<?xml version="1.0" encoding="utf-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Hijacked by Spam</title>
	<atom:link href="http://vaxcave.com/2005/07/06/hijacked-by-spam/feed/" rel="self" type="application/rss+xml" />
	<link>http://vaxcave.com/2005/07/06/hijacked-by-spam/</link>
	<description>Extreme Minutiae since 2000!</description>
	<lastBuildDate>Wed, 24 Feb 2010 04:29:53 -0500</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.3</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Cameron</title>
		<link>http://vaxcave.com/2005/07/06/hijacked-by-spam/comment-page-1/#comment-5664</link>
		<dc:creator>Cameron</dc:creator>
		<pubDate>Fri, 16 Dec 2005 20:23:18 +0000</pubDate>
		<guid isPermaLink="false">/?p=345#comment-5664</guid>
		<description>&lt;p&gt;They&#039;re doing that backscatter thing to &lt;em&gt;everybody&lt;/em&gt;.  It just feels like they&#039;re singling you out because the total volume is so huge.  Folks who seem to know estimate less than one in half a million spams generates a correctly targeted complaint.  People have just stopped complaining, because the major culprits effectively ignore complaints.&lt;/p&gt;

&lt;p&gt;The ICANN is a sock puppet of the US Dept of Commerce.  If the US Govt wanted spam stopped, ICANN would enforce its rules quickly and spammers would lose their domains so fast there would be no point in spamming any more.  Spam is company policy.  They want to get rid of the public SMTP email system and replace it with something centralized with back doors for govt and advertisers.&lt;/p&gt;

&lt;p&gt;Imagine what would happen if &lt;em&gt;60 Minutes&lt;/em&gt; did an expose on Microsoft&#039;s and Yahoo&#039;s role in the Nigeria fraud spam.  Now ask why they never will.&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>They&#8217;re doing that backscatter thing to <em>everybody</em>.  It just feels like they&#8217;re singling you out because the total volume is so huge.  Folks who seem to know estimate less than one in half a million spams generates a correctly targeted complaint.  People have just stopped complaining, because the major culprits effectively ignore complaints.</p>

<p>The ICANN is a sock puppet of the US Dept of Commerce.  If the US Govt wanted spam stopped, ICANN would enforce its rules quickly and spammers would lose their domains so fast there would be no point in spamming any more.  Spam is company policy.  They want to get rid of the public SMTP email system and replace it with something centralized with back doors for govt and advertisers.</p>

<p>Imagine what would happen if <em>60 Minutes</em> did an expose on Microsoft&#8217;s and Yahoo&#8217;s role in the Nigeria fraud spam.  Now ask why they never will.</p>]]></content:encoded>
	</item>
	<item>
		<title>By: AxsDeny</title>
		<link>http://vaxcave.com/2005/07/06/hijacked-by-spam/comment-page-1/#comment-5549</link>
		<dc:creator>AxsDeny</dc:creator>
		<pubDate>Sat, 03 Dec 2005 19:42:20 +0000</pubDate>
		<guid isPermaLink="false">/?p=345#comment-5549</guid>
		<description>&lt;p&gt;Don,&lt;/p&gt;

&lt;p&gt;Your site, as well as mine, were used as reference sites for the ICANN team to look at as domains that have been used as hijacked senders. Since you mention it on your front page it seemed appropriate to include.&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>Don,</p>

<p>Your site, as well as mine, were used as reference sites for the ICANN team to look at as domains that have been used as hijacked senders. Since you mention it on your front page it seemed appropriate to include.</p>]]></content:encoded>
	</item>
	<item>
		<title>By: Don</title>
		<link>http://vaxcave.com/2005/07/06/hijacked-by-spam/comment-page-1/#comment-5548</link>
		<dc:creator>Don</dc:creator>
		<pubDate>Fri, 02 Dec 2005 22:10:35 +0000</pubDate>
		<guid isPermaLink="false">/?p=345#comment-5548</guid>
		<description>&lt;p&gt;Hi,&lt;/p&gt;

&lt;p&gt;You seem to be fighting the good fight, but may I ask why my domain name is listed in the &quot;Dear ICANN team&quot; mail(s) cited above?  I hope it is as an example of the victimized and not the perpetrators.  If so, please make this more clear in future.&lt;/p&gt;

&lt;p&gt;My domain [veino dot com] has been victimized in the same way by this &quot;fake sender&quot; scheme.  I and it are not part of the origination of this scourge.  I too get 0-&gt;~50 bounced messages returned to me daily, whenever the mood hits them for some more SPAMming (interestingly enough they seem to be now using a x weeks on, y weeks off approach; the traffic ebbs and flows).&lt;/p&gt;

&lt;p&gt;The thing that really ticks me off is that I am losing more and more email addresses at my domain... as I need to disable them due to the faked outgoing addresses becoming incoming SPAM targets, after they apparently end up in some other victim&#039;s address book (and subsequent virus target?).  Some of them turn out to be desireable or valid addresses at my domain, and now they are trashed.  So not only am I being robbed of my time in filtering the bounces, but the value of my domain is being impacted.&lt;/p&gt;

&lt;p&gt;I have archived every mail returned from the SPAM activities and live in the good old state of Massachusetts, so I will be giving the AG&#039;s office a call.  I have had similar problems with the lack of effective registrar response to those I see cited above.  In my experience, you were lucky even to get a reply... I&#039;ve not experienced even that, when I&#039;ve complained to the registrars.&lt;/p&gt;

&lt;p&gt;DonV&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>Hi,</p>

<p>You seem to be fighting the good fight, but may I ask why my domain name is listed in the &#8220;Dear ICANN team&#8221; mail(s) cited above?  I hope it is as an example of the victimized and not the perpetrators.  If so, please make this more clear in future.</p>

<p>My domain [veino dot com] has been victimized in the same way by this &#8220;fake sender&#8221; scheme.  I and it are not part of the origination of this scourge.  I too get 0-&gt;~50 bounced messages returned to me daily, whenever the mood hits them for some more SPAMming (interestingly enough they seem to be now using a x weeks on, y weeks off approach; the traffic ebbs and flows).</p>

<p>The thing that really ticks me off is that I am losing more and more email addresses at my domain&#8230; as I need to disable them due to the faked outgoing addresses becoming incoming SPAM targets, after they apparently end up in some other victim&#8217;s address book (and subsequent virus target?).  Some of them turn out to be desireable or valid addresses at my domain, and now they are trashed.  So not only am I being robbed of my time in filtering the bounces, but the value of my domain is being impacted.</p>

<p>I have archived every mail returned from the SPAM activities and live in the good old state of Massachusetts, so I will be giving the AG&#8217;s office a call.  I have had similar problems with the lack of effective registrar response to those I see cited above.  In my experience, you were lucky even to get a reply&#8230; I&#8217;ve not experienced even that, when I&#8217;ve complained to the registrars.</p>

<p>DonV</p>]]></content:encoded>
	</item>
	<item>
		<title>By: Lee</title>
		<link>http://vaxcave.com/2005/07/06/hijacked-by-spam/comment-page-1/#comment-5514</link>
		<dc:creator>Lee</dc:creator>
		<pubDate>Fri, 28 Oct 2005 21:49:18 +0000</pubDate>
		<guid isPermaLink="false">/?p=345#comment-5514</guid>
		<description>&lt;p&gt;It doesn&#039;t look like this thread has seen a lot of activity lately, but I found useful spam advice here before, so I&#039;ll try this one again.
I&#039;ve been getting a lot of pharmaceutical spam - you know, the type that wants to sell cheap viagra and whatnot.  I have been angered enough by the volume of this that I thought I would try going after its source, and try to shut down the sites in a legal manner.  So I have started running WHOIS on all of them, and I have noticed something in common.
The almost always tend to rely on the same name servers.  I have seen six name server domains occur frequently now:&lt;/p&gt;

&lt;p&gt;yourgoldenhealth.info
drrecommends.info
themeds.info
yourmedz.info&lt;/p&gt;

&lt;p&gt;-and more recently-
yourbestmedz.info
healzymen.info&lt;/p&gt;

&lt;p&gt;As I dug through these domains trying to get these shut down, as they seem to serve only for spamming domains, I found something interesting in common for all six of them:  Tucows.com.
I didn&#039;t even know they were a registrar for internet domains.  In fact, they happen to be known to ICANN as R139-LRMS.  They have registered, and continue to hold registration status &quot;OK&quot; for all six of these domains.  I have contacted tucows, and they refuse to do anything about this.&lt;br /&gt;
I have since taken my complaint to ICANN, and have not yet received any response from them.  I brought this to ICANN on the merit of the fact that of the original four, three of them are registered to invalid email addresses (hence bad WHOIS data).  Nothing has changed in response to that, either.&lt;/p&gt;

&lt;p&gt;Any ideas from anywhere would be great.  The first four domains all resolve to a Chineese ISP (chinamobile.com) for the ns1.&lt;em&gt;.info address, with their ns2.&lt;/em&gt;.info addresses resolving to a Korean ISP.  Trying to get through to these ISPs has been almost impossible.  I am in the process of working with their CERT teams, but that is excrutiatingly slow going.&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>It doesn&#8217;t look like this thread has seen a lot of activity lately, but I found useful spam advice here before, so I&#8217;ll try this one again.
I&#8217;ve been getting a lot of pharmaceutical spam &#8211; you know, the type that wants to sell cheap viagra and whatnot.  I have been angered enough by the volume of this that I thought I would try going after its source, and try to shut down the sites in a legal manner.  So I have started running WHOIS on all of them, and I have noticed something in common.
The almost always tend to rely on the same name servers.  I have seen six name server domains occur frequently now:</p>

<p>yourgoldenhealth.info
drrecommends.info
themeds.info
yourmedz.info</p>

<p>-and more recently-
yourbestmedz.info
healzymen.info</p>

<p>As I dug through these domains trying to get these shut down, as they seem to serve only for spamming domains, I found something interesting in common for all six of them:  Tucows.com.
I didn&#8217;t even know they were a registrar for internet domains.  In fact, they happen to be known to ICANN as R139-LRMS.  They have registered, and continue to hold registration status &#8220;OK&#8221; for all six of these domains.  I have contacted tucows, and they refuse to do anything about this.<br />
I have since taken my complaint to ICANN, and have not yet received any response from them.  I brought this to ICANN on the merit of the fact that of the original four, three of them are registered to invalid email addresses (hence bad WHOIS data).  Nothing has changed in response to that, either.</p>

<p>Any ideas from anywhere would be great.  The first four domains all resolve to a Chineese ISP (chinamobile.com) for the ns1.<em>.info address, with their ns2.</em>.info addresses resolving to a Korean ISP.  Trying to get through to these ISPs has been almost impossible.  I am in the process of working with their CERT teams, but that is excrutiatingly slow going.</p>]]></content:encoded>
	</item>
	<item>
		<title>By: Eugene</title>
		<link>http://vaxcave.com/2005/07/06/hijacked-by-spam/comment-page-1/#comment-5462</link>
		<dc:creator>Eugene</dc:creator>
		<pubDate>Thu, 15 Sep 2005 23:02:09 +0000</pubDate>
		<guid isPermaLink="false">/?p=345#comment-5462</guid>
		<description>&lt;p&gt;Sorry for the late reply on &quot;where&quot; ICANN stipulates accurate/valid whois info. Boss is strict if you work for yourself :-)&lt;/p&gt;

&lt;p&gt;See http://www.icann.org/announcements/advisory-03apr03.htm
Note reason 1 for immediate domain suspension:
&#039;The customer&#039;s &quot;willful provision of inaccurate or unreliable information&quot; &#039;&lt;/p&gt;

&lt;p&gt;Yep, that is our Leo.&lt;/p&gt;

&lt;p&gt;Report these domains to ICANN here:
http://wdprs.internic.net/&lt;/p&gt;

&lt;p&gt;If the registrar refuses to do anything, you can report here: (this implies having contacted the registrar directly at addresses found at http://www.internic.net/contact.html)
http://reports.internic.net/cgi/registrars/problem-report.cgi&lt;/p&gt;

&lt;p&gt;Alternatively, if you believe you have valid proof that the registrar is deliberately not honouring his registrar agreement(see http://www.icann.org/registrars/ra-agreement-10nov99.htm), mail registrar-info@icann.org.&lt;/p&gt;

&lt;p&gt;Best of luck.&lt;/p&gt;

&lt;p&gt;Regards&lt;/p&gt;

&lt;p&gt;E&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>Sorry for the late reply on &#8220;where&#8221; ICANN stipulates accurate/valid whois info. Boss is strict if you work for yourself <img src='http://vaxcave.com/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /> </p>

<p>See <a href="http://www.icann.org/announcements/advisory-03apr03.htm" rel="nofollow">http://www.icann.org/announcements/advisory-03apr03.htm</a>
Note reason 1 for immediate domain suspension:
&#8216;The customer&#8217;s &#8220;willful provision of inaccurate or unreliable information&#8221; &#8216;</p>

<p>Yep, that is our Leo.</p>

<p>Report these domains to ICANN here:
<a href="http://wdprs.internic.net/" rel="nofollow">http://wdprs.internic.net/</a></p>

<p>If the registrar refuses to do anything, you can report here: (this implies having contacted the registrar directly at addresses found at <a href="http://www.internic.net/contact.html)" rel="nofollow">http://www.internic.net/contact.html)</a>
<a href="http://reports.internic.net/cgi/registrars/problem-report.cgi" rel="nofollow">http://reports.internic.net/cgi/registrars/problem-report.cgi</a></p>

<p>Alternatively, if you believe you have valid proof that the registrar is deliberately not honouring his registrar agreement(see <a href="http://www.icann.org/registrars/ra-agreement-10nov99.htm)" rel="nofollow">http://www.icann.org/registrars/ra-agreement-10nov99.htm)</a>, mail <a href="mailto:&#114;&#x65;&#x67;&#x69;&#115;&#x74;&#x72;&#x61;&#x72;&#45;&#x69;&#x6E;&#x66;&#111;&#64;&#105;&#x63;&#x61;&#x6E;&#x6E;&#46;&#x6F;rg">&#114;&#101;&#103;&#105;&#115;&#x74;&#x72;&#x61;&#x72;&#x2D;&#x69;&#x6E;&#x66;&#x6F;&#64;&#x69;&#x63;&#97;&#x6E;&#110;&#46;&#111;rg</a>.</p>

<p>Best of luck.</p>

<p>Regards</p>

<p>E</p>]]></content:encoded>
	</item>
	<item>
		<title>By: kjz</title>
		<link>http://vaxcave.com/2005/07/06/hijacked-by-spam/comment-page-1/#comment-5452</link>
		<dc:creator>kjz</dc:creator>
		<pubDate>Fri, 09 Sep 2005 21:20:23 +0000</pubDate>
		<guid isPermaLink="false">/?p=345#comment-5452</guid>
		<description>&lt;p&gt;Spammy now has shift his registrations from Yesnic (too many nukes I suppose) to Joker in Germany. your-domains-here.com is only a reseller for Joker, which seems quite resistant to complants. 
Whois contact for your-domains-here.com is domainz@web2mail.com in Belize City, so I suspect your-domains-here.com is the spammer itself. Yahoo now seems to be the favorite freemailer for spammers whois registration because Yahoo also seems quite unresponsive because of complaints against using Yahoo addresses for faked whois entries.&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;kjz&lt;/li&gt;
&lt;/ul&gt;
</description>
		<content:encoded><![CDATA[<p>Spammy now has shift his registrations from Yesnic (too many nukes I suppose) to Joker in Germany. your-domains-here.com is only a reseller for Joker, which seems quite resistant to complants. 
Whois contact for your-domains-here.com is <a href="mailto:&#x64;&#111;&#x6D;&#97;&#105;&#110;&#x7A;&#x40;&#x77;&#101;&#x62;&#50;&#x6D;&#97;&#x69;&#x6C;&#46;&#x63;om">&#x64;&#x6F;&#109;&#97;&#x69;&#x6E;&#x7A;&#64;&#x77;&#101;&#x62;&#50;&#x6D;&#x61;&#x69;&#x6C;&#46;&#x63;om</a> in Belize City, so I suspect your-domains-here.com is the spammer itself. Yahoo now seems to be the favorite freemailer for spammers whois registration because Yahoo also seems quite unresponsive because of complaints against using Yahoo addresses for faked whois entries.</p>

<ul>
<li>kjz</li>
</ul>]]></content:encoded>
	</item>
	<item>
		<title>By: Mantazz</title>
		<link>http://vaxcave.com/2005/07/06/hijacked-by-spam/comment-page-1/#comment-5448</link>
		<dc:creator>Mantazz</dc:creator>
		<pubDate>Thu, 08 Sep 2005 02:18:32 +0000</pubDate>
		<guid isPermaLink="false">/?p=345#comment-5448</guid>
		<description>&lt;p&gt;I believe someone earlier pointed out that the physical address &quot;Westbury&quot; is using is actually a PO Box.  I have also reported many domains owned by this person, as well as his (yahoo) email addresses.  They have all been shut down.  As was pointed out, though, he just goes off and finds a new registration host.&lt;br /&gt;
I&#039;ve found a couple of registration hosts to be particularly troublesome (as in I have difficulties gettingthem to take action):
your-domains-here.com
logicboxes.com&lt;/p&gt;

&lt;p&gt;Each of these two have at least one alias name that they also own and register under.  It also doesn&#039;t seem that they do anything to actually verify the information given to them.&lt;/p&gt;

&lt;p&gt;If you&#039;re looking to get the domains shut down due to bad registrant info, I would recommend going after the email address.  For some reason spammers like to use yahoo addresses (because they&#039;re free, I suppose).  If you show yahoo proof that the yahoo address is being used to register spamming internet domains, they will shut down the email account, and then you can pass that data back to the registrant and/or ICANN as bad WHOIS data.&lt;/p&gt;

&lt;p&gt;Happy hunting...&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>I believe someone earlier pointed out that the physical address &#8220;Westbury&#8221; is using is actually a PO Box.  I have also reported many domains owned by this person, as well as his (yahoo) email addresses.  They have all been shut down.  As was pointed out, though, he just goes off and finds a new registration host.<br />
I&#8217;ve found a couple of registration hosts to be particularly troublesome (as in I have difficulties gettingthem to take action):
your-domains-here.com
logicboxes.com</p>

<p>Each of these two have at least one alias name that they also own and register under.  It also doesn&#8217;t seem that they do anything to actually verify the information given to them.</p>

<p>If you&#8217;re looking to get the domains shut down due to bad registrant info, I would recommend going after the email address.  For some reason spammers like to use yahoo addresses (because they&#8217;re free, I suppose).  If you show yahoo proof that the yahoo address is being used to register spamming internet domains, they will shut down the email account, and then you can pass that data back to the registrant and/or ICANN as bad WHOIS data.</p>

<p>Happy hunting&#8230;</p>]]></content:encoded>
	</item>
	<item>
		<title>By: AxsDeny</title>
		<link>http://vaxcave.com/2005/07/06/hijacked-by-spam/comment-page-1/#comment-5445</link>
		<dc:creator>AxsDeny</dc:creator>
		<pubDate>Wed, 07 Sep 2005 17:06:59 +0000</pubDate>
		<guid isPermaLink="false">/?p=345#comment-5445</guid>
		<description>&lt;p&gt;That doesn&#039;t get us far since he just creates 6 new registrations every day. Boy, would I like to get my hands on this guy.&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>That doesn&#8217;t get us far since he just creates 6 new registrations every day. Boy, would I like to get my hands on this guy.</p>]]></content:encoded>
	</item>
	<item>
		<title>By: Rich</title>
		<link>http://vaxcave.com/2005/07/06/hijacked-by-spam/comment-page-1/#comment-5444</link>
		<dc:creator>Rich</dc:creator>
		<pubDate>Wed, 07 Sep 2005 16:58:38 +0000</pubDate>
		<guid isPermaLink="false">/?p=345#comment-5444</guid>
		<description>&lt;p&gt;I started reporting &quot;Westbury&quot; on 04/17/2005, 238 reports later I have wittled away and seen domain after domain finally being shut down - mostly through reports to ICANN.  With patience, something in the registrant information becomes invalid, be it the email, a change in tel #, whatever.  Now I&#039;m trying to find out what or who is at 177 Beak Street.  Since &quot;Westbury&quot; changed to &quot;Dean Westbury&quot; at 177 Beak from 77 Beak (which most registrars accepted as not a real address, I have come to a dead end.  Anyone know who or what is at 177 Beak Street?  All I can say is keep reporting him and eventually the domain gets shut down :-)&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>I started reporting &#8220;Westbury&#8221; on 04/17/2005, 238 reports later I have wittled away and seen domain after domain finally being shut down &#8211; mostly through reports to ICANN.  With patience, something in the registrant information becomes invalid, be it the email, a change in tel #, whatever.  Now I&#8217;m trying to find out what or who is at 177 Beak Street.  Since &#8220;Westbury&#8221; changed to &#8220;Dean Westbury&#8221; at 177 Beak from 77 Beak (which most registrars accepted as not a real address, I have come to a dead end.  Anyone know who or what is at 177 Beak Street?  All I can say is keep reporting him and eventually the domain gets shut down <img src='http://vaxcave.com/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /> </p>]]></content:encoded>
	</item>
	<item>
		<title>By: AxsDeny</title>
		<link>http://vaxcave.com/2005/07/06/hijacked-by-spam/comment-page-1/#comment-5436</link>
		<dc:creator>AxsDeny</dc:creator>
		<pubDate>Sun, 04 Sep 2005 16:29:24 +0000</pubDate>
		<guid isPermaLink="false">/?p=345#comment-5436</guid>
		<description>&lt;p&gt;I didn&#039;t write that letter. Eugene did. But I still get spam returned to me on a daily basis. It&#039;s getting ridiculous.&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>I didn&#8217;t write that letter. Eugene did. But I still get spam returned to me on a daily basis. It&#8217;s getting ridiculous.</p>]]></content:encoded>
	</item>
	<item>
		<title>By: Kanenas</title>
		<link>http://vaxcave.com/2005/07/06/hijacked-by-spam/comment-page-1/#comment-5414</link>
		<dc:creator>Kanenas</dc:creator>
		<pubDate>Sat, 03 Sep 2005 22:25:11 +0000</pubDate>
		<guid isPermaLink="false">/?p=345#comment-5414</guid>
		<description>&lt;p&gt;AxsDeny --
In your letter to Abacus, you mention ICANN policy requires that domain registration info be correct.  What section of which document is this from?  Do you know if there is a similar valid info requirement for IP allocation?  I&#039;m hoping to refer to the policy in e-mails to registrars, in particular mentioning the consequences registrars are supposed to apply (cancelation if the registrant doesn&#039;t supply valid info?).  I&#039;ve been searching the ICANN website but am having difficulties finding the policy information on my own.&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>AxsDeny &#8211;
In your letter to Abacus, you mention ICANN policy requires that domain registration info be correct.  What section of which document is this from?  Do you know if there is a similar valid info requirement for IP allocation?  I&#8217;m hoping to refer to the policy in e-mails to registrars, in particular mentioning the consequences registrars are supposed to apply (cancelation if the registrant doesn&#8217;t supply valid info?).  I&#8217;ve been searching the ICANN website but am having difficulties finding the policy information on my own.</p>]]></content:encoded>
	</item>
	<item>
		<title>By: Mantazz</title>
		<link>http://vaxcave.com/2005/07/06/hijacked-by-spam/comment-page-1/#comment-5267</link>
		<dc:creator>Mantazz</dc:creator>
		<pubDate>Sun, 21 Aug 2005 16:00:01 +0000</pubDate>
		<guid isPermaLink="false">/?p=345#comment-5267</guid>
		<description>&lt;p&gt;Has anyone successfully contacted &quot;names4ever.com&quot; / &quot;aplus.net&quot; / &quot;abacus america&quot; regarding westbury?  &lt;br&gt;
I have tried several times to contact them about this guy, and they seem to continually do nothing.  In fact, they even registered him a new domain last week:
&lt;code&gt;
Domain name: amturiam.com&lt;/p&gt;

&lt;p&gt;Registrant:
   JEFF westbury (PM4ZV) jeff_resale_domains2@yahoo.com
   77 Beek Street 118
   London,    GB    w1f9db
   United Kingdom
   Phone: (1)3473285225 x&lt;/p&gt;

&lt;p&gt;Administrative Contact:
   JEFF westbury (ETMVB) jeff_resale_domains2@yahoo.com
   77 Beek Street 118
   London,    GB    w1f9db
   United Kingdom
   Phone: (1)3473285225 x&lt;/p&gt;

&lt;p&gt;Technical Contact:
   JEFF westbury (PM4ZV) jeff_resale_domains2@yahoo.com
   77 Beek Street 118
   London,    GB    w1f9db
   United Kingdom
   Phone: (1)3473285225 x&lt;/p&gt;

&lt;p&gt;Billing Contact:
   JEFF westbury (XWPYF) jeff_resale_domains2@yahoo.com
   77 Beek Street 118
   London,    GB    w1f9db
   United Kingdom
   Phone: (1)3473285225 x&lt;/p&gt;

&lt;p&gt;Record last updated on 2005-08-19 00:00:00
Record created on 2005-08-17 00:00:00
Record expires on 2006-08-17 00:00:00
&lt;/code&gt;
I have since reported this group to internic, by emailing &quot;abuse@internic.net&quot;.  We&#039;ll see if that does anything, as abuse@aplus.net certainly doesn&#039;t.  On the same note, I&#039;ve also tried the support link on aplus.net, which leads to a &quot;chat&quot; window.  In the window, you&#039;ll see any of a variety of names, accompanies by one of about 5 &quot;real pictures&quot;.  The chat seems to be driven by a bot, as they never say anything useful other than to send your complaint to &quot;abuse@aplus.net&quot;.&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>Has anyone successfully contacted &#8220;names4ever.com&#8221; / &#8220;aplus.net&#8221; / &#8220;abacus america&#8221; regarding westbury?  <br />
I have tried several times to contact them about this guy, and they seem to continually do nothing.  In fact, they even registered him a new domain last week:
<code>
Domain name: amturiam.com</code></p>

<p>Registrant:
   JEFF westbury (PM4ZV) <a href="mailto:&#x6A;&#101;&#x66;&#x66;&#x5F;&#114;&#101;&#115;&#97;&#108;&#x65;&#95;&#100;&#x6F;&#109;&#97;&#x69;&#x6E;&#115;&#x32;&#64;&#121;&#97;&#104;&#111;&#x6F;&#x2E;&#x63;om">&#x6A;&#101;&#102;&#102;&#x5F;&#x72;&#101;&#115;&#97;&#x6C;&#101;&#x5F;&#x64;&#111;&#109;&#x61;&#x69;&#110;&#115;&#x32;&#64;&#121;&#97;&#104;&#111;&#111;&#46;&#x63;om</a>
   77 Beek Street 118
   London,    GB    w1f9db
   United Kingdom
   Phone: (1)3473285225 x</p>

<p>Administrative Contact:
   JEFF westbury (ETMVB) <a href="mailto:&#106;&#101;&#102;&#x66;&#95;&#x72;&#101;&#x73;&#x61;&#108;&#101;&#x5F;&#100;&#111;&#x6D;&#x61;&#x69;&#x6E;&#x73;&#x32;&#64;&#x79;&#97;&#104;&#111;&#111;&#46;&#x63;om">&#x6A;&#x65;&#102;&#x66;&#x5F;&#114;&#101;&#115;&#97;&#x6C;&#101;&#x5F;&#100;&#111;&#109;&#97;&#x69;&#x6E;&#x73;&#50;&#x40;&#x79;&#97;&#x68;&#x6F;&#111;&#x2E;&#99;om</a>
   77 Beek Street 118
   London,    GB    w1f9db
   United Kingdom
   Phone: (1)3473285225 x</p>

<p>Technical Contact:
   JEFF westbury (PM4ZV) <a href="mailto:&#x6A;&#101;&#x66;&#102;&#x5F;&#114;&#101;&#115;&#x61;&#108;&#101;&#x5F;&#100;&#x6F;&#109;&#97;&#x69;&#x6E;&#115;&#x32;&#x40;&#121;&#97;&#104;&#x6F;&#111;&#x2E;&#x63;om">&#106;&#x65;&#x66;&#x66;&#x5F;&#x72;&#101;&#115;&#x61;&#108;&#x65;&#95;&#x64;&#111;&#109;&#x61;&#x69;&#x6E;&#x73;&#x32;&#64;&#121;&#97;&#x68;&#111;&#111;&#46;&#99;om</a>
   77 Beek Street 118
   London,    GB    w1f9db
   United Kingdom
   Phone: (1)3473285225 x</p>

<p>Billing Contact:
   JEFF westbury (XWPYF) <a href="mailto:&#106;&#101;&#x66;&#x66;&#x5F;&#x72;&#101;&#115;&#97;&#x6C;&#x65;&#x5F;&#x64;&#111;&#109;&#97;&#105;&#x6E;&#115;&#x32;&#64;&#121;&#97;&#104;&#111;&#x6F;&#46;&#x63;om">&#x6A;&#x65;&#x66;&#102;&#x5F;&#x72;&#x65;&#115;&#97;&#108;&#x65;&#x5F;&#x64;&#111;&#x6D;&#x61;&#105;&#110;&#x73;&#x32;&#x40;&#121;&#97;&#104;&#111;&#x6F;&#x2E;&#99;om</a>
   77 Beek Street 118
   London,    GB    w1f9db
   United Kingdom
   Phone: (1)3473285225 x</p>

<p>Record last updated on 2005-08-19 00:00:00
Record created on 2005-08-17 00:00:00
Record expires on 2006-08-17 00:00:00

I have since reported this group to internic, by emailing &#8220;&#97;&#x62;&#x75;&#115;&#101;&#x40;&#x69;&#110;&#116;&#101;&#114;&#x6E;&#105;&#99;&#x2E;&#110;et&#8221;.  We&#8217;ll see if that does anything, as <a href="mailto:&#x61;&#98;&#x75;&#115;&#101;&#x40;&#x61;&#112;&#x6C;&#117;&#115;&#46;&#x6E;et">&#x61;&#98;&#117;&#x73;&#101;&#x40;&#97;&#x70;&#108;&#117;&#115;&#46;&#x6E;et</a> certainly doesn&#8217;t.  On the same note, I&#8217;ve also tried the support link on aplus.net, which leads to a &#8220;chat&#8221; window.  In the window, you&#8217;ll see any of a variety of names, accompanies by one of about 5 &#8220;real pictures&#8221;.  The chat seems to be driven by a bot, as they never say anything useful other than to send your complaint to &#8220;&#x61;&#x62;&#x75;&#x73;&#101;&#64;&#x61;&#112;&#108;&#x75;&#x73;&#46;&#110;et&#8221;.</p>]]></content:encoded>
	</item>
	<item>
		<title>By: Jorge</title>
		<link>http://vaxcave.com/2005/07/06/hijacked-by-spam/comment-page-1/#comment-5266</link>
		<dc:creator>Jorge</dc:creator>
		<pubDate>Fri, 19 Aug 2005 22:11:26 +0000</pubDate>
		<guid isPermaLink="false">/?p=345#comment-5266</guid>
		<description>&lt;p&gt;One of his emails does not work!
&lt;jeff_resale_domains2 @yahoo.com&gt;: host mx3.mail.yahoo.com[64.156.215.5] said:
   554 delivery error: dd This user doesn&#039;t have a yahoo.com account
   (jeff_resale_domains2@yahoo.com) [-5] - mta155.mail.scd.yahoo.com (in reply
   to end of DATA command)&lt;/p&gt;

&lt;p&gt;Lart away at http://wdprs.internic.net/  (Invalid whois data)&lt;/jeff_resale_domains2&gt;&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>One of his emails does not work!
<jeff_resale_domains2 @yahoo.com>: host mx3.mail.yahoo.com[64.156.215.5] said:
   554 delivery error: dd This user doesn&#8217;t have a yahoo.com account
   (&#x6A;&#101;&#102;&#x66;&#x5F;&#x72;&#101;&#115;&#x61;&#108;&#x65;&#x5F;&#x64;&#x6F;&#109;&#97;&#105;&#x6E;&#115;&#50;&#x40;&#x79;&#x61;&#x68;&#111;&#x6F;&#46;&#99;om) [-5] &#8211; mta155.mail.scd.yahoo.com (in reply
   to end of DATA command)</jeff_resale_domains2></p>

<p>Lart away at <a href="http://wdprs.internic.net/" rel="nofollow">http://wdprs.internic.net/</a>  (Invalid whois data)</p>]]></content:encoded>
	</item>
	<item>
		<title>By: Derek</title>
		<link>http://vaxcave.com/2005/07/06/hijacked-by-spam/comment-page-1/#comment-5262</link>
		<dc:creator>Derek</dc:creator>
		<pubDate>Thu, 18 Aug 2005 08:04:23 +0000</pubDate>
		<guid isPermaLink="false">/?p=345#comment-5262</guid>
		<description>&lt;p&gt;Please supply more info.&lt;/p&gt;

&lt;p&gt;&quot;17. They seem to have hijacked my domain name as well for their fake FROM headers. The web addresses in the message have domain names that trace back to the same Jeff Westbury, IP of web server 221.11.133.68 is in China.&quot;&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>Please supply more info.</p>

<p>&#8220;17. They seem to have hijacked my domain name as well for their fake FROM headers. The web addresses in the message have domain names that trace back to the same Jeff Westbury, IP of web server 221.11.133.68 is in China.&#8221;</p>]]></content:encoded>
	</item>
	<item>
		<title>By: Derek</title>
		<link>http://vaxcave.com/2005/07/06/hijacked-by-spam/comment-page-1/#comment-5261</link>
		<dc:creator>Derek</dc:creator>
		<pubDate>Thu, 18 Aug 2005 08:02:40 +0000</pubDate>
		<guid isPermaLink="false">/?p=345#comment-5261</guid>
		<description>&lt;p&gt;MPA? (Multiple Personaility Disorder)&lt;/p&gt;

&lt;p&gt;Or is Leo Kuvayev still evolving? more likely ....&lt;/p&gt;

&lt;p&gt;Domain Name       : mirooteryci.com (MIROOT2-BMN-DOM)
Registrar         : BookMyName
Whois Server      : whois.bookmyname.com
Referral URL      : https://www.bookmyname.com&lt;/p&gt;

&lt;p&gt;Registrant / Admin Contact :
PERSON
Jeff WESTBURY (WESTBU18-BMN-PE)&lt;/p&gt;

&lt;p&gt;77 BEAK STREET 118&lt;/p&gt;

&lt;p&gt;w1f9db London
 UNITED KINGDOM 
 phone            : 13473285225
 fax              : 
 e-mail           : JohsephWinst@yahoo.com&lt;/p&gt;

&lt;p&gt;Billing Contact   :
PERSON
Jeff WESTBURY (WESTBU18-BMN-PE)&lt;/p&gt;

&lt;p&gt;77 BEAK STREET 118&lt;/p&gt;

&lt;p&gt;w1f9db London
 UNITED KINGDOM 
 phone            : 13473285225
 fax              : 
 e-mail           : JohsephWinst@yahoo.com&lt;/p&gt;

&lt;p&gt;Technical Contact :
PERSON
Jeff WESTBURY (WESTBU18-BMN-PE)&lt;/p&gt;

&lt;p&gt;77 BEAK STREET 118&lt;/p&gt;

&lt;p&gt;w1f9db London
 UNITED KINGDOM 
 phone            : 13473285225
 fax              : 
 e-mail           : JohsephWinst@yahoo.com&lt;/p&gt;

&lt;p&gt;Domain servers    : 
ns0.hostsbackop.com (NHC124-BMN-HST)&lt;/p&gt;

&lt;h2&gt;ns1.hostsbackop.com (NHC125-BMN-HST)&lt;/h2&gt;

&lt;p&gt;However, looking at NS!
Registrant:
 Individual
 77 BEAK STREET 118
 London, GB w1f9db
 GB
 13473285225&lt;/p&gt;

&lt;p&gt;Domain Name: HOSTSBACKOP.COM&lt;/p&gt;

&lt;p&gt;Administrative Contact: 
 Winst, Johseph JohsephWinst@yahoo.com
 77 BEAK STREET 118
 London, GB w1f9db
 GB
 13473285225&lt;/p&gt;

&lt;p&gt;Technical Contact: 
 Winst, Johseph JohsephWinst@yahoo.com
 77 BEAK STREET 118
 London, GB w1f9db
 GB
 13473285225&lt;/p&gt;

&lt;p&gt;Record last updated 08-15-2005 05:28:07 PM
Record expires on 08-15-2006
Record created on 08-15-2005&lt;/p&gt;

&lt;p&gt;Domain servers in listed order:
    NS0.HOSTSBACKOP.COM 222.47.94.32
    NS1.HOSTSBACKOP.COM 61.234.241.246&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>MPA? (Multiple Personaility Disorder)</p>

<p>Or is Leo Kuvayev still evolving? more likely &#8230;.</p>

<p>Domain Name       : mirooteryci.com (MIROOT2-BMN-DOM)
Registrar         : BookMyName
Whois Server      : whois.bookmyname.com
Referral URL      : <a href="https://www.bookmyname.com" rel="nofollow">https://www.bookmyname.com</a></p>

<p>Registrant / Admin Contact :
PERSON
Jeff WESTBURY (WESTBU18-BMN-PE)</p>

<p>77 BEAK STREET 118</p>

<p>w1f9db London
 UNITED KINGDOM 
 phone            : 13473285225
 fax              : 
 e-mail           : <a href="mailto:&#x4A;&#111;&#104;&#115;&#101;&#112;&#104;&#87;&#105;&#110;&#x73;&#116;&#64;&#121;&#x61;&#104;&#111;&#x6F;&#46;&#x63;om">&#x4A;&#111;&#104;&#115;&#x65;&#x70;&#x68;&#87;&#x69;&#110;&#115;&#116;&#x40;&#121;&#97;&#104;&#x6F;&#111;&#x2E;&#99;om</a></p>

<p>Billing Contact   :
PERSON
Jeff WESTBURY (WESTBU18-BMN-PE)</p>

<p>77 BEAK STREET 118</p>

<p>w1f9db London
 UNITED KINGDOM 
 phone            : 13473285225
 fax              : 
 e-mail           : <a href="mailto:&#x4A;&#111;&#104;&#115;&#101;&#112;&#104;&#x57;&#105;&#x6E;&#x73;&#x74;&#64;&#x79;&#x61;&#104;&#x6F;&#x6F;&#46;&#99;om">&#74;&#111;&#104;&#x73;&#x65;&#x70;&#x68;&#x57;&#x69;&#x6E;&#x73;&#x74;&#x40;&#121;&#x61;&#104;&#x6F;&#111;&#46;&#x63;om</a></p>

<p>Technical Contact :
PERSON
Jeff WESTBURY (WESTBU18-BMN-PE)</p>

<p>77 BEAK STREET 118</p>

<p>w1f9db London
 UNITED KINGDOM 
 phone            : 13473285225
 fax              : 
 e-mail           : <a href="mailto:&#x4A;&#x6F;&#104;&#115;&#x65;&#112;&#104;&#87;&#x69;&#110;&#x73;&#x74;&#x40;&#x79;&#x61;&#x68;&#111;&#x6F;&#46;&#99;om">&#74;&#111;&#104;&#x73;&#x65;&#x70;&#104;&#87;&#x69;&#110;&#x73;&#x74;&#x40;&#121;&#97;&#104;&#111;&#111;&#x2E;&#99;om</a></p>

<p>Domain servers    : 
ns0.hostsbackop.com (NHC124-BMN-HST)</p>

<h2>ns1.hostsbackop.com (NHC125-BMN-HST)</h2>

<p>However, looking at NS!
Registrant:
 Individual
 77 BEAK STREET 118
 London, GB w1f9db
 GB
 13473285225</p>

<p>Domain Name: HOSTSBACKOP.COM</p>

<p>Administrative Contact: 
 Winst, Johseph <a href="mailto:&#x4A;&#111;&#104;&#x73;&#101;&#x70;&#104;&#x57;&#x69;&#110;&#115;&#x74;&#x40;&#121;&#x61;&#104;&#x6F;&#111;&#46;&#x63;om">&#74;&#111;&#x68;&#115;&#101;&#x70;&#x68;&#x57;&#x69;&#110;&#x73;&#116;&#x40;&#x79;&#97;&#104;&#x6F;&#111;&#x2E;&#x63;om</a>
 77 BEAK STREET 118
 London, GB w1f9db
 GB
 13473285225</p>

<p>Technical Contact: 
 Winst, Johseph <a href="mailto:&#x4A;&#x6F;&#x68;&#115;&#x65;&#112;&#104;&#x57;&#x69;&#x6E;&#115;&#x74;&#x40;&#x79;&#97;&#x68;&#111;&#x6F;&#46;&#99;om">&#74;&#111;&#x68;&#x73;&#101;&#x70;&#x68;&#x57;&#x69;&#x6E;&#115;&#116;&#x40;&#x79;&#x61;&#104;&#111;&#x6F;&#46;&#99;om</a>
 77 BEAK STREET 118
 London, GB w1f9db
 GB
 13473285225</p>

<p>Record last updated 08-15-2005 05:28:07 PM
Record expires on 08-15-2006
Record created on 08-15-2005</p>

<p>Domain servers in listed order:
    NS0.HOSTSBACKOP.COM 222.47.94.32
    NS1.HOSTSBACKOP.COM 61.234.241.246</p>]]></content:encoded>
	</item>
	<item>
		<title>By: David</title>
		<link>http://vaxcave.com/2005/07/06/hijacked-by-spam/comment-page-1/#comment-5259</link>
		<dc:creator>David</dc:creator>
		<pubDate>Sun, 14 Aug 2005 23:38:15 +0000</pubDate>
		<guid isPermaLink="false">/?p=345#comment-5259</guid>
		<description>&lt;p&gt;&lt;html&gt;
Perhaps a little more information would be helpful?  I just got an spam that appears to be from this character (see&lt;/p&gt;

&lt;blockquote cite=&quot;&quot;&gt;&lt;&lt;a href=&quot;http://www.spamcop.net/sc?id=z796153090z5b763850c042ec7bed4cb0040cd5d220z&quot;&gt;http://www.spamcop.net/sc?id=z796153090z5b763850c042ec7bed4cb0040cd5d220z&lt;/a&gt;&gt;
&lt;/blockquote&gt;

&lt;p&gt;which leads to a website:&lt;/p&gt;

&lt;blockquote cite=&quot;&quot;&gt;&lt;gggthx.bcunbrentmh.com&gt;.
&lt;/blockquote&gt;

&lt;p&gt;Doing a little &#039;nslookup&#039; digging, I find that bcunbrentmh.com&#039;s authority DNS records are at &lt;b&gt;ns0.mammonnnjff.com&lt;/b&gt; and &lt;b&gt;ns1.mammonnnjff.com&lt;/b&gt;.  When I set my DNS server to ns0.mammonnnjff.com, and look up gggthx.bcunbrentmh.com, it then claims there that the DNS authority records are &lt;b&gt;ns1.raperconnn.biz&lt;/b&gt; and &lt;b&gt;ns1.raperconnn.biz&lt;/b&gt;.&lt;/p&gt;

&lt;p&gt;Interesting name, &#039;raperconnn&#039;??  :)

&lt;p&gt;Further, gggthx.bcunbrentmh.com having an IPv4 address of &lt;b&gt;222.47.78.229&lt;/b&gt; == &lt;em&gt;the IPv4 address of ns1.raperconnn.biz == the IPv4 address of ns0.mammonnnjff.com!!&lt;/em&gt;

&lt;blockquote&gt;&lt;pre&gt;&lt;code&gt;
&gt; set debug
&gt; gggthx.bcunbrentmh.com
Server:  ns0.mammonnnjff.com
Address:  &lt;b&gt;222.47.78.229&lt;/b&gt;

;; res_mkquery(0, gggthx.bcunbrentmh.com, 1, 1)
------------
Got answer:
    HEADER:
        opcode = QUERY, id = 61633, rcode = NOERROR
        header flags:  response, auth. answer, want recursion
        questions = 1,  answers = 1,  authority records = 2,  additional = 2

    QUESTIONS:
        gggthx.bcunbrentmh.com, type = A, class = IN
    ANSWERS:
    -&gt;  gggthx.bcunbrentmh.com
        internet address = &lt;b&gt;222.47.78.229&lt;/b&gt;
        ttl = 259200 (3D)
    AUTHORITY RECORDS:
    -&gt;  bcunbrentmh.com
        nameserver = ns1.raperconnn.biz
        ttl = 259200 (3D)
    -&gt;  bcunbrentmh.com
        nameserver = ns2.raperconnn.biz
        ttl = 259200 (3D)
    ADDITIONAL RECORDS:
    -&gt;  ns1.raperconnn.biz
        internet address = &lt;b&gt;222.47.78.229&lt;/b&gt;
        ttl = 259200 (3D)
    -&gt;  ns2.raperconnn.biz
        internet address = 221.11.133.68
        ttl = 259200 (3D)

------------
Name:    gggthx.bcunbrentmh.com
Address:  &lt;b&gt;222.47.78.229&lt;/b&gt;
&lt;/code&gt;&lt;/pre&gt;&lt;/blockquote&gt; guess what ya get when you do a whois on &lt;b&gt;raperconnn.biz&lt;/b&gt;:

&lt;blockquote&gt;&lt;pre&gt;&lt;code&gt;
[Querying whois.neulevel.biz]
[whois.neulevel.biz]
Domain Name:                                 RAPERCONNN.BIZ
Domain ID:                                   D10251032-BIZ
Sponsoring Registrar:                        NETWORK SOLUTIONS INC.
Sponsoring Registrar IANA ID:                2
Domain Status:                               clientTransferProhibited
Registrant ID:                               39651578
Registrant Name:                             DEAN WESTBURY
Registrant Address1:                         177 Beak Street
Registrant City:                             London
Registrant State/Province:                   GB
Registrant Postal Code:                      W1F 9DB
Registrant Country:                          Great Britain (UK)
Registrant Country Code:                     GB
Registrant Phone Number:                     +1.13473285225
Registrant Email:                            jeff_resale_domainz@yahoo.co.uk
Administrative Contact ID:                   39723119
Administrative Contact Name:                 Dean Westbury
Administrative Contact Organization:         NA
Administrative Contact Address1:             77 Beak Street, #118
Administrative Contact City:                 London
Administrative Contact State/Province:       GB
Administrative Contact Postal Code:          w1f9db
Administrative Contact Country:              Great Britain (UK)
Administrative Contact Country Code:         GB
Administrative Contact Phone Number:         +1.13473285225
Administrative Contact Email:                deanwestbury@pookmail.com
Billing Contact ID:                          39651578
Billing Contact Name:                        DEAN WESTBURY
Billing Contact Address1:                    177 Beak Street
Billing Contact City:                        London
Billing Contact State/Province:              GB
Billing Contact Postal Code:                 W1F 9DB
Billing Contact Country:                     Great Britain (UK)
Billing Contact Country Code:                GB
Billing Contact Phone Number:                +1.13473285225
Billing Contact Email:                       jeff_resale_domainz@yahoo.co.uk
Technical Contact ID:                        39723119
Technical Contact Name:                      Dean Westbury
Technical Contact Organization:              NA
Technical Contact Address1:                  77 Beak Street, #118
Technical Contact City:                      London
Technical Contact State/Province:            GB
Technical Contact Postal Code:               w1f9db
Technical Contact Country:                   Great Britain (UK)
Technical Contact Country Code:              GB
Technical Contact Phone Number:              +1.13473285225
Technical Contact Email:                     deanwestbury@pookmail.com
Name Server:                                 NS1.RAPERCONNN.BIZ
Name Server:                                 NS2.RAPERCONNN.BIZ
Created by Registrar:                        NETWORK SOLUTIONS INC.
Last Updated by Registrar:                   NETWORK SOLUTIONS INC.
Domain Registration Date:                    Fri Jul 01 13:15:42 GMT 2005
Domain Expiration Date:                      Fri Jun 30 23:59:59 GMT 2006
Domain Last Updated Date:                    Tue Jul 26 16:25:34 GMT 2005

&gt;&gt;&gt;&gt; Whois database was last updated on: Sun Aug 14 23:05:04 GMT 2005 &lt;&lt;&lt;&lt;

  &lt;i&gt;(NeuLevel, Inc. disclaimers and terms omitted.)&lt;/i&gt;
&lt;/code&gt;&lt;/pre&gt;&lt;/blockquote&gt;

&lt;p&gt;I wonder if this problem could be attacked by going to the sponsoring registrar for the DNS, Network Solutions?  

&lt;p&gt;I hope this helps.   -David
&lt;/p&gt;&lt;/p&gt;&lt;/p&gt;&lt;/p&gt;

&lt;p&gt;&lt;/html&gt;&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p><html>
Perhaps a little more information would be helpful?  I just got an spam that appears to be from this character (see</html></p>

<blockquote cite="">&lt;<a href="http://www.spamcop.net/sc?id=z796153090z5b763850c042ec7bed4cb0040cd5d220z">http://www.spamcop.net/sc?id=z796153090z5b763850c042ec7bed4cb0040cd5d220z</a>&gt;
</blockquote>

<p>which leads to a website:</p>

<blockquote cite="">&lt;gggthx.bcunbrentmh.com&gt;.
</blockquote>

<p>Doing a little &#8216;nslookup&#8217; digging, I find that bcunbrentmh.com&#8217;s authority DNS records are at <b>ns0.mammonnnjff.com</b> and <b>ns1.mammonnnjff.com</b>.  When I set my DNS server to ns0.mammonnnjff.com, and look up gggthx.bcunbrentmh.com, it then claims there that the DNS authority records are <b>ns1.raperconnn.biz</b> and <b>ns1.raperconnn.biz</b>.</p>

<p>Interesting name, &#8216;raperconnn&#8217;??  <img src='http://vaxcave.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> 

</p><p>Further, gggthx.bcunbrentmh.com having an IPv4 address of <b>222.47.78.229</b> == <em>the IPv4 address of ns1.raperconnn.biz == the IPv4 address of ns0.mammonnnjff.com!!</em>

<blockquote><pre><code>
&gt; set debug
&gt; gggthx.bcunbrentmh.com
Server:  ns0.mammonnnjff.com
Address:  <b>222.47.78.229</b>

;; res_mkquery(0, gggthx.bcunbrentmh.com, 1, 1)
------------
Got answer:
    HEADER:
        opcode = QUERY, id = 61633, rcode = NOERROR
        header flags:  response, auth. answer, want recursion
        questions = 1,  answers = 1,  authority records = 2,  additional = 2

    QUESTIONS:
        gggthx.bcunbrentmh.com, type = A, class = IN
    ANSWERS:
    -&gt;  gggthx.bcunbrentmh.com
        internet address = <b>222.47.78.229</b>
        ttl = 259200 (3D)
    AUTHORITY RECORDS:
    -&gt;  bcunbrentmh.com
        nameserver = ns1.raperconnn.biz
        ttl = 259200 (3D)
    -&gt;  bcunbrentmh.com
        nameserver = ns2.raperconnn.biz
        ttl = 259200 (3D)
    ADDITIONAL RECORDS:
    -&gt;  ns1.raperconnn.biz
        internet address = <b>222.47.78.229</b>
        ttl = 259200 (3D)
    -&gt;  ns2.raperconnn.biz
        internet address = 221.11.133.68
        ttl = 259200 (3D)

------------
Name:    gggthx.bcunbrentmh.com
Address:  <b>222.47.78.229</b>
</code></pre></blockquote> guess what ya get when you do a whois on <b>raperconnn.biz</b>:

<blockquote><pre><code>
[Querying whois.neulevel.biz]
[whois.neulevel.biz]
Domain Name:                                 RAPERCONNN.BIZ
Domain ID:                                   D10251032-BIZ
Sponsoring Registrar:                        NETWORK SOLUTIONS INC.
Sponsoring Registrar IANA ID:                2
Domain Status:                               clientTransferProhibited
Registrant ID:                               39651578
Registrant Name:                             DEAN WESTBURY
Registrant Address1:                         177 Beak Street
Registrant City:                             London
Registrant State/Province:                   GB
Registrant Postal Code:                      W1F 9DB
Registrant Country:                          Great Britain (UK)
Registrant Country Code:                     GB
Registrant Phone Number:                     +1.13473285225
Registrant Email:                            <a href="mailto:&#x6A;&#101;&#x66;&#102;&#95;&#x72;&#101;&#x73;&#x61;&#108;&#x65;&#x5F;&#x64;&#111;&#x6D;&#x61;&#105;&#x6E;&#x7A;&#x40;&#121;&#97;&#104;&#x6F;&#111;&#x2E;&#99;o.uk">&#x6A;&#x65;&#102;&#x66;&#x5F;&#x72;&#x65;&#x73;&#x61;&#108;&#x65;&#x5F;&#100;&#111;&#109;&#x61;&#x69;&#x6E;&#x7A;&#x40;&#x79;&#97;&#104;&#x6F;&#111;&#46;&#99;o.uk</a>
Administrative Contact ID:                   39723119
Administrative Contact Name:                 Dean Westbury
Administrative Contact Organization:         NA
Administrative Contact Address1:             77 Beak Street, #118
Administrative Contact City:                 London
Administrative Contact State/Province:       GB
Administrative Contact Postal Code:          w1f9db
Administrative Contact Country:              Great Britain (UK)
Administrative Contact Country Code:         GB
Administrative Contact Phone Number:         +1.13473285225
Administrative Contact Email:                <a href="mailto:&#100;&#101;&#97;&#x6E;&#x77;&#101;&#x73;&#116;&#x62;&#x75;&#x72;&#121;&#x40;&#112;&#111;&#111;&#107;&#x6D;&#97;&#105;&#108;&#46;&#x63;om">&#x64;&#101;&#x61;&#110;&#x77;&#101;&#115;&#x74;&#x62;&#117;&#x72;&#121;&#64;&#x70;&#111;&#111;&#x6B;&#109;&#97;&#x69;&#x6C;&#46;&#99;om</a>
Billing Contact ID:                          39651578
Billing Contact Name:                        DEAN WESTBURY
Billing Contact Address1:                    177 Beak Street
Billing Contact City:                        London
Billing Contact State/Province:              GB
Billing Contact Postal Code:                 W1F 9DB
Billing Contact Country:                     Great Britain (UK)
Billing Contact Country Code:                GB
Billing Contact Phone Number:                +1.13473285225
Billing Contact Email:                       <a href="mailto:&#x6A;&#x65;&#x66;&#102;&#95;&#114;&#101;&#x73;&#97;&#108;&#x65;&#95;&#100;&#111;&#109;&#97;&#105;&#x6E;&#x7A;&#x40;&#x79;&#x61;&#104;&#111;&#111;&#46;&#99;o.uk">&#106;&#x65;&#x66;&#x66;&#95;&#x72;&#101;&#x73;&#x61;&#x6C;&#x65;&#x5F;&#x64;&#111;&#x6D;&#x61;&#105;&#110;&#122;&#64;&#121;&#97;&#104;&#111;&#x6F;&#46;&#99;o.uk</a>
Technical Contact ID:                        39723119
Technical Contact Name:                      Dean Westbury
Technical Contact Organization:              NA
Technical Contact Address1:                  77 Beak Street, #118
Technical Contact City:                      London
Technical Contact State/Province:            GB
Technical Contact Postal Code:               w1f9db
Technical Contact Country:                   Great Britain (UK)
Technical Contact Country Code:              GB
Technical Contact Phone Number:              +1.13473285225
Technical Contact Email:                     <a href="mailto:&#x64;&#x65;&#97;&#110;&#119;&#x65;&#115;&#x74;&#98;&#x75;&#114;&#x79;&#x40;&#x70;&#x6F;&#111;&#107;&#x6D;&#97;&#105;&#x6C;&#46;&#99;om">&#100;&#x65;&#97;&#x6E;&#x77;&#101;&#x73;&#x74;&#98;&#x75;&#x72;&#x79;&#x40;&#x70;&#x6F;&#111;&#107;&#109;&#97;&#x69;&#x6C;&#x2E;&#99;om</a>
Name Server:                                 NS1.RAPERCONNN.BIZ
Name Server:                                 NS2.RAPERCONNN.BIZ
Created by Registrar:                        NETWORK SOLUTIONS INC.
Last Updated by Registrar:                   NETWORK SOLUTIONS INC.
Domain Registration Date:                    Fri Jul 01 13:15:42 GMT 2005
Domain Expiration Date:                      Fri Jun 30 23:59:59 GMT 2006
Domain Last Updated Date:                    Tue Jul 26 16:25:34 GMT 2005

&gt;&gt;&gt;&gt; Whois database was last updated on: Sun Aug 14 23:05:04 GMT 2005 &lt;&lt;&lt;&lt;

  <i>(NeuLevel, Inc. disclaimers and terms omitted.)</i>
</code></pre></blockquote>

</p><p>I wonder if this problem could be attacked by going to the sponsoring registrar for the DNS, Network Solutions?  

</p><p>I hope this helps.   -David
</p>

<p></p>]]></content:encoded>
	</item>
	<item>
		<title>By: AxsDeny</title>
		<link>http://vaxcave.com/2005/07/06/hijacked-by-spam/comment-page-1/#comment-5258</link>
		<dc:creator>AxsDeny</dc:creator>
		<pubDate>Sat, 13 Aug 2005 12:14:34 +0000</pubDate>
		<guid isPermaLink="false">/?p=345#comment-5258</guid>
		<description>&lt;p&gt;It has tapered off, but I still get at least 20 failure messages a day. This has been going on for at least 5 weeks.&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>It has tapered off, but I still get at least 20 failure messages a day. This has been going on for at least 5 weeks.</p>]]></content:encoded>
	</item>
	<item>
		<title>By: Another Hijack Victim</title>
		<link>http://vaxcave.com/2005/07/06/hijacked-by-spam/comment-page-1/#comment-5257</link>
		<dc:creator>Another Hijack Victim</dc:creator>
		<pubDate>Fri, 12 Aug 2005 22:38:51 +0000</pubDate>
		<guid isPermaLink="false">/?p=345#comment-5257</guid>
		<description>&lt;p&gt;They seem to have hijacked my domain name as well for their fake FROM headers.  The web addresses in the message have domain names that trace back to the same Jeff Westbury, IP of web server 221.11.133.68 is in China.&lt;/p&gt;

&lt;p&gt;Did it ever stop?  Did you somehow get them to stop?&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>They seem to have hijacked my domain name as well for their fake FROM headers.  The web addresses in the message have domain names that trace back to the same Jeff Westbury, IP of web server 221.11.133.68 is in China.</p>

<p>Did it ever stop?  Did you somehow get them to stop?</p>]]></content:encoded>
	</item>
	<item>
		<title>By: Derek</title>
		<link>http://vaxcave.com/2005/07/06/hijacked-by-spam/comment-page-1/#comment-5256</link>
		<dc:creator>Derek</dc:creator>
		<pubDate>Fri, 12 Aug 2005 02:08:54 +0000</pubDate>
		<guid isPermaLink="false">/?p=345#comment-5256</guid>
		<description>&lt;p&gt;Well&lt;/p&gt;

&lt;p&gt;Today is the 12th of August.&lt;/p&gt;

&lt;p&gt;ICANN has done njada. But then ICANN has of late become nothing more than a lot of hot air. Despite concrete proof of wrong doings by registrars, they do zip. $$$$$$?&lt;/p&gt;

&lt;p&gt;Registrars have done njada. $$$$$$?&lt;/p&gt;

&lt;p&gt;Party is Russian, in fact it is Leo Kuvayev.&lt;/p&gt;

&lt;p&gt;Anybody in Massachusetts, you may wish to phone up Attorney General Tom Reilly&#039;s Hotline. &quot;Attorney General Reilly&#039;s Consumer Hotline at (617) 727-8400&quot;&lt;/p&gt;

&lt;p&gt;The Russian &quot;Mr Westbury&quot; New Yorker may have a bit of a suprise comming.&lt;/p&gt;

&lt;p&gt;http://www.ago.state.ma.us/sp.cfm?pageid=986&amp;id=1426&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>Well</p>

<p>Today is the 12th of August.</p>

<p>ICANN has done njada. But then ICANN has of late become nothing more than a lot of hot air. Despite concrete proof of wrong doings by registrars, they do zip. $$$$$$?</p>

<p>Registrars have done njada. $$$$$$?</p>

<p>Party is Russian, in fact it is Leo Kuvayev.</p>

<p>Anybody in Massachusetts, you may wish to phone up Attorney General Tom Reilly&#8217;s Hotline. &#8220;Attorney General Reilly&#8217;s Consumer Hotline at (617) 727-8400&#8243;</p>

<p>The Russian &#8220;Mr Westbury&#8221; New Yorker may have a bit of a suprise comming.</p>

<p><a href="http://www.ago.state.ma.us/sp.cfm?pageid=986&amp;id=1426" rel="nofollow">http://www.ago.state.ma.us/sp.cfm?pageid=986&amp;id=1426</a></p>]]></content:encoded>
	</item>
	<item>
		<title>By: kjz</title>
		<link>http://vaxcave.com/2005/07/06/hijacked-by-spam/comment-page-1/#comment-5250</link>
		<dc:creator>kjz</dc:creator>
		<pubDate>Fri, 05 Aug 2005 18:21:01 +0000</pubDate>
		<guid isPermaLink="false">/?p=345#comment-5250</guid>
		<description>&lt;p&gt;You can also use the Registrar Problem Report Form at Internic:&lt;/p&gt;

&lt;p&gt;http://reports.internic.net/cgi/registrars/problem-report.cgi&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;kjz&lt;/li&gt;
&lt;/ul&gt;
</description>
		<content:encoded><![CDATA[<p>You can also use the Registrar Problem Report Form at Internic:</p>

<p><a href="http://reports.internic.net/cgi/registrars/problem-report.cgi" rel="nofollow">http://reports.internic.net/cgi/registrars/problem-report.cgi</a></p>

<ul>
<li>kjz</li>
</ul>]]></content:encoded>
	</item>
	<item>
		<title>By: Bill Levinson</title>
		<link>http://vaxcave.com/2005/07/06/hijacked-by-spam/comment-page-1/#comment-5249</link>
		<dc:creator>Bill Levinson</dc:creator>
		<pubDate>Fri, 05 Aug 2005 15:58:16 +0000</pubDate>
		<guid isPermaLink="false">/?p=345#comment-5249</guid>
		<description>&lt;p&gt;Derek,&lt;/p&gt;

&lt;p&gt;Valid or not, he listed jeffwestbury@pookmail.com as his contact address. I sent an E-mail to that address placing him ON NOTICE under the provisions of the CAN-SPAM Act that my address is off limits to spam and that I would file criminal (felony?) charges against him if the harassment continued. I also used the &quot;Remove Me&quot; feature on two of his pharmacy pages and took screen shots (with the date) to use as evidence in filing CAN-SPAM charges.&lt;/p&gt;

&lt;p&gt;I also wrote to his registrars and accused him of having fraudulent registration information because 1.3473285225 cannot be reached in the United Kingdom, where he says he is registered. (I did try to place the international call twice.) Only later did I learn that the number is in the U.S. but that is his problem; a reasonable person would not try to place a domestic call to the United Kingdom.&lt;/p&gt;

&lt;p&gt;When I called 1.3473285225, I got someone with a very thick accent (Russian?) who said he was not responsible for the spam and that he only sold Web space to customers, or something to that effect. I reminded him that, as he is actually in the U.S., he is subject to the jurisdiction of CAN-SPAM.&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>Derek,</p>

<p>Valid or not, he listed <a href="mailto:&#106;&#101;&#102;&#102;&#119;&#101;&#115;&#x74;&#98;&#117;&#114;&#x79;&#x40;&#112;&#x6F;&#111;&#x6B;&#109;&#97;&#105;&#x6C;&#46;&#x63;om">&#106;&#101;&#102;&#x66;&#119;&#x65;&#x73;&#116;&#x62;&#x75;&#x72;&#121;&#64;&#x70;&#x6F;&#x6F;&#107;&#x6D;&#x61;&#105;&#108;&#46;&#x63;om</a> as his contact address. I sent an E-mail to that address placing him ON NOTICE under the provisions of the CAN-SPAM Act that my address is off limits to spam and that I would file criminal (felony?) charges against him if the harassment continued. I also used the &#8220;Remove Me&#8221; feature on two of his pharmacy pages and took screen shots (with the date) to use as evidence in filing CAN-SPAM charges.</p>

<p>I also wrote to his registrars and accused him of having fraudulent registration information because 1.3473285225 cannot be reached in the United Kingdom, where he says he is registered. (I did try to place the international call twice.) Only later did I learn that the number is in the U.S. but that is his problem; a reasonable person would not try to place a domestic call to the United Kingdom.</p>

<p>When I called 1.3473285225, I got someone with a very thick accent (Russian?) who said he was not responsible for the spam and that he only sold Web space to customers, or something to that effect. I reminded him that, as he is actually in the U.S., he is subject to the jurisdiction of CAN-SPAM.</p>]]></content:encoded>
	</item>
	<item>
		<title>By: Derek</title>
		<link>http://vaxcave.com/2005/07/06/hijacked-by-spam/comment-page-1/#comment-5241</link>
		<dc:creator>Derek</dc:creator>
		<pubDate>Fri, 29 Jul 2005 10:38:55 +0000</pubDate>
		<guid isPermaLink="false">/?p=345#comment-5241</guid>
		<description>&lt;p&gt;Mail sento the Abbacus at info@aplus.net, registrar who is regsitering Leo&#039;s domains under the name &#039;Jeff Westbury&#039;&lt;/p&gt;

&lt;hr /&gt;

&lt;p&gt;Dear Abacus Team&lt;/p&gt;

&lt;p&gt;I see you have not reacted to my previous mail on this subject.&lt;/p&gt;

&lt;p&gt;Please see ICANN&#039;s regulations on this issue. These are made very clear in your registration agreement.&lt;/p&gt;

&lt;p&gt;The registration have to be correct, else the registration is invalid.&lt;/p&gt;

&lt;p&gt;A fictitious name is not acceptable for for whois details.&lt;/p&gt;

&lt;p&gt;A valid working address is required.&lt;/p&gt;

&lt;p&gt;A valid working email address is required. By definition the type of email address given here, pookmail.com is the physical equivalent of saying &quot;put my mail in the street somehere, I will find it.&quot;&lt;/p&gt;

&lt;p&gt;This type of registration goes against everything contemplated in the requirements for a valid whois details. As such I am extremely supprised that these domains are still valid after my previous mail.&lt;/p&gt;

&lt;p&gt;Please note that you are now becomming responsible for network abuse. While this would not normally the case, by allowing your user Leo to knowingly continue using these fake details with your sponsorship in direct violation of ICANN&#039;s whois requirements, you are becoming part of a problem. It is also not that you can say you had to verify the fact given. This can be done in ten minutes on the internet, especially if you have the details as submitted to ICANN. It is just a case of verifying it.&lt;/p&gt;

&lt;p&gt;Maybe I should ensure that all abuse reports (spam, hijacking etc) get copied you for the domains you are sponsoring. Is this the evidence you require? I am sure a few million internet users will appreciate the opportunity of telling you exactly what Leo is doing with the domains he has registered under the alias &quot;Jeff Westbury&quot;. Based on this mail, you can not then hide behinf &quot;We are not responsible for the usage&quot;. If you know the details to be fake and allow the abuse - you are responsible!&lt;/p&gt;

&lt;p&gt;I am also sending a mail to Attorney General Tom Reilly&#039;s office on this issue. He has more than an axe to grind with your client. It is up to you to decide if you wish to be part of this fight ....&lt;/p&gt;

&lt;p&gt;Best regards&lt;/p&gt;

&lt;p&gt;D Smythe&lt;/p&gt;

&lt;hr /&gt;

&lt;p&gt;R157-LRMS    Abacus America, Inc. dba Names4ever.com&lt;/p&gt;

&lt;p&gt;DFMARTINOEIF.COM
DECRETIVEFD.INFO
EMBDENDKEIJ.INFO
FCVOMITUREGG.NET
GJPOALIKELC.COM
GJPOALIKELC.COM
IGSTATDLYDM.INFO
JJPLANULARCH.INFO&lt;/p&gt;

&lt;h2&gt;UPWHIRCADMH.NET&lt;/h2&gt;

&lt;p&gt;NO SPAM wrote:&lt;/p&gt;

&lt;p&gt;&lt; Dear Abacus team
&lt;
&lt; The domain FCVOMITUREGG.NET refers - bad whois.
&lt;
&lt; Below also communication to ICANN on this issue that explains the situation. Unfortunately you are one of these victims.
&lt;
&lt; Please act as per ttp://www.icann.org/announcements/advisory-03apr03.htm
&lt;
&lt; Best regards
&lt;
&lt; D Smythe
&lt;
&lt; --------------------------------------------------------------
&lt; Domain name: fcvomituregg.net
&lt;
&lt; Registrant:
&lt;    JEFF westbury (AAHQ4) jeffwestbury@pookmail.com
&lt;    77 beak street #118
&lt;    London,    GB    w1f9db
&lt;    United Kingdom
&lt;    Phone: (1)3473285225 x
&lt;
&lt;    Domain Name: FCVOMITUREGG.NET
&lt;    Registrar: ABACUS AMERICA, INC. DBA NAMES4EVER
&lt;    Whois Server: whois.names4ever.com
&lt;    Referral URL: http://www.names4ever.com
&lt;    Name Server: NS1.RAPERCONNN.BIZ
&lt;    Name Server: NS2.RAPERCONNN.BIZ
&lt;    Status: ACTIVE
&lt;    Updated Date: 21-jul-2005
&lt;    Creation Date: 21-jul-2005
&lt;    Expiration Date: 21-jul-2006
&lt;&lt;/p&gt;

&lt;p&gt;This was followed by mail from Eugeen to ICANN&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>Mail sento the Abbacus at <a href="mailto:&#x69;&#110;&#102;&#111;&#64;&#97;&#112;&#108;&#117;&#x73;&#46;&#110;et">&#x69;&#x6E;&#x66;&#111;&#x40;&#97;&#x70;&#x6C;&#x75;&#115;&#46;&#110;et</a>, registrar who is regsitering Leo&#8217;s domains under the name &#8216;Jeff Westbury&#8217;</p>

<hr />

<p>Dear Abacus Team</p>

<p>I see you have not reacted to my previous mail on this subject.</p>

<p>Please see ICANN&#8217;s regulations on this issue. These are made very clear in your registration agreement.</p>

<p>The registration have to be correct, else the registration is invalid.</p>

<p>A fictitious name is not acceptable for for whois details.</p>

<p>A valid working address is required.</p>

<p>A valid working email address is required. By definition the type of email address given here, pookmail.com is the physical equivalent of saying &#8220;put my mail in the street somehere, I will find it.&#8221;</p>

<p>This type of registration goes against everything contemplated in the requirements for a valid whois details. As such I am extremely supprised that these domains are still valid after my previous mail.</p>

<p>Please note that you are now becomming responsible for network abuse. While this would not normally the case, by allowing your user Leo to knowingly continue using these fake details with your sponsorship in direct violation of ICANN&#8217;s whois requirements, you are becoming part of a problem. It is also not that you can say you had to verify the fact given. This can be done in ten minutes on the internet, especially if you have the details as submitted to ICANN. It is just a case of verifying it.</p>

<p>Maybe I should ensure that all abuse reports (spam, hijacking etc) get copied you for the domains you are sponsoring. Is this the evidence you require? I am sure a few million internet users will appreciate the opportunity of telling you exactly what Leo is doing with the domains he has registered under the alias &#8220;Jeff Westbury&#8221;. Based on this mail, you can not then hide behinf &#8220;We are not responsible for the usage&#8221;. If you know the details to be fake and allow the abuse &#8211; you are responsible!</p>

<p>I am also sending a mail to Attorney General Tom Reilly&#8217;s office on this issue. He has more than an axe to grind with your client. It is up to you to decide if you wish to be part of this fight &#8230;.</p>

<p>Best regards</p>

<p>D Smythe</p>

<hr />

<p>R157-LRMS    Abacus America, Inc. dba Names4ever.com</p>

<p>DFMARTINOEIF.COM
DECRETIVEFD.INFO
EMBDENDKEIJ.INFO
FCVOMITUREGG.NET
GJPOALIKELC.COM
GJPOALIKELC.COM
IGSTATDLYDM.INFO
JJPLANULARCH.INFO</p>

<h2>UPWHIRCADMH.NET</h2>

<p>NO SPAM wrote:</p>

<p>&lt; Dear Abacus team
&lt;
&lt; The domain FCVOMITUREGG.NET refers &#8211; bad whois.
&lt;
&lt; Below also communication to ICANN on this issue that explains the situation. Unfortunately you are one of these victims.
&lt;
&lt; Please act as per ttp://www.icann.org/announcements/advisory-03apr03.htm
&lt;
&lt; Best regards
&lt;
&lt; D Smythe
&lt;
&lt; &#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8211;
&lt; Domain name: fcvomituregg.net
&lt;
&lt; Registrant:
&lt;    JEFF westbury (AAHQ4) <a href="mailto:&#x6A;&#x65;&#102;&#x66;&#119;&#x65;&#x73;&#116;&#x62;&#x75;&#114;&#121;&#x40;&#x70;&#111;&#111;&#107;&#109;&#97;&#105;&#108;&#46;&#99;om">&#106;&#x65;&#x66;&#x66;&#119;&#101;&#115;&#x74;&#x62;&#117;&#114;&#x79;&#x40;&#x70;&#111;&#x6F;&#x6B;&#x6D;&#x61;&#x69;&#x6C;&#x2E;&#99;om</a>
&lt;    77 beak street #118
&lt;    London,    GB    w1f9db
&lt;    United Kingdom
&lt;    Phone: (1)3473285225 x
&lt;
&lt;    Domain Name: FCVOMITUREGG.NET
&lt;    Registrar: ABACUS AMERICA, INC. DBA NAMES4EVER
&lt;    Whois Server: whois.names4ever.com
&lt;    Referral URL: <a href="http://www.names4ever.com" rel="nofollow">http://www.names4ever.com</a>
&lt;    Name Server: NS1.RAPERCONNN.BIZ
&lt;    Name Server: NS2.RAPERCONNN.BIZ
&lt;    Status: ACTIVE
&lt;    Updated Date: 21-jul-2005
&lt;    Creation Date: 21-jul-2005
&lt;    Expiration Date: 21-jul-2006
&lt;</p>

<p>This was followed by mail from Eugeen to ICANN</p>]]></content:encoded>
	</item>
	<item>
		<title>By: Spam Hater</title>
		<link>http://vaxcave.com/2005/07/06/hijacked-by-spam/comment-page-1/#comment-5236</link>
		<dc:creator>Spam Hater</dc:creator>
		<pubDate>Tue, 26 Jul 2005 16:25:30 +0000</pubDate>
		<guid isPermaLink="false">/?p=345#comment-5236</guid>
		<description>&lt;p&gt;Got a &quot;Visit our NEW PHARMACY E-Store&quot; spam from this guy today 7/26/05 @ 12:02pm EST&lt;/p&gt;

&lt;p&gt;From: &quot;Cranny V. Peddled&quot; &lt;overuse @fiddlechicks.com&gt;
Return-Path: &lt;overuse @fiddlechicks.com&gt;
X-ClientAddr: 85.64.18.48
Received: from 85-64-18-48.barak-online.net&lt;/p&gt;

&lt;p&gt;HTML Links pointing to: lhperdixnd.com
Whois of lhperdixnd.com is:&lt;/p&gt;

&lt;p&gt;Jeff WESTBURY (WESTBU12-BMN-PE)
77 beak street #118
w1f9db LONDON
UNITED KINGDOM 
phone: 1.3473285225
e-mail: jeff_resale_domains@yahoo.co.uk&lt;/overuse&gt;&lt;/overuse&gt;&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>Got a &#8220;Visit our NEW PHARMACY E-Store&#8221; spam from this guy today 7/26/05 @ 12:02pm EST</p>

<p>From: &#8220;Cranny V. Peddled&#8221; <overuse @fiddlechicks.com>
Return-Path: </overuse><overuse @fiddlechicks.com>
X-ClientAddr: 85.64.18.48
Received: from 85-64-18-48.barak-online.net</overuse></p>

<p>HTML Links pointing to: lhperdixnd.com
Whois of lhperdixnd.com is:</p>

<p>Jeff WESTBURY (WESTBU12-BMN-PE)
77 beak street #118
w1f9db LONDON
UNITED KINGDOM 
phone: 1.3473285225
e-mail: <a href="mailto:&#x6A;&#x65;&#x66;&#102;&#x5F;&#x72;&#101;&#115;&#x61;&#x6C;&#101;&#x5F;&#100;&#x6F;&#x6D;&#x61;&#x69;&#110;&#x73;&#64;&#x79;&#x61;&#104;&#111;&#111;&#46;&#99;o.uk">&#106;&#x65;&#x66;&#102;&#x5F;&#x72;&#101;&#115;&#x61;&#x6C;&#101;&#x5F;&#x64;&#111;&#x6D;&#97;&#105;&#110;&#115;&#x40;&#x79;&#x61;&#104;&#111;&#111;&#x2E;&#99;o.uk</a></p>]]></content:encoded>
	</item>
	<item>
		<title>By: Sol</title>
		<link>http://vaxcave.com/2005/07/06/hijacked-by-spam/comment-page-1/#comment-5226</link>
		<dc:creator>Sol</dc:creator>
		<pubDate>Sun, 24 Jul 2005 15:43:45 +0000</pubDate>
		<guid isPermaLink="false">/?p=345#comment-5226</guid>
		<description>&lt;h2&gt;Mail to Mail Boxes etc. Reponse, if any, to follow.&lt;/h2&gt;

&lt;p&gt;Dear Mail Boxes Etc team&lt;/p&gt;

&lt;p&gt;A party, believed to be Leo Kuvayev based on evidence, is using the address
  Westbury, Jeff
  77 Beak Street, #118
  London, GB w1f9db
  GB&lt;/p&gt;

&lt;p&gt;I need to know if there is a Jeff Westbury renting such an address, or if this is incorrect (ie a fake mail address)&lt;/p&gt;

&lt;p&gt;The party I am seeking details on is repsonsible for various forms of fraud:
  Using email addresses without the permission of the owner,
  selling illegal pirated software via internet downloads (Microsoft, Macromedia, Adobe, Symantec, Corel etc)
  selling drugs illegally
  internet pornography and exploitation
  etc etc&lt;/p&gt;

&lt;p&gt;All this can be evidenced by doing a search via your favourite internet search engine, example:
http://www.google.com/search?hl=en&amp;lr=&amp;q=Jeff+Westbury+spam&amp;btnG=Search&lt;/p&gt;

&lt;p&gt;Additionally, this party is believed to be Leo Kuvayev: 
http://www.spamhaus.org/rokso/evidence.lasso?rokso_id=ROK5278
Additional info also exists that prooves this info to be correct.&lt;/p&gt;

&lt;p&gt;More info on Leo Kuvayev and his legal issues:
&quot;AG REILLY FILES LAWSUIT, OBTAINS EMERGENCY ORDER SHUTTING DOWN INTERNET SPAM GANG BELIEVED TO BE ONE OF THE WORLD’S LARGEST SPAM OPERATIONS&quot;
http://www.ago.state.ma.us/sp.cfm?pageid=986&amp;id=1416
Also
http://www.ago.state.ma.us/sp.cfm?pageid=986&amp;id=1426&lt;/p&gt;

&lt;p&gt;Awaiting your reply.&lt;/p&gt;

&lt;p&gt;Best regards&lt;/p&gt;

&lt;p&gt;Sol&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<h2>Mail to Mail Boxes etc. Reponse, if any, to follow.</h2>

<p>Dear Mail Boxes Etc team</p>

<p>A party, believed to be Leo Kuvayev based on evidence, is using the address
  Westbury, Jeff
  77 Beak Street, #118
  London, GB w1f9db
  GB</p>

<p>I need to know if there is a Jeff Westbury renting such an address, or if this is incorrect (ie a fake mail address)</p>

<p>The party I am seeking details on is repsonsible for various forms of fraud:
  Using email addresses without the permission of the owner,
  selling illegal pirated software via internet downloads (Microsoft, Macromedia, Adobe, Symantec, Corel etc)
  selling drugs illegally
  internet pornography and exploitation
  etc etc</p>

<p>All this can be evidenced by doing a search via your favourite internet search engine, example:
<a href="http://www.google.com/search?hl=en&amp;lr=&amp;q=Jeff+Westbury+spam&amp;btnG=Search" rel="nofollow">http://www.google.com/search?hl=en&amp;lr=&amp;q=Jeff+Westbury+spam&amp;btnG=Search</a></p>

<p>Additionally, this party is believed to be Leo Kuvayev: 
<a href="http://www.spamhaus.org/rokso/evidence.lasso?rokso_id=ROK5278" rel="nofollow">http://www.spamhaus.org/rokso/evidence.lasso?rokso_id=ROK5278</a>
Additional info also exists that prooves this info to be correct.</p>

<p>More info on Leo Kuvayev and his legal issues:
&#8220;AG REILLY FILES LAWSUIT, OBTAINS EMERGENCY ORDER SHUTTING DOWN INTERNET SPAM GANG BELIEVED TO BE ONE OF THE WORLD’S LARGEST SPAM OPERATIONS&#8221;
<a href="http://www.ago.state.ma.us/sp.cfm?pageid=986&amp;id=1416" rel="nofollow">http://www.ago.state.ma.us/sp.cfm?pageid=986&amp;id=1416</a>
Also
<a href="http://www.ago.state.ma.us/sp.cfm?pageid=986&amp;id=1426" rel="nofollow">http://www.ago.state.ma.us/sp.cfm?pageid=986&amp;id=1426</a></p>

<p>Awaiting your reply.</p>

<p>Best regards</p>

<p>Sol</p>]]></content:encoded>
	</item>
	<item>
		<title>By: Eugene</title>
		<link>http://vaxcave.com/2005/07/06/hijacked-by-spam/comment-page-1/#comment-5225</link>
		<dc:creator>Eugene</dc:creator>
		<pubDate>Sun, 24 Jul 2005 14:37:22 +0000</pubDate>
		<guid isPermaLink="false">/?p=345#comment-5225</guid>
		<description>&lt;p&gt;Additional info on the matter. In the mean time, use http://wdprs.icann.org/ to lart away. Just keep it factual. Remember The registrar is NOT responsible for his client&#039;s internet abuse, only to ensure that the whois is correct. If it is bad, he can boot him. See http://www.icann.org/announcements/advisory-03apr03.htm&lt;/p&gt;

&lt;p&gt;Mail sent to ICANN on issue. Leo has hundreds upon hundreds of domains, all with bad whois.&lt;/p&gt;

&lt;hr /&gt;

&lt;p&gt;Dear ICANN team&lt;/p&gt;

&lt;p&gt;A situation has arisen that it appears is not covered under the normal procedures for domain registrations.&lt;/p&gt;

&lt;p&gt;I do believe that this calls for some type of alert to registrars. This type of whois abuse is also becoming more commonplace.&lt;/p&gt;

&lt;p&gt;A party, suspected to be Leo Kuvayev, is registering domains by the hundreds, literally, and using the for net abuse (spam with all the other associated net abuses).&lt;/p&gt;

&lt;p&gt;The registration details reflect a mailbox in the UK, but this mailbox is a mail forwarding company.&lt;/p&gt;

&lt;p&gt;He uses the name of Jeff Westbury, but this is obviously not real.&lt;/p&gt;

&lt;p&gt;He uses a USA tel number. The party answering the phone at 13473285225 has a strong Russian accent, acknowledging that he is Jeff Westbury?? However, he says he has sold the domain in question and like. Also note the change of whois details for ADDADCBAL.COM:&lt;/p&gt;

&lt;p&gt;Administrative Contact:
 Perenskiy, Anatoliy jeffwestbury@pookmail.com
 Lugskaya uliza 4/1, 31
 Saint Peterburg, LA 195265
 RU
 13473285225&lt;/p&gt;

&lt;p&gt;... is now&lt;/p&gt;

&lt;p&gt;Administrative Contact:
 Westbury, Jeff jeffwestbury@pookmail.com
 77 Beak Street, #118
 London, GB w1f9db
 GB
 1.3473285225&lt;/p&gt;

&lt;p&gt;As regards this email address: The homepage at http://www.pookmail.com describes usage as:
&quot;
    * Step 1
      Instead of giving your real email address to every website on Earth, just make up an imaginary name for @pookmail.com.
      Example: dontbotherme@pookmail.com&lt;/p&gt;

&lt;pre&gt;&lt;code&gt;* Step 2
  Wait for your email to arrive.

* Step 3
  Login to PookMail.com by typing your imaginary email name (dontbotherme) into the login form, and click GO

* Step 4
  After 24 hours, the email associated with your login name will be cleaned from the system.
&lt;/code&gt;&lt;/pre&gt;

&lt;p&gt;&quot;&lt;/p&gt;

&lt;p&gt;Based on the massive number of domains involved, spanning numerous registrars, the WDPRS mechanism as at  http://wdprs.icann.org/ does not work.&lt;/p&gt;

&lt;p&gt;As such we currently have domains without any accountability. See:
http://vaxcave.com/index.php?p=345
http://veino.com/&lt;/p&gt;

&lt;p&gt;Please attend as a matter of urgency.&lt;/p&gt;

&lt;p&gt;Thank you.&lt;/p&gt;

&lt;p&gt;D Smythe&lt;/p&gt;

&lt;p&gt;Sample of domain names:
ADDADCBAL.COM
upwhircadmh.net
stagermiecc.com
rebornfgief.com (This domain cancelled during registration process after mail to Communigal)
agnosislk.com
EMBDENDKEIJ.INFO
granchdlcdm.info
PTBHPVT.COM
GRANCHDLCDM.INFO
MAMMONNNJFF.COM
ollieffmng.com
relentenfcl.info
etc etc&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>Additional info on the matter. In the mean time, use <a href="http://wdprs.icann.org/" rel="nofollow">http://wdprs.icann.org/</a> to lart away. Just keep it factual. Remember The registrar is NOT responsible for his client&#8217;s internet abuse, only to ensure that the whois is correct. If it is bad, he can boot him. See <a href="http://www.icann.org/announcements/advisory-03apr03.htm" rel="nofollow">http://www.icann.org/announcements/advisory-03apr03.htm</a></p>

<p>Mail sent to ICANN on issue. Leo has hundreds upon hundreds of domains, all with bad whois.</p>

<hr />

<p>Dear ICANN team</p>

<p>A situation has arisen that it appears is not covered under the normal procedures for domain registrations.</p>

<p>I do believe that this calls for some type of alert to registrars. This type of whois abuse is also becoming more commonplace.</p>

<p>A party, suspected to be Leo Kuvayev, is registering domains by the hundreds, literally, and using the for net abuse (spam with all the other associated net abuses).</p>

<p>The registration details reflect a mailbox in the UK, but this mailbox is a mail forwarding company.</p>

<p>He uses the name of Jeff Westbury, but this is obviously not real.</p>

<p>He uses a USA tel number. The party answering the phone at 13473285225 has a strong Russian accent, acknowledging that he is Jeff Westbury?? However, he says he has sold the domain in question and like. Also note the change of whois details for ADDADCBAL.COM:</p>

<p>Administrative Contact:
 Perenskiy, Anatoliy <a href="mailto:&#x6A;&#101;&#x66;&#x66;&#x77;&#101;&#x73;&#116;&#98;&#117;&#114;&#121;&#x40;&#x70;&#x6F;&#x6F;&#107;&#x6D;&#97;&#x69;&#108;&#x2E;&#x63;om">&#x6A;&#x65;&#102;&#102;&#x77;&#x65;&#115;&#116;&#98;&#x75;&#x72;&#121;&#64;&#x70;&#x6F;&#111;&#107;&#109;&#97;&#105;&#108;&#x2E;&#x63;om</a>
 Lugskaya uliza 4/1, 31
 Saint Peterburg, LA 195265
 RU
 13473285225</p>

<p>&#8230; is now</p>

<p>Administrative Contact:
 Westbury, Jeff <a href="mailto:&#x6A;&#101;&#x66;&#102;&#x77;&#x65;&#115;&#x74;&#98;&#x75;&#x72;&#x79;&#x40;&#112;&#111;&#x6F;&#x6B;&#x6D;&#97;&#x69;&#x6C;&#46;&#x63;om">&#x6A;&#101;&#102;&#x66;&#119;&#101;&#x73;&#116;&#98;&#x75;&#x72;&#x79;&#x40;&#112;&#x6F;&#111;&#x6B;&#x6D;&#97;&#x69;&#108;&#x2E;&#x63;om</a>
 77 Beak Street, #118
 London, GB w1f9db
 GB
 1.3473285225</p>

<p>As regards this email address: The homepage at <a href="http://www.pookmail.com" rel="nofollow">http://www.pookmail.com</a> describes usage as:
&#8221;
    * Step 1
      Instead of giving your real email address to every website on Earth, just make up an imaginary name for @pookmail.com.
      Example: <a href="mailto:&#x64;&#111;&#110;&#x74;&#98;&#x6F;&#x74;&#104;&#x65;&#x72;&#109;&#101;&#64;&#x70;&#111;&#111;&#107;&#109;&#97;&#x69;&#108;&#46;&#x63;om">&#100;&#111;&#110;&#x74;&#x62;&#111;&#116;&#104;&#x65;&#x72;&#x6D;&#101;&#x40;&#x70;&#111;&#111;&#107;&#109;&#x61;&#x69;&#108;&#x2E;&#x63;om</a></p>

<pre><code>* Step 2
  Wait for your email to arrive.

* Step 3
  Login to PookMail.com by typing your imaginary email name (dontbotherme) into the login form, and click GO

* Step 4
  After 24 hours, the email associated with your login name will be cleaned from the system.
</code></pre>

<p>&#8220;</p>

<p>Based on the massive number of domains involved, spanning numerous registrars, the WDPRS mechanism as at  <a href="http://wdprs.icann.org/" rel="nofollow">http://wdprs.icann.org/</a> does not work.</p>

<p>As such we currently have domains without any accountability. See:
<a href="http://vaxcave.com/index.php?p=345" rel="nofollow">http://vaxcave.com/index.php?p=345</a>
<a href="http://veino.com/" rel="nofollow">http://veino.com/</a></p>

<p>Please attend as a matter of urgency.</p>

<p>Thank you.</p>

<p>D Smythe</p>

<p>Sample of domain names:
ADDADCBAL.COM
upwhircadmh.net
stagermiecc.com
rebornfgief.com (This domain cancelled during registration process after mail to Communigal)
agnosislk.com
EMBDENDKEIJ.INFO
granchdlcdm.info
PTBHPVT.COM
GRANCHDLCDM.INFO
MAMMONNNJFF.COM
ollieffmng.com
relentenfcl.info
etc etc</p>]]></content:encoded>
	</item>
</channel>
</rss>
