Possible attack from 198.137.241.197 – IP appears to belong to the WhiteHouse?

Home Forums Wordfence Support Questions Possible attack from 198.137.241.197 – IP appears to belong to the WhiteHouse?

This topic contains 5 replies, has 2 voices, and was last updated by  mark 9 months, 1 week ago.

Viewing 6 posts - 1 through 6 (of 6 total)
Author Posts
Author Posts

Rebecca Mecomber

said

Hey! This is my first time in the forums. LOVE the plugin.

I often get emails telling me that WF has detected and blocked a possible SQL Injection attack. Sometimes I check up on the IPs, sometimes I don’t. This time I did. The results are baffling:

Web Page: newyorktraveler.net/
Warning: URL may contain dangerous content!
Offending IP: 198.137.241.197 [ Get IP location ]

Offending Parameter: __gads = ID=2d61acce4548d02d:T=1345045601:S=ALNI_MZqjTInnSGUl1dgHIfY1c371-0xDA

I looked up the IP, and its the White House. Of the President of the United States….

HUH?

Anybody got any ideas? Is this a spoofed IP address or is the White House really attacking my website! :S

I’m also a little alarmed that it says that the main URL of my site may contain malicious content. My server and blogs were severely hacked a few months ago so I’m very jumpy. Please help, anyone! Thanks

  • This topic was modified 9 months, 1 week ago by  mark. Reason: Edited the post title for clarity
August 15, 2012 at 9:20 am

mark

said

Hi Rebecca,

I must admit this is one of the more intriguing posts I’ve received this week. That security alert is not a message generated by Wordfence. It is generated by the “WordPress firewall plugin”, but it looks like you may have already figured that out:

http://wordpress.org/support/topic/plugin-wordpress-firewall-2-sql-injection-attack-from-the-white-house-so-says-wp-firewall?replies=2

Julio, who is replying to you on that forum appears to be mistaken based on my research. Several location databases including Maxmind, which is in my opinion the most reputable, show that IP as belonging to the Executive Office of the President of the United States. I’d like to see data suggesting otherwise because I could not find any.

You can look it up yourself here: http://www.maxmind.com/app/locate_demo_ip

I would encourage you to contact the makers of WordPress Firewall and ask them about this, which appears to be a false positive. Here is why:

The “Offending parameter” that they list is the “__gads” cookie which is used by “DoubleClick For Publishers – Small Business” which is a division of Google. You can find out more about it here:

http://support.google.com/dfp_sb/bin/answer.py?hl=en&answer=2551880

So it looks like Mr President may have clicked an ad which brought him to your site and DFP included a query string parameter called “__gads” for tracking purposes so that any DFP code you may have running on your site could set a cookie. Or maybe it was the janitor, who knows.

Either way I think I’d be pretty happy to get the Whitehouse visiting my site. Congrats on being interesting enough for that. It’s unfortunate though that this message makes it appear that WordPress Firewall blocked them from actually visiting your site. I’m not sure how that plugin works, but that’s at least what the message suggests.

Hope that helps, let me know if you have more questions, or found any data conflicting with my hypotheses above. I’m sure the community here may also have some input, perhaps this is something they’ve seen before. By the way, I’m going to change the Title on this topic to be a little more descriptive in case someone else has this issue, so hope you don’t mind.

Regards,

Mark.

August 15, 2012 at 10:20 am

Rebecca Mecomber

said

Mark, thank you for your kind reply. Yes, after posting the thread here, I realized (with much chagrin) that I had the plugin names confused. Still, I love WordFence and thank God it protects me from all the attacks! It’s saved my websites many times since I installed it in May. So thanks for a great plugin. I’m still in the “testing” stage and will probably purchase it for added protection. I really appreciate you offering such a good plugin for free, too.

In reading your response, Mark– it brings up even more questions! I do not have any advertisements for my website, that I am aware of! I would love to have the executive office visiting my site… but I don’t know where they are coming from and exactly why they are rebuffed.

August 15, 2012 at 11:15 am

Rebecca Mecomber

said

Just as an aside, the IP visit was very attack-like. I got about 100 “blocked and detected notices” from Firewall all within a two minute interval.

August 15, 2012 at 11:17 am

mark

said

Interesting thanks for sharing Rebecca. If you like you can email me those log entries to mark@wordfence.com. It’s possible it is something like a caching proxy that is “pre loading” data very rapidly by doing a kind of crawl. Or it could be that you have pages on your site that include other content on the site (like in iframes for example) so it appears that you’re getting many page hits when it fact it’s one page that loads multiple URL’s.

I’m always interested in seeing what the Whitehouse is up to ;-) so I’d like to see what kind of traffic you got from that IP.

And moving into crazy conspiracy theory territory… maybe one of their servers was compromised and is in fact being used as an attack platform. Now wouldn’t it be cool if we broke that story? Highly unlikely of course.

Regards,

Mark.

August 15, 2012 at 12:40 pm

mark

said

Just for fun I wanted to update this.

I did some research at ARIN and found that the owner of this block of IP addresses is:

Name Executive Office Of The President
Handle EXOP
Street 725 17th Street, NW
City Washington
State/Province DC
Postal Code 20503
Country US
Registration Date 1993-05-21
Last Updated 2012-08-15

They own the following blocks of IP’s:

MBOE-A (NET6-2620-10F-B000-1) 2620:10F:B000:: – 2620:10F:B0FF:FFFF:FFFF:FFFF:FFFF:FFFF
EOPNET-B (NET-165-119-0-0-1) 165.119.0.0 – 165.119.255.255
NETBLK-EOPNET-C (NET-198-137-240-0-1) 198.137.240.0 – 198.137.241.255
MOHAWK (NET-204-68-207-0-1) 204.68.207.0 – 204.68.207.255

Here’s the full entry: http://whois.arin.net/rest/org/EXOP/pft

EOPNET-B is a big one which is over 65,000 addresses. They own everything that starts with 165.119.

The other two blocks are smaller , roughly 512 and 255 addresses if you exclude network and broadcast addresses.

The block in question is a block of 512 addresses. Keep in mind that even 1 IP address can have hundreds of thousands of employees behind it if it is a firewall or proxy server, which is most definitely the case for the whitehouse.

What I did find with some Googling is that the http://www.ustr.gov/ or Office of the United States Trade Representative used to be on the block of IP’s that accessed your site. But they’re now on a different block. Just to give you an idea of how diverse the people and services are that are all lumped into the US president’s office.

Regards,

Mark.

  • This reply was modified 9 months, 1 week ago by  mark.
August 15, 2012 at 5:00 pm
Viewing 6 posts - 1 through 6 (of 6 total)

The topic ‘Possible attack from 198.137.241.197 – IP appears to belong to the WhiteHouse?’ is closed to new replies.

About Wordfence

Wordfence is part of Feedjit Inc. based in Seattle Washington in the USA. Our founders are Mark Maunder (CEO) and Kerry Boyte (COO). Feedjit has been providing real-time analytics and real-time ad serving solutions since 2007 and today supports over 700,000 publishers. Our mission with Wordfence is to provide security and peace of mind to WordPress publishers. Please contact us at support@wordfence.com.
Copyright © 2011 to 2012 Wordfence.com. All rights reserved. Please see our Terms of Use & Privacy Policy.