Dear colleagues
In february this year we detected a lot of spam, being sent from dial-up accounts in the responsibility of AS9145.
Those spam emails are sent from the well known swiss spamer 'Martin Fürst' who won't get internet-access at almost all ISP in Switzerland and many more in UK Germany and China.
I had quite a few phone calls with EWETEL techs and finaly with their law responsible (Mr. Heder.)
As I understood their policy does not allow them to block internet-access to the customer sending those spam mails. (Nor to reveal his identity which I never asked for... he is too well known).
Today more spam-mails with typical 'Martin Fürst' signatures arrived to various spam-traps and customer addresses.
Unfortunately right now I was not able to catch Mr. Heder, and on the support number they again didn't want to put me through to the abuse-desk responsible or to the management, ceo or cto of EWETEL.
So I think time has come the ISP running mailservers affected by those spam-floods from EWETEL have to put up a bit more pressure.
We are considering filtering AS9145 on our routers and to list the IP-ranges of AS9145 on the SWINOG Antispam Blacklists; if we still don't get the reply from EWETEL that this customer is definitively banned from their network within a few days.
What are your opinions? Would other ISP join?
Mit freundlichen Grüssen
Benoit Panizzon -- I m p r o W a r e A G - System Services ______________________________________________________
Zurlindenstrasse 29 Tel +41 61 826 93 00 CH-4133 Pratteln Fax +41 61 826 93 01 Schweiz Web http://www.imp.ch ______________________________________________________
I think two we can not abuse a AS9145. I think over 1000 normal clients have a big problem. For spamers like Fürst. It give only one way. The big ISP like Sunrise must make a better authorisation. This is for spammers and hobby hackers not the best way if you dial a Phonne Number 0840555555 and you take as username sunrise Password freesurf. Some of the bigger Provider has Dial in Numbers with bad or zero access control.
Blacklist all Dial in Numbers is a Problem like Sorbs...
I don't like Fürst... I think we shall canceld his phone line. This is the best way.
The big ISP like Sunrise must make a better authorisation.<
Trust me, we see wich CLI was used to send "Socks Spam" and "Swissair Things". Therefore we have blocked a wide range of ISDN Blocks. I hope the new law of Spam here in Switzerland will come fastly, because then it's not important wich ISP the Spamer uses. If he has his Business here in Switzerland, we can catch him. (And Mr. Fürst has all Business in Regensdorf)
So, i don't know why we need to take away / change the sunrise/freesurf dialup ? We can react very fast on dialup users and also we can block very fast dial up on our Switches. We see all CLI used on the dial up.
Sincerely
Daniele
-----Original Message----- From: swinog-bounces@lists.swinog.ch [mailto:swinog-bounces@lists.swinog.ch] On Behalf Of Xaver Aerni Sent: Freitag, 23. Juni 2006 17:03 To: swinog@swinog.ch Subject: AW: [swinog] RFD: Filtering/Blacklisting AS9145 (EWETEL)Cause:Providing internet access to known spamer
I think two we can not abuse a AS9145. I think over 1000 normal clients have a big problem. For spamers like Fürst. It give only one way. The big ISP like Sunrise must make a better authorisation. This is for spammers and hobby hackers not the best way if you dial a Phonne Number 0840555555 and you take as username sunrise Password freesurf. Some of the bigger Provider has Dial in Numbers with bad or zero access control.
Blacklist all Dial in Numbers is a Problem like Sorbs...
I don't like Fürst... I think we shall canceld his phone line. This is the best way.
_______________________________________________ swinog mailing list swinog@lists.swinog.ch http://lists.swinog.ch/cgi-bin/mailman/listinfo/swinog