Skip to content

Twitter Updates for 2012-12-09

Twitter Updates for 2012-12-08

Twitter Updates for 2012-12-07

  • Why doesn't clicking on an artist in Apple iTunes 11 search take you to that artist's songs in your library? #bug #
  • It's a shame that #ADNSecretSanta had to use spam service EventBrite to coordinate the event. #

GoodNewsClicks.com Spam Network

Since November 30th, I’ve been getting hammered by spam coming from many different places, but based on the message headers, it’s all part of the same spam network.

91.92.0.0 - 91.92.255.255 Bulgaria
fortunebanker.com [91.92.98.57]
mx1.fortunebanker.com [91.92.98.58]
mx2.fortunebanker.com [91.92.98.59]
mx3.fortunebanker.com [91.92.98.60]

dollarstools.com [91.92.98.73]
mx1.dollarstools.com [91.92.98.74]
mx2.dollarstools.com [91.92.98.75]
mx3.dollarstools.com [91.92.98.76]

5.135.71.64 - 5.135.71.95 Portugal
norbertwst.com [5.135.71.67]
mx1.norbertwst.com [5.135.71.68]
mx2.norbertwst.com [5.135.71.69]

5.135.246.64 - 5.135.246.95 Czech Republic
goodnewsclicks.com [5.135.246.76]
mx1.goodnewsclicks.com [5.135.246.77]
mx2.goodnewsclicks.com [5.135.246.78]

178.33.212.192 - 178.33.212.223 Netherlands
livecashgenerator.com [178.33.212.210]
mx1.livecashgenerator.com [178.33.212.211]
mx2.livecashgenerator.com [178.33.212.212]

I recommend you block/firewall all of these IP addresses and domain names.

Twitter Updates for 2012-12-04

Twitter Updates for 2012-12-02

  • It looks like the Richmond Times-Dispatch has removed all their RSS feeds from their site. I've asked them about the feeds. #

Twitter Updates for 2012-12-01

  • @ConstantContact How do I report a spammer to you who is using your email spam services? #

Twitter Updates for 2012-11-30

  • Would anyone like an invite to http://t.co/vtkoBwNr? Get one month free to try it out. You do have to provide your CC# to them. #

Twitter Updates for 2012-11-26

  • @WPDensity What's wrong with your RSS feed? It is only for comments, not posts #

Login Attempts to wp-login.php

While checking out my apache server logs last week, I noticed that one of my older sites was getting a fair amount of login attempts to wp-login.php from all over the world. So I started grabbing the login information to see what they were trying. The next batch of attacks lasted 23 minutes. The username was always “admin” and the testcookie was always “1”. Here are the passwords:

  • example.org123
  • example
  • password1
  • test123
  • 12345
  • admin
  • password
  • admin1
  • qwerty123
  • admin111
  • pass
  • life777
  • 123456
  • password123
  • abc123
  • admin123
  • example.org

I replaced the actual domain name with “example” in the above list. If you are using any of those passwords, you may want to consider changing it.

The user-agent doing the probe was always “Mozilla/3.0 (compatible; Indy Library)”. The attacks came from these IP addresses. I assume they were running some form of infected Windows operating system.

  • 110.153.9.250: Host 250.9.153.110.in-addr.arpa. not found: 3(NXDOMAIN) (China)
  • 120.50.0.61: 61.0.50.120.in-addr.arpa domain name pointer ws4-tunghai-grp-telnet.com.bd. (Bangladesh, not assigned?)
  • 202.70.136.158: Host 158.136.70.202.in-addr.arpa. not found: 3(NXDOMAIN) (Indonesia)
  • 173.8.94.5: 5.94.8.173.in-addr.arpa domain name pointer 94.8.173.5-Draper.hfc.comcastbusiness.net. (Comcast, USA)
  • 175.25.243.22: Host 22.243.25.175.in-addr.arpa. not found: 3(NXDOMAIN) (China, not assigned?)
  • 119.187.148.51: Host 51.148.187.119.in-addr.arpa. not found: 3(NXDOMAIN) (China)
  • 121.100.28.18: Host 18.28.100.121.in-addr.arpa. not found: 3(NXDOMAIN) (Indonesia)
  • 120.132.132.119: Host 119.132.132.120.in-addr.arpa. not found: 3(NXDOMAIN) (China)
  • 190.0.9.202: 202.9.0.190.in-addr.arpa domain name pointer Wimax-Cali-190-0-9-202.orbitel.net.co. (Brazil)
  • 60.28.209.24: Host 24.209.28.60.in-addr.arpa. not found: 3(NXDOMAIN) (China)
  • 89.144.131.106: Host 106.131.144.89.in-addr.arpa. not found: 3(NXDOMAIN) (Iran)
  • 177.70.68.155: Host 155.68.70.177.in-addr.arpa. not found: 3(NXDOMAIN) (Brazil)
  • 89.222.181.225: 225.181.222.89.in-addr.arpa domain name pointer host-181-225.dialog-k.ru. (Russia)
  • 120.198.232.8: Host 8.232.198.120.in-addr.arpa. not found: 3(NXDOMAIN) (China)
  • 110.139.173.217: 217.173.139.110.in-addr.arpa domain name pointer 217.subnet110-139-173.speedy.telkom.net.id. (Indonesia)
  • 221.2.80.126: Host 126.80.2.221.in-addr.arpa. not found: 3(NXDOMAIN) (China)
  • 124.160.147.173: Host 173.147.160.124.in-addr.arpa. not found: 3(NXDOMAIN) (China)
  • 195.158.107.5: 5.107.158.195.in-addr.arpa domain name pointer adsl5p5.access.maltanet.net. (Malta)
  • 217.129.77.17: 17.77.129.217.in-addr.arpa domain name pointer st-217-129-77-17.netvisao.pt. (Portugal)