... Good evening, all, I'm seeing a _lot_ of URL redirection sites I've never seen before:
shorten.in, registered Aug 20, 2006 (http://shorten.in/194 -> prosperityautomatedsystem.com) simurl.com (http://simurl.com/ss-nn-uu -> julesent4.info -> prosperityautomatedsystem.com) qdeo.com (http://qdeo.com/53 -> julesent4.info -> prosperityautomatedsystem.com) kuturl.com (http://kuturl.com/x.php?za -> 404)
This last one now shows:
Because of the actions of a SPAMMER - we have withdrawn this service. So, apologies to all of you who genuinely used our free service. You can blame the scum who ruined it for everyone else. We try hard to help others, while some are determined to prove themselves as lower than amoeba crap.
Many of the URLs redirect to www.prosperityautomatedsystem.com.
Try submitting a URL to these; you'll see the number returned is very low, indicating these are either fake redirectors or rarely used.
Thoughts? Opinions? Strawberry-banana smoothies? ;-) Cheers,
- Bill
I are sigfile disease!! All your quote are belong to us. Copy us every "sig"! (Courtesy of Charlie Stross, on an lwn.net letter)
William Stearns (wstearns@pobox.com). Mason, Buildkernel, freedups, p0f, rsync-backup, ssh-keyinstall, dns-check, more at: http://www.stearns.org ...
Well, at least part of the path is well known and recognizable: See Spamhaus' ROK3985, ROK4460, ROK4682, ROK6181, ROK6713 and ROK6937 for the address in shdns.info)
Paul Shupak track@plectere.com
... ;; ANSWER SECTION: julesent4.info. 86400 IN NS ns2.shdns.info. julesent4.info. 86400 IN NS ns1.shdns.info.
;; ADDITIONAL SECTION: ns2.shdns.info. 86400 IN A 211.144.69.237 ns1.shdns.info. 86400 IN A 220.164.140.232
;; Query time: 20 msec ;; SERVER: 199.7.66.33#53(199.7.66.33) ;; WHEN: Wed Sep 27 03:36:13 2006 ;; MSG SIZE rcvd: 106
% jwhois shdns.info [Querying whois.afilias.info] [whois.afilias.info] Access to INFO WHOIS information is provided to assist persons in determining the contents of a domain name registration record in the Afilias registry database. The data in this record is provided by Afilias Limited for informational purposes only, and Afilias does not guarantee its accuracy. This service is intended only for query-based access. You agree that you will use this data only for lawful purposes and that, under no circumstances will you use this data to: (a) allow, enable, or otherwise support the transmission by e-mail, telephone, or facsimile of mass unsolicited, commercial advertising or solicitations to entities other than the data recipient's own existing customers; or (b) enable high volume, automated, electronic processes that send queries or data to the systems of Registry Operator, a Registrar, or Afilias except as reasonably necessary to register domain names or modify existing registrations. All rights reserved. Afilias reserves the right to modify these terms at any time. By submitting this query, you agree to abide by this policy.
Domain ID:D13029584-LRMS Domain Name:SHDNS.INFO Created On:10-Apr-2006 19:59:26 UTC Last Updated On:09-Jun-2006 21:01:15 UTC Expiration Date:10-Apr-2007 19:59:26 UTC Sponsoring Registrar:eNom, Inc. (R126-LRMS) Status:OK Registrant ID:9902F5AE7419E685 Registrant Name:bill lai Registrant Organization:newtech co. Registrant Street1:211 yangzi road Registrant Street2:211 yangzi road widf Registrant Street3: Registrant City:widf Registrant State/Province:SD Registrant Postal Code:23423424 Registrant Country:US Registrant Phone:+91.343282334 Registrant Phone Ext.: Registrant FAX: Registrant FAX Ext.: Registrant Email:daniel@sv-luka.org Admin ID:9902F5AE7419E685 Admin Name:bill lai Admin Organization:newtech co. Admin Street1:211 yangzi road Admin Street2:211 yangzi road widf Admin Street3: Admin City:widf Admin State/Province:SD Admin Postal Code:23423424 Admin Country:US Admin Phone:+91.343282334 Admin Phone Ext.: Admin FAX: Admin FAX Ext.: Admin Email:daniel@sv-luka.org Billing ID:9902F5AE7419E685 Billing Name:bill lai Billing Organization:newtech co. Billing Street1:211 yangzi road Billing Street2:211 yangzi road widf Billing Street3: Billing City:widf Billing State/Province:SD Billing Postal Code:23423424 Billing Country:US Billing Phone:+91.343282334 Billing Phone Ext.: Billing FAX: Billing FAX Ext.: Billing Email:daniel@sv-luka.org Tech ID:9902F5AE7419E685 Tech Name:bill lai Tech Organization:newtech co. Tech Street1:211 yangzi road Tech Street2:211 yangzi road widf Tech Street3: Tech City:widf Tech State/Province:SD Tech Postal Code:23423424 Tech Country:US Tech Phone:+91.343282334 Tech Phone Ext.: Tech FAX: Tech FAX Ext.: Tech Email:daniel@sv-luka.org Name Server:DNS1.NAME-SERVICES.COM Name Server:DNS2.NAME-SERVICES.COM Name Server:DNS3.NAME-SERVICES.COM Name Server:DNS4.NAME-SERVICES.COM Name Server:DNS5.NAME-SERVICES.COM Name Server: Name Server: Name Server: Name Server: Name Server: Name Server: Name Server: Name Server:
On Wednesday, September 27, 2006, 3:45:46 AM, List User wrote:
... Good evening, all, I'm seeing a _lot_ of URL redirection sites I've never seen before:
shorten.in, registered Aug 20, 2006 (http://shorten.in/194 -> prosperityautomatedsystem.com) simurl.com (http://simurl.com/ss-nn-uu -> julesent4.info -> prosperityautomatedsystem.com) qdeo.com (http://qdeo.com/53 -> julesent4.info -> prosperityautomatedsystem.com) kuturl.com (http://kuturl.com/x.php?za -> 404)
This last one now shows:
Because of the actions of a SPAMMER - we have withdrawn this service. So, apologies to all of you who genuinely used our free service. You can blame the scum who ruined it for everyone else. We try hard to help others, while some are determined to prove themselves as lower than amoeba crap.
Many of the URLs redirect to www.prosperityautomatedsystem.com.
[...]
Well, at least part of the path is well known and recognizable:
See Spamhaus' ROK3985, ROK4460, ROK4682, ROK6181, ROK6713 and ROK6937 for the address in shdns.info)
But does that inform us about the redirection sites themselves? That's what the questions really about. We do know that they're being abused by spammers, but are the redirectors owned or operated by spammers?
Jeff C. -- Don't harm innocent bystanders.