# This blacklist of DCC clients is used by the public DCC servers. # It contains IP addresses and blocks of addresses of DCC clients # that persistently cause problems including sending more than 100,000 # requests per day to the public DCC servers. # # This is http://www.rhyolite.com/anti-spam/dcc/client-blacklist.html # and http://www.dcc-servers.net/dcc/client-blacklist.html # # See also http://www.dcc-servers.net/dcc/ or # http://www.rhyolite.com/anti-spam/dcc/ # # Contact vjs@rhyolite.com or use the web form at # http://www.rhyolite.com/cgi-bin/ct.cgi?sb=public+server+blacklist # about 500K pure NOPS/day; no response to mail from abuse@twtelecom.net # 66-193-204-14.static.twtelecom.net 66.193.204.14 # 1.6 million NOPs/day # no response to email to abuse@business.telecomitalia.it # host26-64-static.118-81-b.business.telecomitalia.it 81.118.64.0/24 # 600K NOPs/day # no response from abuse@spot.net.ar, abusenet@datamarkets.com.ar, # or postmaster@spot.net.ar # 200.32.3.233 host1.spot.net.ar 200.32.3.233 # 700K NOPs/day from 206.167.139.101 # no response from support@risq.qc.ca 206.167.139.0/24 # continuing unauthorized attempts to connect to TCP port 6277 # from 38.101.236.64, mail.epochtimes.com # John Tang, AsianBay Technology, Inc., 1322 Briarwood Rd, #J-6, # Atlanta, GA, johnztang@yahoo.com # from 38.101.236.69, mail.ntdtv.com # Domains by Proxy, but "New Tang Dynasty Television" on # http://ntdtv.com/xtr/firstPage.htm # from 38.101.236.222, mail.edoors.com # Whois Privacy Protection Service 38.101.236.0/24 # continuous bogus attempts to connect to TCP port 6277 from 212.75.36.124 # sodes.net, Tobias Wagener, Silcherstr. 1, Neu-Ulm, 89231, DE 212.75.36.0/24 # hol.gr # more than 800K requests from 194.30.193.15 194.30.193.14 194.30.193.12 # and 194.30.193.13 # no response to mail from abuse@hol.gr or postmaster@hol.gr 194.30.193.0/24 # ains.net.au # Australia InterNet Solutions # 380K to 1.2M requests/day from 202.126.109.235, or far more than the # threshold that causes the automaticDoS defenses to block all of # their requests # They respond to email with pleas to not blacklist them, but no effective # or enduring actions 202.126.109.235 # more than 3.7 million requests/day, probably in violation of the license # on the free source # aotech.net AO Technologies, 8314 Harlem Road, Westerville OH # 216.185.43.244 mail.mailrescue.in # qualispace.com, QuantumPages Technologies, Maharashtra IN # 216.185.43.250 216-185-43-250.qualispace.com # 216.185.43.251 216-185-43-251.qualispace.com # 216.185.43.252 216-185-43-252.qualispace.com 216.185.43.128/25 # Fortinet.com seems to be following a familiar business plan # and not only selling a product that misappropriates the CPU cycles, # bandwidth, and human administration efforts of the public DCC servers # but also generates bogus DCC requests packets. # Michael Xie, Sunnyvale CA 65.39.139.0/24 # fortinet.com has address 203.160.224.97 # fortinet.com mail is handled by 5 MAIL.APSECURE.com. # Wen-Shyang Shiau Chunghwa Telecom wsshiau@chti.com.tw # AP Secure Technologies Burnaby BC # APSECURE.com has address 203.160.224.97 # asianproducts.com Media Federal Co. Taipei TW # APSYS.NET Media Federal Co. Taipei TW 203.160.224.0/19 # Guardian Digital seems to be yet another organization with a business # plan based on selling the misappropriated CPU cycles, bandwidth, # and human system administration labor spent on the public DCC servers. # 350K OPs/day from 64.1.16.5, bwimail01.guardiandigital.com 64.1.16.0/24 # 300K OPs/day from 74.201.172.168, bwimail02.guardiandigital.com 74.201.172.0/24 # FortressITX, 100 Delawanna Ave, Clifton, NJ # 400-500K NOPs/day and no response to questions # The reverse DNS for 69.72.145.30 changed to mail.pwebtech.com and # then to mail-intake.fortressitx.com # Pegasus Web Technologies, Franklin Lakes, NJ 69.72.145.0/24 # cryptoheaven.com, # Adam Kurzawa # 5-2325 Hurontario Street, Suite 206 # Mississauga CA # 986,723 ops/day # yet another seller of misappropriated CPU cycles, bandwidth, and system # administration labor of the public DCC servers 64.34.231.40/29 # viruscheckservice.de # 300K operations/day # yet another seller of misappropriated CPU cycles, bandwidth, and system # administration labor of the public DCC servers # particularly amusing is that mail to postmaster@viruscheckservice.de # and flo@degnet.de, the contact address for viruscheckservice.de, # is rejected with # "450-Your address 192.188.61.3 has mailed to spamtraps here" 80.73.96.0/24 # First Gulf Bank, P O Box 6316, Abu Dhabi, UAE # Suresh Rajagopalan 195.229.126.213 fgb-mail.fgb.ae # configured a DCC client to send requests to the public DCC servers, # did not configure their firewall to accept the DCC responses, # and then on Oct 9 demanded the identity of an attacker on their # "web-server" doing "TCP / UDP / ICMP scans" so that "action # could be initiated against user as per law of UAE or any other # countries applicable laws" # # I removed this entry after the principals apologized to one of # the public DCC server operators, after they had made a second # complaint a week or two later. More recently on November 4, 2006 # they repeated their old GFW complaints. That will teach me. 195.229.126.208/28 # mail.stute.de # attempts to connect to TCP port 6277 on public DCC servers every 10 minutes 62.206.130.151 # unspam.com, openpop3.com # Eric Langheinrich, # Unspam Technologies, Inc., 1901 Prospector Avenue, Park City, Utah # violates the license on the free DCC software in both its business model # and not sharing checksums with the rest of the DCC network. # 340K ops/day from 66.114.104.70 66.114.104.64/26 # mailroute.net # suppress system log complaints in case these dead servers awaken 199.89.0.0/21 # antivirus.ie 195.97.252.83 195.97.252.86 195.97.252.84 # does not meet the terms & conditions for use of the public DCC servers 195.97.252.80/28 # aaaonlinux.com, indiannic.com # does not meet the terms & conditions for use of the public DCC servers 208.115.35.224 # $Date: 2008/07/06 22:10:37 $
Contact vjs@rhyolite.com by mail or using the form. Do not send mail to the spam trap.