Blog for hpHosts, and whatever else I feel like writing about ....

Thursday, 3 November 2016

Updated: hpHosts - 4th November 2016

The hpHOSTS Hosts file has been updated. There is now a total of 498,048 listed hostsnames.

If you are NOT using the installer, please read the included Readme.txt file for installation instructions. Enjoy! :)
  1. Latest Updated: 04/11/2016
  2. Last Verified: 04/11/2016
Download hpHosts now!
http://hosts-file.net/?s=Download

Enjoy!

Wednesday, 26 October 2016

Ten Years of Cybercrime & Doing Time

Very little is left worth celebrating any more (Christmas, Halloween, birthdays, Easter, the new Star Wars film, they're all over-rated rubbish), but this is one of those that you have to celebrate.

http://garwarner.blogspot.co.uk/2016/10/ten-years-of-cybercrime-doing-time.html

Dear Tagged, still not learned?

I've been getting Tagged spam on and off for years (sometimes it stops coming in). Seems they've still not learned to act like an ethical and honest company, and instead have decided that acting like complete unethical wankers is a better idea.



For those wondering, no, I don't usually have HTML email enabled (picture wouldn't have made as much sense in plain text).

As Tagged still haven't learnt, I've expanded the block on them ........ let's see if they work it out (I'll not hold my breath).

References

Tagged spam - with a difference
https://hphosts.blogspot.co.uk/2009/10/tagged-spam-with-difference.html

Tagged.com being sued - and about bloody time too!
https://hphosts.blogspot.co.uk/2009/07/taggedcom-being-sued-and-about-bloody.html

Tagged.com pays $750,000 over deceptive emails
http://www.theregister.co.uk/2009/11/10/new_york_ag_fines_tagged/

Dear Tagged .... weren't you already being sued for this?
https://hphosts.blogspot.co.uk/2009/07/dear-tagged-werent-you-already-being.html

Microsoft, Google, Facebook, Tagged et al - they never learn
https://hphosts.blogspot.co.uk/2010/04/microsoft-google-facebook-tagged-et-al.html

Wednesday, 21 September 2016

WARNING: Apple phishes

Been yet another influx of Apple phishes, all seemingly registered to the same individual, all using those lovely new gTLDs (cheers for that ICANN!).

uk_iosapplecareupdate.saf1.cloud
uk_iosAppleCareupdate.vefy1.support
uk_iosAppleCareupdate.vefy1.cloud
uk_iosAppleCareupdate.upd1.cloud
uk_iosAppleCareupdate.sgn1.support
uk_iosAppleCareupdate.sgn1.cloud
uk_iosAppleCareupdate.set1.support
uk_iosAppleCareupdate.set1.cloud
uk_iosAppleCareupdate.serv1.support
uk_iosAppleCareupdate.serv1.cloud
uk_iosAppleCareupdate.saf1.support
uk_iosAppleCareupdate.saf1.cloud
uk_iosAppleCareupdate.reg1.support
uk_iosAppleCareupdate.reg1.cloud
uk_iosAppleCareupdate.prof1.support
uk_iosAppleCareupdate.prof1.cloud
uk_iosAppleCareupdate.pro1.support
uk_iosAppleCareupdate.pro1.cloud
uk_iosAppleCareupdate.int1.support
uk_iosAppleCareupdate.int1.cloud
uk_AppleCarevalidate.vefy1.support
uk_AppleCarevalidate.vefy1.cloud
uk_AppleCarevalidate.upd1.cloud
uk_AppleCarevalidate.sgn1.support
uk_AppleCarevalidate.sgn1.cloud
uk_AppleCarevalidate.set1.support
uk_AppleCarevalidate.set1.cloud
uk_AppleCarevalidate.serv1.support
uk_AppleCarevalidate.serv1.cloud
uk_AppleCarevalidate.saf1.support
uk_AppleCarevalidate.saf1.cloud
uk_AppleCarevalidate.reg1.support
uk_AppleCarevalidate.reg1.cloud
uk_AppleCarevalidate.prof1.support
uk_AppleCarevalidate.prof1.cloud
uk_AppleCarevalidate.pro1.support
uk_AppleCarevalidate.pro1.cloud
uk_AppleCarevalidate.int1.support
uk_AppleCarevalidate.int1.cloud
uk_AppleAssistverifylog_in.vefy1.support
uk_AppleAssistverifylog_in.vefy1.cloud
uk_AppleAssistverifylog_in.upd1.cloud
uk_AppleAssistverifylog_in.sgn1.support
uk_AppleAssistverifylog_in.sgn1.cloud
uk_AppleAssistverifylog_in.set1.support
uk_AppleAssistverifylog_in.set1.cloud
uk_AppleAssistverifylog_in.serv1.support
uk_AppleAssistverifylog_in.serv1.cloud
uk_AppleAssistverifylog_in.saf1.support
uk_AppleAssistverifylog_in.saf1.cloud
uk_AppleAssistverifylog_in.reg1.support
uk_AppleAssistverifylog_in.reg1.cloud
uk_AppleAssistverifylog_in.prof1.support
uk_AppleAssistverifylog_in.prof1.cloud
uk_AppleAssistverifylog_in.pro1.support
uk_AppleAssistverifylog_in.pro1.cloud
uk_AppleAssistverifylog_in.int1.support
uk_AppleAssistverifylog_in.int1.cloud
ukappleverify.sub1.link
ukAppleAssistverify.int1.link
ukAppleAssistverify.ap1.link
uk_applesecurelog_in.int1.link
uk_applesecurelog_in.ap1.link
uk_applesafeauth.sub1.link
uk_applesafeauth.int1.link
uk_appleglobalupdate.sub1.link
uk_appleglobalupdate.int1.link
uk_applecarevalidate.sub1.link
uk_applecarevalidate.ap1.link
uk_iosAppleCareupdate.upd1.support
uk_AppleCarevalidate.upd1.support
uk_AppleAssistverifylog_in.upd1.support
ukappleverify.int1.link
ukappleverify.ap1.link
ukAppleCareverify.sub1.link
ukAppleCareverify.int1.link
ukAppleCareverify.ap1.link
ukAppleAssistverify.sub1.link
uk_applesecurelog_in.sub1.link
uk_applesafeauth.ap1.link
uk_appleglobalupdate.ap1.link
uk_applecarevalidate.int1.link


The vast majority are housed on:

IP: 23.95.37.25
AS: 36352 23.95.36.0/22 AS-COLOCROSSING - ColoCrossing, US

With the rest on;

IP: 104.232.32.18
ASN: 36352 104.232.32.0/22 AS-COLOCROSSING - ColoCrossing, US

IP: 216.126.225.145
ASN: 20150 216.126.225.0/24 SERVERCRATE - CubeMotion LLC, US

Personally I'd suggest firewalling both the IPs and ALL of the new gTLDs, but that's just me. I'll leave the decision to you.

Saturday, 27 August 2016

Fixed: sURL.co.uk

Just an FYI folks, the issue with surl.co.uk producing an HTTP 500 has now been fixed. Sorry for the delay.

Saturday, 6 August 2016

sevenforums.com: A lesson in screwing your users

Not content with the previous actions which at least used ads that weren't quite, it seems the owner of sevenforums.com has gone further down the "lets screw the users" path, in an effort to peddle crapware.

If you've been keeping up, you'll have seen the previous post I did on them, if not have wander, I'll wait;

https://hphosts.blogspot.co.uk/2013/07/alert-fake-google-chrome-and-yet-more.html

Now however, it appears the owner has thrown ethics and morals out of the window, users be damned. Now, if you happen on a thread that has certain keywords in the post, such as drivers, you'll see a link - but not a link the poster has put there themselves. No, this link goes to another domain owned by the same person that owns sevenforums.com (John Fairbrother, Designer Media Ltd) - win7.tips. This leads unsuspecting victims to reviversoft.com (paying more than SysTweak are they?).



And not surprisingly, it's the same story on his other sites;

hxxp://www.eightforums.com/drivers-hardware/10569-windows-8-alps-touchpad-driver.html



Only difference here, is it's not going via win7.tips, but via goo.gl, to;

hxxps://secure.reviversoft.com/576/cookie?affiliate=9809&redirectto=http://www.reviversoft.com/driver-reviver/lp/sf/wddc/index.php

And on;

hxxp://www.tenforums.com/drivers-hardware/5993-latest-realtek-hd-audio-driver-version.html



And;

hxxp://www.vistax64.com/sound-audio/64250-latest-realtek-hd-audio-driver-version-97.html



The disgusting parts here of course are;

1. These are not clearly marked as affiliate links/ads, but are disguised as regular links as if the posters themselves included them
2. They're leading to crapware
3. This is supposed to be a security forums, helping users clean up their machine - not have them get more crap on their machines!

By far the most disgusting however, and embarrassing for the rest of us, is the owner is supposed to be a Microsoft MVP!

Not surprisingly, these activities have landed his domains in hpHosts, with the MMT classification, and there they'll stay until this is stopped. Those of us that work in the security community are doing so to help users clean up and secure their machines etc. Those engaged in activities such as the above are doing entirely the opposite, for their own personal gain - users be damned, and this can not be tolerated.

hpHosts: Updated Saturday August 6th 2016

The hpHOSTS Hosts file has been updated. There is now a total of 422,975 listed hostsnames.

If you are NOT using the installer, please read the included Readme.txt file for installation instructions. Enjoy! :)
  1. Latest Updated: 06/08/2016
  2. Last Verified: 06/08/2016
Download hpHosts now!
http://hosts-file.net/?s=Download

Enjoy!

Sunday, 26 June 2016

Pixel Federation: Downside of no weekend working .....

.... amongst other things.

What do you get if you cross an extremely prolific pharma spammer, with a company that both doesn't have anyone working weekends, nor allows non-staff to moderate? A crap ton of errr, crap of course. In this case, over 900 posts spanning almost 4 pages, from a single user account;

hxxps://forum.trainstationgame.com/search.php?author_id=414709&sr=posts

I've already grabbed a copy of the offending domains involved, and they're all sitting on just 2 IPs (or were at the time of writing);

208.81.4.19
208.81.4.20

These IPs belong to AS394466 208.81.4.0/24 MyNetMojo (C02682025), aka Fiber Hosting Canada, leased to them by AS18451 Les.Net. Personally, I'd blackhole the entire /24, but I've got zero tolerance for this rubbish. At the time of writing, I'm only seeing badness on these two specific IPs, so I'll leave the decision to you.

Domains list for anyone wanting it (if you see any not on this list, and owned by the same bunch of miscreants, feel free to ping me);

100mg-doxycycline-buy.net
100mg-online-doxycycline.com
100mg-pillsviagra.com
100mggenericviagra.net
100mgviagra-buy.com
100mgviagra-online.org
20mg-cialis-5mg.net
20mg-cialis-canada.net
20mg-cialis-lowest-price.com
20mg-cialis-lowest-price.org
20mg-cialis-lowestprice.com
20mg-cialis5mg.com
20mg-cialiscanadian.com
20mg-cialischeapest.net
20mg-prednisone-buy.org
20mgcialis-canada.net
5mg-cheapest-cialis.com
5mg20mg-cialis.net
5mgbuy-propecia.net
5mgonline-propecia.com
amoxilamoxicillinbuy.com
antibiotic-flagyl500mg.com
antibioticazithromycinzithromax.org
autobahn.moonie.ca
buy-20mg-prednisone.net
buy-cheapest-price-viagra.com
buy-cialis-withoutprescription.net
buy-dapoxetinepriligy.org
buy-lowest-pricecialis.net
buy-pharmacy-canadian.org
buy-prednisone20mg.com
buy-propecia-generic.net
buy-propranololinderal.org
buy20mgprednisone.net
buyamoxicillinamoxil.org
buygeneric-levitra.org
buygeneric-propecia.com
buylasixfurosemide.org
buyretin-a-ca.org
canada-20mg-cialis.net
canada-cialis-5mg.com
canada5mgcialis.net
canadatadalafilcialis.com
canadian-100mg-viagra.com
canadian5mg-cialis.org
canadianprices-pharmacy.net
celebrex-noprescription-200mg.org
cheapest-pricelevitra-20mg.com
cheapestonline-cialis.com
cheapestonline-levitra.com
cheapestprice-cialis20mg.net
cialis-20mg5mg.com
cialis-5mgonline.net
cialis-buylowestprice.org
cialis-buytadalafil.org
cialis-canada-online.org
cialis-canada20mg.net
cialis-cheapest-price-20mg.com
cialis-generic-pills.org
cialis20mg5mg.com
cialis20mgcanada.net
cialis20mgcanadian.org
cialisbuylowest-price.org
cialischeapest20mg.net
cialisgeneric-5mg.net
cialisgeneric5mg.net
cialisgenericlowest-price.com
cialislowestpricegeneric.com
cialisonline-cheapest-price.net
cialistadalafil-buy.org
cialistadalafil-canada.org
cialistadalafilcheapest.com
clomiphene-citratebuyclomid.org
cytotec-onlinebuy.org
dapoxetine-priligy-buy.net
dapoxetine-priligycanada.net
doxycyclinehyclate-100mg.com
dutasterideavodartgeneric.org
enligne-pharmacycanadian.org
for-salepropeciaonline.org
furosemide-buylasix.net
furosemideonlinelasix.net
generic-buypropecia.org
generic-canadalevitra.com
generic-cialislowestprice.org
generic-levitravardenafil.com
generic-levitravardenafil.net
generic-lowest-price-cialis.net
generic-lowestpricecialis.org
generic-propecia-5mg.org
generic-propecia-buy.com
genericlevitra-buy.com
genericprice-oflevitra.com
genericpriceslevitra.net
jellyoral-kamagra.net
kamagra-jelly-forsale.org
lasixbuywithout-prescription.com
lasixfurosemideonline.net
levitra-canada-generic.com
levitra-cheapestgeneric.com
levitra-cheapgeneric.org
levitra-discount-generic.org
levitra-generic-buy.net
levitra-onlinevardenafil.org
levitra-prices-buy.org
levitra-tablets-generic.net
levitra-vardenafil-online.com
levitra20mg-order.net
levitrabuy-generic.org
levitrabuy-vardenafil.org
levitraonline-vardenafil.net
lowest-price-cialis-20mg.org
lowest-price-online-cialis.org
lowest-price20mg-cialis.org
lowest-priceonline-cialis.net
lowest-priceretin-a-online.org
lowestprice-20mg-cialis.org
lowestprice-cialis-generic.com
lowestpricecialiscanadian.com
nexium-generic40mg.org
no-prescription-viagracheapest.net
noprescription-online-prednisone.com
online-100mg-viagra.net
online-amoxil-amoxicillin.org
online-amoxilamoxicillin.org
online-cheapest-prednisone.net
online-cheapestpriceviagra.org
online-cialis-canada.net
online-ciprofloxacinbuy.net
online-ciprofloxacinhcl500mg.org
online-kamagra-buy.net
online-without-prescriptioncialis.com
online20mg-prednisone.com
onlineamoxicillin-amoxil.net
onlinebuy-flagyl.org
onlinebuy-nexium.org
onlinecialistadalafil.net
onlinelowest-pricecialis.net
onlinepharmacy-usa.org
onlinepharmacyforsale.net
onlineprednisone-20mg.com
onlineprednisonewithout-prescription.net
onlineprednisonewithoutprescription.org
onlinepropecia5mg.net
onlinevardenafillevitra.net
orderwithout-prescription-prednisone.org
pharmacy-buycanadian.net
pharmacy-onlineforsale.net
pills-cialis20mg.com
pillsgenericcialis.org
prednisone-buy-20mg.com
prednisone-order-20mg.net
prednisone-without-prescriptionbuy.net
prednisoneno-prescription-order.com
prednisoneonline-no-prescription.org
prednisoneonline20mg.org
prednisoneorderonline.net
price-of-cialis-tadalafil.com
price-ofbuyretin-a.com
prices-levitrageneric.com
pricesgeneric-levitra.com
priligybuy-online.com
propecia-online-cheap.net
propecia-online-priceof.com
propeciabuy-generic.org
propeciacheapbuy.org
propeciafinasterideonline.net
propeciageneric-buy.org
propeciageneric-without-prescription.com
propeciaonline-order.com
purchase-online-strattera.com
salbutamolbuyventolin.org
stratteraorderonline.net
tablets-doxycycline-100mg.com
tadalafilcialisprices.net
tamoxifen-nolvadex-for-sale.com
tamoxifen-onlinenolvadex.com
tamoxifenordernolvadex.com
usapharmacy-online.net
vardenafil-genericlevitra.org
vardenafillevitra-canada.org
vardenafillevitra-online.com
vardenafillevitracheapest.org
vardenafilonlinelevitra.com
ventolin-salbutamolonline.net
ventolinbuyonline.net
ventolinonlinebuy.org
viagra-cheapestcanadian.net
viagra-generic-100mg.net
viagra-online-100mg.net
viagra100mgonline.org
viagrabuy-cheapest-price.org
viagrapills-discount.com
without-prescription-cheap-propecia.net
without-prescription-cialiscanada.org
without-prescription-online-prednisone.net
without-prescription-propeciabuy.com
without-prescriptionprednisoneorder.net
withoutprescriptionpropeciabuy.com
zithromax-250mg-azithromycin.org
zithromaxonlineazithromycin.org

Friday, 24 June 2016

Oi BBC, Nigel - STOP IT!

Been watching the latest unfold all morning, and since the results were finalized, there's been one constant - a claim "the UK has voted to leave" - NO WE DID NOT!, only HALF of the UK did (51.9% to be exact, out of a 72% turnout (just under 3 quarters voted) - that is not "the UK", that's only half of those that voted!).

Wednesday, 22 June 2016

[INFO] hpHosts forums and website

Just a note folks, the hpHosts forums and website are now SSL (you shouldn't notice any different, the site will auto-redir an HTTP to HTTPS request). If you do encounter problems, please ping me.

[INFO] Site updates

Just a note folks, some of the sites are to be moved from their existing server, primarily the mysteryfcm.co.uk site, which is to be moved to to a server in the 1&1 DC.

Hoping to get it done by tomorrow, but may take longer (extremely swamped atm).

Additionally, the hpHosts website and forums are to finally have SSL by the end of today (if we can get DigiCert to play nicely).

Saturday, 18 June 2016

hpHosts: Updated Saturday June 18th 2016

The hpHOSTS Hosts file has been updated. There is now a total of 379,840 listed hostsnames.

If you are NOT using the installer, please read the included Readme.txt file for installation instructions. Enjoy! :)
  1. Latest Updated: 19/05/2016
  2. Last Verified: 19/05/2016
Download hpHosts now!
http://hosts-file.net/?s=Download

Enjoy!

[INFO] Server updates

Just an FYI folks, the fSpamlist, vURL etc servers are being updated, shouldn't take long (will only be down whilst they reboot)

Thursday, 16 June 2016

fSpamlist: DB server downtime

Just a note folks, the DB server used for fSpamlist detected a power spike whilst I was sleeping this morning and went into fail-safe, effectively shutting itself down.

It's back online now. Apologies for any inconvenience.

Wednesday, 15 June 2016

Dear ClickSure - are you insane?

I send a plethora of abuse reports daily, for everything from generic spam to malware, exploits and our friendly tech support scammers (yes, you guys too - woops!). However, I received what has entered the list of the most frustrating responses, this time from ClickSure:

Hello Steven,

This is an automated email, please DO NOT reply to this message as responses are not monitored on this email address.

There has been a New Reply to the discussion entitled "Spam" (#CLKSPT4905643):

Hello,

Thank you for contacting support.

We take spam complaints very seriously and will look into this.

Additionally can you please unsubscribe from any unwanted emails

Regards,

Indy

Best regards,

ClickSure Support


Why is it frustrating you ask? Lets see shall we;

1. It doesn't include the original resport
2. It fails to provide a method for reply
3. It says there's been a reply to the discussion (errr, the what?)
4. It actively encourages those reporting spam to USE THE UNSUBSCRIPTION LINK

I can hear the cries already - why is using the unsubscription link a bad thing?

Well for starters, I never subscribed in the first place! You should NEVER EVER EVER (repeat that to yourself a hundred times, I'll wait) click an unsubscription link, reply with unsubscribe etc in the subject/body/whateveritisasking if you did not subscribe to it in the first place - all this does, is tells Mr and Mrs Spammy that the address is active and monitored (woops, you're now going to get a ton more).

ClickSure on the other hand, seem to be smoking something seriously wonky (or have had a severe case of the wedontgiveatossitis (what!, everything has an "itis" now apparently!), yep, I'm being VERY polite here for some reason). They may as well have responded with "just lean forward and allow that tree to be shoved up there, we're raking it in!" - it would've inferred the same lack of giving a toss.

Wednesday, 18 May 2016

hpHosts: Updated Thursday 19th May 2016

The hpHOSTS Hosts file has been updated. There is now a total of 379,840 listed hostsnames.

If you are NOT using the installer, please read the included Readme.txt file for installation instructions. Enjoy! :)
  1. Latest Updated: 19/05/2016
  2. Last Verified: 19/05/2016
Download hpHosts now!
http://hosts-file.net/?s=Download

Enjoy!

Monday, 16 May 2016

Updated: Spambot Search Tool

v0.59 has been released. Modified MySQL functions to use mysqli_ instead of mysql_ Ref: http://php.net/manual/en/ref.mysqli.php Notes: If running PHP 5.5 or earlier, you will need to either stay with v0.58, or upgrade PHP to 5.6 or above, as the mysql_* extension has been deprecated by the PHP developers, in favour of the improved mysqli_* extension.

Download: http://support.it-mate.co.uk/?mode=Products&p=spambotsearchtool

Saturday, 14 May 2016

Dear Microsoft: For the sake of $diety get it right!

I had to choose a smartphone when my old dumb phone died (couldn't get batteries for it anymore), and figured bugger it, I despise Android, despise Apple (it's over-priced rubbish), and use primarily, Windows, so went with the Lumia 550.

Whilst a pain, it's been better than the alternatives - until now.

Why exactly, do you make it so god damn difficult to connect the phone to the laptop, so the SD card can be accessed? (have you guessed I've not went with Windows 10 for my laptop yet? (get rid of the Fisher Price UI, telemetry, forced updates etc and I may try it again).

I went to the site (https://www.microsoft.com/en-gb/mobile/support/product/lumia550/) to find the software, and I'll be damned if I can find it. Not surprisingly, Windows 7 (yep, I hate 8/8.1 too) can't install the driver either - ah the joys.

If you're going to do this - do it right! (hint: the OS SHOULD NOT MATTER!)

/edit

Oh and no, once I found the "Windows Phone app [sic] for desktop", it did NOT help (couldn't find the phone .......... what a surprise (and yep, the "Find my phone" option is beyond useless)).

Can't exactly recommend others get a Windows phone if it doesn't even do basic things like USB sharing without an extremely bad headache (I've fixed Android etc phones and in most cases, I can either use the SDK, or the SD card shows up when I plug the phone in)

Wednesday, 16 March 2016

hpHosts: Updated March 17th 2016

The hpHOSTS Hosts file has been updated. There is now a total of 360,309 listed hostsnames.

If you are NOT using the installer, please read the included Readme.txt file for installation instructions. Enjoy! :)
  1. Latest Updated: 17/03/2016
  2. Last Verified: 17/03/2016
Download hpHosts now!
http://hosts-file.net/?s=Download

Enjoy!

Wednesday, 27 January 2016

hpHosts: Updated 27th January 2016

The hpHOSTS Hosts file has been updated. There is now a total of 350,932 listed hostsnames.

If you are NOT using the installer, please read the included Readme.txt file for installation instructions. Enjoy! :)
  1. Latest Updated: 27/01/2016
  2. Last Verified: 27/01/2016
Download hpHosts now!
http://hosts-file.net/?s=Download

Enjoy!