Thứ Bảy, 30 tháng 10, 2010

Alot has been publicized regarding malicious hosts, both by myself and many others. Of course, in the cybercrime world, along with campaigns to infect you, the criminals are also fighting with each other, to out-do each other.ASs such as AlfaHost (AS50793), Ecatel (AS29073), GlobalNET (AS42560), VLineTelecom (AS39150), ALTNET-LV (AS41390), Akrino Inc (AS44571), VolgaHost (Bondarenko Dmitriy

Thứ Tư, 27 tháng 10, 2010

A while ago now, I was asked to test AnchorFree's "Hotspot Shield", to determine whether or not it did what it claimed. I've had no contact with their software or website ever since, and as such, was rather shocked this morning when an e-mail came through to an e-mail address I'd only ever used for them (was a tracked e-mail address), pointing me to a fake Adobe site.This e-mail from
I do sometimes wonder what some of the folks over at Microsoft are smoking. Sure, they're mostly obsessed with "social media" (aka social networking - YUCK!), but this does not excuse their trying to push things like this down my throat.Take Windows live Essentials 2011 for example, I'm not annoyed it's being pushed through MU (Microsoft Update), it's a Microsoft product and WLM is installed.

Thứ Hai, 25 tháng 10, 2010

hpHOSTS - UPDATED October 25th, 2010The hpHOSTS Hosts file has been updated. There is now a total of 125,886 listed hostsnames.If you are NOT using the installer, please read the included Readme.txt file for installation instructions. Enjoy! :)Latest Updated: 25/10/2010 16:00Last Verified: 24/10/2010 18:00Download hpHosts now!http://hosts-file.net/?s=Download

Thứ Sáu, 22 tháng 10, 2010

Okay, so Surftown (or the sites actual owner), have finally cleaned the first site I reported (simple-tea.dk), but what about the rest?At the time of writing this, there are hundreds of sites on 212.97.132.0/24 (Surftown IP range), and SurfTown whilst having been notified of this by myself, and others, have yet to do anything to either suspend or cleanup the sites, let alone prevent it happening
Following the recent network downtime, I am pleased to report, it appears to have now sorted itself out.Still unsure as to the exact cause, but at least it's back and stable (lasted over 24 hours now). I'm continuing to monitor it of course - just incase (seems to be one thing after another lately, so I'm obviously skeptical).

Thứ Ba, 19 tháng 10, 2010

At around 23:00 GMT London yesterday, the internet connection to the hpHosts network went down. I spoke with the ISP and was told there were no problems at either their end, or any reported problems or expected maintenance at BT's end (though BT never told them about the work they were doing last time).The connection came back around 02:15 this morning, but problems have developed with the

Thứ Năm, 14 tháng 10, 2010

A friend alerted me, after reading my blog, to a plethora of other sites on SurfTown IP space he'd found, that were also carrying malicious code.SurfTown did get back to me after my last blog, telling me it had been cleaned up but alas - it hadn't. A quick check showed the infection was very much still there, and indeed, a quick check a second ago, shows it's still there as of 15-10-2010 03:03 (

Thứ Tư, 13 tháng 10, 2010

I've no idea when this actually happened, but it seems the IWF (Internet Watch Foundation) have re-designed their website.Quite why they've done this is a mystery. However, one thing is clear - it's no longer as simple to report anything to them if you have flash/ActiveX disabled, and don't know the direct URL to the report form (it's https://www.iwf.org.uk/report by the way).Unfortunately,

Chủ Nhật, 10 tháng 10, 2010

There's two kinds of parking pages - the annoying kind, and the less annoying kind.The annoying kinds are those such as dedicated parking servers, that shove sponsored rubbish in your face, should you go to a domain that used to exist, has just been created, or has been suspended or {insert some other reason here}.The less annoying kind, are those with a plain page, and simple text telling you

Thứ Năm, 7 tháng 10, 2010

I contact a slew of domain owners, hosts and registrars each day both via e-mail and telephone, to get domains/IPs cleaned, suspended or completely nuked. The vast majority generally go something like this;1. Contact domain owner/host/registrar2. Report what was foundIn the case of domain owners, I typically also have to give advise on what's needed as far as getting it cleaned up and secured,

Thứ Sáu, 1 tháng 10, 2010

I've just had a call from a company calling themselves GFK NOP (gfknop.com), telling me they were conducting a survey on how satisfied people are with their banks or some rubbish like that. The call came from 0207890905.Now here's the problem - I'm ex-directory and TPS - which means they shouldn't have my number. When quizzed as to where they got it, I was told they obtained it using "standard