Re: IP not found ... discarding as fake

"Mike Easter" <[email protected]> Sun, 14 May 2006 09:04:57 -0700
Newsgroups gmane.mail.spam.spamcop.user,gmane.spam.detected
Organization SpamCop
Message-ID <[email protected]>
Jeffery Jones wrote:
www.spamcop.net/sc?id=z943514725ze5e5cb3156cbeedf6ef0870049ff803cz

> IP not found ... akbvci.salaryquilt.net discarding as fake:   I'm
> seeing this fairly often - it resolves fine here.   I'm assuming that
> the spammers just block Spamcop's nameservers.

It is a complicated subject, or at least it is when I answer :-)

When you can resolve, but the parser doesn't on a spamvertiser url -- 
sometimes the parser *can* resolve but 'chooses' not to.  Sometimes the
parser can't resolve -- either because of being blocked or because the
url has shoddy namesservice.

If you want, you can 'play with it' by asking the parser to try to
resolve the naked url, not in a spam.  If the parser does that, then you
also get a SC recommended address.

Using this example:

In your tracker:
Cannot resolve http://akbvci.salaryquilt.net/?35227582

Naked url:
Cannot resolve http://akbvci.salaryquilt.net/?35227582
No valid email addresses found, sorry!

When the parser still can't do it, you can do it yourself and you can
also 'test' the dns timing of the name resolution at DNSStuff.

Average of all 4 nameservers: 617ms (plus 484ms overhead).
Score: F
<with lengthy explanation and details of lookup starting at the root
servers>

>   Is there an easy way to get the abuse reporting address from the IP
> after I look it up?

Yes.  It depends on which tools you are using.

dns akbvci.salaryquilt.net  218.24.148.105

Then you lookup the IP in the appropriate RIR whois which in this case
is apnic

whois -h whois.apnic.net 218.24.148.105 ...
inetnum:      218.24.0.0 - 218.25.255.255
descr:        CNCGROUP Liaoning
admin-c:      CH455-AP  =  [email protected]
tech-c:       GZ84-AP = [email protected]

You can also put the naked IP into the parser and get SC's opinion,
which will also tell you SC's experience with the addresses

Parsing input: 218.24.148.105
host 218.24.148.105 (getting name) no name
Routing details for 218.24.148.105
[refresh/show] Cached whois for 218.24.148.105 : [email protected]
[email protected]
Using abuse net on [email protected]
abuse net cnc-noc.net = [email protected], [email protected]
Using abuse net on [email protected]
abuse net online.ln.cn = [email protected], [email protected],
[email protected]
Using best contacts [email protected] [email protected]
[email protected] [email protected]
[email protected] bounces (1 sent : 105 bounces)

Using postmaster#[email protected] for statistical
tracking.
[email protected] bounces (6 sent : 6 bounces)

Using postmaster#[email protected] for statistical
tracking.
[email protected] bounces (1 sent : 99 bounces)

Using abuse#[email protected] for statistical tracking.

Reporting addresses:
[email protected]

You can also evaluate the IP for unresponsiveness about it being listed
in spamhaus or spews

218.24.148.105/32 is listed on the Spamhaus Block List

218.24.148.105/32 is listed on the Register Of Known Spam Operations
(ROKSO) database as being assigned to, under the control of, or
providing service to a known professional spam operation run by Yambo
Financials.

>   Could Spamcop use some sort of distributed network of resolvers to
> make this harder to block?

IMO SC should handle the problem and the management of spamvertisers
completely differently than its current strategy.  I'll go into that in
another post.

>  Sort of a reverse Blue Frog - volunteers
> could download a remote resolver utility that Spamcop could call on
> as a secondary resource in resolving otherwise blocked names - then
> cache them.

IMO the notification business for spamvertisers is a useless waste of
time for a variety of reasons.  And, besides, SC notification and
discovery of the spamvertisers has no real teeth.  All SC should be
doing is giving the spamvertised sites to sc-surbl and do no notifying
or resolving.

-- 
Mike Easter
kibitzer, not SC admin