.US harbors prolific malicious link shortening service
krebsonsecurity.com
krebsonsecurity.com
If anyone is looking for an alternative, CloudFlare domains are super cheap!
After a forum I was on got flooded with CSAM shit, I did some hunting and found out it was all hosted on Godaddy hosting. I collected all the info and sent it to them, and got silence. I checked around, and it sounds like tons of people had done the same thing, and the ones who got responses were along the lines of "not our problem, call the FBI", and people who reported through FBI/NCMEC still saw zero action. I was looking at years old threads of people reporting the same exact sites I was trying to report, with no one getting anywhere.
These are straight up child porn sites, hosted by GoDaddy hosting (not just the domains), which were up for years on the plain internet, not on Tor, or even something where passwords were required or something. This wasn't a long time ago either, this was like, a few years ago, and no one at GoDaddy gave a shit. Absolutely infuriating.
But if the proper US authorities were knowingly permitting that material and activity to persist on a big US company's servers, one theory would be that they're using it to map out people who produce, distribute, and seek that material.
This resulting in more people encountering the evil material might only increase political support for this and other surveillance efforts.
Or maybe this is actually small potatoes among the tasking of the authorities, and they don't have enough resources for all of it, so they have to triage.
If you actually look into the history of the domains linked to "Josef Bakhovsky" and registered with Namecheap you can see they've got put on serverHold
A lot of registrars don't deal with abuse at all and simply say "report it to the hosting company", example here (domain in question was a Redline Stealer C2):
> Please, be aware that we, as a domain-only provider and not providing any content, hosting or e-mail services, are not in a position to judge the content of a website. For that reason, our normal procedure is that we inform our reseller and the domain holder, but will not suspend the domain names without an official WIPO decision or court order.
And an example from the article, NameSilo didn't take the domains down even after talking to Krebs?
> dig +short 1ox.us
> 167.71.25.56
> 157.245.248.19
I don't know what your secret is. I'll admit they're a bit better than they used to be, but I regularly see stuff I report to them left online for weeks! Is there something that works better than their online reporting form?
Domains used for things like URL shorteners or free form/survey/website builders that get abused by phishers over and over and over again stay online too. Domains that eventually take down a single URL within a few weeks after it's reported, but do nothing to prevent the next one or the next one or the next one.
Namecheap seems perfectly happy to keep taking money from what are basically safe havens for scammers.
What kind of abuse are you reporting? The few reports I send about spam tend to take a bit longer than the rest (since I need to send along email headers, etc.) but I've never had reports take weeks.
> Is there something that works better than their online reporting form?
I've used both Twitter and the form, there's been a few times where I've had to nudge them, but with the hundreds of reports I've done I'd say they're definitely one of the best domain registrars at handling abuse, some registrars I don't even bother reporting to anymore because they refuse to do anything whatsoever (dynadot, openprovider, godaddy, nicenic, key-systems to name a few)
> Domains used for things like URL shorteners or free form/survey/website builders that get abused by phishers over and over and over again stay online too. Domains that eventually take down a single URL within a few weeks after it's reported, but do nothing to prevent the next one or the next one or the next one.
That's a case I rarely come across but yeah that does sound like they handle it poorly, in my opinion they should be suspending the entire domain if the service is repeatedly slow at taking action.
Fun fact: they, in contrast to just about every other TLD, refuse to redact WHOIS information. Having my address and phone number connected to my domains is so fun! I feel so young again.
WHOIS redaction is a standard feature of domain registrars these days, about N-1 TLDs support it, and like you said I can vote with my feet (and I am).
e.g. https://www.domain.com/help/article/domain-management-tlds-n...
It is quite logical for TLDs with nexus requirements. Not every TLD operates like a free-for-all in the way some of the more popular gTLDs do.
The .in TLD doesn't allow privacy protection as seen in the list you linked above but whois still shows "Redacted for Privacy Purposes" for everything but the country and state/province of the registrant.
I have a .us. I solved that by getting a PO Box and a Google Voice number (which doesn't ring my phone, and I think might actually be dead now).
URLs would be like 123NotRealSteetCA, or even otRealStreetCalifornia, where NotRealStreet are actually real US addresses or portions or real addresses.
no, what actually happens is they run a stupid global shared phonebook and le bad people add entries to malware in it. le bad people could just as well do this (whatever it is the'yre doing) without domains at all. but i don't expect anyone who's hobby horse is DNS to tell the forest from the trees. the fact that people get uppity over stuff like this is a testament to the internet being too locked down (it also costed billions of dollars of tax money to get here). i don't get why nobody remembers 20 years ago when they knew how every malware scam etc was obvious and trivial to avoid except for their bumpkin parents.
Russians are looking at my data? Oh wow(?)
Is it really called outsourcing when they are themselves located in Ukraine (formerly Russia)?
Will likely be slowly transferring my domains to porkbun.