New York's Oldest ISP Gets Domain-Jacked
Howard Roark writes "Panix, the oldest commercial Internet provider in New York, had its domain name 'panix.com' hijacked by persons unknown. The main effect on users is that mail sent to panix's customers is being routed to a bogus mail server run by the hijackers."
First Post!
One domain hijacked and another soon to be slashdotted, sucks to be them.
Just in case:
"Status as of Sat Jan 15 22:04:33 EST 2005
Panix's main domain name, panix.com, has been hijacked by parties unknown. The ownership of panix.com was moved to a company in Australia, the actual DNS records were moved to a company in the United Kingdom, and panix.com's mail has been redirected to yet another company in Canada. Panix staff are currently working around the clock to recover our domain, but this may take until Monday, due to the time differences and difficulties in reaching responsible parties over the weekend.
For most customers, accesses to Panix using the panix.com domain will not work or will end up at a false site."
Their catch phrase "Your $HOME away from home" is quite cute.
Distributed proteome folding @ WorldCommunityGrid.org
Team Slashdot - Members:#1 Run Time:#1 Points:#1 Results:#1
Do you realize how hypocritical that Michael is posting this story when Michael himself hijacked censorware.org from the people it belonged to? I reproduce the story here (you can read the original here:
h2>Michael Sims, Domain Hijacking and Moral Equivalency by Jonathan Wallace jw@bway.net
How would you feel if your webmaster maliciously took your web-site offline, then, when you demanded its return, put up a site attacking your company at your old URL? It happened to a group I was involved in, the Censorware Project, currently at http://www.censorware.net. The purpose of this essay is to put the behavior on record, and to give you some impressions and inferences about it.
The Censorware Project was originally an informal collective of six people who collaborated online to fight censorware: Seth Finkelstein, Bennett Haselton, Jamie McCarthy, Mike Sims, Jim Tyre and myself. Several of us had never met or even spoken on the phone, yet for some time -- around two years as I recall -- we had a remarkably easy collaboration. There was no funding, no hierarchy, no titles, not even project managers. Someone would suggest a project and take the responsibility for a part of it, others would sign up for other elements, and proceeding this way we got a remarkable amount of work done, including reports on X-Stop, Cyberpatrol, Bess and other censorware products.
Even though two of us were attorneys -- Jim and myself -- we never incorporated the group or wrote a charter or any contracts among ourselves. Mike Sims was obliging enough to register the domain, just as other members paid for press releases and the other incidental expenses which came along. Mike also served as webmaster of the censorware.org site and did substantial work for the group, including writing contributions to several of the reports and lead authorship of at least one. Seth was the source of our decrypted censorware blacklists and managed many technical tasks, but later felt he had to leave the group because of the increasing prospects of a lawsuit, particularly under the Digital Millennium Copyright Act (DMCA). After Seth left the group, the remaining five continued.
Robert Frost said that "nothing gold can stay," and the Censorware Project was no exception. Over the summer of 2000, Mike Sims' reaction to a perceived slight from Jim Tyre was to take the site down for a week. He sent us mail at the time saying something like "The Censorware Project is now closed." I replied to him that, given that the group was a collective and we all had an interest in its work product, the domain, and the goodwill it had achieved, the decision was not his to make. Sims did not reply.
After Seth created a partial, text, mirror, Mike put the site back up a week later without explaining, let alone apologizing for, his actions. Given his continuing failure to answer any email from me (and I think from others) and the overall signs that Sims thought the group was exclusively his, I wrote him several emails requesting that he turn the domain over to Jamie or Bennett, as I felt we could no longer trust him to administer it. We also found out during that time that important email from people trying to contact us, including members of the press, was not being answered by Sims, nor being forwarded to other members.
I ultimately became exasperated that my name was listed as a principal on what had now become a "rogue" site I had no control over. Over about
How would you feel if your webmaster maliciously took your web-site offline, then, when you demanded its return, put up a site attacking your company at your old URL? It happened to a group I was involved in, the Censorware Project, currently at http://www.censorware.net. The purpose of this essay is to put the behavior on record, and to give you some impressions and inferences about it.
The Censorware Project was originally an informal collective of six people who collaborated online to fight censorware: Seth Finkelstein, Bennett Haselton, Jamie McCarthy, Mike Sims, Jim Tyre and myself. Several of us had never met or even spoken on the phone, yet for some time -- around two years as I recall -- we had a remarkably easy collaboration. There was no funding, no hierarchy, no titles, not even project managers. Someone would suggest a project and take the responsibility for a part of it, others would sign up for other elements, and proceeding this way we got a remarkable amount of work done, including reports on X-Stop, Cyberpatrol, Bess and other censorware products.
Even though two of us were attorneys -- Jim and myself -- we never incorporated the group or wrote a charter or any contracts among ourselves. Mike Sims was obliging enough to register the domain, just as other members paid for press releases and the other incidental expenses which came along. Mike also served as webmaster of the censorware.org site and did substantial work for the group, including writing contributions to several of the reports and lead authorship of at least one. Seth was the source of our decrypted censorware blacklists and managed many technical tasks, but later felt he had to leave the group because of the increasing prospects of a lawsuit, particularly under the Digital Millennium Copyright Act (DMCA). After Seth left the group, the remaining five continued.
Robert Frost said that "nothing gold can stay," and the Censorware Project was no exception. Over the summer of 2000, Mike Sims' reaction to a perceived slight from Jim Tyre was to take the site down for a week. He sent us mail at the time saying something like "The Censorware Project is now closed." I replied to him that, given that the group was a collective and we all had an interest in its work product, the domain, and the goodwill it had achieved, the decision was not his to make. Sims did not reply.
After Seth created a partial, text, mirror, Mike put the site back up a week later without explaining, let alone apologizing for, his actions. Given his continuing failure to answer any email from me (and I think from others) and the overall signs that Sims thought the group was exclusively his, I wrote him several emails requesting that he turn the domain over to Jamie or Bennett, as I felt we could no longer trust him to administer it. We also found out during that time that important email from people trying to contact us, including members of the press, was not being answered by Sims, nor being forwarded to other members.
I ultimately became exasperated that my name was listed as a principal on what had now become a "rogue" site I had no control over. Over about a five week period, I wrote Sims several more emails asking him to delete my name from the site if he wasn't going to transfer the domain. Again, I received no reply.
In November 2000, Sims took the Censorware Project site offline again, with a message saying "Due to demands from some of the peo
There are some scum sucking bastards out there, i hope they fry
oh and "first post" perhaps?
Life is like a box of chocolates, you never know when your gonna get food poisoning.
GNAA declares boycott of all foods that make sperm taste bad
Washington, District of Columbia (USNS) - Gathered on the steps of the Justice Department, gay niggers worldwide announced their most ambitious ploy for political power to date, a boycott of all foods that make semen taste awful. GNAA president timecop led the rally with a pink megaphone, shouting over the noise of riot cops assembling in case the peaceful assembly turned violent.
"My friends," he lisped at the top of his lungs. "As America's - no, the world's - foremost consumers of sperm and without a doubt its greatest enjoyers and advocates, we plead - no, we demand - that these prostate poisons be eliminated from the modern diet." Around him, a surging throng of foamy devotees showed their approval with a shower of bodily fluids.
According to timecop, numerous studies prove that gay volunteers not only found that tobacco left a lingering moldy taste in semen, but that such commonplace items as coffee and multivitamin pills could make semen taste muddy and like insecticide, respectively. "These are intolerant, I mean, intolerable substances," timecop spluttered.
GNAA member DiKKy, on loan from NATO class dunce Norway, as if on cue dumped a 55 gallon drum of whipped semen into the Justice Department's Martin Luther King, Jr. meditative koi pond. As carp drowned in the sticky mucosal fluid, DiKKy took the microphone from a timecop overcome by emotion at the sacrifice of so much precious gay nigger seed. "Gummy bears make it taste like rubber cement - no, that's not a pun. And salmon, of course," said DiKKy, "which makes it taste oily. Oh, and here's a big no-no: asparagus. Yucky."
United Asparagus Growers President Ralph Gruntligel was interviewed by CBS' "60 Minutes," which, in trying to downplay its recent scandal over forging records to replace the lost forged records of a famous politician, has changed focus to such cutting edge topics as sitting room makeovers and loose candle wax.
"While we support every group who wishes to consume asparagus, and do not discriminate on the basis of age, sex, race, gender, sexual orientation, bondage role, condom use, ethnicity or major league baseball fan identification," Gruntligel said from a leather sofa in his Greenwich Village headquarters, "to indict a source of income for roughly one in 65,536 Americans that is ranked fifty-fourth among the world's most valuable vegetables, is not only a crime against asparagus, but a terrorist action against one of nature's most perfect foods and an important source of revenue for government and industry."
Back at the rally, timecop sniffed in response. "Like his ugly fat bitch of a wife will ever give him this kind of head," he said, demonstrating on Morgan Freeman, who happened to be passing on his way to testify before a Senate committee on racial discrimination in the color of fingernail clippers. "Desist -- cease, I say!" began Freeman, but then, in his characteristic basso profundo, began moaning rhythmically to the motion of gay nigger tongues.
Semen, the technical name for the fluid of male sexual emission which occurs at ejaculation, has a generally salty or sweet taste, depending on what the person responsible has consumed since his last ejaculation, said Dr. Ben Rodriguez-Silverstein. "It's entirely possible that these foods make semen taste disgusting," he said. "But unfortunately, most of them are necessary for survival."
He was immediately mobbed by gay niggers wielding placards reading "READ MY LIPS: NO RANCID SEMEN."
Contacted via phone, Robert Liebovitz, lead counsel for the Association of Confection Producers, said, "Can I get AIDS from this?"
Rodriguez-Silverstein, who was later spotted receiving $250,000 in small denomination bills smeared with a sticky, mushroom-smelling substance, announced that his lab was conducting independent tests using AOL Afghanistan employees to sample semen from every ethnic, racial, social and animal family group. "We will get to the bottom of
www.gnaa.us
Wish I was witty enought to come up with a pun using the ISP name of Panix, and something in a calamity, like, being in a Panic or something.
Anyone got a good pun?
Waiting for an amusing sig.
I'd like to jack your domain, if you're servicing my backbone.
Just a subject gag
Panix can't hold their "intellectual property" for a ridiculously long time (as the usual whining goes around here), and you are complaining?
It's not surprising this has happened. Many, many companies do not take administrating their domain seriously, and several registrars -- Network Solutions especially -- make it very easy to steal domains.
I know this from experience -- many years back one morning I woke up and Excite.com, Angelfire.com, and a few other domains were mysterically owned by me. The only thing the hijacker needed to do (it wasn't me, by the way) was send in a single email. Old Story at Wired.
the admins were sleeping in their glories instead of paying for the domain, you know what they say finders keepers.
You just got owned.
*How did this happen?
*Was it the registrar that was at fault?
*Did they forget to renew the domain?
*What is the registrar doing about the issue? (if anything)
I'm kind of curious about this..
Found crsnic referral to whois.melbourneit.com.
Domain Name.......... panix.com
Creation Date........ 1991-04-22
Registration Date.... 2005-01-15
Expiry Date.......... 2006-04-23
Organisation Name.... vanessa Miranda
Organisation Address. 1010 Grand Cerritos Ave
Organisation Address.
Organisation Address. Las Vegas
Organisation Address. 89123
Organisation Address. NV
Organisation Address. UNITED STATES
Admin Name........... na vanessa Miranda
Admin Address........ 1010 Grand Cerritos Ave
Admin Address........
Admin Address........ Las Vegas
Admin Address........ 89123
Admin Address........ NV
Admin Address........ UNITED STATES
Admin Email.......... jzoh@yahoo.com
Admin Phone.......... +44.702413697
Admin Fax............ +44.7026413697
Tech Name............ Domain Admin
Tech Address......... Burnhill Business Centre
Tech Address.........
Tech Address......... Beckenham
Tech Address......... BR3 3LA
Tech Address......... Kent
Tech Address......... GREAT BRITAIN (UK)
Tech Email........... admin@powerhost.co.uk
Tech Phone........... +44.2082496081
Tech Fax............. +44.2082496076
Name Server.......... ns1.ukdnsservers.co.uk
Name Server.......... ns2.ukdnsservers.co.uk
now that you know the email address...spam away!
End a brandname in 'x'. Lead it with an 'e'.
Those were the days...
Anyway, so what? So a few people have some problems with their ISP. This is New York we're talking about. The city is a hellhole anyway, what's a little more screwed up services going to do? Bring the city to a halt? Not likely.
The customers of course get what they deserve here. The only real ISPs that have any serious clout are run directly by the phone companies. All other ISPs run on the phone company lines at the good graces of the phone companies. That someone came along and hijacked the domain is not even a surprise.
widespread panix rocks and will be on tour soon!
How can someone take my domain, that I paid for, and hijack it? And if you register for a domain, for a period of time, say 1 year, can someone at the end of that time come and take the domain away, or do you always get the first chance to renew?
Does security of domains have anything to do with the company that registers??
There are so many questions...
Rosco: "If brains were gunpowder, Enos couldn't blow his nose."
When Microsoft let its registration of Hotmail.com lapse? That was about the funniest thing I read that year.
The whois record for panix.com is:
Domain Name.......... panix.com
Creation Date........ 1991-04-22
Registration Date.... 2005-01-15
Expiry Date.......... 2006-04-23
Organisation Name.... vanessa Miranda
Organisation Address. 1010 Grand Cerritos Ave
Organisation Address.
Organisation Address. Las Vegas
Organisation Address. 89123
Organisation Address. NV
Organisation Address. UNITED STATES
Admin Name........... na vanessa Miranda
Admin Address........ 1010 Grand Cerritos Ave
Admin Address........
Admin Address........ Las Vegas
Admin Address........ 89123
Admin Address........ NV
Admin Address........ UNITED STATES
Admin Email.......... [protected]
Admin Phone.......... +44.702413697
Admin Fax............ +44.7026413697
Tech Name............ Domain Admin
Tech Address......... Burnhill Business Centre
Tech Address.........
Tech Address......... Beckenham
Tech Address......... BR3 3LA
Tech Address......... Kent
Tech Address......... GREAT BRITAIN (UK)
Tech Email........... [protected]
Tech Phone........... +44.2082496081
Tech Fax............. +44.2082496076
Name Server.......... ns1.ukdnsservers.co.uk
Name Server.......... ns2.ukdnsservers.co.uk
Fod God's sake, this ISP has enough problems as it is. They already have their domain hijacked, the last thing they need is the rest of their website to be unavliable because of a slashdotting.
Also, this is the 2nd post! Since the 1st post was a troll, how in the F is this redundant?
Heh. And now I cannot connect to censorware.org at all.
1 steal domain 2 sell it back 3 ??? 4 PROFIT!!!
What seems to have happened is that somehow the Australian registrar "melbourneIT.com" yanked the fully paid-up registration away from Dotster (where Panix had it) without any notice whatsoever (this violates all the relevant RFCs for the Shared Registration System and the current ICANN policy *and* seems to indicate a severe bug or security problem somewhere in the registration system).
What's particularly scary is that melbourneIT.com isn't open on the weekends, period (though oddly enough they transferred the domain first thing on Saturday, hmmmm) and won't do anything to help. There are lots of ugly details in the NANOG mailing-list archive, particularly in this message from Perry Metzger, this message from Richard Cox, and this message from me, which includes a slimy note from some customer-service flack at Verisign.
This has clearly happened to others in the past, and highlights a serious flaw in the current registry-registrar system. We are not 100% sure how the domain was transferred between registrars with no notice to anyone (though I have some hunches I won't go into here right now) but consider this: a rogue or penetrated registrar can effectively put you out of business for the duration of the ICANN complaint and appeals process, with no notice, and there may be nothing you or anyone else can do about it short of extremely expensive legal action, even if you get law enforcement involved. Yuck.
You think?
Looks like they sent the "by the way, your domain name address change is pending and will go through in 5 days so don't delete this" to dev/null.
beat. to. death.
I blame it partially on the registrar for not verifying the identity of the person attempting to transfer the domain.
Granted an ISP should have known to use REGISTRAR-LOCK, but what about Joe Shmoe with his domain to host family pictures?
People do not like him as an editor here. Michael constantly editorializes by sticking his opinions into the article submission instead of in a comment like the rest of us have to. He often modbombs threads and blacklists people who post in them from moderating. Even if you don't like Taco's endless dupes or typos, at least he lets the submission speak for itself (iPod launch comment excluded). Michael does very unprofessional things like the infamous all-caps attack toward Intel in the 64-bit chip article last year.
No, this is not just a hobby site where those kinds of things fly. This is a highly-visited news site, considered a major source of tech news for geeks, and a corporate-owned entity of OSTG who employs Malda and company. There's an amount of responsibility you ethically must adopt when your site gets so popular that it's name alone becomes a verb due to the server-killing power of its readerbase.
Michael also does things like edit the words of people's submissions, like adding quotation marks around the word "revealed" in this story (now in my sig). Regardless of what you think of the story, that's just plain misleading and twisting the words and intent of the submitter, making it appear they meant something other than what they did. If it was an anonymous submitter, that would be different, but now Michael has stuffed a message into the submitter's mouth that was not there. At least show a little respect for the people who are providing your content.
See this story on Netcraft, which details the recent policy change by ICANN.
In short, if someone initiates a transfer request, you then have 5 calendar days to respond, or else the transfer happens unopposed. You can prevent this by activating the REGISTRAR-LOCK feature on your domain name. The procedure varies by registrar, but it's usually called "domain lock" or something similar. All registrars have to at least give you the option of requesting this feature.
Some registrars (godaddy, I know for sure does) activate this lock by default, Some require you to activate it explicitly. Check with the support dept. at your registrar for further details.
bash: rtfm: command not found
...melbourneit, the registrar responsible for the mess, basically told panix to take a flying leap. verisign wasnt any help either.
what a sad state of affairs when it's trivial to hijack a domain, but it takes an act of god to return it to its rightful owner. apparently, even law enforcement can't get verisign or melbourneit to do squat:
Date: Sun, 16 Jan 2005 07:04:46 +0000
From: Thor Lancelot Simon
To: nanog@merit.edu
Subject: Re: panix.com hijacked (VeriSign refuses to help)
Alexis Rosen tried to send this to NANOG earlier this evening but it
looks like it never made it. Apologies if it's a duplicate; we're
both reduced to reading the list via the web interface since the
legitimate addresses for panix.com have now timed out of most folks'
nameservers and been replaced with the hijacker's records.
Note that we contacted VeriSign both directly and through intermediaries
well known to their ops staff, in both cases explaining that we suspect
a security compromise (technical or human) of the registration systems
either at MelbourneIT or at VeriSign itself (we have reasons to suspect
this that I won't go into here right now). We noted that after calling
every publically available number for MelbourneIT and leaving polite
messages, the only response we received was a rather rude brush-off from
MelbourneIT's corporate counsel, who was evidently directed to call us
by their CEO.
We are also told that law enforcement separately contacted VeriSign on
our behalf, to no avail.
Below please find VeriSign's response to our plea for help. We're rather
at a loss as to what to do now; MelbourneIT clearly are beyond reach,
VeriSign won't help, and Dotster just claim they still own the domain and
that as far as they can tell nothing's wrong. Panix may not survive this
if the formal complaint and appeal procedure are the only way forward.
> Date: Sun, 16 Jan 2005 00:21:33 -0500
> To: , NOC Supervisor
> Subject: Re: FW: [alexis@panix.com: Brief summary of panix.com hijacking incident]
(KMM2294267V49480L0KM)
> From: VeriSign Customer Service
> X-Mailer: KANA Response 7.0.1.127
>
> Dear Alexis,
>
> Thank you for contacting VeriSign Customer Service.
>
> Unfortunately there is little that VeriSign, Inc. can do to rectify this
> situation. If necessary, Dotster (or Melbourne) is more than welcome to
> contact us to obtain the specific details as to when the notices were
> sent and other historical information about the transfer itself.
>
> Dotster can file a Request for Enforcement if Melbourne IT contends that
> the request was legitimate and we will review the dispute and respond
> accordingly. Dotster can also contact Melbourne directly and if they
> come to an agreement that the transfer was fraudulent they can file a
> Request for Reinstatement and the domain would be reinstated to its
> original Registrar. Dotster could submit a normal transfer request to
> Melbourne IT for the domain name and hope that Melbourne IT agrees to
> transfer the name back to them outside of a dispute having been filed.
> In order to expedite processing the transfer or submitting a Request for
> Reinstatement however Dotster will need to contact Melbourne IT
> directly. If Dotster is unable to get in touch with anyone at Melbourne
> IT we can assist them directly if necessary.
>
> Best Regards,
>
> Melissa Blythe
> Customer Service
> VeriSign, Inc.
> www.verisign.com
> info@verisign-grs.com
melbourneIT.com isn't open on the weekends, period
What did you expect? Australians are possibly the laziest bunch of (fat ugly) losers on the planet.
Panix panics?
Make even shorter URLs - 8LN.org
The biggest perk of being a servant of the devil is you can have sex with goats.
Freely
-tb
Why is this flamebait? For telling the truth??
Then what do they expect? While the article is vague as to how it happened, I certainly wouldn't be calling it "DOMAIN JACKING" if this is a case of bad administration and management. Simply, it should heed as a warning to website owners the world over. If you don't renew your domain someone could register it themselves. Even more so for high profile domains.
The Russian Mafia is already encrypting their email anyway.
Seastead this.
Panix is an old haunt of lots of very savvy New York geeks, particularly security and OS hackers with lots of money and techniques. I'd hate to piss them off, especially with an attitude that merely a planet-width and a foreign law license protects me from my obligation not to screw them.
--
make install -not war
You project that someone else will persecute simply so you can rail against it? And then people think this is somehow laudable?
I don't get it. Why not wait and find out what happens?
Just bizarre. Slashdot is one of the most unusal communities I've ever seen. Complain about anything, or in this case nothing, and you're an instant hero.
they're real good about protecting their customers from hijackers. They were one of the first ones to lock down outside domain transfers when that whole domain expiration thing happened a few months ago.
As this post points out, having hijacked panix.com, MelbourneIT could be logging all userID/password logins to shell.panix.com . So Panix customers should all login to the "temporary" replacement, shell.panix.net , and change their passwords ASAP. Then fly to Melbourne with baseball bats.
--
make install -not war
Michael has irritated a lot of people over the years, so when an opportunity comes up to complain, there's a lot of people who do, and a lot more people who smile and say "finally!"
(Whether this is a good or bad phenomenon is left as an exercise to the reader.)
10 PRINT CHR$(205.5+RND(1)); : GOTO 10
Anyone in Melbourne with a baseball bat, who wants free drinks the next time they visit New York, want to go "knocking" on MelbourneIT's door?
--
make install -not war
i would vote but i m not a metamoderator
_ In Egypt Networks: Network Solutions with a Twist
I know some people in MelbourneIT, and have already spoken to them. They are looking into the issue
`find / -name "*your_base*" -exec chown us:us {} \;`
I have to post this as an AC but ....
This is an issue like spam. Frankly, and I doupt Alexis Rosen et all will go this route, but what should happen now is gunshot wounds to the head. My guess is this is a scam to clean out the paypal accounts of panix customers and/or steal domains that are hosted by panix.
This has nothing to do with hijacking.
He's the only domain hijacker I know of.
[Below is the message which kicked-off the "hostage crisis" of censorware.org. Yes, Michael Sims really did throw a temper-tantrum over email criticism, and shut down the censorware.org website in retaliation. See also Jonathan Wallace account , Bennett Haselton account ]
[This came up on a freedom of expression mailing list. Jonathan Wallace commented as follows (used with permission - from Jonathan Wallace)]
From: Jonathan Wallace
To: [a freedom of expression mailing list]
Sent: Saturday, August 04, 2001 9:34 AM
Mike characterizes his shut-down of www.censorware.org as choosing to stop doing volunteer work. He was free to stop volunteering but not to destroy the site.
Below is the mail Mike Sims sent when he first pulled the plug on www.censorware.org. Note the unilateral "The Censorware Project is now closed." Note also, "If I am to be continuously accused of evil deeds, I might as well do them" and the reference to "settling old debts with violence while the opportunity existed." Then ask yourself whether your webmaster has the right to shut down your site because he's angry.
Below that is one of several messages I sent Mike asking him to relinquish the domain and the content to the group, or, failing that, to remove my name from it.
As I wrote in private to a couple of you, this is not a "moral equivalency" or "cultural relativism" situation. Mike was in a position of trust which he violated by taking down the web site of an active group and bouncing its mail.
[Note - this is the full Michael Sims message, from another copy]
From: "Michael Sims"
To: cwp@censorware.org
Date: Wed, 30 Aug 2000 17:04:42 -0400
Subject: Re: The CWP Unperson
Included below is the response that I started writing, and choked down, a few weeks ago. I think I had the thought that I ought not to escalate, perhaps Jim would come to his senses and realize how utterly and totally offensive it was to be compared to Big Brother. I suppose I could achieve the same response by comparing Jim or Jamie or Jonathan to Adolf Hitler, or Goebbels, or Mengele. I don't know what might achieve the same reaction from Bennett - perhaps comparing him to Brian Milburn? Those depths are too low for me to plumb, however.
In any case, since Jim has so kindly provided Seth with the cruelest criticism I've ever received, I shall never hear the end of it. Thanks, Jim. You're a real friend.
The Censorware Project is now closed.
Good luck, Bennett. You've taken the wisest course. I don't know whether it was true wisdom or merely luck... Jonathan, I don't know what you're up to, really, but I hope you will continue to make (it will have to be made, you can't simply wait for opportunities) time to write. Jamie I will continue to see since we work for the same company - I hope introducing Jamie to Andover is not a decision I shall also regret.
Jim, you and Seth can go fuck yourselves. I wouldn't treat a dog the way you've treated me. Hell, I wouldn't treat Seth the way you've treated me.
------- Forwarded message follows -------
Date sent: Fri, 4 Aug 2000 07:44:47 -0400 (EDT)
From: Michael Sims
To: jellicle@inch.com
Subject: Re: The CWP Unperson
On Fri, 4 Aug 2000, James S. Tyre wrote:
> You and he have become enemies, and there is nothing which I can do about
> that, apparently.
I don't think you should confuse an unwillingness to become involved with impossibility.
> But you can not deny the contributions he made, that CWP likely never
> would have existed but for him.
>
> He had been listed as a former member, though I do not recall the exact
> language. Unpersoning him is just wrong.
>
> Please reconsider.
Seth's attacks have far outweighed any work he's ever done. At this point, I can say with some assurance that the Project would have been more successful in the long run had Seth never been a part of it.
I decided that I might as well fulfill
[Below is the message which kicked-off the "hostage crisis" of censorware.org. Yes, Michael Sims really did throw a temper-tantrum over email criticism, and shut down the censorware.org website in retaliation. See also Jonathan Wallace account , Bennett Haselton account ]
[This came up on a freedom of expression mailing list. Jonathan Wallace commented as follows (used with permission - from Jonathan Wallace)]
From: Jonathan Wallace
To: [a freedom of expression mailing list]
Sent: Saturday, August 04, 2001 9:34 AM
Mike characterizes his shut-down of www.censorware.org as choosing to stop doing volunteer work. He was free to stop volunteering but not to destroy the site.
Below is the mail Mike Sims sent when he first pulled the plug on www.censorware.org. Note the unilateral "The Censorware Project is now closed." Note also, "If I am to be continuously accused of evil deeds, I might as well do them" and the reference to "settling old debts with violence while the opportunity existed." Then ask yourself whether your webmaster has the right to shut down your site because he's angry.
Below that is one of several messages I sent Mike asking him to relinquish the domain and the content to the group, or, failing that, to remove my name from it.
As I wrote in private to a couple of you, this is not a "moral equivalency" or "cultural relativism" situation. Mike was in a position of trust which he violated by taking down the web site of an active group and bouncing its mail.
[Note - this is the full Michael Sims message, from another copy]
From: "Michael Sims"
To: cwp@censorware.org
Date: Wed, 30 Aug 2000 17:04:42 -0400
Subject: Re: The CWP Unperson
Included below is the response that I started writing, and choked down, a few weeks ago. I think I had the thought that I ought not to escalate, perhaps Jim would come to his senses and realize how utterly and totally offensive it was to be compared to Big Brother. I suppose I could achieve the same response by comparing Jim or Jamie or Jonathan to Adolf Hitler, or Goebbels, or Mengele. I don't know what might achieve the same reaction from Bennett - perhaps comparing him to Brian Milburn? Those depths are too low for me to plumb, however.
In any case, since Jim has so kindly provided Seth with the cruelest criticism I've ever received, I shall never hear the end of it. Thanks, Jim. You're a real friend.
The Censorware Project is now closed.
Good luck, Bennett. You've taken the wisest course. I don't know whether it was true wisdom or merely luck... Jonathan, I don't know what you're up to, really, but I hope you will continue to make (it will have to be made, you can't simply wait for opportunities) time to write. Jamie I will continue to see since we work for the same company - I hope introducing Jamie to Andover is not a decision I shall also regret.
Jim, you and Seth can go fuck yourselves. I wouldn't treat a dog the way you've treated me. Hell, I wouldn't treat Seth the way you've treated me.
------- Forwarded message follows -------
Date sent: Fri, 4 Aug 2000 07:44:47 -0400 (EDT)
From: Michael Sims
To: jellicle@inch.com
Subject: Re: The CWP Unperson
On Fri, 4 Aug 2000, James S. Tyre wrote:
> You and he have become enemies, and there is nothing which I can do about
> that, apparently.
I don't think you should confuse an unwillingness to become involved with impossibility.
> But you can not deny the contributions he made, that CWP likely never
> would have existed but for him.
>
> He had been listed as a former member, though I do not recall the exact
> language. Unpersoning him is just wrong.
>
> Please reconsider.
Seth's attacks have far outweighed any work he's ever done. At this point, I can say with some assurance that the Project would have been more successful in the long run had Seth never been a part of it.
I decided that I might as well fulfill
Jonathan Wallace's account of Michael Sims' destruction of censorware.org
[From a public mailing-list posting ] Date: Sat, 4 Nov 2000 16:49:46 -0500
From: Jonathan Wallace
Subject: The Censorware Project
To: CYBERIA-L[at-sign]LISTSERV.AOL.COM
I've been trying hard to avoid washing dirty laundry in public, but a couple of recent posts have raised the issue and I'd like to give an account of what happened to the Censorware Project (the site at http://censorware.org is now offline). What we have here is the spectacle of a group member who volunteered to act as webmaster effectively closing a group which wants to continue, because the domain happened to be registered in his name.
The Censorware Project was originally an informal collective of six people who collaborated online to fight censorware: Seth Finkelstein, Bennett Haselton, Jamie McCarthy, Mike Sims, Jim Tyre and myself. After Seth left the group, the remaining five continued. Several of us had never met or even spoken on the phone, yet for some time--around two years as I recall--we had a remarkably easy collaboration. There was no funding, no hierarchy, no titles, not even project managers. Someone would suggest a project and take the responsibility for a part of it, others would sign up for other elements, and proceeding this way we got a remarkable amount of work done, including reports on X-Stop, Cyberpatrol, Bess and other products.
Even though two of us were attorneys--Jim and myself--we never incorporated the group or wrote a charter or any contracts among ourselves. Mike Sims was obliging enough to register the domain, just as other members paid for press releases and the other incidental expenses which came along.
Robert Frost said that "nothing gold can stay," and the Censorware Project was no exception. Over the summer, Mike Sims' reaction to a perceived slight was to take the site down for a week, exactly as Seth says in his mail. He sent us mail at the time saying something like "The Censorware Project is over." I replied to him that, given that the group was a collective and we all had an interest in its work product, the domain, and the goodwill it had achieved, the decision was not his to make. Sims did not reply.
Mike put the site back up a week later without explaining, let alone apologizing for, his actions. Given his continuing failure to answer any email from me (and I think from others) and the overall signs that Sims thought the group was exclusively his, I wrote him several emails requesting that he turn the domain over to Jamie or Bennett, as I felt we could no longer trust him to administer it. We also found out during that time that important email from people trying to contact us, including members of the press, was not being answered by Sims, nor being forwarded to other members.
I ultimately became exasperated that my name was listed as a principal on what had now become a "rogue" site I had no control over. Over about a five week period, I wrote Sims several more emails asking him to delete my name from the site if he wasn't going to transfer the domain. Again, I received no reply.
Today, Sims took the Censorware Project site offline again, with a message which says "Due to demands from some of the people who contributed, in however minor a fashion, to this site, it has been taken down." Judging from some email I received from him today, this means me.
Its a sad thing, both because we got some good work done and because some of the other members of the group were eager to continue and in fact have continued working, while deprived of the Censorware Project site, name, email aliases and public recognition. These further efforts are appearing on Bennett Haselton's Peacefire site, www.peacefire.org. (I applaud the work but take no credit as I have not been involved in some time.)
On the page currently at www.censorware.org Sims makes the following request: "If you are interested in volunteering to fight censorware, please contact me." One of the reasons I
Bennett Haselton on Michael Sims' hijacking of censorware.org
:)
[These are comments by Bennett Haselton (Peacefire ) regarding the lack of consequences for Slashdot "editor" Michael Sims' domain-hijacking of censorware.org , and how it's not a case of truth-is-in-the-middle. Used with permission.]
[This was written to someone who made a plea to resolve the conflict, but also refers to trivializing and dismissive comments made in a public interview by Michael Sims' supervisor at Slashdot ]
Date: Sat, 20 Apr 2002 10:03:02 -0700
From: Bennett Haselton
Subject: Re: Please resolve the censorware conflict.
Any discussion of the Censorware.org controversy has to start from the fact that Michael and the rest of the former CWP are not "equal sides" in this, are not "both right and both wrong", etc.
Michael did not own the Censorware Project and did not do a majority of the work involved, he just hi-jacked the domain name and stole it from the rest of us. The fact that people look at what he did, and look at the response from the rest of the group, and call it "infighting" or "airing dirty laundry" is frankly an insult to the Censorware Project and its work. If the EFF webmaster put the eff.org domain in his own name and then hi-jacked it from the organization, he'd be branded a traitor and a pariah in the Internet community for the rest of his life, and nobody would ever forget what he did. Same if it was the CPSR.org webmaster, the EPIC.org webmaster, or whoever. But if the Censorware Project webmaster does it, we're expected to "work out our differences" with him?
There is an absolute difference between Michael and the rest of us. None of us, despite some personal animosities (not between me and anybody, but between people that I know), would ever, ever do anything like what Michael did. But Michael did it.
It doesn't matter whether or not Michael promotes anti-censorship work in his position as a Slashdot writer; he's hardly making much a difference by saying things that were going to get said anyway, and nothing he does there will ever come close to canceling out the harm he did by shutting down the one-time Censorware Project website.
The only legitimacy that Michael has is through his position as a Slashdot writer; he has just enough writing skills to make his writings sound seductively intelligent to anybody who doesn't know the real story. The fact that Slashdot hired Michael should be deeply embarrassing to them, and is in fact eroding Slashdot's credibility according to comments made by some people who found out about the Censorware.org site. But Slashdot is apparently too deeply wedded that decision to reconsider, and comments from [Michael Sims' direct supervisor] have been more of the same along the lines of "They should work out their differences" instead of acknowledging Michael Sims's utterly disgraceful behavior as compared to the average person. You think Slashdot really believes Michael is trustworthy, after what he did? Do you think they're going to let him put the Slashdot.org domain in his name?
-Bennett
Checking the IP that panix.com is on shows several thousand domains, and all seem to have odd names.
That Las Vegas address used for panix.com is also similar to some used by spammers registering domains, and using a Nevada address in the whois.
Maybe a check of some of the blocklists will show the panix.com IP listed already. 142.46.200.72
You could try this link and see if the server is still up. (hint, slashdot effect)
Pete Carr Owner Chatmag.com
Why is panix offering 128Kbps ISDN for $50 a month? Who actually uses this?
FAILED
The Melbourne IT Registry Key for Domain Name panix.com was not able to be retrieved. This could be due to the Domain Name being managed by a Melbourne IT Reseller. Please contact your Reseller for assistance. If this fails, please go to our help center.
www.panix.com is coming up with a freeparking.co.uk web page. This means that SOMEONE is handling DNS for the domain. That is the one piece of useful information in the current whois record. ns1.ukdnsservers.co.uk
OK, looks like ukdnsservers.co.uk belongs to:
Domain Name:
ukdnsservers.co.uk
Registrant:
ActiveBytes Software LLC
Administrative Contact's Address:
2530 Channin Drive
Wilmington
DE
19810 US
Registrant's Agent:
Fibranet Services Ltd [Tag = FIBRANET]
Relevant Dates:
Registered on: 25-Mar-2000
Renewal Date: 25-Mar-2006
Last updated: 11-Dec-2004
Registration Status:
Registered until renewal date.
Name servers listed in order:
ns3.ukdnsservers.co.uk 142.46.200.68
ns4.ukdnsservers.co.uk 207.61.90.197
This is a company on US soil. If the authorities have been contacted, the FBI should be breaking down these guys' doors right about now, cause they're involved in what could be considered an act of international terrorism, and I'm not being sarcastic. Either ActiveBytes Software, or one of their representatives has knowingly set up DNS records for panix.com, or they have been hacked.
Unfortunately, it appears that even though their offices may be in Delaware, their DNS is a little farther north:
traceroute 142.46.200.67
(Most of traceroute omitted to pass bullshit lameness filter)
23 145 ms 75 ms 74 ms AL-7304-GigE2.telecomottawa.net [142.46.200.1]
24 82 ms 85 ms 88 ms 142.46.200.67
Trace complete.
traceroute 207.61.90.197
(Most of traceroute omitted to pass bullshit lameness filter)
18 65 ms 75 ms 64 ms core1-ottawa23-pos2-2.in.bellnexxia.net [64.230.234.90]
19 221 ms 204 ms 217 ms ottcorr01-pos5-0-0.in.bellnexxia.net [206.108.99.146]
20 Request timed out.
21 244 ms 183 ms 225 ms ns4.ukdnsservers.co.uk [207.61.90.197]
Trace complete.
Maybe someone at telecomottawa.net could be contacted to track these people down or help out in some small way. Here's their Customer Care Page They have a toll-free number! Let's see if enough of us call it, or perhaps if enough of Panix's unhappy customers call it, maybe TelecomOttawa will help out (wouldn't it suck if someone were to steal the telecomottawa.net domain name from them in a similar fashion?) Anyway, the TF# is 1-888-424-7771 (X3?)
Man, this really pisses me off that someone was able to do this, and that these guys aren't having any luck getting the problem fixed.
These people looked deep into my soul and assigned me a number based on the order in which I joined.
Does anyone know where, or how, one can discover the provider for any given email address? For example, if I have an email account "@consultant.com," it turns out that I log into www.mail.com to sign-up for and use that suffix/account. Is it possible to figure out where/who issues any given address or type of address? Thanks! David
It's 9pm on a Sunday night for melbourneIT at the moment. At worst, they'll be open in twelve hours time from now.
Si tacuisses philosophus mansisses. If you had kept quiet, you would have remained a philosopher.
look at the NANOG discussion. After everyone and their brother tried to get in touch with melbourne IT to let them know there was a problem, Melbourne IT's response was to have its corporate legal counsel call Panix and tell them they wouldn't do anything to help until Monday even if the Oz police themselves called and asked them to. "copping a lot of shit for something that's not their fault" ha ha ha.
Cyber police?
First name server is ns1.ukdnsservers.co.uk, iP 142.46.200.67
Connecting to whois.arin.net...
Telecom Ottawa Inc. HOT-TELECOMOTTAWA-9 (NET-142-46-199-0-1) 142.46.199.0 - 142.46.202.255
Koallo Inc. TOL-142-46-200-64-95 (NET-142-46-200-64-1) 142.46.200.64 - 142.46.200.95
# ARIN WHOIS database, last updated 2005-01-15 19:10
So, IPs 64-95 belong to Koallo, Inc. A little Googling turns up the following:
http://www.whois.sc/bellsquarry.info
Which lists the Registrant as one Ann Street, 5 Calder Road, Bellsquarry, Livingston, GB. ann.street@btinternet.com
Fake? Probably. But I'd be sending some buddies with baseball bats over to check it out, anyway, and also to 2530 Cannin Drive, Wilmington, Delaware.
These people looked deep into my soul and assigned me a number based on the order in which I joined.
You can slashdot this site: http://freeminimacs.slashdot.us/
http://freeminimacs.slashdot.us/
This is a superb example of "irony," oft-misapplied on Slashdot, not hypocricy.
Ignorance is curable, stupid is forever.
How about: You suck?
bash$
And get you a free Mac at the same time?
st3v@hotmail.com?
The system had the verbosity of HTML combined with all the readability of compiled assembly viewed as bitmap images
"The Bush-Cheney White House. You will never find a more wretched hive of scum and villainy. www.whatreallyhappened.com"
I think that is excessively positive for a group that has borrowed so much the U.S. has more debt than ever before.
Genesis 11 The LORD said, "If as one people speaking the same language they have begun to do this, then nothing they plan to do will be impossible for them. 7 Come, let us go down and confuse their language so they will not understand each other."
8 So the LORD scattered them from there over all the earth, and they stopped building the city. 9 That is why it was called Babel [c] -because there the LORD confused the language of the whole world. From there the LORD scattered them over the face of the whole earth.
Physics is like sex: sure, it may give some practical results, but that's not why we do it.
... no idea how seriously they are taking the matter though.
i'd love to see someone arrested from this...
Funnily enough, they're the registrar for the scam site http://american-redcross.org/.
Coincidence? You decide.
Peter
Where is the DCMA when you need it?
I don't disagree with any of your points but one thing I did like about them is that I could email them and say, "This customer is having issues with their domain record control, could you please call them." and the customer would get a call back.
Try doing that with Verisign or netsol. ha!
I haven't tried this in many years so I'm not sure if it's still possible to pull it off.
The man who trades freedom for security does not deserve nor will he ever receive either. - Benjamin Franklin
DNS Report DNS Report for panix.comGenerated by www.DNSreport.com at 13:18:18 GMT on 16 Jan 2005. status = "Getting data from root..."; CategoryStatusTest NameInformation Parent PASSMissing Direct Parent checkOK. Your direct parent zone exists, which is good. Some domains (usually third or fourth level domains, such as example.co.us) do not have a direct parent zone ('co.us' in this example), which is legal but can cause confusion. INFONS records at parent serversYour NS records at the parent servers are: /24) range, because the root servers are not sending glue. We plan to add such a test later, but today you will have to manually check to make sure that they are on separate Class C ranges. Your nameservers should be at geographically dispersed locations. You should not have all of your nameservers at the same location. RFC2182 3.1 goes into more detail about secondary nameserver location.
PASSAll NS IPs publicOK. All of your NS records appear to use public IPs. If there were any private IPs, they would not be reachable, causing
ns1.ukdnsservers.co.uk. [142.46.200.67 (NO GLUE)] [CA] ns2.ukdnsservers.co.uk. [207.61.90.196 (NO GLUE)] [CA] [These were obtained from f.gtld-servers.net] PASSParent nameservers have your nameservers listedOK. When someone uses DNS to look up your domain, the first step (if it doesn't already know about your domain) is to go to the parent servers. If you aren't listed there, you can't be found. But you are listed there WARNGlue at parent nameserversWARNING. The parent servers (I checked with f.gtld-servers.net.) are not providing glue for all your nameservers. This means that they are supplying the NS records (host.example.com), but not supplying the A records (192.0.2.53), which can cause slightly slower connections, and may cause incompatibilities with some non-RFC-compliant programs. This is perfectly acceptable behavior per the RFCs. This will usually occur if your DNS servers are not in the same TLD as your domain (for example, a DNS server of "ns1.example.org" for the domain "example.com"). In this case, you can speed up the connections slightly by having NS records that are in the same TLD as your domain. status = "Waiting for NS results from your nameservers..."; NS INFONS records at your nameserversYour NS records at your nameservers are:
ns1.ukdnsservers.co.uk. [TTL=86400] ns2.ukdnsservers.co.uk. [TTL=86400] PASSAll nameservers report identical NS recordsOK. The NS records at all your nameservers are identical. PASSAll nameservers respondOK. All of your nameservers listed at the parent nameservers responded. PASSNameserver name validityOK. All of the NS records that your nameservers report seem valid (no IPs or partial domain names). PASSNumber of nameserversOK. You have 2 nameservers. You must have at least 2 nameservers (RFC2182 section 5 recommends at least 3 nameservers), and preferably no more than 7. PASSLame nameserversOK. All the nameservers listed at the parent servers answer authoritatively for your domain. PASSMissing (stealth) nameserversOK. All 2 of your nameservers (as reported by your nameservers) are also listed at the parent servers. PASSMissing nameservers 2OK. All of the nameservers listed at the parent nameservers are also listed as NS records at your nameservers. PASSNo CNAMEs for domainOK. There are no CNAMEs for panix.com. RFC1912 2.4 and RFC2181 10.3 state that there should be no CNAMEs if an NS (or any other) record is present. Note that I only checked panix.com, I did not check the NS records, which should not have CNAMEs either. PASSNo NSs with CNAMEsOK. There are no CNAMEs for your NS records. RFC1912 2.4 and RFC2181 10.3 state that there should be no CNAMEs if an NS (or any other) record is present. WARNNameservers on separate class C'sWARNING: We cannot test to see if your nameservers are all on the same Class C (technically,
LISTSERV.AOL.COM
All involved parties just lost all credibility.
fast as fast can be. you'll never catch me.
We started in 1989, before the advent of the Internet.
Who knew?
But the inverse isn't necessarily true.
10 PRINT CHR$(205.5+RND(1)); : GOTO 10
As of 8:30 AM 2005-01-16, the moderation stands at: "40% Informative, 10% Offtopic, 10% Troll". So, what is the remaining 40%?
...I thought the ISP I worked for was *one* of the oldest (not the oldest but one of them.) Then I remembered, our place was started in 1991. They had us beat by two years! Ours was only a BBS then...
... do the domain hijackers as well? Anyone wanna go on a butt-kicking expedition? Actually looks like the hijackers live in Las Vegas, if they didn't fake the whois info.
On the topic, seeing as I live in NY
FLR
POTS not good enough?
10 PRINT CHR$(205.5+RND(1)); : GOTO 10
The Hitchhiker's Guide to the Galaxy : Don't Panix :)
Pretty bad when your mail doesnt come to you..
Espcially if you are business taking orders.. or have the potential for confidential or personal info being in your emails..
Good thing we all encrypt our mail.. right?
---- Booth was a patriot ----
What I don't understand is how both Melbourne IT and Verisign seem to be involved in domain registration. Unless I'm missing something, you register with Verisign and that's that. I am a Panix customer and have my own website registered through Verisign. Another question. I am surprised that Panix did not mention anything about changing passwords. If my mail is being routed to some mail server in Canada, can anybody read it even if they don't have my password? Finally, on the question of Panix going out of business. That would be a real shame. I have been using them since 1998 and am *very happy* with their service. Unlike some of the giants, you always get tech support in under a minute. And they know what they are doing.
Verisign has spent big $$$ to advertise its brand as the choice for heavyweight corporate customers. It boggles my mind that they're letting a high-visibility ISP twist in the wind. Talk about brand devaluation.
Any slashdot reader in coroporate IT should be writing a memo on this and sending it to the CIO/CTO and Legal teams. What will *your* company's registrar do if someone jacks your domain on a weekend? If you're paying the bucks for Verisign, the answer seems to be nada, or maybe they'll write you an infuriating not-out-problem e-mail.
I think the marketing/sales task for Verisign's competitors just got a notch easier too. Nothing like a good horror story...
Date: Sun, 16 Jan 2005 10:07:04 +0000
:43 is broken. They want perfect data at no cost and w/o restriction. Registrars don't want slamming, today's owie, and registrants don't want spam (which some ISPs do), so the whole :43 issue is a trainwreck of non-operational interests overriding operational interests. Registrars would be happy to pump :43 data to operators, if we could manage the abuse, instead we get knuckleheads who insist that spam would be solved forever if ...]
From: Eric Brunner-Williams in Portland Maine
To: nanog@merit.edu
Cc: brunner@nic-naa.net, alexis@panix.net
Subject: Re: panix.com hijacked (VeriSign refuses to help)
Oki all,
Its dawn in Maine, the caffine delivery system has only just started, but I'll comment on the overnight.
You're welcome alexis@panix.net. If you'll send me the cell phone number for the MIT managment I will call wearing my registrar hat and inform whoever I end up speaking with that Bruce needs to call me urgently, on Registrar Constituency business.
Next, put a call into the Washingtom Post. They lost the use of the name "washpost.com" which all their internal email used, to due to expiry, so their internal mail went "dark" for several hours. This was haha funny during the primary season (Feb 6). If they don't get it try the NYTimes. Put the problem on record. There is an elephant in the room.
The elephant is that the existing regime is organized around protecting the IPR lobby from boogiemen of their own invention. They invented the theory that trademark.tld (and trademark.co.cctld) existence dilutes the value of trademark, hence names-are-marks, bringing many happy dollars (10^^6 buys) into the registrar/registry system ($29-or-less/$6, resp., per gtld and some cctlds), and retarding new "gTLD" introductions, as each costs the IPR interests an additional $35 million annually.
To solve their division of spoils problem, is "united.com" UAL or is it UA?, we had DRPs, which is now a UDRP, and more DRPs for lots of cctlds.
These [U]DRPs take many,many,many,many units of 24x7. They were invented for the happy IPR campers, who care about _title_, not _function_. If the net went dark that would be fine with them to, so long as the right owners owned the right names.
Restated, there is no applicable (as in "useful for a 24x7 no downtime claimant") law in the ICANN jurisdiction.
And it is your own damn fault. Cooking up the DRPs took years of work by the concerned interests, and they were more concerned with enduring legal title then momentary loss of possession. During those years, interest in the DNSO side of ICANN by network operators went from some to zero, and at the Montevideo meeting the ISP and Business constituencies were so small they meet in a small room and only half the seats were taken. After that point they were effectively merged. IMHO, Marilyn Cade and Phillipe Shepard are the ISP/B Constituency, and they can't hear you (for all 24x7 operational values of "you").
In case it isn't obvious, the "your own damn fault" refers to a much larger class of "you" than Alexis Rosen.
[Oh, the same happy campers are why
There is a fundamental choice of jurisdictions question. Is ICANN the correct venue for ajudication, or is there another venue? This is what recourse to the "ask a real person" mechanism assumes, that talking to a human being is the better choice.
Bill made this comment:
> Since folks have been working on this for hours, and
> according to posts on NANOG, both MelbourneIT and
> Verisign refuse to do anything for days or weeks,
> would it be a good time to take drastic action?
>
> Think of what we'd do about a larger ISP, or the
> Well, or really any serious financial target.
>
> Think of the damage from harvesting logins and
> mail passwords of panix users.
You (collectively) are
this technology is new but this type of scenarios should speed things up in making it a requirement for dns deployments.
Live your life each day as if it was your last.
"Who's panicking now, Biotch"
Panix at least used to have a lot of users with jobs like "NY Times reporter" and "Wall Street technology analyst." This story needs to be amplified to the point where there's a total restructuring of the domain registration system, one which removes Network Solutions entirely from the business. Can we assume that Panix users will be doing their part to play this up in the mainstream media capital of America?
"with their freedom lost all virtue lose" - Milton
Dude, that was nice.
And the slashdot moderators bitchslap him. This post is one of the many modded 100% insightful, with an overall score of one.
whois south-parsonalbanking.com
.com and .net domains can now be registered
.COM, .NET, .EDU domains and
Whois Server Version 1.3
Domain names in the
with many different competing registrars. Go to http://www.internic.net
for detailed information.
Domain Name: SOUTH-PARSONALBANKING.COM
Registrar: MELBOURNE IT, LTD. D/B/A INTERNET NAMES WORLDWIDE
Whois Server: whois.melbourneit.com
Referral URL: http://www.melbourneit.com
Name Server: YNS1.YAHOO.COM
Name Server: YNS2.YAHOO.COM
Status: ACTIVE
Updated Date: 15-jan-2005
Creation Date: 15-jan-2005
Expiration Date: 15-jan-2006
>>> Last update of whois database: Sun, 16 Jan 2005 07:38:23 EST
NOTICE: The expiration date displayed in this record is the date the
registrar's sponsorship of the domain name registration in the registry is
currently set to expire. This date does not necessarily reflect the expiration
date of the domain name registrant's agreement with the sponsoring
registrar. Users may consult the sponsoring registrar's Whois database to
view the registrar's reported date of expiration for this registration.
TERMS OF USE: You are not authorized to access or query our Whois
database through the use of electronic processes that are high-volume and
automated except as reasonably necessary to register domain names or
modify existing registrations; the Data in VeriSign Global Registry
Services' ("VeriSign") Whois database is provided by VeriSign for
information purposes only, and to assist persons in obtaining information
about or related to a domain name registration record. VeriSign does not
guarantee its accuracy. By submitting a Whois query, you agree to abide
by the following terms of use: You agree that you may use this Data only
for lawful purposes and that under no circumstances will you use this Data
to: (1) allow, enable, or otherwise support the transmission of mass
unsolicited, commercial advertising or solicitations via e-mail, telephone,
or facsimile; or (2) enable high volume, automated, electronic processes
that apply to VeriSign (or its computer systems). The compilation,
repackaging, dissemination or other use of this Data is expressly
prohibited without the prior written consent of VeriSign. You agree not to
use electronic processes that are automated and high-volume to access or
query the Whois database except as reasonably necessary to register
domain names or modify existing registrations. VeriSign reserves the right
to restrict your access to the Whois database in its sole discretion to ensure
operational stability. VeriSign may restrict or terminate your access to the
Whois database for failure to abide by these terms of use. VeriSign
reserves the right to modify these terms at any time.
The Registry database contains ONLY
Registrars.
Domain Name.......... south-parsonalbanking.com
Creation Date........ 2005-01-15
Registration Date.... 2005-01-15
Expiry Date.......... 2006-01-15
Organisation Name.... Douglas Hurcomb
Organisation Address. 1516 Hidden Valley Ln
Organisation Address.
Organisation Address. Rochester
Organisation Address. 48306
Organisation Address. MI
Organisation Address. UNITED STATES
Admin Name........... Douglas Hurcomb
Admin Address........ 1516 Hidden Valley Ln
Admin Address........
Admin Address........ Rochester
Admin Address........ 48306
Admin Address........ MI
Admin Address........ UNITED STATES
Admin Email.......... douglashurcomb@yahoo.com
Admin Phone.......... +1.2486568102
Admin Fax............
Tech Name............ YahooDomains TechContact
Tech Address......... 701 First Ave.
Tech Address.........
Tech Address......... Sunnyvale
Tech Address.........
120 chars is not bloody enough for a real sig!!! you bastards even count spaces!!!
Panix thought that they had all of their domains in registrar-lock status. When they checked panix.net and panix.org after panix.com got swiped, they were no longer locked.
.com registrations) allowed a domain to be transferred to a different regsitrar without following the published procedures. Even if a domain is not locked, there is a notification and waiting period that was ignored. Somehow MelbourneIT and Verisign short-circuited the system (quite possibly an inside job at both).
.net control is up for renewal soon and other companies may bid to take it away from Verisign; let's hope that happens (my main domains are all .net).
However, this has nothing to do with them being locked or not. The registrar Panix uses is Dotster, and they show no record of panix.com being transferred. In other words, Verisign (who is in charge of all
IIRC the
It's an exact copy of the redcross.org site, complete with VeriSign Secure Site logo (which, when clicked, verifies redcross.org and not american-redcross.org). It's registered through Yahoo domains to Elizabeth Cantrell of Alabama (probably false) and hosted by Yahoo. It was just created yesterday. Why doesn't yahoo lay the smack down on this scam immediately?
Remember, Panix was using Dotster as their registrar and not Network Solutions.
Where Network Solutions gets involved is that they are still responsible for the root servers (I think) and could change which registrar owns the name.
All I know is that this multiple registrars for the domains is just making things worse even though it caused registration rates to drop.
Anyone who believes Verisign is trustworthy isn't paying attention. I personally admire their competence almost as much as I admire their integrity....
What I say does not represent the views of my employers, my friends, my cats, or myself.
MelbourneIT just happens to be the back end registrar.
a quick google news search shows:
"Allan Sloan is Newsweek's Wall Street editor. His e-mail address is sloan@panix.com"
lets hope the press picks up on this and puts some pressure on the companies responsible. Maybe we'll see some much needed change in the registrar system.
.net is not just for internet infrastructure companies. It is also for a company's own network infrastructure.
.net .com & .org been used correctly in the past umpteen years?
Besides when has
and I lurk slashdot. Panix has been my main e-mail address for the last 14 years. I have found the panix staff to be very competent and the panix community very knowledgeable. As a victim, who and where can I register my complaint. I simply want my ISP back online. thank you
This does happen a lot more than you think. I started a blog to document it at Orangelimey.blogs.com
NSI is currently claiming that the transfer was legitimate - somehow the hijacker got into the administrative contact's email and compromised the accounts - how we still don't know. However, the person that ended up with the domain seems to be willing to give it back.
Really, the whole domain security thing is ridiculous. For a domain (which is considered property under a ruling from the appeals court in the sex.com case) to be transfered with such lax legal proceedings is pathetic. Can I steal your car or your house by simply faking email and guessing passwords? Of course not.
Maybe panix can make enough of a stink about this to get someone to stand up and take notice - although who can do this I don't know. ICANN is toothless and only cares about trademark disputes.
Someone told me as a result of this that 40,000 domains were hijacked in the last year. I don't know where this data comes from, but really, obviously something is wrong.
Feel sorry for panix, I used them when I lived in NYC
I experienced this once, me and some friends formed a group to do web work.
Well the guy in charge of our hosting forgot to renew the site. The site got taken by some name camper and they wanted something like $300 to get the domain back we were not willing to pay.
The temporary site the set up was hilarious had job postings for secretaries and had hot pictures of them. The company was out of the Bahamas or some place which is funny as i often go to the Caribbean! Anyway, it was nice to see some domain lurker schwag a domain and host a domain that was interesting, bunch of cute women looking for temp work, sure beats the way other domain lurkers schwag a site.
http://shit.slashdot.org/article.pl?sid=05/01/16/0 027213
Exsqueeze me? One of the biggest registrars that a lot of poeple have had trouble with is CLOSED for the weekend?
I run a bunch of (free) mailing lists and DNS for a variety of stupid things like cars, tropical fish, dns etc. I'm open 24/7 and get calls at 4:30 am, not happily, but I do fix stuff. That MIT as a multimillion dollar organization thinks it's ok to take the weekend off critical internet infrastructure should be enough to get their precious ICANN accreditation yanked. But given how much money MIT pays ICANN this will never happen.
Expect fully a press release from ICANN saying how responsive MIT was in this situation.
Welcome to the modern internet.
Need Mercedes parts ?
I *am* getting my panix.com mail by going to mail.panix.NET, and using their web-based mail client.
By way of background, I've been a Panix user for more than a decade. They are classy, intelligent people, which sets them apart from most folks in their line of work.
Isn't panix known for allowing questionale activity ? IIRC, Kevin Mitnick had a shell account with them before he was busted by the Feds. Mitnick used the account in his online crimes.
Any ISP that allows people like this to have shell accounts and then turn away while they do wrong, deserves whatever they get.
They got a taste of their own medicene and now they're upset... too bad.
First LiveJournal falls over due to Internap and then Panix was domainjacked?
What else is going to happen internet-wise this weekend?
(I know, I know, I really should not ask that question, it begs something to happen.)
In an environment like email where 90% of traffic is noise (spam), it is very likely that such emails would get lost, and I am sure ICANN are aware of this. Not to mention that this opens the possibility of bombing (i.e. send 100 transfer requests, you only need one to go unanswered). This ruling is idiotic and makes no sense. A domain is a lease, if it's paid up then it doesn't matter that you ignore somebody else wanting it. It's still yours.
Consider the following evidence against the infidels: anti-slash has recently compiled a library of injustices at anti-slash.org that precisely document the abuses of slashdot's editors. From the stupidity to the censorship, you can view and share the facts all recorded in one place.
I'd also like to take this opportunity to invite you to use the database tool at anti-slash.org. With this database of highly-moderated slashdot posts, you can repost and gain carma for future jihad operations, and suck up mod points and pollute the meta-moderation system. These disruptive activities help lower slashdot's already low signal-to-noise ratio and further discredit the editors.
In Sacred Jihad,
jihadi_31337
(Yes I'm shouting. I don't even have a caps lock key)
If the oppertunity presents itself to repair this it would be good to know what they are.
Need Mercedes parts ?
The main effect on users is that mail sent to panix's customers is being routed to a bogus mail server run by the hijackers."
IANAL, But doesn't this violate federal wiretap laws somehow? Intercepting communications intended for another party? Shouldn't the FBI be involved?
As it was unlawfully taken away from Panix, can't they take the same or similar steps and simply take their domain back? Presumably the jerks who did this in the first place aren't exactly in a position to cry foul.
As an aside, if not Panix, then why not IBM or ebay or Amazon? Is it a case of "nobody's tried this yet" or do the "big names" have something that everybody else doesn't? I would think microsoft.com is presumably just as vunerable to domain theft as joespixoftoilets.com. Also, while if the folks who did this to Panix were Aussies, and if they tried it with IBM or Microsoft, those companies would have lawyers literally pounding on the door of the offending registrar within minutes, who's to say the person can't do it at some ISP in Russia or some other country where the likelyhood of having any legal weight is practically nil?
Update: As of this morning, all web and mail traffic going to the hijacked panix.com domain goes in to a network black hole (A .0 address, to be exact). The listed email servers for panix.com do not respond to port 25 connections.
This means that email sent to name@panix.com will be queues by the sender's host for a period of three to five days, and will not be delivered to a malicious entity.
MelbourneIT, Verisign, ICANN, and anyone else responsible for this fiasco needs to quickly get their stuff together to this sender-queued mail does not bounce.
I think it's good that the response was what it was. After the lawsuits service providers like verisign will have learned an important lesson. Had they just put things back and said "opps" the chance to teach them them the importance of not letting this happen in the first place might have been lost.
I'm an American. I love this country and the freedoms that we used to have.
An address ending in .0 can be valid, it just depends on the netmask associated with the address.
Berryhill went to the house in Wilmington. The address is bogus.
Or rather the address is real but the guy we're looking for doesn't live there any more and the poeple there get all "sorts of wierd things".
This apparanly is not the first time this happened.
The lawyer in question has moved to PA.
John's gong home to check state corporate registration records to try to find him.
Need Mercedes parts ?
Don't panix! (-1, Not Funny.)
No matter how quickly this is resolved, I believe Panix will lose a noticable percentage of their customers.
In the case of a few people I know, they will keep their account until their [pre]paid time runs out, which could be up to almost a year.
So, the true extent of this domainjacking may not be known for many months unless Panix issues partial refunds to people cancelling their accounts.
And even then, I know some won't cancel for a couple of months at least to make sure they have caught everybody and updated their email addresses everywhere.
(Posted by Ed Ravin [staff]) Sun, Jan 16 2005 -- 5:41 PM
----------------
Recovery is underway from the panix.com domain hijack.
The root name servers now have the correct information, as does the WHOIS registry. Portions of the Internet will still not be able to see panix.com until their name servers expire the false data. More info soon.
-- Ed
There is someone out there who seems to really want my domain, really bad, but evidently not badly enough :-)
to warm me up by, say, buying me a beachfront house in Kaui and a nice Gulfstream as an ante to open negotiations
Now, I would never, ever, do anything stupid like forget to renew the registration (and I believe that anyone this careless *SHOULD* lose his registration.)
But aside from keeping it renewed, what should I be doing to protect my domain name?
I get calls once in a while, and I make it very clear to the callers that I am not interested in surrendering my domain to anyone, and that I do not even want to hear their offer (because I *know* it's not going to start with the house in Kaui and the Gulfstream, and that's not my price, that's the incentive to get me interested in talking about negotiating. I want my lawyers to be comfortable while we begin the negotiation process.)
I usually piss off the solicitors pretty bad by basically telling them they don't have anything to offer me to get my interest, and that since they've insulted me by calling without being prepared to meet my terms, then they are harassing me. They never get it.
But what stops them from simply *taking* my name?
-fb Everything not expressly forbidden is now mandatory.
ns1.access.net 198.7.0.1
ns2.access.net 198.7.0.2
Note that access.net DNS was _not_ hijacked. Just panix.com.
BTW, it's morning in Melbourne, and the root DNS is now fixed.
Ben "You have your mind on computers, it seems."
Slashdot's search engine turns up no articles for 'censorware.org' after the point in time that Michael Sims hijacked the domain, a grand total of 26 articles overall. That's if you search under 'Stories'. If you search 'Censorware.org' under 'Comments', it turns up exactly 18 comments. Interesting, considering that I've witnessed many, many threads about 'censorware.org' across dozens of articles Michael approved.
It seems as though Slashdot has anti-"Censorware.org" censorware built into their version of slashcode.
I fully expect this comment to disappear, at least from the search engine, if not the database.
Big Daddy, Johnny, Burp, Aunt Zelda, Scott, Slurp, Big Momma
This can be simple, like sending an E-mail confirmation of someone's (honeypot) E-mail address, and seeing if it gets spam at a later date. Then log all attempts to access the account.
For a more interesting example, if someone can quickly setup a reasonably official looking honeypot online banking site, then send an E-mail pretending to be the parent of a college student letting him know that his "allowance account" for the upcoming semester is online, with username and password and balance.
This could help out enormously in tracking down the culprits at a later date.
The root dns was never broken. The NS records for panix.com were wrong in the .com zone. The root DNS tells you where to find the pointers to the .com tld servers.
But I'm glad it's fixed.
Need Mercedes parts ?
The now defunct Mindvox was the first ISP in NYC. There was a bitter rivalry between the Panix and Mindvox people back in the early 1990's. Considering that Mindvox is now defunct its easy to try and say that it was Panix... but it really wasn't. Of course, Panix was always run by much more competant people that weren't shooting up heroin half the time.
More love for Slashdot, eh old troll?
Your advocacy of anything is a good sign the thing is pure bullshit. Let's go back in time and look at some of the M$ love fest, apologizing and Slashdot insulting from Bonch:
All of the above was found by looking at two pages of google results for bonch slashdot. More than half of the results were like those.
Well, that's enough fun for me for now. Thanks for playing, Bonch. I hope your account is deleted soon. Until then, I think I'll save this post and put it wherever you show up.
Don't fall for the propaganda. I've heard September 11 being used as an excuse to crack down on noisy parties. Lets keep it real, call these guys domain stealers or confidence trickers or whatever, and stop stirring people up.
The proper geek way to fix this is with BGP. Why hasn't anybody had the cajones to do this yet?
But... the proper "business" way to fix this is for Panix to sue the holy fawk out of all the domain registrar organizations both directly and indirectly involved in this domain-jacking episode for being negligent in failing to authenticate who actually had permission to move/manipulate the established domain.
Attack the registrars themselves with armys of lawyers to put the fear into them in order to force them to be abso-fawking-lutely positive that any serious domain changes are concretely proven to be legitimate before allowing those changes to be applied to the global DNS system.
Litigation, not technology, will be the ultimate fix for these kinds of problems.
If you're with godaddy and haven't locked yours, go check now. I just locked mine at godaddy.
They may lock new accounts by default... mine's a couple or three years old. I'm just saying don't count on your domain being locked unless you have locked it yourself.
Tech Public Policy stuff
Are you one of these people who don't know the difference between right and wrong? Who make excuses like "I did nothing illegal" when caught doing something WRONG?
Taking time to point out that something patently wrong is technically legal in order to defend or justify it is well....disturbing. It shows a clear lack of any sort of a moral compass, and that is a character flaw that is all too common in today's world.
Don't feel too bad, at least you're in famous (if not good) company. Bill Clinton, SCO executives, Enron Execs, etc. etc.
Lee
Muslim community leaders warn of backlash from tomorrow morning's terrorist attack.
Hmm that's not good news !
Chris ,
Php Programmers.
I have been a Panix customer for almost 10 years. I manage a number of domains with that address as a contact address. The hijackers could have requested the transfer keys to all of my registered domains. My domains could disappear tomorrow and without the contacts Alexis has, I might never get them back.
I have discovered a truly marvelous sig, unfortunately the sig limit is too small to contain i
Yeah, I mis-spoke. Sorry. I plead stress due to working all weekend.
Ben "You have your mind on computers, it seems."
Moderators: Please note that "bonch" is a known fanatical psycophant whose obnoxious offtopic rants are legend here on Slashdot. It doesn't matter what the topic is, he'll find a way to scrape in some pointless Microsoft shilling. While nobody expects us to love Microsoft in any way, his particularly tepid style of calling anyone he replies to "troll" or "liar" because he happens to disagree with whatever they're saying is well documented and should not be rewarded. If anything, bonch is the type of person that should not be part of the open source/free software community. He is an anathema to all that is good about free software.
/. subscriber, I invite you to look through some of his posting history. I guarantee that you'll be hard pressed to find someone that is more "out there" than bonch. You'll also probably notice he's got quite an AC following. Don't just read his posts, make sure you go through the replies.
I'm posting this so that you (the moderator) have some context to consider bonch and not mod him up whenever he posts his filler preformatted rants about installing Windows or whatever that unfortunately get him karma every single time and allow him to continue posting his trademark toxic crap (read on) day in and day out. You may consider this a troll - I consider it community service. And I ain't kidding.
If you're a
For example, in this recent post bonch not only calls the OP a troll but attempts to "tell it like it is" while making some vague argument about "MS". Yes, if you're confused, you're not alone. The reply (modded +0) proceeds to simply destroy his bogus argument. You will notice he did not reply. This is what some people call "drive-by advocacy". A sort of I'll just leave you with my thoughts here and move on to the next flamebait kind of deal. In fact, he almost never replies because he knows that his fanatical arguments simply do not hold up to any sort of discussion. It's not that he's chosen the wrong cause - he's just going at it in a completely wrong way.
More? Just read though this post and the subsequent replies. I guess this stands on its own.
More? Bad spelling in astounding conspiracy theories, more offtopic FUD and uninformed "I'm right, look at me" rants, promptly proven wrong. Worse even, bonch wants to be Bill Gates, apparently (that first one is a winner). I mean, really. You think?
FUD, FUD, FUD, FUD, offtopic FUD, and more FUD. This guy is like the Monty Python SPAM skit, but with FUD and more FUD instead of canned meat. Amazed yet? Don't forget that KDE and Gnome make you dumb, and it's all a Slashdot conspiracy. How low do you want to go? Maybe as low as this?
The infamous Fax Manifest? Nuclear fireballs? It goes on and on and on and on and on and on and on (troll?). Like the energizer bunny. Or take these two, which stretch the definition of weird.
It's up to you. We can get rid of this guy and make Slashdot a better place. I don't know about you, but I'd rather take the trolls and crapflooders over people like "bonch" any day. And I sure as hell don't want to be categorized along with him. This is not how you advocate free software, period.
"Never ascribe to malice that which is adequately explained by incompetence."