|
Donation/Premium |
|
 |
|
|
|
|
|
|
|
 |
 |
| View previous topic :: View next topic |
| Author |
Message |
ahoier
SIRT Handler
 Joined: Jan 14, 2006 Posts: 1113 Location: USA
|
Posted: Tue Sep 02, 2008 10:26 pm Post subject: HICHINA honors requests from CNCERT...? |
|
|
For a while now, I've been "manually reporting" spam through SpamCop using the cut-and-paste feature, fill in the comment field(s) with a "condensed" complainterator-ish template, something like:
"Please suspend the domain referenced within this unsolicited spam e-mail that has been registered by you."
To also include link(s) to CastleCops Bulk Spam Report progress page if it's a "targetted" registrar.
Anyways, the following mail floated into my box from HICHINA - since I included the HICHINA contacts for a HICHINA-registered domain I reported within SpamCop:
From: "cathy peng" <pengqing@hichina.com>
To: "'me'" <me@reports.spamcop.net>,
<english@hichina.com>
Cc: <abuse@hichina.com>
Subject: RE: [SpamCop (Forwarded Spam) id:3xxxxxxx17]rw:
Date: Wed, 16 Jul 2008 11:19:20 +0800
MIME-Version: 1.0
Content-Type: text/plain;
charset="gb2312"
In-Reply-To: <rid_xxxxxx1917@msgid.spamcop.net>
Message-ID: <1216xxxxxx$8xxxx$1xxx5371@pengqing@hichina.com>
Dear Sir/Madam,
Please contact CNCERT/CC CNCERT/CC(National Computer network Emergency
Response
technical Team/Coordination Center of China www.cert.org.cn) directly.=20
We'll conform to their advices.
=20
Email=A3=BAcncert@cert.org.cn=A1=A1=20
Tel=A3=BA 086-10-82990999=20
Best Regards,
Cathy Peng =20[/quote]
Here's what the report looked like that SpamCop sent - by using SpamCop's "Third party Contact Preferences" control panel, as an FYI.
| Quote: | To: english@hichina.com
Subject: Fwd: [SpamCop (Forwarded Spam) id:3xxxxxx917]rw:
[ SpamCop V2 ]
This message is brief for your comfort. Please use links below for =
details.
User-targeted report, see notes, if any.
http://www.spamcop.net/w3m?i=3Dzxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx5a1=
65z
[ Comments from recipient regarding Forwarded Spam ]
> This is a request for you to remove the spamvertized illegal domain=20
> shapewing[dot]com
>=20
> EVIDENCE
>=20
> Your company is the registrar for the domain name referenced within =
this
complaint.
>=20
> Additionally, be alerted, your registrar is being _tracked_ by the
CastleCops Wiki Bulk Spam Reporting Project:
> http://wiki.castlecops.com/Bulk_Spam_Reporting
>=20
> ACTION
>=20
> Removal instructions for 'spammed domains' are in this link:
> > http://www.spamtrackers.eu/wiki/index.php?title=3DRegistrar_Advice
> > http://www.spamtrackers.hk/wiki/index.php?title=3DRegistrar_Advice=20
> > (for China)
>=20
> This is a request for you to remove the domain awiauadsi[dot]com and=20
> to remove its name server Address record ns3.awiauadsi[dot]com=20
> [60.172.219.21], ns4.awiauadsi[dot]com [60.12.107.8]
>=20
> EVIDENCE
>=20
> From this link, you can see that it is used as a name server for a=20
> spammed site
> > =
http://www.dnsstuff.com/tools/traversal.ch?domain=3Dshapewing.com&type
> > =3Da&token=3Dcomplainterator&src=3Dcomplainterator
>=20
> You will find this domain name operating as a nameserver is currently
allowing many criminal domains to resolve:
> http://rss.uribl.com/ns/awiauadsi_com.html
[ Offending message ]
Delivered-To: xxx
Received: by 10.114.191.7 with SMTP id o7cs56235waf;
Tue, 15 Jul 2008 18:32:58 -0700 (PDT)
Received: by 10.210.49.19 with SMTP id =
w19mr10571423ebw.69.1216171877096;
Tue, 15 Jul 2008 18:31:17 -0700 (PDT)
Return-Path: <sfrzqqfpjd@indco.net>
Received: from 35E92D98 (bzq-84-108-82-66.cablep.bezeqint.net
[84.108.82.66])
by mx.google.com with SMTP id =
6si355041nfv.21.2008.07.15.18.31.03;
Tue, 15 Jul 2008 18:31:17 -0700 (PDT)
Received-SPF: softfail (google.com: domain of transitioning
sfrzqqfpjd@indco.net does not designate 84.108.82.66 as permitted =
sender)
client-ip=3D84.108.82.66;
Authentication-Results: mx.google.com; spf=3Dsoftfail (google.com: =
domain of
transitioning sfrzqqfpjd@indco.net does not designate 84.108.82.66 as
permitted sender) smtp.mail=3Dsfrzqqfpjd@indco.net
Received: from parkish.org (beresford.dominique.icdc.com [barbital.44])
by equidistant.linus.com (8.9.1/8.9.1) with ESMTP id OAA2wacke
for <dextrose@are.pm.org>; Fri, 15 Aug 2008 03:28:10 +0100
Message-ID: <3upraise.boraxB@cage.org>
Date: Fri, 15 Aug 2008 07:23:10 +0500
From: "Jefferson Marquez" <sfrzqqfpjd@indco.net>
To: burgessfrank73@gmail.com
Subject: rw:
X-Accept-Language: en
The girls love me :) www.shapewing.com
|
This just serves as an FYI, it may be advisable to include cncert@cert.org.cn when reporting illegal/spam domains to HICHINA. I guess, to "throw more fuel (up their ass?) on the fire" :)
P.S. I realize the "Bulk Spam Reporting Project" has 100% status dealing with HICHINA currently, this is merely a point/suggestion/idea/insight for those who feel reports are getting lost, or not acted upon -Use the info as you please ;)
|
|
| Back to top |
|
 |
Krivoi
Sergeant

 Joined: Mar 03, 2008 Posts: 90
|
Posted: Sat Nov 22, 2008 11:29 pm Post subject: |
|
|
Hi everyone - my reason for posting in this particular thread will become apparent!
I've been quiet here as my little group of sites gets hardly any spam now & in particular I've gone from 20+ a day on my own address to zero.
Since my clients' sites are unconnected I deduced that the similar-looking spams were all coming from one culprit - we nicknamed him "Mister Tosser" and went after him ruthlessly in every way we could! As most of you here know, he was recently unmasked as Lance Atkinson in New Zealand, and is looking at some serious prison time.
The McColo takedown (San Jose, California, USA) & sentencing of Robert Soloway of Seattle, USA, are also pleasing and contributed hugely to the slump! I posted elsewhere about the extreme effect I have seen, but got the impression others are still receiving loads of spam. Are you?
Apparently there is a major relocation to Russia going on and we'll soon see the same old volumes but I am increasingly sceptical.
Anyway, reason for the post in this thread is this, received from HiChina. We've all been reporting to them for ages, but one of my people has suddenly got this first-ever reply to a last-gasp spam they received.
I think this episode demonstrates that Complainterator has the correct email address ie anti-spam [@] hichina.com. Nonetheless, the question remains - should we copy in cncert?. I never check the links, so it would be good to hear whether or not the offending site is dead:
"RE:Removal request: greatdnserrorinternet[dot]com
Thank you for contacting us and providing the evidence, we have warned
the enterprise email services which you complained.Should you have any
further questions, please feel free to contact us at anti-spam [@] hichina.com
Best wishes,
HiChina Web Solutions Limited
xiaobo he 【 Customer Service Center】
Tel: (86-10)64242299-8313
Fax: (86-10)84134247
Hotline: 400-600-8500
Address: HiChina Mansion, No. 27 Gulouwai Avenue, Dongcheng District,
Beijing 100120, China
Website: www.net.cn www.com.cn
HiChina - Web Solutions to Enterprises"
Any comments appreciated.
K
|
|
| Back to top |
|
 |
AlphaCentauri
SIRT Handler Premium Member
 Joined: Nov 20, 2003 Posts: 2889
|
Posted: Sun Nov 23, 2008 5:45 am Post subject: |
|
|
I told my ISP not to filter my email, as they blocked valid ones, too. I use MWP to filter it myself.
That means I can see what is really being sent, not just what is able to evade spam filters. I saw no decrease when SanCash went down, just a change in the brands being spammed. The mccolo thing did have a very big effect, but I'm still getting hundreds of spams a day, and it's starting to go back up again now.
|
|
| Back to top |
|
 |
pwillener
SRT Trainee
 Premium Member
 Joined: Apr 17, 2006 Posts: 1830 Location: Japan
|
Posted: Tue Nov 25, 2008 4:32 am Post subject: |
|
|
Friday was a historic day for me -- I got only 3 (three) spam messages that day. Over the weekend it got already back into the hundreds.
|
|
| Back to top |
|
 |
|
|
|
You can post new topics in this forum You can reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum You cannot vote in polls in this forum You can attach files in this forum You can download files in this forum
|
Powered by phpBB © 2001 phpBB Group
|