<?xml version="1.0" encoding="UTF-8"?><!-- generator="wordpress/2.0.7" -->
<rss version="2.0" 
	xmlns:content="http://purl.org/rss/1.0/modules/content/">
<channel>
	<title>Comments on: Spamblog links</title>
	<link>http://spamhuntress.com/2005/08/27/spamblog-links/</link>
	<description>Just another WordPress weblog</description>
	<pubDate>Sat, 17 May 2008 04:33:12 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.0.7</generator>

	<item>
		<title>by: Administrator</title>
		<link>http://spamhuntress.com/2005/08/27/spamblog-links/#comment-1153</link>
		<pubDate>Sun, 28 Aug 2005 19:21:24 +0000</pubDate>
		<guid>http://spamhuntress.com/2005/08/27/spamblog-links/#comment-1153</guid>
					<description>The neatest tricks are in the source code, and you need a text browser to see'em.</description>
		<content:encoded><![CDATA[<p>The neatest tricks are in the source code, and you need a text browser to see&#8217;em.
</p>
]]></content:encoded>
				</item>
	<item>
		<title>by: Lemat</title>
		<link>http://spamhuntress.com/2005/08/27/spamblog-links/#comment-1152</link>
		<pubDate>Sun, 28 Aug 2005 15:15:38 +0000</pubDate>
		<guid>http://spamhuntress.com/2005/08/27/spamblog-links/#comment-1152</guid>
					<description>I use built-in *nix whois, www.ripe.net, arin.net, apnic.net, lacnic.net. The spamcop.net is really cool stuff to look at the mail headers. The needed info is built from scratch - sometimes I enter spammers site just to look at the source code and HTTP headers and compare with other spammer's sites - the light of inwention comes to them every half year (or not much often) so it's easy to compare the tricks they use.

If you have all the evidence - for egzample 100 domain names and their IP's (much likely all in /24 netblock) - then it's time to notify search engine guys. After that find yourself a cozy place and watch their PR goes to zero.

Lately I have figured, that spammers use open-proxys and therefore they can be redirected to somewhere else (using PHP header('Location: xxx'); ) - a large file or their ISP home page will be sufficient - just grep your log files and search for IP's and referrer headers, fill a database with them and search with every request made to your guestbook/wiki/stats scripts.

Oh. BTW: Dear spammers, please figure out some new tricks, It's about time for me to get bored... ;)</description>
		<content:encoded><![CDATA[<p>I use built-in *nix whois, <a href="http://www.ripe.net," rel="nofollow">www.ripe.net,</a> arin.net, apnic.net, lacnic.net. The spamcop.net is really cool stuff to look at the mail headers. The needed info is built from scratch - sometimes I enter spammers site just to look at the source code and HTTP headers and compare with other spammer&#8217;s sites - the light of inwention comes to them every half year (or not much often) so it&#8217;s easy to compare the tricks they use.</p>
<p>If you have all the evidence - for egzample 100 domain names and their IP&#8217;s (much likely all in /24 netblock) - then it&#8217;s time to notify search engine guys. After that find yourself a cozy place and watch their PR goes to zero.</p>
<p>Lately I have figured, that spammers use open-proxys and therefore they can be redirected to somewhere else (using PHP header(&#8217;Location: xxx&#8217;); ) - a large file or their ISP home page will be sufficient - just grep your log files and search for IP&#8217;s and referrer headers, fill a database with them and search with every request made to your guestbook/wiki/stats scripts.</p>
<p>Oh. BTW: Dear spammers, please figure out some new tricks, It&#8217;s about time for me to get bored&#8230; <img src='http://spamhuntress.com/wp-includes/images/smilies/icon_wink.gif' alt=';)' class='wp-smiley' />
</p>
]]></content:encoded>
				</item>
	<item>
		<title>by: DraDomains</title>
		<link>http://spamhuntress.com/2005/08/27/spamblog-links/#comment-1150</link>
		<pubDate>Sun, 28 Aug 2005 11:56:40 +0000</pubDate>
		<guid>http://spamhuntress.com/2005/08/27/spamblog-links/#comment-1150</guid>
					<description>I think I posted in the wrong (old/archive) place so I'm sorry if this is duplicated in wrong place again but I hope to get some insight/help.  thanks.


hi:  i'm new to all this stuff, and I am not a techie -- just have a very basic understanding of this stuff (still learning) so i hope this isn't too much of a stupid newbie question, but .... what are the best tools online for de-obfuscating URLS/DNS settings, email headers, etc and ultimately finding out who really owns a website or domain name, server, site, etc?  How do you get to the root of these things?  I just came across this great blog by accident and I would really like to know better how to track these creeps down who run a lot of these fly-by-night sites and operations, not just the spam, but that too, so they can be reported, identified, shared with anti-spam sites, etc.

I noticed that there are sites that host sites that host sites like leap-frog or hop-scotch or something.  They start at one place and end at an entirely different but are linked somehow, but I don't know if I'm checking the right information or using the right tools.  I would really appreciate feedback on the best tools and places to use (and where / how to understand all the terms and the tricks I'm missing).  I have been using Whois.sc and DNSstuff.com to look up these jerks.  Where else do I need to look and to learn?  

Thank you so much.

Moderator: Removed the URL. Too commercial</description>
		<content:encoded><![CDATA[<p>I think I posted in the wrong (old/archive) place so I&#8217;m sorry if this is duplicated in wrong place again but I hope to get some insight/help.  thanks.</p>
<p>hi:  i&#8217;m new to all this stuff, and I am not a techie &#8212; just have a very basic understanding of this stuff (still learning) so i hope this isn&#8217;t too much of a stupid newbie question, but &#8230;. what are the best tools online for de-obfuscating URLS/DNS settings, email headers, etc and ultimately finding out who really owns a website or domain name, server, site, etc?  How do you get to the root of these things?  I just came across this great blog by accident and I would really like to know better how to track these creeps down who run a lot of these fly-by-night sites and operations, not just the spam, but that too, so they can be reported, identified, shared with anti-spam sites, etc.</p>
<p>I noticed that there are sites that host sites that host sites like leap-frog or hop-scotch or something.  They start at one place and end at an entirely different but are linked somehow, but I don&#8217;t know if I&#8217;m checking the right information or using the right tools.  I would really appreciate feedback on the best tools and places to use (and where / how to understand all the terms and the tricks I&#8217;m missing).  I have been using Whois.sc and DNSstuff.com to look up these jerks.  Where else do I need to look and to learn?  </p>
<p>Thank you so much.</p>
<p>Moderator: Removed the URL. Too commercial
</p>
]]></content:encoded>
				</item>
</channel>
</rss>
