ollioe Posted October 1, 2013 Posted October 1, 2013 Hi Communitiy, we are receiving very, very much spam from one "Organisation". As they use Chinanet to host the spamvertised sites I was wondering if the Hostmaster is not able to get his network controlled. I wrote to the official mailadress as listed in the report Same adress is used by Spamcop. Okay, we have send tons of abuse mails with Spamcop and now I have to see that the mailbox is full, the mailserver did respond with Quota... Is there any way to get in contact or is this the sign that the hoster and ISP does not care about spam? Why does Spamcop not recognize the response from the mailserver? I think I could stop sending abuse reports as they are not received.
turetzsr Posted October 1, 2013 Posted October 1, 2013 Hi, ollioe, ...For this, you may need direct SpamCop support. Please send a brief note about your issue to deputies[at]admin.spamcop.net. ...Good luck.
SpamCopAdmin Posted October 1, 2013 Posted October 1, 2013 It looks like they are mostly getting our reports. We have sent them 1,514,402 reports and 32,173 have bounced. - Don D'Minion - SpamCop Admin - - Service[at]Admin.SpamCop.net -
ollioe Posted October 2, 2013 Author Posted October 2, 2013 It looks like they are mostly getting our reports. I agree for the past. Since days the Mailbox for Chinanet is full. Checked again this morning, same time as yesterday, 07:30 MET (+2). äº²çˆ±çš„ç”¨æˆ·ï¼Œæ‚¨çš„é‚®ä»¶ç”±äºŽä»¥ä¸‹åŽŸå› æ— æ³•é€è¾¾ä»¥ä¸‹åœ°å€, <gzipdz[at]public.gz.cn>: 收信人邮箱空间ä¸è¶³ã€‚ The user's space has been used up. I even checked the abused sites, all are online and healthy and spamvertised. Wil check again serveral times today but I think they did stop to act against the Spammer Organisation, this group creates tons of sites every week. On a normal day we have ~500 spam Mails only for this "Health Service"
petzl Posted October 2, 2013 Posted October 2, 2013 Hi Communitiy, we are receiving very, very much spam from one "Organisation". As they use Chinanet to host the spamvertised sites I was wondering if the Hostmaster is not able to get his network controlled. I wrote to the official mailadress as listed in the report Same adress is used by Spamcop. Okay, we have send tons of abuse mails with Spamcop and now I have to see that the mailbox is full, the mailserver did respond with Quota... Is there any way to get in contact or is this the sign that the hoster and ISP does not care about spam? Why does Spamcop not recognize the response from the mailserver? I think I could stop sending abuse reports as they are not received. Don't know if they will bother listning but looked around and came up with this 21483925[at]qq.com from google translation http://tinyurl.com/owfhnsd Don't forget to thank them for invites to Falun Dafa but you do not wish to get their messages even though your company openly supports freedom and democracy (sarcasm China has the death penalty for those in China doing this)
ollioe Posted October 2, 2013 Author Posted October 2, 2013 Checked the CN mailbox several time, it still is: full
petzl Posted October 2, 2013 Posted October 2, 2013 Checked the CN mailbox several time, it still is: full The whole IP range seems run by Botnets Run by "public servants" who don't give a toss http://www.spamhaus.org/sbl/query/SBL189726 The threat of a death penalty might make them reconsider
ollioe Posted October 2, 2013 Author Posted October 2, 2013 Now I got it: chinanet-gz is providing services to spammers and botnet operators since years and ignoring all abuse complaints sent by Spamhaus and 3rd parties It does not fit to: It looks like they are mostly getting our reports but nobody is able to know every "Service" Nice to know that I could save the time to report CNNET. Next step: Blacklist on our GFI to /dev/null
petzl Posted October 3, 2013 Posted October 3, 2013 Now I got it: It does not fit to: but nobody is able to know every "Service" Nice to know that I could save the time to report CNNET. Next step: Blacklist on our GFI to /dev/null One never knows who SpamCops "interested parties" are http://krebsonsecurity.com/2013/10/feds-ta...ged-mastermind/
ollioe Posted October 4, 2013 Author Posted October 4, 2013 It is very frustrating that fighting spam is useless. No law does help us fighting spam, every country hosts spamvertised sites and just no one is willing to take down the Black Hats. It's just easy to ignore abuse reports or to shut down the abuse mailbox. The answer from Spamcop Admin does show the situation. He thinks that there are only a few reports did bounce but in real CN is not interested to block spammers. And yes, the abuse mailbox of CN still is full. Only 3 hours per day are needed to clean the GFI Filters and catched mails to recognize the real ones...
turetzsr Posted October 4, 2013 Posted October 4, 2013 It is very frustrating that fighting spam is useless. <snip> ...Direct attempts by us "little people" to fight spam are, indeed, doomed to fail. War, famine, inequity, crime and death all have existed for far longer and one can be equally frustrated by one's inability to do anything about them ... but life's far too short! At least with spam we have tools like SpamCop to help us by finding the right place to send spam reports, helpful for the otherwise ignorant "white hats" and provides the blacklist so that e-mail admins can lessen the impact on their customers.
ollioe Posted October 11, 2013 Author Posted October 11, 2013 Just for the memories: The mailbox still is full. I'm wondering that it's allowed and without any consequences to have no reachable mailbox, registered at apnic. Just used anti-spam[at]ns.chinanet.cn.net and will see what will happen
Farelf Posted October 11, 2013 Posted October 11, 2013 Thanks ollioe - your updates are appreciated. APNIC has a very limited"abuse of process" role if I recall their website/FAQs correctly. At least when members initiate SC reports they contribute to the SCbl statistics and possible IP address listing when the abuse becomes excessive, regardless of ISP and APNIC inattention.
ollioe Posted October 16, 2013 Author Posted October 16, 2013 Good morning, after one day not in the office the madness is growing. Surely, gzipdz[at]public.gz.cn still is bouncing with mailbox full. So I started to collect responsibles and wrote an very large email with many details to everybody that may have a chance to act on this violation. There are more and more ROKSO using Chinanet, as there is no chance to report an abuse. The last good known adress to interact with Chinanet was: hostmaster[at]ns.chinanet.cn.net If somebody may wonder, here is the reply: hostmaster[at]ns.chinanet.cn.net mirapoint #<mirapoint #4.4.7 smtp; 450 4.2.2 Mailbox full (user.hostmaster)> #SMTP# This is the worst case I've ever seen (yes there are a few one but not with such a charge). A hoster ignoring everything. I don't see any chance to stop Chinanet nor the Organisations using this Black Hat. I'll try to fire up to the embassy to get in contact with any responsible person in the China government. The amount of spamvertised sites is growing every hour. Spamcop does not recognize the bouncing mails, this is even very strange.
ollioe Posted November 7, 2013 Author Posted November 7, 2013 After complaining the case to IC3, 14 days ago, the trouble stopped. We're no longer subject of this ROKSO. Any other action failed, nobody in China is responsible or interested to stop crime over Internet. Case is solved
Recommended Posts
Archived
This topic is now archived and is closed to further replies.