Re: Request Spamhaus contact

2011-01-18 Thread Simon Waters
On Tuesday 18 January 2011 11:46:53 Ken Gilmour wrote: Obviously they know about them because google has the information. I'm not sure this is a reasonable deduction.

Re: Internet to Tunisia

2011-01-11 Thread Simon Waters
On Tuesday 11 January 2011 14:58:51 Marshall Eubanks wrote: On twitter right now there are frequent claims that all https is blocked (presumably a port blocking). A quick search pulls up. http://www.cpj.org/internet/2011/01/tunisia-invades-censors-facebook-other-accounts.php Since Gmail

Re: Spamhaus under DDOS from AnonOps (Wikileaks.info)

2010-12-19 Thread Simon Waters
On 19/12/10 18:51, Paul Ferguson wrote: Not for nothing, but Spamhaus wasn't the only organization to warn about Heihachi: http://blog.trendmicro.com/wikileaks-in-a-dangerous-internet-neighborhood/ All the domains listed by Trend Micro as neighbours appear to be down. Have to say as someone

Re: Abuse@ contacts

2010-12-07 Thread Simon Waters
Or have had any luck with abuse@ contacts in the past? Who's good and who isn't? http://www.rfc-ignorant.org/tools/submit_form.php?table=abuse

Re: (wikileaks) Fwd: [funsec] And Google becomes a DNS..

2010-12-06 Thread Simon Waters
On Sunday 05 December 2010 15:50:32 Gadi Evron wrote: I withhold comment... discuss amongst yourselves. Since it is an uncommon but occasional complaint that someones site is indexed in Google by IP address not domain name, I assume simply that since wikileaks were redirecting to URLs with IP

Re: Cloud proof of failure - was:: wikileaks unreachable

2010-12-06 Thread Simon Waters
On Monday 06 December 2010 09:47:43 Jay Mitchell wrote: The Cloud went down? I think not. It did for at least one customer. Having ones account terminated as opposed to an outage caused by DDoS are two very different things. Although not for all DNS providers. There are operational lessons

Re: wikileaks dns (was Re: Blocking International DNS)

2010-12-03 Thread Simon Waters
On Friday 03 December 2010 13:22:19 Frank Bulk wrote: I guess the USG's cyberwar program does work (very dryly said). They missed ;) http://wikileaks.ch http://twitter.com/wikileaks

Bot reporting - best procedure?

2010-11-16 Thread Simon Waters
Sure it is something I should know, but I keep hitting dead ends. What is current state on botnet reporting procedures? A minor irritation currently, but clearly well resource botnet is pestering one of our services, only a couple of thousand IP addresses in use, but I'd like to mop up as much

Re: Anyone on a Virgin Media UK broadband connection?

2008-12-08 Thread Simon Waters
On Sunday 07 December 2008 14:10:02 Drew Linsalata wrote: Drop me a note off-list if possible. We have a business line from them Urm no Wikipedia this morning - hmm - I think the IWF is self destructing.

Re: [funsec] McColo: Major Source of Online Scams andSpams KnockedOffline (fwd)

2008-11-13 Thread Simon Waters
On Wednesday 12 November 2008 21:52:12 Nick Newman wrote: Let's compare these two scenarios: 1. The world-wide community of people who essentially run the Internet have had enough with a nasty webhosting company in California. They've determined that the majority of spam world-wide

Re: mail traffic

2008-11-13 Thread Simon Waters
On Thursday 13 November 2008 13:13:17 Revolver Onslaught wrote: Did you enconuter the same problem ? The view here is see McColo thread. Spamcop and DCC report significant drop coincident with McColo going offline. I just wish I could say the same about local spam volumes. We were blocking

Re: Hostexploit report/Intercage/Esthost

2008-10-13 Thread Simon Waters
On Monday 13 October 2008 15:30:07 Konstantin Poltev wrote: and Spamhaus itself claims not to be subject to any US laws, where it clearly does business. The Spamhaus website lists addresses in the UK and Switzerland. They appear to operate from the UK, and they claim to be subject to UK

Re: ingress SMTP

2008-09-05 Thread Simon Waters
On Friday 05 September 2008 00:33:54 Mark Foster wrote: *rest snipped* Is the above described limitation a common occurrance in the world-at-large? If the ISP blocks port 25, then the ISP is taking responsibility for delivering all email sent by a user, and they have to start applying rate

Re: ingress SMTP

2008-09-03 Thread Simon Waters
On Wednesday 03 September 2008 18:07:22 Stephen Sprunk wrote: When port 25 block was first instituted, several providers actually redirected connections to their own servers (with spam filters and/or rate limits) rather than blocking the port entirely. This seems like a good compromise for

TLD servers with recursion was Re: Exploit for DNS Cache Poisoning - RELEASED

2008-07-24 Thread Simon Waters
On Thursday 24 July 2008 05:17:59 Paul Ferguson wrote: Let's hope some very large service providers get their act together real soon now. http://www.hackerfactor.com/blog/index.php?/archives/204-Poor-DNS.html It isn't going to happen without BIG political pressure, either from users, or

Re: Multiple DNS implementations vulnerable to cache poisoning

2008-07-09 Thread Simon Waters
On Wednesday 09 July 2008 14:16:53 Jay R. Ashworth wrote: On Wed, Jul 09, 2008 at 04:39:49AM -0400, Jean-Fran?ois Mezei wrote: My DNS server made the various DNS requests from the same port and is thus vulnerable. (VMS TCPIP Services so no patches expected). Well, yes, but unless I've badly

Re: ICANN opens up Pandora's Box of new TLDs

2008-06-30 Thread Simon Waters
On Monday 30 June 2008 17:24:45 John Levine wrote: In the usual way. Try typing this into your browser's address bar: http://museum/ That was amusing. Firefox very handily took me to a search results page listing results for the word museum, none of which was the actual page in

Re: [NANOG] Tired of ...

2008-05-15 Thread Simon Waters
On Thursday 15 May 2008 16:23, Jay Hennigan wrote: Someone via nanog@nanog.org spammed: Tired of [snip] Can anyone suggest a faster way to get yourself blackholed than to spam this list? Spammers still spam our abuse address, that might do it.