Google Groups Home
Help | Sign in
SUCCESS!
There are currently too many topics in this group that display first. To make this topic appear first, remove this option from another topic.
There was an error processing your request. Please try again.
flag
  Messages 26 - 50 of 207 - Collapse all < Older  Newer >
The group you are posting to is a Usenet group. Messages posted to this group will make your email address visible to anyone on the Internet.
Your reply message has not been sent.
Your post was successful
Sun Tsu  
View profile
 More options Aug 6 2004, 7:46 pm
Newsgroups: news.admin.net-abuse.email
From: bananana...@spamblocked.com (Sun Tsu)
Date: 6 Aug 2004 16:46:07 -0700
Local: Fri, Aug 6 2004 7:46 pm
Subject: Re: SUCCESS!

You do know that BellSouth offers service in more states than just
Florida, don't you Mr. Anonymous, "I know so much about the Internet,
spammers and fighting spam, but I don't know what SPEWS S2134 means."

> Hey, spammy, I don't care where you host your websites, if you spam our
> domain, I'm hitting them and getting them borked. If you think you can stop
> me, think again... you've become a major cost of doing business, so now I
> am YOUR cost of doing business. And I'm not going away until you do. Get
> used to it, like we've all had to get used to putting up with your spew.

> You stop spamming our domain, I'll stop hitting your spamvertised websites.
> That's the deal. No negotiations.

Have you no shame, Bob, following up your own post in NANAE.  Are you
*sure* that you aren't a spammer involved in a pissing contest with
some Florida spammers/competitors.  If you were a true spam fighter
you wouldn't offer to stop hitting spammy's spamvertised websites once
he stopped spamming your domain.

What is your domain anyway?  It shouldn't be a problem mentioning it
if spammy already knows what it is.  You keep referring to "we" and if
you have partners in this one lone website.  Do you perhaps have a
frog in your pocket?

You are posting from,

NNTP-Posting-Host: 63.207.207.234

Pac Bell Internet Services PBI-NET-7 (NET-63-192-0-0-1)
                                  63.192.0.0 - 63.207.255.255

STAN FISHER SBCIS-100531-182148 (NET-63-207-207-232-1)
                                  63.207.207.232 - 63.207.207.239

So, Stan, why do you also go by the name of Bob and what do you need 8
IP's for if you only have one website?

CustName:   STAN FISHER
Address:    303 Second Street
City:       San Francisco
StateProv:  CA
PostalCode: 94107
Country:    US
RegDate:    2000-06-01
Updated:    2000-06-01

NetRange:   63.207.207.232 - 63.207.207.239
CIDR:       63.207.207.232/29
NetName:    SBCIS-100531-182148
NetHandle:  NET-63-207-207-232-1
Parent:     NET-63-192-0-0-1
NetType:    Reassigned
Comment:    
RegDate:    2000-06-01
Updated:    2000-06-01

Hmm, you've had this /29 for four years and you've just started
posting in NANAE sounding like either a tenured regular or a tenured
spammer.  Bob, did you hijack this IP block from Stan?

Your posting IP resolves to   151.164.243.21

        60 ms   70 ms   84 ms   64.200.89.70    
washdc5lcx1-pos11-0.wcg.net.    245     UNITED STATES
11      61 ms   70 ms   79 ms   64.200.95.114  
washdc5lcx1-sbc-pos.wcg.net.    244     UNITED STATES   Unix: 23:39:44. 26
12      60 ms   69 ms   79 ms   151.164.191.137
bb2-p2-0.hrndva.sbcglobal.net.  243     UNITED STATES   Unix: 23:39:44.214
13      68 ms   75 ms   85 ms   151.164.243.21  
bb1-p6-0.hrndva.sbcglobal.net.  242     UNITED STATES   Unix: 23:39:45.267

::::    or are you this spammer?    ::::

 Google Search: 151.164.243.21

http://groups.google.com/groups?q=151.164.243.21&hl=en&lr=&ie=UTF-8&s...

::::    which leads to    ::::

Registrant:
 none>>>>>>>>>>>>>>>>>>>>>>>>>>ATTN: DIRECTNIC.COM
 1516 Horrell Ave
 Mckinleyville, CA 95519
 US

 Domain Name: THEANSWERTO.COM

Monteforte, Patrick &amp;amp; Tracy  gtp...@northcoast.com
    1516 Horrell Ave
    Mckinleyville, CA 95519
    US
    707-840-9517

 Registration Service Provider:
    Intercosmos Media Group Inc. dba directNIC.com,
supp...@directnic.com
    504 679 5173
    http://www.directnic.com

 Record last updated on 20-Mar-2002.
 Record expires on 02-Sep-2002.
 Record Created on 02-Sep-2000.

::::    NEW REGISTRATION    ::::

Registration Service Provided By: WTPowers
Contact: doma...@wtpowers.com

Domain name- theanswerto.com

Nameservers-
    NS3.PLUGIT.COM
    NS4.PLUGIT.COM

Start of registration- Sat Sep 02 2000 00:41:28
Registered through- Thu Sep 02 2004 00:41:28

Registrant Contact-
   WTPowers
   Patrick Monteforte   (p...@wtpowers.com)
   +1.7078409517
   FAX- +1.7078399559
   2617 Northbaink RD
   PO Box 2490
   Mckinleyville, CA 95519
   US

Administrative Contact-
   WTPowers
   Patrick Monteforte   (p...@wtpowers.com)
   +1.7078409517
   FAX- +1.7078399559
   2617 Northbaink RD
   PO Box 2490
   Mckinleyville, CA 95519
   US

Billing Contact-
   WTPowers
   Patrick Monteforte   (p...@wtpowers.com)
   +1.7078409517
   FAX- +1.7078399559
   2617 Northbaink RD
   PO Box 2490
   Mckinleyville, CA 95519
   US

Technical Contact-
   WTPowers
   Patrick Monteforte   (p...@wtpowers.com)
   +1.7078409517
   FAX- +1.7078399559
   2617 Northbaink RD
   PO Box 2490
   Mckinleyville, CA 95519
   US

Say, Bob, aren't you that "phool" who claims to be new here?

Google Groups: View Thread "[proxy hijacking] theplanet.com /
valueweb.net / atr..."

<http://groups.google.com/groups?hl=en&lr=&ie=UTF-8&threadm=2f0f6d90.0...>

> Ok, I'm new here, so I'm not familiar with the language, and these may be
> dumb questions, but I'll ask anyway... What is S2134? Is it the tracking
>number for a particular SPEWS-blocked spammer? Where do I find these?

Say what?  You're new here?  Oh, really!

If you are new here then why do you know so much about whois, LARTing,
dig, reporting chains, etc.?

Let's have a look and see if it's you and examine some of the cr@p you
have been spewing in NANAE the last few days.  Seems you have been
having a bit of a go with the good folks in NANAE.

Google Search: author:Anonym...@domain.invalid

<http://groups.google.com/groups?hl=en&lr=&ie=UTF-8&q=author:Anonymous...>

It would appear that you know a great deal about spammers and fighting
spam for someone who claims to be new here, "don'tja," Bob?

:: Re: How Millionaire gets 20,000 visitors a day

> Big deal, I've never spent a dime on advertising either, my website's been
> as high as around 2000, and I didn't spam to get there. I'm also ranked #12
> for our second-best search term and #21 for our best search term on Google.
> It's called website optimization and creating content people want to read.
> Get a life and a clue.

:: Re: repost Morely if UUNET is Bad then WHY are you WORSE???

> Man, you'd be amazed at how many people are using the email address of
> 'anonym...@domain.invalid'. No wonder I get so much spam... I've got
> Sanford Wallace AND Scott Richter right in my Inbox!

Why would someone as "clued" as you use such an address then, hmm,
Bob?

Say, Bob, didn't you say that 100% of your spam in the last month was
from that Russian spam gang?  Make up your mind, Bob!

:: Re: webrider.ru - Russian Spam Gang

> Yes, but he's not getting those addresses out of the blue,
> or from his Contacts list, he's getting them (I would assume,
> since this is how I do it) from doing WHOIS and abuse.net
> lookups on the URL and IP address of the abusing domain.
> If those addresses are listed there, then I'd say LART away.

Interesting, Bob, you know all of this but you don't know that S2134
refers to a SPEWS record number.  Total cr@p, Bob, just more and more
pure 100% prime government inspected bullsh!t from you.

:: Re: Reveal who is behind SPEWS

> The reason I hate spammers is because my dear departed
> mother was raped by a spam gang. I guess all those penis
> enlargement, viagra and porn ads they were sending finally
> got to be too much for them to bear, and they grabbed
> the nearest moving object to vent their frustrations on,
> which happened to be my mother, God rest her poor
> over-humped soul.
> She expired giving birth to me, the unholy product of
> the evil seed of a thousand spammers, risen from the
> very bowels of hell itself to wreak vengeance upon the
> spammers of the world in revenge for my dear departed
> mother.

That's about the same kind of believable cr@p you have been spewing
here in NANAE the last few days.  Why, Bob, why are you acting like
such a "phool" claiming to be so concerned about a Russian spam gang
and that *you* are responsible for "inspiring" InterCosmos.com to
cancel spammy's domains.  You do realise that most people don't know
that InterCosmos.com is DirectNIC.com and that ab...@DirectNIC.com
uses a DirectNIC email address, not an InterCosmos.com address, don't
you, Bob?  How about you post some of the email, along with headers
adnd responses, you have been sending (sic) to DirectNic.com
concerning this Russian spam gang.

:: Re: SUCCESS!

> bjbmdbe.info is now dead. Another Russian Spam Gang
> domain gone... and this one, they didn't even get a chance
> to send any spam for. InterCosmos is killing them off
> preemptively now. I've got them searching through their records
> for the email addresses the Russian Spam Gang has used
> to register other domains, and they're killing any off that were
> registered with those email addresses.
> This is too much fun... 4 spammer domains killed off
> (and possibly quite a few more once they find them) in two
> days... the Russian Spam Gang has got to be wondering
> what's going on.

You're full of cr@p, Bob.  Prove it!  Post your email exchange with
DirectNic.com complete with headers.  Otherwise, it's all just spammer
speak coming from an idiot/k00k like yourself.

:: Re: Spam Surge?

...

read more »


    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
brad.madison  
View profile
 More options Aug 6 2004, 8:48 pm
Newsgroups: news.admin.net-abuse.email
From: "brad.madison" <brad.madi...@mail.tds.net>
Date: Fri, 06 Aug 2004 19:48:18 -0500
Local: Fri, Aug 6 2004 8:48 pm
Subject: Re: SUCCESS!

Ouch.  Picture me falling backwards off a fence (John Cleese as Fool)
once again.

Still, there's nothing to be gained by the spammer from knowing how its
done.  The best and ultimately the only defense is to stop spamming (or
to stop using abuse to spam, which makes blocklists real easy and real
powerful.)  It's a temporary defense to move to another form of abuse
(like to open proxy abusde and then to spam zombie abuse), but if people
start combating that abuse the spammers (Hi, Bob) lose.  It's not the
spammers knowing the tools agaist them that hurts, its the lack of
practitioners of the art.

Uh, what's Book 13 of Sun-Tzu?  Go into the enemy's camp and play dumb,
play the novice, get the enemy to talk?   Human engineering?  No sweat -
the secrets aren't the "how" but the "where" - and that's only if the
user chooses the secret route.

One mode of honeypot counter-attack is to PUBLISH the honeypot IPs on a
web page.  Most of them, with some ringers thrown in.  Like Nimitz said:
"Send them our latitude and longitude."


    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Andrew - Supernews  
View profile
 More options Aug 6 2004, 9:08 pm
Newsgroups: news.admin.net-abuse.email
From: Andrew - Supernews <andrew+non...@supernews.com>
Date: Sat, 07 Aug 2004 01:08:54 -0000
Local: Fri, Aug 6 2004 9:08 pm
Subject: Re: SUCCESS!
On 2004-08-06, Sun Tsu <bananana...@spamblocked.com> wrote:

> Your posting IP resolves to   151.164.243.21

What kind of crack are you smoking? That's one of sbcglobal's backbone
routers, searching for references to is isn't going to give you anything
useful, it just turns up a lot of traceroutes that happen to go through it.

--
Andrew, Supernews
http://www.supernews.com - individual and corporate NNTP services


    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Anonymous  
View profile
 More options Aug 6 2004, 9:30 pm
Newsgroups: news.admin.net-abuse.email
From: "Anonymous" <Anonym...@domain.invalid>
Date: Sat, 07 Aug 2004 01:30:52 GMT
Local: Fri, Aug 6 2004 9:30 pm
Subject: Re: SUCCESS!
"Sun Tsu" <bananana...@spamblocked.com> wrote in message

news:2f0f6d90.0408061546.7fd0be7b@posting.google.com...
<snip>
<snip>
<snip>
<snip>
<snip>
<snip>
<snip>
<snip>

ROTFLMAO! God, Sun Tsu, you do the best impression of a crazy person that
I've /ever/ seen! That was hilarious! Thanks for making me laugh so hard...
I haven't laughed like that in ages.


    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Alexis  
View profile
 More options Aug 6 2004, 9:48 pm
Newsgroups: news.admin.net-abuse.email
From: "Alexis" <Ale...@invalid.domain>
Date: Fri, 6 Aug 2004 21:48:07 -0400
Local: Fri, Aug 6 2004 9:48 pm
Subject: Re: SUCCESS!
"Anonymous" <Anonym...@domain.invalid> wrote in message

news:GdcQc.494$g57.177@newssvr29.news.prodigy.com...

Well, I tried it and they just tell me to go after the host. Maybe you're
perfuming your notes? :)

Here's another, please sic 'em-

eknmeem.info

I talked to someone else wanting to coordinate efforts. Wonder how you 2 and
others could hook up
at some place where people like your angry little jilted lover Sun Tsu won't
get in the way  :)

Maybe set up a members-only board somewhere?

- Alexis, schmelexis


    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
glgxg  
View profile
 More options Aug 6 2004, 9:56 pm
Newsgroups: news.admin.net-abuse.email
From: glgxg <gl...@mfire.invalid.com>
Date: Fri, 06 Aug 2004 18:56:58 -0700
Local: Fri, Aug 6 2004 9:56 pm
Subject: Re: SUCCESS!
Sun Tsu wrote something I reckon...

Must be Friday... checks calendar... yep it is.  Probably a full moon
somewhere as well.

Sun - get some sun, relax, enjoy your weekend & cool your jets.


    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Anonymous  
View profile
 More options Aug 6 2004, 10:15 pm
Newsgroups: news.admin.net-abuse.email
From: "Anonymous" <Anonym...@domain.invalid>
Date: Sat, 07 Aug 2004 02:15:34 GMT
Local: Fri, Aug 6 2004 10:15 pm
Subject: Re: SUCCESS!
"Anonymous" <Anonym...@domain.invalid> wrote in message

news:ghWQc.2721$yB3.125@newssvr29.news.prodigy.com...

> ROTFLMAO!

And just in case you're wondering... no, I'm not a spammer. And I /am/ a
relative UseNet newby (newbie? newbee? whatever.)... I had enough trouble
just figuring out how to get NANAE to load into my newsgroup reader. I
never used usenet back in the days when it was all the rage.

As for the SPEWS listing numbers... I'm unfamiliar with a lot of things, so
I ask questions about them to learn. I am also familiar with a lot of
things, and I offer my advice on those things. Having never visited SPEWS
before, I didn't know how they kept track of which spammer was which. Now I
know.

As for the InterCosmos correspondence, here's a snippet (names, email
addresses and IP addresses of the innocent munged to protect against usenet
k00ks):

Received: from icmail.intercosmos.net [xxx.xxx.xxx.xxx] by mail.xxxxxx.com
with ESMTP
  (SMTPD32-6.06) id AD1050209E1; Fri, 06 Aug 2004 12:08:48 -0400
Received: (qmail 6031 invoked by uid 306); 6 Aug 2004 16:05:23 -0000
Received: from xxxx...@intercosmos.com by icmail.intercosmos.net by uid 51
with qmail-scanner-1.20
 (clamuko: 0.65. spamassassin: 2.63.
Clear:RC:0(204.251.2.111):SA:0(3.2/5.0):.
 Processed in 0.145533 secs); 06 Aug 2004 16:05:23 -0000
X-Spam-Status: No, hits=3.2 required=5.0
Received: from unknown (HELO donnyxxx)
(xxxxxxx...@intercosmos.com@xxx.xxx.xxx.xxx)
  by 0 with SMTP; 6 Aug 2004 16:05:23 -0000
From: "Donny Xxxxxxxxxx" xxx...@intercosmos.com
To: xxxxxxxxxx...@xxxxxxxxxxxxx.com
Subject: RE: Hi, Donny. Got a whole batch of them for you to check out...
ADDENDUM
Date: Fri, 6 Aug 2004 11:05:42 -0500
MIME-Version: 1.0
Content-Type: text/plain;
 charset="us-ascii"
Content-Transfer-Encoding: 7bit
X-Mailer: Microsoft Office Outlook, Build 11.0.5510
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2900.2149
Thread-Index: AeL7A46u+d5tqnJpQTfS2x5I4cbtngBZ2TtA
In-Reply-To:
<IMFEKIJDNQIKEHMBMPBNDFCJDHBB.xxxxxxxxxxx...@xxxxxxxxxxxxx.com>
X-Qmail-Scanner-Message-ID: <11029183346627...@icmail.intercosmos.net>
Message-Id: <20040806120815.SN02...@icmail.intercosmos.net>
X-RCPT-TO: xxxxxxxxxxx...@xxxxxxxxxxxxxx.com
X-UIDL: 4785
Status: U

All of them are now on hold.

Donny

<snip>

Happy now? Does that assuage your insanity? No, probably not...

God, I've spun up a net k00k, and his crap-flinger is directed at me...
<sigh>

Rich, now I know why you get so much enjoyment out of watching Brad doing
his little crazy dance... it's incredibly funny.


    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Russell Miller  
View profile
 More options Aug 6 2004, 10:22 pm
Newsgroups: news.admin.net-abuse.email
From: Russell Miller <rmil...@duskglow.com>
Date: Sat, 07 Aug 2004 02:22:44 GMT
Local: Fri, Aug 6 2004 10:22 pm
Subject: Re: SUCCESS!
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

In article <aXWQc.2731$JT3.1...@newssvr29.news.prodigy.com>, Anonymous wrote:

> Rich, now I know why you get so much enjoyment out of watching Brad doing
> his little crazy dance... it's incredibly funny.

It is, but eventually it just becomes a waste of time.  I advise you to prime
your killfile, for eventual action :-)

- --Russell

- --
Russell Miller          - President, Duskglow Consulting, LLC
rmil...@duskglow.com    - http://www.duskglow.com
Le Mars, IA             - +1 712 546 5886
Official NANAE SPEWS Puppet extraordinaire
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.4 (GNU/Linux)

iD8DBQFBFD3eURTA4VCI9OARAnUsAJ97NcZOGvLGBRtrkp71GecHeGNKVACdGGvu
3k1UCn/t4kQDfTrurRmcn4o=
=Aq/f
-----END PGP SIGNATURE-----


    Reply to author    Forward  
You must Sign in before you can post messages.
To post a message you must first join this group.
Please update your nickname on the subscription settings page before posting.
You do not have the permission required to post.
Anonymous  
View profile
 More options Aug 6 2004, 10:58 pm
Newsgroups: news.admin.net-abuse.email
From: "Anonymous" <Anonym...@domain.invalid>
Date: Sat, 07 Aug 2004 02:58:40 GMT
Local: Fri, Aug 6 2004 10:58 pm
Subject: Re: SUCCESS!
"Alexis" <Ale...@invalid.domain> wrote in message

news:8xWQc.2909$923.627@bignews1.bellsouth.net...

> Here's another, please sic 'em-

> eknmeem.info

Oh, if you're a chick, I think I'm in love... you just uncovered yet
another server of theirs (222.233.52.109). The one I was working on was
201.3.240.226. This one is hosted on HanaNet, mine is hosted on
BrasilTelecom.

Ok, here's what you do.

1) Do a DNS lookup on the domain name.
    In this case, that domain resolves to 222.233.52.109.

2) Do a lookup on WHOIS.webhosting.info:
    http://whois.webhosting.info/222.233.52.109
    This doesn't show anything right now... check back tomorrow, after the
server updates, to see if there are any new entries. It also helps to
converse with people here to get the domain names of the Russian Spam
Gang... there is strength in numbers. I'm looking for other methods of
figuring out what websites a server is hosting.

3) Take any FQDN's that you know belong to that IP address that are
registered through InterCosmos, and add /OE017/, /MC021/, /MS020/, and
/ES001/ to that:
http://www.eknmeem.info/OE017/ (pirated software)
http://www.eknmeem.info/MC021/ (penile enlargement)
http://www.eknmeem.info/MS020/ (mortgage quotes)
http://www.eknmeem.info/ES001/ (viagra)

Yep, that is definitely a Russian Spam Gang website.

Now, write up a full LART, and report it to abuse at Intercosmos.com, and
CC it to Donny at InterCosmos (I think you can figure out the email
address...). Tell Donny it's another Russian Spam Gang website. After he
visits the sites and recognizes the content, he should put them on
Registrar Hold status.

All the Russian Spam Gang spamvertised websites that I know of were
registered through either InterCosmos, or NameBay. I'm still trying to get
a contact at NameBay that will act. Once I do, I'll let everyone here know
what it is.

If anyone has a contact at NameBay, let