Rocksolid Light

Welcome to Rocksolid Light

mail  files  register  newsreader  groups  login

Message-ID:  

Earth is a beta site.


computers / news.admin.net-abuse.email / Re: (PDF) Rockwood and Wilkins Fractures in Children 9th Edition by Waters

SubjectAuthor
* (PDF) Rockwood and Wilkins Fractures in Children 9th Edition by WatersAndreas Kohlbach
+* (PDF) Rockwood and Wilkins Fractures in Children 9th Edition byDavid W. Hodgins
|+- (PDF) Rockwood and Wilkins Fractures in Children 9th Edition byThe Doctor
|`* (PDF) Rockwood and Wilkins Fractures in Children 9th Edition by WatersAndreas Kohlbach
| +- (PDF) Rockwood and Wilkins Fractures in Children 9th Edition byDavid Ritz
| `* (PDF) Rockwood and Wilkins Fractures in Children 9th Edition by WatersThe Doctor
|  `- (PDF) Rockwood and Wilkins Fractures in Children 9th Edition byDavid Ritz
`- (PDF) Rockwood and Wilkins Fractures in Children 9th Edition by WatersThe Doctor

1
Re: (PDF) Rockwood and Wilkins Fractures in Children 9th Edition by Waters

<87zghq16jb.fsf@usenet.ankman.de>

  copy mid

https://news.novabbs.org/computers/article-flat.php?id=805&group=news.admin.net-abuse.email#805

  copy link   Newsgroups: comp.os.linux.misc news.admin.net-abuse.email
Followup: news.admin.net-abuse.email
Path: i2pn2.org!i2pn.org!eternal-september.org!reader01.eternal-september.org!.POSTED!not-for-mail
From: ank@spamfence.net (Andreas Kohlbach)
Newsgroups: comp.os.linux.misc,news.admin.net-abuse.email
Subject: Re: (PDF) Rockwood and Wilkins Fractures in Children 9th Edition by Waters
Followup-To: news.admin.net-abuse.email
Date: Sun, 03 Jul 2022 12:54:00 -0400
Organization: A noiseless patient Spider
Lines: 31
Message-ID: <87zghq16jb.fsf@usenet.ankman.de>
References: <59781171-88d3-47ec-98c7-97fc78859159n@googlegroups.com>
<t9qg9g$l2b$46@gallifrey.nk.ca>
<op.1opbr1wla3w0dxdave@hodgins.homeip.net>
MIME-Version: 1.0
Content-Type: text/plain
Injection-Info: reader01.eternal-september.org; posting-host="2cdea5aa58addaddb2632fe5db144d54";
logging-data="3256788"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX19P6ek0Qw/8ivFBn6UHrtzZ"
User-Agent: Gnus/5.13 (Gnus v5.13) Emacs/27.1 (gnu/linux)
Cancel-Lock: sha1:r0iuZWuJT0xfZ7aMwilk7yRsV64=
sha1:/Shm/j6tePYkGhfjmNRk+m4CGKs=
X-No-Archive: Yes
 by: Andreas Kohlbach - Sun, 3 Jul 2022 16:54 UTC

On Sat, 02 Jul 2022 19:05:51 -0400, David W. Hodgins wrote:
>
> On Sat, 02 Jul 2022 18:19:28 -0400, The Doctor <doctor@doctor.nl2k.ab.ca> wrote:
>> In article <59781171-88d3-47ec-98c7-97fc78859159n@googlegroups.com>,
>> hester holt <hesterholt7@gmail.com> wrote:
>> This abusive spamtroll came from
>> whois 146.70.103.22
>> This could be coming from a botnet!
>
> It is coming from a botnet. If you check the headers of the articles, there
> are a few from each of many ip addresses. Makes filtering on posting host
> useless.

It's posted via Google. I don't think a botnet is involved.

> It's may be trying to expand the botnet by getting people to open the pdf
> files using adobe reader. It may only infect systems with users running old
> version. I haven't bothered checking to see what it does. Just basing my
> guess on what I've seen in the past.
>
> Given current trends, it may be trying to deploy ransomware that encrypts the
> user's files. That way it doesn't need to elevate privileges after the user
> opens the pdf file.

I don't see a file attached in the spam. When I visited the URL in the
spam I placed a test order to gather date from the spammer. It then goes
to a legit PayPal page to pay. Since the order (of course) failed I hope
the spammer contact me via the throw-away email address I provided. Will
post what I get then in the abuse group (I set a followup-to here).
--
Andreas

Re: (PDF) Rockwood and Wilkins Fractures in Children 9th Edition by Waters

<op.1oq0e4gda3w0dxdave@hodgins.homeip.net>

  copy mid

https://news.novabbs.org/computers/article-flat.php?id=806&group=news.admin.net-abuse.email#806

  copy link   Newsgroups: news.admin.net-abuse.email
Path: i2pn2.org!i2pn.org!eternal-september.org!reader01.eternal-september.org!.POSTED!not-for-mail
From: dwhodgins@nomail.afraid.org (David W. Hodgins)
Newsgroups: news.admin.net-abuse.email
Subject: Re: (PDF) Rockwood and Wilkins Fractures in Children 9th Edition by
Waters
Date: Sun, 03 Jul 2022 16:55:42 -0400
Organization: A noiseless patient Spider
Lines: 11
Message-ID: <op.1oq0e4gda3w0dxdave@hodgins.homeip.net>
References: <59781171-88d3-47ec-98c7-97fc78859159n@googlegroups.com>
<t9qg9g$l2b$46@gallifrey.nk.ca> <op.1opbr1wla3w0dxdave@hodgins.homeip.net>
<87zghq16jb.fsf@usenet.ankman.de>
MIME-Version: 1.0
Content-Type: text/plain; charset=utf-8; format=flowed; delsp=yes
Content-Transfer-Encoding: 8bit
Injection-Info: reader01.eternal-september.org; posting-host="dd74c5547091f9d7cf3755764a96baf9";
logging-data="3307679"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX18ClVbZTkJWJEZ8D+J6cwqLyeus8k5ihAw="
User-Agent: Opera Mail/12.16 (Linux)
Cancel-Lock: sha1:vOnnkZGK2LJRgNk2Osf7Nd0lAhM=
 by: David W. Hodgins - Sun, 3 Jul 2022 20:55 UTC

On Sun, 03 Jul 2022 12:54:00 -0400, Andreas Kohlbach <ank@spamfence.net> wrote:
> It's posted via Google. I don't think a botnet is involved.

The Injection-Info header in the articles shows it's coming from a wide variety
of ip addresses (hence botnet), and using multiple google accounts.

All done to ensure filtering is more difficult without using wider rules that
may block non spam articles. It also ensures that even if google were handling
spam reports properly, it would be a game of whack-a-mole.

Regards, Dave Hodgins

Re: (PDF) Rockwood and Wilkins Fractures in Children 9th Edition by Waters

<t9t0g5$f3h$57@gallifrey.nk.ca>

  copy mid

https://news.novabbs.org/computers/article-flat.php?id=807&group=news.admin.net-abuse.email#807

  copy link   Newsgroups: news.admin.net-abuse.email
Path: i2pn2.org!i2pn.org!weretis.net!feeder6.news.weretis.net!news.nk.ca!.POSTED.doctor.nl2k.ab.ca!not-for-mail
From: doctor@doctor.nl2k.ab.ca (The Doctor)
Newsgroups: news.admin.net-abuse.email
Subject: Re: (PDF) Rockwood and Wilkins Fractures in Children 9th Edition by Waters
Date: Sun, 3 Jul 2022 21:08:21 -0000 (UTC)
Organization: NetKnow News
Message-ID: <t9t0g5$f3h$57@gallifrey.nk.ca>
References: <59781171-88d3-47ec-98c7-97fc78859159n@googlegroups.com> <t9qg9g$l2b$46@gallifrey.nk.ca> <op.1opbr1wla3w0dxdave@hodgins.homeip.net> <87zghq16jb.fsf@usenet.ankman.de>
Injection-Date: Sun, 3 Jul 2022 21:08:21 -0000 (UTC)
Injection-Info: gallifrey.nk.ca; posting-host="doctor.nl2k.ab.ca:204.209.81.1";
logging-data="15473"; mail-complaints-to="usenet@gallifrey.nk.ca"
X-Newsreader: trn 4.0-test77 (Sep 1, 2010)
Originator: doctor@doctor.nl2k.ab.ca (The Doctor)
 by: The Doctor - Sun, 3 Jul 2022 21:08 UTC

In article <87zghq16jb.fsf@usenet.ankman.de>,
Andreas Kohlbach <ank@spamfence.net> wrote:
>On Sat, 02 Jul 2022 19:05:51 -0400, David W. Hodgins wrote:
>>
>> On Sat, 02 Jul 2022 18:19:28 -0400, The Doctor
><doctor@doctor.nl2k.ab.ca> wrote:
>>> In article <59781171-88d3-47ec-98c7-97fc78859159n@googlegroups.com>,
>>> hester holt <hesterholt7@gmail.com> wrote:
>>> This abusive spamtroll came from
>>> whois 146.70.103.22
>>> This could be coming from a botnet!
>>
>> It is coming from a botnet. If you check the headers of the articles, there
>> are a few from each of many ip addresses. Makes filtering on posting host
>> useless.
>
>It's posted via Google. I don't think a botnet is involved.
>
>> It's may be trying to expand the botnet by getting people to open the pdf
>> files using adobe reader. It may only infect systems with users running old
>> version. I haven't bothered checking to see what it does. Just basing my
>> guess on what I've seen in the past.
>>
>> Given current trends, it may be trying to deploy ransomware that encrypts the
>> user's files. That way it doesn't need to elevate privileges after the user
>> opens the pdf file.
>
>I don't see a file attached in the spam. When I visited the URL in the
>spam I placed a test order to gather date from the spammer. It then goes
>to a legit PayPal page to pay. Since the order (of course) failed I hope
>the spammer contact me via the throw-away email address I provided. Will
>post what I get then in the abuse group (I set a followup-to here).
>--
>Andreas

This botnot is really complicated to explain.
--
Member - Liberal International This is doctor@nk.ca Ici doctor@nk.ca
Yahweh, Queen & country!Never Satan President Republic!Beware AntiChrist rising!
Look at Psalms 14 and 53 on Atheism https://www.empire.kred/ROOTNK?t=94a1f39b
To use too much mercy is to end up with too little. -unknown Beware https://mindspring.com

Re: (PDF) Rockwood and Wilkins Fractures in Children 9th Edition by Waters

<t9t134$f3h$63@gallifrey.nk.ca>

  copy mid

https://news.novabbs.org/computers/article-flat.php?id=808&group=news.admin.net-abuse.email#808

  copy link   Newsgroups: news.admin.net-abuse.email
Path: i2pn2.org!i2pn.org!weretis.net!feeder6.news.weretis.net!news.nk.ca!.POSTED.doctor.nl2k.ab.ca!not-for-mail
From: doctor@doctor.nl2k.ab.ca (The Doctor)
Newsgroups: news.admin.net-abuse.email
Subject: Re: (PDF) Rockwood and Wilkins Fractures in Children 9th Edition by
Waters
Date: Sun, 3 Jul 2022 21:18:28 -0000 (UTC)
Organization: NetKnow News
Message-ID: <t9t134$f3h$63@gallifrey.nk.ca>
References: <59781171-88d3-47ec-98c7-97fc78859159n@googlegroups.com> <op.1opbr1wla3w0dxdave@hodgins.homeip.net> <87zghq16jb.fsf@usenet.ankman.de> <op.1oq0e4gda3w0dxdave@hodgins.homeip.net>
Injection-Date: Sun, 3 Jul 2022 21:18:28 -0000 (UTC)
Injection-Info: gallifrey.nk.ca; posting-host="doctor.nl2k.ab.ca:204.209.81.1";
logging-data="15473"; mail-complaints-to="usenet@gallifrey.nk.ca"
X-Newsreader: trn 4.0-test77 (Sep 1, 2010)
Originator: doctor@doctor.nl2k.ab.ca (The Doctor)
 by: The Doctor - Sun, 3 Jul 2022 21:18 UTC

In article <op.1oq0e4gda3w0dxdave@hodgins.homeip.net>,
David W. Hodgins <dwhodgins@nomail.afraid.org> wrote:
>On Sun, 03 Jul 2022 12:54:00 -0400, Andreas Kohlbach <ank@spamfence.net> wrote:
>> It's posted via Google. I don't think a botnet is involved.
>
>The Injection-Info header in the articles shows it's coming from a wide variety
>of ip addresses (hence botnet), and using multiple google accounts.
>
>All done to ensure filtering is more difficult without using wider rules that
>may block non spam articles. It also ensures that even if google were handling
>spam reports properly, it would be a game of whack-a-mole.
>
>Regards, Dave Hodgins

Europe and Asia. I thought I saw Africa as well.
--
Member - Liberal International This is doctor@nk.ca Ici doctor@nk.ca
Yahweh, Queen & country!Never Satan President Republic!Beware AntiChrist rising!
Look at Psalms 14 and 53 on Atheism https://www.empire.kred/ROOTNK?t=94a1f39b
To use too much mercy is to end up with too little. -unknown Beware https://mindspring.com

Re: (PDF) Rockwood and Wilkins Fractures in Children 9th Edition by Waters

<87zghozqdx.fsf@usenet.ankman.de>

  copy mid

https://news.novabbs.org/computers/article-flat.php?id=809&group=news.admin.net-abuse.email#809

  copy link   Newsgroups: news.admin.net-abuse.email
Path: i2pn2.org!i2pn.org!usenet.goja.nl.eu.org!news.freedyn.de!eternal-september.org!reader01.eternal-september.org!.POSTED!not-for-mail
From: ank@spamfence.net (Andreas Kohlbach)
Newsgroups: news.admin.net-abuse.email
Subject: Re: (PDF) Rockwood and Wilkins Fractures in Children 9th Edition by Waters
Date: Mon, 04 Jul 2022 14:25:46 -0400
Organization: A noiseless patient Spider
Lines: 11
Message-ID: <87zghozqdx.fsf@usenet.ankman.de>
References: <59781171-88d3-47ec-98c7-97fc78859159n@googlegroups.com>
<t9qg9g$l2b$46@gallifrey.nk.ca>
<op.1opbr1wla3w0dxdave@hodgins.homeip.net>
<87zghq16jb.fsf@usenet.ankman.de>
<op.1oq0e4gda3w0dxdave@hodgins.homeip.net>
MIME-Version: 1.0
Content-Type: text/plain
Injection-Info: reader01.eternal-september.org; posting-host="37f373abe3c601025fee41995f57f0bc";
logging-data="3618786"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX1/HGJ/DZLNYkIOV5uiEgtmP"
User-Agent: Gnus/5.13 (Gnus v5.13) Emacs/27.1 (gnu/linux)
Cancel-Lock: sha1:m0oNl0M1A8QmzdyZYaJLBREhFYA=
sha1:QtaGxnYcN933Ue9MwVuRClGHPHQ=
X-No-Archive: Yes
 by: Andreas Kohlbach - Mon, 4 Jul 2022 18:25 UTC

On Sun, 03 Jul 2022 16:55:42 -0400, David W. Hodgins wrote:
>
> On Sun, 03 Jul 2022 12:54:00 -0400, Andreas Kohlbach <ank@spamfence.net> wrote:
>> It's posted via Google. I don't think a botnet is involved.
>
> The Injection-Info header in the articles shows it's coming from a wide variety
> of ip addresses (hence botnet), and using multiple google accounts.

Good point. I overlooked this. Although it could be TOR?
--
Andreas

Re: (PDF) Rockwood and Wilkins Fractures in Children 9th Edition by Waters

<817p663n-9n89-q827-s822-77271rsp351@zvaqfcevat.pbz>

  copy mid

https://news.novabbs.org/computers/article-flat.php?id=810&group=news.admin.net-abuse.email#810

  copy link   Newsgroups: news.admin.net-abuse.usenet news.admin.net-abuse.email
Followup: news.admin.net-abuse.usenet
Path: i2pn2.org!i2pn.org!usenet.goja.nl.eu.org!3.eu.feeder.erje.net!feeder.erje.net!fu-berlin.de!uni-berlin.de!individual.net!not-for-mail
From: dritz@mindspring.com (David Ritz)
Newsgroups: news.admin.net-abuse.usenet,news.admin.net-abuse.email
Subject: Re: (PDF) Rockwood and Wilkins Fractures in Children 9th Edition by
Waters
Followup-To: news.admin.net-abuse.usenet
Date: Mon, 4 Jul 2022 15:08:38 -0500
Organization: SpamBusters!
Lines: 73
Message-ID: <817p663n-9n89-q827-s822-77271rsp351@zvaqfcevat.pbz>
References: <59781171-88d3-47ec-98c7-97fc78859159n@googlegroups.com> <t9qg9g$l2b$46@gallifrey.nk.ca> <op.1opbr1wla3w0dxdave@hodgins.homeip.net> <87zghq16jb.fsf@usenet.ankman.de> <op.1oq0e4gda3w0dxdave@hodgins.homeip.net> <87zghozqdx.fsf@usenet.ankman.de>
Mime-Version: 1.0
Content-Type: text/plain; charset=US-ASCII
X-Trace: individual.net 6z2owABUzSUuj/Nua2xotQ5nn5uZBc3ZxNKYvvVQB//YyhSnq3
X-Orig-Path: not-for-mail
Cancel-Lock: sha1:Ua8MmUuM5ZKAWgb75Qr9xQ4VTrY=
In-Reply-To: <87zghozqdx.fsf@usenet.ankman.de>
OpenPGP: id=9CD055375C05466038D2194852BC29991A12DEEB
X-Comment-1: Spam is bad. <http://trillian.mit.edu/~jc/humor/WhatIsSpam.html>
X-Comment-2: LART a spammer for Dobbs.
X-Comment-3: Invalid assumptions tend to produce invalid conclusions.
X-Comment-4: This message is intended to be read with a monospaced font.
X-Meow: yes
 by: David Ritz - Mon, 4 Jul 2022 20:08 UTC

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

[ note followups-to ]

On Monday, 04 July 2022 14:25 -0400,
in article <87zghozqdx.fsf@usenet.ankman.de>,
Andreas Kohlbach <ank@spamfence.net> wrote:

> On Sun, 03 Jul 2022 16:55:42 -0400, David W. Hodgins wrote:

>> On Sun, 03 Jul 2022 12:54:00 -0400,
>> Andreas Kohlbach <ank@spamfence.net> wrote:

>>> It's posted via Google. I don't think a botnet is involved.

>> The Injection-Info header in the articles shows it's coming from a
>> wide variety of ip addresses (hence botnet), and using multiple
>> google accounts.

Those wildly guessing 'botnet' have failed to do even the most
rudimentary research, before reaching this erroneous and quite
muddleheaded conclusion.

> Good point. I overlooked this. Although it could be TOR?

TOR seems much closer, but slightly off-target, as none of the
addresses I checked were identified as Tor exit nodes.

After looking up the original article,
<59781171-88d3-47ec-98c7-97fc78859159n@googlegroups.com>
(http://al.howardknight.net/?ID=165696354700), I took a look at the
most recent spam from "hester holt <hesterholt7@gmail.com>"blq, in
comp.os.linux.misc.

NNTP-Posting-Host: 68.235.38.177
NNTP-Posting-Host: 217.138.255.202
NNTP-Posting-Host: 198.55.126.214
NNTP-Posting-Host: 104.129.56.166
NNTP-Posting-Host: 149.57.28.198
NNTP-Posting-Host: 178.170.158.41
NNTP-Posting-Host: 45.87.214.77
NNTP-Posting-Host: 149.57.28.76
NNTP-Posting-Host: 45.87.212.78
NNTP-Posting-Host: 37.120.137.72
NNTP-Posting-Host: 217.138.255.203
NNTP-Posting-Host: 208.78.41.158
NNTP-Posting-Host: 146.70.103.22
NNTP-Posting-Host: 178.170.183.64

Running a query for the IP address with the term 'proxy', identifies
some as the Windscribe VPNs (windscribe.com), likely acting as
proxies.

https://www.ipqualityscore.com/free-ip-lookup-proxy-vpn-test/lookup/45.87.212.78
https://www.ipqualityscore.com/free-ip-lookup-proxy-vpn-test/lookup/149.57.28.198
https://www.ipqualityscore.com/free-ip-lookup-proxy-vpn-test/lookup/208.78.41.158
https://www.ipqualityscore.com/free-ip-lookup-proxy-vpn-test/lookup/217.138.255.202

All of this suggests each article is posted manually via Google
Groups. I see nothing to even vaguely suggest the involvement of
automation, let alone a botnet.

- --
David Ritz <dritz@mindspring.com>
Be kind to animals; kiss a shark.

-----BEGIN PGP SIGNATURE-----

iF0EARECAB0WIQSc0FU3XAVGYDjSGUhSvCmZGhLe6wUCYsNIxgAKCRBSvCmZGhLe
6+s2AJ9A1ymdSh/UvlBPte4GctWO2EsKwACeJfNerHrpi1BX4kSDISVMwa+9HNM=
=SeAu
-----END PGP SIGNATURE-----

Re: (PDF) Rockwood and Wilkins Fractures in Children 9th Edition by Waters

<t9vnfp$in4$32@gallifrey.nk.ca>

  copy mid

https://news.novabbs.org/computers/article-flat.php?id=811&group=news.admin.net-abuse.email#811

  copy link   Newsgroups: news.admin.net-abuse.email
Path: i2pn2.org!i2pn.org!weretis.net!feeder6.news.weretis.net!news.nk.ca!.POSTED.doctor.nl2k.ab.ca!not-for-mail
From: doctor@doctor.nl2k.ab.ca (The Doctor)
Newsgroups: news.admin.net-abuse.email
Subject: Re: (PDF) Rockwood and Wilkins Fractures in Children 9th Edition by Waters
Date: Mon, 4 Jul 2022 21:52:57 -0000 (UTC)
Organization: NetKnow News
Message-ID: <t9vnfp$in4$32@gallifrey.nk.ca>
References: <59781171-88d3-47ec-98c7-97fc78859159n@googlegroups.com> <87zghq16jb.fsf@usenet.ankman.de> <op.1oq0e4gda3w0dxdave@hodgins.homeip.net> <87zghozqdx.fsf@usenet.ankman.de>
Injection-Date: Mon, 4 Jul 2022 21:52:57 -0000 (UTC)
Injection-Info: gallifrey.nk.ca; posting-host="doctor.nl2k.ab.ca:204.209.81.1";
logging-data="19172"; mail-complaints-to="usenet@gallifrey.nk.ca"
X-Newsreader: trn 4.0-test77 (Sep 1, 2010)
Originator: doctor@doctor.nl2k.ab.ca (The Doctor)
 by: The Doctor - Mon, 4 Jul 2022 21:52 UTC

In article <87zghozqdx.fsf@usenet.ankman.de>,
Andreas Kohlbach <ank@spamfence.net> wrote:
>On Sun, 03 Jul 2022 16:55:42 -0400, David W. Hodgins wrote:
>>
>> On Sun, 03 Jul 2022 12:54:00 -0400, Andreas Kohlbach
><ank@spamfence.net> wrote:
>>> It's posted via Google. I don't think a botnet is involved.
>>
>> The Injection-Info header in the articles shows it's coming from a
>wide variety
>> of ip addresses (hence botnet), and using multiple google accounts.
>
>Good point. I overlooked this. Although it could be TOR?

TOR! Can it bypass a botnet?

>--
>Andreas

--
Member - Liberal International This is doctor@nk.ca Ici doctor@nk.ca
Yahweh, Queen & country!Never Satan President Republic!Beware AntiChrist rising!
Look at Psalms 14 and 53 on Atheism https://www.empire.kred/ROOTNK?t=94a1f39b
Those who have no argument turn to slander. -unknown Beware https://mindspring.com

Re: (PDF) Rockwood and Wilkins Fractures in Children 9th Edition by Waters

<5nq3o9s3-oons-89o2-2p44-sr842nrnq11@zvaqfcevat.pbz>

  copy mid

https://news.novabbs.org/computers/article-flat.php?id=812&group=news.admin.net-abuse.email#812

  copy link   Newsgroups: news.admin.net-abuse.email news.admin.net-abuse.usenet
Followup: news.admin.net-abuse.usenet
Path: i2pn2.org!i2pn.org!weretis.net!feeder8.news.weretis.net!lilly.ping.de!fu-berlin.de!uni-berlin.de!individual.net!not-for-mail
From: dritz@mindspring.com (David Ritz)
Newsgroups: news.admin.net-abuse.email,news.admin.net-abuse.usenet
Subject: Re: (PDF) Rockwood and Wilkins Fractures in Children 9th Edition by
Waters
Followup-To: news.admin.net-abuse.usenet
Date: Mon, 4 Jul 2022 22:31:39 -0500
Organization: SpamBusters!
Lines: 70
Message-ID: <5nq3o9s3-oons-89o2-2p44-sr842nrnq11@zvaqfcevat.pbz>
References: <59781171-88d3-47ec-98c7-97fc78859159n@googlegroups.com> <87zghq16jb.fsf@usenet.ankman.de> <op.1oq0e4gda3w0dxdave@hodgins.homeip.net> <87zghozqdx.fsf@usenet.ankman.de> <t9vnfp$in4$32@gallifrey.nk.ca>
Mime-Version: 1.0
Content-Type: text/plain; charset=US-ASCII
X-Trace: individual.net Vi+vROvl0wXlCo7zRYbC4wtUQUMbEAhEMsY+a9JBpF/lMeFyKN
X-Orig-Path: not-for-mail
Cancel-Lock: sha1:qb2HAuM6LB+RdUY4itC4chmYA7w=
In-Reply-To: <t9vnfp$in4$32@gallifrey.nk.ca>
OpenPGP: id=9CD055375C05466038D2194852BC29991A12DEEB
X-Comment-1: Spam is bad. <http://trillian.mit.edu/~jc/humor/WhatIsSpam.html>
X-Comment-2: LART a spammer for Dobbs.
X-Comment-3: Invalid assumptions tend to produce invalid conclusions.
X-Comment-4: This message is intended to be read with a monospaced font.
X-Meow: yes
 by: David Ritz - Tue, 5 Jul 2022 03:31 UTC

[ note followup-to ]

On Monday, 04 July 2022 21:52 -0000,
in article <t9vnfp$in4$32@gallifrey.nk.ca>,
The Doctor <doctor@doctor.nl2k.ab.ca> wrote:

> In article <87zghozqdx.fsf@usenet.ankman.de>,

> Andreas Kohlbach <ank@spamfence.net> wrote:

> >On Sun, 03 Jul 2022 16:55:42 -0400, David W. Hodgins wrote:

>>> On Sun, 03 Jul 2022 12:54:00 -0400, Andreas Kohlbach
>><ank@spamfence.net> wrote:

>>>> It's posted via Google. I don't think a botnet is involved.

>>> The Injection-Info header in the articles shows it's coming from a
>>> wide variety of ip addresses (hence botnet), and using multiple
>>> google accounts.

>>Good point. I overlooked this. Although it could be TOR?

> TOR!

Stop guessing; don't be in such a hurry to demonstrate your ignorance.
This is unrelated to TOR, bots and botnets. The Usenet spam in
question is being posted, individually, by hand. This is true for
every single article I've seen, coming from groups.google.com's G2
http2nntp interface.

These are the IP addresses shown in the NPH of the articles appearing
in comp.os.linux.misc, posted by "hester holt <hesterholt7@gmail.com>"
via Google Groups. See
<817p663n-9n89-q827-s822-77271rsp351@zvaqfcevat.pbz>
(http://al.howardknight.net/?ID=165699000400). tor.dnsbl.sectoor.de
provides a database of Tor exit nodes, which can be checked in the
same manner as most other DNSBLs.

178.170.183.64 : tor.dnsbl.sectoor.de : ok
68.235.38.177 : tor.dnsbl.sectoor.de : ok
217.138.255.202 : tor.dnsbl.sectoor.de : ok
198.55.126.214 : tor.dnsbl.sectoor.de : ok
104.129.56.166 : tor.dnsbl.sectoor.de : ok
149.57.28.198 : tor.dnsbl.sectoor.de : ok
178.170.158.41 : tor.dnsbl.sectoor.de : ok
45.87.214.77 : tor.dnsbl.sectoor.de : ok
149.57.28.76 : tor.dnsbl.sectoor.de : ok
45.87.212.78 : tor.dnsbl.sectoor.de : ok
37.120.137.72 : tor.dnsbl.sectoor.de : ok
217.138.255.203 : tor.dnsbl.sectoor.de : ok
208.78.41.158 : tor.dnsbl.sectoor.de : ok
146.70.103.22 : tor.dnsbl.sectoor.de : ok
178.170.183.64 : tor.dnsbl.sectoor.de : ok

These are known proxies, for which I provided evidence. If you're
going to contradict me, Dave, the least you can do is to support your
assertion.

> Can it bypass a botnet?

If you're asking, "Can Tor bypass a botnet?", I'd ask you to rephrase.
As stated, it makes no sense. You are asking, can a network of
anonymous proxies get around a network of compromised hosts, which act
at the behest of nefarious third parties. WTF?

--
David Ritz <dritz@mindspring.com>
"There are no good girls gone wrong, just bad girls found out."
- Mae West (1892-1980)

1
server_pubkey.txt

rocksolid light 0.9.81
clearnet tor