Ravens PHP Scripts: Forums
 

 

View next topic
View previous topic
Post new topic   Reply to topic    Ravens PHP Scripts And Web Hosting Forum Index -> NukeSentinel(tm)
Author Message
captureroftyme
New Member
New Member



Joined: Jan 08, 2005
Posts: 19

PostPosted: Fri Jan 21, 2005 7:14 am Reply with quote

I have this guy who had a free account on my hosting server. I found some files on his website that were attempting to get bank information from my hosting site, so I shut him down. Recently I found that he was trying to do it again, but he is not on my server. I noticed in my webstats that his domain is at the top of the list for external links to my site, and hits on my site. His domain is http://sesesky.rr.nu . How do I ban this guy, press charges, whatever? I tried to do a whois search on him, but it comes back as an invalid domainname.I just want him gone from my site!
 
View user's profile Send private message
hitwalker
Sells PC To Pay For Divorce



Joined:
Posts: 5661

PostPosted: Fri Jan 21, 2005 8:48 am Reply with quote

Well doing a visualroute i get this...


Domain Name (ASCII): rr.nu
Record last updated on 04-Oct-2004.
Record expires on 04-Nov-2006.
Record created on 04-Nov-1998.
Record status: Active.

Domain servers in listed order:
ns1.sitelutions.com 216.88.44.80
ns2.sitelutions.com 69.10.142.4
ns3.sitelutions.com 66.80.146.132
Copyright by .NU Domain Ltd - http://www.nuna





and using some track to the website IP i get :



OrgName: ThePlanet.com Internet Services, Inc.
OrgID: TPCM
Address: 1333 North Stemmons Freeway
Address: Suite 110
City: Dallas
StateProv: TX
PostalCode: 75207
Country: US

ReferralServer: rwhois://rwhois.theplanet.com:4321

NetRange: 67.18.0.0 - 67.19.255.255
CIDR: 67.18.0.0/15
NetName: NETBLK-THEPLANET-BLK-11
NetHandle: NET-67-18-0-0-1
Parent: NET-67-0-0-0-0
NetType: Direct Allocation
NameServer: NS1.THEPLANET.COM
NameServer: NS2.THEPLANET.COM
Comment:
RegDate: 2004-03-15
Updated: 2004-07-29

TechHandle: PP46-ARIN
TechName: Pathos, Peter
TechPhone: +1-214-782-7800
TechEmail: abuse@theplanet.com

OrgAbuseHandle: ABUSE271-ARIN
OrgAbuseName: Abuse
OrgAbusePhone: +1-214-782-7802
OrgAbuseEmail: abuse@theplanet.com

OrgNOCHandle: TECHN33-ARIN
OrgNOCName: Technical Support
OrgNOCPhone: +1-214-782-7800
OrgNOCEmail: admins@theplanet.com

OrgTechHandle: TECHN33-ARIN
OrgTechName: Technical Support
OrgTechPhone: +1-214-782-7800
OrgTechEmail: admins@theplanet.com

That should help a litle....

Edit : and its very likely that "russians" are behind this cause they rent hosting in the u.s and end up running these types of websites.
But mostly to abuse or doing illegal stuff.
I personaly shutdown 2 websites in the last 4 months because of the attacks.
But when given proof hosting companies shut them down the same hour.....
Thats the fun part.
 
View user's profile Send private message
sixonetonoffun
Spouse Contemplates Divorce



Joined: Jan 02, 2003
Posts: 2496

PostPosted: Fri Jan 21, 2005 12:41 pm Reply with quote

Add that to the Nuke-Sentinel refers blocker. Maybe as a redirect to kindom come...

_________________
[b][size=5]openSUSE 11.4-x86 | Linux 2.6.37.1-1.2desktop i686 | KDE: 4.6.41>=4.7 | XFCE 4.8 | AMD Athlon(tm) XP 3000+ | MSI K7N2 Delta-L | 3GB Black Diamond DDR
| GeForce 6200@433Mhz 512MB | Xorg 1.9.3 | NVIDIA 270.30[/size:2b8 
View user's profile Send private message
sixonetonoffun







PostPosted: Fri Jan 21, 2005 12:44 pm Reply with quote

I've never researched theplanet.com much but most of the serious attacks on my home PC and websites have originated from there. I'm talking serious as in simular to the situation you have where they were definetly trying to gain remote access. Not just some script kiddie copy cat.
 
Specks
New Member
New Member



Joined: Jan 24, 2005
Posts: 12

PostPosted: Mon Jan 24, 2005 3:47 pm Reply with quote

Get that ip number and if its from theplanet.com then send it to abuse@theplanet.com. They're very serious about that sort of stuff.
 
View user's profile Send private message
drmike
Worker
Worker



Joined: Jul 15, 2004
Posts: 108
Location: Charlotte, NC

PostPosted: Tue Jan 25, 2005 7:10 pm Reply with quote

Specks wrote:
Get that ip number and if its from theplanet.com then send it to abuse@theplanet.com. They're very serious about that sort of stuff.


Actually I put them up there with EV1 with ignoring complaints. They're both kiddie heavens.

-drmike

_________________
Only registered users can see links on this board! Get registered or login! 
View user's profile Send private message Visit poster's website ICQ Number
Specks







PostPosted: Tue Feb 01, 2005 11:40 am Reply with quote

To be honest with you, my server is with them. All my complaints have been looked at whenever I create a ticket. I complained of someone trying to brute force my box a while ago and they replied to my complaint that they were investigating the attack that came from within. I don't expect them to come back with what they did or found but its better than being ignored.
 
TheosEleos
Life Cycles Becoming CPU Cycles



Joined: Sep 18, 2003
Posts: 960
Location: Missouri

PostPosted: Tue Feb 01, 2005 1:55 pm Reply with quote

I have had servers hosted at "The Planet'. I always had a good experience.

_________________
Only registered users can see links on this board! Get registered or login! 
View user's profile Send private message Visit poster's website AIM Address ICQ Number
Display posts from previous:       
Post new topic   Reply to topic    Ravens PHP Scripts And Web Hosting Forum Index -> NukeSentinel(tm)

View next topic
View previous topic
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You can download files in this forum


Powered by phpBB © 2001-2007 phpBB Group
All times are GMT - 6 Hours
 
Forums ©