Return-Path: Received: from smtp1.linuxfoundation.org (smtp1.linux-foundation.org [172.17.192.35]) by mail.linuxfoundation.org (Postfix) with ESMTPS id 715F43EE for ; Mon, 17 Aug 2015 18:42:02 +0000 (UTC) X-Greylist: whitelisted by SQLgrey-1.7.6 Received: from mail-oi0-f45.google.com (mail-oi0-f45.google.com [209.85.218.45]) by smtp1.linuxfoundation.org (Postfix) with ESMTPS id 8052411E for ; Mon, 17 Aug 2015 18:42:01 +0000 (UTC) Received: by oiew67 with SMTP id w67so67163771oie.2 for ; Mon, 17 Aug 2015 11:42:01 -0700 (PDT) X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20130820; h=x-gm-message-state:mime-version:from:date:message-id:subject:to :content-type; bh=+dKMqsihtizNiSy15qUYGceuVSQxuhkJz+KOAkVe9v8=; b=QaCZLm6AHpaZnWFmUDynhyfa+VSGUR6nhLzc7P7TU3ws0Rlj1wgeDW/M9t6Ald3V01 5xxUqXoPCWWjL9Ub/ycXkjxsMIGgp6p/K8rjrRL7kvsj34iOHzMj2kRlkQqxbppa+z6w 9tK+pcyQ5mDLxurGtDujwi5D0fvmzK0EJMm3bKSPEhiPKYG6VRJN9FVA/+8UBeJmaWCj tQ3K3aw12W82M+JdvzrLNMf20BJ3PCyhwA0M3VxFQ3/rm6mNtp40+J4A3A5b3kJ2Gvit BB79ol1adPC4E2ey4lwPFebVziLRd0snWWIGUCEnkp8fdLNCMOmrLSajyygylBKAljjD lGfw== X-Gm-Message-State: ALoCoQkOpIQZAxEZC7bSrbkovfWLuE0R7C/p8te6SQdliaVQwWn+3e+IBEaVPicKxGRTWC3JZn1Y X-Received: by 10.202.174.141 with SMTP id x135mr2301308oie.50.1439836920769; Mon, 17 Aug 2015 11:42:00 -0700 (PDT) MIME-Version: 1.0 Received: by 10.202.46.147 with HTTP; Mon, 17 Aug 2015 11:41:31 -0700 (PDT) From: Jonathan Wilkins Date: Mon, 17 Aug 2015 11:41:31 -0700 Message-ID: To: bitcoin-dev@lists.linuxfoundation.org Content-Type: multipart/alternative; boundary=001a113cf68032b14a051d86282b X-Spam-Status: No, score=-2.6 required=5.0 tests=BAYES_00,HTML_MESSAGE, RCVD_IN_DNSWL_LOW autolearn=ham version=3.3.1 X-Spam-Checker-Version: SpamAssassin 3.3.1 (2010-03-16) on smtp1.linux-foundation.org Subject: [bitcoin-dev] That email was almost certainly not the real Satoshi X-BeenThere: bitcoin-dev@lists.linuxfoundation.org X-Mailman-Version: 2.1.12 Precedence: list List-Id: Bitcoin Development Discussion List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Mon, 17 Aug 2015 18:42:02 -0000 --001a113cf68032b14a051d86282b Content-Type: text/plain; charset=UTF-8 I'm sure that most people here were skeptical, but FWIW, the server that hosts vistomail.com is a mess, it's a Plesk box with more than a couple of services with dubious security histories. MailEnable smtpd, MSRPC, RDP, see for yourself: Most likely someone popped the box and is entertaining themselves. Nmap scan report for vistomail.com (190.97.163.93) Host is up (0.10s latency). Not shown: 65521 filtered ports PORT STATE SERVICE VERSION 21/tcp open ftp Microsoft ftpd | ssl-cert: Subject: commonName=secureanonymoussurfing.com | Not valid before: 2015-05-03T00:00:00+00:00 |_Not valid after: 2018-05-02T23:59:59+00:00 |_ssl-date: 2015-08-16T00:08:25+00:00; +1m09s from local time. 25/tcp open smtp MailEnable smptd 8.60-- | smtp-commands: vistomail.com [192.241.217.85], this server offers 4 extensions, AUTH LOGIN, SIZE 20480000, HELP, AUTH=LOGIN, |_ 211 Help:->Supported Commands: HELO,EHLO,QUIT,HELP,RCPT,MAIL,DATA,RSET,NOOP 53/tcp open domain Microsoft DNS 6.1.7601 | dns-nsid: |_ bind.version: Microsoft DNS 6.1.7601 (1DB14556) 80/tcp open http Microsoft IIS httpd 7.5 |_http-favicon: Parallels Control Panel | http-methods: Potentially risky methods: TRACE |_See http://nmap.org/nsedoc/scripts/http-methods.html | http-ntlm-info: | Target_Name: DS04 | NetBIOS_Domain_Name: DS04 | NetBIOS_Computer_Name: DS04 | DNS_Domain_Name: DS04 | DNS_Computer_Name: DS04 |_ Product_Version: 6.1 (Build 7601) |_http-title: Domain Default page 110/tcp open pop3 MailEnable POP3 Server |_pop3-capabilities: USER TOP UIDL 135/tcp open msrpc Microsoft Windows RPC 143/tcp open imap MailEnable imapd |_imap-capabilities: completed CAPABILITY AUTH=CRAM-MD5 CHILDREN UIDPLUSA0001 AUTH=LOGIN IMAP4rev1 OK IDLE IMAP4 443/tcp open ssl/http Microsoft IIS httpd 7.5 |_http-favicon: Parallels Control Panel | http-methods: Potentially risky methods: TRACE |_See http://nmap.org/nsedoc/scripts/http-methods.html |_http-title: Domain Default page | ssl-cert: Subject: commonName=secureanonymoussurfing.com | Not valid before: 2015-05-03T00:00:00+00:00 |_Not valid after: 2018-05-02T23:59:59+00:00 |_ssl-date: 2015-08-16T00:08:24+00:00; +1m09s from local time. 587/tcp open smtp MailEnable smptd 8.60-- | smtp-commands: vistomail.com [192.241.217.85], this server offers 4 extensions, AUTH LOGIN, SIZE 20480000, HELP, AUTH=LOGIN, |_ 211 Help:->Supported Commands: HELO,EHLO,QUIT,HELP,RCPT,MAIL,DATA,RSET,NOOP 3389/tcp open ms-wbt-server Microsoft Terminal Service 8443/tcp open https-alt? | ssl-cert: Subject: commonName=Parallels Panel/organizationName=Parallels, Inc./stateOrProvinceName=Virginia/countryName=US | Not valid before: 2015-03-13T19:40:20+00:00 |_Not valid after: 2016-03-12T19:40:20+00:00 |_ssl-date: 2015-08-16T00:08:24+00:00; +1m09s from local time. 8880/tcp open http Microsoft IIS httpd 7.5 |_http-favicon: Parallels Control Panel |_http-methods: No Allow or Public header in OPTIONS response (status code 500) |_http-title: Site doesn't have a title (text/html; charset=utf-8). 49154/tcp open msrpc Microsoft Windows RPC 49156/tcp open msrpc Microsoft Windows RPC Warning: OSScan results may be unreliable because we could not find at least 1 open and 1 closed port Device type: general purpose|phone Running: Microsoft Windows 2008|7|Phone|Vista OS CPE: cpe:/o:microsoft:windows_server_2008:r2 cpe:/o:microsoft:windows_7::-:professional cpe:/o:microsoft:windows_8 cpe:/o:microsoft:windows cpe:/o:microsoft:windows_vista::- cpe:/o:microsoft:windows_vista::sp1 OS details: Windows Server 2008 R2, Microsoft Windows 7 Professional or Windows 8, Microsoft Windows Phone 7.5 or 8.0, Microsoft Windows Vista SP0 or SP1, Windows Server 2008 SP1, or Windows 7, Microsoft Windows Vista SP2, Windows 7 SP1, or Windows Server 2008 --001a113cf68032b14a051d86282b Content-Type: text/html; charset=UTF-8 Content-Transfer-Encoding: quoted-printable
I'm sure that most people here were skeptical, bu= t FWIW, the server that hosts vistomail.co= m is a mess, it's a Plesk box with more than a couple of services w= ith dubious security histories. MailEnable smtpd, MSRPC, RDP, see for yours= elf:

Most likely someone popped the box and is entertaining t= hemselves.

Nmap scan report for vistomail.com (190.97.163.93)
Host is up (0.10s latency).
Not s= hown: 65521 filtered ports
PORT=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0 STATE SERV= ICE=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0 VERSION
21/tcp=C2=A0=C2=A0=C2=A0= open=C2=A0 ftp=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0= Microsoft ftpd
| ssl-cert: Subject: commonName=3Dsecureanonymoussurfing.com
| Not valid befor= e: 2015-05-03T00:00:00+00:00
|_Not valid after:=C2=A0 2018-05-02T23:59:5= 9+00:00
|_ssl-date: 2015-08-16T00:08:25+00:00; +1m09s from local time.25/tcp=C2=A0=C2=A0=C2=A0 open=C2=A0 smtp=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2= =A0=C2=A0=C2=A0=C2=A0 MailEnable smptd 8.60--
| smtp-commands: vistomail.com [192.241.217.85], this server o= ffers 4 extensions, AUTH LOGIN, SIZE 20480000, HELP, AUTH=3DLOGIN,
|_ 21= 1 Help:->Supported Commands: HELO,EHLO,QUIT,HELP,RCPT,MAIL,DATA,RSET,NOO= P
53/tcp=C2=A0=C2=A0=C2=A0 open=C2=A0 domain=C2=A0=C2=A0=C2=A0=C2=A0=C2= =A0=C2=A0=C2=A0 Microsoft DNS 6.1.7601
| dns-nsid:
|_=C2=A0 bind.vers= ion: Microsoft DNS 6.1.7601 (1DB14556)
80/tcp=C2=A0=C2=A0=C2=A0 open=C2= =A0 http=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0 Microsoft II= S httpd 7.5
|_http-favicon: Parallels Control Panel
| http-methods: P= otentially risky methods: TRACE
|_See http://nmap.org/nsedoc/scripts/http-methods.html=
| http-ntlm-info:
|=C2=A0=C2=A0 Target_Name: DS04
|=C2=A0=C2= =A0 NetBIOS_Domain_Name: DS04
|=C2=A0=C2=A0 NetBIOS_Computer_Name: DS04<= br>|=C2=A0=C2=A0 DNS_Domain_Name: DS04
|=C2=A0=C2=A0 DNS_Computer_Name: = DS04
|_=C2=A0 Product_Version: 6.1 (Build 7601)
|_http-title: Domain = Default page
110/tcp=C2=A0=C2=A0 open=C2=A0 pop3=C2=A0=C2=A0=C2=A0=C2=A0= =C2=A0=C2=A0=C2=A0=C2=A0=C2=A0 MailEnable POP3 Server
|_pop3-capabilitie= s: USER TOP UIDL
135/tcp=C2=A0=C2=A0 open=C2=A0 msrpc=C2=A0=C2=A0=C2=A0= =C2=A0=C2=A0=C2=A0=C2=A0=C2=A0 Microsoft Windows RPC
143/tcp=C2=A0=C2=A0= open=C2=A0 imap=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0 Mail= Enable imapd
|_imap-capabilities: completed CAPABILITY AUTH=3DCRAM-MD5 C= HILDREN UIDPLUSA0001 AUTH=3DLOGIN IMAP4rev1 OK IDLE IMAP4
443/tcp=C2=A0= =C2=A0 open=C2=A0 ssl/http=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0 Microsoft IIS http= d 7.5
|_http-favicon: Parallels Control Panel
| http-methods: Potenti= ally risky methods: TRACE
|_See http://nmap.org/nsedoc/scripts/http-methods.html|_http-title: Domain Default page
| ssl-cert: Subject: commonName=3Dsecureanonymoussurfing.com<= br>| Not valid before: 2015-05-03T00:00:00+00:00
|_Not valid after:=C2= =A0 2018-05-02T23:59:59+00:00
|_ssl-date: 2015-08-16T00:08:24+00:00; +1m= 09s from local time.
587/tcp=C2=A0=C2=A0 open=C2=A0 smtp=C2=A0=C2=A0=C2= =A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0 MailEnable smptd 8.60--
| smtp-c= ommands: vistomail.com [192.241.217.85= ], this server offers 4 extensions, AUTH LOGIN, SIZE 20480000, HELP, AUTH= =3DLOGIN,
|_ 211 Help:->Supported Commands: HELO,EHLO,QUIT,HELP,RCPT,= MAIL,DATA,RSET,NOOP
3389/tcp=C2=A0 open=C2=A0 ms-wbt-server Microsoft Te= rminal Service
8443/tcp=C2=A0 open=C2=A0 https-alt?
| ssl-cert: Subje= ct: commonName=3DParallels Panel/organizationName=3DParallels, Inc./stateOr= ProvinceName=3DVirginia/countryName=3DUS
| Not valid before: 2015-03-13T= 19:40:20+00:00
|_Not valid after:=C2=A0 2016-03-12T19:40:20+00:00
|_s= sl-date: 2015-08-16T00:08:24+00:00; +1m09s from local time.
8880/tcp=C2= =A0 open=C2=A0 http=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0 M= icrosoft IIS httpd 7.5
|_http-favicon: Parallels Control Panel
|_http= -methods: No Allow or Public header in OPTIONS response (status code 500)|_http-title: Site doesn't have a title (text/html; charset=3Dutf-8).=
49154/tcp open=C2=A0 msrpc=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2=A0=C2= =A0 Microsoft Windows RPC
49156/tcp open=C2=A0 msrpc=C2=A0=C2=A0=C2=A0= =C2=A0=C2=A0=C2=A0=C2=A0=C2=A0 Microsoft Windows RPC
Warning: OSScan res= ults may be unreliable because we could not find at least 1 open and 1 clos= ed port
Device type: general purpose|phone
Running: Microsoft Windows= 2008|7|Phone|Vista
OS CPE: cpe:/o:microsoft:windows_server_2008:r2 cpe:= /o:microsoft:windows_7::-:professional cpe:/o:microsoft:windows_8 cpe:/o:mi= crosoft:windows cpe:/o:microsoft:windows_vista::- cpe:/o:microsoft:windows_= vista::sp1
OS details: Windows Server 2008 R2, Microsoft Windows 7 Profe= ssional or Windows 8, Microsoft Windows Phone 7.5 or 8.0, Microsoft Windows= Vista SP0 or SP1, Windows Server 2008 SP1, or Windows 7, Microsoft Windows= Vista SP2, Windows 7 SP1, or Windows Server 2008
--001a113cf68032b14a051d86282b--