CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
spacer spacer

Add / Change Registrar
Goto page Previous  1, 2, 3, 4, 5 ... 9, 10, 11, 13, 14, 15  Next
 
Post new topic   Reply to topic       All -> FavForums -> Complainterator [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
Tromso

Corporal
Corporal
Premium Member

Joined: May 25, 2007
Posts: 59

Premium

PostPosted: Mon Jun 30, 2008 3:16 pm    Post subject: T.H.NIC Co., Ltd.
Reply with quote

Spammed domain = tontan-prayatod.go.th
Registrar = T.H.NIC Co., Ltd.
Contact = abuse AT thnic.co.th or postmaster AT thnic.co.th

tontan-prayatod.go.th was used for Lloyds Phishing spam

Could not find T.H.NIC Co., Ltd. on ICANN registrar lists at:
http://www.icann.org/registrars/accredited-list.html
http://www.internic.net/contact.html (can only find DotArai Co., Ltd. for Thailand)

T.H.NIC Co., Ltd. registrar appears to be responsible for the .th TLD ( according to http://www.webnic.cc/ps_domain_registrationagreement.html )

Found T.H.NIC Co., Ltd. policy page in English at:
http://www.thnic.co.th/index.php?page=policy

Could not find an email address for a contact so am trying abuse AT thnic.co.th or postmaster AT thnic.co.th

Have sent a report to ICANN to ask them to add contact details for T.H.NIC Co., Ltd. to their Registrar Accreditation Lists

Back to top
View users profile Send private message
AlphaCentauri

SIRT Handler
Premium Member

Joined: Nov 20, 2003
Posts: 2851

Premium

PostPosted: Mon Jun 30, 2008 4:12 pm    Post subject:
Reply with quote

for .md TLD domains (country code=Moldova, but being marketed outside that country for medical websites; registrations managed by a U.S. company)

abuse report email:
support[at]max.md

whois server is http://www.max.md/whois/

The sample domain I have is sntrst.md, but the traversal is a little screwy, maybe because it was just registered in the last few hours and hasn't propagated.

Back to top
View users profile Send private message
AlphaCentauri

SIRT Handler
Premium Member

Joined: Nov 20, 2003
Posts: 2851

Premium

PostPosted: Mon Jun 30, 2008 5:55 pm    Post subject:
Reply with quote

Re: OnlineNIC.com's contact address. From their website:

Quote:
OnlineNIC has implemented a forms based process that has the following benefits:

* Directs your email to the specific individual(s) best able to help with your question.
* Online Knowledge base & FAQ system is convenient for effective and handy trouble shooting.
* Integrated Live Support for real time trouble shooting.(Coming soon)
Helps us manage and improve our services and website.
Just login http://support.onlinenic.com , then you will experience a completely new trip.
Note: To better serve our much-valued customers, we categorize our customers into 3 different regions, namely Europe & Africa, America, Asia Pacific. To ensure that your requests will be handled timely and properly, please kindly select the right region you are in. Much appreciate your cooperation!

Submit a question by logging in http://support.onlinenic.com

To contact our Support Team
Please use the above online ticket system to submit your requests as we will be cancelling support@onlinenic.com soon; if you prefer to send us an email, please use the following email addresses for different regions -->
America cs-us@OnlineNIC.com
Europe & Africa cs-eu@OnlineNIC.com
Asia & Pacific cs-ap@OnlineNIC.com


There is a separate email address if you are unhappy with their service at complaints@onlinenic.com.

Back to top
View users profile Send private message
ahoier

SIRT Handler


Joined: Jan 14, 2006
Posts: 1085
Location: USA

PostPosted: Mon Jun 30, 2008 6:46 pm    Post subject:
Reply with quote

I CCed the complaints address, but OnlineNic seems extremely stubborn...(see CastleCops Link/p1102266-regarding_OnlineNIC.html#1102266).

Looking for some magic words/formula to throw at em Razz

Back to top
View users profile Send private message Visit posters website AIM Address Yahoo Messenger MSN Messenger
pwillener

SRT Trainee
SRT Trainee
Premium Member

Joined: Apr 17, 2006
Posts: 1810
Location: Japan
Premium

PostPosted: Tue Jul 01, 2008 4:06 am    Post subject:
Reply with quote

Spammed domain: middhs.com
Registrar: Xiamen Bizcn Computer & Network Co. Ltd. (471)
Contact: abuse~AT~bizcn.com

Back to top
View users profile Send private message Visit posters website
ahoier

SIRT Handler


Joined: Jan 14, 2006
Posts: 1085
Location: USA

PostPosted: Tue Jul 01, 2008 1:59 pm    Post subject:
Reply with quote

Spammed domain: fleawirez.com
Registrar: BASIC FUSION, INC.
Contact: info@basicfusion.com

Nameserver used by above spammed domain: dnsnameserver.org
Registrar: Basic Fusion Inc (R1329-LROR)
Contact: info@basicfusion.com

Note: dnsnameserver.org may be another valid/exception to the complainterator exceptions list (re: the GANDI incident).

Back to top
View users profile Send private message Visit posters website AIM Address Yahoo Messenger MSN Messenger
efa

Lieutenant
Lieutenant


Joined: Aug 31, 2007
Posts: 162
Location: Italy

PostPosted: Fri Jul 04, 2008 4:47 pm    Post subject:
Reply with quote

Spammed Domain: cnplot.com
Registrar: FastDomain Inc. (United States)
Registrar: FASTDOMAIN, INC.
Contact: dan@bluehost.com

Back to top
View users profile Send private message
efa

Lieutenant
Lieutenant


Joined: Aug 31, 2007
Posts: 162
Location: Italy

PostPosted: Fri Jul 04, 2008 4:49 pm    Post subject:
Reply with quote

tembow wrote:

dnsnameserver.org should be exempted from removal requests


would be very usefull another online common "database" like:
http://www.spamtrackers.eu/downloads/Complainterator/complainterator.contacts.txt
but with "Registrar" and "registrar main NS".
Or maybe all toghether:
Registrar ~ contactEmailsTo contactEmailsCc ~ registrarMainNS

Back to top
View users profile Send private message
efa

Lieutenant
Lieutenant


Joined: Aug 31, 2007
Posts: 162
Location: Italy

PostPosted: Fri Jul 04, 2008 4:59 pm    Post subject:
Reply with quote

I cannot found Registrar in 'kentenhausen.de' whois report.

Back to top
View users profile Send private message
ahoier

SIRT Handler


Joined: Jan 14, 2006
Posts: 1085
Location: USA

PostPosted: Fri Jul 04, 2008 6:52 pm    Post subject:
Reply with quote

I think the "know legit dns servers" is embedded within Complainterator, so that it doesn't generate reports for a registrar to suspend their own nameservers ;)

It's one of those things that the "typical user" doesn't and shouldn't be able to change :)

Which is I'm sure why tembow has chosen to embed it within the operations of complainterator "under the hood" per se.



@kentenhausen.de - I noticed the same thing....

Though, contact details may be gotten from the whois server's root homepage.

whois.denic.de

But, omit the whois. and make it

http://denic.de/

Back to top
View users profile Send private message Visit posters website AIM Address Yahoo Messenger MSN Messenger
efa

Lieutenant
Lieutenant


Joined: Aug 31, 2007
Posts: 162
Location: Italy

PostPosted: Sat Jul 05, 2008 8:50 am    Post subject:
Reply with quote

ahoier wrote:
It's one of those things that the "typical user" doesn't and shouldn't be able to change Smile
Which is I'm sure why tembow has chosen to embed it within the operations of complainterator "under the hood"


Surely I cannot understand why is dangerous to pubblish such list?

Back to top
View users profile Send private message
tembow

Blue Angel
Premium Member

Joined: Oct 10, 2005
Posts: 2930

Blue Security Premium

PostPosted: Sat Jul 05, 2008 10:15 am    Post subject:
Reply with quote

That is a good suggestion.

Complainterator is undergoing two higher priority updates right now

1. addition of URL obfuscation for the registrars who have SURBL blocking

2. Redesign of the Contacts file to allow a "fuzzy" search on name, which will reduce the number of duplicates in that list.

Many of the registrars' own name servers are known, but there are many where this needs to be found out.

Back to top
View users profile Send private message Visit posters website AIM Address
spam-review

Cadet
Cadet


Joined: Jul 04, 2008
Posts: 4


PostPosted: Sat Jul 05, 2008 7:25 pm    Post subject:
Reply with quote

Complainterator 21.6 wrote:
INTERCOSMOS MEDIA GROUP, INC. D/B/A DIRECTNIC.COM
Dear Registrar

This is a request for you to remove the domain directnic.com
and to remove its name server Address record ns1.directnic.com [69.46.234.245], and ns0.directnic.com [69.46.233.245]

[...]


Added in V22, thanks

Back to top
View users profile Send private message
tembow

Blue Angel
Premium Member

Joined: Oct 10, 2005
Posts: 2930

Blue Security Premium

PostPosted: Sat Jul 05, 2008 10:08 pm    Post subject:
Reply with quote

The list of name servers that are protected from removal requests

01isp.com
1and1.com
4servers.com
afilias-nst.org
ait.com
aitdomains.com
akam.net
anytimesites.com
aol.com
apnic.net
badwhoisshutdown.com
blogspot.com
bnmq.com
by.ru
cnomy.com
comnameservice.com
crispnames.com
crsnic.net
ddns-service.com
directnic.com
dns.com.cn
dnsbakler.com
dnsexit.com
dnsleader.com
dnsnameserver.com
dnsnameserver.org
domaincontrol.com
domaindiscount24.net
domainservice.com
domainsite.com
dootall.com
dotster.com
dsredirection.com
dtdns.com
dtns.com
eadnetworks.com
easydns.com
edu.hk
enom.com
expedient.com
fabulous.com
fastpark.net
foundationapi.com
fraudshutdown.com
gandi.net
gkg.net
godaddy.com
google.com
hosting365.ie
hostmonster.com
iana-servers.net
iana-servers.org
icann.org
informtelecom.ru
interland.net
internet-fr.net
ipower.com
ipowerdns.com
ipowerweb.net
itsyourdomain.com
joker.com
lockeddns.com
lycos.com
melbourneit.com
momiker.com
msft.net
mydomain.com
name-services.com
name.net
nameit.net
nameresolve.com
names4ever.com
namescout.com
nameself.com
naunet.ru
nease.com
netfirms.com
netsol.com
nic.ru
ns-not-in-service.org
nsiregistry.net
onlineaccess.net
onlinenic.com
onlinenic.net
opensrs.net
optus.net
ovh.com
pairnic.com
pochta.ru
prserv.net
r01.ru
register.com
registrationtek.com
ripn.net
secureserver.net
space2host.net
spam-and-abuse.com
spamshutdown.com
spirit-parked-pages.net
srsplus.com
telstra.net
theservercompany.com
tinyurl.com
todayisp.com
trafficclub.com
trellian.com
tucows.com
twnic.net.tw
ultradns.info
ultradns.net
ultradns.org
value-domain.com
worldnic.com
xinnet.cn
xinnetdns.com
yahoo.com
yesnic-delete.com

www.complainterator.com

Back to top
View users profile Send private message Visit posters website AIM Address
trobbins

SIRT Handler
Premium Member

Joined: Feb 19, 2007
Posts: 1176
Location: USA
Premium

PostPosted: Sun Jul 06, 2008 5:12 pm    Post subject:
Reply with quote

Registrar: 北京新网互联科技有限公司

Spammed Domain: wprnryp.cn
Brands:
Powerenlarge
Canadian Healthcare
King Replica

Putting the Chinese char's in google search returns 35.com as number 1

Back to top
View users profile Send private message
Display posts from previous:   
Post new topic   Reply to topic       All -> FavForums -> Complainterator All times are GMT
Goto page Previous  1, 2, 3, 4, 5 ... 9, 10, 11, 13, 14, 15  Next
Page 10 of 15

 
Quick Reply:
Username: 

Quote the last message
Attach signature (signatures can be changed in profile)
 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You can download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer