CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

$9736.22 of $21422.68
left sidedonated so farneed $11686.46 donated to reach our goalright side, our goal
Help CastleCops serve the community on new servers, Donate Here to reach our goal.

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
Survey
spacer
Was 2007 a good year?

Yes it was a wonderful year
Yes, but there is always room for improvement
Status quo
It was a challenge
Other (leave comment)



Results
Polls

Votes: 941
Comments: 25
block bottom
spacer spacer

A reply from BILT!

 
Post new topic   Reply to topic       All -> FavForums -> Complainterator [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
pwillener

SRT Trainee
SRT Trainee
Premium Member

Joined: Apr 17, 2006
Posts: 1725
Location: Japan
Premium

PostPosted: Tue Jul 01, 2008 4:32 am    Post subject: A reply from BILT!
Reply with quote

I sent a (munged) complaint regarding metdns2008.com and received the following response within a minute

Quote:
Hello

At present, we prohibit any possibility of registering the new illegal domain.
As for registered illegal domain, we will remove it in the shortest time after double checking its registration information.
sorry for the inconvenience.

This message was generated by Beijing Innovative Linkage Technology Ltd dba dns.com.cn

Simon Duan

Tel: 86-10-82151122
Fax:86-10-82151122-8129
Mail: duanry@dns.com.cn
Beijing Innovative Linkage Technology Ltd.
Add: 20/F, Block A, SP Tower, Tsinghua Science Park ,No.1 Zhongguancun East Road, Haidian District, Beijing
Zip: 100084
2008-07-01
--------------------------------------------------------------------------------
duanry

We shall see what action follows this rather unexpected surprise.

Back to top
View users profile Send private message Visit posters website
trobbins

SIRT Handler
Premium Member

Joined: Feb 19, 2007
Posts: 1166
Location: USA
Premium

PostPosted: Tue Jul 01, 2008 5:15 am    Post subject:
Reply with quote

Smarty Looks like your the next go to person!

Back to top
View users profile Send private message
trobbins

SIRT Handler
Premium Member

Joined: Feb 19, 2007
Posts: 1166
Location: USA
Premium

PostPosted: Tue Jul 01, 2008 5:22 am    Post subject:
Reply with quote

BTW: Did you report that domain as a Name Server or a spam domain? I see it is client hold but it is a name server and doesn't appear to be black holed.

Back to top
View users profile Send private message
pwillener

SRT Trainee
SRT Trainee
Premium Member

Joined: Apr 17, 2006
Posts: 1725
Location: Japan
Premium

PostPosted: Tue Jul 01, 2008 6:04 am    Post subject:
Reply with quote

It was reported as a name server; unfortunately I forgot to include the new Chinese language link http://wiki.castlecops.com/Suspending_an_EPP_name_server_domain_Chinese

Meanwhile I have received the same reply for name server greatlikeapro.com that I have reported yesterday, as well as some spam domains (middhs.com, promeds911.com) that I have reported today.

Back to top
View users profile Send private message Visit posters website
pwillener

SRT Trainee
SRT Trainee
Premium Member

Joined: Apr 17, 2006
Posts: 1725
Location: Japan
Premium

PostPosted: Tue Jul 01, 2008 6:37 am    Post subject:
Reply with quote

I have sent him a reply with the Chinese language Wiki link, and he replied that "We will remove it in the shortest time."

Back to top
View users profile Send private message Visit posters website
Krivoi

Sergeant
Sergeant


Joined: Mar 03, 2008
Posts: 83
Location: Uk

PostPosted: Tue Jul 01, 2008 11:07 am    Post subject:
Reply with quote

Wow, that was good to see, pwillener! Please keep us posted, as I got spammed this morning by metdns2008.com re the site trayienas.com

Back to top
View users profile Send private message
ahoier

SIRT Handler


Joined: Jan 14, 2006
Posts: 1034
Location: USA

PostPosted: Tue Jul 01, 2008 12:51 pm    Post subject:
Reply with quote

wooo! I got a golden ticket too!

Quote:
Date: Tue, 1 Jul 2008 12:48:17 +0800
From: "duanry" <duanry@dns.com.cn>
Subject: Re: Removal request: metdns2008_com

Hello

At present, we prohibit any possibility of registering the new illegal domain.
As for registered illegal domain, we will remove it in the shortest time after double checking its registration information.
sorry for the inconvenience.

This message was generated by Beijing Innovative Linkage Technology Ltd dba dns.com.cn

Simon Duan

Tel: 86-10-82151122
Fax:86-10-82151122-8129
Mail: duanry@dns.com.cn
Beijing Innovative Linkage Technology Ltd.
Add: 20/F, Block A, SP Tower, Tsinghua Science Park ,No.1 Zhongguancun East Road, Haidian District, Beijing
Zip: 100084


2008-07-01
duanry
发件人: me
发送时间: 2008-07-01 02:35:54
收件人: abuse
抄送: cnreg; huyan; spam
主题: Removal request: metdns2008_com


and here's my original message:
Quote:
BEIJING INNOVATIVE LINKAGE TECHNOLOGY LTD. DBA DNS.COM.CN
Dear Registrar

This is a request for you to remove the domain metdns2008.com
and to remove its name server Address record ns1.metdns2008_com
[221.230.2.221], and ns2.metdns2008_com [124.236.241.91]

EVIDENCE

From this link, you can see that it is used as a name server for a spammed site
> http://www.dnsstuff.com/tools/traversal.ch?domain=trayienas.com&type=a&token=complainterator&src=complainterator

From this link, you can see that your company is the name server's registrar
> http://who.is/whois-net/ip-address/metdns2008.com/

This spam example has been processed by SpamCop, and authorities contacted:
http://www.spamcop.net/sc?id=z2034376541zda06088413fcc4031f30337c73921e5fz

ACTION

Setting the status to client hold is not enough to suspend it.
Use the removal instructions for name servers in this link
> http://www.spamtrackers.eu/wiki/index.php?title=Registrar_Advice
> http://www.spamtrackers.hk/wiki/index.php?title=Registrar_Advice (for China)

Once removed in that manner, this Complaint Generator tool will
generate no more requests on this domain.

Thank you for your efforts to reduce spam and to keep criminals from
abusing your terms of service.

-----
This message was generated by the Complainterator - www.complainterator.com
Wrong address? Send address changes to info@complainterator.com
-----


I don't know if the spamcop tracking URL "did them in" or if perhaps someone is pressuring them to take action...?

Who knows Wink But we got a response! Smile

Keep em targeted.

I sent mine
to: abuse@dns.com.cn
cc: cnreg@dns.com.cn, huyan@dns.com.cn, spam@ccert.edu.cn

Back to top
View users profile Send private message Visit posters website AIM Address Yahoo Messenger MSN Messenger
kamaraju

Corporal
Corporal


Joined: Mar 07, 2007
Posts: 63
Location: USA

PostPosted: Tue Jul 01, 2008 3:34 pm    Post subject:
Reply with quote

I got a reply too... Hope they shut this down. I am getting spammed left and right where the spamvertized domains come under BILT.

raju


Quote:

Hello

At present, we prohibit any possibility of registering the new illegal domain.
As for registered illegal domain, we will remove it in the shortest time after double checking its registration information.
sorry for the inconvenience.

This message was generated by Beijing Innovative Linkage Technology Ltd dba dns.com.cn

Simon Duan

Tel: 86-10-82151122
Fax:86-10-82151122-8129
Mail: duanry@dns.com.cn
Beijing Innovative Linkage Technology Ltd.
Add: 20/F, Block A, SP Tower, Tsinghua Science Park ,No.1 Zhongguancun East Road, Haidian District, Beijing
Zip: 100084


2008-07-01
duanry
发件人: Kamaraju Kusumanchi
发送时间: 2008-07-01 01:31:55
收件人: cnreg; huyan; spam
抄送:
主题: Removal request: metdns2008.com
- Hide quoted text -
BEIJING INNOVATIVE LINKAGE TECHNOLOGY LTD. DBA DNS.COM.CN
Dear Registrar
This is a request for you to remove the domain metdns2008.com
and to remove its name server Address record ns1.metdns2008.com
[221.230.2.221], and ns2.metdns2008.com [124.236.241.91]
EVIDENCE
From this link, you can see that it is used as a name server for a
spammed site
>
http://www.dnsstuff.com/tools/traversal.ch?domain=bmeaoinc.com&type=a&token=complainterator&src=complainterator
From this link, you can see that your company is the name server's
registrar
>
http://www.dnsstuff.com/tools/whois.ch?ip=metdns2008.com&src=complainterator&token=complainterator
ACTION
Setting the status to client hold is not enough to suspend it.
Use the removal instructions for name servers in this link
> http://www.spamtrackers.eu/wiki/index.php?title=Registrar_Advice
> http://www.spamtrackers.hk/wiki/index.php?title=Registrar_Advice (for
China)
Once removed in that manner, this Complaint Generator tool will generate
no more requests on this domain.
Thank you for your efforts to reduce spam and to keep criminals from
abusing your terms of service.
-----
This message was generated by the Complainterator - www.complainterator.com
Wrong address? Send address changes to info@complainterator.com
-----

Back to top
View users profile Send private message
jimVO

Sergeant
Sergeant
Premium Member

Joined: Mar 17, 2008
Posts: 143
Location: USA
Premium

PostPosted: Tue Jul 01, 2008 5:09 pm    Post subject:
Reply with quote

Wow. I got a reply from BILT too for a nameserver removal request. Hopefully things are going to turn around there as well.

from duanry <duanry@dns.com.cn>
to Jim Wasson <capsept@gmail.com>
date Mon, Jun 30, 2008 at 9:51 PM
subject Re: Removal request: thenicespot.com BEIJING INNOVATIVE LINKAGE TECHNOLOGY LTD. DBA DNS.COM.CN
mailed-by dns.com.cn

hide details 9:51 PM (12 hours ago)

Reply

Hello

At present, we prohibit any possibility of registering the new illegal domain.
As for registered illegal domain, we will remove it in the shortest time after double checking its registration information.
sorry for the inconvenience.

This message was generated by Beijing Innovative Linkage Technology Ltd dba dns.com.cn

Simon Duan

Tel: 86-10-82151122
Fax:86-10-82151122-8129
Mail: duanry@dns.com.cn
Beijing Innovative Linkage Technology Ltd.
Add: 20/F, Block A, SP Tower, Tsinghua Science Park ,No.1 Zhongguancun East Road, Haidian District, Beijing
Zip: 100084


2008-07-01
duanry
发件人: Jim Wasson
发送时间: 2008-06-30 15:25:25
收件人: cnreg; huyan
抄送: spam
主题: Removal request: thenicespot.com BEIJING INNOVATIVE LINKAGE TECHNOLOGY LTD. DBA DNS.COM.CN
--- truncated the rest

Back to top
View users profile Send private message
Tromso

Corporal
Corporal
Premium Member

Joined: May 25, 2007
Posts: 50

Premium

PostPosted: Tue Jul 01, 2008 9:53 pm    Post subject: metdns2008.com been on clientHold since 29th November 2007
Reply with quote

pwillener congrats on getting a reply from BILT for metdns2008.com

I also reported metdns2008.com on 30th June 2008 to BILT, but have not got a reply yet. I did ask the name address records to be changed to 61.61.61.61 with some instructions. I've made a note of the Chinese link for another time.

I previously reported metdns2008.com to BILT on 9th December 2007 also asking the name server records to be changed. It had been on clientHold since at least 29th November 2007.

The spammers were part of the Herbal King group also using jdns2008.com, rokodns2008.com on BILT that had been using joker.com as Registrar for spam domains and name servers, but migrated to using name servers on BILT and Xin Net.

Back to top
View users profile Send private message
pwillener

SRT Trainee
SRT Trainee
Premium Member

Joined: Apr 17, 2006
Posts: 1725
Location: Japan
Premium

PostPosted: Thu Jul 03, 2008 2:23 am    Post subject:
Reply with quote

I have recently been adding this Chinese language link in all domain name server reports http://wiki.castlecops.com/Suspending_an_EPP_name_server_domain_Chinese

But I am wondering if this link is actually accessible inside China? It is rather pointless if the recipients cannot access it.

Back to top
View users profile Send private message Visit posters website
ahoier

SIRT Handler


Joined: Jan 14, 2006
Posts: 1034
Location: USA

PostPosted: Thu Jul 03, 2008 1:55 pm    Post subject:
Reply with quote

tembow pointed out (i believe, in the knujon forum) that the castlecops wiki link _is_ indeed accessible from inside China Smile

For the time being anyways.....

Back to top
View users profile Send private message Visit posters website AIM Address Yahoo Messenger MSN Messenger
Display posts from previous:   
Post new topic   Reply to topic       All -> FavForums -> Complainterator All times are GMT
Page 1 of 1

 
Quick Reply:
Username: 

Quote the last message
Attach signature (signatures can be changed in profile)
 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You can download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer