Blog for hpHosts, and whatever else I feel like writing about ....

Friday, 30 March 2012

Hotels: Earn trust before you ask us for it!

I'm off down London next month, for InfoSec, and because of such, have a need for a hotel in Kensington (Earls Court to be precise). I found several, but most were already fully booked, or stupidly expensive (Hilton falling into the latter at £350 PER NIGHT!).

What astounded and disgusted me however, were the following;

1. mowbraycourthotel.com
2. studios92.com
3. bokahotel.com

Why did they disgust me? Let me count the ways;

1. They DO NOT provide their contact information anywhere on their website - instead, the contact information is for a THIRD PARTY*, nice of them to tell you that.

2. The phone numbers listed in the whois details, are either invalid (in the case of mowbraycourthotel.com) or don't accept incoming calls (in the case of the other 2), meaning you can't contact the hotel directly

3. No valid e-mail address to contact the hotels THEMSELVES!, instead, again, you're given the e-mail address for a THIRD PARTY!

4. Worst of all however, is given this, they still require a deposit, which normally would be fine - most hotels do - but the problem here, is they want us to trust them with our credit/debit card details, when they can't even provide basic contact information!


Personally I find that absolutely abhorant. Needless to say, the domains have been reported to Internic/ICANN due to the invalid phone numbers.

* And who is this third party?

traveltura.com

But hang on, if we load the homepage (i.e. no referrer or such), it says it's "Boka Hotel" - but hows that exactly, when it's clearly not? it then gets more confusing if we load its WhoIs details up - guess who we see;

Registrant:
Traveltura com Ltd
3 Littlestone Road
New Romeny
kent, Kent TN28 8LN
GB

Domain name: TRAVELTURA.COM

Administrative Contact:
Traveltura, Traveltura dj@studios92.com
3 Littlestone Road
New Romeny
kent, Kent TN28 8LN
GB
+00447989420877
Technical Contact:
Traveltura, Traveltura dj@studios92.com
3 Littlestone Road
New Romeny
kent, Kent TN28 8LN
GB
+00447989420877

Registration Service Provider:
Fasthosts Internet Limited, domains@fasthosts.co.uk
+44.8708883600
+44.8708883760 (fax)
http://www.Fasthosts.co.uk

Registrar of Record: TUCOWS, INC.
Record last updated on 03-Sep-2011.
Record expires on 15-Dec-2019.
Record created on 15-Dec-2009.

Registrar Domain Name Help Center:
http://tucowsdomains.com

Domain servers in listed order:
NS.RACKSPACE.COM
NS2.RACKSPACE.COM

Domain status: clientTransferProhibited
clientUpdateProhibited


But hang on - we've seen @studios92.com before;

Registrant:
Studios92 com Ltd
Aspect House
16 Wilmer Place
Stoke Newington
London, London N16 0LQ
GB

Domain name: STUDIOS92.COM

Administrative Contact:
Studios92, Studios92 info@studios92.com
Aspect House
16 Wilmer Place
Stoke Newington
London, London N16 0LQ
GB
4402088026646 Fax: 4402082118983

Technical Contact:
Bouderba, Bo info@studios92.com
Aspect House
16 Wilmer Place
Stoke Newington
London, London N16 0LQ
GB
4402088026646 Fax: 4402082118983

Registration Service Provider:
Fasthosts Internet Limited, domains@fasthosts.co.uk
+44.8708883600
+44.8708883760 (fax)
http://www.Fasthosts.co.uk

Registrar of Record: TUCOWS, INC.
Record last updated on 24-Sep-2011.
Record expires on 12-May-2017.
Record created on 12-May-1999.

Registrar Domain Name Help Center:
http://tucowsdomains.com

Domain servers in listed order:
ns1.livedns.co.uk
ns3.livedns.co.uk
ns2.livedns.co.uk

Domain status: clientTransferProhibited
clientUpdateProhibited


And just to confuse matters;

Registrant:
Studios92 com Ltd
Aspect House
16 Wilmer Place
Stoke Newington
London, London N16 0LQ
GB

Domain name: MOWBRAYCOURTHOTEL.COM

Administrative Contact:
Bouderba, Bo info@studios92.com
Aspect House
16 Wilmer Place
Stoke Newington
London, London N16 0LQ
GB
+4402088026646 Fax: +4402082118983

Technical Contact:
Bouderba, Bo info@studios92.com
Aspect House
16 Wilmer Place
Stoke Newington
London, London N16 0LQ
GB
+4402088026646 Fax: +4402082118983

Registration Service Provider:
Fasthosts Internet Limited, domains@fasthosts.co.uk
+44.8708883600
+44.8708883760 (fax)
http://www.Fasthosts.co.uk

Registrar of Record: TUCOWS, INC.
Record last updated on 02-Feb-2012.
Record expires on 03-Mar-2013.
Record created on 03-Mar-2004.

Registrar Domain Name Help Center:
http://tucowsdomains.com

Domain servers in listed order:
NS1.LIVEDNS.CO.UK
NS3.LIVEDNS.CO.UK
NS2.LIVEDNS.CO.UK

Domain status: clientTransferProhibited
clientUpdateProhibited


Registrant:
Boka Hotel
33 Eardley Crescent
SW5 9JT
London, Earls Court SW5 9JT
GB

Domain name: BOKAHOTEL.COM

Administrative Contact:
Boka Hotel, Boka Hotel reservations@bokahotel.com
33 Eardley Crescent
SW5 9JT
London, Earls Court SW5 9JT
GB
+0044.20873701388
Technical Contact:
Boka Hotel, Boka Hotel reservations@bokahotel.com
33 Eardley Crescent
SW5 9JT
London, Earls Court SW5 9JT
GB
+0044.20873701388

Registration Service Provider:
Fasthosts Internet Limited, domains@fasthosts.co.uk
+44.8708883600
+44.8708883760 (fax)
http://www.Fasthosts.co.uk

Registrar of Record: TUCOWS, INC.
Record last updated on 09-Aug-2011.
Record expires on 25-Apr-2013.
Record created on 25-Apr-2003.

Registrar Domain Name Help Center:
http://tucowsdomains.com

Domain servers in listed order:
ns1.livedns.co.uk
ns2.livedns.co.uk

Domain status: clientTransferProhibited
clientUpdateProhibited


The only one that actually has the address of the hotel in the WhoIs, is bokahotel.com, but the e-mail address doesn't appear to exist (bounced), and none of the phone numbers in ANY of the domains whois records, actually work (one doesn't exist (mowbraycourthotel.com) and the others don't accept incoming calls).

But this doesn't add up - traveltura.com insist they're nothing more than an agent - a third party, not the hotels themselves - yet everything says they're all one and the same entity, regardless of the different company names, different WhoIs, invalid phone numbers, etc etc etc.


So given this, given they don't seem to be forthcoming about who they are, and don't want to provide actual valid contact details - phone numbers for the *hotels* themselves being the most important, would you trust them with your credit/debit card? I certainly won't be doing.

Oh and to make matters worse, when you do query with them, and they send you an e-mail - it's actually just a link to the search page - WITH THEIR AFFILIATE ID (yep, I double checked ;o) ) - you could've done the damn search yourself in the time it took for you to pay to phone them, or the time it took you to e-mail the so-called third party!

I've got work that needs doing however, so won't be digging into them any further just yet, will be doing that when I get some free time.

Thursday, 22 March 2012

Info: Paragon to stop providing WinPE

One of the benefits of being an MVP, is you get all sorts of free products, some from Microsoft, and some from third parties. One of the third parties, is Paragon Software. I'm actually in the middle of putting a review together for a Paragon product that I've been using for a while (more on that in due course), but this came in today, which will put a damper on anyones decision to get them;

You own a Paragon product with the WinPE recovery environment. We would like to inform you that Microsoft has changed its license conditions, meaning that we will no longer be allowed to offer you the Paragon WinPE as of March 30, 2012.


If you haven’t downloaded your WinPE from the Paragon website yet, we recommend you to do so by March 30, 2012. To do this, log in at Paragon My Account, download the WinPE and use it to create your boot medium in case of emergency. This is the most convenient way to restart your operating system without reinstallation in the event of system failure.


After March 30th, it will no longer be possible to download the WinPE recovery environment using your account! Customer service/support will not be able to send it retroactively!



Full details here;

http://www.paragon-software.com/newsletter/2012/20120320_winpe_bmb.html

Personally, I hope they come up with an alternative, perhaps using Linux, as this is one of the major benefits of their software.

Monday, 19 March 2012

Alert: Santander phish (aka, when all else fails, fall back on bit.ly - again)

I do despair of the fact the criminals running these, keep going back to old methods - yes they work, but that's irrelevant (and of course, people will always be gullible), going back to old methods means there's no surprises - and I like surprises!

I processed a phish targeting Santander customers a few days ago (led to ~3GB of evidence for not just phishing, but a host of other things too - oh the joys). Already had the server cleaned up and secured as it was re-compromised whilst I was investigating.

In this case, the phish comes with an attachment (letter.html), that contains a link to;

hxxp://bit.ly/GzoQge

This leads to;

hxxp://redirectauth.com/redirect1.php

This then leads to;

hxxp://santander.cgiauthweb.com/santander.co.uk/retail/LOGSUK_NS_ENS/gon.php

You'll not be surprised to learn, both the MITM and the phish, are housed on the same IP;

IP: 93.185.104.27
IP PTR: www17.pipni.cz
ASN: 43541 93.185.96.0/20 VSHOSTING VSHosting s.r.o.

And less surprised to learn, both domains are owned by the same miscreant;

Domain name: CGIAUTHWEB.COM
Name Server: ns.pipni.cz
Name Server: ns2.pipni.cz
Creation Date: 2012.03.15
Expiration Date: 2013.03.15

Status: DELEGATED

Registrant ID: AUVGQVT-RU
Registrant Name: Jonathan Yarrall
Registrant Organization: Jonathan Yarrall
Registrant Street1: 3455 Bellflower Blvd
Registrant City: Long beach
Registrant Postal Code: 90808
Registrant Country: US

Administrative, Technical Contact
Contact ID: AUVGQVT-RU
Contact Name: Jonathan Yarrall
Contact Organization: Jonathan Yarrall
Contact Street1: 3455 Bellflower Blvd
Contact City: Long beach
Contact Postal Code: 90808
Contact Country: US
Contact Phone: +1 562 4294761
Contact E-mail: lilboo2x@gmail.com

Registrar: Regional Network Information Center, JSC dba RU-CENTER



Sunday, 18 March 2012

Canadian pharmacy: Lets play tagged!

As if the reputation of Tagged for spamming people, wasn't bad enough, the boys involved in fake pharmacies have decided to make it even worse, by mis-using the Tagged name, presumably in an attempt to bypass spam filters (woops!).

From: Tagged <Tagged@taggedmail.com>
To: raymonda_laermans@yahoo.co.uk
Sent: Saturday, 17 March 2012, 22:11
Subject: Senga D sent you a message...


<http://sks.yyu.edu.tr/dimensioning.html> My Profile <http://sks.yyu.edu.tr/dimensioning.html> |Messages <http://sks.yyu.edu.tr/dimensioning.html> |Friends <http://sks.yyu.edu.tr/dimensioning.html> |Meet Me <http://sks.yyu.edu.tr/dimensioning.html> |Browse <http://sks.yyu.edu.tr/dimensioning.html> |Search <http://sks.yyu.edu.tr/dimensioning.html>
<http://sks.yyu.edu.tr/dimensioning.html> Senga D, 29 You have a new message!
Senga D says: Hi. Do you remember me ?
View message! <http://sks.yyu.edu.tr/dimensioning.html>

Manage my account and email settings <http://sks.yyu.edu.tr/dimensioning.html> on Tagged Inc., 110 Pacific Mall Box #117, San Francisco, CA. 94111
All Tagged emails will be sent from our official @tagged.com or @taggedmail.com domains to your registered email address. We will never contact you from any other email addresses.


From Tagged Sat Mar 17 21:11:00 2012
X-Apparently-To: [REMOVED] via 87.248.103.88; Sat, 17 Mar 2012 18:28:50 +0000
Return-Path: <billtownsend@talkmatch.com>
X-YahooFilteredBulk: 67.225.143.155
Received-SPF: fail (domain of talkmatch.com does not designate 67.225.143.155 as permitted sender)
X-YMailISG: ZqA8NFgWLDuXaeTEMafLSAqynCwVdfranwA.jeTP3Atwb.F2
3hlABc8WXiYcr9sZCQqUgabP6fGehBSMin8beNWGH_43Igx6zbp1Sq0x2zSG
BBab56U2ZswLQmEXk4qwsKsTOG2vNjpCI.TCwCg0xugmy9n49fxw7gyHd7KS
PfLcxH_Pr9JSpu58zrmmJwUjQxDwGYj7VlTnhoseK.sPnmZ7b_O9j9GZp8Wo
_Kapk5ZQu7xcFgrIIvHY7aeBOSB1Bzu9vQTk.OU3vhjREOTpi4Jb6ZpkDcIF
g64z7FfU7yQgUkxVZzQD46qOcH336b7oAPCZb9QhsSfAAvLmyPDQMjNS50Hh
d5gdYyKryoTYnTo8BKO47tVS0b.nMnn7pwUVlrHIGFM0Y9SgsymUXgzS4u_d
cZIrHE6Luaxt1oFxRaPhfYYqTKPYjvCMoBUSxFk_JpQzAhZ_y28IHT55q6AE
SCnsVjmU_d7.iKvdDp6Dbnx6e4oZLnZbECU4NlrHynmGzeqGEqtnwahD38x6
HkqakM2qLDklQFVr6mFtbfXVYfg7.PYY5lFO163O59_I_6SzZPRwW_BCFc.O
AFd9_5bu7fyaTcIm1pTP5zHm0Lcg3wYB2KH.6uUprdNYiJLzaholknfwbqdJ
8SL_yv2efVSkodO.mO3ZEijwR7WSwDlIFIpYI1e2wXCs3Zap9MUnmoSGhAab
5NwZvAMxAA4zkbs8OsOkiUWHTckslU1tKnpZVlB82.yCTfX2we61AeQw6u9Q
vuL56K1qxOaDjYEcvEdGH5bhfOz_A86s3i3s2vRfX.zevTmAHSAwigyDnXrn
&nbs p;mP19BFWl.Ze5zsFTwsqFSKVqvOQtx_yr7GHhD4bLsalm7stfTPKFF_Th5bl8
u8opt2J3VvI5B.DW8PdW9UufWWwa62Q7zDy9NsXB_jFxoF3XfjrcroJ8QbZP
vBFRm65rDRqOItYagjcysx5gyTtNayN01RYm_y_OuTTALEYALuAzvHmi_orG
Qv5uHioNA0CQuScUCsP_PWJw.nqw1oozWVg.M1QNJmxOfgEGPkpACfEu8iYZ
5dw98B.Uphjl4nXFND_urlgXGjUJtq8JnvdHLdX26f0e
X-Originating-IP: [67.225.143.155]
Authentication-Results: mta1022.mail.ird.yahoo.com from=taggedmail.com; domainkeys=neutral (no sig); from=taggedmail.com; dkim=neutral (no sig)
Received: from 127.0.0.1 (HELO colo4.kaakateeya.com) (67.225.143.155)
by mta1022.mail.ird.yahoo.com with SMTP; Sat, 17 Mar 2012 18:28:50 +0000
Date: Sat, 17 Mar 2012 14:11:00 -0700 (PDT)
From: Tagged<Tagged@taggedmail.com>
To: [REMOVED]
Subject: Senga D sent you a message...
MIME-Version: 1.0
List-Unsubscribe: <http://www.tagged.com/no_more.html?unsem=[REMOVED]
Sender: TaggedTagged@taggedmail.com
Content-Type: text/html; charset="utf-8"
X-Log-Id: 8073775313
Content-Transfer-Encoding: 7bit
Message-ID: <5.23.851.7265.0FCF410F036E793.3@sf-mta-643.taggedmail.com>
Content-Length: 3998


You'd have thought they'd have realised, if you want to bypass a spam filter, the last thing you do is impersonate a company known for spamming - they're already likely to be on everyones favourite blacklist/spam filter.

So what of the link? Well, the link in this case, points to;

URL: sks.yyu.edu.tr/dimensioning.html
IP: 193.255.143.50
IP PTR: yapi.yyu.edu.tr
ASN: 8517 193.255.0.0/16 ULAKNET ULAKNET-ASN

Which uses window.location, to redirect you to;

Host: palliativecarebooks.com
IP: 208.79.81.198
IP PTR: xyw3.x.rootbsd.net
ASN: 13637 13647 208.79.80.0/22 Tranquil Hosting, Inc.



Once you've decided what you want, the checkout then takes you to;

Host: onlinerxbilling.com
IP: 74.86.44.57
IP PTR: 74.86.44.57-static.reverse.softlayer.com
ASN: 36351 74.86.0.0/16 SOFTLAYER - SoftLayer Technologies Inc.



With the SSL cert provided by RapidSSL as of January 4th;



In case you're wondering, 208.79.81.198 also houses;

galaxycialistab.mobi
palliativecarebooks.com
xyw3.x.rootbsd.net
onlinemedicinemedic.ru
ns1.onlinemedicinemedic.ru
ns2.onlinemedicinemedic.ru
mail.onlinemedicinemedic.ru
bho2000.oilrk.ru
budda510.oilrk.ru
bill5150.oilrk.ru
blau5150.oilrk.ru
alfi0.oilrk.ru
bip2001.oilrk.ru
bmarcus001.oilrk.ru
carle01.oilrk.ru
apark01.oilrk.ru
bbeck11.oilrk.ru
amacgregor11.oilrk.ru
dolphi2721.oilrk.ru
dhhc21.oilrk.ru
deuce21.oilrk.ru
djali21.oilrk.ru
dboone1.oilrk.ru
chrismoore1.oilrk.ru
brettg1.oilrk.ru
asaiah1.oilrk.ru
aci1.oilrk.ru
jesmel1.oilrk.ru
dbowen1.oilrk.ru
calvinmiller1.oilrk.ru
chrishowes1.oilrk.ru
clrocks1.oilrk.ru
ns1.oilrk.ru
dcmgmt1.oilrk.ru
aconnolly1.oilrk.ru
bkane012.oilrk.ru
badcad42.oilrk.ru
blackwatch42.oilrk.ru
dwk72.oilrk.ru
ns2.oilrk.ru
dunn13.oilrk.ru
don13.oilrk.ru
c1023.oilrk.ru
davida4353.oilrk.ru
carla5263.oilrk.ru
bhs65.oilrk.ru
bam206.oilrk.ru
depage007.oilrk.ru
barrybragg007.oilrk.ru
bjoerne7.oilrk.ru
dcusack009.oilrk.ru
cherb49.oilrk.ru
bigred359.oilrk.ru
detroitlionsfan1989.oilrk.ru
andymac99.oilrk.ru
benner99.oilrk.ru
abuda.oilrk.ru
alenmila.oilrk.ru
capazasa.oilrk.ru
ckobsa.oilrk.ru
dotsb.oilrk.ru
bennietb.oilrk.ru
aghazariandd.oilrk.ru
xcsdd.oilrk.ru
balloud.oilrk.ru
fvubyd.oilrk.ru
rsmeade.oilrk.ru
archmage.oilrk.ru
bhf-garage.oilrk.ru
abbake.oilrk.ru
benofmooresville.oilrk.ru
anniesunshine.oilrk.ru
allstretchlimousine.oilrk.ru
avolpe.oilrk.ru
blairhouse.oilrk.ru
dougpete.oilrk.ru
driaf.oilrk.ru
chaydogg.oilrk.ru
cmberg.oilrk.ru
alexenberg.oilrk.ru
bertholdkrug.oilrk.ru
cibertech.oilrk.ru
driosh.oilrk.ru
adamjsmith.oilrk.ru
alupnorth.oilrk.ru
davesdj.oilrk.ru
darrinj.oilrk.ru
balok.oilrk.ru
bartlettelectrical.oilrk.ru
ahal.oilrk.ru
agusital.oilrk.ru
docparcel.oilrk.ru
dbaseball.oilrk.ru
btram.oilrk.ru
daydoom.oilrk.ru
bsilverm.oilrk.ru
chsm.oilrk.ru
billidrum.oilrk.ru
bobrieckelman.oilrk.ru
mrhappyheadn.oilrk.ru
asilken.oilrk.ru
bfranzen.oilrk.ru
chrissgriffin.oilrk.ru
cerdmann.oilrk.ru
debusmann.oilrk.ru
bertswanson.oilrk.ru
dennis.robinson.oilrk.ru
dodioflo.oilrk.ru
ddgroto.oilrk.ru
bimber.oilrk.ru
cheezyrider.oilrk.ru
ben_inker.oilrk.ru
jackfulmer.oilrk.ru
chplummer.oilrk.ru
bradayer.oilrk.ru
bsdias.oilrk.ru
bholmes.oilrk.ru
dvdjones.oilrk.ru
chaynes.oilrk.ru
btiefs.oilrk.ru
asulkis.oilrk.ru
anns.oilrk.ru
ceturns.oilrk.ru
atsanders.oilrk.ru
aftermidnight.oilrk.ru
mrsbanksgunit.oilrk.ru
bart.oilrk.ru
anttolbert.oilrk.ru
airblast.oilrk.ru
ashertt.oilrk.ru
bvgut.oilrk.ru
b.simoneau.oilrk.ru
cboudreau.oilrk.ru
blkarrow.oilrk.ru
broux.oilrk.ru
brandy.oilrk.ru
adrianbradley.oilrk.ru
brianmcnasty.oilrk.ru
www10s3mr6.gnmkl.ru
wwwces35c7.gnmkl.ru
www040mjc4b.gnmkl.ru
wwwy3uiywue.gnmkl.ru
wwwndqf.gnmkl.ru
wwwmflt.gnmkl.ru
www26eqnu.gnmkl.ru
tabletrxnutrition.ru
ns1.tabletrxnutrition.ru
ns2.tabletrxnutrition.ru
fitnesspharmacytabs.ru
ns1.fitnesspharmacytabs.ru
ns2.fitnesspharmacytabs.ru
mail.fitnesspharmacytabs.ru
www.fitnesspharmacytabs.ru
onlinemedspills.ru
ns1.onlinemedspills.ru
ns2.onlinemedspills.ru
medtechspillstablets.ru
ns1.medtechspillstablets.ru
ns2.medtechspillstablets.ru
medicinetorepillsrx.ru
ns1.medicinetorepillsrx.ru
ns2.medicinetorepillsrx.ru
drugcutpillsrx.ru
ns1.drugcutpillsrx.ru
ns2.drugcutpillsrx.ru
drugstoremedspharmacy.ru
ns1.drugstoremedspharmacy.ru
ns2.drugstoremedspharmacy.ru
drugstoredrugspharmacy.ru
ns1.drugstoredrugspharmacy.ru
ns2.drugstoredrugspharmacy.ru
bestpillspharmacy.ru
ns1.bestpillspharmacy.ru
ns2.bestpillspharmacy.ru


References

Microsoft, Google, Facebook, Tagged et al - they never learn
http://hphosts.blogspot.co.uk/2010/04/microsoft-google-facebook-tagged-et-al.html

Tagged.com pays $750,000 over deceptive emails
http://www.theregister.co.uk/2009/11/10/new_york_ag_fines_tagged/

Tagged spam - with a difference
http://hphosts.blogspot.co.uk/2009/10/tagged-spam-with-difference.html

Dear Tagged .... weren't you already being sued for this?
http://hphosts.blogspot.co.uk/2009/07/dear-tagged-werent-you-already-being.html

Tagged.com being sued - and about bloody time too!
http://hphosts.blogspot.co.uk/2009/07/taggedcom-being-sued-and-about-bloody.html

Saturday, 10 March 2012

Outlook Export and hpHosts

For those that haven't yet noticed, and use it, I published an Outlook Export update yesterday. Nothing special, just a couple bug fixes.

http://support.it-mate.co.uk/?mode=Products&p=outlookexport

Would of course, be preferable to have the functionality of Outlook Export, built straight into Outlook itself, but it seems Microsoft aren't going to do that (would save the users alot of time, as they'd not need a third party program to do it).

You'll also no doubt be wondering, there's to be an hpHosts update next weekend (would have been sooner, but I'm away at present (saw Billy Connolly in Bournemouth yesterday)). In the meantime, you can of course, use the hpHosts Partial update, to stay updated (best used in conjunction with Hostsman (abelhadigital.com))