CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

$9736.22 of $21422.68
left sidedonated so farneed $11686.46 donated to reach our goalright side, our goal
Help CastleCops serve the community on new servers, Donate Here to reach our goal.

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
Survey
spacer
Was 2007 a good year?

Yes it was a wonderful year
Yes, but there is always room for improvement
Status quo
It was a challenge
Other (leave comment)



Results
Polls

Votes: 940
Comments: 25
block bottom
spacer spacer

XIN NET Removals
Goto page Previous  1, 2, 3, 4
 
Post new topic   Reply to topic       All -> FavForums -> Complainterator [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
ahoier

SIRT Handler


Joined: Jan 14, 2006
Posts: 1033
Location: USA

PostPosted: Fri Jun 20, 2008 5:36 pm    Post subject:
Reply with quote

I noticed a strange suspension of stilltrack.com - I don't know if this can be considered "suspended" - it appears someone has changed the IP addresses to route to localhost/loopback address 127.0.0.1 - which would be "your local address" - though I don't know if this suspension is "sufficient" since it's not been set to "clientHold" status.

The traversal shows:
ns2.xinnetdns.com [123.100.7.207] 127.0.0.1 217ms
ns2.xinnet.cn [202.10.71.53] 127.0.0.1 209ms
ns.xinnetdns.com [123.100.7.206] 127.0.0.1 218ms
ns.xinnet.cn [210.51.171.209] Timeout

And Complainterator halts there, since there are XIN Net addresses within the traversal, thought it did generate a complaint to set the domain to clientHold.

Back to top
View users profile Send private message Visit posters website AIM Address Yahoo Messenger MSN Messenger
Nolimit

Trooper
Trooper


Joined: Jun 13, 2007
Posts: 12
Location: Netherlands

PostPosted: Sat Jun 21, 2008 12:43 am    Post subject:
Reply with quote

All my BIZCN.COM Euro Pharmacy domains from the past week like

Quote:
atomexperience.cn
truebeen.cn
nineduck.cn
witn Xinnet nameservers:
Quote:
renewwdns1.com
nameedns1.com
redirected to Xinnet's developboy.com
with BILT nameservers:
Quote:
forgottensin.com
toptenslist.com
torstenstv.com
tenshinohane.com
The domains from BIZCN.COM, INC give a nice NX.DOMAIN
The nameservers from Xinnet and BILT give a nice NX.DOMAIN

And the result for the nameservers of developboy.com:
Quote:
ns2.xinnetdns.com [123.100.7.207] 79.135.167.4 459ms
ns2.xinnet.cn [123.100.7.203] 79.135.167.4 217ms
ns.xinnet.cn [210.51.171.209] 79.135.167.4 202ms
ns.xinnetdns.com [202.10.71.56] 79.135.167.4 217ms

All domains and nameservers reported, all dead !!

Back to top
View users profile Send private message
ahoier

SIRT Handler


Joined: Jan 14, 2006
Posts: 1033
Location: USA

PostPosted: Sat Jun 21, 2008 2:52 am    Post subject:
Reply with quote

here's another:

doctorgot.com

Address | Reverse | BL | Country | Reporting nameserver | Links
127.0.0.1 | N/A | | | ns2.xinnetdns.com |
127.0.0.1 | N/A | | | ns2.xinnet.cn |

Internal Lookup | Address | Reverse | BL | Country | Links
ns2.xinnetdns.com | 123.100.7.207 | N/A | | China |
ns2.xinnet.cn | 202.10.71.53 | N/A | | China |

I noticed:
*

Quote:
Name Server: NS.XINNETDNS.COM
Name Server: NS2.XINNET.CN
Name Server: NS2.XINNETDNS.COM
Status: ok
Updated Date: 19-jun-2008


I don't know what was "updated" yesterday, but why not just clientHold it while they were at it? Smile

Well....I don't know, this whois seems completely blank of "registrant details" of any type....

Which, now this domain is/would be in "violation" of ICANN rules/regulations, isn't it? Razz

* - whois data kept extremely vage as to avoid being sued for hacking a third party server by whois

Back to top
View users profile Send private message Visit posters website AIM Address Yahoo Messenger MSN Messenger
Display posts from previous:   
Post new topic   Reply to topic       All -> FavForums -> Complainterator All times are GMT
Goto page Previous  1, 2, 3, 4
Page 4 of 4

 
Quick Reply:
Username: 

Quote the last message
Attach signature (signatures can be changed in profile)
 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You can download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer