|
Donation/Premium |
|
 |
|
|
|
|
|
|
|
 |
 |
| View previous topic :: View next topic |
| Author |
Message |
AlphaCentauri
SIRT Handler Premium Member
 Joined: Nov 20, 2003 Posts: 2889
|
|
| Back to top |
|
 |
tembow
Blue Angel Premium Member
 Joined: Oct 10, 2005 Posts: 2942
|
Posted: Sun Jul 06, 2008 8:31 pm Post subject: |
|
|
Reference: [ThePlanetAbuse-C24400082K]
To Whom It May Concern:
Please note that neither the below-referenced [IP address or URL or e-mail] nor the domain name that is being advertised is within our network as of the date stamp .in this email
Regards,
Abuse Department
The Planet
|
|
| Back to top |
|
 |
AlphaCentauri
SIRT Handler Premium Member
 Joined: Nov 20, 2003 Posts: 2889
|
Posted: Mon Jul 07, 2008 5:05 am Post subject: |
|
|
Registered through: GoDaddy.com, Inc. (http://www.godaddy.com)
Domain Name: FREECREDITREPORTS360.COM
Domain servers in listed order:
NS1.THEPLANET.COM
NS2.THEPLANET.COM
ThePlanet.com has the nameservers, not the spammed domain.
|
|
| Back to top |
|
 |
dabug
Cadet

 Joined: Jul 23, 2008 Posts: 1 Location: USA
|
Posted: Wed Jul 23, 2008 10:09 pm Post subject: |
|
|
discovertotal scans the net for 404 - unused domains - old domains - ( by my spam count 100+) but where there is a http server still running. They then upload a short redirect script and hijack the server. You then get spam for travel, training, etc that points you at olddomain.com/wodkvjlatlkaklsdf. The origional owner of olddomain, who doesn't use it any more never knows the difference. If you curl http://olddomain.com you get 404 error but curl olddomain.com/wodkv.... you get "... refresh=0 http://discovertotal.com/[base64-string].
Isn't it a crime to hack into someone computer?
discovertotal is registered by
DomainsByProxy.com
15111 N. Hayden Rd., Ste 160, PMB 353
Scottsdale, Arizona 85260
DomainsByProxy.com is:
Administrative Contact:
GoDaddy.com, Inc., GoDaddy.com, Inc. dns@jomax.net
GoDaddy.com, Inc.
14455 N Hayden Rd #226
Scottsdale, Arizona 85260
jomax is:
Administrative Contact:
GoDaddy.com, Inc., GoDaddy.com, Inc. dns@jomax.net
GoDaddy.com, Inc.
14455 N Hayden Rd #226
Scottsdale, Arizona 85260
and from what I can tell: jomax.net is GoDaddy.com
http://www.aboutus.org/Jomax.net

|
|
| Back to top |
|
 |
AlphaCentauri
SIRT Handler Premium Member
 Joined: Nov 20, 2003 Posts: 2889
|
Posted: Wed Jul 23, 2008 11:29 pm Post subject: |
|
|
| dabug wrote: | discovertotal scans the net for 404 - unused domains - old domains - ( by my spam count 100+) but where there is a http server still running. They then upload a short redirect script and hijack the server. You then get spam for travel, training, etc that points you at olddomain.com/wodkvjlatlkaklsdf. The origional owner of olddomain, who doesn't use it any more never knows the difference. If you curl http://olddomain.com you get 404 error but curl olddomain.com/wodkv.... you get "... refresh=0 http://discovertotal.com/[base64-string].
Isn't it a crime to hack into someone computer? |
That's very significant information if you can document it. I can't track down the owner of this particular spammed domain (bestrockbottom.com) from the registration information in the whois. There is no name, the zip code doesn't exist, and the phone number is a land line in Texas though the address in the registration is in Colorado. Having such a scammy looking registration would tend to argue against the theory that an innocent but neglectful website owner has had his website hacked.
The "404 not found" home page is a typical feature of sites that mail links that encode the ID of the affiliate that spammed you as well as maybe encoding your email address, so they know you clicked through. They don't want traffic from people who ask too many questions and try to view the home page. Other sites like that will put a generic unsubscribe form on the home page. In many cases, it can be quite difficult to view the content without revealing your email address.
|
|
| Back to top |
|
 |
|
|
|
You cannot post new topics in this forum You can reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum You cannot vote in polls in this forum You cannot attach files in this forum You can download files in this forum
|
Powered by phpBB © 2001 phpBB Group
|