Menu

Stop mailing ICANN and RIR's

john
2014-06-02
2014-08-17
  • john

    john - 2014-06-02

    Hello,

    I currently work for the dns operations team at icann and have
    previously worked for RIPE NCC. Projects like this seem to send every
    network they block to every operator all the way up the chain. Take
    for example the report i received this morning[1] which was mailed to
    17 addresses including ICANN and two RIR's. By sending these reports
    to the incorrect addresses you turn your self into the spammer and
    could end up having your email filtered or automatically removed.
    Alternativly this causes operators to change the conatcta information
    to something invalid.

    The ripe ncc has tried to do a lot of work to improve upon how one can
    reach the correct absue contact to send email to[2]. This article
    gives an overview of the issues and how and how ripe ncc has tried to
    resolve it. I would request that you try to first find contacts
    information via the ripe ncc abuse finder[3] of ripe stat
    plugin[4][5]. Which in tis case would have given you the address
    abuse at ovh.net.

    [1]https://xortify.com/ban/index.php?op=member&id=7065
    [2]https://labs.ripe.net/Members/denis/creating-and-finding-abuse-contacts-in-the-ripe-database
    [3]https://apps.db.ripe.net/search/abuse-finder.html
    [4]https://stat.ripe.net/data/abuse-contact-finder/data.json?resource=5.135.99.221
    [5]https://stat.ripe.net/5.135.99.221#tabId=anti-abuse

     
    • Chronolabs Cooperative

      Well then your problem is this is a honeypot for example some of the bans you have ignored which is why you are being sent Abuse@ your holdings, to the following examples of ban's you have ignored, include DoS, BruteForce etc, which are direct methods of abuse of your network you are ment to take responsibility about:~ Some example's of the ban's you have now issue a statement that you are irrisponsible as an organisation to base in the topology of networking the inter*net;

      Ban Examples:

      Banning Comment :: centralcoastpage :: 14-Jun-2014 22:56:20

      2014-06-14 21:56:36 - CRAWLER - Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/32.0.1700.76 Safari/537.36 -
      2014-06-14 21:56:37 - BRUTE FORCE - Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/32.0.1700.107 Safari/537.36 OPR/19.0.1326.63 - Trying to login as 'EQUIKEALARI' found.

      Banning Comment :: centralcoastpage :: 16-Jun-2014 18:30:55

      2014-02-26 17:26:13 - CRAWLER - Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.31 (KHTML, like Gecko) Chrome/26.0.1410.63 Safari/537.31 -
      2014-06-16 17:21:52 - CRAWLER - Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; Trident/4.0; .NET CLR 1.1.4322) -
      2014-06-16 17:23:49 - BRUTE FORCE - Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; Trident/4.0; .NET CLR 1.1.4322) - Trying to login as 'LXkz' found.

      Banning Comment :: centralcoastpage :: 21-Jun-2014 10:21:45

      2014-06-21 09:17:45 - BRUTE FORCE - Mozilla/5.0 (compatible; MSIE 10.0; Windows NT 6.1; Trident/6.0) - Trying to login as 'Gofklanfer' found.

      Banning Comment :: centralcoastpage :: 24-Jun-2014 09:12:16

      2014-06-24 01:35:34 - DoS - Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.0; Trident/5.0) -
      2014-06-24 08:08:59 - BRUTE FORCE - Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.0; Trident/5.0) - Trying to login as 'CNorthcot' found.

      Banning Comment :: jaylach :: 24-Jun-2014 17:42:39

      2014-06-24 16:38:06 - BRUTE FORCE - Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/30.0.1599.101 Safari/537.36 - Trying to login as 'nkenmanp@126.com' found.

      Probably why you haven't remember my tarrier fee which is still outstanding by IANA that belittled me and made me berazzelled on comp.protocol as a 13 yr old australian, during the IPv4 Rework/Redesign; see:~ https://ripe-ncc.labs.coop/ipv4-stratum-licensing-debt-still-outstanding-outlayed-for-iana-fornetwork-tarrier.php

      -- Glossary --

      *inter: The term 'inter' is multiversal, it means your largest extent in measurement of largest orbit mass, here in the milkway that is the total size of andromida and milkways twin orbit, Inter-net is a network extending this mass!

       

      Last edit: Chronolabs Cooperative 2014-08-17
  • Chronolabs Cooperative

    Notabily I see some fairly nafarious stuff happen on ovh.net :: ~ there is some really debauch stuff in that service farm... It started to attack xortify.com which I have moved on to a dynamic SSL link using a camillian cipher that writes back to SSL so it stopped getting caught when it isn't doing Dark Evil Stuff...

     
  • Chronolabs Cooperative

    Also this would normally be a ticket not a discussion, Well want to know sometime, we have been talking to ICANN and IANA since their interest's in our abuse notices about under particular banning conditions the IPv4 Domain class header will be dropped at IANA put into a holding state for 6 months, then on sold too another party as the centroidal solution to IPv4 exhustion as there will always people that mess up!

     

Log in to post a comment.