Spamhaus under DDOS from AnonOps (Wikileaks.info)

2010-12-18 Thread Steve Linford
As many of you know, both Trend Micro and Spamhaus have published warnings about a Wikileaks mirror site 'wikileaks.info' which is run by the person or persons behind 'AnonOps' from an IP address of a Russian dedicated cybercrime host (Heihachi) on which there is nothing but malware and other cy

Re: Spamhaus under DDOS from AnonOps (Wikileaks.info)

2010-12-18 Thread Jack Bates
On 12/18/2010 6:58 AM, Steve Linford wrote: For trying to warn about the crime gangs located at the wikileaks.info mirror IP, Spamhaus is now under ddos by AnonOps. The criminals there do not like our free speech at all. It appears that wikileaks.org is operational again and redirecting to

Re: Spamhaus under DDOS from AnonOps (Wikileaks.info)

2010-12-18 Thread Marshall Eubanks
On Dec 18, 2010, at 4:00 PM, Jack Bates wrote: > On 12/18/2010 6:58 AM, Steve Linford wrote: >> For trying to warn about the crime gangs located at the wikileaks.info >> mirror IP, Spamhaus is now under ddos by AnonOps. The criminals there do not >> like our free speech at all. >> > > It appe

Re: Spamhaus under DDOS from AnonOps (Wikileaks.info)

2010-12-18 Thread Jack Bates
On 12/18/2010 5:15 PM, Marshall Eubanks wrote: I get nothing from wikileaks.org, although the DNS is active : $ host wikileaks.org wikileaks.org has address 64.64.12.170 $ telnet 64.64.12.170 80 Trying 64.64.12.170... Connected to 64.64.12.170. Escape character is '^]'. GET / HTTP/1.1 Host: w

Re: Spamhaus under DDOS from AnonOps (Wikileaks.info)

2010-12-19 Thread Joe Greco
> On 12/18/2010 5:15 PM, Marshall Eubanks wrote: > > > > I get nothing from wikileaks.org, although the DNS is active : > > > > $ host wikileaks.org > wikileaks.org has address 64.64.12.170 Doesn't it seem vaguely suspicious that whois was just updated? Domain ID:D130035267-LROR Domain Name:WIKI

RE: Spamhaus under DDOS from AnonOps (Wikileaks.info)

2010-12-19 Thread Frank Bulk - iName.com
ikileaks.info's claims can be publicly refuted? Kind regards, Frank -Original Message- From: Jack Bates [mailto:jba...@brightok.net] Sent: Saturday, December 18, 2010 3:00 PM To: nanog@nanog.org Subject: Re: Spamhaus under DDOS from AnonOps (Wikileaks.info) On 12/18/2010 6:58 AM,

Re: Spamhaus under DDOS from AnonOps (Wikileaks.info)

2010-12-19 Thread Paul Ferguson
todirekt.com." Any chance that will be done, so > wikileaks.info's claims can be publicly > refuted? > > Kind regards, > > Frank > > -Original Message- > From: Jack Bates [mailto:jba...@brightok.net] > Sent: Saturday, December 18, 2010 3:00 PM > To: nanog@n

Re: Spamhaus under DDOS from AnonOps (Wikileaks.info)

2010-12-19 Thread Marshall Eubanks
On Dec 19, 2010, at 8:06 AM, Joe Greco wrote: >> On 12/18/2010 5:15 PM, Marshall Eubanks wrote: >>> >>> I get nothing from wikileaks.org, although the DNS is active : >>> >> >> $ host wikileaks.org >> wikileaks.org has address 64.64.12.170 > > Doesn't it seem vaguely suspicious that whois was

Re: Spamhaus under DDOS from AnonOps (Wikileaks.info)

2010-12-19 Thread Rich Kulawiec
On Sun, Dec 19, 2010 at 12:46:33PM -0600, Frank Bulk - iName.com wrote: > While I tend to trust Steve and Spamhaus because of their built up > reputation, it would be helpful if some concrete facts were published about > the "more than 40 criminal-run sites operating on the same IP address as > wik

Re: Spamhaus under DDOS from AnonOps (Wikileaks.info)

2010-12-19 Thread Ned Moran
additional evidence http://www.malwaredomainlist.com/mdl.php?search=41947&colsearch=All&quantity=50&inactive=on On Sun, Dec 19, 2010 at 2:25 PM, Rich Kulawiec wrote: > On Sun, Dec 19, 2010 at 12:46:33PM -0600, Frank Bulk - iName.com wrote: > > While I tend to trust Steve and Spamhaus because of

Re: Spamhaus under DDOS from AnonOps (Wikileaks.info)

2010-12-19 Thread Simon Waters
On 19/12/10 18:51, Paul Ferguson wrote: > Not for nothing, but Spamhaus wasn't the only organization to warn about > Heihachi: > > http://blog.trendmicro.com/wikileaks-in-a-dangerous-internet-neighborhood/ All the domains listed by Trend Micro as neighbours appear to be down. Have to say as someo

Re: Spamhaus under DDOS from AnonOps (Wikileaks.info)

2010-12-19 Thread Paul Ferguson
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On Sun, Dec 19, 2010 at 12:29 PM, Simon Waters wrote: > On 19/12/10 18:51, Paul Ferguson wrote: >> Not for nothing, but Spamhaus wasn't the only organization to warn about >> Heihachi: >> >> http://blog.trendmicro.com/wikileaks-in-a-dangerous-interne

Re: Spamhaus under DDOS from AnonOps (Wikileaks.info)

2010-12-19 Thread foks
On 12/19/2010 08:33 PM, Ned Moran wrote: > additional evidence > > http://www.malwaredomainlist.com/mdl.php?search=41947&colsearch=All&quantity=50&inactive=on > > On Sun, Dec 19, 2010 at 2:25 PM, Rich Kulawiec wrote: > >> On Sun, Dec 19, 2010 at 12:46:33PM -0600, Frank Bulk - iName.com wrote: >>>

RE: Spamhaus under DDOS from AnonOps (Wikileaks.info)

2010-12-19 Thread Frank Bulk - iName.com
announcement was not so clear. Frank -Original Message- From: Paul Ferguson [mailto:fergdawgs...@gmail.com] Sent: Sunday, December 19, 2010 12:52 PM To: frnk...@iname.com Cc: Jack Bates; nanog@nanog.org Subject: Re: Spamhaus under DDOS from AnonOps (Wikileaks.info) -BEGIN PGP SIGNED