Blocking SiteFinder Service
apankrat writes "Given VeriSign's position on wildcard redirection service, it looks like it's time for a simplier and more efficient ways of bringing things back to where they were. For those running BIND there is a patch;
for those on the client side - there is a dnsfix for Windows and the usual iptables hackery under Linux. Aware of any other clean and easy ways to block wildcarding ? Post below."
here.
version 1.16 is ok.
others have fixes, too, you can find them in this place.
hope I have helped,
It's better to be the foot on the boot than the face on the pavement. ~~ tkx Kadin2048
how do I go about explaining to my ISP that this needs to be blocked?
I added this to my FORWARD rule on the Firewall:
iptables -A blocked_sites -p TCP -d 64.94.110.11 -j REJECT --reject-with icmp-host-unreachable
Will be doing the DNS patch soon. But this works for now.
Chris Southern
The way I've dealt with it under both XP & OS X is to modify etc/hosts.
Under OS X, Solaris, Linux, etc., it's "/etc/hosts". Under Windows XP, it's "C:\Windows\system32\drivers\etc\hosts"
In either case, add this to the end of the file:
0.0.0.0 sitefinder.verisign.com
Wah-lah!
the clock on the wall says 4 til 7
Verisign switched from their buggy, not SMTP-compliant mailrejector "Snubby Mail Rejector Daemon v1.3" on 64.94.110.11 towards postfix (according to the banner)?
...
$ telnet oauwnxtrgqoiezrfgnxocrzq.net 25
Trying 64.94.110.11...
Connected to oauwnxtrgqoiezrfgnxocrzq.net.
Escape character is '^]'.
220 sitefinder.verisign.com VeriSign mail rejector (Postfix)
At least, they are now able to bounce properly
/graf0z.
Patch 'em up and move 'em out...
Warning: This signature may offend some viewers.
Which should mean that mail etc. will be unaffected.
acl verisign dst 64.94.110.11
http_access deny verisign
Interesting discussion tonight with Verisign/Network solution supprot line (Worldwide: +1-703-742-0914 then 2 then 7). I was complaining that while trying to reach my own mydomain.com (true name replaced here) I did a mistake and was drag to sitefinder.verisign.com and that i didn'' agree with that. The man then went straight to tell me that I should buy misplling variants of my domain name !!! I couldn't believe my ears ! I regret I hadn't a lawer to record the conversation ...
The man just agreed finaly it was not possible to buy all possible mistyppings in all languages keyboards lay-outs.
After a few minutes of exchanges (the total communication lasted for 12 minutes) the man finally failed to understand that I just wanted my IP to be excluded from siteFinder system, which I was telling him from the begining. Anymay, he then asked if I was the owner of the mis-typed name and I had to admit I was not. His point was that since I was not the owner of the mis-typed domain I had no right on it. True.
Now I reversed the charge and asked him if Verisign was the owner of the mis-typed domain and he was forced to admit that the answer was "no".
As we reached a dead end by this way we finally courtesy closed the conversation that is very interesting in my point of view.
The summary of this conversation is that :
- Network Solution is actively trying to use sitefinder mess to sell mis-typed domains, which may be reprehensive in some way (I am not a lawer, but if you bring somebody to some place against his will in order to solicitate him to buy something it may be illegal) ;
- Verisign must admit that it doesn't own the mis-typed domains. I don't know if there is an implication of that, through.