<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Fail2Ban Reporting Service</title>
	<atom:link href="http://blog.blocklist.de/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.blocklist.de</link>
	<description>We hope our service makes the Internet better, safer and helps to clean the infected PCs.</description>
	<lastBuildDate>Tue, 15 May 2012 19:24:57 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.2</generator>
		<item>
		<title>hideme.ru prohibits to use there vpn of forum spam and blocking lists as well as basic blocklist.de</title>
		<link>http://blog.blocklist.de/2012/05/15/hideme-ru-prohibits-to-use-there-vpn-of-forum-spam-and-blocking-lists-as-well-as-basic-blocklist-de/</link>
		<comments>http://blog.blocklist.de/2012/05/15/hideme-ru-prohibits-to-use-there-vpn-of-forum-spam-and-blocking-lists-as-well-as-basic-blocklist-de/#comments</comments>
		<pubDate>Tue, 15 May 2012 19:24:57 +0000</pubDate>
		<dc:creator>blocklist</dc:creator>
				<category><![CDATA[Allgemein]]></category>
		<category><![CDATA[blocklist]]></category>
		<category><![CDATA[forum-spam]]></category>
		<category><![CDATA[hideme.ru]]></category>
		<category><![CDATA[vpn]]></category>

		<guid isPermaLink="false">http://blog.blocklist.de/?p=618</guid>
		<description><![CDATA[We have found a leak-Site on there a User have posted a Mail from hideme.ru. Original: &#160; Translated via google to English: &#160; You can see, that he list BlockList.de to one of the Blacklist which the User does not insert there VPN-IP]]></description>
			<content:encoded><![CDATA[<p>We have found a leak-Site on there a User have posted a Mail from hideme.ru.</p>
<p>Original:</p>
<p><a href="http://blog.blocklist.de/wp-content/uploads/2012/05/asdasd.ru_.jpg"><img class="alignnone size-medium wp-image-620" title="asdasd.ru" src="http://blog.blocklist.de/wp-content/uploads/2012/05/asdasd.ru_-300x155.jpg" alt="" width="300" height="155" /></a></p>
<p>&nbsp;</p>
<p>Translated via google to English:</p>
<p><a href="http://blog.blocklist.de/wp-content/uploads/2012/05/asdasd.ru_.translate_en_rot.jpg"><img class="alignnone size-large wp-image-623" title="asdasd.ru.translate_en_rot" src="http://blog.blocklist.de/wp-content/uploads/2012/05/asdasd.ru_.translate_en_rot-1024x532.jpg" alt="" width="1024" height="532" /></a></p>
<p>&nbsp;</p>
<p>You can see, that he list BlockList.de to one of the Blacklist which the User does not insert there VPN-IP <img src='http://blog.blocklist.de/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /> </p>
]]></content:encoded>
			<wfw:commentRss>http://blog.blocklist.de/2012/05/15/hideme-ru-prohibits-to-use-there-vpn-of-forum-spam-and-blocking-lists-as-well-as-basic-blocklist-de/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Nobistech, IP-Range 173.234.225.0 &#8211; 173.234.227.255 permanently blocked</title>
		<link>http://blog.blocklist.de/2012/05/09/nobistech-ip-range-173-234-225-0-173-234-227-255-permanently-blocked/</link>
		<comments>http://blog.blocklist.de/2012/05/09/nobistech-ip-range-173-234-225-0-173-234-227-255-permanently-blocked/#comments</comments>
		<pubDate>Wed, 09 May 2012 02:12:11 +0000</pubDate>
		<dc:creator>blocklist</dc:creator>
				<category><![CDATA[Allgemein]]></category>
		<category><![CDATA[173.234.225.]]></category>
		<category><![CDATA[ipvnow.com]]></category>
		<category><![CDATA[nobistech.net]]></category>
		<category><![CDATA[squid]]></category>
		<category><![CDATA[ubiquityservers]]></category>

		<guid isPermaLink="false">http://blog.blocklist.de/?p=609</guid>
		<description><![CDATA[In earlier Posts we have write over nobistech AS15003 here: Nobistech &#8211; ubiquityservers We see a long time that only Squid-Proxys (Version from 3.1.4 to 3.1.9) with SSH on the Port 2382 and with the Domain ipvnow.com with no sites (linked to a enom-buy-site) in the Reverse-DNS&#8230;. We have 1,406 Records to IPs with the [...]]]></description>
			<content:encoded><![CDATA[<p>In earlier Posts we have write over <a title="Nobistech on blocklist.de" href="https://www.blocklist.de/en/search.html?as=15003" target="_blank">nobistech</a> <a title="Nobistech on blocklist.de" href="https://www.blocklist.de/en/search.html?as=15003" target="_blank">AS15003</a> here:</p>
<p><a title="a lot of new Hosts from nobistech (ubiquityservers) is abused for reg/bad-bot" href="http://blog.blocklist.de/2012/03/27/a-lot-of-new-hosts-from-nobistech-ubiquityservers-is-abused-for-regbad-bot/" target="_blank">Nobistech &#8211; ubiquityservers</a></p>
<p>We see a long time that only Squid-Proxys (Version from 3.1.4 to 3.1.9) with <strong>SSH</strong> on the</p>
<p><strong>Port 2382</strong></p>
<p>and with the Domain <span style="text-decoration: underline;"><strong>ipvnow.com</strong></span> with no sites (linked to a enom-buy-site) in the Reverse-DNS&#8230;.</p>
<p>We have 1,406 Records to IPs with the rdns hase ipvnow.com in the host.<br />
262 with ns0.ipvnow.com</p>
<p>We think the Customer behind is the User &#8220;keliix06&#8243;.</p>
<p>&nbsp;</p>
<p>We have send to abuse AT nobistech.net only for the last 8 Days ~500 Reports and we send only all 24 hours for each ip/attack one report&#8230;</p>
<p>&nbsp;</p>
<p>Now, we have blocked the complete IP-Range permantly:</p>
<p><strong>173.234.225.0 &#8211; 173.234.227.255</strong></p>
<p>in the all-Export-List and in the RBL.</p>
<p>We have informed nobistech too in the same time we public this article.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.blocklist.de/2012/05/09/nobistech-ip-range-173-234-225-0-173-234-227-255-permanently-blocked/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>DNSBL von blocklist.de sehr gefragt</title>
		<link>http://blog.blocklist.de/2012/05/07/dnsbl-von-blocklist-de-sehr-gefragt/</link>
		<comments>http://blog.blocklist.de/2012/05/07/dnsbl-von-blocklist-de-sehr-gefragt/#comments</comments>
		<pubDate>Mon, 07 May 2012 15:11:43 +0000</pubDate>
		<dc:creator>blocklist</dc:creator>
				<category><![CDATA[Allgemein]]></category>
		<category><![CDATA[blacklist]]></category>
		<category><![CDATA[dnsbl]]></category>
		<category><![CDATA[forum]]></category>
		<category><![CDATA[postfix]]></category>
		<category><![CDATA[rbl]]></category>

		<guid isPermaLink="false">http://blog.blocklist.de/?p=605</guid>
		<description><![CDATA[Ein kurzes aktivieren der Logs auf einem der mittlerweile 4 RBL-Server hat gezeigt, das in 2 Minuten mehreer hundert unterschiedliche (unique) IP-Adressen (hauptsächlich DNS-Server) die RBL-Listen von blocklist.de abfragen. Je nach Liste, welche nach Service-Diensten/Arten aufgesplittet sind, umfassen diese im Durschnitt über 6.000 IP-Adressen. Wie man die RBL-Listen von blocklist z.B. selbst im Postfix, Amavis, [...]]]></description>
			<content:encoded><![CDATA[<p>Ein kurzes aktivieren der Logs auf einem der mittlerweile 4 RBL-Server hat gezeigt, das in 2 Minuten mehreer hundert unterschiedliche (unique) IP-Adressen (hauptsächlich DNS-Server) die RBL-Listen von blocklist.de abfragen.</p>
<p>Je nach Liste, welche nach Service-Diensten/Arten aufgesplittet sind, umfassen diese im Durschnitt über 6.000 IP-Adressen.</p>
<p>Wie man die RBL-Listen von blocklist z.B. selbst im Postfix, Amavis, Policyd oder Apache einsetzten kann ist unter folgender URL im Forum beschrieben:</p>
<p><a title="Anleitung zur Nutzung der rbl von blocklist in verschiedenen diensten" href="https://forum.blocklist.de/viewtopic.php?f=11&amp;t=17" target="_blank">https://forum.blocklist.de/viewtopic.php?f=11&amp;t=17</a></p>
<p>Aktuell unterstüzten die RBL-Server noch kein IPv6, da müssen wir auf Updates vom Hersteller warten.</p>
<p>Bei Fragen, Anregungen oder Wünschen einfach ins Forum posten <img src='http://blog.blocklist.de/wp-includes/images/smilies/icon_wink.gif' alt=';-)' class='wp-smiley' /> </p>
]]></content:encoded>
			<wfw:commentRss>http://blog.blocklist.de/2012/05/07/dnsbl-von-blocklist-de-sehr-gefragt/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>New Tor-Server-Check (dnsbl from sectoor.de)</title>
		<link>http://blog.blocklist.de/2012/05/07/new-tor-server-check-dnsbl-from-sectoor-de/</link>
		<comments>http://blog.blocklist.de/2012/05/07/new-tor-server-check-dnsbl-from-sectoor-de/#comments</comments>
		<pubDate>Mon, 07 May 2012 00:45:12 +0000</pubDate>
		<dc:creator>blocklist</dc:creator>
				<category><![CDATA[Allgemein]]></category>
		<category><![CDATA[badbot]]></category>
		<category><![CDATA[dnsbl]]></category>
		<category><![CDATA[regbot]]></category>
		<category><![CDATA[sectoor.de]]></category>
		<category><![CDATA[tor]]></category>
		<category><![CDATA[torservers]]></category>
		<category><![CDATA[whitelist]]></category>

		<guid isPermaLink="false">http://blog.blocklist.de/?p=601</guid>
		<description><![CDATA[After our last notice we have build a new Check after the &#8220;normal&#8221; Whitelist and other Checks. Now, we look into the DNSBL from sectoor.de for the spaming IP, when the Attack-Typ is RegBot or BadBot. When the Tor-Server is in the dnsbl, but not in our Whitelist we received a notification to check the [...]]]></description>
			<content:encoded><![CDATA[<p>After our last <a title="Dear Tor-Server owners" href="http://blog.blocklist.de/2012/04/29/dear-tor-server-owners/">notice</a> we have build a new Check after the &#8220;normal&#8221; Whitelist and other Checks.</p>
<p>Now, we look into the DNSBL from <a title="tor dnsbl" href="http://sectoor.de/tor.php" target="_blank">sectoor.de</a> for the spaming IP, when the Attack-Typ is RegBot or BadBot.</p>
<p>When the Tor-Server is in the dnsbl, but not in our Whitelist we received a notification to check the Tor-Server and block them permanently from our Honeypot-systems or whitelist them.</p>
<p>&nbsp;</p>
<p>This make the way from tor-Server-Admins easier.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.blocklist.de/2012/05/07/new-tor-server-check-dnsbl-from-sectoor-de/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Dear Tor-Server owners</title>
		<link>http://blog.blocklist.de/2012/04/29/dear-tor-server-owners/</link>
		<comments>http://blog.blocklist.de/2012/04/29/dear-tor-server-owners/#comments</comments>
		<pubDate>Sun, 29 Apr 2012 13:06:09 +0000</pubDate>
		<dc:creator>blocklist</dc:creator>
				<category><![CDATA[Allgemein]]></category>
		<category><![CDATA[exit-node]]></category>
		<category><![CDATA[tor]]></category>
		<category><![CDATA[tor-server]]></category>
		<category><![CDATA[tor-servers]]></category>
		<category><![CDATA[whitelist]]></category>

		<guid isPermaLink="false">http://blog.blocklist.de/?p=592</guid>
		<description><![CDATA[Dear Tor-Server-Owners, please set a Webpage online on the Tor-Exit-IP which show that the IP is an Tor-Exit-Node-Server like this: Site is from http://torservers.net And when you received a Report from us, please contact us and send us your IP-Adresses from your Tor-Servers. We check the http-Site and when you have a short Text online [...]]]></description>
			<content:encoded><![CDATA[<p>Dear Tor-Server-Owners,</p>
<p>please set a Webpage online on the Tor-Exit-IP which show that the IP is an Tor-Exit-Node-Server like this:</p>
<p><a href="http://blog.blocklist.de/wp-content/uploads/2012/04/tor-servers.jpg"><img class="alignnone size-large wp-image-593" title="tor-servers" src="http://blog.blocklist.de/wp-content/uploads/2012/04/tor-servers-1024x536.jpg" alt="" width="1024" height="536" /></a></p>
<p><a title="torservers.net" href="http://torservers.net" target="_blank">Site is from http://torservers.net</a></p>
<p>And when you received a Report from us, please <a title="contact us (blocklist)" href="https://www.blocklist.de/en/contact.html" target="_blank">contact us</a> and send us your IP-Adresses from your Tor-Servers. We check the http-Site and when you have a short Text online which say or linked to more over Tor-Server, we add your IP into the Whitelist and mark them as Tor-/Proxy-Server and dont send new Reports to you.</p>
<p>But when you have not a description or site online which tell that the ip is an Tor-Server, we could not add your IP into the whitelist. And we thinking your are only a SEO-Spamer and you will safe your Spam-Server with xrumer, senuke, sickmarekting&#8230;..</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.blocklist.de/2012/04/29/dear-tor-server-owners/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>BadBot-Attacks is almost at 400k mark</title>
		<link>http://blog.blocklist.de/2012/04/23/badbot-attacks-is-almost-at-400k-mark/</link>
		<comments>http://blog.blocklist.de/2012/04/23/badbot-attacks-is-almost-at-400k-mark/#comments</comments>
		<pubDate>Mon, 23 Apr 2012 19:50:16 +0000</pubDate>
		<dc:creator>blocklist</dc:creator>
				<category><![CDATA[Allgemein]]></category>
		<category><![CDATA[footer]]></category>
		<category><![CDATA[forum]]></category>
		<category><![CDATA[google]]></category>
		<category><![CDATA[honeypots]]></category>
		<category><![CDATA[seo]]></category>
		<category><![CDATA[spam]]></category>

		<guid isPermaLink="false">http://blog.blocklist.de/?p=585</guid>
		<description><![CDATA[On the the &#8220;SEO-User&#8221; (Foren-Spamer) found one of a honeypot-site which are not direct from us: http://theseobay.com/xrumer-support/1599-blocklist-de-footprint.html But the Volume of Spampostings and Spam-Registratios continues to rise more and more: &#160; Our Honeypot-Sites has in all Header/Footer and Agreements a Text, that all Postings and Registrations will be automatically reported. But we have a lot [...]]]></description>
			<content:encoded><![CDATA[<p>On the the &#8220;SEO-User&#8221; (Foren-Spamer) found one of a honeypot-site which are not direct from us:</p>
<p><a title="http://theseobay.com/xrumer-support/1599-blocklist-de-footprint.html" href="http://theseobay.com/xrumer-support/1599-blocklist-de-footprint.html" target="_blank">http://theseobay.com/xrumer-support/1599-blocklist-de-footprint.html</a></p>
<p><a href="http://blog.blocklist.de/wp-content/uploads/2012/04/honeypot-keliix06-spamer_k.jpg"><img class="alignnone size-medium wp-image-586" title="honeypot-keliix06-spamer_k" src="http://blog.blocklist.de/wp-content/uploads/2012/04/honeypot-keliix06-spamer_k-300x157.jpg" alt="" width="300" height="157" /></a></p>
<p>But the Volume of Spampostings and Spam-Registratios continues to rise more and more:</p>
<p><a href="http://blog.blocklist.de/wp-content/uploads/2012/04/allstats-day_388_badbots.png"><img class="alignnone size-medium wp-image-587" title="allstats-day_388_badbots" src="http://blog.blocklist.de/wp-content/uploads/2012/04/allstats-day_388_badbots-300x205.png" alt="" width="300" height="205" /></a></p>
<p>&nbsp;</p>
<p>Our Honeypot-Sites has in all Header/Footer and Agreements a Text, that all Postings and Registrations will be automatically reported. But we have a lot of Honeypots too which are not from us, so there use other methods to identify the spamer and report them over us. In the next Step, we lookup for the AS-Networks which have to much ignorant our Reports and block them complete (like <a title="http://www.blocklist.de/en/search.html?as=15895" href="http://www.blocklist.de/en/search.html?as=15895" target="_blank">AS15895</a>).</p>
<p>Google blocks the urls which are listen in the postings from the seo-user, because he downloads our Lists of links from your postings and used it to find Spamer or User who works against the rules <img src='http://blog.blocklist.de/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /> </p>
]]></content:encoded>
			<wfw:commentRss>http://blog.blocklist.de/2012/04/23/badbot-attacks-is-almost-at-400k-mark/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Kein wirklicher Rückgang vom Foren-Spam</title>
		<link>http://blog.blocklist.de/2012/04/12/kein-wirklicher-ruckgang-vom-foren-spam/</link>
		<comments>http://blog.blocklist.de/2012/04/12/kein-wirklicher-ruckgang-vom-foren-spam/#comments</comments>
		<pubDate>Thu, 12 Apr 2012 00:39:12 +0000</pubDate>
		<dc:creator>blocklist</dc:creator>
				<category><![CDATA[Allgemein]]></category>
		<category><![CDATA[foren]]></category>
		<category><![CDATA[proxy]]></category>
		<category><![CDATA[regbot]]></category>
		<category><![CDATA[reverse-proxy]]></category>
		<category><![CDATA[seo]]></category>
		<category><![CDATA[spam]]></category>

		<guid isPermaLink="false">http://blog.blocklist.de/?p=574</guid>
		<description><![CDATA[Trotz das XSserver.eu IPs/Server nun sperrt, welche Foren-Spam versenden, ist kein Rückgang fest zu stellen, wobei recht viele IPs nun weg sind: Am 01.04.2012 hat XSserver.eu damit angefangen die Server zu sperren. Kurz davor und danach haben wir bereits festgestellt, das immer mehr neue IP-Adressen für BadBod und RegBot genutzt wurden (allein von einer Honeypot-Domain, [...]]]></description>
			<content:encoded><![CDATA[<p>Trotz das XSserver.eu IPs/Server <a title="XSserver.eu sperrt SEO-/Foren-Spamer" href="http://blog.blocklist.de/2012/04/05/xsserver-eu-sperrt-nun-endlich-foren-seo-spamer/">nun sperrt</a>, welche Foren-Spam versenden, ist kein Rückgang fest zu stellen, wobei recht viele IPs nun weg sind:</p>
<p><a href="http://blog.blocklist.de/wp-content/uploads/2012/04/allstats-week_xsserver.eu_.png"><img class="alignnone size-medium wp-image-575" title="allstats-week_xsserver.eu" src="http://blog.blocklist.de/wp-content/uploads/2012/04/allstats-week_xsserver.eu_-300x205.png" alt="" width="300" height="205" /></a></p>
<p>Am 01.04.2012 hat XSserver.eu damit angefangen die Server zu sperren.</p>
<p>Kurz davor und danach haben wir bereits festgestellt, das immer mehr neue IP-Adressen für BadBod und RegBot genutzt wurden (allein von einer Honeypot-Domain, wo sehr wenig Eintragungen stattfinden):</p>
<p><a href="http://blog.blocklist.de/wp-content/uploads/2012/04/newips.jpg"><img class="alignnone size-medium wp-image-583" title="newips" src="http://blog.blocklist.de/wp-content/uploads/2012/04/newips-300x59.jpg" alt="" width="300" height="59" /></a></p>
<p>In einem anderen Foren, werden neue, falsch konfigurierte oder öffentliche Proxy-Server angeboten und das wohl mit einer großen Anzahl:</p>
<p><a href="http://blog.blocklist.de/wp-content/uploads/2012/04/xrumer-proxys1.jpg"><img class="alignnone size-medium wp-image-580" title="xrumer-proxys" src="http://blog.blocklist.de/wp-content/uploads/2012/04/xrumer-proxys1-300x167.jpg" alt="" width="300" height="167" /></a></p>
<p>&nbsp;</p>
<p>Dies sind hauptsächlich auch Reverse-Proxy wie z.B. nginx, die eigentlich zum Caching genutzt werden sollen. Aktuell scheinen die Seo-User die falsch konfigurierten Proxy zu suchen.</p>
<p>Wir reporten diese aber natürlich, wenn die in unsere Honeypots spamen und haben dadurch schon viele IPs mit falschen Proxy-Server deaktiviert, bzw. die Inhaber haben diese korrigiert.</p>
<p><em>Liebe Spamer</em>, ein Captcha wo immer z.B. nur 1234 drin steht, sollte doch auffallen oder? <img src='http://blog.blocklist.de/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /> </p>
]]></content:encoded>
			<wfw:commentRss>http://blog.blocklist.de/2012/04/12/kein-wirklicher-ruckgang-vom-foren-spam/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>xsserver.eu sperrt endlich Foren-/Seo-Spamer</title>
		<link>http://blog.blocklist.de/2012/04/05/xsserver-eu-sperrt-nun-endlich-foren-seo-spamer/</link>
		<comments>http://blog.blocklist.de/2012/04/05/xsserver-eu-sperrt-nun-endlich-foren-seo-spamer/#comments</comments>
		<pubDate>Thu, 05 Apr 2012 14:59:19 +0000</pubDate>
		<dc:creator>blocklist</dc:creator>
				<category><![CDATA[Allgemein]]></category>
		<category><![CDATA[blackhatworld]]></category>
		<category><![CDATA[blocked]]></category>
		<category><![CDATA[seo]]></category>
		<category><![CDATA[spam]]></category>
		<category><![CDATA[stopforumspam]]></category>
		<category><![CDATA[xsserver.eu]]></category>

		<guid isPermaLink="false">http://blog.blocklist.de/?p=566</guid>
		<description><![CDATA[Xsserver.eu ist ein Provider, welcher beim Reseller Optimate-Server.de hosted. Dieses AS hatte zuletzt über 700 IPs bei blocklist gelistet, welche RegBot- und BadBot-Spam gelistet waren. Zum Teil hatte abuse@xss&#8230;eu mehrere tausend Abuse-Reports von uns erhalten, aber nie etwas unternommen. Nachdem wir einmal das Netz komplett geblockt hatten, weil zu viele unterschiedliche IPs zu sehr gespamt [...]]]></description>
			<content:encoded><![CDATA[<p>Xsserver.eu ist ein Provider, welcher beim Reseller <a title="AS 197043 optimate-server.de" href="https://www.blocklist.de/de/search.html?as=197043" target="_blank">Optimate-Server.de</a> hosted.</p>
<p>Dieses AS hatte zuletzt über 700 IPs bei blocklist gelistet, welche RegBot- und BadBot-Spam gelistet waren. Zum Teil hatte abuse@xss&#8230;eu mehrere tausend Abuse-Reports von uns erhalten, aber nie etwas unternommen. Nachdem wir einmal das Netz komplett geblockt hatten, weil zu viele unterschiedliche IPs zu sehr gespamt hatten, war das Netz aber in der <a title="Export listed IPs" href="https://www.blocklist.de/de/export.html" target="_blank">Export-Liste</a> immer noch gelistet.</p>
<p>Der Netzwerk-Inhaber (Marcel Edler) hat uns dann vor ein paar Tagen angeschrieben und uns mitgeteilt, das er die IPs sperrt und xsserver.eu noch mal informiert. Wir haben darauf hin alle IP-Adressen gelöscht und natürlich auch den längst überfälligen Netz-Block.</p>
<p>&nbsp;</p>
<p>Nun sehen wir in vielen Foren wie <strong>theseobay.com</strong> oder <strong>blackhatworld.com, </strong>das XSserver.eu die IPs mitlerweile sperrt und für 10$ eine neue IP zuteilt, wenn diese aber auch gelistet wird,  wird der Server komplett gesperrt:</p>
<p>Auszug aus dem Forum:</p>
<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-</p>
<div><img src="http://www.blackhatworld.com/blackhat-seo/images/icons/icon1.gif" alt="Default" border="0" /> <strong>Xsserver Not Allowing SB and Xrumer</strong></div>
<hr size="1" />
<div id="post_message_4071999">
<p>Just got this email from them:</p>
<div>
<div>Quote:</div>
<table width="100%" border="0" cellspacing="0" cellpadding="6">
<tbody>
<tr>
<td>From past few months we are facing lots of issues from SPAMHAUS they have blacklisted all our IPs due to ongoing complaints from forum SPAM, from now onwards we are not allowing those <acronym title="Search Engine Optimization">SEO</acronym> tools i.e XRUMER or Scrapebox etc, our network provider is suspending all the IPs which are active on forum spam and which are listed on <a href="http://www.stopforumspam.com/" target="_blank">http://www.stopforumspam.com/</a>, please note that once your IPs are blocked we will assign you clean un-used IP for $10 extra charge and if again the new IP is blocked then the server will be suspended permanently.Please note that this email is only for those customers who are using our servers for Forum SPAM.If you have any question please do not hesitate to open a support ticket.Kind Regards,</p>
<p>XSserver.Eu Team</td>
</tr>
</tbody>
</table>
</div>
<p>I am cancelling my service now <img title="Big Grin" src="http://www.blackhatworld.com/blackhat-seo/images/smilies/biggrin.gif" alt="" border="0" /></p>
<p>&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;-</p>
<p><a href="http://blog.blocklist.de/wp-content/uploads/2012/04/xsserver.eu-block-forum-spamer.jpg"><img class="alignnone size-medium wp-image-567" title="xsserver.eu-block-forum-spamer" src="http://blog.blocklist.de/wp-content/uploads/2012/04/xsserver.eu-block-forum-spamer-300x157.jpg" alt="" width="300" height="157" /></a></p>
<p>&nbsp;</p>
<p>Aktuell sind für das ASN nur 20 IPs gelistet, wovon 10 aktiv gelistet sind (letzter Angriff/Spam ist jünger als 48 Stunden).</p>
<p>Wir haben die Hoffnung, das dadurch der Foren-Spam zurückgeht und Deutschland in der Statistik sinkt.</p>
<p>Wir sind gespannt. Meinungen gerne hier oder im Forum:</p>
<p><a title="[Blog] xsserver.eu sperrt nun endlich Foren-/&quot;Seo&quot;-Spamer" href="https://forum.blocklist.de/viewtopic.php?f=4&amp;t=100" target="_blank">https://forum.blocklist.de/viewtopic.php?f=4&amp;t=100</a></p>
</div>
]]></content:encoded>
			<wfw:commentRss>http://blog.blocklist.de/2012/04/05/xsserver-eu-sperrt-nun-endlich-foren-seo-spamer/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>current stats of blocklist (user, traffic, attacks&#8230;..)</title>
		<link>http://blog.blocklist.de/2012/04/04/current-stats-of-blocklist-user-traffic-attacks/</link>
		<comments>http://blog.blocklist.de/2012/04/04/current-stats-of-blocklist-user-traffic-attacks/#comments</comments>
		<pubDate>Wed, 04 Apr 2012 09:49:09 +0000</pubDate>
		<dc:creator>blocklist</dc:creator>
				<category><![CDATA[Allgemein]]></category>
		<category><![CDATA[1]]></category>
		<category><![CDATA[5TB]]></category>
		<category><![CDATA[mysql]]></category>
		<category><![CDATA[rbl-api]]></category>
		<category><![CDATA[traffic]]></category>

		<guid isPermaLink="false">http://blog.blocklist.de/?p=561</guid>
		<description><![CDATA[Currently, blocklist.de has the following Stats/User: User: 453 Server: 568 Attacks: 16,559,116 Reports: 2,696,197 Daily Mails: ~280499 Web-Traffic: ~78 GB RBL-/API-Traffic: ~210 GB Mail (In/Out)-Traffic: ~29 GB Traffic over IPv6 (Mail, Web..): ~2GB To this data, there comes 1,5TB  Traffic between the Web-/Mail-Server and the MySQL-Server. The MySQL-Server sends over 4.1 GB each Hour out.]]></description>
			<content:encoded><![CDATA[<p>Currently, blocklist.de has the following Stats/User:</p>
<p>User: <strong>453</strong></p>
<p>Server: <strong>568</strong></p>
<p>Attacks: <strong>16,559,116</strong></p>
<p>Reports: <strong>2,696,197</strong></p>
<p>Daily Mails: <strong>~280499</strong></p>
<p>Web-Traffic: <strong>~78 GB</strong></p>
<p>RBL-/API-Traffic: <strong>~210 GB</strong></p>
<p>Mail (In/Out)-Traffic: <strong>~29 GB </strong><strong></strong></p>
<p>Traffic over IPv6 (Mail, Web..): <strong>~2GB<br />
</strong></p>
<p>To this data, there comes <strong>1,5TB </strong> Traffic between the Web-/Mail-Server and the MySQL-Serve<strong>r. </strong>The MySQL-Server sends over <strong>4.1 GB </strong>each Hour out.<strong><br />
</strong></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.blocklist.de/2012/04/04/current-stats-of-blocklist-user-traffic-attacks/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>China169Backbone top 12 of 15</title>
		<link>http://blog.blocklist.de/2012/04/04/china169backbone-top-12-of-15/</link>
		<comments>http://blog.blocklist.de/2012/04/04/china169backbone-top-12-of-15/#comments</comments>
		<pubDate>Tue, 03 Apr 2012 23:04:16 +0000</pubDate>
		<dc:creator>blocklist</dc:creator>
				<category><![CDATA[Allgemein]]></category>
		<category><![CDATA[attackers]]></category>
		<category><![CDATA[brute-force]]></category>
		<category><![CDATA[china]]></category>
		<category><![CDATA[china169]]></category>
		<category><![CDATA[login]]></category>
		<category><![CDATA[top]]></category>

		<guid isPermaLink="false">http://blog.blocklist.de/?p=557</guid>
		<description><![CDATA[This Month, the CHINA169-BACKBONE CNCGROUP China169 Backbone  has the most attacking IP-Addresses. In the top 15 of the IP-Addresses with the most Attacks, 12 IPs are from China169Backbone: &#160; This is realy bad. Also the Brute-Force-Attacks on the Login has greatly increased. The most Netzworks from China who calls the Login-Page are few Minutes later [...]]]></description>
			<content:encoded><![CDATA[<p>This Month, the <a title="Weitere Details zu dem AS-Netz: CHINA169-BACKBONE CNCGROUP China169 Backbone" href="http://www.blocklist.de/de/search.html?as=4837">CHINA169-BACKBONE CNCGROUP China169 Backbone  </a>has the most attacking IP-Addresses. In the top 15 of the IP-Addresses with the most Attacks, 12 IPs are from China169Backbone:</p>
<p><a href="http://blog.blocklist.de/wp-content/uploads/2012/04/blocklist.de-top-atacker-china.jpg"><img class="alignnone size-medium wp-image-558" title="blocklist.de-top-atacker-china" src="http://blog.blocklist.de/wp-content/uploads/2012/04/blocklist.de-top-atacker-china-300x266.jpg" alt="" width="300" height="266" /></a></p>
<p>&nbsp;</p>
<p>This is realy bad. Also the Brute-Force-Attacks on the <a title="Login of blocklist" href="https://www.blocklist.de/de/login.html" target="_blank">Login </a>has greatly increased. The most Netzworks from China who calls the Login-Page are few Minutes later complete blocked&#8230;.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.blocklist.de/2012/04/04/china169backbone-top-12-of-15/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

