nanog mailing list archives

Re: Request Spamhaus contact


From: Steve Atkins <steve () blighty com>
Date: Mon, 17 Jan 2011 17:10:02 -0800


On Jan 17, 2011, at 4:42 PM, Jeffrey Lyon wrote:

I fat fingered the netmask, try now.

Mmm hmm.

  platter steve$ telnet 208.64.127.78 80
  Trying 208.64.127.78...
  Connected to 208.64.127.78.
  Escape character is '^]'.
  HEAD / HTTP/1.1
  Host: viagra-shopping.com

  HTTP/1.1 301 Moved Permanently
  Cache-Control: private
  Content-Length: 0
  Location: http://www.viagra-shopping.com/Home.aspx
  Server: Microsoft-IIS/7.0
  X-AspNet-Version: 4.0.30319
  X-Powered-By: ASP.NET
  Date: Tue, 18 Jan 2011 00:57:55 GMT
  Connection: close

If you've given spamhaus the same sort of response you're
showing here I'm not surprised they're not prioritizing dealing
with you.

Cheers,
  Steve



Thanks, Jeff


On Mon, Jan 17, 2011 at 7:39 PM, Raymond Dijkxhoorn
<raymond () prolocation net> wrote:
Hi!

We've acted on every report that we're aware of and instead you want
to play pharmacy domain scavenger hunt. This domain at 208.64.120.197
redirects to IP space we already null routed. It's the same customer.

Either you place strange nullroutes or you did not at all.

[root@mi10 tmp]# wget -S www.vertrouwdeapotheek.nl
--01:37:29--  http://www.vertrouwdeapotheek.nl/
          => `index.html'
Resolving www.vertrouwdeapotheek.nl... done.
Connecting to www.vertrouwdeapotheek.nl[208.64.120.197]:80... connected.
HTTP request sent, awaiting response...
 1 HTTP/1.1 301 Moved Permanently
 2 Cache-Control: private
 3 Content-Length: 0
 4 Location: http://www.vertrouwdeapotheek.nl/Home.aspx
 5 Server: Microsoft-IIS/7.0
 6 X-AspNet-Version: 4.0.30319
 7 X-Powered-By: ASP.NET
 8 Date: Tue, 18 Jan 2011 00:37:04 GMT
 9 Connection: close
Location: http://www.vertrouwdeapotheek.nl/Home.aspx [following]
--01:37:29--  http://www.vertrouwdeapotheek.nl/Home.aspx
          => `Home.aspx'
Connecting to www.vertrouwdeapotheek.nl[208.64.120.197]:80... connected.
HTTP request sent, awaiting response...

Does this look as its nullrouted?

P.S. Someone at Spamhaus PLEASE remove the /21 listing?

I highly doubt. There is much more to clean on your network before i hope
they would even reconsider.

Bye,
Raymond.




-- 
Jeffrey Lyon, Leadership Team
jeffrey.lyon () blacklotus net | http://www.blacklotus.net
Black Lotus Communications - AS32421
First and Leading in DDoS Protection Solutions




Current thread: