CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
spacer spacer

Set-up problem
Goto page Previous  1, 2, 3, 4  Next
 
Post new topic   Reply to topic       All -> FavForums -> Complainterator [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
pwillener

SRT Trainee
SRT Trainee
Premium Member

Joined: Apr 17, 2006
Posts: 1830
Location: Japan
Premium

PostPosted: Sat Mar 15, 2008 8:53 am    Post subject:
Reply with quote

I had another one today, but this time the spam domain registrar was different from the name server registrar. (Sorry, I canceled the message without saving it.)

I noticed that not only the domain name in the subject line was wrong, but also all To and Cc addresses were those for the name server registrar complaint. So all header information were inconsistent with the body information.

Back to top
View users profile Send private message Visit posters website
Krivoi

Sergeant
Sergeant


Joined: Mar 03, 2008
Posts: 90


PostPosted: Sun Mar 16, 2008 10:00 pm    Post subject:
Reply with quote

tembow, your efforts are much appreciated!

Windows XP SP2 here, Thunderbird. When I use Complainterator I always make sure I have a blank Internet Explorer page open, with the url address line "about:blank" highlighted and the cursor within the page. I check that Thunderbird is already open.

All the DNS pages are opening up nicely now, but I still get the partially formed emails; usually four blank emails to the correct addressees with blank subject line, but occasionally with parts of the report in the subject line.

Back to top
View users profile Send private message
Krivoi

Sergeant
Sergeant


Joined: Mar 03, 2008
Posts: 90


PostPosted: Tue Mar 25, 2008 2:22 pm    Post subject:
Reply with quote

I thought I should post this set-up issue as a separate report, since it's on one of the work computers:

Windows 2000 v5.00, service pack 4.
Internet Explorer 6.0
Outlook Express 6.00

In Complainterator, the first DNS page opens up, but I can never get past the error message "Name servers not found" even if I pause the script.

Not a major problem, as I just forward a list of the offending nameservers to one of my other Complainterators and report from there. Very Happy

Back to top
View users profile Send private message
AlphaCentauri

SIRT Handler
Premium Member

Joined: Nov 20, 2003
Posts: 2886

Premium

PostPosted: Tue Mar 25, 2008 3:17 pm    Post subject:
Reply with quote

Krivoi wrote:
In Complainterator, the first DNS page opens up, but I can never get past the error message "Name servers not found" even if I pause the script.


Which domain were you reporting?

Back to top
View users profile Send private message
Krivoi

Sergeant
Sergeant


Joined: Mar 03, 2008
Posts: 90


PostPosted: Tue Mar 25, 2008 4:05 pm    Post subject:
Reply with quote

The most recent one was:

cheapndea.com

I've just tried it again, & get the same error. I get as far as the dnsstuff page telling me it's a Xin Net ns-martian.com site [surprise, surprise!], then get the "could not find name servers" error message.

All feedback is appreciated.

Back to top
View users profile Send private message
ahoier

SIRT Handler


Joined: Jan 14, 2006
Posts: 1102
Location: USA

PostPosted: Tue Mar 25, 2008 4:38 pm    Post subject:
Reply with quote

What speed do you have Complainterator set to? Maybe try increasing it +2 or something. I'm using 3, and it worked fine, using IE7 with the suppress mail setting.

Back to top
View users profile Send private message Visit posters website AIM Address Yahoo Messenger MSN Messenger
AlphaCentauri

SIRT Handler
Premium Member

Joined: Nov 20, 2003
Posts: 2886

Premium

PostPosted: Tue Mar 25, 2008 4:45 pm    Post subject:
Reply with quote

It's working okay for me. I'm not sure why it would make a difference which computer you are using, either.

Back to top
View users profile Send private message
Krivoi

Sergeant
Sergeant


Joined: Mar 03, 2008
Posts: 90


PostPosted: Tue Mar 25, 2008 4:53 pm    Post subject:
Reply with quote

Hi again.

I've tied it at speeds 3,5,10 and 20 but always the error "name servers not found". I get this with every site I enter on this machine.

I should confirm we are using broadband, and I am not aware of any speed problems. It couldn't be some kind of firewall/anti-virus issue, could it?

Back to top
View users profile Send private message
AlphaCentauri

SIRT Handler
Premium Member

Joined: Nov 20, 2003
Posts: 2886

Premium

PostPosted: Tue Mar 25, 2008 5:11 pm    Post subject:
Reply with quote

I would think if it were an antivirus issue you would get a popup from the antivirus program, not complainterator. And I would expect a firewall to get involved at the point you tried to send the emails with those spammy domains in them, not when you are just visiting another page on the same DNSstuff domain it let you visit for the traversal and whois for the domain. Xin Net does block access to its whois server, but I don't know that it would only do that for your job computer (unless you work for ICANN Wink )

Have you tried clicking the "who.is" choice so you only use DNSstuff for the traversal? (The checkbox is in the initial window where you enter the domain to report.) Another option is to try setting your browser to use a proxy if they will allow that on your job.

Back to top
View users profile Send private message
trobbins

SIRT Handler
Premium Member

Joined: Feb 19, 2007
Posts: 1180
Location: USA
Premium

PostPosted: Tue Mar 25, 2008 7:47 pm    Post subject:
Reply with quote

XIN Net's whois server goes down quite often. When I collect domains, I don't use dnsstuff's whois, but my own. Sometimes I get domains without the registrar info and when I check, XIN Net's whois server is down. If I then check on dnsstuff, I can get the whois info but no dns info. Apparently, dnsstuff cache's the first query for a domain because if the domain is really new, I don't get anything from dnsstuff when XIN Nets whois server is down.

Back to top
View users profile Send private message
ahoier

SIRT Handler


Joined: Jan 14, 2006
Posts: 1102
Location: USA

PostPosted: Tue Mar 25, 2008 8:17 pm    Post subject:
Reply with quote

What browser are you using?

Perhaps take a screenshot (PrintScreen) of your screen at the time of this "error" that complainterator gives.

I know it can sometimes take a bit for the traversal to complete since there's a couple steps, and time-outs can occur, but I haven't had too many problems...

What browser are you using? If IE, is Portable Firefox an option? Smile Or another alternative? Something to try.

From what it seems, Complainterator is grabbing the contents of the traversal page repeatedly (using CTRL+A/Select All?) _until_ it finds the traversal final results.

Next domain you report, try using the Pause/Break key, to allow the DNSStuff site to "catch up" for a couple seconds, then hit the button again once the traversal page is fully loaded; Complainterator should be able to then grab the text/results and goto the next step of the process.

Back to top
View users profile Send private message Visit posters website AIM Address Yahoo Messenger MSN Messenger
tembow

Blue Angel
Premium Member

Joined: Oct 10, 2005
Posts: 2942

Blue Security Premium

PostPosted: Tue Mar 25, 2008 9:37 pm    Post subject:
Reply with quote

If you do not select Who.is in the front screen, you should see on the first lookup screen:

Code:

WHOIS - cheapndea.com
mail iconEmail link to results
Generated by www.DNSstuff.com

Registrar:     XIN NET TECHNOLOGY CORPORATION
Status:        ok
Dates:         Created 24-mar-2008   Updated 25-mar-2008  Expires 24-mar-2009
DNS Servers:   NS1.NS-MARTIAN.COM  NS2.NS-MARTIAN.COM 

I was referred to whois.paycenter.com.cn; I'm looking it up there.
and the bottom of the page should have "© Copyright 2000-2008 DNSstuff, LLC All Rights Reserved"

The next tabbed page should contain the traversal:
Code:

DNS Traversal for cheapndea.com.
mail iconEmail link to results
Generated by www.DNSstuff.com at 21:34:04 GMT on 25 Mar 2008.



Getting NS record list at g.root-servers.net... Done!
Looking up at the 13 com. parent servers:

Server   Response   Time
a.gtld-servers.net [192.5.6.30]   ns1.ns-martian.com. ns2.ns-martian.com.    62ms
etc
and end with "© Copyright 2000-2008 DNSstuff, LLC All Rights Reserved"
Try again and copy / paste what you are seeing.

Back to top
View users profile Send private message Visit posters website AIM Address
Krivoi

Sergeant
Sergeant


Joined: Mar 03, 2008
Posts: 90


PostPosted: Tue Mar 25, 2008 11:54 pm    Post subject:
Reply with quote

Thanks everyone - I'll be in touch once I've tried those suggestions.

Meanwhile, I'll check Complainterator on a newer PC at that same office.

Back to top
View users profile Send private message
Krivoi

Sergeant
Sergeant


Joined: Mar 03, 2008
Posts: 90


PostPosted: Wed Mar 26, 2008 3:45 pm    Post subject:
Reply with quote

Me again.

I get the same error on a completely different computer elsewhere in the building. It is running these:

Windows XP Home 2002 SP2
IE7
Outlook Express 6

The first page is exactly as Tembow describes, but I can't get past there on either machine. I've uploaded a screen grab to Imageshack, but can't get it to preview for some reason. I'll post it soon, once I've checked the code on some example images here on CastleCops.

I'm beginning think the problem's something to do with the particular network set-up in this building.

Back to top
View users profile Send private message
ahoier

SIRT Handler


Joined: Jan 14, 2006
Posts: 1102
Location: USA

PostPosted: Wed Mar 26, 2008 4:15 pm    Post subject:
Reply with quote

So it's the traversal page that is not loading for you properly?

Back to top
View users profile Send private message Visit posters website AIM Address Yahoo Messenger MSN Messenger
Display posts from previous:   
Post new topic   Reply to topic       All -> FavForums -> Complainterator All times are GMT
Goto page Previous  1, 2, 3, 4  Next
Page 3 of 4

 
Quick Reply:
Username: 

Quote the last message
Attach signature (signatures can be changed in profile)
 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You can download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer