| View previous topic :: View next topic |
| Author |
Message |
Chao284
Guest IP: 24.16.*.*
|
Posted: Sun Jan 06, 2008 9:31 am Post subject: |
|
|
| AlphaCentauri wrote: | I can get Spamhaus fine right now, and it was okay last night for me, too. Comcast certainly has plenty of storm-infested computers on their network, and spamhaus is under pretty much perpetual DDoS from what I understand. But because Comcast has so many users on dynamic IP addresses, it's harder for DDoS targets to just block entire IP ranges as they are also blocking a lot of legitimate users. It's possible that the last time you logged on, you were assigned an IP address recently used by a bot. You could find out by trying a proxy, or disconnecting from the internet long enough to get a new IP address assigned. Also, I don't know the details of cable internet -- do other people in your neighborhood share the same IP address?
Or, you could be infected yourself. |
I checked and I have nothing infected, but for some apparent reason, I did use another computer to check Spamhaus, no response either, and now completewhois is doing the same thing too,
my Finial guess, Comcast is doing something sneaky that is very foul and apparently them blocking Received data package connection ends up going silent, which in turn Comcast might be blacking listing sites without warning that I think is just unfair.
|
|
| Back to top |
|
 |
ahoier
SIRT Handler
 Joined: Jan 14, 2006 Posts: 1102 Location: USA
|
Posted: Sun Jan 06, 2008 5:05 pm Post subject: |
|
|
Just a guess (stab in the dark...) but try using a different DNS server addresses?
I use 208.67.222.222 and 208.67.220.220 (opendns.com for more information).
|
|
| Back to top |
|
 |
Chao284
Guest IP: 24.16.*.*
|
Posted: Tue Jan 08, 2008 12:19 am Post subject: |
|
|
| ahoier wrote: | Just a guess (stab in the dark...) but try using a different DNS server addresses?
I use 208.67.222.222 and 208.67.220.220 (opendns.com for more information). |
Problem, Comcast is ONLY allowed to change the IP, not the user or head owner of the person's connection, because of certain restrictions and policies that must be followed with in comcast's contract when signed to their services.
|
|
| Back to top |
|
 |
ahoier
SIRT Handler
 Joined: Jan 14, 2006 Posts: 1102 Location: USA
|
Posted: Tue Jan 08, 2008 5:37 am Post subject: |
|
|
Really...? So you don't have access to Start > Control Panel > Network Connections? To change your network adapter settings from "Automatic" (or whatever Comcast has set them to for you, If present).
Or have they somehow disabled your access to this area...? If so, how?
|
|
| Back to top |
|
 |
Ikeb
Special Response Team Forums Admin
 Joined: Apr 20, 2003 Posts: 16542
|
Posted: Tue Jan 08, 2008 6:22 am Post subject: |
|
|
I suspect there's a bit of confusion here. I seriously doubt that an ISP would restrict which DNS server a customer may use. I suspect that Chaos is for some reason referring to the customer's source IP address ... which of course can't be changed without causing routing problems.
|
|
| Back to top |
|
 |
ahoier
SIRT Handler
 Joined: Jan 14, 2006 Posts: 1102 Location: USA
|
Posted: Tue Jan 08, 2008 3:41 pm Post subject: |
|
|
That could be....after reading the other thread, referring to not being able to access spamhaus and completewhois - these two sites in particular must block Comcast due to the huge number of infectious machines on their network...
In that case, the only way to resolve it would be to use a proxy such as anonymouse, proxy.org or any other number of proxies around the net..
Then again, one could bi*ch and complain to their ISP, complaining that sites (spamhaus and completewhois as read above) are restricting their access due to the huge amount of infectious computers within their IP space...
Threaten to switch ISPs, etc....maybe they will give you a free month, find you another IP block that is clean(er), or whatever.
One can only wish 
|
|
| Back to top |
|
 |
tembow
Blue Angel Premium Member
 Joined: Oct 10, 2005 Posts: 2942
|
Posted: Wed Jan 09, 2008 1:43 am Post subject: |
|
|
Re the inability of Comcast users to access two hosts -
my dictum states that one should never attribute to human malice that which may be readily explained by computer malfunction.
Probably an error in a routing table.
|
|
| Back to top |
|
 |
maques
Trooper

 Joined: Dec 27, 2007 Posts: 10 Location: Hungary
|
Posted: Wed Jan 09, 2008 3:28 pm Post subject: |
|
|
Just got an email from RU-CENTER, that they disabled the domains:
"Dear Sirs,
The domains:
HAPPYCARDS2008.COM
NEWYEARWITHLOVE.COM
UHAVEPOSTCARD.COM
MERRYCHRISTMASDUDE.COM
are put on hold,
--
Best Regards,"
I checked all known domains, even one which is not listed in their reply and they show "NOT-DELEGATED" and seems like they dont't work anymore.
And it only took like 16 days!!!
Let's be happy folks - and prepare for the new domains which will be registered soon...
(full: http://www.huweb.hu/maques/mblog/?p=71)
|
|
| Back to top |
|
 |
pwillener
SRT Trainee
 Premium Member
 Joined: Apr 17, 2006 Posts: 1830 Location: Japan
|
Posted: Thu Jan 10, 2008 2:28 am Post subject: |
|
|
Thanks, maques, for you help with this!
Actually, it may just be their email reply that took so long; the whois records show that the last updates on these domains were Dec 28, Jan 04, and Jan 06.
|
|
| Back to top |
|
 |
tembow
Blue Angel Premium Member
 Joined: Oct 10, 2005 Posts: 2942
|
Posted: Thu Jan 10, 2008 10:22 am Post subject: |
|
|
Very few of the storm distribution IPs are left operating. As each infected machine is rebooted, it will not be able to establish connections with the Storm network. There is a possibility that the simultaneous removal of all the resolving names will result in Storm losing track of a large portion of the existing network. The machines will be infected, but permanently orphaned.
This has been a major breakthrough. Previously, as one domain name was removed, another has already been in place to take over, and the code has been refreshed to use the replacement without losing bots. This time there could be a major impact.
The next few days will tell.
|
|
| Back to top |
|
 |
maques
Trooper

 Joined: Dec 27, 2007 Posts: 10 Location: Hungary
|
Posted: Thu Jan 10, 2008 1:30 pm Post subject: |
|
|
pwillener: I see "Last updated on 2008.01.10 16:21:26 MSK/MSD" now, and yesterday I saw 2008.01.09 on all domains.
tembow: don't worry, there will be new domains.
However, I got this today from RU-CENTER:
----- Original Message -----
From: "RU-CENTER NCC" <tld-ncc [A] nic.ru>
Sent: Thursday, January 10, 2008 11:51 AM
Subject: [ru-center #1781157] Re: open letter to RU-CENTER
> Dear Sirs,
>
> The domains are put on hold, thank you for your report.
> New alike registrations are monitored.
>
> --
> Best Regards,
>
> Julia A. Lotkova
> Regional Network Information Center (RU-CENTER)
> Phone: +7 495 737-0601
> fax: +7 495 737-0602
> http://www.nic.ru
so let's hope that at least the domains won't be registered here [which could be either good or bad...]
|
|
| Back to top |
|
 |
AlphaCentauri
SIRT Handler Premium Member
 Joined: Nov 20, 2003 Posts: 2886
|
Posted: Thu Jan 10, 2008 3:06 pm Post subject: |
|
|
Bad news -- they didn't remove the glue records from the nameservers. They are now fast flux and apparently performing the function the regular domains did before.
|
|
| Back to top |
|
 |
AlphaCentauri
SIRT Handler Premium Member
 Joined: Nov 20, 2003 Posts: 2886
|
Posted: Thu Jan 10, 2008 3:29 pm Post subject: |
|
|
Good news -- looks like they caught it -- the glue records are gone now.
|
|
| Back to top |
|
 |
tembow
Blue Angel Premium Member
 Joined: Oct 10, 2005 Posts: 2942
|
Posted: Fri Jan 11, 2008 12:45 am Post subject: |
|
|
I am given to believe that Storm has an initial bootstrap list of IPs to use to establish contact with peers on the network. The domain name lookup to a zero-duration fast-flux host name would be the fall-back if that fails, or else the bootstrap peers may simply feed back to a joining bot a few domain names to use to locate further peers.
A more effective storm botnet removal would involve simultaneously removing all bootstrap IPs and all zero-flux hosts.
|
|
| Back to top |
|
 |
AlphaCentauri
SIRT Handler Premium Member
 Joined: Nov 20, 2003 Posts: 2886
|
Posted: Tue Jan 15, 2008 11:59 pm Post subject: |
|
|
| Quote: | Subject: Our Journey
You're my Dream http://74.78.105.255/ |
Site is titled "With Love!" and looks like this.
Payload = withlove.exe although there are two decoy files, "fck2008.exe" and "fck2009.exe"
| Description: |
|
| Filesize: |
15.79 KB |
| Viewed: |
36 Time(s) |

|
|
|
| Back to top |
|
 |
|
|