amuck-landowner

Quadranet Needs to BAN SMTP. Spammer UTOPIA.

drmike

100% Tier-1 Gogent
Been a week since the last screen cap.. and we have much of the same...


1UDnOIJQ68kh161.png
 
Last edited by a moderator:

AuroraZero

Active Member
This does not surprise me really, and would be the reason I dropped my Crissic account like a hot potato when they took over there. Sometimes it is just not worth the head ache and grief you get from new owners. It is easier to set up shop on a new clean system some place else.
 

drmike

100% Tier-1 Gogent
Doesn't look to well for QuadraSpam...


Will have to move out of that net. 

Well, I just talked the other day with a provider in QN LAX, and they are having constant issues with ranges from QN on various blacklists.  Not their customers who are the issue, but other Quadranet customers soiling the larger ranges.  Collateral damage in essence,  the effects of having your data living in a crime infested IP neighborhood.


Lots more folks out of necessity are going to migrate away from Quadranet. 


Right now on Senderbase, QN is #2 for Domains at 83.   QN is #1 for Last Day Volume at 8.1.  
 

Licensecart

Active Member
Well what do we expect with their buyouts :) but yeah they are the new ColoCrossing and who thought we'd say that. If they don't clean it up a lot of hosts will just block their IPs and then they'll have legit un-happy customers.
 

willie

Active Member
What does this mean about blocking IP's?  Blocking email or complete nullrouting?  I have a Crissic vps that has been working pretty well but I don't send any email from it and don't plan to.  I could see not renewing it but it has around 9 months before expiration so I'm wondering what problems I'm in for if I keep using it til then.
 

Licensecart

Active Member
What does this mean about blocking IP's?  Blocking email or complete nullrouting?  I have a Crissic vps that has been working pretty well but I don't send any email from it and don't plan to.  I could see not renewing it but it has around 9 months before expiration so I'm wondering what problems I'm in for if I keep using it til then.

Adding the ranges in a blacklist (block list) so if someone visits on a VPN / Sends email they get rejected.
 
... and now Quadranet is #1 on Senderbase...  Congrats to QN for all the effort.  I think it's time for a press release.

@"drmike"


First off, we aren't the only ones on this list, so keep watching the list and hammer us only. Evidently you have a problem with us.


If it is due to recent buyouts, then I'd like to tell you I'm sincerely sorry you lost your job as "marketing" at Crissic. Ever since, you've been a sour one. Also I'd say it would be very nice that you shared with the community your involvement with *many* VPS companies, as you "silently" work for many brands and or offer your services to them on the down low. While OK to do so, you shouldn't have to hide it :)


As for senderbase, this list is going to change daily, and we're doing our best to eliminate any spammers on our network. 


Nothing more needs to be said from our end in this thread, and anyone seeking abuse support, or wishes to report spam on our network please e-mail [email protected]
 

drmike

100% Tier-1 Gogent
@"drmike"


As for senderbase, this list is going to change daily, and we're doing our best to eliminate any spammers on our network. 

Hey, you guys are first and been riding top 3 for weeks if not months.  No grand scam in making you guys number one, you folks earn that rank on a daily basis.  I don't own Cisco so, be assured there is no fiddling with your rank to meet my needs.  I just wish you'd clean the place up and have competence in house doing what is necessary.  You have the staff, either they are on leashes and abuse is cash and off limits or folks are incompetent.  There is no excuse for abuse at this level.

First off, we aren't the only ones on this list, so keep watching the list and hammer us only. Evidently you have a problem with us.


If it is due to recent buyouts, then I'd like to tell you I'm sincerely sorry you lost your job as "marketing" at Crissic. Ever since, you've been a sour one. Also I'd say it would be very nice that you shared with the community your involvement with *many* VPS companies, as you "silently" work for many brands and or offer your services to them on the down low. While OK to do so, you shouldn't have to hide it :)

As for the other pointed finger,  I don't think it's any secret that I've offered services to companies in this industry for a number of years.


Prior to that buyout I mostly gave you lads a free ride ticket.  Not like folks didn't drop bunches of data about abuse and issues at QN, cause they did.  Figured Adam was good people so I let you guys slide.  Should have been on QN's case years back.


I AM ON YOUR SHIT NOW NOT BECAUSE OF YOUR IP WHORING, BUT BECAUSE OF WHAT GOES ON WITHIN YOUR ASN IS HIGH LEVEL OF BAD. 


You want me to turn my head and cough/ignore, clean up the abuse.  That simple.
 
Last edited by a moderator:

drmike

100% Tier-1 Gogent
120% increase ouch :eek:

120% is a lot but the way they factor numbers at Senderbase is not linear.  The math is greatly multiplied.  You go from a 7.0 to an 8.0 it isn't like you sent 1 million more pieces of spam.  It's like you sent 7 million and then tossed at least millions more on top.


I need to document the formula so we can estimate the sheer volume we are speaking of.
 
Last edited by a moderator:

DomainBop

Dormant VPSB Pathogen
Happy 2016 everyone, quadranet still is at the spam spam spam game..... ugh!


firefox_2016-02-06_23-30-34.png

All that SPAM is probably a result of lazy idiots (it takes 2 friggin' seconds to press the update button on WP) having their blogs compromised because they're running very old WordPress versions that have several critical vulnerabilities.  Here's an example of one of those sites running outdated software on the Quadranet network. The site's IP address is blacklisted by Barracuda (see http://www.barracudacentral.org/reputation?r=1&ip=72.11.150.114 ) and is running the very outdated  WordPress 4.2.4  http://www.ilanmishan.com/readme.html .  

  • WordPress versions 4.3 and earlier are vulnerable to a cross-site scripting vulnerability when processing shortcode tags (CVE-2015-5714). Reported by Shahar Tal and Netanel Rubin of Check Point.
  • A separate cross-site scripting vulnerability was found in the user list table. Reported by Ben Bidner of the WordPress security team.
  • Finally, in certain cases, users without proper permissions could publish private posts and make them sticky (CVE-2015-5715). Reported by Shahar Tal and Netanel Rubin of Check Point.
  • -------------------------------------------
  • WordPress versions 4.4 and earlier are affected by a cross-site scripting vulnerability that could allow a site to be compromised. This was reported by Crtc4L.
  • -----------------------------------------------
  • WordPress versions 4.4.1 and earlier are affected by two security issues: a possible SSRF for certain local URIs, reported by Ronni Skansing; and an open redirection attack, reported by Shailesh Suthar.
 

drmike

100% Tier-1 Gogent
All that SPAM is probably a result of lazy idiots (it takes 2 friggin' seconds to press the update button on WP) having their blogs compromised because they're running very old WordPress versions that have several critical vulnerabilities.  Here's an example of one of those sites running outdated software on the Quadranet network. The site's IP address is blacklisted by Barracuda (see http://www.barracudacentral.org/reputation?r=1&ip=72.11.150.114 ) and is running the very outdated  WordPress 4.2.4  http://www.ilanmishan.com/readme.html .  

Well anything is possible, but usually unlikely. I never understand why people leave things online, unused and lingering...


Quite funny that Ilan's blog is busted up example.   We can't blame him though, I don't think he understands English very well (so was said in moons past).  You know malware like Word-de-Press-ion is all about manual in English. :)


Not to worry though, on the very same IP = http://supercrazybananas.com/readme.html = WP Version 3.5


^^^ I kid you not.
 

graeme

Active Member
I don't know the last time I've need to send email out via SMTP normally.

I do, and most of clients do, if only to send and error reporting and web form emails to ourselves. Admittedly it would not be terribly difficult to send it, but I have not bothered so far.

Everyone seems to use 3rd party systems to broadcast their email since it is such a PITA otherwise

True, but that bothers me. Instead of it being an open service everyone can run, we are are being gradually being pushed towards a smaller number of providers able to deliver email. The more we deliver through a few suppliers, the more willing everyone will be to blacklist anyone other than the biggest suppliers, the more pressure there will be to use the biggest suppliers in a vicious circle. We could easily end with only a handful of organisations able to reliably deliver email, which is worrying in terms of both privacy and competition.
 
Top
amuck-landowner