Re: IP not found ... discarding as fake
"Mike Easter" <[email protected]> Sun, 14 May 2006 09:04:57 -0700
| Newsgroups | gmane.mail.spam.spamcop.user,gmane.spam.detected |
|---|---|
| Organization | SpamCop |
| Message-ID | <[email protected]> |
Jeffery Jones wrote: www.spamcop.net/sc?id=z943514725ze5e5cb3156cbeedf6ef0870049ff803cz > IP not found ... akbvci.salaryquilt.net discarding as fake: I'm > seeing this fairly often - it resolves fine here. I'm assuming that > the spammers just block Spamcop's nameservers. It is a complicated subject, or at least it is when I answer :-) When you can resolve, but the parser doesn't on a spamvertiser url -- sometimes the parser *can* resolve but 'chooses' not to. Sometimes the parser can't resolve -- either because of being blocked or because the url has shoddy namesservice. If you want, you can 'play with it' by asking the parser to try to resolve the naked url, not in a spam. If the parser does that, then you also get a SC recommended address. Using this example: In your tracker: Cannot resolve http://akbvci.salaryquilt.net/?35227582 Naked url: Cannot resolve http://akbvci.salaryquilt.net/?35227582 No valid email addresses found, sorry! When the parser still can't do it, you can do it yourself and you can also 'test' the dns timing of the name resolution at DNSStuff. Average of all 4 nameservers: 617ms (plus 484ms overhead). Score: F <with lengthy explanation and details of lookup starting at the root servers> > Is there an easy way to get the abuse reporting address from the IP > after I look it up? Yes. It depends on which tools you are using. dns akbvci.salaryquilt.net 218.24.148.105 Then you lookup the IP in the appropriate RIR whois which in this case is apnic whois -h whois.apnic.net 218.24.148.105 ... inetnum: 218.24.0.0 - 218.25.255.255 descr: CNCGROUP Liaoning admin-c: CH455-AP = [email protected] tech-c: GZ84-AP = [email protected] You can also put the naked IP into the parser and get SC's opinion, which will also tell you SC's experience with the addresses Parsing input: 218.24.148.105 host 218.24.148.105 (getting name) no name Routing details for 218.24.148.105 [refresh/show] Cached whois for 218.24.148.105 : [email protected] [email protected] Using abuse net on [email protected] abuse net cnc-noc.net = [email protected], [email protected] Using abuse net on [email protected] abuse net online.ln.cn = [email protected], [email protected], [email protected] Using best contacts [email protected] [email protected] [email protected] [email protected] [email protected] bounces (1 sent : 105 bounces) Using postmaster#[email protected] for statistical tracking. [email protected] bounces (6 sent : 6 bounces) Using postmaster#[email protected] for statistical tracking. [email protected] bounces (1 sent : 99 bounces) Using abuse#[email protected] for statistical tracking. Reporting addresses: [email protected] You can also evaluate the IP for unresponsiveness about it being listed in spamhaus or spews 218.24.148.105/32 is listed on the Spamhaus Block List 218.24.148.105/32 is listed on the Register Of Known Spam Operations (ROKSO) database as being assigned to, under the control of, or providing service to a known professional spam operation run by Yambo Financials. > Could Spamcop use some sort of distributed network of resolvers to > make this harder to block? IMO SC should handle the problem and the management of spamvertisers completely differently than its current strategy. I'll go into that in another post. > Sort of a reverse Blue Frog - volunteers > could download a remote resolver utility that Spamcop could call on > as a secondary resource in resolving otherwise blocked names - then > cache them. IMO the notification business for spamvertisers is a useless waste of time for a variety of reasons. And, besides, SC notification and discovery of the spamvertisers has no real teeth. All SC should be doing is giving the spamvertised sites to sc-surbl and do no notifying or resolving. -- Mike Easter kibitzer, not SC admin