You are missing our premiere tool bar navigation system! Register and use it for FREE!

NukeCops  
•  Home •  Downloads •  Gallery •  Your Account •  Forums • 
Readme First
- Readme First! -

Read and follow the rules, otherwise your posts will be closed
Modules
· Home
· FAQ
· Buy a Theme
· Advertising
· AvantGo
· Bookmarks
· Columbia
· Community
· Donations
· Downloads
· Feedback
· Forums
· PHP-Nuke HOWTO
· Private Messages
· Search
· Statistics
· Stories Archive
· Submit News
· Surveys
· Theme Gallery
· Top
· Topics
· Your Account
Who's Online
There are currently, 133 guest(s) and 1 member(s) that are online.

You are Anonymous user. You can register for free by clicking here
Nuke Cops :: View topic - SPAMMER Killing Everyone On JaguarPC [ ]
 Forum FAQ  •  Search  •   •  Memberlist  •  Usergroups   •  Register  •  Profile •    •  Log in to check your private messages  •  Log in

 
Post new topic  Reply to topicprinter-friendly view
View previous topic Log in to check your private messages View next topic
Author Message
Zhen-Xjell
Nuke Cops Founder
Nuke Cops Founder


Joined: Nov 14, 2002
Posts: 5939


PostPosted: Fri Jul 25, 2003 12:50 pm Reply with quoteBack to top

Already alerted JagPC via a dedicated server ticket and their forums: http://jaguarpc.com/forums/showthread.php?s=&threadid=9823

I'm checking my root email and what do I find?

(reason: 550 5.7.1 ... Mail from 66.227.19.111 refused by blackhole site relays.osirusoft.com)

So I go here:

http://relays.osirusoft.com/cgi-bin/rbcheck.cgi

And enter the base IP of my dedicated server running nukecops.com and computercops.biz:

http://relays.osirusoft.com/cgi-bin/rbcheck.cgi

This is the result problem:

[1] Jaguar Technologies, see http://spews.org/ask.cgi?S2763

So I goto Spews and run a check on my IP:

66.227.19.111

What do I find?

Quote:
Jaguar Technologies
|--------------------
1, 66.227.16.0 - 66.227.23.255, Jaguar Technologies (Yipes)
0, 66.227.56.0 - 66.227.63.255, Jaguar Technologies (Yipes)
0, 66.227.64.0 - 66.227.71.255, Jaguar Technologies (Yipes)
0, 66.227.72.0 - 66.227.87.255, Jaguar Technologies (Yipes)
---------------------|

One spammer too many hosting here.

See: <http://groups.google.com/groups?q=22&scoring=d>
<http://groups.google.com/groups?selm=spam-2207031025380001%40csgmac.chem.utoronto.ca>

--------------------------------------------------------------------------------
[66.227.19.150] server1.netprofitleads.com

www.extremepowerline.com has address 65.73.206.81
www.extremepowerline.com has address 65.73.206.82
www.extremepowerline.com has address 65.73.206.86

genovadiscounts.com has address 65.249.65.36

1, 66.227.17.84, Peter DeCaro / i-marketingpro.com (Jaguar Technologies LLC / nocdirect.com)
1, 66.227.17.0/25, Jaguar Technologies LLC / nocdirect.com (Peter DeCaro / i-marketingpro.com)

[66.227.18.1] texas.businessx.com / www.pos2life.biz

1, 64.46.108.35, u-bulk.com
1, 64.46.108.1 - 64.46.108.255, u-bulk.com (aletia.com)
--------------------------------------------------------------------------------
OrgName: Jaguar Technologies LLC
OrgID: JTL-8
Address: 4201 SW Freeway
City: Houston
StateProv: TX
PostalCode: 77478
Country: US

NetRange: 66.227.16.0 - 66.227.23.255
CIDR: 66.227.16.0/21
NetName: YIPS-JTL-8-S020303
NetHandle: NET-66-227-16-0-1
Parent: NET-66-227-0-0-1
NetType: Reassigned
NameServer: NS.NOCDIRECT.COM
NameServer: NS2.NOCDIRECT.COM
Comment:
RegDate: 2003-02-04
Updated: 2003-02-04
--------------------------------------------------------------------------------
OrgName: Jaguar Technologies LLC
OrgID: JTL-8
Address: 4201 SW Freeway
City: Houston
StateProv: TX
PostalCode: 77478
Country: US

NetRange: 66.227.56.0 - 66.227.63.255
CIDR: 66.227.56.0/21
NetName: YIPS-JAGUAR-S082102-2
NetHandle: NET-66-227-56-0-1
Parent: NET-66-227-0-0-1
NetType: Reassigned
NameServer: NS.NOCDIRECT.COM
NameServer: NS2.NOCDIRECT.COM
Comment:
RegDate: 2002-08-22
Updated: 2002-09-25

TechHandle: GL538-ARIN
TechName: Landis, Greg
TechPhone: +1-832-279-5529
TechEmail: admin@jaguarpc.net
--------------------------------------------------------------------------------
OrgName: Jaguar Technologies LLC
OrgID: JTL-8
Address: 4201 SW Freeway
City: Houston
StateProv: TX
PostalCode: 77478
Country: US

NetRange: 66.227.72.0 - 66.227.87.255
CIDR: 66.227.72.0/21, 66.227.80.0/21
NetName: YIPS-JTL-8-A102102
NetHandle: NET-66-227-72-0-1
Parent: NET-66-227-0-0-1
NetType: Reallocated
Comment:
RegDate: 2002-10-21
Updated: 2002-10-21
--------------------------------------------------------------------------------
OrgName: Jaguar Technologies LLC
OrgID: JTL-8
Address: 4201 SW Freeway
City: Houston
StateProv: TX
PostalCode: 77478
Country: US

NetRange: 66.227.64.0 - 66.227.71.255
CIDR: 66.227.64.0/21
NetName: YIPS-JTL-8-S092302
NetHandle: NET-66-227-64-0-1
Parent: NET-66-227-0-0-1
NetType: Reassigned
NameServer: NS.NOCDIRECT.COM
NameServer: NS2.NOCDIRECT.COM
Comment:
RegDate: 2002-09-23
Updated: 2002-09-23
--------------------------------------------------------------------------------
Domain Name: NOCDIRECT.COM

Registrant:
Secure Web Services
SSL Service (admin@nocdirect.com)
4002 sw freeway
Houston
TX,77026
US
Tel. +713.9601581

Creation Date: 13-Jan-2002
Expiration Date: 13-Jan-2004

Domain servers in listed order:
ns.nocdirect.com
ns2.nocdirect.com


Administrative Contact:
Secure Web Services
SSL Service (admin@nocdirect.com)
4002 sw freeway
Houston
TX,77026
US
Tel. +713.9601581

Status: ACTIVE
--------------------------------------------------------------------------------
--- contacting nameserver: ns.nocdirect.com [66.227.57.1]

nocdirect.com MX 0 nocdirect.com
nocdirect.com NS ns.nocdirect.com
nocdirect.com NS ns2.nocdirect.com
nocdirect.com A 66.227.84.185
nocdirect.com SOA
origin = ns.nocdirect.com
mail addr = root@ns.nocdirect.com
serial = 2003052301
refresh = 10800 (3 hours)
retry = 3600 (1 hour)
expire = 604800 (7 days)
minimum ttl = 86400 ()
nocdirect.com A 66.227.84.185
ns.nocdirect.com A 66.227.57.1
ns2.nocdirect.com A 66.227.56.5
--------------------------------------------------------------------------------
Domain name- NOCDNS.COM

Nameservers-
ns1.aletia.com
ns2.aletia.com

Start of registration- Fri May 18 2001 03:50:17
Registered through- Tue May 18 2004 03:50:17

Registrant Contact-
Jaguar Technologies LLC
Domain Administrator (admin@jaguarpc.net)
+1.112816330343
FAX- +1.118885603607
4201 sw freeway
houston, TX 77027
US

Status: PROTECTED
--------------------------------------------------------------------------------
--- contacting nameserver: ns1.aletia.com [66.227.56.34]

nocdns.com MX 0 nocdns.com
nocdns.com SOA
origin = ns.nocdirect.com
mail addr = root@krypton.nocdirect.com
serial = 1035812419
refresh = 28800 (8 hours)
retry = 7200 (2 hours)
expire = 3600000 (41 days 16 hours)
minimum ttl = 86400 ()
nocdns.com NS ns2.nocdirect.com
nocdns.com NS ns.nocdirect.com
nocdns.com A 66.227.83.157
nocdns.com A 66.227.83.157
ns.nocdirect.com A 66.227.57.1
ns2.nocdirect.com A 66.227.56.5
--------------------------------------------------------------------------------
Domain name: ALETIA.COM

Registrant :
Jaguar Technologies LLC
Domain Administrator (admin@jaguarpc.net)
+1.112816330343
FAX: +1.118885603607
4201 sw freeway
houston, TX 77027
US

Status: PROTECTED

Name servers:
NS1.ALETIA.COM
NS2.ALETIA.COM
--------------------------------------------------------------------------------
--- contacting nameserver: ns2.aletia.com [66.227.56.246]

aletia.com SOA
origin = ns1.aletia.com
mail addr = root@ns1.aletia.com
serial = 2002121905
refresh = 28800 (8 hours)
retry = 7200 (2 hours)
expire = 3600000 (41 days 16 hours)
minimum ttl = 86400 ()
aletia.com NS ns1.aletia.com
aletia.com NS ns2.aletia.com
aletia.com NS ns3.aletia.com
aletia.com A 66.227.56.28
aletia.com MX 0 aletia.com
ns1.aletia.com A 66.227.56.34
ns2.aletia.com A 66.227.56.246
ns3.aletia.com A 66.227.56.28
--------------------------------------------------------------------------------


I follow the link to Google Groups:

http://groups.google.com/groups?selm=spam-2207031025380001%40csgmac.chem.utoronto.ca

And sure enough as the above quote says:

Quote:
host server1.netprofitleads.com
server1.netprofitleads.com has address 66.227.19.150

host netprofitleads.com
netprofitleads.com has address 66.227.19.150

[whois.arin.net]
Yipes Communications, Inc. YIPES-BLK5 (NET-66-227-0-0-1)
66.227.0.0 - 66.227.127.255
Jaguar Technologies LLC YIPS-JTL-8-S020303 (NET-66-227-16-0-1)
66.227.16.0 - 66.227.23.255

First spam was advertising:

MMF internet home business @ www.extremepowerline.com

host www.extremepowerline.com
www.extremepowerline.com has address 65.73.206.81
www.extremepowerline.com has address 65.73.206.82
www.extremepowerline.com has address 65.73.206.86

Second spam was advertising:

anabolic steroids @ www.genovadiscounts.com

host www.genovadiscounts.com
www.genovadiscounts.com is an alias for genovadiscounts.com.
genovadiscounts.com has address 65.249.65.36

At first sight, there doesn't appear to be any obvious connection
between netprofitleads and the spam-advertised domains.


This means the entire YIPES/JaguarPC IP Blocks are now BLOCKED in SPEWS. Get ready for your servers not being able to send emails because of these a-hole spammers.

They need to be dealt with IMMEDIATELY as business is now at risk.

The SPEWS FAQ # 42:

Quote:
Q42: My IP address/range is being listed by SPEWS but I'm not a spammer and I just signed up for this/these address(s). What can I do to be removed from the list?
A42: SPEWS is just an automated system, if spam or spam involvement (hosting spammers, selling spamware) from your IP address/range ceases, it will drop out of the list in time. Normally the listing involves spam related problems with your host and the first step you need to take is to complain to them about the listing, in almost all cases, they are the only people who can get an address/range out of the SPEWS list. If there is a spam related problem with your host, their IP address/range will not be removed until it is resolved. If your host or network is certain a listing mistake has been made, ask them to read this FAQ then post a message in a public forum mentioned above with the SPEWS record number (eg. S123) and/or the IP address/range information in it. Placing the text "SPEWS:" in the subject can help a SPEWS editor or developer see the message and they may double check the listing - note that, although others may, no SPEWS editor or developer will ever reply to the posting. Will this get your IP address/range removed from a SPEWS listing? Again, not if there are currently spam related problems with your host. Be aware that posting ones email address to any publicly viewable forum or website makes it instantly available to spammers. If you're concerned about getting spammed, change or "mung" the email address you use to post with.


I have just opened an URGENT dedicated ticket with JagPC on this issue.

Heads up everyone, it seems like we may all be blocked right now. I'm not confirming everyone's IP, but via SPEWS, it seems like the whole blocks are listed.

Test yours here:

http://relays.osirusoft.com/cgi-bin/rbcheck.cgi

And certainly post results. Is this just me? I hope so... but I fear it may not be.

Thanks to www.extremepowerline.com and www.genovadiscounts.com for taking doing this to us.

_________________
Paul Laudanski, Microsoft MVP Windows-Security
CastleCops: [de] [en] [wiki]
Find all posts by Zhen-XjellView user's profileSend private messageSend e-mailVisit poster's website
MikeMiles
Lieutenant
Lieutenant


Joined: May 29, 2003
Posts: 231


PostPosted: Fri Jul 25, 2003 7:22 pm Reply with quoteBack to top

The SPEWS FAQ is accurate on how it works. My host has had four servers on the spammer black list. They took immediate action each time to terminate the spammer's account. Within three days or less the servers were taken off the list, but it does require them to jump thru hoops to get removed. The first three times only the one server was banned. The fourth time the blacklist banned up to three digits catching innocent servers (including mine) as well. Not sure if this is the new practice, this is done after so many offenses, or each list just does it differently.

My host and its datacenter have never had all their IPs banned like Jaguar/Yipes seem to have. My guess is SPEWS is doing it because these guys may have a track record of harboring spammers. After reading masood's posts on that thread, I think he has the wrong attitude. They should be getting off their butts and taking some action to get your servers removed. Not everyone uses those blacklists, but it's enough to be pretty annoying if any of your emails get caught up in the mess.

I think the blacklists end up banning wide IP ranges in order to get a greater number of customers complaining and applying pressure onto the harboring host/datacenter to do something.
Find all posts by MikeMilesView user's profileSend private message
Display posts from previous:      
Post new topic  Reply to topicprinter-friendly view
View previous topic Log in to check your private messages View next topic
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum



Powered by phpBB © 2001, 2005 phpBB Group

Ported by Nuke Cops © 2003 www.nukecops.com
:: FI Theme :: PHP-Nuke theme by coldblooded (www.nukemods.com) ::
Powered by · TOGETHER TEAM srl ITALY http://www.togetherteam.it · DONDELEO E-COMMERCE http://www.DonDeLeo.com
Web site engine's code is Copyright © 2002 by PHP-Nuke. All Rights Reserved. PHP-Nuke is Free Software released under the GNU/GPL license.
Page Generation: 0.195 Seconds - 280 pages served in past 5 minutes. Nuke Cops Founded by Paul Laudanski (Zhen-Xjell)
:: FI Theme :: PHP-Nuke theme by coldblooded (www.nukemods.com) ::