| Registrars
Abuse Overall: 1. ENOM 2. GODADDY 3. .ru 4. OVERSEE 5. NETWORKSOLUTIONS | Owners/Registrants
Overall Abused: 1. contact@privacyprotect.org 2. privacyprotect@dynamicdolphin.com 3. adambengur@yahoo.com 4. designshadows@yahoo.com 5. brokerage@buydomains.com |
| Hosts/IPs/ISPs
Overall Absued: 1. 195.178.160.40 2. 68.178.232.100 3. 64.202.189.170 4. 208.73.210.29 5. 64.95.64.197 | Nameservers
Overall Absued: 1. DNS1.REGISTRAR-SERVERS.COM 2. NS1.MONIKERDNS.NET 3. DNS1.NAME-SERVICES.COM 4. NS1.DOMAINSITE.COM 5. NS1.SEDOPARKING.COM |
Port 43 WHOIS Availability Failures for 4/17/2012
ABSYSTEMS INC DBA YOURNAMEMONKEY.COM ADD2NET INC. COMPANA LLC DOMAIN JAMBOREE, LLCNAMESTREAM.COM INC. NAMEVIEW INC. NETPIA.COM INC. NEW GREAT DOMAINS
FREEPARKING DOMAIN R HECTA MEDIA , AKA TOP-Level Holdings (mindsandmachines.com) ID GENESIS INTERNET VIENNAWEB SERVICE GMBH
IWELT AG KOMPLEX.NET GMBH NAME FOR NAME NAMESHIELD
REGISTRATION TECHNOLOGIES SAVEMORENAMES.COM SCHUECHTERNET LTD D SEDO.COM LLC
SITENAME.COM LLC TURNCOMMERCE, INC. DBA NAMEBRIGHT.COM USA INTRA CORP. VOCALSPACE LLC DBA DESKTOPDOMAINER.COM
XIN NET TECHNOLOGY CORPOR ZOG MEDIA, INC. DBA ZOG NAMES *
"3.3.1 At its expense, Registrar shall provide an interactive web page and a port 43 Whois service providing free public query-based access to up-to-date (i.e., updated at least daily) data concerning all active Registered Names sponsored by Registrar for each TLD in which it is accredited."
* = Registrar is in breach
February 2012 Port 43 WHOIS Test Results
NETFIRMSINC 80% Failure, UNIVERSO 80%, Failure, WEBWERKS 53% Failure, NAMEVIEWINC 46% Failure, FUNPEASMEDIA 33% Failure, LIMELABS 33% Failure, NAUGUSLIMITED 26% Failure, HICHINAWEBSOLUTIONS 20% Failure, NETDORMINC 20% Failure, USAWEBHOST 20%, ALANTRONBLTD 13% Failure, FABULOUSCOM 13% Failure, GLOBIXKFT 13% Failure.
January 2012 Port 43 WHOIS Test Results
NAMEFORNAME 89% Failure, ABSYSTEMS 72% Failure, ATECHNOLOGYCOM 61% Failure, FUNPEASMEDIA 44% Failure, WEBWERKS 27% Failure, USAWEBHOST 22% Failure, HEBEIGUOJI 22% Failure, NICTRADE 22% Failure, DOMAINZLIMITED 16% Failure, RESELLERCAMP 16% Failure.
December 2011 Port 43 WHOIS Test Results
FUNPEASMEDIA 82% Failure, INTERNETGROUPDOBRASIL 69% Failure, ATECHNOLOGYCOM 60% Failure, VISESHINFOTECNICS 60% Failure, DOMAINREGI 56% Failure, HOOYOO 52% Failure, LIMELABS 52% Failure, REGTIME 52% Failure, KUWAITNET 47% Failure, DOMAINZLIMITED 39% Failure, HOOYOOUS 39% Failure, WEBZERO 26% Failure, INTERDOMSA 21% Failure, DOMAINREGISTRY.COM 17%, NETDORM 17% Failure.
KnujOn at ICANN 42
![]() Meeting with IANA (Audio Transcript) Meeting with ICANN Compliance (Audio Transcript) Action Items/Resolutions (Submitted: October 19, 2011) |
The Report That Shook ICANN![]() Get on Kindle| Order hardcopy |
Thwarting Abusive Registrations
PDF Brief At CircleID.com At infosecurity.us |
KnujOn's Dakar Agenda
- Registrars still failing basic compliance
It is with great disappointment that we must report some Registrars remain out of compliance for the same issues first reported in June 2011 by KnujOn. Resolutions:
- We are requesting that ICANN compliance address these outstanding issues in the 15 days allotted by the RAA.
- We are requesting that At-Large be notified whenever a new Registrar is accredited or a current Registrar has their contract renewed.
- Publishing of the Lifecycle of Registrar Breach Notices
In the interest of transparency and accountability ICANN should publish the full lifecycle of contractual breaches. Currently, the results of breach notices posted by compliance are only known if the Registrar is terminated. Some cure notices are posted but this is done in an Ad Hoc fashion. The following Registrars appear to be in perpetual breach of contract with no closure (Breaches must be cured in 15 Days):
- Alantron Bilisim Ltd - Issue: Port 43 WHOIS Failure Since 11.07.2011 Escalated to Suspension, 16 Feb 2012
- Samjung Data Service Co., Ltd - Issue(s): Port 43 WHOIS Failure and Failure to Escrow Since 09.02.2011 Apparently Cured
- Asadal, Inc. - Issue(s): Failure to Escrow and non-compliant transfer policies Since 06.09.2011 Apparently Cured
- iWelt AG - Issue(s): Failure to Escrow Since 01.12.2011 Apparently Cured
- Zog Media, Inc. DBA Zog Names - Issue(s): Failure to Escrow Since 01.12.2011 Apparently Cured, but Registrar status unknown
ICANN compliance should publish an annual audit of Registrar compliance on each section of the RAA, sharing the results with the community in a public report as well as a fixed posting of basic compliance data within the ICANN website. This compliance data should include for each Registrar:
- A link to the Registrar website where their mailing address is posted. Why? Background articles: 1, 2, 3, 4, 5, 6, 7, 8, 9
- A link to the Registrar website where their policies and pricing are posted. Why? Background Article
- The location of the Registrar Port 43 WHOIS server. Why? Background Article
- A link to the Registrar website where the web-based WHOIS is found. Why? Background Article
- The most recent Registrar fee payment date. Why? The most common grounds for termination is failure to pay fees.
OnlineNIC settled cybersquatting suits with Verizon, Microsoft and Yahoo in 2009. While a settlement may have saved OnlineNIC from a violation under RAA 5.3.2, OnlineNIC has in doing so admitted to warehousing domain names for speculation. Resolution: We request an investigation of this situation and a public statement of the findings.
Pending Rogue Registrar Scoring
Based on responses to complaints and follow-up in this area we are drafting a list of rogue Registrars. At this time
the following Registrars (but not limited to) may be designated as rogue:
NetLynx, BizCN, eNom, OnlineNIC, Core, Joker, URL Solutions (list to be updated and may include Registrars with other issues).
Update from 11/20/11
The chart below shows the results of a recent study by KnujOn
in terms of follow-up compliance with WHOIS inaccuracy complaints
filed by KnujOn. This is about response, not just volume.
While some Registrars have many abusive domains with false WHOIS,
in addressing complaints the issues are resolved. In the case
of NetLynx the number
of unresolved complaints indicates possible problems at this Registrar.
Fortunately, Net-Chinese Co deleted
EVERY domain in the complaints, Thanks!
Each complaint was the result of a false WHOIS record found while investigating
spammed domains reported by KnujOn members. The first column next to each
Registrar name indicates the total number of false WHOIS complaints, the
second has the number of domains deleted after the complaints were filed,
and the third shows specifically how many illicit pharmacy domains remain
online regardless of the complaints. The last shows the number of domains still
online beyond the ICANN lifecycle deadline (See previous chart).
KnujOn Confirms Hostexploit.com '11 Q3 Report: HostExploit has flagged Oversee in its "Top 50 Bad Hosts & Networks 2011 Q3" Report as the "#1 Bad Host." Knujon can confirm this. The IP 208.73.210.29 (OVERSEE-NET-2) is our #5 overall host of spammed domains, Moniker (Oversee affiliate) is our #4 biggest sponsor of spammed domain names, and NS1.MONIKERDNS.NET (Oversee affiliate) is our #3 worst nameserver for spammed domains. The above chart also ranks Moniker as the 6th worst Registrar in terms of false WHOIS with a surprising number of illicit pharmacy domains enduring beyond the complaint cycle. Review Moniker-Sponsored "No Prescription" Pharmacy Domains (.PDF)
KnujOn - Turning your spam into a safer Internet
- Anti-Spam Research Update (infosecurity.us) More News...
- IANA: "You're going to laugh at our process" (dakar42.icann.org) More News...
- The Death of the Internet: How It May Happen and How It Can Be Stopped (amazon.com) More News...
- Whois, DNSSEC and Domain Security: An Interview With Garth Bruen of Knujon (circleid.com) More News...
- KnujOn Releases New Security, Abuse and Compliance Report (circleid.com) More News...
- Privacy-Proxy WHOIS Use Higher for Illicit Domains (circleid.com) More News...
- Whois, DNSSEC and Domain Security: An Interview With Knujon (namesmash.com) More News...
- KnujOn "forces rogue domains out of gTLDs" More News...
- Internet compliance firm KnujOn conducted studies of Internet advertisers purporting to be pharmacies More News...
- KnujOn Cited by National Research Council More News...
- WHOIS privacy and proxy services as "shelters" for criminal activity. (blog.blacknight.com) More News...
- The changing landscape of online fraud: Long life spam (economist.com) More News...
- White House Calls Meeting on Rogue Online Pharmacies (krebsonsecurity.com) More News...
- ICANN asks Demand Media for answers after report (reuters.com) More News...
- ICANN Identity Crisis Blunts Moves Against Rogue Pharma (internetevolution.com) More News...
- To some people, Internet compliance is a big joke: "KnujOn Demands to verify birth certificate of #ICANN Chairman" (twitter.com) More News...
KnujOn.com, LLC is an independent, non-sponsored abuse handler and Internet security research company based in Boston, Massachusetts and Wilmington, Vermont. KnujOn accepts abuse data in the form of spam and other security threats to develop a clear picture of conditions facing the Internet. KnujOn builds profiles of online criminal groups, evaluates the quality of Registrars and Internet Service Providers, issues WHOIS challenges, documents policy failures, tests compliance mechanisms, issues reports to law enforcement, and educates the public about complex Internet security issues. We see our role as one of assisting the ordinary Internet user in navigating the complex technical bureaucracy of the global network and augmenting public services in the face of rampant illicit electronic traffic.
Contact KnujOn email: contact@KnujOn.com LinkedInKnujOn Forums and Discussions KnujOn Members Forum - M.I.T. Anti-Spam Conference
Follow KnujOn CricleID, Twitter, Internet Governance Forum, and ICANN At-Large
Learn about KnujOn Wikipedia About - Submit Spam - Join - FAQ - Choose your level of involvement - DATA
| Get a KnujOn Account! |
KnujOn Services Policy Research, Analysis, Development Spam processing(for enforcement) Network and website penetration testing Solutions:
Personal: KnujOn.com is proud to help individuals with their junk mail problems. Personal email application.
Law Enforcement Forensic Tool: KnujOn is designed to collect and sort data for investigations and data analysis. For a demonstration or more information please email contact@knujon.com.
Support Us
{top}
Utilities and Submission Methods
Spam and Abuse - Spam isn't about who sent it, it's about who benefits from it. "Sneakernet" (SnailMail) | Submit Image-only Junk Mail | Webmail | Desktop/GUI Clients | As an attachment | Outlook PST| Eudora | Entourage | Others | Boxbe | Zipped Files | MailWasherSpam Reporting Utilities - These are plug-in add-ons for your email client and all free: Outlook VBA Macro "Advanced" Outlook Macro | Gmail |Yahoo | Thunderbird | Apple Mail | K9 | Habu | gloomytrousers | Okopipi|
The Path of Fake Goods Sold in SPAM
Information
Right Now! - BlogKnujOn News Archive: Past Blogs - Current - KnujOn covered by... - Мошеннической Деятельности!
- 2010 - 2009 - 2008 - 2007 - 2006 - 2005
|
KnujOn Presentation by Garth Bruen at
OWASP Sept 24th 2008 in New York |
KnujOn at Ole Miss ![]() NAGTRI/NCJRL CYBERSECURITY Conference |
{top}
Cybercrime and Security
Illicit Internet Pharmacy may be one of many types cybercrime but it is the most prevelent, most criminally profitable, and the most dangerous.Read Our Series on Illicit Pharmacy:
When Registrars Look the Other Way, Drug-Dealers Get Paid [CircleID]
What's Driving Spam and Domain Fraud? Illicit Drug Traffic [CircleID]
Online Drug Traffic and Registrar Policy [CircleID]
Internet Drug Traffic, Service Providers and Intellectual Property [CircleID]
|
Video explains underground Internet drug market |
Support KnujOn by buying this messenger bag
|
Who Hosts/Sponsors the Illicit Pharamcy Sites?
[DATA TO BE POSTED]
{top}
{top}
Infrastructure and Industry
ICANN
ben edelman danny younger (icannology)| Kieren McCarthy| Internic|IANA
ICANN WDPRS Compliance Failures
ICANN and Registrar Reports ICANN Registrar Audit June, 2010 - Registrar Report February, 2009 - Registrar Report May, 2008 - Phantom Registrars - Registries|ccTLD||Regional Registries
Registrars||ISPs Registrar Port 43 Failures
Protect Yourself
{top}
Tech Security Feeds:
cnn| fox| msnbc| zdnet| bbc| gcn| reuters| theregister|
KnujOn Press| techworld| computerworld| securityblog.itproportal| castlecops| brian krebs| spamhaus|
first| mcafee avert labs| dhs| cnet| contrarisk| ddanchev.blogspot| jonathan zdziarski|
Мошеннической Деятельности!
Виагры больше нет? (osp.ru)Оплот мирового зла: россия и киберпреступность (ibusiness.ru)
обама проведёт зачистку интернет-регистраторов (habrahabr.ru)
Нeykрoтимый спap (kommersant.ru)
Международная организация ICANN обвиняется во взяточничестве (dinohost.ru)
KnujOn Has Been Covered By...






