CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

$9736.22 of $21422.68
left sidedonated so farneed $11686.46 donated to reach our goalright side, our goal
Help CastleCops serve the community on new servers, Donate Here to reach our goal.

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
Survey
spacer
Was 2007 a good year?

Yes it was a wonderful year
Yes, but there is always room for improvement
Status quo
It was a challenge
Other (leave comment)



Results
Polls

Votes: 952
Comments: 28
block bottom
spacer spacer

XIN NET Removals
Goto page Previous  1, 2, 3, 4  Next
 
Post new topic   Reply to topic       All -> FavForums -> Complainterator [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
trobbins

SIRT Handler
Premium Member

Joined: Feb 19, 2007
Posts: 1171
Location: USA
Premium

PostPosted: Tue Jun 03, 2008 9:41 pm    Post subject:
Reply with quote

Ignore #7

In the beginning when that page failed to load and I didn't realize I could go directly to the edit page, I abandoned it and started over with Todaynic2.

Back to top
View users profile Send private message
tembow

Blue Angel
Premium Member

Joined: Oct 10, 2005
Posts: 2901

Blue Security Premium

PostPosted: Tue Jun 03, 2008 10:19 pm    Post subject:
Reply with quote

Use the Wiki sidebar and see Recent Changes.
Also the overview to links across registrars at
http://wiki.castlecops.com/Bulk_Spam_Reporting

Back to top
View users profile Send private message Visit posters website AIM Address
trobbins

SIRT Handler
Premium Member

Joined: Feb 19, 2007
Posts: 1171
Location: USA
Premium

PostPosted: Thu Jun 05, 2008 2:30 am    Post subject:
Reply with quote

The wiki is now up to date.!

Back to top
View users profile Send private message
AlphaCentauri

SIRT Handler
Premium Member

Joined: Nov 20, 2003
Posts: 2776

Premium

PostPosted: Thu Jun 05, 2008 2:39 am    Post subject:
Reply with quote

trobbins wrote:
The wiki is now up to date.!


Thanks! I am constantly in awe of your ability to track all these domains. Cool

Back to top
View users profile Send private message
tembow

Blue Angel
Premium Member

Joined: Oct 10, 2005
Posts: 2901

Blue Security Premium

PostPosted: Thu Jun 05, 2008 9:30 am    Post subject:
Reply with quote

Acting as a trigger for Xin Net, the wiki entry for Xin Net is proving a wonderful means of cleaning up a huge backlog of illegal domains.

In the past two weeks, Xin Net has gone from a rate of <2% compliance to 60%, and we are talking 13,000 identified sites.
The remaining 5,460 are being removed today, and the task is more than half way through already.

If Xin Net can match TodayNic-1 at 100% of 1,650 requests, we will have a major turn-around. And at the rate they are going, that looks achievable before the end of the next week.

Huge kudos goes to trobbins for tracking and reporting all these sites.

Back to top
View users profile Send private message Visit posters website AIM Address
tembow

Blue Angel
Premium Member

Joined: Oct 10, 2005
Posts: 2901

Blue Security Premium

PostPosted: Thu Jun 05, 2008 1:10 pm    Post subject:
Reply with quote

Today, working into the night, Xin Net removed all but a tiny few of the 13,280 spammed sites reported in the Wiki at http://wiki.castlecops.com/Bulk_Spam_Reporting#Overall_results

Congratulations to the team of "digilantes" who put this campaign together, with an unprecedented result.

Back to top
View users profile Send private message Visit posters website AIM Address
trobbins

SIRT Handler
Premium Member

Joined: Feb 19, 2007
Posts: 1171
Location: USA
Premium

PostPosted: Fri Jun 06, 2008 3:21 am    Post subject:
Reply with quote

461 new domains added to the wiki since 2008-06-04

Back to top
View users profile Send private message
AlphaCentauri

SIRT Handler
Premium Member

Joined: Nov 20, 2003
Posts: 2776

Premium

PostPosted: Fri Jun 06, 2008 5:38 pm    Post subject:
Reply with quote

I thought I'd gather the Chinese names of these companies to make it easier to tell which is which. Unfortunately, it turns out those names are a lot more similar than the English names would suggest. But here goes:

TodayNIC = 广东时代互联科技有限公司
广东
Guangdong
时代
Era

of the Internet
科技
Technology
有限
Limited
公司
Company

Bizcn.com = 厦门华商盛世网络有限公司
厦门
Xiamen
商盛世
Towards Prosperity
网络
Internet
有限
Limited
公司
Company

Xin Net = 北京新网数码信息技术有限公司
北京
Beijing

New

Net
数码
Digital
信息
Information

Technology
有限
Limited
公司
Company
(but usually you just see 新网 "New Net")

Beijing Innovative Linkage Technology (BILT, dns.com.cn) =
北京新网互联科技有限公司

北京
Beijing

New

Net

Internet
科技
Technology
有限
Limited
公司
Company
(Their logo has 新网互 -- plus a fourth character that doesn't seem to want to copy and paste -- which is basically new (xin) net internet).

It must be lots of fun telling them apart in Chinese.

Back to top
View users profile Send private message
AlphaCentauri

SIRT Handler
Premium Member

Joined: Nov 20, 2003
Posts: 2776

Premium

PostPosted: Sat Jun 07, 2008 10:28 am    Post subject:
Reply with quote

Just figured out bizcn.com's logo: 商务中国
商务
business
中国
in China

And I just got spammed with some Penis Enlarge Patch/Anatrim/Erectofix domains registered as .com.cn domains by 北京新网数码信息技术有限公司 (Xin Net) using a registrant name 李小惠 (Li Xiaohui).

Those sites had been using U.S. residents' stolen identities to be registered with more "legitimate" registrars in the past. Did they think we wouldn't figure out this is Xin Net? Talk about out of the frying pan, into the fire. Rolling Eyes

Back to top
View users profile Send private message
trobbins

SIRT Handler
Premium Member

Joined: Feb 19, 2007
Posts: 1171
Location: USA
Premium

PostPosted: Sat Jun 07, 2008 5:02 pm    Post subject:
Reply with quote

I noticed that too last night. I have 370 registered at 北京新网数码信息技术有限公司 (XIN NET) I'm going to add them to the XIN NET wiki page.

Back to top
View users profile Send private message
kamaraju

Corporal
Corporal


Joined: Mar 07, 2007
Posts: 65
Location: USA

PostPosted: Wed Jun 18, 2008 5:54 pm    Post subject:
Reply with quote

I have a question about http://wiki.castlecops.com/index.php?title=XIN_NET_Removals#Name_Servers . I have a bunch of nameservers that I have reported to Xin Net via complainterator. I would like to add these nameservers in the above link. That way I can track the progress of my complaints. However I do not know in what category these nameservers fit in. For example, when I reported successand[dot]com, complainterator also reports ns0[dot]yourfastbox[dot]com etc., But I am not sure if all the sites in ns0[dot]yourfastbox[dot]com are of "canadian pharmacy" type. How can I find out the category for a given nameserver? Is there any deterministic way of doing this?

thanks in advance

Back to top
View users profile Send private message
AlphaCentauri

SIRT Handler
Premium Member

Joined: Nov 20, 2003
Posts: 2776

Premium

PostPosted: Wed Jun 18, 2008 6:58 pm    Post subject:
Reply with quote

kamaraju wrote:
How can I find out the category for a given nameserver? Is there any deterministic way of doing this?


Unfortunately, you pretty much have to look at each domain and see what site they load. There are some useful tools on the spamtrackers site http://spamtrackers.eu/downloads/

IDSpam: will take a list of domains and look up the registrar from the whois, the title from the page source, or both, and output in a text file. If you have a list of domains on URIBL or some similar feeds, it will take that as input without you having to extract the list of domains yourself. Downsides: Some heavily spammed brands, such as Elite Herbal or Canadian Health&Care Mall/My Canadian Pharmacy, will count how many time you visit from the same IP and start giving you a blank page. And the Elite Herbal/King Replica/Canadian Healthcare folks are great for rearranging which brand is on which domain. If you are posting to SiteAdvisor, for instance, your reviews have to take that into account or they won't make any sense a week later. Also, since you are actually visiting these websites, all the usual cautions apply about avoiding malware. I would use a browser other than Internet Explorer and have javascripts turned off, eg. via the Noscript extension for Mozilla browsers. And I'd be sitting nearby to make sure nothing tried to download a file by refreshing the page (generally IDSpam moves to the next lookup too fast for that to happen, but if you see a spam page hanging, watch out for a download window popping up so you can pause the program and cancel the download). In the unlikely event you miscalculate what type of domains you are looking up and you see kiddie porn images on a site, terminate IDSpam and report the domain to Cybertipline (http://www.missingkids.com/cybertip/) to protect yourself from any possibility someone could accuse you of "viewing child porn," since those images will be on your hard drive.

Prefix: will take a list of domains in a text file and do various repetitive tasks from the command prompt window. You can get the list of which domain is on which IP, for instance (good for distinguishing live from parked from dead domains), lookup the whois for each domain and search for terms like "clientHold" or the name of the registrar, etc. This is a faster way to do the registrar lookup than IDSpam, but it won't be able to tell you the spam brand. If you are looking up whois info, it is subject to the usual limitations, eg, the information may not be up to date, or a site that does not say "clientHold" may still be dead for other reasons, at least temporarily.

Back to top
View users profile Send private message
ahoier

SIRT Handler


Joined: Jan 14, 2006
Posts: 1065
Location: USA

PostPosted: Wed Jun 18, 2008 7:25 pm    Post subject:
Reply with quote

The reference to 北京新网数码信息技术有限公司 could/should/may also be added to the "long list" of "AKAs" for XIN Net Tech.... AKA SINO-I...etc.etc.etc Smile

I find myself google searching those characters quite a bit Razz

Luckily the "XIN Net Removals" post on the forums is in spot number 4 (under the "local businesses"/onebox search....), for that query Smile lol.

Back to top
View users profile Send private message Visit posters website AIM Address Yahoo Messenger MSN Messenger
trobbins

SIRT Handler
Premium Member

Joined: Feb 19, 2007
Posts: 1171
Location: USA
Premium

PostPosted: Wed Jun 18, 2008 8:20 pm    Post subject:
Reply with quote

ahoier wrote:
The reference to 北京新网数码信息技术有限公司 could/should/may also be added to the "long list" of "AKAs" for XIN Net Tech.... AKA SINO-I...etc.etc.etc Smile

I find myself google searching those characters quite a bit Razz

Luckily the "XIN Net Removals" post on the forums is in spot number 4 (under the "local businesses"/onebox search....), for that query Smile lol.

Like Todaynic2, that is another branch of XIN NET used for registering .cn domains. Originally, I had included Todaynic2 .cn domains on the same page as Todaynic's .com domain, but then I started to get 1,000's/week of .cn domains, so I started a seperate page for .cn domains. I will do the same for XIN NET .cn domains if they start to increase in number.

Back to top
View users profile Send private message
trobbins

SIRT Handler
Premium Member

Joined: Feb 19, 2007
Posts: 1171
Location: USA
Premium

PostPosted: Wed Jun 18, 2008 8:26 pm    Post subject:
Reply with quote

kamaraju wrote:
I have a question about http://wiki.castlecops.com/index.php?title=XIN_NET_Removals#Name_Servers . I have a bunch of nameservers that I have reported to Xin Net via complainterator. I would like to add these nameservers in the above link. That way I can track the progress of my complaints. However I do not know in what category these nameservers fit in. For example, when I reported successand[dot]com, complainterator also reports ns0[dot]yourfastbox[dot]com etc., But I am not sure if all the sites in ns0[dot]yourfastbox[dot]com are of "canadian pharmacy" type. How can I find out the category for a given nameserver? Is there any deterministic way of doing this?

thanks in advance

I have a single field for brand in my db and I put every brand I know of for each name server in that field. When I export the name servers, they are grouped by the brand field. That is how I put them in the wiki. Now, I didn't put all the name servers there yet, I only added a few to get them started and to see if they could suspend them successfully first before adding any more. I have about 3x as many name servers left as are listed waiting to be put in the wiki.

Back to top
View users profile Send private message
Display posts from previous:   
Post new topic   Reply to topic       All -> FavForums -> Complainterator All times are GMT
Goto page Previous  1, 2, 3, 4  Next
Page 3 of 4

 
Quick Reply:
Username: 

Quote the last message
Attach signature (signatures can be changed in profile)
 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You can download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer