[SpamCop.net - protecting the internet through technology]

[SpamCop-List] Likely hijacked IP?

JLS test at mailandnews.com
Mon Aug 16 17:11:08 EDT 2004


Tracking message source: 61.253.52.34:
Display data:
"whois 61.253.52.34 at whois.arin.net" (Getting contact from whois.arin.net )
   Redirect to apnic:
   "whois 61.253.52.34 at whois.apnic.net" (Getting contact from
whois.apnic.net mirror)
   Display data:
      whois.apnic.net redirects to krnic
      Display data:
      "whois 61.253.52.34 at whois.krnic.net" (Getting contact from
whois.krnic.net) - not found
host 61.253.52.34 (getting name) no name
Falling back on IP addressing:postmaster@[61.253.52.34]

61.253.52.34 is an open proxy

and no name:
NS Lookup: 61.253.52.34/A/206.83.0.42/Emulate = false

 <-- Name UNAVAIL -->
 <--  Non-Auth  -->
 <-- Complete -->
 <--Recursion Avail-->
 Answers= 0
 Auths= 1
 Addtl= 0
 Domain = 253.61.in-addr.arpa
 Authority = a.dns.kr

I have never seen addressing like "postmaster@[61.253.52.34]"
do anything other than bounce so I have no idea why SpamCop bothers to do it
in cases like this.

The REAL contact person in this case would probably more appropriately be
hostmaster at nic.or.kr since the whois data seems to indicate nobody should
have this address in the first place, no?

query: 61.253.52.34

# ENGLISH

KRNIC is not a ISP but a National Internet Registry similar to APNIC.
The IPv4 address is allocated from APNIC to KRNIC.
KRNIC is holding the IPv4 address for further allocation to its member ISPs
in the furture. If you have any question with the IPv4 address,
Please contact at hostmaster at nic.or.kr

Have seen ARIN take hijacked IPs out of the database entirely - Wonder if
this might be KRNIC's version of the same?




More information about the SpamCop-List mailing list