CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
spacer spacer

The Spam Balloon

 
Post new topic   Reply to topic       All -> FavForums -> Knujon General Discussion [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
Knujon

Captain
Captain
Premium Member

Joined: May 25, 2006
Posts: 592
Location: USA
Premium

PostPosted: Thu May 22, 2008 12:46 am    Post subject: The Spam Balloon
Reply with quote

Knowing that a minority of companies control most of the sites advertised in spam helps put the junk email problem into better perspective. To illustrate this consider a typical spam campaign. The emails are generated by tens of thousands of malware compromised machines and networks on the Internet. They send millions of spam messages to millions of victims. Sounds like a big problem, right? Not exactly. Because the number of actual websites advertised in those millions of messages is rather small in comparison the derivative of a spam campaign is seriously reduced. Reducing the true size even further is the fact that these real websites are held by one or maybe two registrar companies per campaign. Imagine that a spam campaign is a balloon. A balloon is actually made of a very small amount of real material, it only appears bigger because it's full of hot air. The huge volume of sent spam messages is the hot air that pushes the boundaries the Internet's resources, making the problem look bigger than it is. However, the air only stays in the balloon because it is knotted at the bottom. The registrars are this knot.

Graphic here:
http://www.knujon.com/news.html#05202008

Back to top
View users profile Send private message Visit posters website
ahoier

SIRT Handler


Joined: Jan 14, 2006
Posts: 1118
Location: USA

PostPosted: Thu May 22, 2008 5:07 am    Post subject:
Reply with quote

Another thing I was thinking....Smile

XIN Net for example....hmm...I wonder (and many others too, I'm sure) if they have _ANY_ "legit"/non-illegal domains registered by them...?

In my case, the balloon would be XIN Net (which is made of a very small amount of real domains)- and it appears to be a huge registrar, due to all of the one-off, illegal domain registrations, registered using stolen credit cards.


BTW, glad to see you back active on hte forums, KnujOn Smile

Back to top
View users profile Send private message Visit posters website AIM Address Yahoo Messenger MSN Messenger
tembow

Blue Angel
Premium Member

Joined: Oct 10, 2005
Posts: 2944

Blue Security Premium

PostPosted: Fri May 23, 2008 2:43 am    Post subject:
Reply with quote

Food for thought.

To hell with my gut feel, let's look at the actual statistics.

Just how big is Xin Net / Sino-I.com?
http://www.domaintools.com/internet-statistics/registrar-stats-2007.html
Number 19 on the chart.
GoDaddy is 25 times their size, Enom is 10 times their size.

Just how polluted are their registered domains?
http://rss.uribl.com/nic/
Compared with the big boys, Xin Net is very polluted.

Back to top
View users profile Send private message Visit posters website AIM Address
Knujon

Captain
Captain
Premium Member

Joined: May 25, 2006
Posts: 592
Location: USA
Premium

PostPosted: Fri May 23, 2008 3:06 am    Post subject:
Reply with quote

Very polluted. And it's pills pills pills. Pills for breakfast, pills for lunch, pills for dinner.

Back to top
View users profile Send private message Visit posters website
tembow

Blue Angel
Premium Member

Joined: Oct 10, 2005
Posts: 2944

Blue Security Premium

PostPosted: Fri May 23, 2008 4:20 am    Post subject:
Reply with quote

That's my feel, too. Testing the theory, and looking at the last 20 Xin Net registered sites to hit url=http://rss.uribl.com/nic/XIN_NET_TECHNOLOGY_CORPORATION.html]spam traps[/url] in the last 20 minutes as a sample and feeding them into IDSpam to brand them -

manusuxbig.com MaxGain+
holepeople.com Canadian Pharmacy
hellupakse.com LNHSolutions
ontaornia.com Canadian Healthcare
personloud.com Canadian Pharmacy
oatronadls.com King Replicas
nciueai.com MaxGain+
swaruggu.com Canadian Healthcare
humoalit.com Canadian Healthcare
truttya.com King Replicas
systemsegment.com Canadian Pharmacy
bexerz.com Canadian Healthcare
producemorning.com Canadian Pharmacy
nuyeaoiru.com Canadian Healthcare
liaokest.com Exquisite Footwear
camebreak.com Canadian Pharmacy
nearwife.com Canadian Pharmacy
oieajlo.com VPXL - Penis Enlargement
fractionbranch.com Canadian Pharmacy
stupeedmu.com MaxGain+

Pills, potions, watches and shoes

Back to top
View users profile Send private message Visit posters website AIM Address
Knujon

Captain
Captain
Premium Member

Joined: May 25, 2006
Posts: 592
Location: USA
Premium

PostPosted: Fri May 23, 2008 2:22 pm    Post subject:
Reply with quote

Look at this: http://fluxor.laser.dico.unimi.it/~fluxor/

Tracking fast-flux, most of it is at Xinnet

Back to top
View users profile Send private message Visit posters website
Alvaro

Trooper
Trooper


Joined: Jan 28, 2008
Posts: 31
Location: Reno, NV (USA)

PostPosted: Sat May 24, 2008 5:42 am    Post subject:
Reply with quote

Note to intrepid neophytes like myself to the wonderful world of fast-flux: there's a one-minute explanation (with pointers to more info, if you must) on Wikipedia here.

Edited to add a statement of bewilderment at the data on the FluXOR page from the University of Milan's LASER initiative, linked to by KnujOn: mouse over the two line graphs there to see the rapidly increasing amount of data on bad networks and agents they're collecting...

Staggering. But mostly illustrative of KnujOn's point is the pie chart: take out Xin Networks and Beijing Innovative Linkage and... Some others will jump in. Laughing

Back to top
View users profile Send private message Visit posters website
Knujon

Captain
Captain
Premium Member

Joined: May 25, 2006
Posts: 592
Location: USA
Premium

PostPosted: Sat May 24, 2008 12:59 pm    Post subject:
Reply with quote

Alvaro wrote:
Staggering. But mostly illustrative of KnujOn's point is the pie chart: take out Xin Networks and Beijing Innovative Linkage and... Some others will jump in. Laughing


Yes, this is why taking out specific sites or even whole providers is just a start. We need critical changes to the policy structure that prevent criminal elements from accessing this much control.

Back to top
View users profile Send private message Visit posters website
Alvaro

Trooper
Trooper


Joined: Jan 28, 2008
Posts: 31
Location: Reno, NV (USA)

PostPosted: Sun May 25, 2008 1:46 am    Post subject:
Reply with quote

Knujon wrote:
We need critical changes to the policy structure [...]
Sounds more like a political type goal.

Why not think about ways to set up a snowball in motion to sway public opinion > pressure pertinent political targets?

Edited to add: just to be sure, I'm thinking additive action, most certainly not "in lieu of" what's already being done!

Back to top
View users profile Send private message Visit posters website
Knujon

Captain
Captain
Premium Member

Joined: May 25, 2006
Posts: 592
Location: USA
Premium

PostPosted: Sun May 25, 2008 5:48 pm    Post subject:
Reply with quote

Alvaro wrote:
Why not think about ways to set up a snowball in motion to sway public opinion > pressure pertinent political targets?


Be careful what you wish for

http://www.icann.org/announcements/announcement-23may08.htm

Back to top
View users profile Send private message Visit posters website
Display posts from previous:   
Post new topic   Reply to topic       All -> FavForums -> Knujon General Discussion All times are GMT
Page 1 of 1

 
Quick Reply:
Username: 

Quote the last message
Attach signature (signatures can be changed in profile)
 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You can download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer