CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

$9736.22 of $21422.68
left sidedonated so farneed $11686.46 donated to reach our goalright side, our goal
Help CastleCops serve the community on new servers, Donate Here to reach our goal.

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
Survey
spacer
Was 2007 a good year?

Yes it was a wonderful year
Yes, but there is always room for improvement
Status quo
It was a challenge
Other (leave comment)



Results
Polls

Votes: 937
Comments: 25
block bottom
spacer spacer

Complainterator: enhancement request

 
Post new topic   Reply to topic       All -> FavForums -> Complainterator [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
pwillener

SRT Trainee
SRT Trainee
Premium Member

Joined: Apr 17, 2006
Posts: 1721
Location: Japan
Premium

PostPosted: Thu Jul 03, 2008 4:43 am    Post subject: Complainterator: enhancement request
Reply with quote

Although the Complainterator is already a great resource, there is always room for a little improvement. Allow me to present an enhancement request.

I try not to send the same removal request more than once in a day, so I always check my Sent Items if I've already sent a specific request today.

It would be great if Complainterator could check by itself (from the date in the stored text file in the Archive folder) if the current request has already been sent on the same calendar day.

Is that possible? Easy? Useful?

Back to top
View users profile Send private message Visit posters website
pwillener

SRT Trainee
SRT Trainee
Premium Member

Joined: Apr 17, 2006
Posts: 1721
Location: Japan
Premium

PostPosted: Thu Jul 03, 2008 4:52 am    Post subject:
Reply with quote

I would also love a little help from Complainterator with munging (to prevent bouncing).

I do two types of munging

  1. worldiwins.com ↷ worldiwins~DOT~com : I obviously have to do that myself when I know that it goes to a "bouncer".
  2. http://who.is/whois-net/ip-address/worldiwins.com/http://who.is/whois-net/ip-address/worldiwins%2Ecom/ : that would be great if Complainterator could do that automatically (and always) for me.
    The same should also be done in the traversal link.

Back to top
View users profile Send private message Visit posters website
ahoier

SIRT Handler


Joined: Jan 14, 2006
Posts: 1024
Location: USA

PostPosted: Thu Jul 03, 2008 1:52 pm    Post subject:
Reply with quote

As far as munging goes.

In my experience with BILT-reporting I've found that the who.is and/or dnsstuff links don't need to be "munged".


The message should get through, simply by munging the "target" in the subject line, and then the domain name itself within the e-mail body.

Well....that is until SURBL (or their own personal filters.....lol) add http://who.is/ and/or http://*.dnsstuff.com/ to their filter Razz


So in this case, for me I would use:

Subject: Removal request: worldiwins_com

And then in the body, where it would list worldiwins.com and/or the list of spam-related nameservers, under-score the dots and it should be good to go. No need to munge the domains within the dnsstuff or who.is urls - since the SURBL only "queries" _who.is_ and _dnsstuff.com_ I suppose?

Done

But yea, I know Complainterator was created as a simple set and go app, but "templates" would be neat too.

I.E.: For chinese registrars it could be auto-set to include the spamtrackers.hk links, and the new Chinese-translated castlecops wiki removal directions.

intention - to add the Chinese updated version to the .hk site

Lately, I've just been using that "signature file" and "scooting everything up" into the body of the report. Kinda as a reminder to not forget any pertinent evidence.

Back to top
View users profile Send private message Visit posters website AIM Address Yahoo Messenger MSN Messenger
secure_blue

Corporal
Corporal
Premium Member

Joined: May 05, 2006
Posts: 73
Location: USA
Premium

PostPosted: Thu Jul 10, 2008 1:58 pm    Post subject:
Reply with quote

I would like to suggest that when Complainterator finds NS of Everydns, it not originate to Dotster, but rather add a :CC to the spamdomain (that was reported) of ABUSE@EVERYDNS.NET

This is presently problematic as WHOIS does, indeed, ID everydns and the end-user is lead to believe the spam NS is everydns.

TIA,

Back to top
View users profile Send private message
AlphaCentauri

SIRT Handler
Premium Member

Joined: Nov 20, 2003
Posts: 2668

Premium

PostPosted: Thu Jul 10, 2008 3:55 pm    Post subject:
Reply with quote

Everydns.net is not the registrar, so Complainterator would still address the report to Dotster. In this case, you would just not send the report, since it's not a spammer nameserver, and suspending it would impact innocent domains.

If someone is abusing everydns.net's service, it's appropriate to notify them, just as you would notify Geocities, Blogger, url shortening services, or ISPs for hijacked servers, but that would require a different software program to automate reporting.

Back to top
View users profile Send private message
Display posts from previous:   
Post new topic   Reply to topic       All -> FavForums -> Complainterator All times are GMT
Page 1 of 1

 
Quick Reply:
Username: 

Quote the last message
Attach signature (signatures can be changed in profile)
 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You can download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer