Null-routing complainers

I was talking too soon about US webhosts understanding about webspam.

One of them just nullrouted the IP to my webserver, from their webserver.

Translation: They don’t know how, or don’t care, to stop the referrer spamming, and want to prevent the spamming from reaching my website, in order to stop me from complaining.

They just waved a big red TENT in front of my eyes, that’s what they did!

They better figure out how to stop that spamming, and TELL ME, or I’ll be so incredibly tempted to tell the world exactly what webhost this is.

So guys, watch out for webhosts nullrouting the IP of your servers when you complain, instead of actually dealing with the problem!

Here’s HostGator’s latest missive to me regarding the referrer spamming: (timestamped 03:51:28 -0700, July 21)

Dear Spamhuntress,
Setting up an actual packet sniffer would require admin time needed to install and configure it for your purposes. We would be happy to do so for you but there would be a fee associated with this service.

We could easily set it up just to log the fact that packets were sent using a series of iptables rules, but since we want the actually packets we would need to compile the pcap libraries and go with a program such as ethereal or dsniff, both which are pretty generally out of our line of work. It’s defiantly doable though if you like.

We do apologize, but we’re not accustomed to customers actually wanting to track spam! Hence, our actions were taken in order to simply prevent the spam entirely. Please let us know how we may best assist you.

I find that rather offensive. They’re NOT preventing the spam entirely. They’re just stopping it from reaching MY little website! And where did they get the idea I was their customer? I definitely never will be, from what I’ve seen lately.

Bear in mind:

This host replied to my complaints. Not every host will even reply to an abuse complaint. Some silently null-route them. So this isn’t the worst offender in any way. But it highlights something that’s fairly typical of webhosts today: The margins are small. The prices for webhosting are very low compared to what they were, and people are price shopping. Many hosts say they’ll charge a fee for investigating mail spam - charged to the offender, when they’ve received a complaint. So they were - par for course - looking for someone to bill the investigation to. It was just so offensive to me that they wanted to bill the complainer for something that’s their duty (in my opinion) to investigate and mitigate completely. I DID tell them I’d blog this if they insisted null routing me was solving the problem, and then they came up with the idea to charge me… Like Joe said below - this could be the tip of the ice berg concerning that particular server. And they don’t care. Remember before blocklists made it important for ISP’s and webhosts to remove mail spam off their services immediately? They didn’t care either. Investigation costs, and booting customers costs. It isn’t until businesses are compelled that they’ll actually do something about spam. So this is a beautiful example.

Update: Just got an apology (timestamped 21 Jul 2006 05:28:35 -0700) about the misunderstanding about me being a customer, and to wait for another response from one of the other team members.

Partial victory: They’re removing the null routing, and will be monitoring connections to my site only, to see if they can figure it out. That’s a solution I can live with, and hopefully they’ll figure out how to stop the abuse, and hopefully also figuring out how others can check their servers to boot.

3 Responses to “Null-routing complainers”

  1. Joe says:

    I hope they don’t actually think that is dealing with the problem. If every person who was referrer spammed through from their machines complained and had to be null-routed, just think of all the work that would require. If this is the best a host that actually understands web spam is a problem can do, the internet is just going to continue to degrade into garbage.

    Might as well announce the name so spammers know where to sign up for spam complaint proof hosting.

  2. IncrediBILL says:

    Go ahead and tell us who it is as I block entire webhosts all the time and if it’s someone new, I’d block them in a heartbeat.

    The hosts tend to have tons ot scrapers, spybots and proxy servers which can get you hijecked in Google or worse so the hosting companies with the most offenders are now being locked out on my server and quite a bit of the nonsense has diminished greately.

    Try it, you’ll sleep better at night ;)

  3. Joe says:

    If they think preventing the spammer from hitting your one site is solving anything, they clearly don’t understand the problem of web spamming. Stopping any kind of spammer from using their service should be something that any good host strives to do. Spamming from a shared host can affect others on that server if it gets blacklisted. If the spammer is a customer then that account should be closed. If the problem is a compromised server, they should be eager to hunt it down. Spamming is not the only problem a compromised server can cause.

Leave a Reply