I got this email inquiring about data center space, from the most honest scumbag, *EVER* today. Operational relevance? Well, if everyone would turn these people down, we'd have a lot less problems to deal with. Sadly, requests like these happen far too often, but never have I had someone come right out and explain what they were doing up front like this without having to dig in to it. Scumbag email: ------------ Hello, I need servers to host botnet controller. Botnet controller is software that sends tasks to bots. Bots are hosts which send spam emails to millions of addresses. It's not direct spam but abuses on botnet contoller are received from time to time. What is your policy in case of receiving abuses and what is your policy in case of receiving a lot of abuses? What is policy about spam (not direct from your ips as I mentioned above)? Is it possible to host botnet controller in your datacenter during long-term time? Thank you. -------------- The part that leaves me feeling good is that they do get abuse complaints from time to time. There's hope.
On Dec 30, 2009, at 1:04 PM, Jerry Pasker wrote:
I got this email inquiring about data center space, from the most honest scumbag, *EVER* today. Operational relevance? Well, if everyone would turn these people down, we'd have a lot less problems to deal with. Sadly, requests like these happen far too often, but never have I had someone come right out and explain what they were doing up front like this without having to dig in to it.
They are going around to many providers. Word of warning: At least one provider has commented that www.$COMPANY.com was DoS'ed when he turned down their request, although he said it was a pretty weak DoS. Guess his botnet controller isn't very good. :) -- TTFN, patrick
Scumbag email: ------------ Hello,
I need servers to host botnet controller. Botnet controller is software that sends tasks to bots. Bots are hosts which send spam emails to millions of addresses. It's not direct spam but abuses on botnet contoller are received from time to time. What is your policy in case of receiving abuses and what is your policy in case of receiving a lot of abuses? What is policy about spam (not direct from your ips as I mentioned above)? Is it possible to host botnet controller in your datacenter during long-term time?
Thank you. --------------
The part that leaves me feeling good is that they do get abuse complaints from time to time. There's hope.
On Dec 30, 2009, at 1:04 PM, Jerry Pasker wrote:
I got this email inquiring about data center space, from the most honest scumbag, *EVER* today. Operational relevance? Well, if everyone would turn these people down, we'd have a lot less problems to deal with. Sadly, requests like these happen far too often, but never have I had someone come right out and explain what they were doing up front like this without having to dig in to it.
Scumbag email: ------------ Hello,
I need servers to host botnet controller. Botnet controller is software that sends tasks to bots. Bots are hosts which send spam emails to millions of addresses. It's not direct spam but abuses on botnet contoller are received from time to time. What is your policy in case of receiving abuses and what is your policy in case of receiving a lot of abuses? What is policy about spam (not direct from your ips as I mentioned above)? Is it possible to host botnet controller in your datacenter during long-term time?
Thank you. --------------
The part that leaves me feeling good is that they do get abuse complaints from time to time. There's hope.
Of course, it could also be a joe job to frame the inquirer... --Steve Bellovin, http://www.cs.columbia.edu/~smb
Would it be possible to string along and coordinate with the appropriate law enforcement entity? tv ----- Original Message ----- From: "Jerry Pasker" <info@n-connect.net> To: <nanog@nanog.org> Sent: Wednesday, December 30, 2009 12:04 PM Subject: just...wow.
I got this email inquiring about data center space, from the most honest scumbag, *EVER* today. Operational relevance? Well, if everyone would turn these people down, we'd have a lot less problems to deal with. Sadly, requests like these happen far too often, but never have I had someone come right out and explain what they were doing up front like this without having to dig in to it.
Scumbag email: ------------ Hello,
I need servers to host botnet controller. Botnet controller is software that sends tasks to bots. Bots are hosts which send spam emails to millions of addresses. It's not direct spam but abuses on botnet contoller are received from time to time. What is your policy in case of receiving abuses and what is your policy in case of receiving a lot of abuses? What is policy about spam (not direct from your ips as I mentioned above)? Is it possible to host botnet controller in your datacenter during long-term time?
Thank you. --------------
The part that leaves me feeling good is that they do get abuse complaints from time to time. There's hope.
Would it be possible to string along and coordinate with the appropriate law enforcement entity?
tv
Probably, but the fourth basic law of human stupidity (google it, and have a laugh) promisees that I would suffer for doing so. It's why I've never ever attempted to deal with any of these types of requests beyond just figuring out what the game is. Once you know the game, any intelligent person quickly concludes that the only way to win at that game is to not play.
LOL! That was purty good and mostly true. Well, I was thinking from the standpoint of 1) They are going somewhere, maybe not you 2) breaking law(s) 3) someone has to intervene, eventually. You could apply the above to any crime really. And they essentially told you they are going to commit it...sort of like our recent plane story. I don't think it's a question of intelligence. It's more a question of risk and whether or not it fits your profile. If not, turn your head the other way and cough. :) tv ----- Original Message ----- From: "Jerry Pasker" <info@n-connect.net> To: <nanog@nanog.org> Sent: Wednesday, December 30, 2009 5:57 PM Subject: Re: just...wow.
Would it be possible to string along and coordinate with the appropriate law enforcement entity?
tv
Probably, but the fourth basic law of human stupidity (google it, and have a laugh) promisees that I would suffer for doing so. It's why I've never ever attempted to deal with any of these types of requests beyond just figuring out what the game is. Once you know the game, any intelligent person quickly concludes that the only way to win at that game is to not play.
participants (4)
-
Jerry Pasker
-
Patrick W. Gilmore
-
Steven Bellovin
-
Tony Varriale