91.215.158.80 false positive?
#21
Posted 29 February 2012 - 03:36 AM
that MB team do it in such a way.
But back to one IP address from the whole range 91.215.156.0 - 91.215.159.255, back to IP address 91.215.158.80
It looks as there is not anything wrong with IP address 91.215.158.80. If there is something wrong then show me any of the malicious site below (all using IP address 91.215.158.80) and if there is not anything wrong, then please unblock IP address 91.215.158.80.
I'm asking again and again and again to show me evidence what is wrong 91.215.158.80. Do not block 91.215.158.80 becasue of some other IP address in same IP range. You should never do it such a way. It is completely wrong.
If there is one killer who living in one city then it does not mean that all citizens in that city are killers. And logical from MB is that all citizen in that city are killers.
It is exactly what you are doint for IP ranges 91.215.156.0 - 91.215.159.255. Because of one or two or even 100 wrong IP addresses you are blocking 10.000.
List of website using 91.215.158.80
www.ibrowse-dev.net
www.wordpressthemespark.com
www.costdental.org
www.theartofslowtravel.com
www.paulsmithsuk.com
microshots.org
www.proxyserverprivacy.com
www.pangasinandentist.com
www.ip-address.org
atacsolutions.com
www.adentistfind.com
neurontin.org
itsmynortheast.com
spotceleb.com
picturenames.com
home-design-ideas.net
www.maorlevi.com
soccermust.com
www.tezeo.com
www.afhussey.co.uk
www.medcates.com
edhardypro.com
latest-business.com
medica-now.com
bopabikers.com
www.collectionbuddy.com
celebrityflux.com
www.frantroadclinic.co.uk
www.flowforums.com
fuji.drillspirits.net
unicoinvest.com
www.marasusa-apartments.com
heykessy.com
www.ant-comics.com
goalbite.com
mega-webhosting.net
indianbee.com
steltect.com
www.undercovershadows.co.uk
www.petaworld.com
www.metalcreationsuk.co.uk
www.kidviduk.com
www.xhtmltemplates.eu
www.latestdentalnews.com
www.b4lhost.com
www.youdownload.newdigest.com
www.picturenames.com
www.robertsandson.co.uk
www.hotel-penarth.com
nice-items.com
www.warpdt.co.uk
www.web2design.gr
luxusdesignideas.com
intothenightgames.com
rakebackfulltilt.net
www.somer-solvit.co.uk
www.happypaws.org.mt
blog.atacsolutions.com
www.restorick.co.uk
starmountaingems.com
www.dora-explorer.co.uk
thethird.dk
www.lazertraxx.com
www.textbookwarehouse.co.uk
luxurydecoratingideas.com
celebrity-hub.com
www.costablancawriters.com
furnitureinteriorideas.com
marckerstein.com
www.yesbluff.com
www.lazytown-mall.co.uk
www.miditracks.co.uk
www.blitzkrieg.biz
www.londoncognitivetherapy.co.uk
homefurnituredesignideas.com
lokovita.net
www.zariex.com
agniveer.org
www.airsender.com
tfroc.net
www.webio.ro
www.sunpoker.biz
gaff.tv
www.tank-engine-thomas.co.uk
www.unlockworks.com
ethnologe.com
www.800-number.net
www.worldcup2010store.info
emailfaxphone.net
popconreality.com
www.roadbangkok.com
www.heathfieldscaffolding.co.uk
joaoluis.eu
www.venteasperge-france.com
fingerspace.co.uk
ruta47.com
bawal.com
photoblog.robbysmets.be
mikehillier.com
davidecanali.com
imillardplumbingandheating.co.uk
www.bestnewspaper.info
www.meddling-kids.co.uk
pinballroulette.org.uk
simsgalerie.com
www.simcookie.com
www.paintedcakes.net
juxtaposing.com
www.freetv-home.co.uk
satori.juxtaposing.com
www.prcboardexamresultsph.com
dmr.juxtaposing.com
www.fuelbillslashed.com
www.rethymnonhotels.eu
blog.mikehillier.com
www.ink-cartridge-mall.co.uk
leadership-qualities.net
restarick.org
www.amigaf1.co.uk
siberian-larch.com
www.manilastars.com
www.forum-camioane.com
www.lovedogmusic.co.uk
www.charlie-lola.co.uk
www.simonatomarchio.net
www.senshinkai.net
www.hotels2mykonos.com
www.promeco.dk
www.shadowsradio.co.uk
drillspirits.net
www.stp.ee
uhl.juxtaposing.com
cd.juxtaposing.com
www.bestread.info
www.toll-free-numbers.org
www.informationaboutcaves.net
www.handheldgpsuk.co.cc
www.toys-4-tots.co.uk
www.deepfryershop.co.uk
www.rukino-blog.info
www.edgarcollection.com
www.yoga-mall.co.uk
www.coachhandbags.eu
www.silverprice24.info
jointproblemsdogs.com
www.cheapheadphonesuk.co.cc
www.olgartrujillo.com
comics-home.com
www.dominikfejer.com
forum.popconreality.com
applicationinterface.net
house-infrance-for-sale.com
www.indeicy-sewernoiameriki.info
some.randomhash.net
ucl.juxtaposing.com
premiumthemewordpress.net
www.getyourlogo.in
www.kontiki-bonaire.com
www.acetrategic.com
otakucy.com
pvrbugs.futaura.co.uk
www.wegdromen.be
homeluxurydesign.net
www.filmy-vam.info
photo.greenfox.ro
worldwidebarguide.com
allmovieplace.com
kero-pics.com
vpsforscrapebox.com
www.demerdzhi.info
farumkyokushin.dk
the6o.com
www.genrih-muller.info
#23
Posted 29 February 2012 - 04:15 AM
---------------------------------------------------
Hello ...,
There is no issue with 91.215.158.80 and no other customer complaint about IP blockage yet.
Our data center have very restrict policy for abuse issues. If possible please tell them to send us "sheer volume of abuse logs" at support@downtownhost.com and we will take care of it.
Kind Regards,
Scott Pates
Downtownhost
#24
Posted 29 February 2012 - 04:35 AM
And little hint: trying to insult the person working on this is just going to get you ignored.
As an aside by the way, I don't know what your connection to the IP is, but lovely tidbit for you - whilst downtownhost.com cleaned one of the files on the site housing the exploit, he didn't clean it properly, which left at least 2 other files still housing exploit code. He was sent another e-mail about this earlier.
#25
Posted 01 March 2012 - 03:19 AM
Quote
The last information that i have is that all the malware files are cleaned now. Can you confirm it and wonder when you gonna to release the blockade of IP address 91.215.158.80.
#27
Posted 03 March 2012 - 06:32 PM
MysteryFCM, on 01 March 2012 - 03:25 AM, said:
Hmmm.... We are 3 days later and nothing has been changed. Not at all.
#29
Posted 04 March 2012 - 11:25 AM
Malwarebytes ask us to remove some sites (abandoned spammed blogs , /according to malwarebytes and don't know how they know) fake med sites or forums not even hosted in our server but with the domain pointing to it), even they ask us to remove sites which have problems with clickbank in order of get the IP block released, we wont tolerate nor we are going to accomplish with such extorsive request. Unfortunately for those who use the software, that IP is going to be blocked according to Steven Burn which works for Malwarebytes.
Just wanted to say our side of the history.
#30
Posted 04 March 2012 - 11:27 AM
#31
Posted 04 March 2012 - 11:59 AM
but also website with suspicious content (who can take such a role to decide what is good content and what not) - without any exploit.
And the websites that supposedly cheats Clickbank or whatever - that's are again website without exploit?
I'm seriously thinking about dropping of using MBAM because of very bizarre dealing with supposedly exploits and
about the way that websites are blocked (option "website blocking" should be renamed to "IP address" blocking.
You block actually not website but you block IP addresses with thousand websites).
#32
Posted 04 March 2012 - 04:08 PM
Those for example, heavily spammed, isn't just spam linking to the odd fraud - it's spam linking to everything else, and isn't just one or two posts or one site - the guy has several sites, all of which have the same issues. You're the one that has refused to do anything about it (and FYI, the domains resolve to your IP, there isn't a redirect anywhere else - you claimed the content is pulled from elsewhere server-side, not client-side, which makes it YOUR problem as well as wherever it is being pulled from).
As for your refusal to deal with it (and given the content of your other IPs, I wasn't surprised at your refusal ......), I've already escalated the cases to your upstream, so will be letting them and LE handle it (little hint: your host is on a Leaseweb IP range - and they do not permit fake meds for example).
#33
Posted 04 March 2012 - 04:13 PM
deny, on 04 March 2012 - 11:59 AM, said:
but also website with suspicious content (who can take such a role to decide what is good content and what not) - without any exploit.
And the websites that supposedly cheats Clickbank or whatever - that's are again website without exploit?
Clickbank issues aren't the cause for the block, and never have been, nor would they ever be.
As for the rest, had it only been a single domain at issue on a shared server, or less domains than actual "legit" domains, it wouldn't have been blocked. It's the volume of domains with issues out-numbering the legit domains, that are the cause for the block.
This particular IP is going to be continued to be blocked due not only to the domains with issues, but the hosts point blank refusal to deal with such.
#34
Posted 04 March 2012 - 05:30 PM
MysteryFCM, on 04 March 2012 - 04:08 PM, said:
Those for example, heavily spammed, isn't just spam linking to the odd fraud - it's spam linking to everything else, and isn't just one or two posts or one site - the guy has several sites, all of which have the same issues. You're the one that has refused to do anything about it (and FYI, the domains resolve to your IP, there isn't a redirect anywhere else - you claimed the content is pulled from elsewhere server-side, not client-side, which makes it YOUR problem as well as wherever it is being pulled from).
Quote
#35
Posted 04 March 2012 - 05:33 PM
MysteryFCM, on 04 March 2012 - 04:13 PM, said:
As for the rest, had it only been a single domain at issue on a shared server, or less domains than actual "legit" domains, it wouldn't have been blocked. It's the volume of domains with issues out-numbering the legit domains, that are the cause for the block.
This particular IP is going to be continued to be blocked due not only to the domains with issues, but the hosts point blank refusal to deal with such.
#36
Posted 04 March 2012 - 05:38 PM
JorgeC, on 04 March 2012 - 05:30 PM, said:
I asked you to get it cleaned or suspended - there's a difference.
JorgeC, on 04 March 2012 - 05:30 PM, said:
How am I lying? I asked you to take action, you refused - plain and simple.
#37
Posted 04 March 2012 - 05:43 PM
JorgeC, on 04 March 2012 - 05:33 PM, said:
Errr no, think you'll find I'm not. I didn't mention unlawful. I said the list of sites needed dealt with. I deliberately didn't say how they needed dealt with, due to some simply needing cleaned (i.e. those heavily spammed). I also deliberately didn't bother sending you the list of splogs, as I knew you wouldn't deal with those (there were 78 splogs alone).
#38
Posted 04 March 2012 - 05:45 PM
Quote
My apologies for the confusion on this one
#39
Posted 04 March 2012 - 05:49 PM
MysteryFCM, on 04 March 2012 - 05:38 PM, said:
So? I don't really care, you can't nor should ask to a host to clean a forum or suspend the account, is just an abandoned forum with spam links, big deal.
Quote
How am I lying? I asked you to take action, you refused - plain and simple.
I refused to remove sites that are not illegal, I did took actions with countefied sites and with sites with malware, that's how you are lying.
#40
Posted 04 March 2012 - 05:53 PM
MysteryFCM, on 04 March 2012 - 05:43 PM, said:
Besides that I really don't know who you think to are to request that we remove splogs, no, I wont remove them, nor will request to the owners to do it.
0 user(s) are reading this topic
0 members, 0 guests, 0 anonymous users












