Toy model of matter that exhibits phase transition in dimension 2 and greater. It does not provide numerically exact results by itself, but can serve as a tool to theorize existing and new phase transitions.
Each point in the lattice has two possible states: TODO insert image.
As mentioned at: stanford.edu/~jeffjar/statmech/intro4.html some systems which can be seen as modelled by it include:
- the spins direction (up or down) of atoms in a magnet, which can undergo phase transitions depending on temperature as that characterized by the Curie temperature and an externally applied magnetic fieldNeighboring spins like to align, which lowers the total system energy.
- the type of atom at a lattice point in a 2-metal alloy, e.g. Fe-C (e.g. steel). TODO: intuition for the neighbour interaction? What likes to be with what? And aren't different phases in different crystal structures?
Also has some funky relations to renormalization TODO.
Bibliography:
One promising way to find more of those would be with IP searches, since it was stated in the Reuters article that the CIA made the terrible mistake of using several contiguous IP blocks for those website. What a phenomenal OPSEC failure!!!
The easiest way would be if Wayback Machine itself had an IP search function, but we couldn't find one: Search Wayback Machine by IP.
viewdns.info was the first easily accessible website that Ciro Santilli could find that contained such information.
Our current results indicate that the typical IP range is about 30 IPs wide.
E.g. searching: viewdns.info/iphistory and considering only hits from 2011 or earlier we obtain:
- capture-nature.com
- 65.61.127.163 - Greenacres - United States - TierPoint - 2013-10-19
- activegaminginfo.com
- 66.175.106.148 - United States - Verizon Business - 2012-03-03
- iraniangoals.com
- 68.178.232.100 - United States - GoDaddy.com - 2011-11-13
- 69.65.33.21 - Flushing - United States - GigeNET - 2011-09-08
- rastadirect.net
- 68.178.232.100 - United States - GoDaddy.com - 2011-05-02
- iraniangoalkicks.com
- 68.178.232.100 - United States - GoDaddy.com - 2011-04-04
- headlines2day.com
- 118.139.174.1 - Singapore - Web Hosting Service - 2013-06-30. Source: viewdns.info
- 184.168.221.91 2013-08-12T06:17:39. Source: 2013 DNS Census grep
- fightwithoutrules.com
- 204.11.56.25 - British Virgin Islands - Confluence Networks Inc - 2013-09-26
- 208.91.197.19 - British Virgin Islands - Confluence Networks Inc - 2013-05-20
- 212.4.17.38 - Milan - Italy - MCI Worldcom Italy Spa - 2012-03-03
- fitness-dawg.com
- 219.90.62.243 - Taiwan - Verizon Taiwan Co. Limited - 2012-01-11
Neither of these seem to be in the same ranges, the only common nearby hit amongst these ranges is the exact
68.178.232.100
, and doing reverse IP search at viewdns.info/reverseip/?host=68.178.232.100&t=1 states that it has 2.5 million hostnames associated to it, so it must be some kind of Shared web hosting service, see also: superuser.com/questions/577070/is-it-possible-for-many-domain-names-to-share-one-ip-address, which makes search hard.Ciro then tried some of the other IPs, and soon hit gold.
Initially, Ciro started by doing manual queries to viewdns.info/reversip until his IP was blocked. Then he created an account and used his 250 free queries with the following helper script: cia-2010-covert-communication-websites/viewdns-info.sh. The output of that script can be seen at: github.com/cirosantilli/media/blob/master/cia-2010-covert-communication-websites/viewdns-info.sh.
Ciro then found 2013 DNS Census which contained data highly disjoint form the viewdns-info one!
Summaries of the IP range exploration done so far follows, combined data from all databases above.
alljohnny.com: one of the Reuters websites.
- 208.91.197.132: rdns source: viewdns.info. Big virtual.
- 65.218.91.17: rdns source? : viewdns.info. Tested viewdns.info range: 65.218.91.13 - 65.218.91. 17
- 65.218.91.9: welcometonyc.net. Hit. rdns source: ipinf.ru. Later also at 208.91.197.132 British Virgin Islands CONFLUENCE-NETWORK-INC 2013-10-21 by viewdns.info
- also on: 65.218.91.17,
- international-smallbusiness.com. Stylitsic match, but some uncommon features like the country seelctor dropdown.
- Archives:Also a potential unarchived CGI comms: web.archive.org/web/20110202031627/https://ssl.international-smallbusiness.com/cgi-bin/starting.cgi Perhaps with some better HTML reversing we could confirm a hit.
- 208.91.197.132 British Virgin Islands CONFLUENCE-NETWORK-INC 2013-10-19. Big virtual.
- 65.218.91.17 United States UUNET 2013-09-06
- Archives:
- international-smallbusiness.com. Stylitsic match, but some uncommon features like the country seelctor dropdown.
- 216.168.229.50: whoisxmlapi 2008-09-01 (15 years) 2010-04-17. Checked viewdns.info range: 216.168.229.45 - 216.168.229.55
62.22.60.49: telecom-headlines.com. Found with: visual inspection of full 2013 DNS Census virtual host cleanup list just before worldnewsnetworking.com. Tested viewdns.info range: 62.22.60.34 - 62.22.60.66
- 62.22.60.33: newsperk.com. Unclear. Stylistically perfect, but no comms not found. 2011. English. Egypt. news.
- 62.22.60.34: freeslideshow.net. Legit? Attempting to open any HTML archives leads to an infinite page load loop, e.g. 2010. A subpage however exists: web.archive.org/web/20101230001640/http://freeslideshow.net/index_files/a.htm and appears legit.
- 62.22.60.40: travel-passage.com. Unclear. No archives of toplevel, only subpage: 2009. No clear comms. Chinese.
- 62.22.60.42: newsupdatesite.com. Hit.
- 62.22.60.46: flyingtimeline.com. Hit.
- 62.22.60.47: globalemergenceadvisorsbkserver.com. Legit.
- 62.22.60.48: currentcommunique.com. Hit.
- 62.22.60.49: telecom-headlines.com. Hit.
- 62.22.60.52: collectedmedias.com. Hit.
- 62.22.60.54: romulusactualites.com. No archives.
- 62.22.60.55: thefilmcentre.com. Hit.
- 62.22.60.56: traveltimenews.com. Hit.
62.22.61.206 worldnewsnetworking.com. Found with: 2013 DNS Census virtual host cleanup heuristic keyword searches. Tested viewdns.info range: 62.22.61.188 - 62.22.61.224
- 62.22.61.193: awfaoi.org. Hit.
- 62.22.61.197: rc5sports.com. Hit.
- 62.22.61.198: inside-vc.com. Hit.
- 62.22.61.202: bailsnboots.com. Hit.
- 62.22.61.203: the-cricketer-online.com. Hit.
- 62.22.61.204: hollywoodscreen.net. Hit.
- 62.22.61.206: worldnewsnetworking.com. Hit.
- 62.22.61.212: nuestrasfinanzas.com. Hit.
- 62.22.61.215: the-tech-mind.com. Welcome to the US Petabox
- 62.22.61.217: court-masters.com. Hit.
- 62.22.61.219: allworldstatistics.com. Hit.
- 62.22.61.220: newsjaka.com. Hit.
- 62.22.61.221: biochemresource.com. Archive broken/empty. One archive: contains an epically long URL that might shed light into something: web.archive.org/web/20120529121245/http://www.biochemresource.com/?fp=iboHtuxnjLG66y52DkK1xCFuZDBnVC8wovQepLt2Tk%2Bo1JIgIdVb6WL8kv6sSOEtxwcq4EbiJ0GxFY9N6HSWlg%3D%3D&prvtof=97vgfKVqt1Sd68qgNDPXB0o7Rwo%2FO3GKiiMG7fane6A%3D&poru=Zd9DHFaHFZ6ZrRLm8SW3egagqvdpzHhWb%2FoulRGeEYIUSVATB5gwTIDhluetONjG7xovtb%2FrvDStoqiAF1O8wA%3D%3D&. Asked at: stackoverflow.com/questions/47310661/any-idea-what-are-fp-prvtof-poru-in-a-url but no reply so far. One day my friend, one day.
- 62.22.61.222: www.news-blitz-ar.com (ipinf.ru). No archives. Perfect theme match.
63.131.229.12 cyberreportagenews.com. Tested viewdns.info range: 63.131.228.248 - 63.131.229.30
- 63.131.229.2: fightskillsresource.com. Hit
- 63.131.229.4: unitedterritorynews.com. Hit
- 63.131.229.9: show-dustry.com. Hit
- 63.131.229.10: afghanpoetry.net. Hit. Also at 74.254.12.166 in another range.
- 63.131.229.11: mythriftytrip.com. Hit
- 63.131.229.12: cyberreportagenews.com. Hit.
- 63.131.229.13: sunrise-news.com. Hit.
- 63.131.229.15: cricketnewsforindia.com. Archive quite broken, likely hit.
- 63.131.229.16:
- nutricion-saludable.info. No archives.
- nutricion-saludable.net. Hit.
- 63.131.229.18: itnl-xchange.com. Hit.
- 63.131.229.20:
- fixashion.net. Hit.
- a few others
63.130.160.50 theglobalheadlines.com. Found with: 2013 DNS census secureserver.net MX records intersection 2013 DNS Census virtual host cleanup. Tested viewdns.info range: 63.130.160.35 - 63.130.160.75
- 63.130.160.50: theglobalheadlines.com. Hit.
- 63.130.160.51:
- hai-pow.com. Hit.
- secudenetworksecurity.com. No archives.
- 63.130.160.53: echessnews.com. Hit.
- 63.130.160.59: technologiewissen.com. No archives from the time. Would be Technology knowledge in German, so another likely German hit. Shame.
- 63.130.160.60: boxingstop.net. Hit.
- 63.130.160.61: bookmarksthis.com. No archives.
- 63.130.160.62: azerinews.org. Hit.
64.16.204.55 holein1news.com. Found with: 2013 DNS Census virtual host cleanup heuristic keyword searches. Tested viewdns.info range: 64.16.204.50 - 64.16.204.63. With did Wayback Machine have so few archives here? TODO stopping viewdns.info exploration a bit short due to that.
- 64.16.204.35: ironcityfootball.com. Legit/broke.
- 64.16.204.51: africannewsandsports.com. No archives. rdns source: viewdns.info
- 64.16.204.53: bosniakbusinessnews.com. No archives. A Bosniak is someone from an ethnicity from Bosnia.
- 64.16.204.54: affairesdumonde.com. No archives. rdns source: viewdns.info
- 64.16.204.55: holein1news.com. Hit.
- 64.16.204.56: fightorgohome.com. No archives. rdns source: viewdns.info
- 64.16.204.58: tech-topix.com. Hit.
- 64.16.204.60: pakpoldaily.com. No archives. rdns source: viewdns.info. TODO meaning? Might be Indonesian, maybe linked to police: www.facebook.com/watch/?v=880204266271955
65.61.127.163 capture-nature.com. whois.arin.net/rest/net/NET-65-61-96-0-1/pft?s=65.61.127.163: Net Range: 65.61.96.0 - 65.61.127.255. Organization. Name: TierPoint, LLC. Tested viewdns.info range: 65.61.127.149 -
- 65.61.127.46: anahuacchamber.com 2012-12-22T14:59:01
- 65.61.127.117: medicaresupplementalinsurance.com, 2013-08-21T09:49:41. Legit.
- 65.61.127.121: counter-images.com 2013-08-22T11:14:44: web.archive.org/web/20110208173132/http://www.counter-images.com/
- 65.61.127.125 zaphound.com 2013-08-21T02:25:40. Legit.
- 65.61.127.130: ambitions.org 2013-08-22T01:43:40. Legit.
- 65.61.127.161: european-footballer.com. 2011 archive. web.archive.org/web/20110319111233/http://european-footballer.com/. The website is quite broken so it is hard to say, but possible hit.
- 65.61.127.163: capture-nature.com. Hit.
- 65.61.127.164: futbolistico.net. 2012-02-20T03:25:33. Legit. web.archive.org/web/20130509004058/http://futbolistico.net/
- 65.61.127.165: travelconnectionsonline.com. Ciro initially though this might be a hit. But upon Googling it, there's now a mirror at: travelconn.tripod.com/. Combined with the lack of a standard communications mechanism and the 2001 copyright, maybe it isn't a hit after all
- 65.61.127.166: globalnewsbulletin.com: Hit.
- 65.61.127.167: internationalwhiskylounge.com. No Wayback Machine archives.
- 65.61.127.168: the-golden-rule.info 2013-09-20T02:13:52. Website error archived: web.archive.org/web/20131011012026/http://the-golden-rule.info/
- 65.61.127.169: crossovernews.net. Hit.
- 65.61.127.170: newsidori.com. Very broken 2013 archive: 2013. "Idori" sounds Japanese, but the meaning is unclear.
- 65.61.127.171: nrgconsultingandnews.com. 2013-08-13T18:45:05. No archives.
- 65.61.127.172: premierstriker.com. No Wayback Machine archives from the time, and has been since parked by something apparently as of 2022 onwards. Last resolved: 2012-01-11.
- 65.61.127.174: dedrickonline.com. Hit.
- 65.61.127.175: altworldnews.com. Hit.
- 65.61.127.176: american-historyonline.com. No Wayback Machine archives. Last resolved: 2011-09-08.
- 65.61.127.177: material-science.org 2009. Shallow, narrow. No comms found. .org hit?
- 65.61.127.178: tee-shot.net. Hit.
- 65.61.127.180: screencentral.info. Buggy Wayback Machine archive from 2013: web.archive.org/web/20130713224951/http://screencentral.info/. Last resolved: 2013-05-08.
- 65.61.127.181: worldnewsandtravel.com. No Wayback Machine archives. Last resolved: 2011-11-13.
- 65.61.127.182: pangawana.com. Hit.
- 65.61.127.183: cutabovenews.com. Hit.
- 65.61.127.184: worldwildlifeadventure.com. Hit.
- 65.61.127.186: explorealtmeds.com. Hit.
- 65.61.127.194: 16 domains, so unclear.
- about-video-games.com: web.archive.org/web/20121013013710/http://about-video-games.com/
- aboutfaceonline.com: web.archive.org/web/20120701000000*/aboutfaceonline.com
- 65.61.127.200: cdl-link.com (ipinf.ru). Legit.
- 65.61.127.222: asianwhitecoffee.com 2012-07-16T09:21:05 web.archive.org/web/20110903080036/http://asianwhitecoffee.com/. Could be legit.
66.45.179.205 noticiasporjanua.com. Found with: 2013 DNS Census virtual host cleanup. Tested viewdns.info range: 66.45.179.187 - 66.45.179.223
- 66.45.179.187: mail03.gatesfoundation.org. Legit.
- 66.45.179.192: thegraceofislam.com. Hit.
- 66.45.179.193: arabicnewsunfiltered.com. Hit.
- 66.45.179.194: raulsonsglobalnews.com. Hit.
- 66.45.179.195: aryannews.net. Hit.
- 66.45.179.199: attivitaestremi.com. Hit.
- 66.45.179.200: foodwineandsuch.com. No archives.
- 66.45.179.201: hitthepavementnow.com. Hit.
- 66.45.179.203: noticiascontinental.com. Hit.
- 66.45.179.205: noticiasporjanua.com. Hit.
- 66.45.179.206: podisticamondiale.com. Hit.
- 66.45.179.207: reflectordenoticias.com. Hit.
- 66.45.179.208: havenofgamerz.com. Hit.
- 66.45.179.209: vejaaeuropa.com. web.archive.org/web/20130810131440/http://www.vejaaeuropa.com/: Welcome to the US Petabox. Shame, could be another Brazil hit since "veja" (look in Brazilian Portuguese) would be "mira" in Spanish, not "veja".
- 66.45.179.210: sa-michigan.com. Hit.
- 66.45.179.211: absolutebearing.net. Hit.
- 66.45.179.212: grandretirement.net. No archives.
- 66.45.179.213: myportaltonews.com. Hit.
- 66.45.179.214: investmentintellect.com. Hit.
- 66.45.179.215: nigeriastar.net 2012-03-12. Hit.
66.104.169.184 bcenews.com. Found with: 2013 DNS Census virtual host cleanup heuristic keyword searches. Tested viewdns.info range: 66.104.169.158 - 66.104.169.189
- 66.104.169.162: bestsportsnews.net. Archive broken.
- 66.104.169.163: doctorsoncallsite.com. Hit.
- 66.104.169.164: lightandshadowonline.com. Hit.
- 66.104.169.168: plugged-into-news.net. Hit.
- 66.104.169.169: worldsportsite.com. Likely hit, but comms not found. 2011. Arabic. . sports. has some apparently unrelated archives from 2008.
- 66.104.169.171: golf-on-holiday.com. Hit.
- 66.104.169.172: perspectiva-noticias.com. Hit.
- 66.104.169.175: aquaswimming.com. Hit.
- 66.104.169.177: dojo-temple.com. Hit.
- 66.104.169.179: neighbour-news.com. Hit.
- 66.104.169.180: medicatechinfo.com. Hit.
- 205.178.189.131: securitytrails.com 2009-06-25 - 2009-07-02 Network Solutions, LLC., "ip_count": 726755. Moved to new one 2009-07-02 - 2010-11-03
- 66.104.169.181: brickmanfinancialnews.com. Hit.
- 66.104.169.182: casanewsnow.com. Hit.
- 66.104.169.183: aworldofnews.com. No archives.
- 66.104.169.184: bcenews.com. Hit.
- 66.104.169.197: teamshula.com. Legit.
66.104.173.186 myworldlymusic.com. Found with: 2013 DNS Census virtual host cleanup heuristic keyword searches. Tested viewdns.info range: 66.104.173.158 - 66.104.173.194
- 66.104.173.161: fanatic-pc-gamers.com. 2013: Welcome to the US Petabox
- 66.104.173.163: runakonews.com. Hit.
- 66.104.173.164: shoppingadventure.net. Hit.
- 66.104.173.165: entertaining-ly.com. Hit.
- 66.104.173.166: zubeenews.com. Hit.
- 66.104.173.169: smart-financeology.com. Hit.
- 66.104.173.173: remarkably has two potential hits, both shown in viewdns.info, and one of them was also in the 2013 DNS Census.
- worldfeedstoday.com. No main page archives. Subpage archive: 2011. English. news.
- world-newsfeeds.com. No archives.
- 66.104.173.175: media-coverage-now.com. Hit.
- 66.104.173.176: jbc-online-news.com. Hit.
- 66.104.173.177: webscooper.com. Hit.
- 66.104.173.178: dk-dcinvestment.com. Hit.
- 66.104.173.179: newsforthetech.com. Welcome to the US Petabox.
- 66.104.173.180: stara-turistick.com. Hit.
- 66.104.173.181: playbackpolitics.com. Hit.
- 66.104.173.182: snapnewsfront.net. Hit.
- 66.104.173.183: ingenuitytrendz.com. Hit.
- 66.104.173.184: armashoy.com. Hit.
- 66.104.173.185: baocontact.com. Hit.
- 66.104.173.186: myworldlymusic.com. Hit.
- 66.104.173.189: hitpoint-gaming.com. Hit.
66.104.175.40 beyondnetworknews.com. whois.arin.net/rest/net/NET-66-104-0-0-1/pft?s=66.104.175.40. Net Range:66.104.0.0 - 66.107.255.255. 2012 Internet Census puts most/all hits in this range under ip66-104-175-34.z175-104-66.customer.algx.net,
algx.net
redirects to verizon.com as of 2023. Related: superuser.com/questions/956568/why-are-my-pings-going-to-customer-algx-net. Tested viewdns.info range: 66.104.175.24 - unknown- 66.104.175.34: itwebtoday.com. Hit.
- 66.104.175.35: drglobalnews.com. Hit.
- 66.104.175.36: adilnews.net. Hit.
- 66.104.175.37: technewstogo.com. web.archive.org/web/20110201205946/http://technewstogo.com/ "UNDER CONSTRUCTION"
- 66.104.175.40: beyondnetworknews.com. Hit.
- 66.104.175.41: grubbersworldrugbynews.com. Hit.
- 66.104.175.44: yourtripfinder.net. Hit.
- 66.104.175.45: rollinsnetwork.com. Hit.
- 66.104.175.46: infosharenews.com. Hit.
- 66.104.175.47: southasiaheadlines.com. Hit.
- 66.104.175.48: worlddispatch.net. Hit.
- 66.104.175.49: webworldsports.com. Hit.
- 66.104.175.50: fly-bybirdies.com. Hit.
- 66.104.175.51: businessexchangetoday.com. Hit.
- 66.104.175.52: mensajeradenoticias.com. Hit.
- 66.104.175.53: info-ology.net. Hit.
- 66.104.175.54: marketflows.net. Hit.
- 66.104.175.57: metanewsdaily.com. Hit.
- 66.104.175.218: remote.taxconsultantsgroup.com. No archives.
66.175.106.148 activegaminginfo.com. whois.arin.net/rest/net/NET-66-175-106-128-1/pft?s=66.175.106.148: Net Range: 66.175.106.128 - 66.175.106.159. Customer Name: DIAMOND-COLESON. Tested viewdns.info range: 66.175.106.131 - 66.175.106.178
- 66.175.106.10: nationalchecktrust.com. Legit?
- 66.175.106.134: paddlescoop.com. Hit.
- 66.175.106.137: kessingerssportsnews.com. Hit.
- 66.175.106.138: factorforcenews.com. Hit.
- 66.175.106.140: aroundthemiddleeast.com. No Wayback Machine hits. Last resolved: 2012-06-29.
- 66.175.106.142: kanata-news.com. Hit.
- 66.175.106.143: thecricketfan.com. Hit.
- 66.175.106.146: inews-today.com. Initially found with 2013 DNS Census virtual host cleanup heuristic keyword searches which gave IP address 193.203.49.212. But that has no nearby hits. 66.175.106.146 was later found on viewdns.info, and slotted into this other existing IP range.
- 193.203.49.211 datingso.com: legit? Russian dating website
- 193.203.49.212 inews-today.com. Hit.
- 193.203.49.223 zatysi.net: legit
- 193.203.49.226 kinotopik.com: legit? Russian
- 193.203.49.229 rotor-volgograd.com. Legit.
- 193.203.49.233 ordercytotec.com. Broken.
- 66.175.106.147: starwarsweb.net. Hit.
- 66.175.106.149: feedsdemexicoyelmundo.com. Hit.
- 66.175.106.150: noticiasmusica.net. Hit.
- 66.175.106.155: atomworldnews.com. Hit.
- 66.175.106.158: nouvellesetdesrapports.com. Hit.
- 66.175.106.166: exchange.katzbarron.com. Legit. Reverse IP source: 2012 Internet Census
- 66.175.106.183: mail.lfdatacenter.com. No archives.
66.237.236.247 comunidaddenoticias.com. Tested viewdns.info range: 66.237.236.222 - 66.237.236.254
- 66.237.236.227: newsandmusicminute.com. Hit.
- 66.237.236.229: pearls-playlist.com 2011-11-13. Hit.
- 66.237.236.230: beyondthefringe.info 2013-01-02. Hit.
- 66.237.236.231: primetimemovies.net 2011-06-22. Hit.
- 66.237.236.235: persephneintl.com. Hit.
- 66.237.236.236: directoalgrano.net 2012-01-23. Hit.
- 66.237.236.240: actualizaciondebeisbol.com. Hit.
- 66.237.236.243: mygadgettech.com. Hit.
- 66.237.236.247: comunidaddenoticias.com. Hit.
- 66.237.236.249: sumerjaseahora.com. Hit.
69.84.156.90 stickshiftnews.com. Found with: 2013 DNS Census virtual host cleanup heuristic keyword searches. Tested viewdns.info range: 69.84.156.64 - 69.84.156.95
- 69.84.156.69: al-ashak-news-me.com. Hit.
- 69.84.156.70: theventurenews.info. No archives. business.
- 69.84.156.71: worldfinancetoday.net. Hit.
- 69.84.156.72: autonewsarabia.com. Hit.
- 69.84.156.74: blue-moon-news.com. Hit.
- 69.84.156.75: theoutergreen.com. No archives. Might have been another golf hit.
- 69.84.156.76: tnc-urdu.com. Hit.
- 69.84.156.79: jassimnews.com. No archives/broken.
- 69.84.156.80: noticiasdenuestromundo.com. No archives. Spanish. news.
- 69.84.156.82: arabicnewsonline.com. Hit.
- 69.84.156.83: unganadormundial.com. Hit.
- 69.84.156.84: focusonbokeh.com. No archives/broken. Only a "Sony" logo remains: web.archive.org/web/20110207222330/http://focusonbokeh.com/images/logo_014.jpg
- 69.84.156.85: classic-rocktopia.com. No archives. Presumably rock climbing.
- 69.84.156.87: i7diver.com. No archives.
- 69.84.156.88: diariodeelmundo.com. Hit.
- 69.84.156.89: todaysarabnews.com. Hit.
- 69.84.156.90: stickshiftnews.com. Hit.
- 69.84.156.91: theinternationalgoal.com. Hit.
74.116.72.236 techtopnews.com. Found with: 2013 DNS Census virtual host cleanup heuristic keyword searches. Tested viewdns.info range: 74.116.72.215 - 74.116.72.254
- 74.116.72.199: newsungraphics.com. Legit.
- 74.116.72.209: newsung.com. Legit/broken.
- 74.116.72.214: ofinancialinc.com. Legit.
- 74.116.72.219: stockpromoters.com. Legit.
- 74.116.72.227: dayenews.com. hit.
- 74.116.72.229: guide-daventure.com. Hit.
- 74.116.72.230: spaceage-exchange.com. No archives.
- 74.116.72.231: bleachersfootballnews.com. Hit.
- 74.116.72.232: indirectfreekick.com. Hit.
- 74.116.72.233: wwiichronicles.net. Hit.
- 74.116.72.234: petroleumagenews.com. Hit.
- 74.116.72.235: the-open-book-online.com. Hit.
- 74.116.72.236: techtopnews.com. Hit.
- 74.116.72.237: noticiasdiariasdedeportes.com. No archives. Sad, another potential Brazil hit.
- 74.116.72.238: pohandakhbar.com. No archives. TODO meaning. "akhbar" is news in Arabic. But what is "Poh"? Sounds like a South Asian name.
- 74.116.72.239: crickettoday.info. Hit.
- 74.116.72.240: zafernews.com. Hit.
- 74.116.72.241: itechnewstoday.com. Broken/GoDaddy takeover
- 74.116.72.242: gdgtsource.com. Hit.
- 74.116.72.243: waronfilmonline.com. No archives.
- 74.116.72.244: arborstribune.org. No archives.
- 74.116.72.245: wineenthusiastonline.com. Welcome to the US Petabox.
- 74.116.72.246: vuvuzelanews.com. Hit.
- 74.116.72.247: ballbatstumpsandbails.com. Hit.
- 74.116.72.248: kioni-sailing.com. No archives.
- 74.116.72.249: round-trip-travel.com. Hit.
- 74.116.72.250: arabicnewsource.com. Hit.
74.254.12.168 non-stop-news.net. Found with: 2013 DNS Census virtual host cleanup heuristic keyword searches. Tested viewdns.info range: 74.254.12.158 - 74.254.12.195. This domain exceptionally also has a second IP also with multihits: 207.239.196.230. The fact that the range has rdns sources with hits from both 2013 DNS Census and viewdns.info suggests this range is correct.
- 74.254.12.163: half-court.net. Hit.
- 74.254.12.163: dailywellnessnews.com. Hit.
- 74.254.12.165: dylandon.net. Hit. rdns source: viewdns.info.
- 74.254.12.166: afghanpoetry.net. Hit.
- 74.254.12.168: non-stop-news.net. Hit.
- 74.254.12.169: soldiersofsouthasia.com. Hit.
- 74.254.12.170: greek-news.info. 2013. Welcome to the US Petabox. rdns source: viewdns.info
- 74.254.12.171: autism-news.org. Hit.
- 74.254.12.172: thesportsguidebook.com. rdns source: 2013 DNS Census. Only has archive of one subpage: 2009. English. sports.
- 74.254.12.174: reliefline.info. web.archive.org/web/20090416064302/http://www.reliefline.info:80/ Archive too broken.
- 74.254.12.176: pakcricketgrd.com. Hit.
- 74.254.12.177: networkofnews.com. Hit.
- 74.254.12.179: wineconnaisseur.net. Hit.
- 74.254.12.180: helpinghandssite.com. Hit.
- 74.254.12.185: newskwest.com. No archives.
- 74.254.12.187: efiinvestment.com. No archives.
- 74.254.12.188: first-tee-golf.com. Hit.
- 74.254.12.189: fabu-foto.com. Hit.
- 74.254.12.190: viptravelabroad.com. Hit.
199.85.212.118 just-kidding-news.com
- 199.85.212.118 rdns source: 2013 DNS Census virtual host cleanup heuristic keyword searches, dnshistory.org (2009-09-23 -> 2011-01-25) and viewdns.info: "location": "United States", "owner": "VIMRO, LLC", "lastseen": "2012-01-11". Tested viewdns.info range: 199.85.212.95 - 199.85.212.128. Not sure worth it given the many 2013 DNS Census misses surrounding.
- 199.85.212.98: colorsxpress.com. Legit
- 199.85.212.104:
- jobindons.com 2013-10-19.
- piogroup.org 2012-12-29.
- 199.85.212.105: mide-news.com. Hit.
- 199.85.212.109: game2be.com. Infinite load loop: web.archive.org/web/20080102074404/http://www.game2be.com/
- 199.85.212.111:
- newsandsportscentral.com. Hit.
- and many many others, not bothering with it
- 199.85.212.115: veryperi.com. Legit? 2011. Style is similar.
- 199.85.212.116: approselect.com. Legit?
- 199.85.212.117: innovative-software-solutions.com. broken/legit
- 199.85.212.118: just-kidding-news.com. Hit.
- 199.85.212.119: invisus.com. Legit
- 199.85.212.120: allurebyjustine.com. Legit?
- 199.85.212.121: stockprouniversity.com
- 199.85.212.122: stjosephswoodshop.com Legit?
- 199.85.212.125: time-spacer.net. Welcome to the US Petabox.
- 199.85.212.132: qualitytrans.net. Legit?
- 199.85.212.134: mywellnessminder.com. Legit?
- 199.85.212.138: crystalglassinc.com
- 199.85.212.140: davistech-llc.com
- 68.178.232.100: see rastadirect.net. rdns source: viewdns.info: "location": "United States", "owner": "GoDaddy.com, LLC", "lastseen": "2012-06-29"
- 209.85.45.84. Tested viewdns.info range: 209.85.45.74 - 209.85.45.94.
- 209.85.45.2: dz8.dailyrazor.com
- 209.85.45.2: jr4consulting.com
- 209.85.45.41: guitarzza.com. No archives of time.
- 209.85.45.46: evergraindecking.com. No archives of time.
- 209.85.45.114: mauritiuspropertyconsultant.com. Legit/ broken.
- 209.85.45.160: bieltvedt.net. No archives of time.
- 209.85.45.160: golfstats.dk. No archives.
- 209.85.45.225: infokus.ca
- 209.85.45.225: mail.tomlatham.net
- 209.85.45.225: mail.tomlatham.org
- 209.85.45.239: flavacationcenter.com
204.176.38.143 noticiassofisticadas.com. Found with: 2013 DNS Census virtual host cleanup. Tested viewdns.info range: 204.176.38.125 - 204.176.38.154
- 204.176.38.130: i-pressnews.com. Hit.
- 204.176.38.132: turkishnewslinks.com. Hit.
- 204.176.38.134: photographyarecord.com. Hit.
- 204.176.38.135: breakingthewicket.com. Hit.
- 204.176.38.136: politicalworldtoday.com. Hit.
- 204.176.38.137: hi-tech-today.com. Hit.
- 204.176.38.138: continental-business-news.com. TODO. 2011. Cannot find comms. Also header and footer are not limited width which is unusual. Further HTML similarity reversing would be needed.
- 204.176.38.139: bigscreenbattles.com. Hit.
- 204.176.38.141: rakotafootball.com. Hit.
- 204.176.38.142: senderosdemontana.com. Hit.
- 204.176.38.143: noticiassofisticadas.com. Hit.
- 204.176.38.144: techno-today.com. Hit.
- 204.176.38.145: tickettonews.com. Hit.
- 204.176.38.146: dps-digitalphotosharing.com. Hit.
- 204.176.38.147: theputtingreen.com. Hit.
- 204.176.38.149: sportsnewstodayar.com. Hit.
- 204.176.38.150: kairuafricanews.com. Hit.
204.176.39.115 globalprovincesnews.com. Tested viewdns.info range: 204.176.39.93 - 204.176.39.124
- 204.176.39.97: beamingnews.com. Hit.
- 204.176.39.98: cubriendonoticias.com. Hit.
- 204.176.39.100: rowleyworldpost.com. Hit.
- 204.176.39.101: noticiastopicas.com. No archives.
- 204.176.39.103: economicnewsbuzz.com. Hit.
- 204.176.39.104: spectranewsonline.com. Hit.
- 204.176.39.105: entertainmentnewscompany.com. Hit.
- 204.176.39.107: guidetoelectronics.net. Uncertain. 2010. English. tech, electronics. Possible CGI comms variant.
- 204.176.39.110: arabnewsatdawn.com. Hit.
- 204.176.39.114: messengergalaxy.com. Uncertain. 2011. Would be the first example of something more commercial/service offering we've seen so far. Possible CGI comms variant.
- 204.176.39.115: globalprovincesnews.com. Hit.
- 204.176.39.116: mahparah-news.com. Hit.
- 204.176.39.119: commercialspacedesign.com. Hit.
207.210.250.132 aeronet-news.com. Found with: 2013 DNS Census virtual host cleanup heuristic keyword searches. Tested viewdns.info range: 207.210.250.126 - 207.210.250.157
- 207.210.250.131: starrynightnews.com. Hit.
- 207.210.250.132: aeronet-news.com. Hit.
- 207.210.250.133: bakaribulletin.com. Hit.
- 207.210.250.134: deprensaenlarevisiondehoy.com. Hit.
- 207.210.250.135: icwb-news.com. Hit.
- 207.210.250.136: sportsreelhighlights.com. Hit.
- 207.210.250.137: fashionforward.info. No archives.
- 207.210.250.138: inquiry-human-past.com. Hit.
- 207.210.250.139: thefairwaysaregreen.com. Hit.
- 207.210.250.142: russiaupdate.com 2011-11-13. No archives of the time, only older unrelated archives: web.archive.org/web/20010429003443/http://russiaupdate.com/.
- 207.210.250.143: archaeologyreview.net. Hit.
- 207.210.250.144: highspeed-news.com. No archives.
- 207.210.250.146: noticias-caracas.com. Hit.
- 207.210.250.147: bailandstump.com. Hit.
- 207.210.250.148: classicalmusic4arab.com. No archives.
- 207.210.250.149: globalventurestat.com. Hit.
- 207.210.250.152: al-rashidrealestate.com. Hit.
- 207.210.250.153: newsintheworld-ru.com. Hit.
- 207.210.250.154: news-unlimited.info. No archives. Shame, as perfect theme, and has per ipinf.ru/domains/207.210.250.154/
208.254.40.117 worldnewsandent.com. whois.arin.net/rest/net/NET-208-192-0-0-1/pft?s=208.254.40.117: Net Range 208.192.0.0 - 208.255.255.255. Tested viewdns.info range: 208.254.40.92 - 208.254.40.135
- 208.254.40.96: sixty2media.com. Hit.
- 208.254.40.99: newspoliticssource.com. Hit.
- 208.254.40.110 musical-fortune.net. Hit.
- 208.254.40.113: ashoka-gemstones.com. Hit.
- 208.254.40.117: worldnewsandent.com. Hit.
- 208.254.40.124: riskandrewardnews.com. Hit.
- 208.254.40.129: mailb.casella.com. Legit.
208.254.42.205 driversinternationalgolf.com. Not too far from 208.254.40.117 right? Tested viewdns.info range: 208.254.42.178 - 208.254.42.233.
- 208.254.42.35: mystorytimefriends.com. Broken/legit.
- 208.254.42.194: it-proonline.com. Hit.
- 208.254.42.200: riccs.mwcog.org. Legit. Reverse IP source: 2012 Internet Census, 2012-05-14.
- 208.254.42.205: driversinternationalgolf.com. Hit.
- 208.254.42.209: mardelsurnoticias.com. Hit. Reverse IP source: viewdns.info
- 208.254.42.215: nowfreshfinances.com. Hit.
- 208.254.42.216: circulatingnews.net. Hit.
- 208.254.42.219: westingtonpassnews.com. Hit. Reverse IP source: 2013 DNS Census
- 208.254.44.155: brandimpact.com. Legit/broken: web.archive.org/web/20070801000000*/brandimpact.com
- 208.254.45.105: operatorenum.com. Legit/broken: web.archive.org/web/20100301000000*/operatorenum.com
210.80.75.55 philippinenewsonline.net. Tested viewdns.info range: 210.80.75.30 - 210.80.75.67
- 210.80.75.35: aroundtheworldnews.net. No archives. ipinf.ru/domains/210.80.75.33/ disagrees and places it at .33.
- 210.80.75.36: e-commodities.net. Hit.
- 210.80.75.37: trekkingtoday.com. Hit.
- 210.80.75.41: multinews-33.com. Hit.
- 210.80.75.42: movimientodenticias.com. No archives.
- 210.80.75.43: gulfandmiddleeastnews.com. Hit.
- 210.80.75.44: whirlybirdinflight.com. Hit.
- 210.80.75.45: kings-game.net. Hit.
- 210.80.75.46: topglobalnewsdaily.com. Hit.
- 210.80.75.49: recipe-dujour.com. Hit.
- 210.80.75.53: sportsman-elite.com. No archives.
- 210.80.75.55: philippinenewsonline.net. Hit.
- 210.80.75.56: technewsforme.com. Hit.
- 210.80.75.59: goldeportesnoticias.com. No archives.
- 210.80.75.68: gigabyte-usa.com. Legit.
212.4.16.232 mynewscheck.com. Found with: 2013 DNS Census virtual host cleanup heuristic keyword searches. Tested viewdns.info range: 212.4.16.214 - 212.4.17.10.Other hits:
- 212.4.16.224: lanoticiasdehoyelinforme.com. Hit.
- 212.4.16.232: mynewscheck.com. Hit.
- 212.4.16.239: saktimarsgolf.com 2012-06-29. Broken/legit/no archives of relevant date: web.archive.org/web/20081031060207/http://saktimarsgolf.com/
- 212.4.16.245: financial-crisis-news.com. Hit.
- 212.4.16.252: minutosdenoticias.com. Hit. web.archive.org/web/20100517151612/http://minutosdenoticias.com/
- 208.91.197.132. rdns source: viewdns.info: "location" : "British Virgin Islands", "owner" : "Confluence Networks Inc", "lastseen" : "2013-09-26". So this is after the previous one, unlikely to be correct.
- 205.178.189.131. source: securitytrails.com
212.4.17.38 fightwithoutrules.com. whois.arin.net/rest/net/NET-208-192-0-0-1/pft?s=208.254.40.117. Net Range: 208.192.0.0 - 208.255.255.255. Organization: Name: Verizon Business. Tested viewdns.info range: 212.4.17.8 - 212.4.17.79There were also some other reverse IP hits for fightwithoutrules.com, but no CIA websites there:
- 212.4.17.41: newtechfrontier.com. Hit.
- 212.4.17.43: smart-travel-consultant.com. Hit.
- 212.4.17.46: atentlaloc.com. Hit.
- 212.4.17.53: newsresolution.net. Hit.
- 212.4.17.56: lesummumdelafinance.com. Hit.
- 212.4.17.56: thepinnacleoffinance.com. No Wayback machine archives.
- 212.4.17.61: tech-stop.org. Archive: 2011. Feels likely. No commons found. .org hit? Has subdomain "gear.tech-stop.org" according to 2013 DNS Census, which suggests CGI comms, but no links to it
- 212.4.17.98: topbillingsite.com. Hit.
- 212.4.17.122: b2bworldglobal.com. Hit.
- 204.11.56.25 - British Virgin Islands - Confluence Networks Inc - 2013-09-26. Many domains.
- 208.91.197.19 - British Virgin Islands - Confluence Networks Inc - 2013-05-20. Many domains.
212.4.18.129 sightseeingnews.com. Found with: 2013 DNS Census virtual host cleanup heuristic keyword searches. Tested viewdns.info range: 212.4.18.115 - 212.4.18.148. TODO expand. Interesting wide/sparse range? Or perhaps it's two separate ranges?
- 212.4.18.129: sightseeingnews.com. Hit. Presumably also present under fgnl.net on its second IP range, since this is near 212.4.18.133? viewdns.info gives this as the only IP for the domain.
- 212.4.30.210: iprintitaly.com. Legit: web.archive.org/web/20230000000000*/http://www.iprintitaly.com/
212.209.74.105 globalbaseballnews.com. Tested viewdns.info range: 212.209.74.100 - 212.209.74.132. Found with: 2013 DNS Census virtual host cleanup heuristic keyword searches
- 212.209.74.105: globalbaseballnews.com. Hit.
- 212.209.74.106: football-de-luxe.com. Hit.
- 212.209.74.111: worldconcerns.info. No archives.
- 212.209.74.112: developmental-league.com. Unclear. CGI comms variant? 2010. English. CGI. American football.
- 212.209.74.115: mediocampodefutbol.com. Hit.
- 212.209.74.117: myengineeringaffinity.com. Hit.
- 212.209.74.122: atthemovies.biz. Archive very broken. Has link to unarchived JAR: web.archive.org/web/20110809232811oe_/http://www.atthemovies.biz/movieslides.jar. Would have been the fist .biz hit found: Non .com .net TLDs
- 212.209.74.123: worldfinancialexchangenews.com. Hit.
- 212.209.74.124: urouttahere.com. No archives. Meaning presumably "you're out of here"? One wonders what the theme would have been!
- 212.209.74.125: avoilurefixe.com. Hit.
- 212.209.74.126: headlines2day.com. Hit.
- 118.139.174.11. Reverse IP source: viewdns.info
- 118.139.174.11: 712 domain hits on it
- 118.139.174.21: theargentineanwineco.com 2013-09-26. No Wayback machine archive.
- nothing else on the +-20 range
- 184.168.221.91. Reverse IP source: 2013 DNS Census
- 184.168.221.91: 40k hits on 2013 DNS Census
- 118.139.174.11. Reverse IP source: viewdns.info
- 212.209.74.127: construction-zones.com. Unclear. CGI comms variant? 2009. No known comms found. English. construction. Has a login page: web.archive.org/web/20091130144158/http://construction-zones.com/login.html so maybe CGI comms variant
212.209.79.40 hydradraco.com. Found with: visual inspection of full 2013 DNS Census virtual host cleanup list just after globalbaseballnews.com. Tested viewdns.info range: 212.209.79.35 - 212.209.79.63
- 212.209.79.34: fgnl.net. Hit. securitytrails.com provides IP history:both under MCI Communications Services, Inc. d/b/a Verizon Business.
- 212.209.79.34: 2008-09-01 - 2010-04-19.
- 212.4.18.133: 2010-04-19 - 2019-06-19. Tested viewdns.info range: 212.4.18.122 - 212.4.18.148
- 212.209.79.37: fitness-sources.com. Hit.
- 212.209.79.40: hydradraco.com. Hit.
- 212.209.79.41: noticiasdelmundolatino.com. Hit.
- 212.209.79.42: suparakuvi.com. Hit.
- 212.209.79.44: myigadgets.net. Unclear. 2010. tech. Contains some helpers to: iGoogle. This page is very interesting. and quite different from the others, as it contains highly specialized functionality. No known comms found. The choice of homepage languages is also very suspicious: Arabic, Farsi, French, Chinese and Spanish.
- 212.209.79.46: cetusdelph.com. Hit.
- 212.209.79.47: willtoworship.com. Hit.
- 212.209.79.48: themvconnection.com. Hit.
- 212.209.79.51: pi-resources.net. Hit.
- 212.209.79.52: newel-adserver.com. Redirects to newel.com which is legit.
- 212.209.79.53: ourscubaworld.com. Hit.
- 212.209.79.58: tech-love-home.com. Hit.
- 212.209.79.60: first-solo-aviation.com. Hit.
- 212.209.79.61: china-destinations.org. Hit.
212.209.90.84 thenewseditor.com. Found with: 2013 DNS Census virtual host cleanup heuristic keyword searches. Tested viewdns.info range: 212.209.90.64 - 212.209.90.99
- 212.209.90.69: worldedgenews.com. Hit.
- 212.209.90.72: talkingpointnews.info. No archives.
- 212.209.90.75: prebitinvestment.com. No archives.
- 212.209.90.77: energy-bulb.com 2011. English. energy. Comms not found, but has unarchived link to: web.archive.org/web/20110128182345/https://webmail.energy-bulb.com/login.html. CGI comms variant?
- 212.209.90.79: freeblink.com. No archives for timerange, then legit.
- 212.209.90.80: nsmovies.net. Hit.
- 212.209.90.82: middleeastjournal.net. Hit.
- 212.209.90.84: thenewseditor.com. Hit.
- 212.209.90.87: newsandweathersource.com. Hit.
- 212.209.90.89: pakisports.com. Hit.
- 212.209.90.90: vriha-aesthetics.com. Hit.
- 212.209.90.92: amishkanews.com. Hit.
- 212.209.90.93: theentertainbiz.com. Hit.
- 212.209.90.94: eurosportssummary.com. Hit.
- 212.209.91.14: teracom.net. Legit
216.105.98.152: modernarabicnews.com. Found with: 2013 DNS Census virtual host cleanup heuristic keyword searches. Tested viewdns.info range: 216.105.98.125 - 216.105.98.167
- 216.105.98.118:
- estudashboard.com: broken
- fintrade.us: legit
- 216.105.98.132: europeantravelcafe.com. Likely a hit, but comms not found. 2010. English. Europe. travel. Marked copyright 2009. There's a currency converter at: web.archive.org/web/20100724024644/http://www.europeantravelcafe.com/tools.html which could be suspicious.
- 216.105.98.134: fuenteneta.com. No archives.
- 216.105.98.135: ilat-news.com. No archives.
- 216.105.98.136: etherealinspirations.net. No archives.
- 216.105.98.137: the-news-zone.com. Archive very broken: web.archive.org/web/20130814194744/http://the-news-zone.com/
- 216.105.98.138: photozoomnews.com. No archives.
- 216.105.98.139: cultura-digital.net. Hit.
- 216.105.98.140: uaeshoppingspree.com. Hit.
- 216.105.98.141: jabarifootball.com. No archives. "Jabari" is a Swahili/Arabic name[ref]
- 216.105.98.142: globalreview-ar.com. No archives. Shame, could have been our first Argentinian site.
- 216.105.98.144: garanziadellasicurezza.com. Archives quite broken: web.archive.org/web/20110424044637/http://www.garanziadellasicurezza.com:80/ Unarchived JAR:
/web/20110424044637oe_/http://www.garanziadellasicurezza.com/garanzia.jar
Would be another precious Italy hit... - 216.105.98.145: montanismoaventura.com. Hit.
- 216.105.98.146: large-format-news.com. No archives.
- 216.105.98.147: nepalnewsbrief.com. Hit. dnshistory.org marks it as having IP 2010-03-10 -> 2010-08-15 216.169.148.94 [ref]. This range does feel a bit different from the others, too many broken archives, and relatively early ones too. Explored viewdns.info range: 216.169.148.84 - 216.169.148.104, empty for period.
- 216.105.98.148: teclafinance.com. No archives. One wonders what "tecla" would have stood for. It is Portuguese for "keyboard key", but finance is English so.
- 216.105.98.149: entreman.com: legit? web.archive.org/web/20110128212738/http://entreman.com/
- 216.105.98.152: modernarabicnews.com. Hit.
- 216.105.98.153: global-headlines.com. No archives of the period, then was a legitimate WordPress website for a while.
- 216.105.98.154: everythingcricket.org. Hit.
- 216.105.98.156: familyhealthonline.net. Hit.
- 216.105.98.157: delacorne.com. No archives.
- 216.105.98.158: econfutures.com. No archives.
- 216.105.98.161: kstcloud.com. No archives.
219.90.61.123 journeystravelled.com Tested viewdns.info range: 219.90.61.100 - 219.90.61.133
- 219.90.61.100: pressstory.com: "Under construction". web.archive.org/web/20110128124548/http://pressstory.com/
- 219.90.61.103: bet2plays.com. "Under construction". Unlikely thematic, too spicy.
- 219.90.61.110: surya-brahma.com. Hit
- 219.90.61.111: classicalmusicboxonline.com. Hit.
- 219.90.61.116: athletepro.net. Hit.
- 219.90.61.117: lajornadanow.com. Hit.
- 219.90.61.119: aviation-navigation.com. No archives.
- 219.90.61.120: theinternationalworld.com. Hit.
- 219.90.61.121: thepyramidnews.com. Hit.
- 219.90.61.122: iran-newslink-today.com. Hit.
- 219.90.61.123: journeystravelled.com. Hit.
219.90.62.243 fitness-dawg.com. whois.arin.net/rest/net/NET-219-0-0-0-1/pft?s=219.90.62.243. Net Type: Allocated to APNIC. Tested viewdns.info range: unknown - 219.90.62.255
- 219.90.62.173:
- dominatingduos.com: 2013-08-12T17:53:09. No archive
- has other domains
- 219.90.62.193: centralnewsreleasers.com. Only a 2018 of the robots.txt: web.archive.org/web/*/http://centralnewsreleasers.com/* so likely not a hit
- 219.90.62.209: penniesbythemillions.com. No archives.
- 219.90.62.229: information-junky.com. Hit.
- 219.90.62.231: todosperuahora.com. Hit.
- 219.90.62.232: race26point2.com. Hit. No archives, but has subdomain: secure.race26point2.com, so likely CGI comms.
- 219.90.62.233: theworld-news.net. Hit.
- 219.90.62.234: recuerdosdeviajeonline.com. Hit
- 219.90.62.235: ordenpolicial.com. No Wayback Machine archives. Last resolved: 2012-01-11.
- 219.90.62.237: elcorreodenoticias.com. Hit.
- 219.90.62.238: freshtechonline.com. Hit.
- 219.90.62.240: cityworldnewsnow.com. Hit. No archives but has subdomain: secure.cityworldnewsnow.com so likely CGI comms.
- 219.90.62.241: newscentertoday.com. Hit.
- 219.90.62.242: ride-captain.com. Hit.
- 219.90.62.244: easytraveleurope.com. Hit.
- 219.90.62.245: world-news-now.net. Hit.
- 219.90.62.246: negativeaperture.com. Hit.
- 219.90.62.247: conquermstoday.com. Hit
- 219.90.62.249: forensic-exchange.com. 2013 archive: web.archive.org/web/20130714094026/http://forensic-exchange.com/. Appears to be a buggy Wayback Machine archive somehow, so inconclusive.
A tiny idealized magnet! It is a very good model if you have a small strong magnet interacting with objects that are far away, notably other magnetic dipoles or a constant magnetic field.
The cool thing about this model is that we have simple explicit formulas for the magnetic field it produces, and for how this little magnet is affected by a magnetic field or by another magnetic dipole.
This is the perfect model for electron spin, but it can also be representative of macroscopic systems in the right circumstances.
The intuition for the name is likely that "dipole" means "both poles are on the same spot".
Login without password: askubuntu.com/questions/915585/how-to-login-mysql-shell-when-mysql-have-no-passwordworks on Ubuntu 20.10.
sudo mysql
Create user for further logins without
sudo
askubuntu.com/questions/915585/how-to-login-mysql-shell-when-mysql-have-no-password/1325689#1325689:sudo mysql -e "CREATE USER $USER"
Run command from CLI stackoverflow.com/questions/1602904/how-do-you-run-a-single-query-through-mysql-from-the-command-line
mysql -e 'SHOW DATABASES'
Create test user with password:and login as that user:Login with password given on the command line:The
sudo mysql -e 'CREATE USER user0 IDENTIFIED WITH mysql_native_password BY "a"'
sudo mysql -e 'GRANT ALL PRIVILEGES ON database_name.* TO "user0"'
mysql -u user0 -p
mysql -u user0 -pmypassword
IDENTIFIED WITH mysql_native_password
part is to overcome "Client does not support authentication protocol requested by server" when connecting from Node.js.List users:
sudo mysql -e 'SELECT * FROM mysql.user'
View permissions for each user on each DB: serverfault.com/questions/263868/how-to-know-all-the-users-that-can-access-a-database-mysql
sudo mysql -e 'SELECT * FROM mysql.db'
List databases:
sudo mysql -e 'SHOW DATABASES'
Create database:
sudo mysql -e 'CREATE DATABASE mydb0'
Destroy database:
sudo mysql -e 'DROP DATABASE mydb0'
Show tables in database:or:
sudo mysql -e 'SHOW TABLES' mydb0
sudo mysql -e 'SHOW TABLES FROM mydb0'
Likely hits possible but whose archives is too broken to be easily certain. If:were to ever be found, these would be considered hits.
- nearby IP hits
- proper reverse engineering of their comms if any, or any other page fingerprints
- 216.97.231.56 nouvelles-d-aujourdhuis.com. 2011. Stylistically perfect, but no nearby IP hits. Maybe looking into HTML would help confirm:But wrong IP? likely CGI comms variant under the signup page: web.archive.org/web/20090405045548/http://nouvelles-d-aujourdhuis.com/members.html.
rss-items
Tested viewdns.info range: 216.97.231.46 - 216.97.231.66. Not a single reverse IP hit in there.viewdns.info also assigns it 50.63.202.46, GoDaddy.com, LLC, 2013-11-08 in addition to 216.97.231.56, Canada, IPXO LLC, 2013-09-06. This is very near other iranfootballsource.com flukes, so likely useless.securitytrails.com also gives it one earlier IP 209.200.240.250 last seen 2008-09-20: securitytrails.com/domain/nouvelles-d-aujourdhuis.com/history/a Hydra Communications Ltd before 216.97.231.56 "ASU doctor" first seen 2008-09-20 (15 years)> Tested viewdns.info range: 209.200.240.240 - 209.200.240.260 empty at the time of interest.Marked copyright 2006, so mega early.
africainnews.com
- no archives of the HTML
- SWF. A reverse engineering of the SWF should be able to confirm.
- web.archive.org/web/20111007194814/http://africainnews.com/robots.txt
- dnshistory.org/historical-dns-records/a/africainnews.com
- 2009-12-29 -> 2010-07-28 72.167.232.43. Tested viewdns.info range: 72.167.232.33 - 72.167.232.53. Several virtual hosts there.
- 2011-10-14 -> 2011-10-14 68.178.232.100 virtual
- 2012-08-12 -> 2012-08-12 97.74.42.79. Tested viewdns.info range: 97.74.42.69 - 97.74.42.89
- 97.74.42.74: landtex.net 2023-03-22
- 97.74.42.76: solidasshonky.com 2023-03-07
- 97.74.42.77: solidasshonky.com 2023-03-07
- 97.74.42.78: blakebrothers.co 2018-05-05
- 97.74.42.78: learningjbe.com 2023-02-02
- 97.74.42.78: solidasshonky.com 2023-03-07
- 97.74.42.78: sourceuae.com 2023-03-07
- 97.74.42.78: superiorfoodservicesales.com 2017-09-10
- 97.74.42.79: large virtual
- 97.74.42.80: waiasialtd.com 2016-10-17
- viewdns.info/iphistory/?domain=africainnews.com
- 50.63.202.92 United States AS-26496-GO-DADDY-COM-LLC 2013-06-30. Likely large virtual.
- 97.74.42.79 United States AS-26496-GO-DADDY-COM-LLC 2013-05-20. tested.
- 68.178.232.100 United States AS-26496-GO-DADDY-COM-LLC 2012-06-29 virtual
- 68.178.232.99 United States AS-26496-GO-DADDY-COM-LLC 2011-11-13
- 68.178.232.100 United States AS-26496-GO-DADDY-COM-LLC 2011-10-09 virtual
- 72.167.232.43 United States GO-DADDY-COM-LLC 2011-09-08. Tested.
globalsentinelsite.com
- dnshistory.org/historical-dns-records/a/globalsentinelsite.com 2010-02-13 -> 2010-08-04 74.124.210.249 unknown
- viewdns.info/iphistory/?domain=globalsentinelsite.com 74.124.210.249 United States INMOTION 2011-11-13 unknownviewdns.info/reverseip/?host=74.124.210.249&t=1 has 347 hits
todaysolar.com. This might just be legit, but keeping it around just in case.
2011 | JAR | dnshistory.org/historical-dns-records/a/todaysolar.com 2009-08-11 -> 2011-03-01 74.208.62.112 unknown | viewdns.info/iphistory/?domain=todaysolar.com 74.208.62.112 United States PROFITBRICKS-USA 2012-11-12 |
Grepping the 2013 DNS Census first by overused CGI comms subdomains
secure.
and ssl.
leaves 200k lines. Grepping for the overused "news" led to hits:- secure.worldnewsandent.com,2012-02-13T21:28:15,208.254.40.117
- ssl.beyondnetworknews.com,2012-02-13T20:10:13,66.104.175.40
Also tried but failed:
sports
:- secure.motorsportdealers.com,2012-04-10T20:19:09,64.73.117.38 web.archive.org/web/20110501000000*/motorsportdealers.com
OK, after the initial successes in New results: only one...
secure.
, we went a bit more data intensive:- took all
secure.*
ssl.*
URLs in the 2013 DNS Census, 70k entries - cleaned up a bit, e.g. only
.com
or.net
. this left only, 30k entries only - lopped over all of them in archive CDX: Wayback Machine CDX scanning, searching for those that also end in
.cgi
web.archive.org/cdx/search/cdx?url=$domain&matchType=domain&filter=urlkey:.*.cgi&to=20140101000000. Took an afternoon, but no rate limit block. - this leaves about 1000, so we loop over all of them manually on web archive with a script, and opened any that had the pattern of very vew hits between 2010 and 2013 only, and on those check for visual/thematic style match. Careful not to make more than 15 requests per minute or else 5 min blacklist!
- 208.254.42.205 secure.driversinternationalgolf.com,2012-02-13T10:42:20,
After 2013 DNS Census virtual host cleanup heuristic keyword searches we later understood why there were so few hits here: the 2013 DNS Census didn't capture the
secure.
subdomains of many domains it had for some reason. Shame, because if it had, this method would have yielded many more results.Dire times require dire methods: cia-2010-covert-communication-websites/cdx-tor.sh.
First we must start the tor servers with the and then use it on a newline separated domain name list to check;This creates a directory
tor-army
command from: stackoverflow.com/questions/14321214/how-to-run-multiple-tor-processes-at-once-with-different-exit-ips/76749983#76749983tor-army 100
./cdx-tor.sh infile.txt
infile.txt.cdx/
containing:infile.txt.cdx/out00
,out01
, etc.: the suspected CDX lines from domains from each tor instance based on the simple criteria that the CDX can handle directly. We split the input domains into 100 piles, and give one selected pile per tor instance.infile.txt.cdx/out
: the final combined CDX output ofout00
,out01
, ...infile.txt.cdx/out.post
: the final output containing only domain names that match further CLI criteria that cannot be easily encoded on the CDX query. This is the cleanest domain name list you should look into at the end basically.
Since archive is so abysmal in its data access, e.g. a Google BigQuery would solve our issues in seconds, we have to come up with creative ways of getting around their IP throttling.
The CIA doesn't play fair. They're actually the exact opposite of fair. So neither shall we.
Distilled into an answer at: stackoverflow.com/questions/14321214/how-to-run-multiple-tor-processes-at-once-with-different-exit-ips/76749983#76749983
This should allow a full sweep of the 4.5M records in 2013 DNS Census virtual host cleanup in a reasonable amount of time. After JAR/SWF/CGI filtering we obtained 5.8k domains, so a reduction factor of about 1 million with likely very few losses. Not bad.
5.8k is still a bit annoying to fully go over however, so we can also try to count CDX hits to the domains and remove anything with too many hits, since the CIA websites basically have very few archives:This gives us something like:sorted by increasing hit counts, so we can go down as far as patience allows for!
cd 2013-dns-census-a-novirt-domains.txt.cdx
./cdx-tor.sh -d out.post domain-list.txt
cd out.post.cdx
cut -d' ' -f1 out | uniq -c | sort -k1 -n | awk 'match($2, /([^,]+),([^)]+)/, a) {printf("%s.%s %d\n", a[2], a[1], $1)}' > out.count
12654montana.com 1
aeronet-news.com 1
atohms.com 1
av3net.com 1
beechstreetas400.com 1
New results from a full CDX scan of 2013-dns-census-a-novirt.csv:
- 219.90.61.123 journeystravelled.com
These come with pre-installed drivers, so e.g. nvidia-smi just works on them out of the box, tested on g5.xlarge which has an Nvidia A10G GPU. Good choice as a starting point for deep learning experiments.
Experiments that involve sequencing bulk DNA found in a sample to determine what species are present, as opposed to sequencing just a single specific specimen. Examples of samples that are often used:
- river water to determine which bacteria are present, notably to determine if the water is free of dangerous bacteria. A concrete example is shown at: Section "How to use an Oxford Nanopore MinION to extract DNA from river water and determine which bacteria live in it".
- sea water biodiversity: ocean-microbiome.embl.de/companion.html
- food, including searching for desirable microorganisms such as in cheese or bread yeast
- poo, e.g. to study how the human microbiome influences health. There are companies actively working on this, e.g.: www.microbiotica.com/
One related application which most people would not consider metagenomics, is that of finding circulating tumor DNA in blood to detect tumors.
For this sub-case, we can define the Lie algebra of a Lie group as the set of all matrices such that for all :If we fix a given and vary , we obtain a subgroup of . This type of subgroup is known as a one parameter subgroup.
The immediate question is then if every element of can be reached in a unique way (i.e. is the exponential map a bijection). By looking at the matrix logarithm however we conclude that this is not the case for real matrices, but it is for complex matrices.
TODO example it can be seen that the Lie algebra is not closed matrix multiplication, even though the corresponding group is by definition. But it is closed under the Lie bracket operation.
It appears that Maxwell's equations can be derived directly from Coulomb's law + special relativity:
This idea is suggested by the charged particle moving at the same speed of electrons thought experiment, which indicates that magnetism is just a consenquence of special relativity.
Design software for synthetic biological circuit.
The input is in Verilog! Overkill?
Then it essentially maps to a standard cell library of biological primitives!
Ciro Santilli's jaw dropped when he learned about this concept. A Small Talent for War, are you sure?
Unlisted articles are being shown, click here to show only listed articles.