 0551 5185089<br />
fax-no:       +86 0551 5185500<br />
e-mail:       <a href="mailto:xxx@anhuitelecom.com">xxx@anhuitelecom.com</a><br />
trouble:      send spam reports to <a href="mailto:xxx@ah163.com">xxx@ah163.com</a><br />
trouble:      and abuse reports to <a href="mailto:xxx@ah163.com">xxx@ah163.com</a><br />
trouble:      Please include detailed information and<br />
trouble:      times in GMT+8:00<br />
admin-c:      LW604-AP<br />
tech-c:       LW604-AP<br />
nic-hdl:      AT318-AP<br />
remarks:      <a href="http://www.ah163.net" rel="nofollow">http://www.ah163.net</a><br />
notify:       <a href="mailto:wxxx@anhuitelecom.com">wxxx@anhuitelecom.com</a><br />
mnt-by:       MAINT-CHINANET-AH<br />
changed:      <a href="mailto:xxx@anhuitelecom.com">xxx@anhuitelecom.com</a> 20060323<br />
source:       APNIC</p>
<p>person:       Chinanet Hostmaster<br />
nic-hdl:      CH93-AP<br />
e-mail:       <a href="mailto:xxx@ns.chinanet.cn.net">xxx@ns.chinanet.cn.net</a><br />
address:      No.31 ,jingrong street,beijing<br />
address:      100032<br />
phone:        +86-10-58501724<br />
fax-no:       +86-10-58501724<br />
country:      CN<br />
changed:      <a href="mailto:xxx@cndata.com">xxx@cndata.com</a> 20070416<br />
mnt-by:       MAINT-CHINANET<br />
source:       APNIC</p>
<p>*****One of the Search Results was from SANS to which I have provided the link&#8230; and results below&#8230;.</p>
<p><a href="http://isc.sans.org/ipinfo.html?ip=218.023.053.228" rel="nofollow">http://isc.sans.org/ipinfo.html?ip=218.023.053.228</a></p>
<p>IP Info (218.23.53.228)<br />
IP Address (click for more detail): 	218.23.53.228<br />
Hostname: 	218.23.53.228<br />
Country: 	CN<br />
AS: 	4134<br />
AS Name: 	CHINANET-BACKBONE No.31,Jin-rong Street<br />
Reports: 	91384<br />
Targets: 	55345<br />
First Reported: 	2008-08-04<br />
Most Recent Report: 	2008-11-24<br />
Comment: 	- none -</p>
<p>Note: This data is updated periodially. In order to refresh the data, click here. Not all source IPs in our database are &#8220;attackers&#8221;. There are a few common false positives. For example, hosts that participate in P2P networks, mail servers and DNS servers are some of the most common issues. You can see more details if you click on the number of reports. This may allow you to conclude if a host is a false positive or not.<br />
Whois Info</p>
<p>[Querying whois.apnic.net]<br />
[whois.apnic.net]<br />
% [whois.apnic.net node-2]<br />
% Whois data copyright terms    <a href="http://www.apnic.net/db/dbcopyright.html" rel="nofollow">http://www.apnic.net/db/dbcopyright.html</a></p>
<p>inetnum:      218.22.0.0 &#8211; 218.23.255.255<br />
netname:      CHINANET-AH<br />
country:      CN<br />
descr:        CHINANET Anhui province network<br />
descr:        Data Communication Division<br />
descr:        China Telecom<br />
admin-c:      CH93-AP<br />
tech-c:       AT318-AP<br />
status:       ALLOCATED PORTABLE<br />
mnt-by:       APNIC-HM<br />
mnt-lower:    MAINT-CHINANET-AH<br />
changed:      <a href="mailto:xxx@apnic.net">xxx@apnic.net</a> 20060322<br />
source:       APNIC</p>
<p>role:         ANHUI TELECOM<br />
address:      305 Changjiang West Road<br />
address:      Hefei Anhui China<br />
country:      CN<br />
phone:        +86 0551 5185089<br />
fax-no:       +86 0551 5185500<br />
e-mail:       <a href="mailto:xxx@anhuitelecom.com">xxx@anhuitelecom.com</a><br />
trouble:      send spam reports to <a href="mailto:xxx@ah163.com">xxx@ah163.com</a><br />
trouble:      and abuse reports to <a href="mailto:xxx@ah163.com">xxx@ah163.com</a><br />
trouble:      Please include detailed information and<br />
trouble:      times in GMT+8:00<br />
admin-c:      LW604-AP<br />
tech-c:       LW604-AP<br />
nic-hdl:      AT318-AP<br />
remarks:      <a href="http://www.ah163.net" rel="nofollow">http://www.ah163.net</a><br />
notify:       <a href="mailto:xxx@anhuitelecom.com">xxx@anhuitelecom.com</a><br />
mnt-by:       MAINT-CHINANET-AH<br />
changed:      <a href="mailto:xxxx@anhuitelecom.com">xxxx@anhuitelecom.com</a> 20060323<br />
source:       APNIC</p>
<p>person:       Chinanet Hostmaster<br />
nic-hdl:      CH93-AP<br />
e-mail:       <a href="mailto:xxx@ns.chinanet.cn.net">xxx@ns.chinanet.cn.net</a><br />
address:      No.31 ,jingrong street,beijing<br />
address:      100032<br />
phone:        +86-10-58501724<br />
fax-no:       +86-10-58501724<br />
country:      CN<br />
changed:     <a href="mailto:xxxy@cndata.com">xxxy@cndata.com</a> 20070416<br />
mnt-by:       MAINT-CHINANET<br />
source:       APNIC</p>
<p><a href="http://sitetheory.com/index.php?m=portsentry" rel="nofollow">http://sitetheory.com/index.php?m=portsentry</a></p>
<p>Beginning 11/12/2008<br />
13:50:20 Host: 228.53.23.218.broad.static.hf.ah.cndata.com/218.23.53.228<br />
         Port: 2967 TCP Blocked<br />
         Analysis: Stack-based buffer overflow in Symantec Antivirus<br />
10:24:49 Host: adsl-074-172-016-248.sip.asm.bellsouth.net/74.172.16.248<br />
         Port: 135 TCP Blocked</p>
<p>  Analysis: Possible MS Baster or various other Worm Attack<br />
06:12:16 Host: 2.b2.374a.static.theplanet.com/74.55.178.2<br />
         Port: 1433 TCP Blocked<br />
         Analysis: Probable Scan for MS SQL Server &#8211; Most likely malicious</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on George, The Real Whitehouse Turkey by Whitehouse On Best Political Blogs &#187; George, The Real Whitehouse Turkey « This Way Up, Seattle, Washington.</title>
		<link>http://thiswayupseattle.wordpress.com/2008/11/13/the-real-whitehouse-turkey/#comment-45</link>
		<dc:creator><![CDATA[Whitehouse On Best Political Blogs &#187; George, The Real Whitehouse Turkey « This Way Up, Seattle, Washington.]]></dc:creator>
		<pubDate>Sun, 23 Nov 2008 03:19:30 +0000</pubDate>
		<guid isPermaLink="false">http://thiswayupseattle.wordpress.com/?p=1109#comment-45</guid>
		<description><![CDATA[[...] George, The Real Whitehouse Turkey « This Way Up, Seattle, Washington. George, The Real Whitehouse Turkey. P112205SC-0073.JPG. Posted in Humor. « State of the Division - Taxpayers Invest in America’s Sovereign Debt Fund · B.O.H.I.C.A. ». Leave a response. You must be logged in to post a comment. Categories &#8230; [...]]]></description>
		<content:encoded><![CDATA[<p>[...] George, The Real Whitehouse Turkey « This Way Up, Seattle, Washington. George, The Real Whitehouse Turkey. P112205SC-0073.JPG. Posted in Humor. « State of the Division &#8211; Taxpayers Invest in America’s Sovereign Debt Fund · B.O.H.I.C.A. ». Leave a response. You must be logged in to post a comment. Categories &#8230; [...]</p>
]]></content:encoded>
	</item>
</channel>
</rss>
