<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: More Amsterdam Spam?   from 212.95.54.38</title>
	<atom:link href="http://aldebaranwebdesign.com/blog/more-amsterdam-spam-212955438-from-ripe/feed/" rel="self" type="application/rss+xml" />
	<link>http://aldebaranwebdesign.com/blog/more-amsterdam-spam-212955438-from-ripe/</link>
	<description>Just another WordPress weblog</description>
	<lastBuildDate>Sat, 15 May 2010 18:18:37 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
	<item>
		<title>By: Strangely Perfect</title>
		<link>http://aldebaranwebdesign.com/blog/more-amsterdam-spam-212955438-from-ripe/comment-page-1/#comment-2672</link>
		<dc:creator>Strangely Perfect</dc:creator>
		<pubDate>Wed, 19 Nov 2008 20:28:21 +0000</pubDate>
		<guid isPermaLink="false">http://aldebaranwebdesign.com/blog/?p=400#comment-2672</guid>
		<description>Hi Jill.
My original post is here:  http://strangelyperfect.tv/1576/more-info-on-eurosoftware-eurosoftmarket-dot-con/ and there&#039;s a follow up too. I&#039;ve had several investigations like this over the last few months.  By the continuing hits on these posts, people are obviously peeved by the continuing dross.
Like you, I&#039;ve been trying to make some (personal) sense out of the deluge of drivel etc and to hope that it&#039;ll give me a clearer understanding of how it all works.

The Complainerator is here: http://www.complainterator.com/download.html  Follow through on the simple menu system for more usage links etc and to learn about the dark world of the international spammer...
You need to get a good grasp of what it&#039;s doing before you use it.  When I ran it, it took about five minutes to complete all the lookups and make mail messages - so it&#039;s not frozen!

Keep well!

Rees</description>
		<content:encoded><![CDATA[<p>Hi Jill.<br />
My original post is here:  <a href="http://strangelyperfect.tv/1576/more-info-on-eurosoftware-eurosoftmarket-dot-con/" rel="nofollow">http://strangelyperfect.tv/1576/more-info-on-eurosoftware-eurosoftmarket-dot-con/</a> and there&#8217;s a follow up too. I&#8217;ve had several investigations like this over the last few months.  By the continuing hits on these posts, people are obviously peeved by the continuing dross.<br />
Like you, I&#8217;ve been trying to make some (personal) sense out of the deluge of drivel etc and to hope that it&#8217;ll give me a clearer understanding of how it all works.</p>
<p>The Complainerator is here: <a href="http://www.complainterator.com/download.html" rel="nofollow">http://www.complainterator.com/download.html</a>  Follow through on the simple menu system for more usage links etc and to learn about the dark world of the international spammer&#8230;<br />
You need to get a good grasp of what it&#8217;s doing before you use it.  When I ran it, it took about five minutes to complete all the lookups and make mail messages &#8211; so it&#8217;s not frozen!</p>
<p>Keep well!</p>
<p>Rees</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jill Olkoski</title>
		<link>http://aldebaranwebdesign.com/blog/more-amsterdam-spam-212955438-from-ripe/comment-page-1/#comment-2668</link>
		<dc:creator>Jill Olkoski</dc:creator>
		<pubDate>Wed, 19 Nov 2008 18:02:01 +0000</pubDate>
		<guid isPermaLink="false">http://aldebaranwebdesign.com/blog/?p=400#comment-2668</guid>
		<description>Hi Strangely Perfect,
That&#039;s a shame about your cats. Great names though!

The Russian Doll analogy is really interesting - I was unaware that you could somehow layer registrations, other than perhaps buying from a reseller. Please feel free to add a link to your &quot;The Complainerator&quot; link on your site, I&#039;d like to read it and so might others.</description>
		<content:encoded><![CDATA[<p>Hi Strangely Perfect,<br />
That&#8217;s a shame about your cats. Great names though!</p>
<p>The Russian Doll analogy is really interesting &#8211; I was unaware that you could somehow layer registrations, other than perhaps buying from a reseller. Please feel free to add a link to your &#8220;The Complainerator&#8221; link on your site, I&#8217;d like to read it and so might others.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Strangely Perfect</title>
		<link>http://aldebaranwebdesign.com/blog/more-amsterdam-spam-212955438-from-ripe/comment-page-1/#comment-2660</link>
		<dc:creator>Strangely Perfect</dc:creator>
		<pubDate>Wed, 19 Nov 2008 08:49:55 +0000</pubDate>
		<guid isPermaLink="false">http://aldebaranwebdesign.com/blog/?p=400#comment-2660</guid>
		<description>Doh!
I&#039;ve just checked your &quot;about&quot; page where you&#039;ve explained everything perfectly.  
We sort of adopted two almost feral kittens in Provence.  We called them Capella &amp; Aldebaran because of my astronomical bent!  Space considerations forced us to leave Albebaran and we took just Capella with us for a few months in our van on our French travels before we had to return to the UK.  Because of UK quarantine regs, we had to leave the (now big) cat because of the cost.  So we found Bridget Bardot&#039;s place in the north of France and tearfully left it there.
I don&#039;t know why I&#039;ve told this little tale here.  It&#039;s not connected apart from the name of the cat.

Tseug is a bit gruff and curt.  But the info is right.  Sometimes doing a whois isn&#039;t straightforward as there&#039;s no obligation for each organisation to pass any extra domain info to the rest.  All they are required to do is serve names....I think!  Because of this, the bad guys have registrations within registrations within registrations like a (somewhat appropriately) Russian Doll!
In a recent post on my site, I describe how I used “The Complainerator” to speed up this process.  If you do this, make sure that you use an old spammers email address, not your good one - I detail what happened afterwards in a follow up.  What happened was that I got bombarded by XIN NET who are obviously the lowest of the low and make no pretence about following the normal abuse channels that almost everyone else in the world adheres to.
Alternatively, it&#039;s likely that there&#039;s an already extant automation tool that will burrow down through the whois&#039;s for you to speed up the manual searching, like The Complainerator but without the emailing.  I haven&#039;t looked for one yet.

Rees</description>
		<content:encoded><![CDATA[<p>Doh!<br />
I&#8217;ve just checked your &#8220;about&#8221; page where you&#8217;ve explained everything perfectly.<br />
We sort of adopted two almost feral kittens in Provence.  We called them Capella &amp; Aldebaran because of my astronomical bent!  Space considerations forced us to leave Albebaran and we took just Capella with us for a few months in our van on our French travels before we had to return to the UK.  Because of UK quarantine regs, we had to leave the (now big) cat because of the cost.  So we found Bridget Bardot&#8217;s place in the north of France and tearfully left it there.<br />
I don&#8217;t know why I&#8217;ve told this little tale here.  It&#8217;s not connected apart from the name of the cat.</p>
<p>Tseug is a bit gruff and curt.  But the info is right.  Sometimes doing a whois isn&#8217;t straightforward as there&#8217;s no obligation for each organisation to pass any extra domain info to the rest.  All they are required to do is serve names&#8230;.I think!  Because of this, the bad guys have registrations within registrations within registrations like a (somewhat appropriately) Russian Doll!<br />
In a recent post on my site, I describe how I used “The Complainerator” to speed up this process.  If you do this, make sure that you use an old spammers email address, not your good one &#8211; I detail what happened afterwards in a follow up.  What happened was that I got bombarded by XIN NET who are obviously the lowest of the low and make no pretence about following the normal abuse channels that almost everyone else in the world adheres to.<br />
Alternatively, it&#8217;s likely that there&#8217;s an already extant automation tool that will burrow down through the whois&#8217;s for you to speed up the manual searching, like The Complainerator but without the emailing.  I haven&#8217;t looked for one yet.</p>
<p>Rees</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jill Olkoski</title>
		<link>http://aldebaranwebdesign.com/blog/more-amsterdam-spam-212955438-from-ripe/comment-page-1/#comment-2656</link>
		<dc:creator>Jill Olkoski</dc:creator>
		<pubDate>Wed, 19 Nov 2008 03:55:28 +0000</pubDate>
		<guid isPermaLink="false">http://aldebaranwebdesign.com/blog/?p=400#comment-2656</guid>
		<description>Hi Strangely Perfect,
Whew, thanks for the nice comment. After that rant it&#039;s nice to hear from someone friendly. Thank you for the additional resources. Yes, I&#039;m a Taurus. :-)</description>
		<content:encoded><![CDATA[<p>Hi Strangely Perfect,<br />
Whew, thanks for the nice comment. After that rant it&#8217;s nice to hear from someone friendly. Thank you for the additional resources. Yes, I&#8217;m a Taurus. <img src='http://aldebaranwebdesign.com/blog/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jill Olkoski</title>
		<link>http://aldebaranwebdesign.com/blog/more-amsterdam-spam-212955438-from-ripe/comment-page-1/#comment-2655</link>
		<dc:creator>Jill Olkoski</dc:creator>
		<pubDate>Wed, 19 Nov 2008 03:51:52 +0000</pubDate>
		<guid isPermaLink="false">http://aldebaranwebdesign.com/blog/?p=400#comment-2655</guid>
		<description>Dear Tseug,
At least in this comment you didn&#039;t violate the &lt;a href=&quot;http://aldebaranwebdesign.com/blog/discussion-rules/&quot; rel=&quot;nofollow&quot;&gt;Discussion Rules&lt;/a&gt; like you did in previous comment you left on my blog. I appreciate your trying to help and suggest you tone down the hostility a bit. I believe this post was all about trying to understand something, and getting beaten over the head after you&#039;ve already said you&#039;re confused, doesn&#039;t help.</description>
		<content:encoded><![CDATA[<p>Dear Tseug,<br />
At least in this comment you didn&#8217;t violate the <a href="http://aldebaranwebdesign.com/blog/discussion-rules/" rel="nofollow">Discussion Rules</a> like you did in previous comment you left on my blog. I appreciate your trying to help and suggest you tone down the hostility a bit. I believe this post was all about trying to understand something, and getting beaten over the head after you&#8217;ve already said you&#8217;re confused, doesn&#8217;t help.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Tseug</title>
		<link>http://aldebaranwebdesign.com/blog/more-amsterdam-spam-212955438-from-ripe/comment-page-1/#comment-2639</link>
		<dc:creator>Tseug</dc:creator>
		<pubDate>Tue, 18 Nov 2008 18:20:12 +0000</pubDate>
		<guid isPermaLink="false">http://aldebaranwebdesign.com/blog/?p=400#comment-2639</guid>
		<description>You&#039;re using RIPE wrongly then .. it&#039;s a database for European IP addresses, just like I have to use ARIN or LACNIC etc to find IP addresses from other countries. It doesn&#039;t mean that there&#039;s an Amsterdam based spam operation going on .. visit RIPE.NET and input the IP address and it&#039;ll give you :-


inetnum:         212.95.54.0 - 212.95.54.255
netname:         V3SERVERS-NET-967806
descr:           v3Servers.net
country:         BY
admin-c:         SA4597-RIPE
tech-c:          SR614-RIPE
status:          ASSIGNED PA &quot;status:&quot; definitions
mnt-by:          NETDIRECT-MNT
mnt-lower:       NETDIRECT-MNT
mnt-routes:      NETDIRECT-MNT
source:          RIPE # Filtered

person:          Sogreev Anton
address:         12 Knez Mihailova
address:         apt. 18
address:         Belgrade
address:         11000
address:         Serbia
phone:           +1 619 684 2664
abuse-mailbox:   abuse@v3servers.net
nic-hdl:         SA4597-RIPE
mnt-by:          NETDIRECT-MNT
source:          RIPE # Filtered

route:           212.95.32.0/19
descr:           ORG-nA8-RIPE
origin:          AS28753
org:             ORG-nA8-RIPE
mnt-lower:       NETDIRECT-MNT
mnt-routes:      NETDIRECT-MNT
mnt-by:          NETDIRECT-MNT
source:          RIPE # Filtered

organisation:    ORG-nA8-RIPE
org-name:        netdirect
org-type:        LIR
address:         netdirekt e. K.
                Kleyer Strasse 79 / Tor 14
                60326 Frankfurt
                Germany
phone:           +49 69 90556880
fax-no:          +49 69 905568822
admin-c:         SR614-RIPE
admin-c:         WW200-RIPE
mnt-ref:         NETDIRECT-MNT
mnt-ref:         RIPE-NCC-HM-MNT
mnt-by:          RIPE-NCC-HM-MNT
source:          RIPE # Filtered


.. meaning that the spam operation is from an IP address in Belgrade - Serbia which uses an IP range hosted from a German server ..

There are several IP databases available to trace things ..:-

ripe.net - Europe
arin.net - N.America
lacnic.net - Latin America
AfriNIC.net - Africa
APNIC.net - Asia Pacific

Hope that helps .. cos you&#039;ve gotten mighty confused LOL ;oP</description>
		<content:encoded><![CDATA[<p>You&#8217;re using RIPE wrongly then .. it&#8217;s a database for European IP addresses, just like I have to use ARIN or LACNIC etc to find IP addresses from other countries. It doesn&#8217;t mean that there&#8217;s an Amsterdam based spam operation going on .. visit RIPE.NET and input the IP address and it&#8217;ll give you :-</p>
<p>inetnum:         212.95.54.0 &#8211; 212.95.54.255<br />
netname:         V3SERVERS-NET-967806<br />
descr:           v3Servers.net<br />
country:         BY<br />
admin-c:         SA4597-RIPE<br />
tech-c:          SR614-RIPE<br />
status:          ASSIGNED PA &#8220;status:&#8221; definitions<br />
mnt-by:          NETDIRECT-MNT<br />
mnt-lower:       NETDIRECT-MNT<br />
mnt-routes:      NETDIRECT-MNT<br />
source:          RIPE # Filtered</p>
<p>person:          Sogreev Anton<br />
address:         12 Knez Mihailova<br />
address:         apt. 18<br />
address:         Belgrade<br />
address:         11000<br />
address:         Serbia<br />
phone:           +1 619 684 2664<br />
abuse-mailbox:   <a href="mailto:abuse@v3servers.net">abuse@v3servers.net</a><br />
nic-hdl:         SA4597-RIPE<br />
mnt-by:          NETDIRECT-MNT<br />
source:          RIPE # Filtered</p>
<p>route:           212.95.32.0/19<br />
descr:           ORG-nA8-RIPE<br />
origin:          AS28753<br />
org:             ORG-nA8-RIPE<br />
mnt-lower:       NETDIRECT-MNT<br />
mnt-routes:      NETDIRECT-MNT<br />
mnt-by:          NETDIRECT-MNT<br />
source:          RIPE # Filtered</p>
<p>organisation:    ORG-nA8-RIPE<br />
org-name:        netdirect<br />
org-type:        LIR<br />
address:         netdirekt e. K.<br />
                Kleyer Strasse 79 / Tor 14<br />
                60326 Frankfurt<br />
                Germany<br />
phone:           +49 69 90556880<br />
fax-no:          +49 69 905568822<br />
admin-c:         SR614-RIPE<br />
admin-c:         WW200-RIPE<br />
mnt-ref:         NETDIRECT-MNT<br />
mnt-ref:         RIPE-NCC-HM-MNT<br />
mnt-by:          RIPE-NCC-HM-MNT<br />
source:          RIPE # Filtered</p>
<p>.. meaning that the spam operation is from an IP address in Belgrade &#8211; Serbia which uses an IP range hosted from a German server ..</p>
<p>There are several IP databases available to trace things ..:-</p>
<p>ripe.net &#8211; Europe<br />
arin.net &#8211; N.America<br />
lacnic.net &#8211; Latin America<br />
AfriNIC.net &#8211; Africa<br />
APNIC.net &#8211; Asia Pacific</p>
<p>Hope that helps .. cos you&#8217;ve gotten mighty confused LOL ;oP</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Strangely Perfect</title>
		<link>http://aldebaranwebdesign.com/blog/more-amsterdam-spam-212955438-from-ripe/comment-page-1/#comment-2633</link>
		<dc:creator>Strangely Perfect</dc:creator>
		<pubDate>Tue, 18 Nov 2008 09:45:47 +0000</pubDate>
		<guid isPermaLink="false">http://aldebaranwebdesign.com/blog/?p=400#comment-2633</guid>
		<description>Hi Jill.
I got one of these this morning, exactly the same.  I also got the earlier ones last week in a big splurge, 94.102.60.150-3 I think they were (they&#039;re gone now).
A simple search always seems to pop up the Netherlands connection, as you&#039;ve found, but if you use different whois tools from different places, you get a fuller picture, I&#039;ve discovered.  And yes, nearly everything seems to end up in St Petersburg or XIN NET!  Or both!!
http://whois.domaintools.com/  give a nice big picture of things, and don&#039;t forget spamtracker and Castlecops as two big resources.
I had a purge of my htaccess file recently following this lot as they&#039;d by-passed Akismet &amp; htaccess.  I reckon that Akismet et al do such a good job with their database collection of spammers that blocking individual IP addresses is self-defeating in personal time and the actual performance hit on the website.  So I whipped all the IP blocks out but left the rest of the stuff of course.
The link you provided to the WordPress documentation says it all really, in that you have to keep on the ball at all times and change your defences as the spammers/crackers are always morphing and developing.  There&#039;s no one solution for everything.
For me, SABRE works well for registration spam in addition to Akismet for normal comments.  The French guy that wrote it is here 
http://didier.lorphelin.free.fr/blog/index.php/wordpress/sabre/
BTW.  You&#039;re not Taurus are you?  ;-)

Rees</description>
		<content:encoded><![CDATA[<p>Hi Jill.<br />
I got one of these this morning, exactly the same.  I also got the earlier ones last week in a big splurge, 94.102.60.150-3 I think they were (they&#8217;re gone now).<br />
A simple search always seems to pop up the Netherlands connection, as you&#8217;ve found, but if you use different whois tools from different places, you get a fuller picture, I&#8217;ve discovered.  And yes, nearly everything seems to end up in St Petersburg or XIN NET!  Or both!!<br />
<a href="http://whois.domaintools.com/" rel="nofollow">http://whois.domaintools.com/</a>  give a nice big picture of things, and don&#8217;t forget spamtracker and Castlecops as two big resources.<br />
I had a purge of my htaccess file recently following this lot as they&#8217;d by-passed Akismet &amp; htaccess.  I reckon that Akismet et al do such a good job with their database collection of spammers that blocking individual IP addresses is self-defeating in personal time and the actual performance hit on the website.  So I whipped all the IP blocks out but left the rest of the stuff of course.<br />
The link you provided to the WordPress documentation says it all really, in that you have to keep on the ball at all times and change your defences as the spammers/crackers are always morphing and developing.  There&#8217;s no one solution for everything.<br />
For me, SABRE works well for registration spam in addition to Akismet for normal comments.  The French guy that wrote it is here<br />
<a href="http://didier.lorphelin.free.fr/blog/index.php/wordpress/sabre/" rel="nofollow">http://didier.lorphelin.free.fr/blog/index.php/wordpress/sabre/</a><br />
BTW.  You&#8217;re not Taurus are you?  <img src='http://aldebaranwebdesign.com/blog/wp-includes/images/smilies/icon_wink.gif' alt=';-)' class='wp-smiley' /> </p>
<p>Rees</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ari Herzog</title>
		<link>http://aldebaranwebdesign.com/blog/more-amsterdam-spam-212955438-from-ripe/comment-page-1/#comment-2631</link>
		<dc:creator>Ari Herzog</dc:creator>
		<pubDate>Tue, 18 Nov 2008 08:01:00 +0000</pubDate>
		<guid isPermaLink="false">http://aldebaranwebdesign.com/blog/?p=400#comment-2631</guid>
		<description>If you google for RIPE Network Coordination Centre and spam, you can see results going back a few years.

The problem is RIPE is an internet registry and serves several countries. So, it can&#039;t be blocked.

I saw a new RIPE-hosted IP address add spam comment: 195.149.90.86</description>
		<content:encoded><![CDATA[<p>If you google for RIPE Network Coordination Centre and spam, you can see results going back a few years.</p>
<p>The problem is RIPE is an internet registry and serves several countries. So, it can&#8217;t be blocked.</p>
<p>I saw a new RIPE-hosted IP address add spam comment: 195.149.90.86</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jill Olkoski</title>
		<link>http://aldebaranwebdesign.com/blog/more-amsterdam-spam-212955438-from-ripe/comment-page-1/#comment-2626</link>
		<dc:creator>Jill Olkoski</dc:creator>
		<pubDate>Tue, 18 Nov 2008 02:51:19 +0000</pubDate>
		<guid isPermaLink="false">http://aldebaranwebdesign.com/blog/?p=400#comment-2626</guid>
		<description>Hi Ari,
I&#039;m not running any anti-spam programs at all on my computer. Just Akismet in the blog.</description>
		<content:encoded><![CDATA[<p>Hi Ari,<br />
I&#8217;m not running any anti-spam programs at all on my computer. Just Akismet in the blog.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ari Herzog</title>
		<link>http://aldebaranwebdesign.com/blog/more-amsterdam-spam-212955438-from-ripe/comment-page-1/#comment-2625</link>
		<dc:creator>Ari Herzog</dc:creator>
		<pubDate>Tue, 18 Nov 2008 02:48:59 +0000</pubDate>
		<guid isPermaLink="false">http://aldebaranwebdesign.com/blog/?p=400#comment-2625</guid>
		<description>Ahh, but RIPE is an internet registry: http://en.wikipedia.org/wiki/RIPE_NCC

What anti-spam programs are you running?</description>
		<content:encoded><![CDATA[<p>Ahh, but RIPE is an internet registry: <a href="http://en.wikipedia.org/wiki/RIPE_NCC" rel="nofollow">http://en.wikipedia.org/wiki/RIPE_NCC</a></p>
<p>What anti-spam programs are you running?</p>
]]></content:encoded>
	</item>
</channel>
</rss>
