Jump to content

gnarlymarley

Memberp
  • Posts

    839
  • Joined

  • Last visited

Posts posted by gnarlymarley

  1. Hmmm, seems there is a problem with the blocking list.  I dropped a note to deputies[at]admin[dot]spamcop[dot]net and I hope it goes through.

    C:\>dig 444.333.222.111.bl.spamcop.net any
    
    ; <<>> DiG 9.7.3 <<>> 444.333.222.111.bl.spamcop.net any
    ;; global options: +cmd
    ;; Got answer:
    ;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 37143
    ;; flags: qr rd ra; QUERY: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 0
    
    ;; QUESTION SECTION:
    ;444.333.222.111.bl.spamcop.net.        IN      ANY
    
    ;; ANSWER SECTION:
    444.333.222.111.bl.spamcop.net. 1493 IN A       91.195.240.87
    
    ;; Query time: 27 msec
    ;; SERVER: 192.168.16.1#53(192.168.16.1)
    ;; WHEN: Sun Jan 31 08:53:18 2021
    ;; MSG SIZE  rcvd: 64
    
    
    C:\>

    SpamCop always has returned an IP in the localhost range.  My fear is something may have been cached for a period of time and I hope this doesn't take a few days to resolve.

  2. You say that your IP is not listed on the blocking list.  There may have been some sort of DNS problem.  Try checking your IP using dig or nslookup to see if that could be the issue.

    C:\>dig 444.333.222.111.bl.spamcop.net
    
    ; <<>> DiG 9.7.3 <<>> 444.333.222.111.bl.spamcop.net
    ;; global options: +cmd
    ;; Got answer:
    ;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 63152
    ;; flags: qr rd ra; QUERY: 1, ANSWER: 1, AUTHORITY: 0, ADDITIONAL: 0
    
    ;; QUESTION SECTION:
    ;444.333.222.111.bl.spamcop.net.        IN      A
    
    ;; ANSWER SECTION:
    444.333.222.111.bl.spamcop.net. 1800 IN A       91.195.240.87
    
    ;; Query time: 195 msec
    ;; SERVER: 192.168.16.1#53(192.168.16.1)
    ;; WHEN: Sun Jan 31 08:48:11 2021
    ;; MSG SIZE  rcvd: 64
    
    
    C:\>

    yeah, the 444 is not a valid octet and spamcop is returning everything is on the blocking list.  You may want to send an email to deputies[at]admin[dot]spamcop[dot]net.

  3. I see different abused addresses on your list such as eonix, layerhost and heficed.

    104.140.0.0/16 net-admin@eonix.net
    104.140.84.0/23 net-admin@eonix.net
    104.148.28.0/24 abusenoc@layerhost.com
    104.206.117.32/27 net-admin@eonix.net
    104.206.96.0/22 net-admin@eonix.net
    104.223.153.0/24 abusenoc@layerhost.com
    170.130.0.0/16 net-admin@eonix.net
    191.101.128.0/21 abuse@heficed.com
    23.228.64.0/18 abusenoc@layerhost.com
    23.231.0.0/17 net-admin@eonix.net
    50.2.0.0/15 net-admin@eonix.net
    50.2.188.0/22 net-admin@eonix.net
    50.2.212.0/22 net-admin@eonix.net

  4. 6 hours ago, petzl said:

    50.31.49.42 listed in bl.spamcop.net (127.0.0.2)
     If there are no reports of ongoing objectionable email from this system it will be delisted automatically in approximately 20 hours.

    Yep, it is listed.

    10 hours ago, noisydaddy said:

    Any insight on how to solve this "blocked-but-not-listed" problem is much appreciated.

    I have also seen where some is using their own blocking list, but giving the message as coming from bl.spamcop.net which can be confusing.

    If there are no reports of ongoing objectionable email from this system it will be delisted automatically in approximately 19 hours.

    Must have had some spam go out as it appears to have restarted the counter about an hour after petzl posted.

  5. On 1/13/2021 at 11:53 AM, xebeche said:

    SpamCop forwards them to abuse@microsoft.com. Usually, after a few days I get a message from cdoccm@microsoft.com saying:

    Quote

    If these are replies to your reports, I see in my spamcop account preferences I have "Forward only replies from sentient people" under report handling selected.  I don't get very many replies from the reports that I send.  So far, I have no replies for anything I have sent to abuse@microsoft.com.

  6. On 1/16/2021 at 3:03 PM, ford78 said:

    Anyone knows how can I try to contact them? on gremli.ru web Page there's nothing available (an email, or a form, nothing)  to contact .

    Apparently, they don't have a contact directly, but they do have who added you to the list with a contact in the database file.  Per http://drbl.gremlin.ru/en.html, it appears, you need to download the .tar.gz file and it has a contact person inside it.

    On 11/7/2010 at 10:53 AM, Farelf said:

    The point is you need to interrogate the data to find out who added you to the bl and write to them, not gremlin, per the FAQ http://gremlin.ru/soft/drbl/en/faq.html#howtogetout.

    Currently at that  FAQ page, the link is under the software section at "'Download drbl.tar.gz".

    Delisting requests are accepted only from network administrators according to the whois information. If you aren't the network administrator, don't try to "jump over a head": the effect will be null or even negative.

    Because of too many issues with blacklists, I have moved to a scoring system instead of straight up blocking.  Meaning an IP would have to show up on more than one blacklist before I block the email.

  7. 10 hours ago, giamar2000 said:

    but no code is displayed.

    image

    I see something on mine.  Some have mentioned problems with chrome and other with firefox.

    blob.png.7b7de2b5224082b1d785fd73b8a54d62.png

    It would be nice if the links were corrected, but I think they were broken some time back in one of the "upgrades".

  8. 1 hour ago, bretmaverick999 said:

    So here's the thing, http://eonix.net/ displays a webpage that says the domain has expired (there's a link to renew it http://enom.help/renew-faq) so you can't even view Acceptable Use Policy webpage. 

    Yeah, the domain expired on 1/14.  Spammers like these domains since the registrars don't have a temporary SPF or DMARC record.  Effectively it gives the spammers free reign of the domain.

    1 hour ago, bretmaverick999 said:

    Yes, one possibility is to wade thru 200 spam emails a day and just "take it". But, there has to be some other avenue to persue - FCC? FBI? Any suggestions?  I did find that ARIN has a way to Report Whois Inaccuracy and I'll be using it to report that Eonix's contact info is invalid.

    If it is only an IP or two and you have the ability to block them, I would suggest you put a block on there for a few days.  One thing you can also do is to use a BGP looking glass and head to the upstream provider with your abuse logs.  The bigger ISPs are usually good at fixing the problem with the smaller customer ISPs.

  9. 7 hours ago, Raccoon said:

    As for the user with the most issues, The problem is that they possibly have a virus?  I believe their windows laptop stopped working so she started using a Mac. 

    The cause of listing section says that spam is being received by spamtraps and users coming from 208.180.40.71.

    Causes of listing
     System has sent mail to SpamCop spam traps in the past week (spam traps are secret, no reports or evidence are provided by SpamCop)
     SpamCop users have reported system as a source of spam less than 10 times in the past week

    I have seen where a virus, malware, spyware, or router can be remotely controlled and then the hacker uses the device to send spam.  If that is an open MTA, then anyone can connect and use it it to send spam.  I see the time is changing between 23 and 22 hours, so it would appear that the spam action is still going on.  According to the neighborhood section of https://www.spamcop.net/w3m?action=blcheck&ip=208.180.40.71, I do not see 208.180.40.68 listed.  It would appear to be almost all is from 208.180.40.71.  Securing that IP, and/or the router in front of it should help eliminate the spam that appears to be coming from it.

×
×
  • Create New...