CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
spacer spacer

storm worm spam
Goto page Previous  1, 2, 3, 4, 5  Next
 
Post new topic   Reply to topic       All -> FavForums -> Spam [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
Chao284

Guest
IP: 24.16.*.*






PostPosted: Sun Jan 06, 2008 9:31 am    Post subject:
Reply with quote

AlphaCentauri wrote:
I can get Spamhaus fine right now, and it was okay last night for me, too. Comcast certainly has plenty of storm-infested computers on their network, and spamhaus is under pretty much perpetual DDoS from what I understand. But because Comcast has so many users on dynamic IP addresses, it's harder for DDoS targets to just block entire IP ranges as they are also blocking a lot of legitimate users. It's possible that the last time you logged on, you were assigned an IP address recently used by a bot. You could find out by trying a proxy, or disconnecting from the internet long enough to get a new IP address assigned. Also, I don't know the details of cable internet -- do other people in your neighborhood share the same IP address?

Or, you could be infected yourself.


I checked and I have nothing infected, but for some apparent reason, I did use another computer to check Spamhaus, no response either, and now completewhois is doing the same thing too,

my Finial guess, Comcast is doing something sneaky that is very foul and apparently them blocking Received data package connection ends up going silent, which in turn Comcast might be blacking listing sites without warning that I think is just unfair.

Back to top
ahoier

SIRT Handler


Joined: Jan 14, 2006
Posts: 1102
Location: USA

PostPosted: Sun Jan 06, 2008 5:05 pm    Post subject:
Reply with quote

Just a guess (stab in the dark...) but try using a different DNS server addresses?

I use 208.67.222.222 and 208.67.220.220 (opendns.com for more information).

Back to top
View users profile Send private message Visit posters website AIM Address Yahoo Messenger MSN Messenger
Chao284

Guest
IP: 24.16.*.*






PostPosted: Tue Jan 08, 2008 12:19 am    Post subject:
Reply with quote

ahoier wrote:
Just a guess (stab in the dark...) but try using a different DNS server addresses?

I use 208.67.222.222 and 208.67.220.220 (opendns.com for more information).


Problem, Comcast is ONLY allowed to change the IP, not the user or head owner of the person's connection, because of certain restrictions and policies that must be followed with in comcast's contract when signed to their services.

Back to top
ahoier

SIRT Handler


Joined: Jan 14, 2006
Posts: 1102
Location: USA

PostPosted: Tue Jan 08, 2008 5:37 am    Post subject:
Reply with quote

Really...? So you don't have access to Start > Control Panel > Network Connections? To change your network adapter settings from "Automatic" (or whatever Comcast has set them to for you, If present).

Or have they somehow disabled your access to this area...? If so, how?

Back to top
View users profile Send private message Visit posters website AIM Address Yahoo Messenger MSN Messenger
Ikeb

Special Response Team
Forums Admin

Joined: Apr 20, 2003
Posts: 16542

Forums Admin Moderators MVP Premium SRT Team CC Committee Team F@H

PostPosted: Tue Jan 08, 2008 6:22 am    Post subject:
Reply with quote

I suspect there's a bit of confusion here. I seriously doubt that an ISP would restrict which DNS server a customer may use. I suspect that Chaos is for some reason referring to the customer's source IP address ... which of course can't be changed without causing routing problems.

Back to top
View users profile Send private message
ahoier

SIRT Handler


Joined: Jan 14, 2006
Posts: 1102
Location: USA

PostPosted: Tue Jan 08, 2008 3:41 pm    Post subject:
Reply with quote

That could be....after reading the other thread, referring to not being able to access spamhaus and completewhois - these two sites in particular must block Comcast due to the huge number of infectious machines on their network...

In that case, the only way to resolve it would be to use a proxy such as anonymouse, proxy.org or any other number of proxies around the net..

Then again, one could bi*ch and complain to their ISP, complaining that sites (spamhaus and completewhois as read above) are restricting their access due to the huge amount of infectious computers within their IP space...

Threaten to switch ISPs, etc....maybe they will give you a free month, find you another IP block that is clean(er), or whatever.

One can only wish Wink

Back to top
View users profile Send private message Visit posters website AIM Address Yahoo Messenger MSN Messenger
tembow

Blue Angel
Premium Member

Joined: Oct 10, 2005
Posts: 2942

Blue Security Premium

PostPosted: Wed Jan 09, 2008 1:43 am    Post subject:
Reply with quote

Re the inability of Comcast users to access two hosts -
my dictum states that one should never attribute to human malice that which may be readily explained by computer malfunction.

Probably an error in a routing table.

Back to top
View users profile Send private message Visit posters website AIM Address
maques

Trooper
Trooper


Joined: Dec 27, 2007
Posts: 10
Location: Hungary

PostPosted: Wed Jan 09, 2008 3:28 pm    Post subject:
Reply with quote

Just got an email from RU-CENTER, that they disabled the domains:

"Dear Sirs,

The domains:

HAPPYCARDS2008.COM
NEWYEARWITHLOVE.COM
UHAVEPOSTCARD.COM
MERRYCHRISTMASDUDE.COM

are put on hold,

--
Best Regards,"

I checked all known domains, even one which is not listed in their reply and they show "NOT-DELEGATED" and seems like they dont't work anymore.
And it only took like 16 days!!!
Let's be happy folks - and prepare for the new domains which will be registered soon...

(full: http://www.huweb.hu/maques/mblog/?p=71)

Back to top
View users profile Send private message
pwillener

SRT Trainee
SRT Trainee
Premium Member

Joined: Apr 17, 2006
Posts: 1830
Location: Japan
Premium

PostPosted: Thu Jan 10, 2008 2:28 am    Post subject:
Reply with quote

Thanks, maques, for you help with this!

Actually, it may just be their email reply that took so long; the whois records show that the last updates on these domains were Dec 28, Jan 04, and Jan 06.

Back to top
View users profile Send private message Visit posters website
tembow

Blue Angel
Premium Member

Joined: Oct 10, 2005
Posts: 2942

Blue Security Premium

PostPosted: Thu Jan 10, 2008 10:22 am    Post subject:
Reply with quote

Very few of the storm distribution IPs are left operating. As each infected machine is rebooted, it will not be able to establish connections with the Storm network. There is a possibility that the simultaneous removal of all the resolving names will result in Storm losing track of a large portion of the existing network. The machines will be infected, but permanently orphaned.

This has been a major breakthrough. Previously, as one domain name was removed, another has already been in place to take over, and the code has been refreshed to use the replacement without losing bots. This time there could be a major impact.

The next few days will tell.

Back to top
View users profile Send private message Visit posters website AIM Address
maques

Trooper
Trooper


Joined: Dec 27, 2007
Posts: 10
Location: Hungary

PostPosted: Thu Jan 10, 2008 1:30 pm    Post subject:
Reply with quote

pwillener: I see "Last updated on 2008.01.10 16:21:26 MSK/MSD" now, and yesterday I saw 2008.01.09 on all domains.

tembow: don't worry, there will be new domains.
However, I got this today from RU-CENTER:

----- Original Message -----
From: "RU-CENTER NCC" <tld-ncc [A] nic.ru>
Sent: Thursday, January 10, 2008 11:51 AM
Subject: [ru-center #1781157] Re: open letter to RU-CENTER


> Dear Sirs,
>
> The domains are put on hold, thank you for your report.
> New alike registrations are monitored.
>
> --
> Best Regards,
>
> Julia A. Lotkova
> Regional Network Information Center (RU-CENTER)
> Phone: +7 495 737-0601
> fax: +7 495 737-0602
> http://www.nic.ru

so let's hope that at least the domains won't be registered here [which could be either good or bad...]

Back to top
View users profile Send private message
AlphaCentauri

SIRT Handler
Premium Member

Joined: Nov 20, 2003
Posts: 2886

Premium

PostPosted: Thu Jan 10, 2008 3:06 pm    Post subject:
Reply with quote

Bad news -- they didn't remove the glue records from the nameservers. They are now fast flux and apparently performing the function the regular domains did before.

Back to top
View users profile Send private message
AlphaCentauri

SIRT Handler
Premium Member

Joined: Nov 20, 2003
Posts: 2886

Premium

PostPosted: Thu Jan 10, 2008 3:29 pm    Post subject:
Reply with quote

Good news -- looks like they caught it -- the glue records are gone now.

Back to top
View users profile Send private message
tembow

Blue Angel
Premium Member

Joined: Oct 10, 2005
Posts: 2942

Blue Security Premium

PostPosted: Fri Jan 11, 2008 12:45 am    Post subject:
Reply with quote

I am given to believe that Storm has an initial bootstrap list of IPs to use to establish contact with peers on the network. The domain name lookup to a zero-duration fast-flux host name would be the fall-back if that fails, or else the bootstrap peers may simply feed back to a joining bot a few domain names to use to locate further peers.

A more effective storm botnet removal would involve simultaneously removing all bootstrap IPs and all zero-flux hosts.

Back to top
View users profile Send private message Visit posters website AIM Address
AlphaCentauri

SIRT Handler
Premium Member

Joined: Nov 20, 2003
Posts: 2886

Premium

PostPosted: Tue Jan 15, 2008 11:59 pm    Post subject:
Reply with quote

Quote:
Subject: Our Journey

You're my Dream http://74.78.105.255/


Site is titled "With Love!" and looks like this.
Payload = withlove.exe although there are two decoy files, "fck2008.exe" and "fck2009.exe"




StormValentine.JPG
 Description:
 Filesize:  15.79 KB
 Viewed:  36 Time(s)

StormValentine.JPG


Back to top
View users profile Send private message
Display posts from previous:   
Post new topic   Reply to topic       All -> FavForums -> Spam All times are GMT
Goto page Previous  1, 2, 3, 4, 5  Next
Page 4 of 5

 
Quick Reply:
Username: 

Quote the last message
Attach signature (signatures can be changed in profile)
 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You can download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer