CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
spacer spacer

Add / Change Registrar
Goto page Previous  1, 2, 3, 4, 5, 6 ... 13, 14, 15  Next
 
Post new topic   Reply to topic       All -> FavForums -> Complainterator [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
tembow

Blue Angel
Premium Member

Joined: Oct 10, 2005
Posts: 2933

Blue Security Premium

PostPosted: Mon May 19, 2008 1:08 am    Post subject:
Reply with quote

You have given your answer in forming your question, and AlphaCentauri has confirmed it.

The top level domains are listed at
http://en.wikipedia.org/wiki/List_of_Internet_top-level_domains

If the domain name ends in one of those, then the preceding word may be a enough, such as
example.tw

But if the preceding word is an organization, such as com, org, gov, govt etc then you will need both that and its preceding word, such as example.org.uk



Last edited by tembow on Mon May 19, 2008 4:07 am, edited 1 time in total
Back to top
View users profile Send private message Visit posters website AIM Address
AlphaCentauri

SIRT Handler
Premium Member

Joined: Nov 20, 2003
Posts: 2859

Premium

PostPosted: Mon May 19, 2008 2:36 am    Post subject:
Reply with quote

You may still have to try things out to see what works. After all, com.com is a real domain.

Back to top
View users profile Send private message
tembow

Blue Angel
Premium Member

Joined: Oct 10, 2005
Posts: 2933

Blue Security Premium

PostPosted: Mon May 19, 2008 11:30 am    Post subject: Beijing Innovative Linkage Technology / DNS.COM.CN
Reply with quote

<cnreg@dns.com.cn>
Permanent Failure: Other address status
Delivery last attempted at Mon, 19 May 2008 09:22:46 -0000

<huyan@dns.com.cn>
Permanent Failure: Other address status
Delivery last attempted at Mon, 19 May 2008 09:22:46 -0000

Final-Recipient: rfc822; <cnreg@dns.com.cn>
Action: failed
Status: 5.1.0 MAIL FROM: <my email address> 550 REPLY: 550_Does_not_like_recipient,your_mail_is_rejected!
Diagnostic-Code: smtp; Permanent Failure: Other address status
Last-Attempt-Date: Mon, 19 May 2008 09:22:46 -0000

Same for huyan@dns.com.cn

Back to top
View users profile Send private message Visit posters website AIM Address
ahoier

SIRT Handler


Joined: Jan 14, 2006
Posts: 1087
Location: USA

PostPosted: Mon May 19, 2008 6:08 pm    Post subject:
Reply with quote

They're playing games with us. Most likely they've blacklisted either your whole address, or your complete domain from receiving mail from you.

I've been given similar responses from those addresses.

Previously, they would bounce back due to illegal/bad content (they wanted me to munge the spam evidence).


Then again, "Does_not_like_recipient" - could that indicate it doesn't like the huyan and huvan aliases? Either, because they don't exist any longer, mailbox is full, or some other reasoning?

But the "your_mail_is_rejected!" statement lead me to the first assumption - in which the mailbox received it, but then rejected it for whatever reasoning.

Back to top
View users profile Send private message Visit posters website AIM Address Yahoo Messenger MSN Messenger
efa

Lieutenant
Lieutenant


Joined: Aug 31, 2007
Posts: 163
Location: Italy

PostPosted: Tue May 20, 2008 12:08 am    Post subject:
Reply with quote

the rule to query for an A record with 2 part, and if A missing, retry with 3 part domain seem works.
But should be used only with ccTLD only and not with gTLD?

Example: with domain that do not have an A record neither using 2 or 3 part like:
hxxp://kva.hjwithin.com
to do the whois query I need to remove the kva. part

With 'dig +trace kva.hjwithin.com any'
I see the presence of a CNAME record. It is related to this?

Back to top
View users profile Send private message
AlphaCentauri

SIRT Handler
Premium Member

Joined: Nov 20, 2003
Posts: 2859

Premium

PostPosted: Tue May 20, 2008 12:34 am    Post subject:
Reply with quote

Actually, if I paste kva.hjwithin.com into who.is, it looks up hjwithin.com, so it sort of does it for you.

Back to top
View users profile Send private message
pwillener

SRT Trainee
SRT Trainee
Premium Member

Joined: Apr 17, 2006
Posts: 1813
Location: Japan
Premium

PostPosted: Tue May 20, 2008 5:44 am    Post subject:
Reply with quote

Spammed domain = noomreplase.com
Registrar = DOOTALL, INC.
Contact = info [at] dootall.com, support [at] dootall.com

Back to top
View users profile Send private message Visit posters website
efa

Lieutenant
Lieutenant


Joined: Aug 31, 2007
Posts: 163
Location: Italy

PostPosted: Tue May 20, 2008 11:06 pm    Post subject:
Reply with quote

AlphaCentauri wrote:
Actually, if I paste kva.hjwithin.com into who.is, it looks up hjwithin.com, so it sort of does it for you.


I need a scriptable method.
The A record method is arrived in xComplaint x Linux V0.04.07
thanks!

Back to top
View users profile Send private message
pwillener

SRT Trainee
SRT Trainee
Premium Member

Joined: Apr 17, 2006
Posts: 1813
Location: Japan
Premium

PostPosted: Wed May 21, 2008 4:41 am    Post subject:
Reply with quote

Spammed domain = omelograster.com
Registrar = ONLINE SAS
Contact = skolaric [at] online.net (same as Book My Name?)

Back to top
View users profile Send private message Visit posters website
tembow

Blue Angel
Premium Member

Joined: Oct 10, 2005
Posts: 2933

Blue Security Premium

PostPosted: Wed May 21, 2008 7:09 am    Post subject:
Reply with quote

pwillener wrote:
Spammed domain = omelograster.com
Registrar = ONLINE SAS
Contact = skolaric [at] online.net (same as Book My Name?)


From ICANN http://www.icann.org/registrars/accreditation-qualified-list.html I got
ONLINE SAS ~ icann@free.org

Back to top
View users profile Send private message Visit posters website AIM Address
AlphaCentauri

SIRT Handler
Premium Member

Joined: Nov 20, 2003
Posts: 2859

Premium

PostPosted: Thu May 22, 2008 10:24 pm    Post subject:
Reply with quote

From ESTdomains -- autoreplies from both the sales@ and support@ addresses:

Quote:
Dear Customer,

Due to the huge wave of spam we receive and in order to improve
the speed and quality of the work of our support team we decided
to stop receiving emails.

To get in touch with us please feel free to raise support ticket at

https://support.estdomains.com/

Best regards,
Estdomains, Inc Support Team


Actually, the direct link to their ticket system is
https://support.estdomains.com/index.php?_m=tickets&_a=submit

They will reply with a password that allows you to log in and check to see if there has been any progress on your report.

Back to top
View users profile Send private message
pwillener

SRT Trainee
SRT Trainee
Premium Member

Joined: Apr 17, 2006
Posts: 1813
Location: Japan
Premium

PostPosted: Fri May 23, 2008 2:33 am    Post subject:
Reply with quote

I have reported through their (Est Domains) web interface for quite a while now. They usually act within one hour and remove the offending domain.

Back to top
View users profile Send private message Visit posters website
ahoier

SIRT Handler


Joined: Jan 14, 2006
Posts: 1087
Location: USA

PostPosted: Mon May 26, 2008 5:32 am    Post subject:
Reply with quote

For eNom, the following URL could be added to the To: field, as a reminder obviously, to fill in the form:

http://www.enom.com/help/AbusePolicy.asp

I don't know how reliable the form is, but I'd think a web form is more reliable than e-mail (which usually has filters to jump through...).

I've been reporting all of my kaj52.com spam through this form.

One thing, the page appears to want "headers" - though I don't know, a complainterator "report" could probably substituted Wink As we would do when using the old Joker support ticket system (what a sigh of relief...having not used that form in months now, Thanks Joker lol).

Spammed domain = kaj52.com
Registrar = ENOM, INC.
Contact = http://www.enom.com/help/AbusePolicy.asp

Back to top
View users profile Send private message Visit posters website AIM Address Yahoo Messenger MSN Messenger
pwillener

SRT Trainee
SRT Trainee
Premium Member

Joined: Apr 17, 2006
Posts: 1813
Location: Japan
Premium

PostPosted: Mon May 26, 2008 6:22 am    Post subject:
Reply with quote

The submission form at eNom sends an email message to 'Report.Abuse[@]enom.com' - I know it because it bounces when it contains anything "spammy".

An address at eNom that does not bounce is 'legal[@]name-services.com'.

At the end, whatever addresses we notify at eNom, the result is the same: no action.

Back to top
View users profile Send private message Visit posters website
ahoier

SIRT Handler


Joined: Jan 14, 2006
Posts: 1087
Location: USA

PostPosted: Mon May 26, 2008 6:51 am    Post subject:
Reply with quote

really...the "form submittal" bounces?

I've not seen that here yet....hehehe. I simply pasted in my e-mail address, spamvertised "eNom" domain, and then complete spam source, incl. headers.

I'll give it a day or two and see what happens hehehe.

I'm not holding my breath though lol.

Back to top
View users profile Send private message Visit posters website AIM Address Yahoo Messenger MSN Messenger
Display posts from previous:   
Post new topic   Reply to topic       All -> FavForums -> Complainterator All times are GMT
Goto page Previous  1, 2, 3, 4, 5, 6 ... 13, 14, 15  Next
Page 5 of 15

 
Quick Reply:
Username: 

Quote the last message
Attach signature (signatures can be changed in profile)
 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You can download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer