Blog for hpHosts, and whatever else I feel like writing about ....

Monday, 6 October 2008

Enom - Another bleedin joke!

On October 1st, I sent the following abuse report to eNom concerning h4cky0u.org, one of their customers;

Ref: h4cky0u.org (IP: 216.195.56.228), Registrar: Enom, Host: APS Telecom

I am reporting this group as they are actively involved in illegal activity such as hacking MSN/ICQ/AIM/MySpace/Yahoo/Hotmail and Gmail accounts;

The Hotmail hacks thread
http://www.h4cky0u.org/viewtopic.php?f=3&t=4933

The Yahoo hacks thread
http://www.h4cky0u.org/viewtopic.php?f=3&t=5559

The Gmail hacks thread
http://www.h4cky0u.org/viewtopic.php?f=3&t=5560

MSN/ICQ/AIM/MySpace
http://www.h4cky0u.org/viewtopic.php?f=3&t=29170

Further to this, they are also heavily involved in SQL exploits and RFI (Remote File Injection) attacks;

http://www.h4cky0u.org/viewtopic.php?f=3&t=30223
http://www.h4cky0u.org/viewtopic.php?f=3&t=30222
http://www.h4cky0u.org/viewtopic.php?f=3&t=30068
http://www.h4cky0u.org/viewtopic.php?f=3&t=30207
http://www.h4cky0u.org/viewtopic.php?f=3&t=29950

Further to this, they are also involved in hacking bank accounts, such as;

http://www.h4cky0u.org/viewtopic.php?f=3&t=29883
http://www.h4cky0u.org/viewtopic.php?f=3&t=29747

Since this website is hosted in the US, this e-mail has also been CC'd to the FBI.


5 days later, they responded with an auto-reply, to tell me in no uncertain words, that the abuse e-mail address I'd sent the report to, was not monitored and that I should instead, send the abuse report via their website (in short, my sending an abuse report to their abuse e-mail address was a complete waste of time).

Please be advised this email box is not monitored, and you will not get a reply.

If you have an abuse complaint, please go the Abuse Policy page and complete the form here: www.enom.com/terms/AbusePolicy.asp

If you have an account, please log into your account and click HELP, Support Center and then click the tab to Submit a Ticket to Technical Support. Log into your account at the appropriate site: www.eNom.com, www.eNomCentral.com or www.BulkRegister.com.

If you purchased your domain through one of our resellers, please go to the About Us page on the website: www.enom.com/aboutus.asp On the far right is a box where you can enter your domain name and your reseller information will be returned to you. Please contact them directly for domain assistance.

For all other queries, or if you forgot your user name and password, please go to the About Us page on the website. On the far right side is a Contact Us box, where you can click the link under General Email to enter a form and Submit a Ticket for assistance: www.enom.com/aboutus.asp

If you prefer to call us for assistance our technical support staff can be reached at the numbers below 24 hours a day, 7 days a week.

Thank you for contacting us, we do appreciate your business and look forward to working with you.

__________________________________
eNom, Inc., a Demand Media company
U.S. Technical Support 425.274.4500 Option 3 Technical Support Fax 425.974.4791
15801 NE 24th St.
Bellevue, WA 98008


Fine, I decided to send the report via their website - and what happened? The damn report was forwarded to their abuse e-mail address! (and I know this because they sent me a CC of the report I sent, with my address in the From and CC box, and their abuse dept's e-mail address (report.abuse@enom.com) in the To box). Okay, this is just getting annoying.

More annoyingly however, is that 10 minutes after sending the report via the website, I received the following from their abuse department, which again, looks very much like a form letter auto-reply;

Hello,

Thank you very much for your notification. After researching the domain, we have found that eNom, Inc. only provides domain name registration for this customer. We are not the webhost, internet service provider, or administrator for the reported domain. Given that we are not the webhost for the reported domain, the allegedly infringing material identified in your notification does not reside on eNom's servers. Accordingly, we do not have the technical ability to remove or disable specific items of objectionable content.

Again, due to the limited technical sphere in which eNom operates, we do not believe that we are the correct party to contact regarding this matter. In this instance, we suggest that you contact the party operating the website or the party hosting the website to have this matter properly resolved. A "ping" of the website you indicated often reveals the IP address of the party which probably hosts this website. You may then use http://www.arin.net/whois/ or another similar tool to identify this party.

Thank you again for your report, and please do not hesitate to contact us should you have any further questions.

Regards,

eNom Inc., A Demand Media Company


eNom's taking 5 days to send an auto-reply is bad enough, and then telling me that the abuse e-mail address is not monitored is annoying - but to then tell me they cannot deal with an abuse report for one of their customers, simply because they aren't providing the hosting, is an absolute joke!.

Many other registrars WILL deal with these, and WILL shut down the domain involved - why won't eNom? Indeed, whilst certainly not a fan of Directi, they have shut down domains I've reported (okay, it's taken a bit of work, but they've done it), and other registrars that AREN'T crime friendly, have also shut down domains I've reported.

I suppose I should just consider myself lucky that they bothered responding at all. The sites hosting company (APS Telecom/3FN) haven't bothered (trying to phone either of these results in it ringing for a bit, then going straight to answer phone, and contrary to 3FN's website, their 24 hour MSN support is err, offline!), nor have whoisprivacyprotect.com, which the domain is using to hide the registrants details.

What Tom wants, Tom gets!

Tom asked if I could implement a new "Browse by date" option into the hpHosts interface, and what Tom wants, Tom gets hehe.

When browsing the hpHosts database, you can now choose to filter the display by year, and then drill down to filtering by month;

View entries added in 2008
http://hosts-file.net/?s=Browse&f=2008

View entries added in March 2008
http://hosts-file.net/?s=Browse&f=2008

I've also linkified the "Added" in the Added column, so you can reverse the results if needed (ascending or descending).

Ruby In Steel - New Free Edition includes free copy of Visual Studio

My good friend Huw Collingbourne, from Bitwise Magazine has yet another great and FREE download for you, courtesy of his company SapphireSteel Software!.

Ruby In Steel - New Free Edition includes free copy of Visual Studio

SapphireSteel Software today released a free edition of Ruby In Steel, the Ruby and Rails IDE for Microsoft Visual Studio 2008.

Ruby In Steel Personal Edition (PE) 2008 provides all the tools needed to develop and maintain Ruby or Ruby On Rails projects including syntax sensitive customizable code coloring and code folding, coding tools such as auto-indenting, code reformatting, bracket and keyword matching and integrated consoles to allow users to interact with the Ruby interpreter in docked or floating windows. Ruby In Steel PE 2008 even includes a free copy of Visual Studio 2008!

Ruby In Steel PE 2008 is available for personal or commercial development. It does not require registration and it does not time out. It comes with an ‘All-in-One’ installer to allow users to install all the software required including: Visual Studio 2008 (‘Shell edition’), Ruby, Rails, MySQL and Ruby In Steel. Alternatively, users who already own a commercial edition of Visual Studio 2008 may install Ruby In Steel into that.


See more, and get the download, from my friend Huw!;

http://www.bitwisemag.com/2/Free-Ruby-In-Steel-IDE-includes

If you don't know Ruby, but would like to learn, get the free e-book (inclusive of source code) for free from;


http://www.sapphiresteel.com/The-Little-Book-Of-Ruby

References

Bitwise Magazine
http://www.bitwisemag.com

SapphireSteel Software
http://www.sapphiresteel.com

Saturday, 4 October 2008

hpHosts Second Birthday

At 00:00, approximately 1 hour (give or take 10 mins) from now, will see the second anniversary of my taking over hpHosts from hpGuru.

Last year, I mentioned some changes that were and were still, to be made to hpHosts, including;

1. MX information
2. rDNS
3. IP family
4. WhoIs information

All except one of these have been implemented for some time, with rDNS only being partially implemented (e.g. Host > IP and IP > PTR). Not yet implemented, is full rDNS that would allow you to query an IP and see all of the hostnames that are assigned to it. At present, a query against an IP will only show you the hostnames assigned to that IP, that are listed in hpHosts.

Several other changes have been made to hpHosts during the past 12 months too, such as ammendments to the inclusion policy;

http://forum.hosts-file.net/viewtopic.php?f=9&t=12

And of course, the new hpHosts blog;

http://hphosts.blogspot.com

Indeed, improvements to hpHosts, along with wider use, have also seen several security vendors including the hpHosts database in their own products, including;

FireTrust (SiteHound)
Emsisoft (a-squared Anti-Malware - cookie manager only at present)
Web of Trust
Abelhadigital (HostsMan)

Further improvements, came with the addition of new download mirrors, and re-offering (after hosts-file.info vanished) of the plain .txt file;

http://forum.hosts-file.net/viewtopic.php?f=23&t=6

And of course, the RSS feeds;

http://forum.hosts-file.net/viewtopic.php?f=23&t=220

And allowing others to directly query the hpHosts database from their own applications;

http://forum.hosts-file.net/viewtopic.php?f=23&t=561

These changes however, would mean nothing if it wasn't for the wonderful and much appreciated, work of those that help me identify new hostnames to be added. Whilst I find some of them myself, alot of them are submitted for inclusion by the selfless volunteers - and a huge thank you must go to them.

Of course, without you, the users, there wouldn't be much use in our actually providing this file and service, so to you all, I say thank you - I hope I've done you proud.

Directi have suspended cr4nk.us!

Interestingly, whilst they didn't respond to the abuse e-mail I sent, DirectI have responded to my previous article - by suspending cr4nk.us, yipee!

Hi,

This is with reference to the article dated Friday, 3 October 2008, "Directi and HostFresh still supporting criminals! "

The Domain name CR4NK.US has been suspended and taken down. The customer account is also under investigation for illicit domain names.

We would like to know more about your attempts to contact DirectI before making these remarks. Please update us with the email address from which you tried contacting us. We are asking this because we have a 24x7 abuse team that would have at lease acknowledged your request.

Regards;
Aman Masjide
DirectI Abuse Desk


He's asked about the e-mail address I used - I've responded to his e-mail to let him know (DOH! it was abuse{AT}directi(DOT)com, same as last time), but either way it's great to see cr4nk's site shut down yet again! :o)