Google Groups no longer supports new Usenet posts or subscriptions. Historical content remains viewable.
Dismiss

our /20 is listed at ASPEWS. Scumbags were terminated but we're still listed.

1 view
Skip to first unread message

Eric D.

unread,
Oct 27, 2008, 1:13:34 AM10/27/08
to

I know it's ASPEWS list, their rules and I respect that. I also understand why
we are listed their. We had a customer who resold our servers to spammers. We
gave our customer way more time than we should have and learned the hard way
never to do that again as 8 months later we're still picking up the pieces.

Our entire /20 is listed at ASPEWS : http://www.aspews.org/?ip=67.210.224.0

The customer has been gone for at least 6 months now and our abuse desk is very
quiet, but we remain listed at ASPEWS. Certainly this is not a complaint as I
know why we were listed and rightfully so. I had some pointed discussions with
administration about this and we're all very sorry that we didn't take action
sooner.

Both our company and our Globalcon.net brand has a very strict TOS after the
mess we are in:

http://www.gipnetworks.com/tos.php
http://www.globalcon.net/tos.php


Is there anything else we can do to help expedite the de-listing at ASPEWS or do
we just have to wait it out?

Thanks,

Eric

--
Comments posted to news.admin.net-abuse.blocklisting
are solely the responsibility of their author. Please
read the news.admin.net-abuse.blocklisting FAQ at
http://www.blocklisting.com/faq.html before posting.

Stephen Satchell

unread,
Oct 27, 2008, 9:21:21 AM10/27/08
to
Eric D. wrote:
> I know it's ASPEWS list, their rules and I respect that. I also understand why
> we are listed their. We had a customer who resold our servers to spammers. We
> gave our customer way more time than we should have and learned the hard way
> never to do that again as 8 months later we're still picking up the pieces.

Would you identify the customer, and the domain names that customer used
to send his/her/its spam? Have the domain names been purged from your
DNS servers? Looking at your record, it could be that you haven't
completed the back end of the clean-up process:

"January 12, 2008 Get Rich Quick, Rewards, General Insurance,
Mortgage/Debt, Life Insurance Spam, Opt-Out, Spammer, Spam Support,
Harvesting Spammers

"Expanding the /24 rDNS scan all the way to a /20 shows lots of IPs with
ipn and mxn hostnames with lots of nonsense domains.

"Trapping spew for a short time confirmed the suspicions.

"So, lots and lots of spammers."

> Our entire /20 is listed at ASPEWS : http://www.aspews.org/?ip=67.210.224.0
>
> The customer has been gone for at least 6 months now and our abuse desk is very
> quiet, but we remain listed at ASPEWS. Certainly this is not a complaint as I
> know why we were listed and rightfully so. I had some pointed discussions with
> administration about this and we're all very sorry that we didn't take action
> sooner.

Have you checked your other customers to see if someone isn't continuing
the process? Have you checked for compromised Web CGI that is still
letting spammers use your IP space for their spews? Have you shut down
direct use of port 25/TCP outbound, requiring your customers to use a
mail gateway *you* operate to send messages? (This latter gives you
access to the outgoing mail stream, so that you can look for problems
far more easily. Many people involved with spam control recommend this
practice. Your customers can still send mail with their own domain
name, but the mail flows out through YOUR servers.)

> Both our company and our Globalcon.net brand has a very strict TOS after the
> mess we are in:
>
> http://www.gipnetworks.com/tos.php
> http://www.globalcon.net/tos.php
>
>
> Is there anything else we can do to help expedite the de-listing at ASPEWS or do
> we just have to wait it out?

You may want to check to see if your IP range is listed with any other
blocking lists, and get those listings taken care of. And it may not be
e-mail that is the problem. Web service and DNS service could be where
you are tripping the breakers at ASPEWS. From the FAQ:

> Q5: Why are network addresses listed if no spam has originated from them?
>
> A5: They are listed because they have been set up by known spammers and spam support operations, most with a demonstrable repeated history of spamming or spamming services. They are also listed if they host websites advertised in spam, as this too falls under spamming services - these listings normally occur if the owners of that network address range do not remove the offenders.

It's a pain, I know. I used to run an abuse desk myself, so I
understand just how deep the rot can go if unchecked. My first task on
the abuse desk of a Web hosting company was to remove a /24 listing from
the infamous SPEWS system. I succeeded, but it took work to cross all
the i's and dot all the t's to do it -- and terminate service to the
customer who was using a dedicated server for spammer DNS.

To find out if someone is abusing you for spammer DNS service, sniff
your edge router(s) for outbound DNS responses. Look particularly for
high rates of answers for a particular domain name or IP address with a
short TTL -- that's spammer sign right there, as a spam run may cause a
number of bounce attempts from cluelessly-administered mail servers, or
a spam run that causes a huge number of hits.

The Best Practices recommended TTL for a regular domain name A or MX
record used in mail or Web service is 86400 seconds (one day), and NS
records is 864000 (10 days).

When I was DNS administrator, I would set a TTL of 14400 (ten hours) for
new accounts or change requests, then after a few days set it back up to
86400. That way, changes would propagate faster when an update was
made, but once the update was proved the TTL was raised to the standard.
If an update is pending, I would drop the TTL back down the day before
the update. (This was particularly fun when renumbering. Fortunately,
that was an infrequent occurrence, usually when we changed upstream
providers -- that was before we multi-homed using our own ASN and /21
allocation.)

Eric D.

unread,
Oct 29, 2008, 6:45:45 AM10/29/08
to

Just for clarification sake, Amerihosting were not the "Scumbags" I referred to
in the posting. Amerihosting was bought out while they were our customer. The
new owners of Amerihosting were very responsive to removing the SPAM problem and
terminated their inherited customer - Sonic Media.

Eric D.

unread,
Nov 1, 2008, 7:23:18 PM11/1/08
to

In a flurry of recycled electrons Stephen Satchell wrote:

> > Would you identify the customer, and the domain names that customer used
> > to send his/her/its spam?

Our direct customer was a company called "Amerihosting". At the time
Amerihosting was owned by an individual out of the Atlanta area.
Amerihosting at the time offered dedicated servers which were actually
Globalcon.net servers that Amerihosting was subletting our servers to their own
customers which is a common practice.


Every domain name related to this issue was registered to a company called
"Sonic Media". According to whois:

Sonic Media, LLC
211 South Street
Suite 353
Philadelphia, PA 19147

Which turns out to be a UPS store / MBE mail drop. Their e-mail address in
whois is in...@gamepipe.com which is still in operation but not on our network or
in our datacenter

oliasber.com
tttnitch.com
reevert.com
gpliner.com

Another indirect customer :

PThree
127 W. Fair banks Ave., 285
WinterPark, Florida 32789

antippontha.com
strabilikers.com


I do understand that Amerihosting is no longer owned by Raj and the new owners
appear to have cleaned up their act but Amerihosting is no longer our customer.


> > Have the domain names been purged from your
> > DNS servers? Looking at your record, it could be that you haven't
> > completed the back end of the clean-up process:

You are correct. There was some much needed PTR cleaning that I did this
afternoon which should already be visible. I cleaned up the ones I know are no
longer our customers and I'm working on a process to make sure we remove PTRs
when customers move on.

> > "Expanding the /24 rDNS scan all the way to a /20 shows lots of IPs with
> > ipn and mxn hostnames with lots of nonsense domains.

There are a few 'nonsense' domains left, but the IPs that are associated with
them are used for IRC and we have yet to receive anything related to those
servers through our abuse desk. The customer leasing them is reputable and is
associated with / works for a very well know IT company. We don't have a
specific policy on PTRs and he has valid A records for them and those IRC
servers have not violated our AUP/TOS.

There were quite a few nonsense domains from Sonic Media all of which have been
removed.


> > Have you checked your other customers to see if someone isn't continuing
> > the process? Have you checked for compromised Web CGI that is still
> > letting spammers use your IP space for their spews? Have you shut down
> > direct use of port 25/TCP outbound, requiring your customers to use a
> > mail gateway *you* operate to send messages? (This latter gives you
> > access to the outgoing mail stream, so that you can look for problems
> > far more easily. Many people involved with spam control recommend this
> > practice. Your customers can still send mail with their own domain
> > name, but the mail flows out through YOUR servers.)

The majority of Globalcon.net customers / IP space are leased servers and
colocation. We do keep very close tabs on the servers that Globalcon.net has
has authority over but those are a select few (less than a /24).

We currently rely on reports from spamcop and other reports to abuse@.

We've discussed several things to watch top talkers on 25 outbound using Netflow
and are open to suggestions. I've heard of some ISPs blocking 25/tcp outbound
but the cases I know of are usually residential ISPs that delegate IPS via DHCP
and the customers on those connections have no legitimate reason to operate an
outbound mail server.

What do service providers like 'The Planet', 'Rackspace', 'Steadfast', etc.. do?
Most of the Globalcon.net customers have a legitimate need to send outbound
e-mail and most would balk at having to relay mail through another SMTP server
which is why I ask what other providers do.


> >
> > You may want to check to see if your IP range is listed with any other
> > blocking lists, and get those listings taken care of. And it may not be
> > e-mail that is the problem. Web service and DNS service could be where
> > you are tripping the breakers at ASPEWS.

We were listed on several other lists and have been de-listed after talking with
them and explaining the situation.


Thanks for your help, I'm certainly not complaining as I know why we were
listed. I believe that everyone in our org has learned the headache and
frustration that it is taking to get de-listed was not worth the short term
results and that we follow our TOS / AUP without exception.

Stephen Satchell

unread,
Nov 2, 2008, 8:41:12 PM11/2/08
to
Eric D. wrote:

> What do service providers like 'The Planet', 'Rackspace', 'Steadfast', etc.. do?
> Most of the Globalcon.net customers have a legitimate need to send outbound
> e-mail and most would balk at having to relay mail through another SMTP server
> which is why I ask what other providers do.

I can only talk about what I did at a web hosting company. I worked to
make lemonade from the lemons. Details:

Step 1: offer a spam-filtering outbound mail server with lots and lots
of capacity. The sales pitch: spam can happen to anyone running a web
server -- the number of exploits is a very high (perhaps even unbounded)
number. Furthermore, large mail organizations like AOL can "451" your
mail to death when you have a spew, even a spew of legit mail. By
throttling the spew, one can avoid the constant 451 issue.

You, the customer, still use your server-resident mail server, but you
forward all outbound mail to the outbound mail server. That mail server
slows down outbound mail, by domain name, so you stand a much lower
chance of having your mail 451'ed to death.

Hey, it's what we use for our own shared-hosting Web servers. It works.

For new customers: it helps that our default loads for customer
dedicated servers specifies the throttling outbound mail relay in the
mail server. The customer (if he or she knew how) would have to take
*out* the configuration that does relay.

Step 2: for large-mail-volume customers, offer a dedicated throttling
mail server that works just like the central one. I had a couple of
real-estate MLS service that was a perfect fit for this -- in fact,
that's how my company got the business.

Step 3: publish a deadline for servers to do direct-to-25 mail service.
Encourage customers to use the pooled outbound mail server, or get a
dedicated one.

Step 4: publish a reminder of the deadline, and if you feel the need
offer a limited discount on dedicated throttling mail relay servers.

Step 5: update your edge router ACLs.

Make damn sure those throttling mail relay servers are *not* open relay.
They accept mail for relay only from your IP addresses. For dedicated
mail relay servers, they accept mail only from the associated leased
server or colo server IP addresses.

rey...@gipnetworks.com

unread,
Nov 3, 2008, 6:13:18 PM11/3/08
to

Hello,

In addition to Eric's post above, we also have terminated Amerihosting
altogether a while back due to their possible association to spammers.
We believe that as of now, all our IP address that is listed by ASPEWS
have been cleaned thoroughly. We have been working closely with other
authoritative and aggressive SPAM block list such as SORBS, Spamhaus
and Five Ten who have been so generous in pointing the spammers in our
67.210.224.0/20 block. As result, we terminated all known spammers
that were pointed to us and we have been de-listed from their lists
thereafter.

As of now, we filter new prospects very carefully to avoid potential
spammers. We no longer provide service to prospect that (we believe)
is related to bulk mailers regardless. We have learned our lesson to
do the necessary preventive action and stop spammers early on from
doing business with us.

As you requested, Eric also cleaned all the RDNS records that were
used by Amerihosting and other related spammers we terminated and we
would be glad to provide you list of customers and the type of
business that they do. Most of the IP address that caused this entire
67.210.224.0/20 block to be listed in ASPEWS have been assigned to
local companies with business related to health and financial
industries, so we'd certainly appreciate it if you can help us de-
listing the 67.210.224.0/20. We will do the extreme and will not
hesitate to terminate business with customers that would cause our IP
address to be listed in any DNSBL to protect our current customers.

If there is any further actions that ASPEWS requires us to do in order
for us to have 67.210.224.0/20 de-listed from ASPEWS, please don't
hesitate to let us know. We have carefully read and do the things
required by your policy and if you have found anything else that need
attention on our part, please don't hesitate to let us know.

Thank you.

0 new messages