CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
spacer spacer

Add / Change Registrar
Goto page Previous  1, 2, 3, 4, 5, ... 13, 14, 15  Next
 
Post new topic   Reply to topic       All -> FavForums -> Complainterator [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
AlphaCentauri

SIRT Handler
Premium Member

Joined: Nov 20, 2003
Posts: 2859

Premium

PostPosted: Thu May 15, 2008 11:37 pm    Post subject:
Reply with quote

tembow wrote:
No site loads at that address. What brand of spammed site is it?


The ones I got were phish, and they're still wriggling:

http://chaseonline.chase.com.techldr.co.uk/ReidentifyFormOnine/OnlineForm.aspx/?

http://chaseonline.chase.com.techldr.org.uk/ReidentifyFormOnine/OnlineForm.aspx/?

Both are also registered with stolen identity data.
Nameservers are with SpiritDomains.com, which also hasn't responded.

Add: and there's a new one since I did that reporting:
http://chaseonline.chase.com.modeisp.org.uk/ReidentifyFormOnine/OnlineForm.aspx/

Back to top
View users profile Send private message
tembow

Blue Angel
Premium Member

Joined: Oct 10, 2005
Posts: 2933

Blue Security Premium

PostPosted: Fri May 16, 2008 12:21 am    Post subject:
Reply with quote

Please use the email addresses for GX Networks from my last posting if applicable. There are also phone and fax numbers. Or you could ask a UK resident viewer to call "by proxy" Smile - and ensure the email is OK.

Back to top
View users profile Send private message Visit posters website AIM Address
tembow

Blue Angel
Premium Member

Joined: Oct 10, 2005
Posts: 2933

Blue Security Premium

PostPosted: Fri May 16, 2008 5:26 am    Post subject:
Reply with quote

All add/change requests have been incorporated into the Version 21.4, dated May15

A reported problem with the .kg domains whois server (which does not return requests) has also been circumvented in 21.4. There is no point in leaving any loop-holes open for spammers.

Back to top
View users profile Send private message Visit posters website AIM Address
efa

Lieutenant
Lieutenant


Joined: Aug 31, 2007
Posts: 163
Location: Italy

PostPosted: Fri May 16, 2008 12:59 pm    Post subject:
Reply with quote

tembow wrote:
Please use the email addresses for GX Networks from my last posting if applicable.


I just wrote asking to remove:
grnew.co.uk
grnew.org.uk
grnew.me.uk

Back to top
View users profile Send private message
efa

Lieutenant
Lieutenant


Joined: Aug 31, 2007
Posts: 163
Location: Italy

PostPosted: Fri May 16, 2008 10:37 pm    Post subject:
Reply with quote

tembow wrote:

No site loads at that address. What brand of spammed site is it?

seems a logistics company.
To me works.
I receiving a lot of spam, everytime changing a little the domain name, linking to the same look web site.

Back to top
View users profile Send private message
AlphaCentauri

SIRT Handler
Premium Member

Joined: Nov 20, 2003
Posts: 2859

Premium

PostPosted: Fri May 16, 2008 10:38 pm    Post subject:
Reply with quote

Of the domains related to that phish above:
- nameservers reported to SpiritDomains via email and via their web form, still operational
- domains reported to GX Networks via all the the email addresses above at least once, still operational
- domains reported once by email and only in English to AsiaInfo in Kyrgyzstan: all suspended

Something is wrong here.

Back to top
View users profile Send private message
efa

Lieutenant
Lieutenant


Joined: Aug 31, 2007
Posts: 163
Location: Italy

PostPosted: Sat May 17, 2008 9:29 am    Post subject:
Reply with quote

Domain : "scramignon.com"
Registrar : "IN2NET NETWORK"
Contact : registrar@in2net.com

Back to top
View users profile Send private message
efa

Lieutenant
Lieutenant


Joined: Aug 31, 2007
Posts: 163
Location: Italy

PostPosted: Sat May 17, 2008 9:42 am    Post subject:
Reply with quote

Domain : "com.tw"
Registrar : "TWNIC"
Contact: ???

not ICANN accredited

Back to top
View users profile Send private message
AlphaCentauri

SIRT Handler
Premium Member

Joined: Nov 20, 2003
Posts: 2859

Premium

PostPosted: Sat May 17, 2008 12:56 pm    Post subject:
Reply with quote

Ooops! There's no domain called "com.tw" Those two together are a TLD for a country code domain name, like ".co.uk." Complainterator lost the domain name along the way, something that would have looked like "example.com.tw."

If you see that happen and it starts to do a whois on a double TLD like that, hit the "Pause/Break" key on your keyboard, retype the correct domain into the browser address window, and do the lookup manually. Once the correct whois results are displayed, hit "Pause/Break" again and Complainterator will resume as usual. Then look at your letters carefully and fix any "com.tw's" that made it through.

You should be getting a pop up warning that it isn't a typical TLD like ".com" or ".net" before these happen, so you can watch for it.


Also, scramignon.com is an innocent hacked website, so normally I would complain to the ISP, domain owner, and webmaster to get someone to clean up their site. I reported that one April 29 and it's still active, though it may be that they did an incompetent job of cleaning it up during that time and got reinfected. (I downloaded a copy of the trojan from there yesterday and it was very poorly detected, so it may be a new reinfection. They don't seem to update copies of the trojan that are on sites that have been continuously infected.) If I really think there has been no response at all and the website is abandoned, I will go ahead and ask the registrar to delete the name instead.

Back to top
View users profile Send private message
efa

Lieutenant
Lieutenant


Joined: Aug 31, 2007
Posts: 163
Location: Italy

PostPosted: Sat May 17, 2008 3:58 pm    Post subject:
Reply with quote

ok, the domain was:

Domain : "ultranano.com.tw"
Registrar : "NET-CHINESE"
Contact: ???

How to recognise when, to convert URL to domain for whois query, I must keep the 3th level domain like ultranano, and when not like hxxp://bpi.agtimesx.com/ ?

Back to top
View users profile Send private message
AlphaCentauri

SIRT Handler
Premium Member

Joined: Nov 20, 2003
Posts: 2859

Premium

PostPosted: Sat May 17, 2008 7:46 pm    Post subject:
Reply with quote

Some top level domains, like .com, .net, .edu, .gov, .info, .org, are used by all countries. They may indicate the type of site (commercial, university, government, nonprofit organization), but not the country.

Other TLD's are country codes, like .ca for Canada, .cn for People's Republic of China, .tw for Taiwan, etc. Those countries may further subdivide their TLD's to indicate the type of site, so you can get .co.uk for commercial UK sites, .org.uk for nonprofit UK sites, etc. Other countries don't. You just have to be aware that a .co.cc or .com.cc might be a two-part TLD. Those domains may be registered by registrars that don't have ICANN accreditation, and they may not have the same requirements as far as publicly listing the registrant's info.

Back to top
View users profile Send private message
pwillener

SRT Trainee
SRT Trainee
Premium Member

Joined: Apr 17, 2006
Posts: 1813
Location: Japan
Premium

PostPosted: Sun May 18, 2008 2:08 am    Post subject:
Reply with quote

And some countries, like Japan, use both ways, which may confuse users even more.
- huge.co.jp (3 parts)
- rigoletto.jp (2 parts)
are both valid domain names.

Back to top
View users profile Send private message Visit posters website
tembow

Blue Angel
Premium Member

Joined: Oct 10, 2005
Posts: 2933

Blue Security Premium

PostPosted: Sun May 18, 2008 8:06 am    Post subject:
Reply with quote

At http://www.icann.org/registrars/accreditation-qualified-list.html
Search on NET-CHINESE

Domain : "ultranano.com.tw"
Registrar : "NET-CHINESE"

NET-CHINESE ~ foreign@net-chinese.com.tw

Back to top
View users profile Send private message Visit posters website AIM Address
efa

Lieutenant
Lieutenant


Joined: Aug 31, 2007
Posts: 163
Location: Italy

PostPosted: Sun May 18, 2008 10:35 pm    Post subject:
Reply with quote

Some spamvertized URL example for references:
------------------------------------------------------------------------
hxxp://prettydesert.com/
hxxp://xx-qk.cn:8080/
hxxp://www.prettydesert.com/
hxxp://dqk.alfive.com/

hxxp://huge.co.jp/
hxxp://www.huge.co.jp/
hxxp://dizloing.com.cn/lang-it/index.html
hxxp://business-loandm.com.cn/
hxxp://grtrrh.co.uk/vacancy.php
hxxp://grnew.me.uk/vacancy.php
hxxp://grnew.org.uk/vacancy.php
hxxp://imena.com.ua/
hxxp://cigarettes.xx-qk.cn:88/x1.htm

Please help me to find a general algoritm to convert a URL in a domain
for a whois query:

- remove heading http://
- keep the part until the first / or :

- when a URL contain one dot like 'prettydesert.com' or
'xx-qk.cn', surely the domain is all the remaining part.

- when a URL contain two or more dot, the domain is recovered with those steps:
- if TLD is a gTLDs like .org, .com, .gov, .net, .mil, .edu, .info
remove the first part to first dot (www. or dqk.) for whois query
(but to find and follow the redirect, dqk. is needed here)

- if TLD is a country code ccTLDs like .uk, .tw, .ua, .cn, .jp,
how to understand when to remove the first part to first dot
(like www.), and when we need to keep it
(like grnew., business-loandm., dizloing. or huge.)
?

Back to top
View users profile Send private message
AlphaCentauri

SIRT Handler
Premium Member

Joined: Nov 20, 2003
Posts: 2859

Premium

PostPosted: Mon May 19, 2008 12:17 am    Post subject:
Reply with quote

The name can't be ambiguous. If you allow ".co.uk" as a TLD, then there can't be a "www.co.uk." So try the traversal on the two-part, and if it doesn't have an A record, then try the three-part.

Back to top
View users profile Send private message
Display posts from previous:   
Post new topic   Reply to topic       All -> FavForums -> Complainterator All times are GMT
Goto page Previous  1, 2, 3, 4, 5, ... 13, 14, 15  Next
Page 4 of 15

 
Quick Reply:
Username: 

Quote the last message
Attach signature (signatures can be changed in profile)
 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You can download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer