Sign in to follow this  
Followers 0
ollioe

ISP Mailbox full

15 posts in this topic

Hi Communitiy,

we are receiving very, very much spam from one "Organisation". As they use Chinanet to host the spamvertised sites I was wondering if the Hostmaster is not able to get his network controlled.

I wrote to the official mailadress as listed in the report

Same adress is used by Spamcop.

Okay, we have send tons of abuse mails with Spamcop and now I have to see that the mailbox is full, the mailserver did respond with Quota...

Is there any way to get in contact or is this the sign that the hoster and ISP does not care about spam?

Why does Spamcop not recognize the response from the mailserver?

I think I could stop sending abuse reports as they are not received.

Share this post


Link to post
Share on other sites

Hi, ollioe,

...For this, you may need direct SpamCop support. Please send a brief note about your issue to deputies[at]admin.spamcop.net.

...Good luck.

Share this post


Link to post
Share on other sites

It looks like they are mostly getting our reports.

We have sent them 1,514,402 reports and 32,173 have bounced.

- Don D'Minion - SpamCop Admin -

- Service[at]Admin.SpamCop.net -

Share this post


Link to post
Share on other sites

It looks like they are mostly getting our reports.

I agree for the past. Since days the Mailbox for Chinanet is full.

Checked again this morning, same time as yesterday, 07:30 MET (+2).

亲爱的用户,您的邮件由于以下原因无法é€è¾¾ä»¥ä¸‹åœ°å€,

<gzipdz[at]public.gz.cn>:

收信人邮箱空间ä¸è¶³ã€‚ The user's space has been used up.

I even checked the abused sites, all are online and healthy and spamvertised.

Wil check again serveral times today but I think they did stop to act against the Spammer Organisation, this group creates tons of sites every week. On a normal day we have ~500 spam Mails only for this "Health Service"

Share this post


Link to post
Share on other sites

Hi Communitiy,

we are receiving very, very much spam from one "Organisation". As they use Chinanet to host the spamvertised sites I was wondering if the Hostmaster is not able to get his network controlled.

I wrote to the official mailadress as listed in the report

Same adress is used by Spamcop.

Okay, we have send tons of abuse mails with Spamcop and now I have to see that the mailbox is full, the mailserver did respond with Quota...

Is there any way to get in contact or is this the sign that the hoster and ISP does not care about spam?

Why does Spamcop not recognize the response from the mailserver?

I think I could stop sending abuse reports as they are not received.

Don't know if they will bother listning but looked around and came up with this

21483925[at]qq.com

from google translation

http://tinyurl.com/owfhnsd

Don't forget to thank them for invites to Falun Dafa but you do not wish to get their messages even though your company openly supports freedom and democracy (sarcasm China has the death penalty for those in China doing this)

Share this post


Link to post
Share on other sites

Checked the CN mailbox several time, it still is: full

The whole IP range seems run by Botnets

Run by "public servants" who don't give a toss

http://www.spamhaus.org/sbl/query/SBL189726

The threat of a death penalty might make them reconsider

Share this post


Link to post
Share on other sites

Now I got it:

chinanet-gz is providing services to spammers and botnet operators since years and ignoring all abuse complaints sent by Spamhaus and 3rd parties

It does not fit to:

It looks like they are mostly getting our reports

but nobody is able to know every "Service"

Nice to know that I could save the time to report CNNET.

Next step: Blacklist on our GFI to /dev/null

Share this post


Link to post
Share on other sites

Now I got it:

It does not fit to:

but nobody is able to know every "Service"

Nice to know that I could save the time to report CNNET.

Next step: Blacklist on our GFI to /dev/null

One never knows who SpamCops "interested parties" are

http://krebsonsecurity.com/2013/10/feds-ta...ged-mastermind/

Share this post


Link to post
Share on other sites

It is very frustrating that fighting spam is useless.

No law does help us fighting spam, every country hosts spamvertised sites and just no one is willing to take down the Black Hats. It's just easy to ignore abuse reports or to shut down the abuse mailbox.

The answer from Spamcop Admin does show the situation. He thinks that there are only a few reports did bounce but in real CN is not interested to block spammers.

And yes, the abuse mailbox of CN still is full.

Only 3 hours per day are needed to clean the GFI Filters and catched mails to recognize the real ones...

Share this post


Link to post
Share on other sites
It is very frustrating that fighting spam is useless.

<snip>

...Direct attempts by us "little people" to fight spam are, indeed, doomed to fail. War, famine, inequity, crime and death all have existed for far longer and one can be equally frustrated by one's inability to do anything about them ... but life's far too short! At least with spam we have tools like SpamCop to help us by finding the right place to send spam reports, helpful for the otherwise ignorant "white hats" and provides the blacklist so that e-mail admins can lessen the impact on their customers.

Share this post


Link to post
Share on other sites

Just for the memories: The mailbox still is full.

I'm wondering that it's allowed and without any consequences to have no reachable mailbox, registered at apnic.

Just used anti-spam[at]ns.chinanet.cn.net and will see what will happen

Share this post


Link to post
Share on other sites

Thanks ollioe - your updates are appreciated. APNIC has a very limited"abuse of process" role if I recall their website/FAQs correctly. At least when members initiate SC reports they contribute to the SCbl statistics and possible IP address listing when the abuse becomes excessive, regardless of ISP and APNIC inattention.

Share this post


Link to post
Share on other sites

Good morning,

after one day not in the office the madness is growing.

Surely, gzipdz[at]public.gz.cn still is bouncing with mailbox full. So I started to collect responsibles and wrote an very large email with many details to everybody that may have a chance to act on this violation.

There are more and more ROKSO using Chinanet, as there is no chance to report an abuse. The last good known adress to interact with Chinanet was: hostmaster[at]ns.chinanet.cn.net

If somebody may wonder, here is the reply:

hostmaster[at]ns.chinanet.cn.net

mirapoint #<mirapoint #4.4.7 smtp; 450 4.2.2 Mailbox full (user.hostmaster)> #SMTP#

This is the worst case I've ever seen (yes there are a few one but not with such a charge). A hoster ignoring everything. I don't see any chance to stop Chinanet nor the Organisations using this Black Hat.

I'll try to fire up to the embassy to get in contact with any responsible person in the China government. The amount of spamvertised sites is growing every hour.

Spamcop does not recognize the bouncing mails, this is even very strange.

Share this post


Link to post
Share on other sites

After complaining the case to IC3, 14 days ago, the trouble stopped. We're no longer subject of this ROKSO.

Any other action failed, nobody in China is responsible or interested to stop crime over Internet.

Case is solved

Share this post


Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!


Register a new account

Sign in

Already have an account? Sign in here.


Sign In Now
Sign in to follow this  
Followers 0