<html>
<head>
<meta content="text/html; charset=windows-1252"
http-equiv="Content-Type">
</head>
<body text="#000000" bgcolor="#FFFFFF">
<p>Hi again, Ron!</p>
<p>First of all thank you for all your contributions to this list -
I personally (as I stated before) use to null-route prefixes you
report.</p>
<p>I don't intend to recommend this sort of policy to everyone -
this is just my company's routing policy. Some others (even large
backbones) even use Spamhaus's DROP lists which I don't trust.</p>
<p>I think what we all need is some RIPE-managed database to list
such prefixes and NCC-appointed persons to approve them as 'rogue'
if there was enough evidence provided. Such a database may be
provided by means of DNSBL and BGP feed. Such a database can be <b>voluntarily</b>
used by those ISPs who are commited to keeping Internet clean of
UBE, DDoS, spoofing, and so on and so forth. This would be a good
community-driven alternative to commercial DNSBLs, DROPs, etc.</p>
<br>
<div class="moz-cite-prefix">On 08/09/16 22:53, Ronald F. Guilmette
wrote:<br>
</div>
<blockquote cite="mid:27678.1470772414@server1.tristatelogic.com"
type="cite">
<pre wrap="">I see that there is an interesting and active discussion on this now.
Everyone may be sure that I will be posting further comments shortly
which clarify my personal position on all the matters discussed so far.
In the meantime however, I just realized that I neglected to clarify
how I came to find that VERIFIED[.]IS web site in the first place.
It may not be at all important, but just so everyone knows, I found
that VERIFIED[.]IS indirectly. First, I stumbled onto the following
web site, which is clearly selling credit cards *and* also (U.S.)
social security numbers (SSNs) and dates-of-birth (DOBs). (You can
even pick out which U.S. state you prefer!) These bits of information
are often helpful to people intent on committing identity theft:
<a class="moz-txt-link-freetext" href="http://www.wellsfargo.lequeshop">http://www.wellsfargo.lequeshop</a>[.]ru/
As you can see, there is an email address on the above page. It is
<a class="moz-txt-link-rfc2396E" href="mailto:mixx@exploit.im"><mixx@exploit.im></a>. I simply googled that email address and then
started to visit the web sites found.
One of them was verified[.]is
But this criminal carder ... who seems to be Russian... is also active
on many other web sites, presumably selling what he has to offer in
many different forums.
Regards,
rfg
</pre>
</blockquote>
<br>
<div class="moz-signature">-- <br>
Kind regards,<br>
CTO at<br>
<b>Foton Telecom CJSC</b><br>
Tel.: +7 (499) 679-99-99<br>
AS42861 on <a href="http://as42861.peeringdb.com/">PeeringDB</a>,
<a href="https://radar.qrator.net/as42861">Qrator</a>, <a
href="http://bgp.he.net/AS42861">BGP.HE.NET</a><br>
<a href="%0Ahttp://ipv6actnow.org/">http://ipv6actnow.org/</a></div>
</body>
</html>