[ Sorry for my poor english ]
These two domains have been the source of massive Usenet spam for
*months*, without any reply from their respective newsmasters.
Absolutely no action was taken to stop, or even limit the outgoing spam
from these two servers, despite several mail complaints.
The auna.com domain is notably used to send "dvd100.net" spam, and the
ono.com server used to promote "make money fast" schemes. Currently,
most spam is cancelled using cleaning bots, but this solution is not a
long-term solution.
After an overview on fr.usenet.abus.d, we think that these two domains
should be eligible for a temporary active UDP, that could help to catch
the attention of their newsmasters.
This UDP would be maintained until proper acknowledgement is made from
the respective newsmasters showing that:
- newsmasters/abuse desk is still active
- action is taken against abusing custommers
Is this the correct way to go ?
Example of recent flood coming from these two domains:
Recent example of flood coming from ono.com:
--------------------------------------------
<r6Q5f.107303$US.2...@news.ono.com>
<s6Q5f.107304$US.8...@news.ono.com>
<u6Q5f.107306$US....@news.ono.com>
<u6Q5f.107307$US....@news.ono.com>
<v6Q5f.107309$US.9...@news.ono.com>
<v6Q5f.107308$US.3...@news.ono.com>
<v6Q5f.107310$US.6...@news.ono.com>
<v6Q5f.107312$US....@news.ono.com>
<v6Q5f.107311$US.7...@news.ono.com>
<gcQ5f.107315$US.5...@news.ono.com>
<gcQ5f.107317$US.3...@news.ono.com>
<gcQ5f.107316$US.2...@news.ono.com>
<hcQ5f.107318$US.9...@news.ono.com>
<icQ5f.107320$US.3...@news.ono.com>
<icQ5f.107319$US.6...@news.ono.com>
<kcQ5f.107322$US.7...@news.ono.com>
<kcQ5f.107323$US.5...@news.ono.com>
<lcQ5f.107325$US....@news.ono.com>
<kcQ5f.107324$US.5...@news.ono.com>
<lcQ5f.107326$US....@news.ono.com>
<mcQ5f.107328$US.3...@news.ono.com>
<mcQ5f.107327$US.1...@news.ono.com>
<QeQ5f.107330$US.1...@news.ono.com>
<ReQ5f.107331$US.1...@news.ono.com>
<SeQ5f.107332$US.1...@news.ono.com>
<TeQ5f.107333$US.1...@news.ono.com>
<TeQ5f.107334$US.7...@news.ono.com>
<UeQ5f.107335$US.2...@news.ono.com>
<ZeQ5f.107337$US.9...@news.ono.com>
<_eQ5f.107338$US.1...@news.ono.com>
<_eQ5f.107339$US.1...@news.ono.com>
<_eQ5f.107340$US.5...@news.ono.com>
<_eQ5f.107341$US.1...@news.ono.com>
<%eQ5f.107342$US.4...@news.ono.com>
<%eQ5f.107343$US.7...@news.ono.com>
<AiQ5f.107346$US....@news.ono.com>
<BiQ5f.107347$US.3...@news.ono.com>
<BiQ5f.107348$US.8...@news.ono.com>
<BiQ5f.107349$US.5...@news.ono.com>
<DiQ5f.107350$US.2...@news.ono.com>
<EiQ5f.107351$US....@news.ono.com>
<HiQ5f.107353$US.4...@news.ono.com>
<HiQ5f.107354$US.6...@news.ono.com>
<IiQ5f.107355$US.7...@news.ono.com>
<IiQ5f.107357$US.8...@news.ono.com>
<IiQ5f.107358$US.6...@news.ono.com>
<IiQ5f.107356$US.8...@news.ono.com>
<JiQ5f.107359$US....@news.ono.com>
<I1R5f.107372$US.4...@news.ono.com>
<J1R5f.107373$US.9...@news.ono.com>
<J1R5f.107374$US.4...@news.ono.com>
<K1R5f.107375$US.8...@news.ono.com>
<K1R5f.107377$US....@news.ono.com>
<K1R5f.107376$US.1...@news.ono.com>
<R1R5f.107379$US.6...@news.ono.com>
<R1R5f.107380$US.8...@news.ono.com>
<S1R5f.107381$US.3...@news.ono.com>
<T1R5f.107382$US.4...@news.ono.com>
<T1R5f.107383$US.2...@news.ono.com>
<U1R5f.107384$US.2...@news.ono.com>
<U1R5f.107385$US.1...@news.ono.com>
<i7R5f.107389$US.1...@news.ono.com>
<i7R5f.107390$US.9...@news.ono.com>
<i7R5f.107391$US.9...@news.ono.com>
<i7R5f.107392$US.1...@news.ono.com>
<i7R5f.107393$US.2...@news.ono.com>
<j7R5f.107394$US.2...@news.ono.com>
<l7R5f.107396$US.7...@news.ono.com>
<l7R5f.107397$US.2...@news.ono.com>
<m7R5f.107398$US.6...@news.ono.com>
<n7R5f.107402$US.9...@news.ono.com>
<m7R5f.107399$US.8...@news.ono.com>
<m7R5f.107400$US.6...@news.ono.com>
<m7R5f.107401$US.5...@news.ono.com>
<GbR5f.107404$US.7...@news.ono.com>
<KbR5f.107405$US.1...@news.ono.com>
<KbR5f.107406$US....@news.ono.com>
<KbR5f.107407$US.6...@news.ono.com>
<KbR5f.107408$US.9...@news.ono.com>
<KbR5f.107409$US.8...@news.ono.com>
<MbR5f.107411$US.6...@news.ono.com>
<MbR5f.107412$US.5...@news.ono.com>
<NbR5f.107413$US.7...@news.ono.com>
<NbR5f.107414$US.7...@news.ono.com>
<ObR5f.107415$US.7...@news.ono.com>
<PbR5f.107416$US.3...@news.ono.com>
<PbR5f.107417$US.4...@news.ono.com>
<8iR5f.100921$dr.9...@news.ono.com>
<8iR5f.100920$dr.6...@news.ono.com>
<aiR5f.100923$dr....@news.ono.com>
<9iR5f.100922$dr.7...@news.ono.com>
<biR5f.100925$dr....@news.ono.com>
<biR5f.100924$dr....@news.ono.com>
<ciR5f.100927$dr....@news.ono.com>
<diR5f.100928$dr....@news.ono.com>
<diR5f.100929$dr.1...@news.ono.com>
<eiR5f.100930$dr....@news.ono.com>
<fiR5f.100931$dr.2...@news.ono.com>
<fiR5f.100932$dr.5...@news.ono.com>
<giR5f.100933$dr.1...@news.ono.com>
Recent example of flood coming from twister.auna.com:
-----------------------------------------------------
<WX4af.263408$o8.2...@twister.auna.com>
<WX4af.263409$o8.1...@twister.auna.com>
<YX4af.263412$o8.4...@twister.auna.com>
<YX4af.263411$o8.4...@twister.auna.com>
<ZX4af.263413$o8....@twister.auna.com>
<_X4af.263414$o8.4...@twister.auna.com>
<_X4af.263415$o8.1...@twister.auna.com>
<0Y4af.263417$o8.2...@twister.auna.com>
<%X4af.263416$o8.6...@twister.auna.com>
<0Y4af.263418$o8.2...@twister.auna.com>
<1Y4af.263419$o8.4...@twister.auna.com>
<3Y4af.263422$o8.2...@twister.auna.com>
<2Y4af.263420$o8.2...@twister.auna.com>
<2Y4af.263421$o8.8...@twister.auna.com>
<3Y4af.263423$o8.1...@twister.auna.com>
<4Y4af.263424$o8.1...@twister.auna.com>
<5Y4af.263425$o8.9...@twister.auna.com>
<6Y4af.263426$o8....@twister.auna.com>
<6Y4af.263427$o8.1...@twister.auna.com>
<7Y4af.263428$o8.2...@twister.auna.com>
<8Y4af.263429$o8.1...@twister.auna.com>
<8Y4af.263430$o8.1...@twister.auna.com>
<9Y4af.263431$o8.6...@twister.auna.com>
<aY4af.263432$o8.1...@twister.auna.com>
<aY4af.263433$o8.2...@twister.auna.com>
<bY4af.263434$o8.9...@twister.auna.com>
<cY4af.263435$o8.8...@twister.auna.com>
<cY4af.263436$o8.3...@twister.auna.com>
<dY4af.263437$o8.2...@twister.auna.com>
<dY4af.263438$o8.1...@twister.auna.com>
<fY4af.263440$o8.2...@twister.auna.com>
<eY4af.263439$o8....@twister.auna.com>
<fY4af.263441$o8.3...@twister.auna.com>
<gY4af.263442$o8.4...@twister.auna.com>
<hY4af.263443$o8.1...@twister.auna.com>
<iY4af.263444$o8.1...@twister.auna.com>
<iY4af.263445$o8....@twister.auna.com>
<jY4af.263446$o8.2...@twister.auna.com>
<kY4af.263447$o8.4...@twister.auna.com>
<kY4af.263448$o8.2...@twister.auna.com>
<lY4af.263449$o8.9...@twister.auna.com>
<mY4af.263450$o8....@twister.auna.com>
<mY4af.263451$o8.7...@twister.auna.com>
<nY4af.263452$o8....@twister.auna.com>
<oY4af.263453$o8.2...@twister.auna.com>
<oY4af.263454$o8.9...@twister.auna.com>
<pY4af.263455$o8.6...@twister.auna.com>
<qY4af.263456$o8.7...@twister.auna.com>
<qY4af.263457$o8.5...@twister.auna.com>
<rY4af.263459$o8.3...@twister.auna.com>
<sY4af.263460$o8.1...@twister.auna.com>
<rY4af.263458$o8.1...@twister.auna.com>
<tY4af.263461$o8.2...@twister.auna.com>
<tY4af.263462$o8.8...@twister.auna.com>
<uY4af.263463$o8.1...@twister.auna.com>
<vY4af.263464$o8....@twister.auna.com>
<wY4af.263466$o8.1...@twister.auna.com>
<vY4af.263465$o8.6...@twister.auna.com>
<xY4af.263467$o8.4...@twister.auna.com>
<xY4af.263468$o8.2...@twister.auna.com>
<yY4af.263469$o8.2...@twister.auna.com>
<zY4af.263471$o8.2...@twister.auna.com>
<AY4af.263472$o8.1...@twister.auna.com>
<yY4af.263470$o8.1...@twister.auna.com>
<BY4af.263474$o8.1...@twister.auna.com>
<AY4af.263473$o8.6...@twister.auna.com>
<BY4af.263475$o8.2...@twister.auna.com>
<CY4af.263476$o8.1...@twister.auna.com>
<DY4af.263477$o8.2...@twister.auna.com>
<DY4af.263478$o8.1...@twister.auna.com>
<EY4af.263479$o8.2...@twister.auna.com>
<EY4af.263480$o8.3...@twister.auna.com>
<FY4af.263481$o8.2...@twister.auna.com>
<FY4af.263482$o8.1...@twister.auna.com>
<GY4af.263483$o8.2...@twister.auna.com>
<HY4af.263484$o8.1...@twister.auna.com>
<IY4af.263485$o8.4...@twister.auna.com>
<IY4af.263487$o8.1...@twister.auna.com>
<JY4af.263488$o8.2...@twister.auna.com>
<KY4af.263489$o8.4...@twister.auna.com>
<KY4af.263490$o8.2...@twister.auna.com>
<MY4af.263492$o8.2...@twister.auna.com>
<MY4af.263493$o8.1...@twister.auna.com>
<NY4af.263495$o8.1...@twister.auna.com>
<RY4af.263500$o8.7...@twister.auna.com>
<OY4af.263496$o8.2...@twister.auna.com>
<PY4af.263498$o8.6...@twister.auna.com>
<PY4af.263497$o8.1...@twister.auna.com>
<QY4af.263499$o8.1...@twister.auna.com>
<NY4af.263494$o8.6...@twister.auna.com>
<SY4af.263501$o8.8...@twister.auna.com>
<SY4af.263502$o8.4...@twister.auna.com>
<TY4af.263503$o8.8...@twister.auna.com>
<UY4af.263504$o8....@twister.auna.com>
<VY4af.263506$o8.1...@twister.auna.com>
<UY4af.263505$o8....@twister.auna.com>
<WY4af.263507$o8.4...@twister.auna.com>
<WY4af.263508$o8.5...@twister.auna.com>
<XY4af.263509$o8.6...@twister.auna.com>
<YY4af.263510$o8.8...@twister.auna.com>
> After an overview on fr.usenet.abus.d, we think that these two domains
> should be eligible for a temporary active UDP, that could help to catch
> the attention of their newsmasters.
Agreed. Does someone have direct contact with auna/ono staff ?
--
Xavier Humbert - groumpf.org newsmaster
In article <dkauap$6lo$1...@news.httrack.net>,
Xavier Roche <xro...@free.fr.NOSPAM.invalid> wrote:
XR> These two domains have been the source of massive Usenet spam
XR> for *months*, without any reply from their respective
XR> newsmasters. Absolutely no action was taken to stop, or even
XR> limit the outgoing spam from these two servers, despite several
XR> mail complaints.
XR> The auna.com domain is notably used to send "dvd100.net" spam,
XR> and the ono.com server used to promote "make money fast"
XR> schemes. Currently, most spam is cancelled using cleaning bots,
XR> but this solution is not a long-term solution.
XR> After an overview on fr.usenet.abus.d, we think that these two
XR> domains should be eligible for a temporary active UDP, that
XR> could help to catch the attention of their newsmasters. This UDP
XR> would be maintained until proper acknowledgement is made from
XR> the respective newsmasters showing that: - newsmasters/abuse
XR> desk is still active - action is taken against abusing
XR> custommers
XR> Is this the correct way to go ?
Both of these ISPs are well known for exhibiting massive clue
impairment. I doubt there's much hope of ever hammering a clue
through to them. To my mind, there is little use for either,
beyond the borders of Spain. They would both do well, to
establish themselves as an intranet, with no connection to the
outside world.
In the case of ONO.COM, they've already gone through a formal UDP
process, in June, 2002, with regard to the large numbers of open
proxies operating on their lusers' Windoze boxes. Please see
<http://tinyurl.com/bplwg>.
As an alternative to an active UDP, have you attempted to reach
the appropriate contacts at ONO.COM's and AUNA.NET's upstream news
peers? Passive UDPs, such as de-peering, are often an even more
effective tool in dealing with the clue devoid.
I will note, there is mighty sparse data available in
nana.sightings, regarding any of this spamming activity. Having a
publicly accessible history of what you describe as ongoing abuse,
would be most helpful, were this discussion to deserve further
consideration.
- --
David Ritz <dritz+...@suespammers.org>
"This isn't a win/lose kind of thing. If there's a UDP, we all lose.
If the abuse stops, we all win." - Jeremy Nixon
-----BEGIN PGP SIGNATURE-----
Version: PGP Desktop 9.0.2 (Build 2425)
Comment: PGP Public Keys: <http://dritz.mako.ath.cx/keys.txt>
iQCVAwUBQ2xSwqdkAgrqVVPRAQGCoAP8CYOs9wIlxnK2AEbCQAOBEuw1NzBSbOmk
WBsBwvfuAPbNs9d5G3WTYiIZ1+rVZqhr9jPOLwQEslpI0UYA7DRtp3f214Gm/Lqa
ut+/1H6T/plAOaTzgJf9LudBZu1oqqWsBOpfgEfV40c1OqBEeqgtSBf0dQx0qWBD
Au1DbptxQ10=
=WbVh
-----END PGP SIGNATURE-----
David Ritz wrote:
> In the case of ONO.COM, they've already gone through a formal UDP
> process, in June, 2002, with regard to the large numbers of open
> proxies operating on their lusers' Windoze boxes. Please see
> <http://tinyurl.com/bplwg>.
Did the UDP caught the attention of the newsmaster ? After several mails
two months ago, I just couldn't get any reply from newsmaster and/or
abuse desk (even an automated one)
The ono.com newsserver was a big spam source ; but appently the spam
threshold has decreased.
> As an alternative to an active UDP, have you attempted to reach
> the appropriate contacts at ONO.COM's and AUNA.NET's upstream news
> peers? Passive UDPs, such as de-peering, are often an even more
> effective tool in dealing with the clue devoid.
I just contacted two of their peers (teleglobe.net and news.espanix.net)
to inform them of the problem ; but there might be other peers, too.
(By the way, the auna.com flood goes on)
Note: the current UDP contains the following pseudo-site in the path:
!UDP-AUNA-COM