[Wolves] Amanda Perez Spam

Ron Wellsted wolves at mailman.lug.org.uk
Sat Mar 8 22:48:02 2003


This gets interesting:

The amandaperez.com domain seems to be one of several  setup on a single 
Windows 2000 server running IIS5.0 with the xmail server.  This box is so 
badly configured (either through incompetence or deliberately) so that all 
inbound mail is refused.   This single box at 64.239.9.28 also hosts their 
hosting company's web site, mail server and primary DNS server :-) (this is a 
single point of failure and is a perfect example of how not to operate, as an 
attack on this server would shutdown the hosting company;-). 

The correct way to proceed now would be to complain to dialtone.com where the 
server is located.

The unofficial way to proceed would be to find out more about the server and 
how weak the setup is.

Hmm.  they have an awful lot of ports open on this box (ftp, finger, 
iis-admin, ms-sql and terminal services)  This tends to confirm that they are 
indeed really incompetent.

No robots.txt so they don't want to limit search engines crawling the site.

It gets better, site also hosts https://bettersecure.com and this site is also 
presented if you attach to https://amandaperez.com (These guys are thick!).

-- 
Ron Wellsted
http://www.wellsted.org.uk
mailto:ron@wellsted.org.uk