CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
spacer spacer

Set-up problem
Goto page 1, 2, 3, 4  Next
 
Post new topic   Reply to topic       All -> FavForums -> Complainterator [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
Krivoi

Sergeant
Sergeant


Joined: Mar 03, 2008
Posts: 90


PostPosted: Mon Mar 03, 2008 11:02 am    Post subject: Set-up problem
Reply with quote

Hello there - good work everyone, by the way!

I'm a very successful spammer-trasher via Knujon and SpamCop; my home email & multiple bulk work emails at various companies are all on the same lists despite being completely unrelated so my apparently unconnected reports have been a rather effective pincer movement! I look after sales@, enquiries@, etc for some well-known companies, and I have helped to wipe out several individuals! Very Happy

I have one remaining "pet" spammer, and I can see this name-based method will trash him at a stroke. However, I am having problems setting up Complainterator:

I have successfully downloaded Complainterator, latest version. However, when I put in the spam site (in the correct format), eg
videofsilms.cn

I only get as far as a WHOIS web page with all the details, but no composed complaint. I get the same problem on both home pc and work pc.

A second issue, both at home and at work, is that 9 times out of 10 I get the WHOIS failed message, even with a long wait time. Again, any ideas?

Please advise.

Best wishes, and keep up the good work!

Back to top
View users profile Send private message
AlphaCentauri

SIRT Handler
Premium Member

Joined: Nov 20, 2003
Posts: 2899

Premium

PostPosted: Mon Mar 03, 2008 10:38 pm    Post subject:
Reply with quote

Preparing reports for videofsilms.cn works okay for me. But I can see that the traversal is very slow. When you see it stuck on a traversal page and the text highlighting flashing, hit the pause/break key (upper right keyboard) until the page finishes loading, then hit it again to restart Complainterator. Otherwise Complainterator may time out first.

The traversal for videofsilms.cn showed 5 different IP addresses on multiple ISP's IP ranges, so it's probably hosted on a botnet of trojan-infected computers. That's worth pointing out in your report. It is evidence the sites are illegal and also that there is no ISP knowingly hosting the site that can shut it down for spamming. The registrars for the domain and/or nameservers are the only ones who can effectively shut the site down by stopping the domain from resolving to any of the potentially hundreds of infected servers.

As far as timing out a lot, if you are using who.is for your lookups, it has been having some problems the last few days. Try doing the report without checking the who.is option and see if it works any better. (Or let us know which domains are causing problems -- some like those .es phishing domains, don't even have a whois server, so neither who.is nor dnsstuff can provide the registrar name.)

Back to top
View users profile Send private message
pwillener

SRT Trainee
SRT Trainee
Premium Member

Joined: Apr 17, 2006
Posts: 1840
Location: Japan
Premium

PostPosted: Tue Mar 04, 2008 6:35 am    Post subject:
Reply with quote

Welcome to the CC forum and Complainterator.

Complainterator does have a few problems, but they can be overcome.

  1. It does not work with Firefox (for me); I can only use Internet Explorer. FF must be closed when using it with IE.
  2. It works best when
    • the address bar is selected (F6)
    • the mouse pointer is inside the IE window
    • mouse & keyboard is left alone while Cpltr is doing its work

Even with these precautions, there are occasional snags
  • the address bar sometimes goes blank; leaving Cpltr hang; press F8 to terminate, and restart
  • DNSstuff and Who.is sometimes take too long to respond, and Cpltr "lost a window". Sorry, start again

Of course, the mail client of your choice must be active.

Back to top
View users profile Send private message Visit posters website
tembow

Blue Angel
Premium Member

Joined: Oct 10, 2005
Posts: 2945

Blue Security Premium

PostPosted: Tue Mar 04, 2008 6:55 am    Post subject:
Reply with quote

If anyone has any problem making Complainterator work (eg "Firefox does not work for me" then post the details here so that bugs can be addressed.

Relevant information -

    Language used (English / French / German etc)
    Browser used, and release level and any unusual settings, plug-ins etc
    Error message relating to the problem
    Observations of behavior leading up to the failure
    Operating System and release level
    Screen shots showing the problem

If you get a timeout, or can foresee that response is slow and may lead to a timeout, you can either
    1. use the "de-accelerator" to slow the program down
    2. press Pause until the response catches up, and press it again to release the program

Remember to have your email program running before starting Complainterator.

Suggestions for improvements are welcome.

Back to top
View users profile Send private message Visit posters website AIM Address
Jim_P

Sergeant
Sergeant
Premium Member

Joined: Apr 19, 2004
Posts: 133

Premium

PostPosted: Tue Mar 04, 2008 11:50 am    Post subject:
Reply with quote

[
Of course, the mail client of your choice must be active.[/quote]

Back to top
View users profile Send private message
Jim_P

Sergeant
Sergeant
Premium Member

Joined: Apr 19, 2004
Posts: 133

Premium

PostPosted: Tue Mar 04, 2008 1:02 pm    Post subject:
Reply with quote

It must also be the default broweser

Back to top
View users profile Send private message
AlphaCentauri

SIRT Handler
Premium Member

Joined: Nov 20, 2003
Posts: 2899

Premium

PostPosted: Tue Mar 04, 2008 3:29 pm    Post subject:
Reply with quote

I am able to use it with my default browser Seamonkey (equivalent to Firefox+Thunderbird email) and my emails will go out through Seamonkey even though I have had to make Outlook my Windows default email program in order to use the address book for faxing. So the email program that the browser recognizes as default is the one that counts.

One big caveat is to close any browser windows already open for any kind of whois lookup sites (unless there is only one open and you are starting Complainterator from that particular window). Complainterator should open up multiple tabs on the same window, but if there are other separate whois windows open, it tends to jump around between them and create chimeric reports (mixing up which domain goes with which registrar).

Back to top
View users profile Send private message
Krivoi

Sergeant
Sergeant


Joined: Mar 03, 2008
Posts: 90


PostPosted: Tue Mar 04, 2008 8:47 pm    Post subject:
Reply with quote

Thanks for the replies, everyone - we're getting there. I hope this becomes a useful thread for anyone with set-up issues.

Ok, I'll report back in a day or two as I'm getting different issues on two differently set-up PCs. One thing I have found is that having had Google advanced search as my home page may have been confusing the script. With a blank home page I seem to get further than before, but not yet all the way - the furthest has been an error message about not reaching the traversal page.

The offending spams to my home PC are all for sites such as:

videofiams.cn
vidrofilms.cn
videofixms.cn
videofdlms.cn

-you get the idea!

If anyone wants to report them on my behalf please feel free to go ahead and let me know! Meanwhile I'll carry on with my efforts - the main objective is still to terminate our work spammer. Very Happy

Back to top
View users profile Send private message
AlphaCentauri

SIRT Handler
Premium Member

Joined: Nov 20, 2003
Posts: 2899

Premium

PostPosted: Tue Mar 04, 2008 9:29 pm    Post subject:
Reply with quote

I did report the first one. Both the domain and its nameservers are hosted on botnets, and I was actually able to telephone the person whose identity was stolen to register the nameservers, so I could definitively tell Tucows that it was a fraudulent registration. Hopefully they will deep-six the nameservers and bring down the lot of them. Unfortunately, it apparently takes more than 24 hours for them to act.

Back to top
View users profile Send private message
Krivoi

Sergeant
Sergeant


Joined: Mar 03, 2008
Posts: 90


PostPosted: Tue Mar 04, 2008 9:51 pm    Post subject:
Reply with quote

Heh, that's fantastic, AlphaCentauri! Nice work. Thanks so much. I can see this is going to be fun... I'll let you all know if I get any more vid*ofi*ms.cn spams! Somehow I have a feeling they are going to reduce. Very Happy

Back to top
View users profile Send private message
tembow

Blue Angel
Premium Member

Joined: Oct 10, 2005
Posts: 2945

Blue Security Premium

PostPosted: Wed Mar 05, 2008 3:23 am    Post subject:
Reply with quote

While reporting those, feel free to add a request to remove the whole lot. The rest of the family (refer: http://rss.uribl.com/ns/exponatomuze_com.html ) include
dvideofilms.cn
fastvideoffs.cn
fastvideomfs.cn
fastvideopfs.cn
fastvideorfs.cn
fastvideosfs.cn
fastvideovfs.cn
fastvidetofs.cn
fastvidexofs.cn
nvideofilms.cn
pvideofilms.cn
vcdeofilms.cn
vddeofilms.cn
vhdeofilms.cn
videcfilms.cn
videdfilms.cn
videffilms.cn
videhfilms.cn
videiofilms.cn
videkofilms.cn
videocfilms.cn
videodfilms.cn
videoefilms.cn
videofidlms.cn
videofielms.cn
videofiglms.cn
videofiilms.cn
videofilfdssdfms.cn
videofilgs.cn
videofilhs.cn
videofilks.cn
videofilmq.cn
videofilmt.cn
videofilmw.cn
videofilsdfses.cn
videofinms.cn
videofiqms.cn
videofitms.cn
videofnilms.cn
videofqlms.cn
videofsilms.cn
videofslms.cn
videofwlms.cn
videohfilms.cn
videoofilms.cn
videotilms.cn
videovilms.cn
videowfilms.cn
videowilms.cn
videoxfilms.cn
videozilms.cn
vidheofilms.cn
vidhofilms.cn
vidjofilms.cn
vidkofilms.cn
vidlofilms.cn
vidoeofilms.cn
vidoofilms.cn
vidpeofilms.cn
vidreofilms.cn
vidteofilms.cn
viideofilms.cn
vijdeofilms.cn
vikdeofilms.cn
vildeofilms.cn
vimdeofilms.cn
vipdeofilms.cn
vipeofilms.cn
viqeofilms.cn
vireofilms.cn
viseofilms.cn
viveofilms.cn
vkideofilms.cn
vmideofilms.cn
vnideofilms.cn
vpdeofilms.cn
vwdeofilms.cn
vxdeofilms.cn
vzdeofilms.cn

Back to top
View users profile Send private message Visit posters website AIM Address
pwillener

SRT Trainee
SRT Trainee
Premium Member

Joined: Apr 17, 2006
Posts: 1840
Location: Japan
Premium

PostPosted: Wed Mar 05, 2008 4:58 am    Post subject:
Reply with quote

tembow wrote:
If anyone has any problem making Complainterator work (eg "Firefox does not work for me" then post the details here so that bugs can be addressed.

Thank you for the encouragement! Smile

So, I opened Firefox, logged in to DNSstuff, then ran Complainterator, with notebook in hands to note exactly what's going wrong...

Well - nothing was going wrong; everything works perfectly as it should. In fact it seems to run better than with IE - no 'lost a window' message occurred.

So it was just a false alarm, probably from errors I encountered some time ago with a much older version. (It would constantly select & copy the wrong tab, not the active tab.)

So, for me at least, everything works well Cool

Back to top
View users profile Send private message Visit posters website
tembow

Blue Angel
Premium Member

Joined: Oct 10, 2005
Posts: 2945

Blue Security Premium

PostPosted: Wed Mar 05, 2008 7:50 pm    Post subject:
Reply with quote

tembow wrote:
While reporting those, feel free to add a request to remove the whole lot. The rest of the family (refer: http://rss.uribl.com/ns/exponatomuze_com.html ) include
dvideofilms.cn
.. snipped 75 names
vzdeofilms.cn


The name server has been deactivated and all those sites are out.
Thank you, Tucows!

Registrar: TUCOWS INC.
Whois Server: whois.tucows.com
Referral URL: http://domainhelp.opensrs.net
Name Server: NS1.EXPONATOMUZE.COM.NS-NOT-IN-SERVICE.ORG
Name Server: NS2.EXPONATOMUZE.COM.NS-NOT-IN-SERVICE.ORG
Name Server: NS3.EXPONATOMUZE.COM.NS-NOT-IN-SERVICE.ORG
Name Server: NS4.EXPONATOMUZE.COM.NS-NOT-IN-SERVICE.ORG
Name Server: NS5.EXPONATOMUZE.COM.NS-NOT-IN-SERVICE.ORG
Status: clientHold
Status: clientTransferProhibited
Status: clientUpdateProhibited
Updated Date: 05-mar-2008 << ACTION TAKEN
Creation Date: 20-mar-2007

Back to top
View users profile Send private message Visit posters website AIM Address
Krivoi

Sergeant
Sergeant


Joined: Mar 03, 2008
Posts: 90


PostPosted: Wed Mar 05, 2008 10:24 pm    Post subject:
Reply with quote

Oh yes!!! That^^ is confirmed from the "end-user" ie me! Messages from all kinds of apparently unconnected senders were still incoming during much of today, then got 100% terminated. Very Happy

Bye bye spammer! Very Happy

Update: I now confirm that having Google advanced search as home page does indeed interfere with the script. Setting a blank homepage is a work-around.

I am moving forward: I now get as far as an error message from dnsstuff.com themselves, because I am not yet registered with them. This makes Complainterator give its "failed to get traversal window" message. So it seems one must be registered with dnsstuff for Complainterator to work (not a problem, but thought I should question this).

When I begin to register with dnsstuff they say I need to Buy Now or Try Free for 21 days (again not a problem, I'll do it) - is this a change of their policy, as I had the impression registration was previously merely a formality?

Anyway, I'll be back in touch soon.

Back to top
View users profile Send private message
AlphaCentauri

SIRT Handler
Premium Member

Joined: Nov 20, 2003
Posts: 2899

Premium

PostPosted: Wed Mar 05, 2008 10:43 pm    Post subject:
Reply with quote

tembow wrote:
The name server has been deactivated and all those sites are out.
Thank you, Tucows!


I'm still seeing caching -- I had to go to Tucows' own whois server to see the changes, and the sites are still loading for me. The traversal is timing out but doesn't show blackhole IPs for the nameservers yet. Even on the Tucows whois, they haven't removed the personal data of the woman whose identity was stolen.

My report went in 8pm 3/3. I think I'm in the same time zone as Tucows.

Back to top
View users profile Send private message
Display posts from previous:   
Post new topic   Reply to topic       All -> FavForums -> Complainterator All times are GMT
Goto page 1, 2, 3, 4  Next
Page 1 of 4

 
Quick Reply:
Username: 

Quote the last message
Attach signature (signatures can be changed in profile)
 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You can download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer