Slashdot Log In
Spammers Hijacking IP Space
Posted by
kdawson
on Tuesday April 29, @08:54PM
from the open-and-shut-case dept.
from the open-and-shut-case dept.
Ron Guilmette writes "As reported in the Washington Post's Security Fix blog, a substantial hunk of IP address space has apparently been taken over by notorious mass e-mailing company Media Breakaway, LLC, formerly known as OptInRealBig, via means that are at best questionable. The block in question is 134.17.0.0/16, which I documented in depth in an independent investigation. (Apparently, the President of Media Breakaway has now admitted to the Washington Post that his company has been occupying and using the 134.17.0.0/16 block and that front company JKS Media, which provides routing to the block, is actually owned by Media Breakaway.) Remarkably, the president of Media Breakaway, who happens to be an attorney, is trying to defend his company's apparent snatching of this block based upon his own rather novel legal theory that ARIN doesn't have jurisdiction over any IP address space that was handed out before ARIN was formed, in 1997."
Related Stories
Firehose:Spammers Hijacking IP Space? You be the judge by Anonymous Coward
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
Full
Abbreviated
Hidden
Loading... please wait.

I say we dust off and nuke the site from orbit (Score:3, Funny)
Reply to This
If only we could... (Score:3, Funny)
Hell, if there was any trouble, we could even transform into an angry lynch mob - THEN lets see who owns that space eh? EH? Whaddya say?
Reply to This
Wouldn't it be nice... (Score:4, Insightful)
There was a time when the Internet was a 'small' enough place that it would have even been feasible. Kind of like blacklisting a Usenet server for spam.
Reply to This
Re:Wouldn't it be nice... (Score:4, Insightful)
That would then lead to another group "claiming" another spot of space, and so on and so forth - until there was no legitimate or unused space left at all - then you would have to fight the same fight with many many people rather than one spamming company as we have now.
Reply to This
Parent
Re:Wouldn't it be nice... (Score:4, Insightful)
Reply to This
Parent
Hijacking the IP Space Owners, not just the Space (Score:3, Informative)
The rules for managing pre-ARIN space aren't totally clear, but nobody's worried about them too much because they were mostly owned by large reputable organization
SImple, blackhole the IP space (Score:2)
Re:SImple, blackhole the IP space (Score:4, Interesting)
Reply to This
Parent
Firewall Updated (Score:2)
[John]
Blackhole == Defeat! (Score:5, Insightful)
Also, if we simply blackhole that IP, what's going to happen when a legitimate user tries to use that space. It's going to go to bollocks for them when they find that the rest of the net is ignoring them already.
Reply to This
Snotty Scotty Richter (Score:4, Informative)
Reply to This
Blackholing this address space may not be wise (Score:5, Insightful)
What's been happening for years now is well-meaning admins blocking various IP addresses / blocks and/or domain names. Their motives are good, but after the address or domain name is blocked they almost never go back and recheck to see if the block is still needed. What this leads to over time are holes in the address space that can't be used, awkward or no routes to some addresses from some other addresses, etc. Especially in this time of zombie machines; blackhole that IP address and you've knocked some individual off line - but you've done nothing to reduce the amount of spam / viruses / worms / etc.
This is what killed ORBS and other services of that type. Easy to add domains / addresses to the blocklist, but difficult to remove them. Eventually the list becomes useless...
Much better solution: make an example out of the people who are squatting on this netblock. Break out the pitchforks and torches...
Reply to This
Re:Blackholing this address space may not be wise (Score:5, Insightful)
Reply to This
Parent
Re: (Score:3, Insightful)
If you're willing to pay enough for the bandwidth you will probably find a major provider to let you advertise your range.
For the origin of that range to get as far as they have, they clearly had paperwork to prove to their upstream that the range is a
Spammers know no limits (Score:5, Insightful)
It's good that I do not own any firearms and good that I do not know where these people live and good that I lack the means to get there. If I had those things and an air-tight alibi, I wouldn't hesitate to make my first murder one of these people.
Reply to This
"Hijack?" (Score:5, Interesting)
If he is president of a company that owns the company that provides routing for the block, doesn't that mean he has legal ownership of that block?
Yes, if the block is used primarily for spam, I'm all for people blackholing the range. And if he's using it for illegal purposes, yes, he should be punished (and the range appropriated). But I don't see where the term "hijacking" could be applied at all.
If I own some cars and use them in crimes, I haven't "hijacked" anyone.
What am I missing?
Reply to This
Re:"Hijack?" (Score:5, Informative)
$ whois 134.17.0.0
OrgName: SF Bay Packet Radio
OrgID: SBPR-1
Address: 1490 W 121st Ave
Address: Suite 201
City: Westminster
StateProv: CO
PostalCode: 80234
Country: US
NetRange: 134.17.0.0 - 134.17.255.255
CIDR: 134.17.0.0/16
NetName: BAY-PR-NET
NetHandle: NET-134-17-0-0-1
Parent: NET-134-0-0-0-0
NetType: Direct Assignment
NameServer: NS1.SFBPRSERVICES.COM
NameServer: NS2.SFBPRSERVICES.COM
Comment:
RegDate: 1989-04-12
Updated: 2007-10-05
Reply to This
Parent
Re:"Hijack?" (Score:4, Interesting)
It looks like what they did was just register a company with a similar-sounding name to a defunct organization that had an old
Then they had another front company obtain an AS number and provide routing, and suddenly they have lots of IPs from which to send spam.
The even-creepier part is that it looks like they have another block stolen through similar means (currently registered to a P.O. box in NYC) and possible connections to Russian spammers, which means basically the Russian mafia.
Here's hoping that when the whole thing falls apart, the Russian mob comes calling for this guy's head. Ironically they're the best chance for this guy getting the slow, painful death he so richly deserves.
Reply to This
Parent
A lack of ethics (Score:5, Interesting)
We need a strong societal repudiation of the violation of ethics. Organizations like Microsoft, SCO, and the like and people like Bill Gates, Darl McBride, etc. need to be made pariahs for the shameless unethical and illegal behavior.
"Spamming" is unethical. The only reason why it is done is because their unethical behavior is not shunned.
Reply to This
Re: (Score:3, Insightful)
Set firewalls on shun! (Score:3, Funny)
-ted
Reply to This
who is linking this to the backbone? (Score:3, Insightful)
because that's all it is, a mid level isp has added someone to their routing tables with ip's that they have no right to. simply telling their provider to correct their configurations or all their traffic will be dropped should be enough, indeed it should be mandatory for backbone providers to do this in order for them to legally keep their own ip ranges. anything else is asking for people to start claiming ip's all over the place and before you know it each isp will route you to a different site for the same ip, making the internet useless.
Reply to This
easily fixed...... (Score:3, Funny)
iptables -A spam -s 134.17.0.0/16 -j DROP
Reply to This
Re: (Score:3, Informative)
Re: (Score:3, Informative)