 AVDRespice, Adspice, ProspicePremium join:2003-02-06 Onion, NJ kudos:1 | reply to cyb3rl0g
Re: persistent connection to qw-in-f113.1e100.net on boot said by cyb3rl0g :
We started noticing this too early 10/1/09 and starting calling it "Big G, Phone Home". Around the same time, we learned that Google (Big G) was buying up enormous amounts of bandwidth on a global scale. This transmission capacity they were buying we figured was Big G building their own seperate 'Internet'. We dubbed the new capacity as 'GooglePlanet'. ... I like to use the terms GoogleGod and TheGoogleMatrix.. -- standard disclaimers apply. |
|
 Dude111An Awesome DudePremium join:2003-08-04 USA kudos:11 1 edit | reply to gogregor6 said by dsilvers : Add five spaces between 127.0.0.1 and the URL.
Not needed,i have mine as 127.0.0.1 xxxxxx and it is fine... (1 space is all thats required) |
|
 sbkansasActual ExamplePremium,MVM join:2001-05-10 Hays, KS 1 edit | reply to gogregor6 Just a little FYI for those that don't know, that is 1e1OO.net , ( one e one oh oh dot net , not one e one hundred dot net )
Ignore this info, I have been corrected |
|
|
|
 NetFixerFrom my cold dead handsPremium join:2004-06-24 The Boro Reviews:
·Comcast Business..
·Vonage
·Cingular Wireless
·Comcast
| You are correct that there is a 1e1oo.net.
Domain Name: 1E1OO.NET Registrar: MONIKER Registrant [1530176]: Xander Jeduyu info@ALGEBRALIVE.COM ALGEBRALIVE P.O. Box 523 7480 Praesent Ave Praesent Ave BE 1154AU BE
However, that is not the domain being discussed in this thread.
Registrant: DNS Admin Google Inc. 1600 Amphitheatre Parkway Mountain View CA 94043 US dns-admin@google.com +1.6502530000 Fax: +1.6506188571 Domain Name: 1e100.net Registrar Name: Markmonitor.com Registrar Whois: whois.markmonitor.com Registrar Homepage: »www.markmonitor.com
-- History does not long entrust the care of freedom to the weak or the timid. -- Dwight D. Eisenhower The tree of liberty must be refreshed from time to time with the blood of patriots and tyrants. -- Thomas Jefferson |
|
 sbkansasActual ExamplePremium,MVM join:2001-05-10 Hays, KS | I beleive you are correct, i've been spending some time trying to find out what to block (Blackhole DNS). If I ping 1e100, i get 'Ping request could not find host 1e100.net', if I ping 1e1oo.net the result is 208.73.210.27 - Oversee.net, not matching your results?
I thought Blackhole DNS would work with 1e100.net, but it wasn't working so that's when I thought it was with the O's (still didn't work)
any advice? -- "You will find that the mere resolve not to be useless, and the honest desire to help other people, will, in the quickest and delicatest ways, improve yourself" - John Ruskin
|
|
 NetFixerFrom my cold dead handsPremium join:2004-06-24 The Boro Reviews:
·Comcast Business..
·Vonage
·Cingular Wireless
·Comcast
1 edit | I am not sure exactly what you are trying to do, so I am not able to provide any advice.
I think, however, that you may not understand the difference between a domain name and a host name. A domain name is the registered name for a domain, and a domain may contain many subdomains and host names. The domain name itself does not have to have any specific host associated with it, nor is there any requirement for any domain or host to be pingable.
Examples:
C:\>ping 1e100.net Ping request could not find host 1e100.net. Please check the name and try again.
C:\>ping qw-in-f113.1e100.net
Pinging qw-in-f113.1e100.net [74.125.93.113] with 32 bytes of data:
Reply from 74.125.93.113: bytes=32 time=48ms TTL=44 Reply from 74.125.93.113: bytes=32 time=52ms TTL=47 Reply from 74.125.93.113: bytes=32 time=48ms TTL=44 Reply from 74.125.93.113: bytes=32 time=50ms TTL=47
Ping statistics for 74.125.93.113: Packets: Sent = 4, Received = 4, Lost = 0 (0% loss), Approximate round trip times in milli-seconds: Minimum = 48ms, Maximum = 52ms, Average = 49ms
C:\>nslookup 1e100.net Server: dcs-srv.dcs-net Address: 192.168.10.2
Name: 1e100.net
C:\>nslookup qw-in-f113.1e100.net Server: dcs-srv.dcs-net Address: 192.168.10.2
Non-authoritative answer: Name: qw-in-f113.1e100.net Address: 74.125.93.113
C:\>ping 1e1oo.net
Pinging 1e1oo.net [208.73.210.27] with 32 bytes of data:
Reply from 208.73.210.27: bytes=32 time=66ms TTL=236 Reply from 208.73.210.27: bytes=32 time=68ms TTL=239 Reply from 208.73.210.27: bytes=32 time=65ms TTL=236 Reply from 208.73.210.27: bytes=32 time=68ms TTL=239
Ping statistics for 208.73.210.27: Packets: Sent = 4, Received = 4, Lost = 0 (0% loss), Approximate round trip times in milli-seconds: Minimum = 65ms, Maximum = 68ms, Average = 66ms
C:\>nslookup 1e1oo.net Server: dcs-srv.dcs-net Address: 192.168.10.2
Non-authoritative answer: Name: 1e1oo.net Address: 208.73.210.27
You will note that the domain/host name 1e100.net does not have a DNS record that defines an IP address. The host name qw-in-f113.1e100.net does have an IP address defined in DNS.
OTOH, the domain name 1e1oo.net also has a host name with an IP address defined in DNS. However, that domain is totally unrelated to the Google owned 1e100.net (as I thought I made clear in my previous post).
-- History does not long entrust the care of freedom to the weak or the timid. -- Dwight D. Eisenhower The tree of liberty must be refreshed from time to time with the blood of patriots and tyrants. -- Thomas Jefferson |
|
 ArchivisYour DaddyPremium join:2001-11-26 Earth kudos:18 | Maybe you should try using the letter O instead of zeros (0).
one e one o o dot net |
|
 AVDRespice, Adspice, ProspicePremium join:2003-02-06 Onion, NJ kudos:1 | oh oh |
|
 ArchivisYour DaddyPremium join:2001-11-26 Earth kudos:18 | qw-in-f113.1e1oo.net resolves to 208.73.210.27. |
|
 NetFixerFrom my cold dead handsPremium join:2004-06-24 The Boro Reviews:
·Comcast Business..
·Vonage
·Cingular Wireless
·Comcast
| said by Archivis:qw-in-f113.1e1oo.net resolves to 208.73.210.27. That is because the domain 1e1oo.net uses a wild card DNS as shown below. It is also totally irrelevant since the domain 1e1oo.net has absolutely nothing to do with the Google owned 1e100.net.
C:\>nslookup 1e1oo.net Server: dcs-srv.dcs-net Address: 192.168.10.2
Non-authoritative answer: Name: 1e1oo.net Address: 208.73.210.27
C:\>nslookup qw-in-f113.1e1oo.net Server: dcs-srv.dcs-net Address: 192.168.10.2
Non-authoritative answer: Name: qw-in-f113.1e1oo.net Address: 208.73.210.27
C:\>nslookup stuff.it.where.the.sun.does.not.shine.1e1oo.net Server: dcs-srv.dcs-net Address: 192.168.10.2
Non-authoritative answer: Name: stuff.it.where.the.sun.does.not.shine.1e1oo.net Address: 208.73.210.27
-- History does not long entrust the care of freedom to the weak or the timid. -- Dwight D. Eisenhower The tree of liberty must be refreshed from time to time with the blood of patriots and tyrants. -- Thomas Jefferson |
|
 ArchivisYour DaddyPremium join:2001-11-26 Earth kudos:18 | You're right. I had to check again. My own computer now is connected to 1e100.
vw-in-f100.1e100.net
My bad. It's definitely zeros, not "oh's" -- 'A government big enough to give you everything you want, is strong enough to take everything you have.' -Thomas Jefferson - |
|
 ArchivisYour DaddyPremium join:2001-11-26 Earth kudos:18 | I guess it isn't really going anywhere if the domain doesn't work. |
|
 NetFixerFrom my cold dead handsPremium join:2004-06-24 The Boro Reviews:
·Comcast Business..
·Vonage
·Cingular Wireless
·Comcast
| said by Archivis:I guess it isn't really going anywhere if the domain doesn't work. Oh Oh, I'll bet you didn't know that you had your own subdomain and host name did you?
C:\>/nslookup Archivis.1e1oo.net Server: dcs-srv.dcs-net Address: 192.168.10.2
Non-authoritative answer: Name: Archivis.1e1oo.net Address: 208.73.210.27
C:\>ping Archivis.1e1oo.net
Pinging Archivis.1e1oo.net [208.73.210.27] with 32 bytes of data:
Reply from 208.73.210.27: bytes=32 time=66ms TTL=236 Reply from 208.73.210.27: bytes=32 time=68ms TTL=239 Reply from 208.73.210.27: bytes=32 time=66ms TTL=236 Reply from 208.73.210.27: bytes=32 time=69ms TTL=239
Ping statistics for 208.73.210.27: Packets: Sent = 4, Received = 4, Lost = 0 (0% loss), Approximate round trip times in milli-seconds: Minimum = 66ms, Maximum = 69ms, Average = 67ms
And, that one does seem to go somewhere.
-- History does not long entrust the care of freedom to the weak or the timid. -- Dwight D. Eisenhower The tree of liberty must be refreshed from time to time with the blood of patriots and tyrants. -- Thomas Jefferson |
|
 ArchivisYour DaddyPremium join:2001-11-26 Earth kudos:18 | stop pinging me  |
|
 AVDRespice, Adspice, ProspicePremium join:2003-02-06 Onion, NJ kudos:1 1 edit | reply to gogregor6 nevermind |
|
 NetFixerFrom my cold dead handsPremium join:2004-06-24 The Boro Reviews:
·Comcast Business..
·Vonage
·Cingular Wireless
·Comcast
1 edit | reply to gogregor6 To continue in the same vein as the last few posts in this thread, there is also a leloo.net (el ee el oh oh dot net) domain:
Domain name: leloo.net Administrative Contact: Inside Internet Novi Kod (domene@inside.hr) +385.12341433 Fax: +385.12341434 Cretski Odvojak, 1 Zagreb, 10000 HR
However, for anyone wishing to register it for the purpose of masquerading as Google (and/or blackmailing them to purchase the domain name from you), the domain lel00.net (el ee el zero zero dot net) is currently available. 
-- History does not long entrust the care of freedom to the weak or the timid. -- Dwight D. Eisenhower The tree of liberty must be refreshed from time to time with the blood of patriots and tyrants. -- Thomas Jefferson |
|
 GeekGirl1Premium join:2007-01-28 Morrisville, PA kudos:2 | reply to gogregor6 This persistent connection was driving me crazy. Online Armour (firewall) reported the persistent connections as coming from Avast! (antivirus). However, the source was from Firefox. I guess since the antivirus is hooked into the http traffic, that's how it goes out.
ashWebSv.exe/TCP to qw-in-f113.1e100.net:http. I also see qw-in-f102.1e100.net:http, iad04s01-in-f147.1e100.net:http.
I did some quick research and found that this persistent connection is from Firefox's safe browsing feature. The Mysterious 1e100.net
I unchecked the "Block reported attack sites" and "Block reported web forgeries" choices in the Security tab and most of the persistent connections went away.
In Firefox, do about:config and filter on safebrowsing to see how what Firefox is doing.
Interesting that Thunderbird also connects to 1e100.net when it checks for new mail from my gmail account (Google, smtp.gmail.com is what I entered):
Thunderbird.exe/TCP to qy-in-f109.1e100.net:pop3s
Google is everywhere. Typing text in the search engine box (Google is default) fires up those persistent connections. httpFox showed queries to suggestqueries.google.com. |
|
 NetFixerFrom my cold dead handsPremium join:2004-06-24 The Boro Reviews:
·Comcast Business..
·Vonage
·Cingular Wireless
·Comcast
| That about sums it up. Google is the new Akamai.
The 1e100 pandemic will soon take control of the internet (if not the globe).  -- History does not long entrust the care of freedom to the weak or the timid. -- Dwight D. Eisenhower The tree of liberty must be refreshed from time to time with the blood of patriots and tyrants. -- Thomas Jefferson |
|
 | reply to gogregor6 gogregor6, have you cleared all your cookies from this computer that has these remote connections your talking about? If you disconnect your internet and reboot and use TCPview do you see these connections on start up with no internet access?
just on a side note, I could not help but notice you still use spybot, I would recommend you upgrade to something more modern like SUPERAntiSpyware and Malwarebytes Anti-Malware, anyone here will agree that spybot's time has sorta come and gone. still a useful tool to have mind you, but it's the last one scan with anymore. |
|