Content filter (was - Re: [arin-announce] IPv4 Address Space)

Leave content filtering to the ES, and *force* ES to filter the content.

And just to make sure we know what content filter is, this is what I
received immedialy following my previous post to nanog.

Whoever you are, that did not see my post, please at least configure your
content filter to reject email and specify your own mail server name there
(and preferably specifying what original rcpt to as well), putting my own
server name in "from" is just not very polite, nor is it according to
standards (you have no idea if "Administrator" account exist on my
machine, in fact for most it would not).

William, they might be rejecting your post for SPAM. Take a look at the
link below:

http://groups.google.com/groups?q=dns1.elan.net&hl=en&lr=&ie=UTF-8&oe=UTF-8&safe=off&sa=N&tab=wg

Michael Booth

in On Wed, 29 Oct 2003, Booth, Michael (ENG) wrote:

William, they might be rejecting your post for SPAM. Take a look at the
link below:

http://groups.google.com/groups?q=dns1.elan.net&hl=en&lr=&ie=UTF-8&oe=UTF-8&safe=off&sa=N&tab=wg

Michael Booth

That post was rejected because of the words "porn site". This was quite
clear from the type of filtering message. I'm sure this post will generate
exactly the same reply back to me...

I'm guessing you're are one of those people at nanog who tried to show me
list of sites previously hosted at elan that generated abuse complaints
back in 2001 (i.e. see above url). Those customers are all gone long ago
and none of them actually sent email spam, so there are no filters on
elan anywhere (except rhyolite, who can't distinguish between real spam
and joe-job; using automated means is really not a way to keep long-term
email filter list) nor were there in the past.

On the other hand as26857 is an interesting "character". I've listed you
on completewhois for hijacking ip blocks under "web design house" name
(one more ip block yet to be added, I'm sure you know which one, you will not
have wait long now...). And there are clear evidence for as26857, wdh &
starlan involvement in emailcourier bulk email operation:
http://groups.google.com/groups?q=as26857&hl=en&lr=&ie=UTF-8&oe=UTF-8&selm=3F999398.1080708%40rogers.com&rnum=2
http://groups.google.com/groups?hl=en&lr=&ie=UTF-8&oe=UTF-8&q=emailcourrier.com&sa=N&tab=wg
http://groups.google.com/groups?hl=en&lr=&ie=UTF-8&oe=UTF-8&q=starlan+email

That post was rejected because of the words "porn site". This was quite
clear from the type of filtering message. I'm sure this post will generate
exactly the same reply back to me...

I'm not sure about that. I spoke with several large ISP abuse desks that
have you blackholed, for wasting their time with long-winded and baseless
"abuse" and "hijacking" complaints day after day, or for previous spam
activity behind your network which you neglected to stop and deny to this
day. I figured your mail might have been withheld, or rejected, for one
of these reasons.

I'm guessing you're are one of those people at nanog who tried to show me
list of sites previously hosted at elan that generated abuse complaints
back in 2001 (i.e. see above url). Those customers are all gone long ago

No, I'm not, though that's pretty funny. When did this happen?

And why are you still hosting their domains if they're "gone"?

and none of them actually sent email spam, so there are no filters on

They sure generated a lot of complaints for people who never actually sent
spam.

William, you seem to have an awfully hard time coming to grip with the
fact that you run a spam and IP hijacking operation yourself, despite your
sharp criticism of others doing same.

In the interest of being unbiased, I'd like to respectfully ask that you
list the IP block you hijacked from your dissolved company, BizNet, on the
completewhois site, and then attempt to dispute it with your alternate
personality.

Sorry guys, I left this one out:

http://groups.google.com/groups?q=biznet+spam&hl=en&lr=&ie=UTF-8&oe=UTF-8&safe=off&selm=0.d4e3f0c6.2573f599%40aol.com&rnum=9

And any idea why you're hosting all of these William?

123-EASY-DIET NS DNS1.ELAN.NET.
123-EASY-HOME-MORTGAGE NS DNS1.ELAN.NET.
123-EASY-LIFE-INSURANCE NS DNS1.ELAN.NET.
123-EASY-MORTGAGE NS DNS1.ELAN.NET.
123-EASY-WEB-HOSTING NS DNS1.ELAN.NET.
123-IRA-PORTAL NS DNS1.ELAN.NET.
123-ONLINE-CASINO-PORTAL NS DNS1.ELAN.NET.
123-ROULETTE-PORTAL NS DNS1.ELAN.NET.
123-ZOLOFT-PORTAL NS DNS1.ELAN.NET.
4GAMEPLAY NS DNS1.ELAN.NET.
ABC-BAD-CREDIT-LOAN-ONLINE NS DNS1.ELAN.NET.
ABC-BLACKJACK-ONLINE NS DNS1.ELAN.NET.
ABC-GAMBLING-ONLINE NS DNS1.ELAN.NET.
ABC-GIFTS-ONLINE NS DNS1.ELAN.NET.
ABC-HOME-MORTGAGE-ONLINE NS DNS1.ELAN.NET.
ABC-WEB-HOSTING-ONLINE NS DNS1.ELAN.NET.
ABC-WEIGHT-LOSS-ONLINE NS DNS1.ELAN.NET.
ACTINIUM NS DNS1.ELAN.NET.
ADIPEX-CENTER NS DNS1.ELAN.NET.
ALADHAM NS DNS1.ELAN.NET.
ALTOPARC NS DNS1.ELAN.NET.
AMAZONCA NS DNS1.ELAN.NET.
AMHOUSE NS DNS1.ELAN.NET.
ANTHONYCAGGIANO NS DNS1.ELAN.NET.
ARCADETOWN NS DNS1.ELAN.NET.
AUTO-INSURANCE-NET-RESOURCES NS DNS1.ELAN.NET.
BABY-ROOM-DECORATOR-DESIGNER NS DNS1.ELAN.NET.
BARNEY-RESOURCE NS DNS1.ELAN.NET.
BARNEY-TOYS NS DNS1.ELAN.NET.
BEST-INSURANCE-QUOTE1 NS DNS1.ELAN.NET.
BEST-LIFE-INSURANCE-QUOTER NS DNS1.ELAN.NET.
BEST-ONLINE-AUCTION-NETWORK NS DNS1.ELAN.NET.
BEST-ONLINE-CASINO-NETWORK NS DNS1.ELAN.NET.
BEST-USA-LIFE-INSURANCE NS DNS1.ELAN.NET.
BEST-USA-LOSE-WEIGHT NS DNS1.ELAN.NET.
BEST-USA-ONLINE-CASINO NS DNS1.ELAN.NET.
BEST-USA-WEBSITE-HOSTING NS DNS1.ELAN.NET.
BEST-WEBSITE-HOSTING-NETWORK NS DNS1.ELAN.NET.
BONTRIL-NETWORK NS DNS1.ELAN.NET.
BOWTIE-CATERING NS DNS1.ELAN.NET.
BRANSONTIMESHARE NS DNS1.ELAN.NET.
BUSINESSINTERRUPTION NS DNS1.ELAN.NET.
CAGGIANOELECTRICAL NS DNS1.ELAN.NET.
CAREER-TOTAL-NETWORK NS DNS1.ELAN.NET.
CAREERCONSTRUCTIONSITE NS DNS1.ELAN.NET.
CHEAP-INSURANCE-QUOTE NS DNS1.ELAN.NET.
CHICAGO-DAY-SPAS NS DNS1.ELAN.NET.
CHRISTMASCHINA NS DNS1.ELAN.NET.
CHRISTMASCOLLECTABLES NS DNS1.ELAN.NET.
CHRISTMASDISCOUNTS NS DNS1.ELAN.NET.
CHRISTMASLINENS NS DNS1.ELAN.NET.
CHRISTMASPRODUCTIONS NS DNS1.ELAN.NET.
CHRISTMASWRAPPINGPAPER NS DNS1.ELAN.NET.
CITYMAGNETS NS DNS1.ELAN.NET.
CLOMP NS DNS1.ELAN.NET.
CLOMPCORP NS DNS1.ELAN.NET.
CN-SHOP NS DNS1.ELAN.NET.
COLORADO-SPAS NS DNS1.ELAN.NET.
COMPLETEWHOIS NS DNS1.ELAN.NET.
DANACALDWELL NS DNS1.ELAN.NET.
DATECLOCK NS DNS1.ELAN.NET.
DHNAP NS DNS1.ELAN.NET.
DIDREX-CENTER NS DNS1.ELAN.NET.
DIET-PILLS-INFO NS DNS1.ELAN.NET.
DSL-VOIP NS DNS1.ELAN.NET.
DSLVOIP NS DNS1.ELAN.NET.
ELANTELECOM NS DNS1.ELAN.NET.
EMPLOYMENT-GUARANTEED-ONLINE NS DNS1.ELAN.NET.
EPOSTALPLUS NS DNS1.ELAN.NET.
EXPANDEDSOUND NS DNS1.ELAN.NET.
EXTERIORDECORATIONS NS DNS1.ELAN.NET.
EZIZZA NS DNS1.ELAN.NET.
FAST-ONLINE-CRUISE NS DNS1.ELAN.NET.
FAST-ONLINE-FLOWER-DELIVERY NS DNS1.ELAN.NET.
FAST-ONLINE-GAMBLING NS DNS1.ELAN.NET.
FAST-ONLINE-GIFTS NS DNS1.ELAN.NET.
FAST-ONLINE-HOME-MORTGAGE NS DNS1.ELAN.NET.
FAST-ONLINE-IT-JOBS NS DNS1.ELAN.NET.
FAST-ONLINE-NEW-CARS NS DNS1.ELAN.NET.
FAST-ONLINE-ROULETTE NS DNS1.ELAN.NET.
FAST-ONLINE-WEIGHT-LOSS NS DNS1.ELAN.NET.
FATALBLINDNESS NS DNS1.ELAN.NET.
FIGURE-SKATES NS DNS1.ELAN.NET.
FINANCIAL-PLANNING-COMMUNITY-NETWORK NS DNS1.ELAN.NET.
FLORIDA-SPAS NS DNS1.ELAN.NET.
FLOWER-DELIVERY-INFO-2000 NS DNS1.ELAN.NET.
FLOWER-DELIVERY-INFORMATION-WEB NS DNS1.ELAN.NET.
FOOBOARDS NS DNS1.ELAN.NET.
FREEWEBGAMES NS DNS1.ELAN.NET.
GANS-LASIK NS DNS1.ELAN.NET.
GIFTS-NET-RESOURCES NS DNS1.ELAN.NET.
GZIZZA NS DNS1.ELAN.NET.
HOLIDAYFILMS NS DNS1.ELAN.NET.
HOME-IMPROVEMENT-LOAN-ONLINE-DEPOT NS DNS1.ELAN.NET.
HOMEOWNERS-INSURANCE-WEB NS DNS1.ELAN.NET.
IDNBAR NS DNS1.ELAN.NET.
IETMED NS DNS1.ELAN.NET.
IETMEDICAL NS DNS1.ELAN.NET.
INSTANT-CONSOLIDATE-DEBT-RESOURCE NS DNS1.ELAN.NET.
INSTANT-FINANCIAL-PLANNING-RESOURCE NS DNS1.ELAN.NET.
INSTANT-LIFE-INSURANCE-QUOTES-ONLINE NS DNS1.ELAN.NET.
INSTANT-MORTGAGE-REFINANCING-RESOURCE NS DNS1.ELAN.NET.
INSTANT-ONLINE-CASINO-RESOURCE NS DNS1.ELAN.NET.
IP-WHOIS NS DNS1.ELAN.NET.
IRCWEB NS DNS1.ELAN.NET.
IT-JOBS-INFORMATION-WEB NS DNS1.ELAN.NET.
IVERNISSAGE NS DNS1.ELAN.NET.
LEGALSTUDIESONLINE NS DNS1.ELAN.NET.
LEYBZON NS DNS1.ELAN.NET.
MAGICSCRIPT NS DNS1.ELAN.NET.
MDDLLP NS DNS1.ELAN.NET.
MERIDIA-SOURCE NS DNS1.ELAN.NET.
METRORAILMAPS NS DNS1.ELAN.NET.
MIPANCARTA NS DNS1.ELAN.NET.
MLOSER NS DNS1.ELAN.NET.
MZIZZA NS DNS1.ELAN.NET.
NASTYPALACE NS DNS1.ELAN.NET.
NASTYPIE NS DNS1.ELAN.NET.
NASTYPLAY NS DNS1.ELAN.NET.
NOSTALGIASTUFF NS DNS1.ELAN.NET.
NOVOSOFT-DE NS DNS1.ELAN.NET.
NOVOSOFT-FR NS DNS1.ELAN.NET.
NOVOSOFT-UK NS DNS1.ELAN.NET.
NUEVOPAIS NS DNS1.ELAN.NET.
PHENTERMINE-WEB NS DNS1.ELAN.NET.
POSSUMCOUNTY NS DNS1.ELAN.NET.
PROMOBANDA NS DNS1.ELAN.NET.
PROTECTEDWHOIS NS DNS1.ELAN.NET.
ROCKETPARKMUSIC NS DNS1.ELAN.NET.
SCOTTLABELTOOLS NS DNS1.ELAN.NET.
SEARCH4DOMAIN NS DNS1.ELAN.NET.
SEARCH4HOST NS DNS1.ELAN.NET.
SEEKERSPUB NS DNS1.ELAN.NET.
SHILOV NS DNS1.ELAN.NET.
SIMBOLOSGRAFICOS NS DNS1.ELAN.NET.
SMTP2 NS DNS1.ELAN.NET.
SOUNDCLICK NS DNS1.ELAN.NET.
SPAMBLASTER NS DNS1.ELAN.NET.
SPAMLIBRARY NS DNS1.ELAN.NET.
TEAMOFTHREE NS DNS1.ELAN.NET.
TELEPHONYHOSTING NS DNS1.ELAN.NET.
TENUATE-NETWORK NS DNS1.ELAN.NET.
TERAPY NS DNS1.ELAN.NET.
VOIP-DSL NS DNS1.ELAN.NET.
VOIPDSL NS DNS1.ELAN.NET.
WEB-HOSTING-INFO-2000 NS DNS1.ELAN.NET.
WINSTICKIES NS DNS1.ELAN.NET.
XENICAL-SOURCE NS DNS1.ELAN.NET.
ZIZZAFAMILY NS DNS1.ELAN.NET.
ZOLOFT-PILLS NS DNS1.ELAN.NET.

And how about this one William?

http://216.239.39.104/search?q=cache:Q7SpB-SrrT8J:www.collectibles-auctions-online.com/download_game_warez.html+"216.151.192.0"&hl=en&ie=UTF-8

Google cache doesn't lie.

OK, enough is enough. We've all had a spammer or spam site sign up,
and we've all (presumably) kicked them off. Why are you referencing
data from some spam posting over 4 years old?

"Booth, Michael (ENG)" wrote:

Sorry guys, I left this one out:

http://groups.google.com/groups?q=biznet+spam&hl=en&lr=&ie=UTF-8&oe=UTF-8&safe=off&selm=0.d4e3f0c6.2573f599%40aol.com&rnum=9

I've reviewed all the postings from this Michael (ENG) Booth, and found
none that add to the knowledge of this group.

Moreover, it appears (from not very old postings) that this fellow
didn't exist before August, and seems only to flame on isp-planet
(and now here).

As has been noted, his company is listed as a net hijacker and a spam
friendly carrier.

OK, enough is enough. We've all had a spammer or spam site sign up,
and we've all (presumably) kicked them off. Why are you referencing
data from some spam posting over 4 years old?

Because, as I showed you, Elan is still hosting their domains.

If William would take some action and clean up the spammers on his
network, I wouldn't need to post about it.

Another item of note is the phone number in ELAN.NET domain registration
is invalid. William is in breach of his registration agreement, and
liable to lose his domain name unless he corrects this.

Adding to the indictment, the postings are listed as circa 9 am EST,
but didn't show up until 3 pm EST, and are coming from a machine that
claims to be NANOG.us (with missing inverses). Not a good sign:

  Received: from ns2.nanog.us (unknown [69.60.142.242])
        by segue.merit.edu (Postfix) with ESMTP id 873E85DE94
        for <nanog@merit.edu>; Sun, 2 Nov 2003 14:53:50 -0500 (EST)
  Received: from ns2.nanog.us (localhost [127.0.0.1])
        by ns2.nanog.us (8.12.6/8.12.6) with ESMTP id hA2EgqCm084896;
        Sun, 2 Nov 2003 09:42:52 -0500 (EST)
        (envelope-from mbooth@ns2.nanog.us)
  Received: (from mbooth@localhost)
        by ns2.nanog.us (8.12.6/8.12.6/Submit) id hA2EgqS5084895;
        Sun, 2 Nov 2003 09:42:52 -0500 (EST)

10 so-1-0-0.cr1.lga3.us.above.net (64.125.30.18) 64 ms 64 ms 64 ms
11 64.124.164.21.available (64.124.164.21) 74 ms 77 ms 75 ms
12 69.60.142.242 (69.60.142.242) 73 ms 75 ms 73 ms

I've reviewed all the postings from this Michael (ENG) Booth,
and found none that add to the knowledge of this group.

The only relevance of those postings to this group can be found by
observing exactly how the MX (69.60.142.242) for his email address
(MBooth@corp.as26857.com) answers on Port 25. Most interesting!

As has been noted, his company is listed as a net hijacker
and a spam friendly carrier.

The latter issue is certainly not relevant here, while the former might
be - if any hijacked blocks were being currently announced by their ASN.
That doesn't seem to be the case: whois.cymru.com reports 199.120.254.0
as being NOT currently being announced by any ASN

Unless I missed one?

There has been more operational and useful discussion on #nanog
today than on NANOG-L. Something is wrong with this picture.

Eddy

> OK, enough is enough. We've all had a spammer or spam site sign up,
> and we've all (presumably) kicked them off. Why are you referencing
> data from some spam posting over 4 years old?

Because, as I showed you, Elan is still hosting their domains.

Lets be clear about something - having our nameserver listed as one of
dns servers for domain, does not mean we're hosting it. There are LOTs of
domains which use our dns servers (in fact couple people at nanog receive
free secondary dns from elan), there are also number of domains for which
we're listed but we do not provide dns services any more (I can't really
force somebody to remove our dns server from their domain whois, I can
ask, but they may refuse or do not answer at all - if this is a problem,
then I set our dns server to do reply as "NXDOMAIN", which may get their
attention; but 99% of the time, the domain that was in dns server but is
no more, simply has its records and configs purged from our dns server -
that however means that our server may still answer queries about it in a
normal caching mode, i.e. by getting data from the first listed primary
dns and caching it on the fly without using any local configuration).

If you have problem with any PARTICULAR domain, send email to abuse@elan.net
and clearly indicate what the problem is - you will receive a reply (within
72 hours if email is directly from user and not from automated system).
If the email is ccd to newsgroup (if you want to make it public), there
will be reply to that newsgroup, but be particular about each and every
case separately, don't just list bunch of domains (i.e. those with elan.net
and with with "-" that you sorted out of .com/.net root dns zone file).

For others, please note that I already told all this before to Michael or
else somebody who I'm certain he knows.

If William would take some action and clean up the spammers on his
network, I wouldn't need to post about it.

There are no spammers on the network. Anybody who tries to spam, gets
removed according to our policies, usually within first 24 hours, sometimes
if longer investigations are necessary and they try to "fight" it, then
within 7 days or within 30 days depending on what circumstances are.
Only one case (and it did not involve mass emailing) has ever survived
over 30 days and to get rid of him, the change of AUP was necessary but
this was all several years ago anyway.

And all those google references provided from 2-4 years ago are for
companies that were not even direct customers but customers of a customers,
none are hosted on the network for long long time (several years).

Another item of note is the phone number in ELAN.NET domain registration
is invalid. William is in breach of his registration agreement, and
liable to lose his domain name unless he corrects this.

There are known ICANN approved ways to report invalid registration data.
Otherwise we'll correct any wrong data on the next domain annvessary or
when domain registrar sends a notice (as they should at least once/year)
to check if data is correct.

P.S. This will be the last time I answer this kind of allegations on the
list. All these allegations are baseless as others in fact already said
as well are simply harrassment because you have problem that I'm listing
ip blocks you hijacked (or somebody you know based on the company you
associate with) and posted data about in public as well as references to
what you did. Well, if you yourself want to answer those problems, feel
free to do so on any public list (preferably not nanog, but who am I to
stop you...). I'll reference those posting to on the webpage for wdh/starlan
so others could see your own view on what happened and how you're connected
to mailcourier, etc.

For reference about why this is happening, please see:
http://www.completewhois.com/hijacked/gang_wdh.htm